● Live advisory feed
Security Advisory Fusion for CSIRTs, SOCs & Defenders
Security advisories from 24 sources — CISA, CERT-EU, NCSC-UK, BSI, CERT-FR, NCSC-NL, JPCERT/CC, JVN, HKCERT, the Canadian Cyber Centre, NVD, GitHub, Microsoft, Cisco, Fortinet, Palo Alto Networks and more — normalized, translated to English and flagged against the CISA KEV catalog. One global feed for CSIRTs, SOCs and defenders.
Summary
Prompty loaders expanded ${file:...} references in .prompty frontmatter without enforcing that the resolved path stayed within an authorized directory. An attacker-controlled prompt file could use path traversal or an absolute path to cause the host application to read fi…
Bulletin ID: 2026-060-AWS Scope: AWS Content Type: Important (requires attention) / Informational Publication Date: 07/17/2026 12:45 PM PDT Description: AWS HealthOmics is a HIPAA-eligible service that fully manages the compute, storage, and workflow engine infrastructure require…
Impact
context_import passed the caller-supplied filePath directly to fs.readFileSync with no path confinement. A malicious MCP client — or an LLM agent that is prompt-injected into calling the tool — could point filePath at any file readable by the server process, outside any s…
Bulletin ID: 2026-059-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/17/2026 12:00 PM PDT Description: Amazon Athena is a serverless, interactive query service that lets you analyze data directly in Amazon S3 using standard SQL. Athena Query Fede…
Formie contains a missing authorization vulnerability in administrative settings routes. An authenticated, non-admin Craft CMS control panel user with limited Formie access could directly access Formie settings pages and modify global plugin configuration.
In affected versions, …
CVE Description
Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.
Summary
A critical vulnerability has been discovered in Gitea. It was already reporte…
Summary
PUT /api/basemap (the basemap import endpoint) fetches an attacker-supplied URL server-side with no SSRF protection whatsoever. Any authenticated user can submit a JSON body { "type": "...", "url": "<attacker url>" }; the server calls fetch(url) against that URL and then…
Summary
The vulnerability in oapi-codegen seems to be similar with CVE-2026-22785, which is a generated-code injection issue where untrusted OpenAPI summary text is embedded into generated TypeScript MCP server source without proper escaping. oapi-codegen has a similar vulnerabi…
X-Pipeboard-Token Header Auth Bypass Reuses Operator Meta Token
Summary
AuthInjectionMiddleware in meta-ads-mcp rejects HTTP MCP requests only when both auth_token and pipeboard_token are absent. Because extract_token_from_headers() does not recognise the X-Pipeboard-Token head…
Server-Side Request Forgery (SSRF) in upload_ad_image via Unrestricted image_url Fetch
Summary
The upload_ad_image MCP tool in meta-ads-mcp v1.0.113 passes an attacker-controlled image_url parameter directly to an HTTP fetch helper (httpx.AsyncClient(follow_redirects=True).get(…
Impact
The _uid option performed an incomplete privilege drop on Linux/Unix-like systems.
When sh was run from a process with elevated privileges, such as root, and a command was launched with _uid=<unprivileged user>, the child process changed its UID and primary GID but did no…
Aurora PostgreSQL is a fully managed relational database engine that's compatible with PostgreSQL.
The team has identified CVE-2026-11400, an issue in Aurora PostgreSQL using the AWS Advanced JDBC Wrapper
Impact
An issue in AWS Wrappers for Amazon Aurora PostgreSQL will allow f…
Impact
A stored XSS affecting RichText fields. RichTextValue.output returns the raw, unsanitized stored value whenever the stored mimeType equals the outputMimeType. Because the safe-HTML output type (text/x-html-safe) is the type that signifies "already sanitized", any value wh…
Impact
A stored XSS affecting RichText fields. RichTextValue.output returns the raw, unsanitized stored value whenever the stored mimeType equals the outputMimeType. Because the safe-HTML output type (text/x-html-safe) is the type that signifies "already sanitized", any value wh…
Serial number: AV26-714 Date: July 17, 2026 On July 16, 2026, Microsoft published a security update to address vulnerabilities in the following product: Microsoft Edge Stable Channel – versions prior to 150.0.4078.80 The Cyber Centre encourages users and administrators to review …
Summary
The Kubernetes admission webhook handler reads the entire request body using io.ReadAll(r.Body) without any size limit. Any client that can reach the webhook port within the cluster can send a multi-GB payload, causing the skipper process to exhaust memory and be OOM-kil…
Summary
Current-head vLLM documents VLLM_MAX_AUDIO_CLIP_FILESIZE_MB as the maximum audio file size accepted by the speech-to-text APIs. The default is 25 MB. vllm/envs.py also describes files larger than this value as rejected.
