Security NEXTJuly 23, 2026🇯🇵Translated from Japanese

Dell Releases Security Update for PowerProtect Data Manager Fixing 359 Vulnerabilities

Dell has released a comprehensive security update for its data protection solution Dell PowerProtect Data Manager, addressing a total of 359 vulnerabilities across both native code and third-party components.

The company published security advisory DSA-2026-287 on July 14, 2026, classifying the issues as Critical and strongly recommending that customers apply the patches without delay.

Among the six product-specific vulnerabilities, CVE-2026-40712 affects the REST API due to insufficient input validation. Although exploitation requires high privileges, successful attacks can lead to further privilege escalation. A second flaw, CVE-2026-49499, arises from incorrect security token generation and also enables privilege escalation.

According to the Common Vulnerability Scoring System CVSS v3.1, CVE-2026-40712 received a base score of 9.1 while CVE-2026-49499 scored 8.8. The remaining four native vulnerabilities were rated between 6.0 and 7.2.

The update also resolves 353 vulnerabilities in dependent third-party software. These include 130 issues in the Linux kernel as well as flaws in Apache Log4j, Apache Tomcat, Samba, PostgreSQL, OpenSSL, glibc, Vim, and several other libraries.

Dell advises all users to upgrade to PowerProtect Data Manager 20.2.0.0 or later to eliminate the reported risks.

Related articles

AntiMalwareVulnerabilities & Exploits

AI Uncovers Zoom Vulnerabilities Allowing Silent Device Takeover via Screen Sharing Annotations

Researchers at A Security identified multiple vulnerabilities in Zoom that enabled attackers to compromise participant devices during video calls without any user interaction. The flaws resided in the shared annotations protocol used for drawing and marking on shared screens. Victims only needed to join a meeting where screen sharing was active, affecting both regular participants and meeting organizers. The discovery was notable because it relied on publicly available AI models, requiring fewer than 20 prompts to locate the issues and build a working exploit prototype. The vulnerabilities impacted Zoom clients across Windows, macOS, Linux, iOS, and Android. Zoom addressed the problems through security bulletin ZSB-26015 with server-side and client patches. The research highlights how AI can dramatically accelerate vulnerability discovery compared to traditional manual analysis.

HispasecVulnerabilities & Exploits

Attackers Exploit Critical CVE-2026-59310 in VMware vCenter for Persistent Remote Access

A critical vulnerability identified as CVE-2026-59310 in Broadcom VMware vCenter Server is being actively exploited in the wild against internet-exposed instances. The flaw resides in the Syslog server component and enables remote code execution through a path traversal weakness, carrying a CVSS score of 9.8. Attackers have been observed deploying malicious cron jobs and the reverse_ssh tool to establish persistent outbound command-and-control channels since early August 2026. The campaign has impacted 361 unique IP addresses across 47 countries, with notable concentrations in Germany, the United States, Turkey, Iran, and France. Broadcom has released patches under advisory VMSA-2026-0006.1, which also addresses the related CVE-2026-59309, and strongly recommends immediate updates along with network segmentation and log reviews. No workarounds exist, making prompt patching the only effective mitigation.

BoletimSecVulnerabilities & Exploits

SAP Releases August Security Update Patching 28 Vulnerabilities Including Critical CVSS 10 Flaw

SAP has issued a broad security update to address multiple critical vulnerabilities that could enable code injection, memory corruption, and privilege escalation across enterprise systems. The August package includes 28 new security notes along with a GitHub advisory and two prior fix updates. The highest-severity issue, CVE-2026-58231, carries a maximum CVSS score of 10 and affects the Data Hub Adapter in SAP Commerce Cloud versions 2211 and 2211-JDK21, allowing remote exploitation without user interaction due to improper authorization. Another critical flaw, CVE-2026-44772 rated 9.9, impacts SAP Manufacturing Integration and Intelligence 15.4 and 15.5, permitting malicious code injection into industrial process monitoring systems. Additional vulnerabilities rated 9.1 and lower cover directory traversal, SQL injection, XSS, XXE, hardcoded credentials, and OS command injection across various corporate components. Administrators are advised to identify affected systems and prioritize installation of the critical patches first.

BoletimSecVulnerabilities & Exploits

Zoom Patches Zoomsday Vulnerability Enabling Remote Code Execution in Meetings

Zoom has addressed four vulnerabilities that could allow attackers to compromise meeting participants, including flaws leading to remote code execution without any victim interaction. The most severe issue, CVE-2026-53413, rated 8.3 and nicknamed Zoomsday, resides in the annotation feature used for drawing, highlighting, or adding text during screen sharing. This component processes network data using fixed 128-byte buffers without proper size validation, enabling memory corruption that alters program execution flow. Researchers demonstrated the attack on macOS by silently launching Safari on the victim's machine. The flaws affect Zoom Workplace, Zoom Rooms, Meeting SDK, and VDI clients. Users must update to patched versions such as Workplace 7.1.5 or 7.0.6, and Zoom Rooms or Meeting SDK 7.1.5 to mitigate annotation-related risks. No active exploitation has been observed publicly, yet centralized enterprise deployments require priority updates since attacks can occur during live meetings.