Vendors including Ubuntu, IBM, VMware, Microsoft, Google, and F5 released security advisories and updates between January 5 and 12, 2026, addressing vulnerabilities across a range of widely used products. Notable issues include a high-severity vulnerability (CVE-2026-0628) in Google Chrome’s WebView component, which could allow malicious extensions or payloads to bypass security controls and inject scripts or HTML into privileged pages, as well as a Linux kernel vulnerability (CVE-2024-56614) that could result in out-of-bounds writes and potential memory corruption. Updates were also issued for Ubuntu Linux kernel packages, IBM Cloud Pak and related software, VMware Tanzu Greenplum Backup and Restore, and Microsoft Edge, with users urged to apply patches promptly to mitigate risk.
The Linux kernel vulnerability (CVE-2024-56614) was specifically highlighted by F5, describing how improper bounds checking in the xsk_map_delete_elem function could lead to out-of-bounds memory access and system instability. Google’s Chrome update not only patched a critical security flaw but also introduced new rate limits for push notifications to reduce notification spam. The advisories from Ubuntu, IBM, VMware, and Microsoft Edge all emphasized the importance of applying the latest updates to address recently disclosed vulnerabilities and maintain system security across enterprise and consumer environments.

See real exploitation activity before you spend the cycle.
8 events from the most recent confirmed update back to the earliest known activity.
F5 published product advisory K000159059 concerning Linux kernel vulnerability CVE-2024-56614. No additional synopsis details were provided in the reference content.
The Canadian Centre for Cyber Security published advisories AV26-014, AV26-016, AV26-017, and AV26-018 highlighting recent vendor security updates from IBM, VMware, Microsoft, and Ubuntu. The notices urged administrators and users to review the referenced advisories and apply the necessary patches.
Between January 5 and 11, Ubuntu released security notices addressing Linux kernel vulnerabilities affecting Ubuntu 18.04 LTS, 20.04 LTS, 22.04 LTS, and 24.04 LTS. The notices instructed users to apply the relevant kernel updates.
Between January 5 and 11, VMware published security advisories for VMware Tanzu products, including Tanzu Greenplum Backup and Restore. Version 1.32.2 was identified as the remediating release for affected versions prior to 1.32.2.
Between January 5 and 11, IBM issued multiple advisories covering vulnerabilities in IBM Cloud Pak for Business Automation, IBM Concert Software, IBM Maximo Application Suite Monitor, and watsonx Orchestrate Cartridge for IBM Cloud Pak for Data. The advisories provided updates to address the identified issues.
Microsoft published a security update for Microsoft Edge Stable Channel, remediating vulnerabilities in versions prior to 143.0.3650.139. Users were directed to update to the fixed release.
Google released Chrome 143 stable for Windows, macOS, and Linux, patching the high-severity WebView vulnerability CVE-2026-0628. The release also introduced Push API rate limiting to curb abusive notification spam from disruptive sites.
Security researcher Gal Weizman reported CVE-2026-0628, a high-severity Chrome WebView vulnerability caused by insufficient policy enforcement in the WebView tag, to Google. The flaw could allow bypass of security controls and injection of scripts or HTML into privileged pages.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
6 references tracked. Mallory keeps watching after this page renders.
cyber.gc.ca
Open sourcecyber.gc.ca
Open sourcecyber.gc.ca
Open sourcecyber.gc.ca
Open sourcetechrepublic.com
Open sourcemy.f5.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.