● Live advisory feed
Security Advisory Fusion for CSIRTs, SOCs & Defenders
Security advisories from 24 sources — CISA, CERT-EU, NCSC-UK, BSI, CERT-FR, NCSC-NL, JPCERT/CC, JVN, HKCERT, the Canadian Cyber Centre, NVD, GitHub, Microsoft, Cisco, Fortinet, Palo Alto Networks and more — normalized, translated to English and flagged against the CISA KEV catalog. One global feed for CSIRTs, SOCs and defenders.
Impact
channelBinding=require connections can be silently downgraded from SCRAM-SHA-256-PLUS (with channel binding) to plain SCRAM-SHA-256 (without it), losing the man-in-the-middle protection the setting is meant to guarantee. An attacker who can intercept the TLS connection tr…
Zeng Yunxiang and Song Jiaxuan discovered that jbig2dec had an out-of-bounds read vulnerability in its command-line tool. An attacker could possibly use this issue to cause jbig2dec to crash, resulting in a denial of service. This issue only affected Ubuntu 22.04 LTS. (CVE-2023-4…
It was discovered that libarchive did not properly manage memory when unpacking certain RAR5 archives, leading to a double free. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-14164) It was discovered that libarchive did not properly validate ce…
It was discovered that the Ubuntu-specific SetLanguage patch to AccountsService incorrectly handled dropping privileges. A local attacker could use this issue to execute arbitrary commands as an administrator. (CVE-2026-61897) It was discovered that the Ubuntu-specific SetLanguag…
Microsoft Security Advisory CVE-2026-56170 – .NET Denial of Service Vulnerability
Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core SignalR (Microsoft.AspNetCore.App.Runtime). This advisory also provides…
Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET SDK (Microsoft.NET.Build.Containers). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
A…
Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core Negotiate Authentication (Microsoft.AspNetCore.Authentication.Negotiate). This advisory also provides guidance on what developers can do to update their a…
Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core Negotiate Authentication (Microsoft.AspNetCore.Authentication.Negotiate). This advisory also provides guidance on what developers can do to update their a…
Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET XML Encryption (System.Security.Cryptography.Xml). This advisory also provides guidance on what developers can do to update their applications to remove this vuln…
Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in Windows Presentation Foundation (WPF). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
An el…
A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute arbitrary commands a…
Serial number: AV26-723 Date: July 20, 2026 Date: July 21, 2026 On July 17, 2026, WordPress published a security advisory to address vulnerabilities in the following product: WordPress 7.0 – versions prior to 7.0.2 WordPress 6.9 – versions prior to 6.9.5 WordPress 6.8 – versions …
Summary
Loofah::HTML5::Scrub.allowed_uri? does not correctly reject javascript: URIs when the scheme is split or prefixed by the HTML5 named character references 	 (tab) or 
 (line feed).
This is a bypass of the fix for GHSA-46fp-8f5p-pf2m, which handled the equival…
James Henstridge discovered that snapd's default apparmor template did not restrict access to systemd-userdbd varlink interface. A local attacker could possibly use this issue to obtain sensitive information. (CVE-2024-5300) Qualys discovered that snap-confine can be tricked to c…
Serial number: AV26-726 Date: July 21, 2026 On July 21, 2026, Mozilla published security advisories to address vulnerabilities in the following products. Included were critical updates for the following: Firefox ESR – versions prior to 140.13 Firefox ESR – versions prior to 115.3…
Serial number: AV26-725 Date: July 21, 2026 On July 21, 2026, Zyxel published a security advisory to address a vulnerability in the following products: DSL/Ethernet CPE – multiple versions and models Fiber ONTs – multiple versions and models Wireless Extenders – multiple versions…
Serial number: AV26-724 Date: July 21, 2026 On July 20, 2026, Tenable published a security advisory to address critical vulnerabilities in the following product: Tenable Security Center – version 6.6.0 to 6.8.0 The Cyber Centre encourages users and administrators to review the pr…
Microsoft has fixed vulnerabilities in various Office products, such as Word, Excel, PowerPoint, and SharePoint. An attacker can exploit these vulnerabilities to carry out attacks that may lead to categories of damage, as outlined in the table below. For successful exploitation, …
It was discovered that CUPS did not properly filter control characters in IPP string attributes and PPD keywords. An unauthenticated attacker could exploit this to execute arbitrary code as the lp user on systems with shared target queues.
