● Live advisory feed
Security Advisory Fusion for CSIRTs, SOCs & Defenders
Security advisories from 24 sources — CISA, CERT-EU, NCSC-UK, BSI, CERT-FR, NCSC-NL, JPCERT/CC, JVN, HKCERT, the Canadian Cyber Centre, NVD, GitHub, Microsoft, Cisco, Fortinet, Palo Alto Networks and more — normalized, translated to English and flagged against the CISA KEV catalog. One global feed for CSIRTs, SOCs and defenders.
Serial number: AV26-646 Date: July 2, 2026 On July 1, 2026, Cisco published security advisories to address vulnerabilities in the following: Cisco Catalyst Center Release 2.3.7 – versions prior to 2.3.7.11-VA GSMU100 Cisco Catalyst Center Release 3.1 - versions prior to 3.1.6 GSM…
Summary
Sandboxed session spawn could expose the real workspace path to child prompts. In affected versions, a child session spawned from a sandboxed parent could forward the host workspace path into the child session prompt.
This advisory is scoped to the named feature and con…
Summary
Embedded runner policy could be confused by provider aliases. In affected versions, a request using provider aliases could compare policy against an alias instead of the canonical provider identity.
This advisory is scoped to the named feature and configuration. It does…
Summary
Fake package roots could influence memory-core artifact loading. In affected versions, a local package root resolution path influenced by workspace state could select a package root that was not the intended bundled artifact root.
This advisory is scoped to the named fe…
Summary
Workspace .env could override Homebrew executable selection for skill install flows. In affected versions, a workspace .env in a repository opened by a trusted operator could override the Homebrew executable used by the install helper.
This advisory is scoped to the nam…
Summary
QQBot pre-dispatch slash commands could skip allowFrom checks. In affected versions, a QQBot sender able to invoke slash commands could dispatch the command before applying the configured allowFrom policy.
This advisory is scoped to the named feature and configuration. …
Summary
The bundled device-pair plugin exposed /pair on normal chat command surfaces. In affected releases, authorized non-owner chat senders could issue device-pairing bootstrap codes without having owner, admin, or pairing scope.
This issue does not affect unauthenticated use…
Summary
Browser debug/export routes could reuse already-open blocked tabs. In affected versions, a caller that can reference an already-open browser tab could reuse blocked private-network tabs without reapplying the expected SSRF policy.
This advisory is scoped to the named fe…
Summary
message.action forwarding could send Gateway credentials to model-supplied loopback URLs. In affected versions, model-controlled action metadata that selects a loopback Gateway URL could forward the action payload with Gateway credentials to the supplied loopback URL.
T…
Summary
QQBot admin commands could skip DM-only and allowFrom policy. In affected versions, a QQBot sender able to trigger the exported command could route admin commands without the QQBot-specific DM-only and allowFrom checks.
This advisory is scoped to the named feature and c…
Summary
Mattermost handlers could fall open when channel type was missing. In affected versions, a Mattermost event missing channel type metadata could continue without applying the intended DM policy decision.
This advisory is scoped to the named feature and configuration. It …
Summary
In trusted-proxy Control UI mode, OpenClaw accepted a WebSocket client's declared operator scopes before those scopes were bound to a server-approved pairing or trusted-proxy authorization baseline.
This issue affects trusted-proxy Control UI deployments. It does not ap…
Summary
Slack allowFrom could bind to mutable display names. In affected versions, a Slack account able to change display name metadata could match a policy entry through mutable display metadata.
This advisory is scoped to the named feature and configuration. It does not chang…
Summary
Skill Workshop apply flow could override pending approval. In affected versions, an agent tool call reaching the affected Skill Workshop apply path could set apply: true despite approvalPolicy: pending.
This advisory is scoped to the named feature and configuration. It …
Summary
QQBot streaming command could mutate config without explicit allowFrom. In affected versions, a QQBot sender reaching the affected command could change configuration without requiring an explicit non-wildcard allowlist entry.
This advisory is scoped to the named feature…
Summary
Node pairing reconnection could confuse approval scope state. In affected versions, a paired or reconnecting node session could mutate pairing state in a way that changed the approval scope decision.
This advisory is scoped to the named feature and configuration. It doe…
Summary
Slack plugin approvals used the exec approver gate for plugin actions. In affected versions, a Slack user authorized only for exec approvals could resolve a plugin approval through the exec approver gate.
This advisory is scoped to the named feature and configuration. I…
Summary
memory-wiki ingest could read local files with operator.write scope. In affected versions, a Gateway caller with operator.write access to the plugin tool could read arbitrary local file paths instead of staying within the intended ingest sources.
This advisory is scoped…
Summary
Some internal command handlers require operator.approvals or operator.admin scopes. In affected releases, a scoped Gateway chat.send request delivered through an inherited external route could be evaluated as an external-channel command while still carrying the lower Gat…
Summary
On POSIX nodes, OpenClaw's system.run safe-bin checks could approve a command before shell expansion changed how the command was interpreted. A value that appeared to be a safe-bin argument could expand into additional shell words and become a file operand.
