● Live advisory feed
Security Advisory Fusion for CSIRTs, SOCs & Defenders
Security advisories from 24 sources — CISA, CERT-EU, NCSC-UK, BSI, CERT-FR, NCSC-NL, JPCERT/CC, JVN, HKCERT, the Canadian Cyber Centre, NVD, GitHub, Microsoft, Cisco, Fortinet, Palo Alto Networks and more — normalized, translated to English and flagged against the CISA KEV catalog. One global feed for CSIRTs, SOCs and defenders.
Summary
An inverted-boolean bug in lettre's boring-tls integration silently
disables TLS hostname verification for callers using the default (strict)
configuration. An on-path attacker presenting any chain-valid certificate
for any domain can intercept SMTP submission, including …
Impact
WordPress Coding Standards (WordPressCS) versions before 3.4.1 contain an arbitrary code execution vulnerability in the WordPress.WP.EnqueuedResourceParameters sniff. As a result, running PHPCS with WordPressCS over untrusted PHP code, for example, in a CI pipeline that l…
Summary
When directConnect(true) is enabled, appium/java-client unconditionally
accepts directConnectHost, directConnectPort, and directConnectPath
from the server's NEW_SESSION response and silently redirects all subsequent
session traffic to the attacker-specified endpoint — w…
Reauthentication Bypass via One-Time Access Token Login
Summary
A weaker authentication method (OTA token or signup token) is accepted as passkey step-up proof, yielding unauthorized renewable 30-day OIDC refresh tokens for clients explicitly configured with RequiresReauthentic…
OIDC Refresh Token Flow Bypasses Authorization Revocation, Account Disabling, and Group Restrictions
Summary
The createTokenFromRefreshToken function (oidc_service.go:451) validates the refresh token's cryptographic integrity but does not re-validate the user's current authoriz…
CI Fortify – Advice for isolating vital systems CI Fortify – Advice for isolating vital systems (PDF) CISA and the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), in collaboration with the Federal Bureau of Investigation and international partners,…
View CSAF Summary Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant). Siemens is preparing fix versions and recommends specific countermeasures f…
A highly disruptive incident can feel overwhelming. New guidance provides a framework for response and recovery.
View CSAF Summary Successful exploitation of this vulnerability could allow attackers to rapidly guess passwords and gain unauthorized system access. The following versions of MikroTik RouterOS and Cloud Hosted Router are affected: RouterOS vers:all/* (CVE-2026-16347) Cloud Hoste…
View CSAF Summary Mendix documentation for access rules does not adequately describe the special behavior of the System.User entity, leaving developers without sufficient guidance to configure access rules securely. This documentation gap may lead application developers to unknow…
View CSAF Summary OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution. Siemens has released new versions for several affected products and recommends to u…
View CSAF Summary SIMATIC S7-PLCSIM Advanced contains a vulnerability that could allow an attacker to cause a denial of service condition. Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. The followi…
View CSAF Summary Successful exploitation of this vulnerability could allow an unauthorized actor to access functions or backend services. The following versions of igloohome Smart Lock Mobile Application are affected: Smart Lock Mobile Application (Android) 3.2.3 (CVE-2026-16581…
View CSAF Summary ABB has been contacted by a researcher who identified a vulnerability in one of its products. ABB has been contacted by a researcher who identified a vulnerability in one of its products. The vulnerability report has been shared in responsible disclosure. An att…
A remote, anonymous attacker can exploit a vulnerability in Podman to disclose information.
An attacker can exploit multiple vulnerabilities in Microsoft Visual Studio, Microsoft Visual Studio Code, Microsoft .NET Framework, and Microsoft .NET to execute arbitrary code, manipulate data, escalate privileges, bypass security measures, disclose information, and conduct a d…
A remote, anonymous or authenticated attacker can exploit multiple vulnerabilities in Oracle MySQL to compromise confidentiality, integrity, and availability.
A remote, anonymous attacker can exploit multiple vulnerabilities in OpenSSL and LibreSSL to potentially execute arbitrary code, cause a Denial of Service state, and disclose confidential information.
