FR
live
archive

All articles

Argo CD 3.6 makes progressive sync observable and broadens its health checks

Argo CD 3.6.0-rc1, released September 16, 2026, adds metrics and conditions to ApplicationSet progressive sync and expands the health-check library — CloudNativePG, cert-manager, Prometheus Operator, Kyverno. Teams that roll out changes in waves across clusters should plan the upgrade once the stable release lands.

Check Point patches a login stack overflow that grants unauthenticated root on management servers

On September 17, 2026, Check Point shipped an emergency fix for CVE-2026-91843, a CVSS 9.8 stack overflow in the login process of its management and log servers that lets an unauthenticated attacker run code as root. Apply the Live Patch to every instance, confirm it with cplp list, and tighten Trusted Clients before someone takes over your firewall’s management plane.

AWS Lambda Gets 90-Minute Timeouts and Graviton5 on Managed Instances

On September 9, 2026, AWS raised the Lambda function timeout to 90 minutes on Lambda Managed Instances and added Graviton5 instances, up to 25% faster than Graviton4. Teams that were working around the 15-minute cap or torn between serverless and EC2 now have a single bridge.

JFrog Artifactory piles up two exploited authentication flaws, and your binary registry is the next link

On September 11, 2026, CISA added two JFrog Artifactory flaws to the KEV catalog: CVE-2026-42016, which validates a token’s signature without checking its scope, and CVE-2026-42018, which leaks an anonymous token even when anonymous access is disabled. Upgrade to 7.133.11, revoke the affected tokens and audit anonymous access before a poisoned artifact ships to production.

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss