● Live advisory feed
Security Advisory Fusion for CSIRTs, SOCs & Defenders
Security advisories from 24 sources — CISA, CERT-EU, NCSC-UK, BSI, CERT-FR, NCSC-NL, JPCERT/CC, JVN, HKCERT, the Canadian Cyber Centre, NVD, GitHub, Microsoft, Cisco, Fortinet, Palo Alto Networks and more — normalized, translated to English and flagged against the CISA KEV catalog. One global feed for CSIRTs, SOCs and defenders.
It was discovered that Wget mishandled semicolons in the userinfo subcomponent of a URL. A remote attacker could possibly use this issue to trick a user into connecting to a different host than intended. This issue only affected Ubuntu 14.04 LTS. (CVE-2024-38428) It was discovere…
Impact
A vulnerability in Woodpecker CI's gRPC layer allowed any authenticated agent to impersonate any other agent on the same server by injecting a forged agent_id value into outgoing gRPC metadata. The server correctly verified the JWT token but then discarded the verified age…
Microsoft has fixed a vulnerability in Dynamics NAV and 365 Business Central. An attacker can exploit the vulnerability to execute arbitrary code on the vulnerable system via a malicious login request. Because Dynamics has many publicly accessible interfaces and does not require …
Microsoft has fixed vulnerabilities in various Office products, such as Word, Excel, PowerPoint, and SharePoint. An attacker can exploit the vulnerabilities to carry out attacks that can lead to categories of damage, as mentioned in the table below. For successful exploitation, t…
Microsoft has fixed vulnerabilities in Defender. An attacker can exploit the vulnerabilities to grant themselves elevated privileges, execute arbitrary code with system rights, and/or gain access to sensitive data. The attacker must deceive the victim into downloading and opening…
Serial number: AV26-695 Date: July 14, 2026 On July 14, 2026, Fortinet published security advisories to address vulnerabilities in multiple products: FortiAuthenticator 6.6 - versions 6.6.0 to 6.6.2 FortiAuthenticator 6.5 - versions 6.5.0 to 6.5.7 FortiSandbox 5.0 - versions 5.0.…
Microsoft has fixed vulnerabilities in Developer Tools such as .NET and Visual Studio. An attacker can exploit the vulnerabilities to carry out attacks that can lead to damage in the categories mentioned in the attached table. For successful exploitation, the attacker must deceiv…
Summary
Anyquery's server mode does not disable or restrict native SQLite disk manipulation commands. Unauthenticated attackers connecting to the MySQL-compatible server port can use the ATTACH DATABASE command to write arbitrary SQLite databases to any path on the victim's files…
Microsoft has fixed vulnerabilities in Exchange, both Online and on-premise. An attacker can exploit the vulnerabilities to impersonate other users, grant themselves elevated privileges, potentially execute arbitrary code, and gain access to sensitive data. The vulnerability in E…
Microsoft has fixed vulnerabilities in various Azure components. An attacker can exploit the vulnerabilities to cause a Denial-of-Service, bypass security measures, or grant themselves elevated privileges, potentially gaining access to data to which the attacker was initially not…
Microsoft has fixed vulnerabilities in various components of SQL Server. An attacker can exploit the vulnerabilities to grant themselves elevated privileges, execute arbitrary code, and/or gain access to sensitive data.
Summary
Fedify previously addressed SSRF/internal network access in GHSA-p9cg-vqcc-grcx by adding public URL validation before runtime document and media fetching. However, the current IPv4 validation logic appears incomplete.
