Server is a computer system or software service that receives network requests and delivers data, applications, or shared resources to other systems or users, and it matters in enterprises because it hosts core workloads, data, and digital services.
CISA updated its guidance on a critical vulnerability in Windows Server Update Service. Microsoft urges organizations to apply an out-of-band security update to prevent unauthorized remote code execution.
CISA, in collaboration with NSA and international partners, released a guide on Microsoft Exchange Server Security Best Practices to enhance defenses against cyber threats.
AVEVA disclosed a vulnerability in its Application Server IDE, affecting versions up to 2023 R2 SP1 P02. The issue involves improper HTML tag neutralization, allowing potential XSS code exploitation. Recommended mitigations include updating to a later version and restricting network access.
General Industrial Controls has reported vulnerabilities in Lynx+ Gateway, including weak password requirements and missing authentication, which could lead to unauthorized access. CISA recommends defensive measures to mitigate risks, as no public exploitation targeting these vulnerabilities has been documented.