● Live advisory feed
Security Advisory Fusion for CSIRTs, SOCs & Defenders
Security advisories from 24 sources — CISA, CERT-EU, NCSC-UK, BSI, CERT-FR, NCSC-NL, JPCERT/CC, JVN, HKCERT, the Canadian Cyber Centre, NVD, GitHub, Microsoft, Cisco, Fortinet, Palo Alto Networks and more — normalized, translated to English and flagged against the CISA KEV catalog. One global feed for CSIRTs, SOCs and defenders.
An attacker can exploit multiple vulnerabilities in Red Hat OpenShift Container Platform to execute arbitrary program code, bypass security measures, and manipulate data.
A local attacker can exploit a vulnerability in Linux Kernel to gain administrator rights.
A remote, anonymous attacker can exploit a vulnerability in nmap to conduct a denial of service attack.
An attacker can exploit multiple vulnerabilities in cURL to bypass security measures, disclose confidential information, or cause a denial-of-service condition or memory corruption.
An attacker can exploit multiple vulnerabilities in cURL to bypass security measures, disclose confidential information, manipulate data, or cause a Denial-of-Service condition.
An attacker can exploit multiple vulnerabilities in Node.js to bypass security precautions, manipulate data, disclose confidential information, or cause a denial-of-service condition.
An attacker can exploit multiple vulnerabilities in IBM WebSphere Application Server to execute arbitrary code, perform a Denial of Service attack, bypass security measures, disclose information, and escalate privileges.
A remote, anonymous attacker can exploit a vulnerability in FreeRDP to execute arbitrary code and conduct a denial of service attack.
A remote, anonymous attacker can exploit a vulnerability in Red Hat OpenShift to execute arbitrary program code.
A local attacker can exploit a vulnerability in the Linux Kernel to gain root privileges.
An attacker can exploit multiple vulnerabilities in IBM QRadar SIEM to execute arbitrary code, escalate privileges, conduct a denial of service attack, disclose information, and bypass security measures.
An attacker can exploit a vulnerability in Perl to perform an unspecified attack.
An attacker can exploit multiple vulnerabilities in Unbound to cause a denial of service state, potentially execute code, and cause unspecified impacts.
An attacker can exploit multiple vulnerabilities in Grafana to gain elevated privileges, bypass security measures, manipulate or disclose data, or cause a denial-of-service condition.
A remote, anonymous attacker can exploit multiple vulnerabilities in NGINX Open Source and NGINX Plus to bypass security measures, execute arbitrary code, manipulate data, disclose confidential information, or cause a denial-of-service condition.
An attacker can exploit multiple vulnerabilities in FreeRDP to execute arbitrary program code, cause a denial-of-service state, or conduct unspecified attacks.
A remote, anonymous attacker can exploit a vulnerability in Red Hat Enterprise Linux (LibRaw) to execute arbitrary program code.
An attacker can exploit multiple vulnerabilities in Red Hat Enterprise Linux to execute arbitrary program code or cause a Denial-of-Service condition.
An attacker can exploit a vulnerability in FreeRDP to conduct an unspecified attack.
A remote, anonymous attacker can exploit multiple vulnerabilities in FreeRDP to potentially execute arbitrary code, cause a denial-of-service condition, manipulate data, disclose confidential information, or conduct other unspecified attacks.
A local attacker can exploit multiple vulnerabilities in docker to bypass security measures and disclose information.
A local attacker can exploit multiple vulnerabilities in Linux Kernel to conduct a Denial of Service attack or achieve other unspecified impacts.
A remote, anonymous attacker can exploit multiple vulnerabilities in FreeRDP to execute potentially arbitrary code, cause a denial-of-service condition, create memory corruption, manipulate data, or disclose sensitive information.
An attacker can exploit multiple vulnerabilities in FreeRDP to execute arbitrary program code and to carry out a denial of service attack.
A remote, anonymous attacker can exploit multiple vulnerabilities in Red Hat Enterprise Linux to conduct a denial of service attack.
An attacker can exploit multiple vulnerabilities in the Linux Kernel to conduct unspecified attacks that may lead to a denial-of-service condition or cause memory corruption.
