● Live advisory feed
Security Advisory Fusion for CSIRTs, SOCs & Defenders
Security advisories from 24 sources — CISA, CERT-EU, NCSC-UK, BSI, CERT-FR, NCSC-NL, JPCERT/CC, JVN, HKCERT, the Canadian Cyber Centre, NVD, GitHub, Microsoft, Cisco, Fortinet, Palo Alto Networks and more — normalized, translated to English and flagged against the CISA KEV catalog. One global feed for CSIRTs, SOCs and defenders.
A remote, anonymous attacker can exploit multiple vulnerabilities in Citrix Systems NetScaler ADC and Gateway to disclose information, cause a denial-of-service condition, or trigger other unspecified impacts.
A remote, anonymous attacker can exploit multiple vulnerabilities in mutt to bypass security precautions and cause a denial-of-service condition.
An attacker can exploit multiple vulnerabilities in Red Hat Hardened Images RPMs to conduct a denial of service attack or manipulate data.
A remote, anonymous attacker can exploit multiple vulnerabilities in CoreDNS to bypass security measures and disclose confidential information or cause a denial-of-service condition.
A remote, anonymous attacker can exploit multiple vulnerabilities in Red Hat Enterprise Linux to bypass security precautions or execute a denial of service.
A local attacker can exploit a vulnerability in libxml2 to carry out a denial of service attack.
A local attacker can exploit a vulnerability in libTIFF to carry out a denial of service attack.
An attacker can exploit multiple vulnerabilities in DNSdist to carry out a denial of service attack.
An attacker can exploit multiple vulnerabilities in PowerDNS to bypass security measures and carry out a denial of service attack.
A local attacker can exploit a vulnerability in AMD processors and Xen to disclose information.
A remote, anonymous attacker can exploit a vulnerability in Red Hat Advanced Cluster Security to conduct a Denial of Service attack.
A remote, authenticated attacker can exploit multiple vulnerabilities in IBM DB2 to conduct a Denial of Service attack.
An attacker can exploit a vulnerability in Golang Go to bypass security measures.
A local attacker can exploit multiple vulnerabilities in Linux Kernel to conduct a Denial of Service attack and escalate privileges.
A remote anonymous attacker can exploit multiple vulnerabilities in Red Hat OpenShift to bypass security measures, disclose confidential information, or create a denial-of-service condition.
An attacker can exploit multiple vulnerabilities in Splunk Splunk Enterprise in various third-party components to carry out an unspecified attack.
A remote, anonymous attacker can exploit multiple vulnerabilities in libTIFF to conduct a Denial of Service attack.
A remote, anonymous attacker can exploit multiple vulnerabilities in Red Hat Virtualization to conduct a Denial of Service attack or disclose information.
A remote, authenticated attacker can exploit multiple vulnerabilities in Red Hat Enterprise Linux to conduct an unspecified attack.
A remote, anonymous attacker can exploit a vulnerability in libTIFF to conduct a Denial of Service attack.
An attacker can exploit a vulnerability in Mozilla Firefox to cause a memory corruption or potentially execute arbitrary code.
A local attacker can exploit a vulnerability in avahi to conduct a denial of service attack.
An attacker can exploit multiple vulnerabilities in PowerDNS to disclose information, bypass security measures, cause a denial of service, and potentially execute code.
A remote, authenticated attacker can exploit a vulnerability in Microsoft Edge to execute arbitrary program code.
An attacker can exploit multiple vulnerabilities in Red Hat OpenShift to execute arbitrary program code and disclose information.
An attacker can exploit multiple vulnerabilities in Kemp LoadMaster to bypass security measures, manipulate data, or execute arbitrary code.
Multiple vulnerabilities have been discovered in Google Chrome. They allow an attacker to cause an unspecified security issue by the vendor.
Multiple security issues have been discovered in FastNetMon, a fast DDoS analyzer: TLS connections were insufficently validated and malformed Netflow/sFlow traffic could result in denial of service. https://security-tracker.debian.org/tracker/DSA-6375-1
Multiple vulnerabilities have been discovered in ClamAV. They allow an attacker to cause denial of service and an unspecified security issue by the vendor.
Multiple vulnerabilities have been discovered in Traefik. They allow an attacker to cause security policy bypass.
Multiple vulnerabilities have been discovered in Cisco products. They allow an attacker to cause a remote denial of service and a breach of data confidentiality.
Multiple vulnerabilities have been discovered in Elastic products. Some of them allow an attacker to cause a remote denial of service, a breach of data confidentiality, and a breach of data integrity.
Multiple vulnerabilities have been discovered in Mozilla Thunderbird. They allow an attacker to cause a breach of data integrity and a denial of service.
A vulnerability has been discovered in CPython. It allows an attacker to bypass the security policy.
Root cause
The tar-extraction helper ensureLinkPath at content/file/utils.go:262-275 validates that a hardlink's target resolves inside the extract base, but then returns the original unresolved target string back to the caller:
func ensureLinkPath(baseAbs, baseRel, link, targe…
Impact
A critical command injection vulnerability has been identified in the Rancher Manager cluster import endpoint /v3/import/{token}_{clusterId}.yaml through unsanitized YAML parameters. This endpoint accepts an authImage query parameter that is rendered without sanitization i…
In SurrealDB, records can be connected as a graph: a RELATE statement creates an edge record between two node records. If either endpoint node is deleted, SurrealDB automatically removes the edge row to keep the graph consistent.
A user with permission to delete a node could als…
Bulletin ID: 2026-051-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/01/2026 12:45 PM PDT Description: The AWS Advanced JDBC Wrapper is an open-source JDBC driver wrapper that extends a JDBC driver to enable Amazon Aurora and AWS Cloud features s…
Bulletin ID: 2026-050-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/01/2026 12:15 PM PDT Description: AWS CDK (aws-cdk-lib) is an open-source framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We …
Bulletin ID: 2026-049-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/01/2026 11:45 AM PDT Description: The AWS Command Line Interface (AWS CLI) is a unified tool for managing AWS services from the command line. We identified CVE-2026-13769 in AWS…
On July 1, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories: Cisco Security Advisory CVE-ID Security Impact Rating CVSS Base Score Cisco Catalyst Center Arbitrary File Read Vulnerability CVE-2026-20191 High 7.5 ClamAV Vulnerabilit…
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected devi…
Pen testers suggest what organisations can do to make their job more difficult.