CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

● Live advisory feed

Security Advisory Fusion for CSIRTs, SOCs & Defenders

Security advisories from 24 sources — CISA, CERT-EU, NCSC-UK, BSI, CERT-FR, NCSC-NL, JPCERT/CC, JVN, HKCERT, the Canadian Cyber Centre, NVD, GitHub, Microsoft, Cisco, Fortinet, Palo Alto Networks and more — normalized, translated to English and flagged against the CISA KEV catalog. One global feed for CSIRTs, SOCs and defenders.

Advisories tracked
20,853
Known exploited
1,782
Sources online
24
Last sync
41M AGO
9,405 records · page 11 / 189 · nvd firehose hidden — show all

GHSA-wg2q-39h6-66x9: goshs has a Path Traversal issue

Summary The multipart upload filename fix splits on the path separator but never rejects dot-dot, allowing a write outside the served tree. Finding (Medium): upload filename escapes the served tree (residual of CVE-2026-35393) The multipart filename fix (updown.go lines 135-13

mediumCVSS 6.5CVE-2026-66063ghsa2026-07-28

GHSA-qf5v-m7p4-95rp: Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption

Fission v1.24.0 added PodSpec safety validation for tenant-facing Environment and Function CRDs (ValidatePodSpecSafety / ValidateContainerSafety admission webhook + sanitizeContainerSecurityContext executor merge layer), but the capability check was implemented as a fixed denylis

highCVSS 8.5CVE-2026-50570ghsa2026-07-28

USN-8561-2: FreeRDP regression

USN-8561-1 fixed vulnerabilities in FreeRDP. Unfortunately, the upgrade to version 3.30.0 introduced a regression in the clipboard functionality. This update fixes the problem. We apologize for the inconvenience. Original advisory details: It was discovered that FreeRDP contained

unknownubuntu2026-07-28

Vercel security advisory (AV26-754)

Serial Number: AV26-754 Date: July 28, 2026 As of July 27, 2026, Vercel is affected by vulnerabilities in the following product: next.js Prior to 15.5.21 Prior to 16.2.11 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary

unknowncccs2026-07-28

Apple security advisory (AV26-753)

Serial Number: AV26-753 Date: July 28, 2026 As of July 27, 2026, Apple is affected by vulnerabilities in the following products: iOS and iPadOS Prior to 26.6 macOS Prior to 14.8.8 Prior to 15.7.8 Prior to 26.6 tvOS Prior to 26.6 visionOS Prior to 26.6 Safari Prior to 26.6 watchOS

unknowncccs2026-07-28

JetBrains security advisory (AV26-752)

Serial Number: AV26-752 Date: July 28, 2026 As of July 27, 2026, JetBrains is affected by a vulnerability in the following product: TeamCity Prior to 2026.1.3, 2025.11.7 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary

unknowncccs2026-07-28

Arista Networks security advisory (AV26-751)

Serial Number: AV26-751 Date: July 28, 2026 As of July 27, 2026, Arista Networks is affected by vulnerabilities in the following product: VeloCloud Orchestrator On-Prem from 5.2.0 to versions prior to 5.2.3.14 from 6.1.0 to versions prior to 6.1.3.4 from 6.4.0 to versions prior t

unknownexploitedCVE-2026-16812cccs2026-07-28
← NewerOlder →