A local attacker can exploit a vulnerability in avahi to conduct a denial of service attack.
A local attacker can exploit multiple vulnerabilities in Red Hat Enterprise Linux and Red Hat OpenShift to bypass security measures and cause a Denial of Service.
An attacker can exploit multiple vulnerabilities in Golang Go to conduct a Denial of Service attack or other unspecified attacks.
A remote, anonymous attacker can exploit a vulnerability in Apache Commons Lang to conduct a denial of service attack.
SQLite Consortium has fixed a vulnerability in SQLite version 3.41. The vulnerability concerns a use-after-free in the expression evaluation logic of SQLite. An attacker can exploit this vulnerability remotely by providing specially crafted malicious SQL statements. Exploitation …
A local attacker can exploit a vulnerability in binutils to carry out a Denial of Service attack and disclose data.
A remote, anonymous attacker can exploit a vulnerability in Apache Axis2 to execute arbitrary code.
Maxim Suhanov discovered that the NTFS file system implementation in the Linux kernel did not properly validate file name length in certain situations, leading to an out-of-bounds read. An attacker could use this to construct a malicious NTFS image that, when mounted and operated…
It was discovered that a logic flaw existed in the XFRM ESP-in-TCP subsystem in the Linux kernel when handling socket buffer fragments. This flaw is known as Fragnesia. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-43503) Severa…
An attacker can exploit multiple vulnerabilities in SAP software to manipulate files, carry out a denial of service attack, disclose information, perform an SQL injection attack, conduct a cross-site scripting attack, bypass security measures, and execute arbitrary program code.
On July 29, 2026, we released versions 19.2.1, 19.1.3, 19.0.5 for GitLab Community Edition (CE) and Enterprise Edition (EE). These versions contain important bug and security fixes, and we strongly recommend that all self-managed GitLab installations be upgraded to one of these v…
Multiple vulnerabilities have been discovered in Citrix XenServer. Some of them allow an attacker to cause remote arbitrary code execution, remote denial of service, and an unspecified security issue by the vendor.
A vulnerability has been discovered in Apache Tomcat. It allows an attacker to cause a remote denial of service.
Tomoya Nakanishi discovered a flaw in nss, the Mozilla Network Security Service library, which may result in execution of arbitrary code if a specially crafted certificate is processed. https://security-tracker.debian.org/tracker/DSA-6403-1
Multiple vulnerabilities have been discovered in Xen. Some of them allow an attacker to cause privilege escalation, remote denial of service, and data confidentiality breaches.
On July 29, 2026, we released versions 19.2.1, 19.1.3, 19.0.5 for GitLab Community Edition (CE) and Enterprise Edition (EE). These versions contain important bug and security fixes, and we strongly recommend that all self-managed GitLab installations be upgraded to one of these v…
Multiple vulnerabilities have been discovered in Microsoft Edge. They allow an attacker to cause data integrity issues and an unspecified security issue by the vendor.
Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive …
Summary
sendFile derives the served filename from the raw request path while opening the file from the cleaned path, so appending a trailing slash empties the derived name and defeats both the never-serve rule for the ACL file and the block list.
Finding (Medium): trailing-slas…
Summary
Pagy::I18n.locale= did not validate its argument before using it as a
path component to load the matching dictionary file (<locale>.yml). An
application that assigns untrusted input to the locale — e.g. the common
pattern Pagy::I18n.locale = params[:locale] — let that in…
Impact
skilo add installs a skill by recursively copying the skill directory into the
target skills directory. The copy routine (copy_dir_all) classified each entry
with std::fs::DirEntry::file_type() — which does not follow symlinks — and
then copied non-directory entries with …
Impact
Prototype pollution.
A malicious user can create a token array [{ key: '{proto.foo}', value: 'malicious' }], when processed by convertTokenData() utility function, it will pollute the Object.prototype globally where {}.foo will equal { key: '{proto.foo}', value: 'malicious…
Summary
openhole-server forwarded the URL-decoded request path (r.URL.Path) to tunnel clients instead of the original request-target. Percent-encoded dot-segments (%2e) and separators (%2f) were decoded to ../ and / before reaching the local service.
Go's ServeMux rejects liter…