● Live advisory feed
Security Advisory Fusion for CSIRTs, SOCs & Defenders
Security advisories from 24 sources — CISA, CERT-EU, NCSC-UK, BSI, CERT-FR, NCSC-NL, JPCERT/CC, JVN, HKCERT, the Canadian Cyber Centre, NVD, GitHub, Microsoft, Cisco, Fortinet, Palo Alto Networks and more — normalized, translated to English and flagged against the CISA KEV catalog. One global feed for CSIRTs, SOCs and defenders.
CVE-2026-53275: ipv6: mcast: Fix use-after-free when processing MLD queries
CVE-2026-52954: libceph: handle rbtree insertion error in decode_choose_args()
CVE-2026-52946: fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling
CVE-2026-53150: thunderbolt: Reject zero-length property entries in validator
CVE-2026-53149: thunderbolt: Bound root directory content to block size
CVE-2026-53279: drm/gma500/oaktrail_lvds: fix hang on init failure
CVE-2026-53295: mailbox: add sanity check for channel array
CVE-2026-53314: padata: Put CPU offline callback in ONLINE section to allow failure
CVE-2026-53294: mailbox: mailbox-test: don't free the reused channel
CVE-2026-53284: btrfs: only release the dirty pages io tree after successful writes
CVE-2026-53320: nilfs2: reject zero bd_oblocknr in nilfs_ioctl_mark_blocks_dirty()
CVE-2026-52935: xfrm: espintcp: do not reuse an in-progress partial send
CVE-2026-53034: bpf, sockmap: Fix af_unix null-ptr-deref in proto update
CVE-2026-53050: quota: Fix race of dquot_scan_active() with quota deactivation
CVE-2026-52958: libceph: Fix potential out-of-bounds access in osdmap_decode()
CVE-2026-53232: net: phy: clean the sfp upstream if phy probing fails
CVE-2026-10900: Chromium: CVE-2026-10900 Use after free in Passwords
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-48583: Windows Kernel Elevation of Privilege Vulnerability
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-10897: Chromium: CVE-2026-10897 Out of bounds write in GPU
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-53181: vsock/vmci: fix sk_ack_backlog leak on failed handshake
CVE-2026-10881: Chromium: CVE-2026-10881 Out of bounds read and write in ANGLE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-53184: udp: clear skb->dev before running a sockmap verdict
CVE-2026-10889: Chromium: CVE-2026-10889 Out of bounds read in ANGLE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-57434: Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes
CVE-2026-10888: Chromium: CVE-2026-10888 Use after free in Cast Streaming
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-53135: drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs
CVE-2026-57234: Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247
CVE-2026-52970: netfilter: nft_ct: fix missing expect put in obj eval
CVE-2026-52964: ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans
CVE-2026-52923: ipc: limit next_id allocation to the valid ID range
CVE-2026-53130: fs/omfs: reject s_sys_blocksize smaller than OMFS_DIR_START
CVE-2026-53002: netfilter: conntrack: remove sprintf usage
CVE-2026-57437: Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime
CVE-2026-53111: bpf: test_run: Fix the null pointer dereference issue in bpf_lwt_xmit_push_encap
CVE-2026-44812: Windows Graphics Component Remote Code Execution Vulnerability
Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.
CVE-2026-45446: Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes
CVE-2026-44803: Windows Graphics Component Remote Code Execution Vulnerability
Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.
CVE-2026-44801: Remote Desktop Client Remote Code Execution Vulnerability
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-44807: Windows DWM Core Library Elevation of Privilege Vulnerability
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2026-44808: Windows DWM Core Library Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2026-42991: Windows Push Notifications Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
CVE-2026-42904: Windows TCP/IP Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network.
CVE-2026-12469: Chromium: CVE-2026-12469 Uninitialized Use in GPU
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-11647: Chromium: CVE-2026-11647 Use after free in Printing
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-12449: Chromium: CVE-2026-12449 Use after free in Chromoting
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-12468: Chromium: CVE-2026-12468 Inappropriate implementation in Updater
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-12440: Chromium: CVE-2026-12440 Use after free in DigitalCredentials
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-44967: opentelemetry-cpp: OTLP HTTP exporters read unbounded HTTP response
CVE-2026-12439: Chromium: CVE-2026-12439 Use after free in Digital Credentials
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.