By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Dozens of Vendors Patch Security Flaws Across Enterprise Software and Network Devices
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > Dozens of Vendors Patch Security Flaws Across Enterprise Software and Network Devices
Computing

Dozens of Vendors Patch Security Flaws Across Enterprise Software and Network Devices

News Room
Last updated: 2026/03/11 at 8:37 AM
News Room Published 11 March 2026
Share
Dozens of Vendors Patch Security Flaws Across Enterprise Software and Network Devices
SHARE

Ravie LakshmananMar 11, 2026Vulnerability / Enterprise Security

SAP has released security updates to address two critical security flaws that could be exploited to achieve arbitrary code execution on affected systems.

The vulnerabilities in question listed below –

  • CVE-2019-17571 (CVSS score: 9.8) – A code injection vulnerability in SAP Quotation Management Insurance application (FS-QUO)
  • CVE-2026-27685 (CVSS score: 9.1) – An insecure deserialization vulnerability in SAP NetWeaver Enterprise Portal Administration

“The application uses an outdated artifact of Apache Log4j 1.2.17 that is vulnerable to CVE-2019-17571,” SAP security company Onapsis said. “It allows an unprivileged attacker to execute arbitrary code remotely on the server, causing high impact on confidentiality, integrity, and availability of the application.”

CVE-2026-27685, on the other hand, stems from missing or insufficient validation during the deserialization of uploaded content, which could allow an attacker to upload untrusted or malicious content.

“Only the fact that an attacker requires high privileges for a successful exploit prevents the vulnerability from being tagged with a CVSS score of 10,” Onapsis added.

The disclosure comes as Microsoft shipped patches for 84 vulnerabilities across products, including dozens of privilege escalation and remote code execution flaws.

On Tuesday, Adobe also announced patches for 80 vulnerabilities, four of which are critical flaws impacting Adobe Commerce and Magento Open Source that could result in privilege escalation and security feature bypass. Separately, it fixed five critical vulnerabilities in Adobe Illustrator that could pave the way for arbitrary code execution.

Elsewhere, Hewlett Packard Enterprise put out fixes for five shortcomings in Aruba Networking AOS-CX. The most severe of the flaws is CVE-2026-23813 (CVSS score: 9.8), an authentication bypass affecting the management interface.

“A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls,” HPE said. “In some cases, this could enable resetting the admin password.”

“Exploitation of this Aruba vulnerability potentially gives attackers full control of AOS-CX network devices and the ability to compromise an entire system undetected,” Ross Filipek, CISO at Corsica Technologies, said in a statement.

“A successful compromise could lead to the disruption of network communications or the erosion of the integrity of key business services. This flaw is a reminder that vulnerabilities in network devices are becoming more common in today’s hyper-connected world. When attackers gain privileged access to these devices, it puts organizations at significant risk.”

Software Patches from Other Vendors

Security updates have also been released by other vendors over the past few weeks to rectify several vulnerabilities, including —

  • ABB
  • Amazon Web Services
  • AMD
  • Arm
  • Atlassian
  • Bosch
  • Broadcom (including VMware)
  • Canon
  • Cisco
  • Commvault
  • Dassault Systèmes
  • Dell
  • Devolutions
  • Drupal
  • Elastic
  • F5
  • Fortinet
  • Fortra
  • Foxit Software
  • GitLab
  • Google Android and Pixel
  • Google Chrome
  • Google Cloud
  • Google Pixel Watch
  • Google Wear OS
  • Grafana
  • Hitachi Energy
  • Honeywell
  • HP
  • HP Enterprise (including Aruba Networking and Juniper Networks)
  • IBM
  • Intel
  • Ivanti
  • Jenkins
  • Lenovo
  • Linux distributions AlmaLinux, Alpine Linux, Amazon Linux, Arch Linux, Debian, Gentoo, Oracle Linux, Mageia, Red Hat, Rocky Linux, SUSE, and Ubuntu
  • MediaTek
  • Mitsubishi Electric
  • Moxa
  • Mozilla Firefox, Firefox ESR, and Thunderbird
  • n8n
  • NVIDIA
  • Palo Alto Networks
  • QNAP
  • Qualcomm
  • Ricoh
  • Samsung
  • Schneider Electric
  • ServiceNow
  • Siemens
  • SolarWinds
  • Splunk
  • Synology
  • TP-Link
  • Trend Micro
  • WatchGuard
  • Western Digital
  • WordPress
  • Zoom, and
  • Zyxel

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Labour scarcity is forcing IT leaders to rethink automation economics | Computer Weekly Labour scarcity is forcing IT leaders to rethink automation economics | Computer Weekly
Next Article UK publishing body unveils first AI licensing initiative – UKTN UK publishing body unveils first AI licensing initiative – UKTN
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

inDrive partners Heala to offer healthcare access to drivers
inDrive partners Heala to offer healthcare access to drivers
Computing
10 Ways Workplace Platforms Are Transforming the Future of Work
10 Ways Workplace Platforms Are Transforming the Future of Work
Trending
Canva’s new editing tool adds layers to AI-generated designs
Canva’s new editing tool adds layers to AI-generated designs
News
Your To-Do List Might Be Making You Less Productive. Try These 4 Planner Apps Instead
Your To-Do List Might Be Making You Less Productive. Try These 4 Planner Apps Instead
News

You Might also Like

inDrive partners Heala to offer healthcare access to drivers
Computing

inDrive partners Heala to offer healthcare access to drivers

3 Min Read
CathAI: Researchers Built an AI That Reads Heart Scans Like a Cardiologist | HackerNoon
Computing

CathAI: Researchers Built an AI That Reads Heart Scans Like a Cardiologist | HackerNoon

71 Min Read
Critical n8n Flaws Allow Remote Code Execution and Exposure of Stored Credentials
Computing

Critical n8n Flaws Allow Remote Code Execution and Exposure of Stored Credentials

5 Min Read
Opinion: The wrong tax at the wrong time for Washington
Computing

Opinion: The wrong tax at the wrong time for Washington

7 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?