● Live advisory feed
Security Advisory Fusion for CSIRTs, SOCs & Defenders
Security advisories from 24 sources — CISA, CERT-EU, NCSC-UK, BSI, CERT-FR, NCSC-NL, JPCERT/CC, JVN, HKCERT, the Canadian Cyber Centre, NVD, GitHub, Microsoft, Cisco, Fortinet, Palo Alto Networks and more — normalized, translated to English and flagged against the CISA KEV catalog. One global feed for CSIRTs, SOCs and defenders.
View CSAF Summary Successful exploitation of this vulnerability may return a response containing the CI Server setting information. The following versions of Yokogawa FAST/TOOLS and CI Server are affected: FAST/TOOLS >=R9.01|<=R10.04 Collaborative Information Server (CI Server) >…
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-12569 PTC Windchill and FlexPLM Improper Input Validation Vulnerability CVE-2026-20230 Cisco Unified Communications Manager Server-Side…
View CSAF Summary Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks. The following versions of EVoke Systems Charging…
View CSAF Summary Successful exploitation of this vulnerability in a custom integration version could allow an attacker to steal an authenticated clinician's token via a crafted link. The following versions of OHIF Viewers DICOM are affected: OHIF DICOM Web Viewer Framework <=v3.…
View CSAF Summary Successful exploitation of these vulnerabilities could could provide an unauthenticated user with complete root-level access and control of the system. The following versions of Daktronics Controller Firmware are affected: VFC-DMP-5000 <v8.117.x.x VFC-DMP-5000 <…
Serial number: AV26-632 Date: June 25, 2026 On June 24, 2026, HPE published a security advisory to address a vulnerability in the following product: HPE Unified Correlation Analyzer (UCA) – versions prior to 4.4.10 The Cyber Centre encourages users and administrators to review th…
Serial number: AV26-631 Date: June 25, 2026 On June 24, 2026, Drupal published security advisories to address vulnerabilities in a number of products. Included were critical updates for the following: Geolocation Field – versions prior to 3.15.0 WissKI – versions prior to 4.2.0 T…
GitLab Inc. has fixed multiple vulnerabilities in GitLab Enterprise Edition (EE) and other GitLab versions, specifically in releases from version 8.3 to 19.1.1, with emphasis on versions around 18.11.6, 19.0.3, and 19.1.1. The vulnerabilities affect various components of GitLab, …
Generic IO & Memory Access driver for PCs provided by TOSHIBA CORPORATION and Dynabook Inc. exposes its IOCTL with insufficient access control.
Multiple vulnerabilities have been discovered in GitLab. Some of them allow an attacker to cause a breach of data confidentiality, server-side request forgery (SSRF), and remote indirect code injection (XSS).
Multiple vulnerabilities have been discovered in CPython. Some of them allow an attacker to cause remote denial of service, a breach of data confidentiality, and a breach of data integrity.
Multiple security vulnerabilities were discovered in the SOGo groupware server, which could result in cross-site scripting or SQL injection. https://security-tracker.debian.org/tracker/DSA-6366-1
Multiple vulnerabilities have been discovered in Google Chrome. They allow an attacker to cause an unspecified security issue by the vendor.
Multiple vulnerabilities have been discovered in Microsoft Azure Linux. They allow an attacker to cause an unspecified security issue by the vendor.
PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network.
Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated, remote attacker to write files to the underlying …
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. https://security-tracker.debian.org/tracker/DSA-6364-1
Multiple vulnerabiliites have been discovered in PDNS Recursor, a resolving name server which could result in denial of service, cache poisoning or information disclosure. https://security-tracker.debian.org/tracker/DSA-6369-1
It was discovered that incorrect request handling in the internal web server of the PowerDNS DNS server could result in denial of service. https://security-tracker.debian.org/tracker/DSA-6368-1
Multiple security vulnerabilities were discovered in the dnsdist DNS loadbalancer, which could result in denial of service, information disclosure or bypass of security rules. https://security-tracker.debian.org/tracker/DSA-6367-1
Multiple security vulnerabilities were discovered in libssh2, a client-side C library implementing the SSH2 protocol which could result in memory disclosure, denial of service or potentially the execution of arbitrary code. https://security-tracker.debian.org/tracker/DSA-6365-1
A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and can lead to arbitrary JavaScript execution within the context of the victim's browser session.
