● Live advisory feed
Security Advisory Fusion for CSIRTs, SOCs & Defenders
Security advisories from 24 sources — CISA, CERT-EU, NCSC-UK, BSI, CERT-FR, NCSC-NL, JPCERT/CC, JVN, HKCERT, the Canadian Cyber Centre, NVD, GitHub, Microsoft, Cisco, Fortinet, Palo Alto Networks and more — normalized, translated to English and flagged against the CISA KEV catalog. One global feed for CSIRTs, SOCs and defenders.
Summary
Koel v9.6.0 protects the regular podcast subscription API with SafeUrl, but the Subsonic-compatible createPodcastChannel.view route does not apply the same protection. An authenticated user can supply a private URL and cause Koel to fetch it server-side during podcast par…
Serial number : AV26-705 Date: July 15, 2026 On July 14, 2026, Tenable published a security advisory to address a critical vulnerability in the following product: Nessus Agent – versions 11.2.0 and prior Nessus Agent – versions 11.1.3 and prior The Cyber Centre encourages users a…
A MantisBT user having *$g_update_bug_threshold* (UPDATER by default) can change an Issue's Status via REST and SOAP API, even if the *$g_set_status_threshold* config is set to a higher level (DEVELOPER by default).
Impact
Unauthorized change in Issue workflow.
Patches
https://…
MantisBT 2.28.3 and earlier contains a remote code execution vulnerability in the admin "Manage Configuration" feature (adm_config_set.php). When setting a configuration value with a non-string type (integer, float, complex), the value is passed through ConfigParser -> Tokenizer,…
MantisBT 2.28.3 and earlier contains a critical authentication bypass in the SOAP API's mci_check_login() function. Any user knowing any valid cookie_string can authenticate as any other user (knowing their username), including the administrator, without knowing the target's pass…
MantisBT 2.28.3 and earlier versions contains a SQL injection vulnerability in core/history_api.php. The history_order configuration value is concatenated directly into a SQL ORDER BY clause without any sanitisation, parameterization, or validation against a whitelist.
An admini…
On July 15, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories: Cisco Security Advisory CVE ID Security Impact Rating CVSS Base Score Cisco RoomOS Security Hardening Release: July 2026 CVE-2026-20150 CVE-2026-20153 CVE-2026-20156 CV…
A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or delete arbitrary files. To exploit this …
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabil…
Serial number: AV26-704 Date: July 15, 2026 On July 15, 2026, F5 published a security advisory to address vulnerabilities in the following products: NGINX Agent – versions 2.37.0 to 2.46.5 NGINX Instance Manager – versions 2.17.1 to 2.22.1 NGINX Plus – versions 37.0.0.1 to 37.0.2…
Serial number: AV26-703 Date: July 15, 2026 On July 14, 2026, Notepad++ published a security advisory to address vulnerabilities in the following product: Notepad++ – version prior to v8.9.7 The Cyber Centre encourages users and administrators to review the provided web links and…
Serial number: AV26-702 Date: July 15, 2026 On July 14, 2026, Citrix published security advisories to address vulnerabilities in the following products: Citrix Secure Access Client for Windows – versions prior to 26.6.1.20 Citrix Endpoint Analysis Client for Windows – versions pr…
Serial number: AV26-701 Date: July 14, 2026 On July 14, 2026, Google published a security advisory to address vulnerabilities in the following product: Stable Channel Chrome for Desktop – versions prior to 150.7871.124/125 (Windows/Mac), and 150.0.7871.124 (Linux) The Cyber Centr…
Serial number: AV26-700 Date: July 15, 2026 On July 14, 2026, HPE published security advisories to address vulnerabilities in the following products. Included were critical updates for the following: HPE Telco Intelligent Assurance (FAS and PDO) – versions 4.2.15 and prior HPE Un…
It was discovered that Sympa did not properly validate input on the generic SSO login. A remote attacker could possibly use this issue to perform a path traversal attack and gain unintended access.
It was discovered that Tomcat incorrectly handled authorization when multiple method constraints defined the same HTTP method. A remote attacker could possibly use this issue to bypass authorization restrictions. (CVE-2026-43515) It was discovered that the Tomcat number guess exa…
It was discovered that libslirp incorrectly handled TCP urgent data. A privileged attacker inside a guest VM could possibly use this issue to obtain sensitive information from the host process memory.
It was discovered that idna did not properly reject oversized inputs before performing expensive processing. An attacker could possibly use this issue to cause idna to consume significant resources, leading to a denial of service.