The validatePublicUrl() protection relies on isVali…
Microsoft has fixed a very large number of vulnerabilities in Windows. An attacker can exploit the vulnerabilities to carry out attacks that can lead to categories of damage, as mentioned in the table below. The most severe vulnerabilities have been assigned characteristics CVE-2…
Unbounded Pod Log Read via Attacker-Controlled limitBytes/tailLines Causes Memory Exhaustion
Summary
The MKP (Model Context Protocol for Kubernetes) server exposes a get_resource MCP tool that proxies Kubernetes pod log requests. User-supplied limitBytes and tailLines parameter…
Summary:
Remote post-serve actions use http.DefaultClient without any timeout configuration. When the remote endpoint is unreachable or intentionally slow (accepts TCP connection but never responds), each triggered proxy request spawns a goroutine that blocks indefinitely on htt…
Summary:
When Hoverfly is running in Diff mode, the AddDiff() function writes to the shared responsesDiff map without any synchronization (no mutex). When multiple proxy requests are processed concurrently (the normal case for any proxy), the concurrent map writes trigger Go's b…
Summary
A path traversal vulnerability exists in K3s's etcd snapshot decompression functionality. Zip files containing archive members with maliciously crafted names (e.g., ../../../../etc/password) can be written to arbitrary locations on the filesystem when an administrator re…
Impact
Wasmtime 37.0.0 and 37.0.1 have memory leaks in the C/C++ API when using bindings for the anyref or externref WebAssembly values. This is caused by a regression introduced during the development of 37.0.0 and all prior versions of Wasmtime are unaffected. If anyref or ext…
Yiwei Hou discovered that Dnsmasq incorrectly handled logging of DS or DNSKEY. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-12725) It was discovered that Dnsmasq incorrectly validated the length of fixed-length DNS record fields when par…
Summary
WidgetVariante::renderVariantList (Core/Lib/Widget/WidgetVariante.php:298-330) and WidgetSubcuenta::renderSubaccountList (Core/Lib/Widget/WidgetSubcuenta.php:290-321) build the <tr onclick="..."> row for each modal hit by concatenating the user-controlled referencia / co…
Summary
Live PoC verified 2026-04-30 against a stock FacturaScripts master at 127.0.0.1:8081. A low-privilege user (lowpriv) created a customer with nombre = "=SUM(1+1)*cmd|/c calc!A1". An admin then exported ListCliente to CSV via ?action=export&option=CSV. The downloaded file …
Summary
The static file controllers in FacturaScripts decide whether a request is authorized by looking at the URL string instead of the canonical filesystem path. A request that starts with an allow-listed folder name but contains a ../ segment in the middle ends up serving a f…
Summary
Live PoC verified 2026-04-30 against a stock FacturaScripts master at 127.0.0.1:8081. A scoped ApiKey with fullaccess=0 and an ApiAccess row granting allowget=1 on the clientes resource only (no other rights, no UI session, no admin) issued one GET /api/3/clientes?filter…
Summary
OpenCost contains an unauthenticated file write vulnerability in the /serviceKey endpoint that allows remote attackers to overwrite the GCP service account key file without authentication. This can lead to service disruption, credential theft, and potential privilege esc…
USN-8526-1 fixed vulnerabilities in libheif. This update provides the corresponding updates for CVE-2026-47709 and CVE-2026-47714 in Ubuntu 24.04 LTS. Original advisory details: Junyi Liu discovered that libheif had a null pointer dereference in its image tiling interface. An att…
Hirohito Higashi discovered that Vim incorrectly escaped class or trait names when performing PHP omni-completion. An attacker could possibly use this issue to trick a user into opening a specially crafted PHP file and executing arbitrary commands. This issue only affected Ubuntu…
Serial number: AV26-694 Date: July 14, 2026 On July 14, 2026, Veeam published a security advisor to address a critical vulnerability in the following product: Veeam Software Appliance Updater Component – versions prior to 12.3.0.65 The Cyber Centre encourages users and administra…
It was discovered that OpenVPN had a 1-byte buffer overrun when handling NTLMv2 proxy responses. An attacker could use this issue to cause a denial of service or possibly execute arbitrary code. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-11771) It w…
Haruto Kimura discovered that GnuTLS did not properly apply permitted name constraints in certain certificate validation paths. A remote attacker could possibly use this issue to bypass certificate validation, leading to a machine-in-the-middle attack. (CVE-2026-42011) Oleh Konko…