SCE's purpose is to ensure that only trusted or safe values are …
Serial number: AV26-630 Date: June 24, 2026 On June 24, 2026, GitLab published a security advisory to address vulnerabilities in the following products: GitLab Community Edition (CE) – versions prior to 19.1.1, 19.0.3 and 18.11.6 GitLab Enterprise Edition (EE) – versions prior to…
Serial number: AV26-629 Date: June 24, 2026 On June 24, 2026, Jenkins published a security advisory to address vulnerabilities in the following products: Assembla Plugin – versions prior to 1.4 External Workspace Manager Plugin – versions prior to 1.3.2 OWASP ZAP Plugin – version…
Serial number: AV26-628 Date: June 24, 2026 On June 24, 2026, n8n published security advisories to address vulnerabilities in the following product: n8n – versions prior to 2.28.1 n8n – versions prior to 2.27.4 n8n – versions prior to 1.123.61 The Cyber Centre encourages users an…
Serial number : AV26-627 Date: June 24, 2026 On June 23, 2026, Tenable published a security advisory to address critical vulnerabilities in the following product: Tenable Identity Exposure – versions prior to 3.93.4 The Cyber Centre encourages users and administrators to review t…
Serial number: AV26-626 Date: June 24, 2026 On June 23, 2026, Google published a security advisory to address vulnerabilities in the following product: Stable Channel Chrome for Desktop – versions prior to 149.0.7827.196/197 (Windows/Mac), and 149.0.7827.196 (Linux) The Cyber Cen…
Using SASE in a Modern TIC 3.0 Solution CISA’s guidance, The Journey to Zero Trust – Using Secure Access Service Edge in a Modern TIC 3.0 Solution , details how the Trusted Internet Connections (TIC) 3.0 initiative is helping agencies modernize the way their users connect to appl…
Affects plugin: Active Directory Affects plugin: Assembla Affects plugin: Bitbucket Push and Pull Request Affects plugin: Contrast Continuous Application Security Affects plugin: EC2 Fleet Affects plugin: External Workspace Manager Affects plugin: FitNesse Affects plugin: Git cli…
libssh has fixed vulnerabilities in libssh2 up to version 1.11.1. The first vulnerability concerns a pre-authentication denial of service in the SSH_MSG_EXT_INFO handler. A malicious SSH server can send a specially crafted extension_count value, causing the client to enter a CPU …
Multiple vulnerabilities have been discovered in Microsoft Azure Linux. They allow an attacker to cause an unspecified security issue by the vendor.
Multiple vulnerabilities have been discovered in Tenable Identity Exposure. Some of them allow an attacker to cause remote arbitrary code execution, remote denial of service, and a breach of data confidentiality.
Multiple vulnerabilities have been discovered in cURL and libcurl. Some of them allow an attacker to cause remote denial of service, a breach of data confidentiality, and a security policy bypass.
On June 24, 2026, we released versions 19.1.1, 19.0.3, 18.11.6 for GitLab Community Edition (CE) and Enterprise Edition (EE). These versions contain important bug and security fixes, and we strongly recommend that all self-managed GitLab installations be upgraded to one of these …
On June 24, 2026, we released versions 19.1.1, 19.0.3, 18.11.6 for GitLab Community Edition (CE) and Enterprise Edition (EE). These versions contain important bug and security fixes, and we strongly recommend that all self-managed GitLab installations be upgraded to one of these …
Impact
A user with only users.edit AND api permissions can send a PATCH to /api/v1/users/{their_own_id} and grant themselves any permission except admin and superuser — for example assets.view, assets.create, reports.view, import, etc.
Patches
Patched in https://github.com/groka…
Summary
In BeanDeserializer._deserializeUsingPropertyBased, the active-view (@JsonView) filter was applied only to creator properties; the regular property-buffering branch performed no prop.visibleInView(activeView) check. A change making SetterlessProperty.isMerging() return tr…
Summary
POJOPropertiesCollector._renameProperties() allows a property with @JsonProperty("renamed") on the getter and @JsonIgnore on the setter to be renamed rather than dropped. With MapperFeature.INFER_PROPERTY_MUTATORS enabled (default), the private backing field is retained; …
Summary
In BeanDeserializerBase.createContextual(), per-property @JsonIgnoreProperties exclusions are applied by _handleByNameInclusion(), producing a contextual deserializer whose BeanPropertyMap has the ignored properties removed. The subsequent per-property case-insensitivity …
Summary
JDKFromStringDeserializer constructed InetSocketAddress with new InetSocketAddress(host, port), which performs eager DNS name resolution for hostname inputs at deserialization time. An application that binds untrusted JSON into a type containing an InetSocketAddress field…
Summary
BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concr…
jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety mechanism guarding polymorphic deserialization. When polymorphic typing is enabled and a type identifier contains generic parameters (i.e. the type ID string contains <), DatabindContext._resolveAndValidateGe…
Summary
UnwrappedPropertyHandler.processUnwrappedCreatorProperties() replays buffered JSON into creator parameters but never consults prop.visibleInView(activeView). The normal property-based creator path gates creator properties on the active view, but this unwrapped-creator rep…
Serial number: AV26-241 Date: March 16, 2026 Updated: June 23, 2026 Between March 9 and 15, 2026, CISA published ICS advisories to address vulnerabilities in the following products: Apeman Cameras ID71 – all versions Ceragon Siklu MultiHaul and EtherHaul Series – multiple version…
Serial number: AV26-498 Date: May 22, 2026 Updated: June 23, 2026 On May 21, 2026, Ubiquiti published a security advisory to address vulnerabilities in the following products. Included were critical updates for the following: Express - version 4.0.13 and prior UCG-Industrial - ve…
Summary
The mise HTTP backend builds its install symlink destination from the raw resolved version string for non-latest versions. Normal tool install paths use the sanitized version pathname, but the HTTP backend's symlink path uses the raw value. On Unix-like systems, if that …