Fortinet has fixed vulnerabilities in multiple versions of FortiSIEM (Windows Agent and general product versions), FortiOS, FortiPAM, and FortiProxy. A vulnerability in FortiSIEM Windows Agent (versions 7.4.0 to 7.4.1) identified as CVE-2026-59841 allows malicious actors on the s…
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-jp7m-xcgx-57qm. This link is maintained to preserve external references.
Original Description
n8n before versions 1.123.61, 2.27.4, and 2.28.1 contains a permission bypass vulnerability in ext…
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-2434-3x6q-8r99. This link is maintained to preserve external references.
Original Description
n8n before 2.28.1 contains an information disclosure vulnerability where external secrets are inc…
It was discovered that a logic flaw existed in the XFRM ESP-in-TCP subsystem in the Linux kernel when handling socket buffer fragments. This flaw is known as Fragnesia. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-43503) Severa…
Developed by CISA, the National Security Agency (NSA) and international partners, this joint guidance contains best practices for software manufacturers and online service providers to design and implement a coordinated vulnerability disclosure (CVD) program for working with exte…
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2023-4346 KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability CVE-2026…
Cyber Advisors are offering free 30-minute consultations to help small businesses get started with cyber security.
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - RISC-V architecture; - Cryptographic API; - InfiniBand drivers; - IOMMU subsystem; - Network drive…
An attacker can exploit multiple vulnerabilities in Adobe Magento to escalate privileges, execute arbitrary code, bypass security measures, conduct cross-site scripting attacks, and disclose confidential information.
An attacker can exploit multiple vulnerabilities in Red Hat OpenShift (OpenStack Services) to disclose information.
An attacker can exploit multiple vulnerabilities in Adobe ColdFusion to execute arbitrary program code, escalate privileges, conduct an SQL injection attack, perform a cross-site scripting attack, bypass security precautions, and disclose information.
An attacker can exploit multiple vulnerabilities in Adobe Creative Cloud Applications to escalate privileges, execute arbitrary code, bypass security measures, or disclose confidential information.
A remote, anonymous attacker can exploit multiple vulnerabilities in Sonatype Nexus Repository Manager to bypass security measures, disclose information, and potentially manipulate data.
A remote, anonymous attacker can exploit a vulnerability in Xen to manipulate files.
A remote, anonymous attacker can exploit multiple vulnerabilities in Dell integrated Dell Remote Access Controller to trigger a denial of service, disclose information, bypass security measures, and potentially execute code.
A remote, authenticated attacker can exploit multiple vulnerabilities in Devolutions Server to manipulate data, bypass security measures, and disclose information.
A remote, authenticated attacker can exploit a vulnerability in Tenable Security Nessus Agent to execute arbitrary program code.
A remote, authenticated attacker can exploit a vulnerability in Red Hat OpenStack Keystone to bypass authentication and gain unauthorized access to the system.
A remote, authenticated attacker can exploit a vulnerability in HCL BigFix to disclose information.
A remote, anonymous attacker can exploit multiple vulnerabilities in Erlang/OTP to bypass security measures.
A remote, anonymous attacker can exploit multiple vulnerabilities in SonicWall SMA to bypass security measures and execute arbitrary operating system commands on the affected system.
An attacker can exploit multiple vulnerabilities in Adobe Experience Manager to execute arbitrary program code, bypass security measures, disclose information, and conduct a Cross-Site Scripting attack.
An attacker can exploit multiple vulnerabilities in OpenBao to escalate privileges, bypass security measures, or disclose confidential information.
SonicWall has fixed two vulnerabilities in SonicWall SMA1000 appliances. The vulnerability identified as CVE-2026-15409 is a Server-Side Request Forgery (SSRF) in the Work Place interface, allowing an unauthenticated attacker to make the device send requests to unwanted locations…
An attacker can exploit multiple vulnerabilities in Wireshark to conduct a Denial of Service attack or disclose confidential information.
An attacker can exploit multiple vulnerabilities in Microsoft Windows Terminal and Microsoft 365 Copilot to execute arbitrary code, present false information, and escalate their privileges.
A remote, anonymous attacker can exploit multiple vulnerabilities in Grafana Tempo to conduct a Denial of Service attack.
A local attacker can exploit multiple vulnerabilities in Citrix Systems Secure Access Client for Windows to escalate privileges and disclose information.
A remote, anonymous attacker can exploit a vulnerability in TYPO3 Core to bypass security measures.
A local attacker can exploit multiple vulnerabilities in Rockwell Automation Studio 5000 Logix Designer to execute arbitrary program code.
An attacker can exploit multiple vulnerabilities in Rockwell Automation FactoryTalk products to escalate privileges or conduct Cross-Site Scripting attacks.
A remote, authenticated attacker can exploit a vulnerability in Devolutions Remote Desktop Manager to execute arbitrary program code.