CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

● Live advisory feed

Security Advisory Fusion for CSIRTs, SOCs & Defenders

Security advisories from 24 sources — CISA, CERT-EU, NCSC-UK, BSI, CERT-FR, NCSC-NL, JPCERT/CC, JVN, HKCERT, the Canadian Cyber Centre, NVD, GitHub, Microsoft, Cisco, Fortinet, Palo Alto Networks and more — normalized, translated to English and flagged against the CISA KEV catalog. One global feed for CSIRTs, SOCs and defenders.

Advisories tracked
20,779
Known exploited
1,782
Sources online
24
Last sync
2H AGO
9,405 records · page 1 / 189 · nvd firehose hidden — show all

GHSA-jr6p-8pjj-mfx6: Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation)

Summary CVE-2026-22872 (GHSA-qjjm-7j9w-pw72) reported that a Tenant Owner could create cluster-scoped resources (e.g. ClusterRole, ValidatingWebhookConfiguration) through a TenantResource, because the controller applies them with its cluster-admin ServiceAccount and SetNamespace

mediumCVSS 6.6CVE-2026-65835ghsa2026-07-31

GHSA-xh95-f55m-82fw: Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)

Summary FramenetCorpusReader.frame(name) interpolates a caller-supplied frame name into an XML file path that is read with the builtin open(), bypassing CorpusReader.open() and the nltk.pathsec sandbox — including strict ENFORCE=True mode. A ../ sequence in the name escapes the c

highCVSS 7.5CVE-2026-12074ghsa2026-07-31

Google security advisory (AV26-768)

Serial number: AV26-768 Date: July 31, 2026 As of July 30, 2026, Google is affected by vulnerabilities in the following product: Chrome - Prior to 151.0.7922.72 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as

unknowncccs2026-07-31

Rails security advisory (AV26-767)

Serial Number: AV26-767 Date: July 31, 2026 As of July 30, 2026, Rails is affected by a vulnerability in the following product: Rails Prior to 8.0.5.1 Prior to 8.1.3.1 Prior to 7.2.3.2 The Cyber Centre encourages users and administrators to review the provided web links and apply

unknownpublic exploitCVE-2026-66066cccs2026-07-31

SolarWinds security advisory (AV26-766)

Serial number: AV26-766 Date: July 30, 2026 As of July 30, 2026, SolarWinds is affected by a vulnerability in the following product: Web Help Desk (WHD) Prior to 2026.2.1 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary

unknownCVE-2026-28323cccs2026-07-31
Older →