Serial number: AV26-692 Date: July 14, 2026 On July 14, 2026, Mozilla published a security advisory to address vulnerabilities in the following product. Included was a critical update for the following: Firefox – versions prior to 152.0.6 The Cyber Centre encourages users and adm…
Serial number: AV26-691 Date: July 14, 2026 On July 14, 2026, HPE published a security advisory to address vulnerabilities in the following products: HPE Compute Scale-up Server 3200 - versions prior to v1.76.44 HPE Compute Scale-up Server 3250 - versions prior to v1.02.48 The Cy…
Serial number: AV26-690 Date: July 14, 2026 On July 14, 2026, SAP published security advisories to address vulnerabilities in the following products. Included were critical updates for the following: SAP Approuter node.js package - versions prior to 20.10.0 SAP Approuter node.js …
SAP has fixed vulnerabilities in SAP NetWeaver Application Server ABAP, SAP Approuter, SAP Commerce Cloud, SAP NetWeaver Application Server Java, SAProuter, SAP Change and Transport System Attach Tool, SAP NetWeaver Enterprise Portal, SAP S/4HANA modules, SAP Fiori Launchpad, SAP…
Siemens has fixed vulnerabilities in various products such as CADRA, IAM, Mendix, OpCenter, RUGGEDCOM, SIDIS, and SIMATIC. The vulnerabilities may allow an attacker to execute attacks that can lead to the following categories of damage: - Denial-of-Service (DoS) - Cross-Site Scri…
Serial number: AV26-689 Date: July 14, 2026 On July 14, 2026, Siemens published security advisories to address vulnerabilities in the following products. Included were updates for the following products: CADRA - versions prior to V2511 Desigo CC family V7/V8 - all versions Desigo…
It was discovered that alsa-lib incorrectly handled certain ALSA configuration text. An attacker could use this issue to cause alsa-lib to crash, resulting in a denial of service, or possibly execute arbitrary code.
View CSAF Summary ABB became aware of vulnerability in the products versions listed as affected in the advisory. An update is available that resolves the reported vulnerabilities. An attacker who successfully exploited any of these vulnerabilities could potentially compromise the…
View CSAF Summary ABB became aware of vulnerability in the products versions listed as affected in the advisory, where an incorrect version of Online Builder (ONB) was included in the media. An update is available that resolves the vulnerability, see details in Recommended immedi…
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to read or delete files, stop tasks, modify memory, and change I/O states, potentially impacting the confidentiality, integrity, and availability of the device. The following versions of Rockw…
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-15409 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability CVE-2026-15410 SonicWall SMA1000 Appliances Code Injectio…
Update July 16, 2026 : CISA has updated this Alert to reflect the addition of CVE-2026-58644 to its Known Exploited Vulnerabilities (KEV) Catalog on July 16, 2026. CISA is aware of active exploitation of vulnerabilities CVE-2026-32201 , CVE-2026-45659 , CVE-2026-56164 , and CVE-2…
View CSAF Summary ABB is aware of public reports of a vulnerability CVE‑2026‑31431 (Copy Fail) in the product versions listed as affected in the advisory. An update is available that resolves a publicly reported vulnerability. CVE‑2026‑31431 (Copy Fail) is a Linux kernel vulnerab…
It was discovered that httplib2 performed unbounded decompression of HTTP response bodies when the server used gzip or deflate Content-Encoding. A remote attacker could possibly use this issue to cause httplib2 to use excessive resources, leading to a denial of service.
An attacker can exploit multiple vulnerabilities in AnyDesk to conduct a Denial of Service attack.
An attacker can exploit multiple vulnerabilities in Notepad++ to execute arbitrary code, disclose information, manipulate files, and bypass security measures.
A remote, authenticated attacker can exploit a vulnerability in Apache ActiveMQ to conduct a Cross-Site Scripting attack.
It was discovered that MariaDB did not properly validate parameters supplied by a joiner node during a State Snapshot Transfer using the mariabackup method. An attacker could possibly use this issue to execute arbitrary shell commands on the donor node. (CVE-2026-44168) It was di…
An attacker can exploit multiple vulnerabilities in the Linux Kernel to conduct a denial of service attack or achieve unspecified effects.
An attacker can exploit multiple vulnerabilities in the Linux Kernel to conduct a Denial of Service attack or achieve unspecified effects.
A local attacker can exploit multiple vulnerabilities in different Intel processors to disclose information.