It was discovered that Samba's pam_winbind incorrectly handled home directory ownership when mkhomedir was enabled. A local attacker could possibly use this issue to cause a denial of service by triggering a change in ownership of the root directory. (CVE-2026-15779) Arjun Basnet…
A remote, anonymous attacker can exploit a vulnerability in GNU libc to carry out a denial of service attack.
A remote, anonymous attacker can exploit multiple vulnerabilities in GNU libc to manipulate DNS responses.
A remote, anonymous attacker can exploit a vulnerability in Bouncy Castle to disclose information.
A local attacker can exploit a vulnerability in the cifs-utils of Red Hat Enterprise Linux to execute arbitrary code with administrator rights.
An attacker can exploit multiple vulnerabilities in JFrog Artifactory to execute arbitrary code, escalate privileges, disclose information, manipulate files, and bypass security precautions.
A remote, anonymous, or authenticated attacker can exploit multiple vulnerabilities in various third-party components in Oracle Solaris to carry out an unspecified attack.
An attacker can exploit a vulnerability in OpenBSD to carry out an unspecified attack.
A remote, anonymous attacker can exploit multiple vulnerabilities in GStreamer to disclose information, conduct a Denial-of-Service attack, corrupt data, or execute arbitrary code.
A remote, anonymous attacker can exploit a vulnerability in libssh to carry out a Denial of Service attack.
An attacker can exploit multiple vulnerabilities in GStreamer to disclose information and perform a Denial of Service attack.
A remote, anonymous attacker can exploit multiple vulnerabilities in Apache Wicket to carry out a Cross-Site Scripting attack and to bypass security measures.
An attacker can exploit multiple vulnerabilities in Apple Safari to disclose confidential information, bypass security measures, manipulate data, conduct spoofing attacks, or cause a Denial-of-Service condition.
An attacker can exploit multiple vulnerabilities in Apple macOS Tahoe, Sonoma, and Sequoia to escalate privileges, execute arbitrary code, carry out a Denial of Service attack, disclose information, manipulate files, and bypass security measures.
An attacker from an adjacent network can exploit multiple vulnerabilities in Progress Software LoadMaster and Progress Software MOVEit to execute arbitrary code and gain root privileges.
A remote, authenticated attacker can exploit multiple vulnerabilities in Devolutions Server to gain administrative rights and disclose confidential information.
An attacker can exploit multiple vulnerabilities in Flowise to disclose information and bypass security measures.
A local attacker can exploit multiple vulnerabilities in GIMP to carry out a Denial of Service attack, execute arbitrary code, or disclose confidential information.
A remote, anonymous attacker can exploit a vulnerability in OpenCTI to bypass security measures.
An attacker can exploit multiple vulnerabilities in Apple iOS and Apple iPadOS to execute arbitrary code, escalate privileges, carry out a Denial of Service attack, disclose information, manipulate files, and bypass security measures.
A local attacker can exploit a vulnerability in the Linux Kernel to conduct a denial of service attack or achieve other unspecified effects.
An attacker with physical access can exploit a vulnerability in the Linux Kernel to create a Denial-of-Service condition or potentially execute arbitrary code or disclose information.
An attacker can exploit multiple vulnerabilities in the Linux Kernel to carry out unspecified attacks that may lead to a denial-of-service condition or cause memory corruption.
A local attacker can exploit multiple vulnerabilities in Linux Kernel to conduct a Denial of Service attack or achieve unspecified impacts.
An attacker can exploit multiple vulnerabilities in the Linux Kernel to carry out unspecified attacks that may lead to a denial-of-service condition or cause memory corruption.
A remote anonymous attacker can exploit multiple vulnerabilities in the Linux Kernel to create a denial of service condition or conduct other unspecified attacks.
A remote, anonymous attacker can exploit a vulnerability in JetBrains TeamCity to execute arbitrary program code.
A remote, anonymous attacker can exploit a vulnerability in Microsoft Azure Portal to disclose information.
A local attacker can exploit multiple vulnerabilities in the Linux Kernel to corrupt memory, disclose confidential information, manipulate data, or cause a Denial-of-Service condition.
A remote, anonymous attacker can exploit a vulnerability in Netty to perform a denial of service attack.
An attacker can exploit a vulnerability in Moodle to disclose information.
A local attacker can exploit multiple vulnerabilities in the Linux Kernel to perform a denial of service attack.