CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

● Live advisory feed

Security Advisory Fusion for CSIRTs, SOCs & Defenders

Security advisories from 24 sources — CISA, CERT-EU, NCSC-UK, BSI, CERT-FR, NCSC-NL, JPCERT/CC, JVN, HKCERT, the Canadian Cyber Centre, NVD, GitHub, Microsoft, Cisco, Fortinet, Palo Alto Networks and more — normalized, translated to English and flagged against the CISA KEV catalog. One global feed for CSIRTs, SOCs and defenders.

Advisories tracked
20,890
Known exploited
1,782
Sources online
24
Last sync
25M AGO
9,404 records · page 29 / 189 · nvd firehose hidden — show all

USN-8582-1: jbig2dec vulnerabilities

Zeng Yunxiang and Song Jiaxuan discovered that jbig2dec had an out-of-bounds read vulnerability in its command-line tool. An attacker could possibly use this issue to cause jbig2dec to crash, resulting in a denial of service. This issue only affected Ubuntu 22.04 LTS. (CVE-2023-4

Cisco Catalyst SD-WAN Controller, Catalyst SD-WAN Manager, and Catalyst SD-WAN Validator Authenticated Privilege Escalation Vulnerability

A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute arbitrary commands a

unknownexploitedpublic exploitCVE-2026-20182CVE-2026-20127CVE-2026-20245cisco-psirt2026-07-21

WordPress security advisory (AV26-723) - Update 1

Serial number: AV26-723 Date: July 20, 2026 Date: July 21, 2026 On July 17, 2026, WordPress published a security advisory to address vulnerabilities in the following product: WordPress 7.0 – versions prior to 7.0.2 WordPress 6.9 – versions prior to 6.9.5 WordPress 6.8 – versions

unknownexploitedpublic exploitCVE-2026-60137CVE-2026-63030cccs2026-07-21

Mozilla security advisory (AV26-726)

Serial number: AV26-726 Date: July 21, 2026 On July 21, 2026, Mozilla published security advisories to address vulnerabilities in the following products. Included were critical updates for the following: Firefox ESR – versions prior to 140.13 Firefox ESR – versions prior to 115.3

criticalcccs2026-07-21

Zyxel security advisory (AV26-725)

Serial number: AV26-725 Date: July 21, 2026 On July 21, 2026, Zyxel published a security advisory to address a vulnerability in the following products: DSL/Ethernet CPE – multiple versions and models Fiber ONTs – multiple versions and models Wireless Extenders – multiple versions

unknowncccs2026-07-21

Tenable security advisory (AV26-724)

Serial number: AV26-724 Date: July 21, 2026 On July 20, 2026, Tenable published a security advisory to address critical vulnerabilities in the following product: Tenable Security Center – version 6.6.0 to 6.8.0 The Cyber Centre encourages users and administrators to review the pr

criticalcccs2026-07-21

USN-8577-1: OpenSSH vulnerability

USN-8222-1 fixed a vulnerability in OpenSSH. This update provides the corresponding fix for Ubuntu 16.04 LTS. Original advisory details: Vladimir Tokarev discovered that OpenSSH incorrectly handled certificates with the principal name containing a comma character when using user-

unknownCVE-2026-35414ubuntu2026-07-21

Rockwell Automation 1718-AENTR/1719-AENTR

View CSAF Summary Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product. The following versions of Rockwell Automation 1718-AENTR/1719-AENTR are affected: 1718/ 1719 Ex I/O 3.011 CVSS Vendor Equipment Vulne

criticalCVE-2026-9140cisa2026-07-21

Siemens IAM Client

View CSAF Summary Multiple Siemens products are affected by unquoted search path vulnerability in IAM Client. This could allow an authenticated local attacker to perform privilege escalation. Siemens has released new versions for several affected products and recommends to update

criticalCVE-2025-40945cisa2026-07-21

Tycon Systems TPDIN-Monitor-WEB2

View CSAF Summary Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk. The following versions of Tycon Sys

Rockwell Automation 1734 POINT I/O

View CSAF Summary Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product. The following versions of Rockwell Automation 1734 POINT I/O are affected: 1734 POINT I/O 3.023 CVSS Vendor Equipment Vulnerabilities

criticalCVE-2026-10573cisa2026-07-21

Siemens CADRA

View CSAF Summary CADRA is affected by multiple zlib and Foxit vulnerabilities. Siemens has released a new version for CADRA and recommends to update to the latest version. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes

criticalexploitedpublic exploitCVE-2005-2096CVE-2016-9840CVE-2016-9841CVE-2016-9842cisa2026-07-21

Rockwell Automation FactoryTalk Services Platform

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to impersonate an authorized user on the FTSP server, resulting in unauthorized access to system configurations. The following versions of Rockwell Automation FactoryTalk Services Platform are

criticalCVE-2026-10714cisa2026-07-21

Siemens Opcenter X

View CSAF Summary Opcenter X before V2604 contain an authentication bypass vulnerability that could allow an attacker to gain full unauthorized access to the application. Siemens has released a new version for Opcenter X and recommends to update to the latest version. The followi

criticalCVE-2026-56451cisa2026-07-21
← NewerOlder →