NVIDIA's Sept. 30 List: Four Driver Builds, Then Update GamingOnLinux lists four safe NVIDIA Linux driver builds from the Sept. 30 bulletin. The high scores are local memory bugs. Guest drivers are a separate row. troubleshooting
OpenVPN 2.7.7 Fixes Seven CVEs. Patch Linux First. OpenVPN 2.7.7 patches CVE-2026-84732 on every platform, hardens Linux Netlink, and stops --stale-routes-check from deleting static routes. Here is how to upgrade and verify. linux
Plex Urges Update to 1.43.3: 300,000 Servers Are Exposed Plex patched multiple security flaws with 1.43.3, but thousands of servers are still reachable online. Here's how to update on Docker, NAS, and Linux. security
NGINX CVE-2026-42533: A Critical 9.2-Severity Flaw Affects Every Version Since 2011 — Here's How to Fix It A critical heap buffer overflow vulnerability in NGINX (CVE-2026-42533, CVSS 9.2) affects every version from 0.9.6 through 1.31.2. This guide covers how to check if you're vulnerable, upgrade paths for every distribution, and what to do if you can't patch immediately. server-config
Critical Gitea Docker Vulnerability (CVE-2026-20896): Patch Your Self-Hosted Git Server Now A CVSS 9.8 critical vulnerability in Gitea Docker images allows attackers to impersonate any user via reverse proxy misconfiguration. The flaw is under active exploitation. Here's how to check if you're affected and patch immediately. docker
GhostLock CVE-2026-43499: 15-Year-Old Linux Root Exploit GhostLock (CVE-2026-43499) is a use-after-free vulnerability in the Linux kernel that sat undetected for 15 years, allowing any local user to escalate to root with 97% reliability. Here's how to check and patch your servers. security
Januscape: 16-Year-Old Linux KVM Flaw Allows VM Escape on Intel and AMD Systems A newly disclosed vulnerability tracked as CVE-2026-53359 has been hiding in the Linux kernel's KVM hypervisor since 2010, allowing attackers to break out of virtual machines and execute code on the host. Here's what server administrators need to know and how to patch. security
Bad Epoll: New Linux Kernel Flaw Lets Unprivileged Users Grab Root — and Android Is Affected Too A race condition in the Linux kernel's epoll subsystem allows local privilege escalation to root. Servers, desktops, and Android devices are all vulnerable. Here's what to patch and how to check if you're exposed. linux
DirtyClone (CVE-2026-43503): What Linux Admins Need to Know and How to Mitigate Right Now A newly disclosed kernel vulnerability in the packet cloning subsystem affects every major Linux distribution running kernel 6.1 through 6.12. Here's a practical mitigation guide with step-by-step instructions for Ubuntu, Debian, RHEL, and containerized environments. security
Critical libssh2 Flaw (CVE-2026-55200): How to Check If Your Servers Are Affected and Patch Immediately A public PoC is now circulating for CVE-2026-55200, a critical libssh2 vulnerability with a 9.2 CVSS score. Here's how to identify affected systems, verify your version, and apply the fix across your server fleet. server-config
OpenSSL CVE-2026-45447: Critical PKCS#7 Vulnerability and Server Patch Guide A heap use-after-free bug in OpenSSL's PKCS#7 verification enables remote code execution. Learn how to check your systems, apply the patch, and harden against related attacks. security
Nginx 1.29.5 Security Update: Critical Patches and Upgrade Guide Nginx 1.29.5 addresses critical security vulnerabilities. Learn about the CVEs fixed, impact assessment, and step-by-step upgrade instructions. security