Skip to content
tag — patching

grep -rl "patching" ./articles

#patching

20 articles

REPLICATION was never a read-only privilege. For twelve years it was a shell

2026-09-07Security

CVE-2026-6471 lets any account holding PostgreSQL's REPLICATION attribute load an arbitrary library as a logical decoding plugin and run code as the postgres user. It has been there since logical decoding shipped in 9.4 in 2014, and REPLICATION is the privilege every CDC pipeline in your estate already has.

PaperCut is being exploited, and one of the signs is that your log file is missing

2026-08-29Security

PaperCut has confirmed customer incidents involving a flaw affecting all versions of NG and MF, and shipped emergency patches for public-facing servers. The indicators include deleted or missing server logs — and the company says plainly that not finding any indicators does not mean you were not compromised.

Exploited since January, added to CISA's list in August, due in three days

2026-08-25Security

CVE-2026-21962 is a CVSS 10.0 flaw in Oracle's HTTP Server and WebLogic proxy plug-in. Oracle patched it on 20 January. Exploit code appeared on 22 January and a honeypot logged attacks the same day. CISA added it to the Known Exploited Vulnerabilities catalog on 24 August with a due date of 27 August — and under a directive nobody noticed replacing the old one, agencies now have to check whether they were already breached.