This issue i…
Summary
OpenClaw's QQBot channel can deliver native approval buttons for exec and plugin approvals. In affected releases, the button callback path resolved approvals without enforcing the configured QQBot approver identity.
The text command approval path used the authorization …
Summary
OpenClaw hook ingress can start automated agent runs using a configured hook token. In affected releases, a hook-triggered run could select a bundled CLI backend that received owner-scoped MCP loopback authority instead of a scope appropriate for hook ingress.
This issu…
Summary
In affected LAN/shared-token Control UI deployments, a caller could spoof locality information used during Control UI pairing and obtain a durable admin-capable device token.
This issue is limited to deployments where the caller already has the network/authentication fo…
Summary
Same-host trusted-proxy deployments could accept local forged identity headers. In affected versions, a local same-host caller that can reach the proxy-facing Gateway port could supply identity headers normally reserved for the trusted proxy.
This advisory is scoped to …
Number: AL26-015 Date: July 2, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation ad…
Summary
The BalancerForward proxy helper in GoFiber uses Header.Add() instead of Header.Set() when injecting the X-Real-IP header. This appends the real client IP as a second header value rather than replacing any attacker-supplied value. Upstream servers that read the first X-R…
Cisco has fixed a vulnerability in Cisco Catalyst Center. The vulnerability lies in the insufficient validation of user-supplied input, which can be manipulated via specially crafted HTTP requests to gain access to files within a restricted container. This allows unauthenticated …
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to device information or cause a denial-of-service condition. The following versions of ST Engineering iDirect iQ-Series Terminals are affected: Evolution iQ‑Ser…
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to upload arbitrary malicious firmware to the device. The following versions of CubeSpace CW0057 Reaction Wheel are affected: CW0057 Reaction Wheel CVSS Vendor Equipment Vulnerabilities v3 6.1…
View CSAF Summary Successful exploitation of these vulnerabilities could allow unauthenticated users to access and control IoT Hub managed devices. The following versions of Gardyn IoT Hub are affected: Home Firmware Studio Firmware Cloud API <2.12.2026 (CVE-2026-13768, CVE-2026-…
A remote, authenticated attacker can exploit multiple vulnerabilities in Kibana to conduct a denial of service attack, execute arbitrary code, bypass security measures, and disclose confidential information.
An attacker can exploit multiple vulnerabilities in OPNsense to execute arbitrary code with administrative privileges, bypass security measures, conduct a Cross-Site Scripting attack, manipulate files, disclose information, and perform a Denial of Service attack.
An attacker can exploit multiple vulnerabilities in MediaWiki to conduct Cross-Site Scripting attacks, redirect users to malicious websites, bypass authentication, or perform SQL injection attacks.
A remote, authenticated attacker can exploit a vulnerability in Fleet to perform a Denial of Service attack.
A remote, authenticated attacker can exploit a vulnerability in Hashicorp Vault to bypass security measures.
A remote, authenticated attacker can exploit a vulnerability in Microsoft SharePoint Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint to execute arbitrary program code.
An attacker can exploit multiple vulnerabilities in IBM DB2 to escalate privileges and conduct a denial of service attack.
A remote, anonymous attacker can exploit multiple vulnerabilities in FreeRDP to cause a denial of service or potentially execute arbitrary program code.
An attacker can exploit multiple vulnerabilities in Vercel Next.js to conduct a denial of service attack.
A remote, anonymous attacker can exploit a vulnerability in avahi-daemon to conduct a denial of service attack.
A local attacker can exploit a vulnerability in the glib library of Red Hat Enterprise Linux to conduct a denial of service attack and cause further unspecified impacts.
An attacker can exploit multiple vulnerabilities in Node.js to execute arbitrary code, gain elevated privileges, bypass security measures, manipulate data, and disclose confidential information.
A remote attacker can exploit multiple vulnerabilities in FreeRDP to potentially cause a denial-of-service condition, execute arbitrary code, manipulate data, or disclose confidential information.
An attacker can exploit multiple vulnerabilities in Red Hat Enterprise Linux regarding the components 'tar' and 'Scrapy' to manipulate files and conduct a denial of service attack.
A remote, anonymous attacker can exploit multiple vulnerabilities in Netty to bypass security measures and cause a denial of service.
An attacker can exploit multiple vulnerabilities in Node.js to cause a denial of service, bypass security measures, and disclose information.
A remote, anonymous attacker can exploit a vulnerability in Red Hat JBoss Enterprise Application Platform to carry out a denial of service attack.
A local attacker can exploit a vulnerability in Red Hat Enterprise Linux to escalate their privileges and disclose information.
A remote, anonymous attacker can exploit multiple vulnerabilities in Vercel Next.js to carry out a denial of service attack or bypass security measures.
A remote, authenticated attacker can exploit multiple vulnerabilities in IBM DB2 to conduct a denial of service attack and disclose confidential information.