USN-8222-1 fixed a vulnerability in OpenSSH. This update provides the corresponding fix for Ubuntu 16.04 LTS. Original advisory details: Vladimir Tokarev discovered that OpenSSH incorrectly handled certificates with the principal name containing a comma character when using user-…
View CSAF Summary Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product. The following versions of Rockwell Automation 1718-AENTR/1719-AENTR are affected: 1718/ 1719 Ex I/O 3.011 CVSS Vendor Equipment Vulne…
View CSAF Summary Multiple Siemens products are affected by unquoted search path vulnerability in IAM Client. This could allow an authenticated local attacker to perform privilege escalation. Siemens has released new versions for several affected products and recommends to update…
View CSAF Summary Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Customers are advised to consult and implement the workarounds provided in Palo Alto Net…
View CSAF Summary Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk. The following versions of Tycon Sys…
View CSAF Summary Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product. The following versions of Rockwell Automation 1734 POINT I/O are affected: 1734 POINT I/O 3.023 CVSS Vendor Equipment Vulnerabilities…
View CSAF Summary CADRA is affected by multiple zlib and Foxit vulnerabilities. Siemens has released a new version for CADRA and recommends to update to the latest version. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes …
View CSAF Summary Successful exploitation of these vulnerabilities could allow for a local attacker to execute arbitrary files, alter configurations, or execute arbitrary code. The following versions of Rockwell Automation Studio 5000 Logix Designer are affected: Studio 5000 Logi…
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to impersonate an authorized user on the FTSP server, resulting in unauthorized access to system configurations. The following versions of Rockwell Automation FactoryTalk Services Platform are…
View CSAF Summary Opcenter X before V2604 contain an authentication bypass vulnerability that could allow an attacker to gain full unauthorized access to the application. Siemens has released a new version for Opcenter X and recommends to update to the latest version. The followi…
View CSAF Summary SIDIS Secured SmartPlug before V7.26.0310 is affected by multiple vulnerabilities in the components OpenSSL, OpenSSH, and several other packages as described below. Siemens has released a new version of SIDIS Secured SmartPlug and recommends to update to the lat…
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2021-27137 DD-WRT Stack-Based Buffer Overflow Vulnerability CVE-2026-0770 Langflow Inclusion of Functionality from Untrusted Control Sphere…
An attacker can exploit multiple vulnerabilities in the Linux Kernel to conduct a denial of service attack or achieve unspecified effects.
A local attacker can exploit multiple vulnerabilities in OpenSSH to execute arbitrary program code.
An attacker can exploit multiple vulnerabilities in the Linux Kernel to conduct a denial of service attack or perform other unspecified attacks.
A remote attacker can exploit multiple vulnerabilities in the Linux Kernel to conduct a denial of service attack or cause unspecified effects.
An attacker can exploit multiple vulnerabilities in the Linux Kernel to produce unspecified effects or cause a Denial of Service state.
A local attacker can exploit a vulnerability in GnuTLS to conduct an unspecified attack.
An attacker can exploit multiple vulnerabilities in Linux Kernel to carry out a Denial of Service attack.
An attacker can exploit multiple vulnerabilities in Synacor Zimbra to execute arbitrary code, perform cross-site scripting attacks, bypass security measures, disclose confidential information, and carry out unauthorized actions.
A remote, anonymous attacker can exploit multiple vulnerabilities in Netty to bypass security measures, manipulate data, disclose confidential information, or cause a denial-of-service condition.
An attacker can exploit multiple vulnerabilities in Rsync to escalate privileges, disclose information, bypass security measures, and conduct a Denial of Service attack.
A remote, authenticated attacker can exploit a vulnerability in Rsync to bypass security measures.
A local attacker can exploit multiple vulnerabilities in X.Org X11 and Xwayland to carry out unspecified attacks, potentially including memory corruption, information disclosure, or a denial-of-service condition.
A remote, authenticated attacker can exploit a vulnerability in Red Hat Enterprise Linux to overwrite arbitrary files and potentially execute arbitrary code.
A remote, authenticated attacker can exploit a vulnerability in Zoho ManageEngine Endpoint Central to disclose information.
Maxim Suhanov discovered that the NTFS file system implementation in the Linux kernel did not properly validate file name length in certain situations, leading to an out-of-bounds read. An attacker could use this to construct a malicious NTFS image that, when mounted and operated…
An attacker can exploit multiple vulnerabilities in OPNsense to bypass security measures, disclose information, conduct a cross-site scripting attack, and perform a denial-of-service attack.
Maxim Suhanov discovered that the NTFS file system implementation in the Linux kernel did not properly validate file name length in certain situations, leading to an out-of-bounds read. An attacker could use this to construct a malicious NTFS image that, when mounted and operated…
It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local attacker could use this to expose sensitive information. (CVE-2025-54505) It was discovered that some AMD Zen 2 processors did not prope…
IBM has fixed multiple vulnerabilities in IBM Langflow OSS versions 1.0.0 to 1.10.0. The vulnerabilities in IBM Langflow OSS include: - executing arbitrary file changes by authenticated users via specially crafted Content-Disposition headers - server-side request forgery (SSRF) d…