The /v1/audio/transcriptions and /v1/audio/transla…
Summary
The structured_outputs.regex API parameter passes a user-supplied regex string directly to grammar compiler backends with no compilation timeout. In the xgrammar backend, the string reaches compile_regex() with no guard. In the outlines backend, validate_regex_is_buildab…
Summary
A frontend-legal multi-request speculative workload can make vLLM produce an out-of-vocabulary recovered token equal to vocab_size, convert that value to -1 when choosing the next live token for a request, and then feed that -1 back into the next drafter input ids. On Qw…
Issue Description
Librosa defaults to using numpy.mean for mono downmixing (to_mono), while the international standard ITU-R BS.775-4 specifies a weighted downmixing algorithm. This discrepancy results in:
- Inconsistency between audio heard by humans (e.g., through headphones/re…
Serial number: AV26-713 Date: July 17, 2026 On July 16, 2026, Google published a security advisory to address vulnerabilities in the following product: Stable Channel Chrome for Desktop – versions prior to 150.0.7871.128/.129 (Windows/Mac), and 150.0.7871.128 (Linux) The Cyber Ce…
Serial number: AV26-712 Date: July 17, 2026 On July 14, 2026, Broadcom published security advisories to address vulnerabilities in multiple products. Included was a critical update for the following: VMware Avi Load Balancer – multiple versions The Cyber Centre encourages users a…
Zoom has fixed vulnerabilities in Zoom Client for Windows, Zoom Rooms for Windows, and other Zoom Windows products such as the Windows Desktop Client, VDI Client, and Meeting SDK. The vulnerabilities include a TOCTOU race condition that can be exploited by an authenticated local …
n8n has fixed multiple vulnerabilities in the n8n workflow automation platform, specifically in versions 2.10.1, 2.9.3, 1.123.22, and other related releases. The vulnerabilities affect various components within n8n, including the Form nodes, Python Code node, JavaScript Task Runn…
Splunk has fixed vulnerabilities in Splunk Enterprise and Splunk Cloud Platform. The first vulnerability concerns insufficient CSRF protection and input validation in Deployment Server endpoints, allowing an attacker to execute arbitrary SPL queries under the splunk-system-user c…
Adobe has fixed multiple vulnerabilities in Adobe Experience Manager. The vulnerabilities in Adobe Experience Manager include, among others, the lack of authentication on a critical function, allowing unauthorized write actions without user interaction. Additionally, there is a S…
Serial number: AV26-711 Date: July 17, 2026 On July 17, 2026, FreePBX published security advisories to address vulnerabilities in the following products. Included were critical updates for the following: FreePBX Security-Reporting ucp (FreePBX 17) – versions prior to 17.0.9 FreeP…
A remote, anonymous attacker can exploit a vulnerability in Microsoft Office 365 (Moodle Plugin) to bypass security measures, impersonate users, and thereby gain elevated permissions, including administrator access.
A local attacker can exploit a vulnerability in Bouncy Castle to carry out an unspecified attack.
A remote, authenticated attacker can exploit a vulnerability in Microsoft SharePoint and Microsoft SharePoint Server to carry out a Cross-Site Scripting attack.
A remote, anonymous attacker can exploit a vulnerability in Microsoft Windows Terminal to execute arbitrary program code.
A remote, anonymous attacker can exploit multiple vulnerabilities in HCL BigFix (Service Management) to carry out a Denial of Service attack.
An attacker can exploit multiple vulnerabilities in the ubuntu-pro-client of Ubuntu Linux to execute arbitrary program code with administrator privileges and disclose confidential information.
A remote, anonymous attacker can exploit a vulnerability in Microsoft Windows Admin Center to carry out a Cross-Site Scripting attack.
A remote, anonymous attacker can exploit a vulnerability in Grafana Loki to carry out a Denial of Service attack.
An attacker can exploit multiple vulnerabilities in nginx-ui to execute arbitrary code, including code execution with root privileges; gain elevated rights; perform account takeover; bypass security measures; or disclose and manipulate data.
A remote, authenticated attacker can exploit a vulnerability in Keycloak to disclose information.
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - Block layer subsystem; - Cryptographic API; - DMA engine subsystem; - Infini…
Fortinet has fixed a vulnerability in FortiSandbox. The vulnerability concerns an Exposure of Resource to Wrong Sphere (CWE-668) in the VNC server component used within the scanning virtual machines of FortiSandbox. Unauthenticated attackers can send network requests to gain acce…
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - Block layer subsystem; - Cryptographic API; - DMA engine subsystem; - Infini…
Fortinet has fixed a vulnerability in FortiAuthenticator. The vulnerability concerns an out-of-bounds read in FortiAuthenticator versions 6.5 and 6.6.0 to 6.6.2. An external, unauthenticated attacker can exploit this vulnerability by sending specially crafted requests, leading to…
Fortinet has fixed a vulnerability in FortiClient EMS versions 7.2 to 7.4.5. The vulnerability concerns improper validation of certificates within FortiClient EMS. This allows an external, unauthenticated attacker to impersonate an Active Directory Connector by using a valid API …
A remote, anonymous attacker can exploit multiple vulnerabilities in libssh2 to conduct a denial of service attack or execute code.
SAP has fixed vulnerabilities in SAP NetWeaver Application Server ABAP, SAP Approuter, SAP Commerce Cloud, SAP NetWeaver Application Server Java, SAProuter, SAP Change and Transport System Attach Tool, SAP NetWeaver Enterprise Portal, SAP S/4HANA modules, SAP Fiori Launchpad, SAP…
Microsoft has fixed vulnerabilities in various Office products, such as Word, Excel, PowerPoint, and SharePoint. An attacker can exploit the vulnerabilities to carry out attacks that can lead to categories of damage, as listed in the table below. For successful exploitation, the …
A remote, anonymous attacker can exploit a vulnerability in expat to conduct a Denial of Service attack.
A remote, anonymous attacker can exploit multiple vulnerabilities in Django to disclose information, cause a denial of service, and manipulate data.
An attacker can exploit multiple vulnerabilities in Microsoft Visual Studio Code, Microsoft ASP.NET, Microsoft .NET, and Microsoft Visual Studio 2026 to gain administrative privileges, manipulate data, disclose confidential information, or bypass authentication.
A local attacker can exploit multiple vulnerabilities in PHP and ZendPHP to conduct an unspecified attack.
An authenticated attacker can exploit multiple vulnerabilities in the Flatpak package of Red Hat Enterprise Linux to execute arbitrary code and delete files.