● Live advisory feed
Security Advisory Fusion for CSIRTs, SOCs & Defenders
Security advisories from 24 sources — CISA, CERT-EU, NCSC-UK, BSI, CERT-FR, NCSC-NL, JPCERT/CC, JVN, HKCERT, the Canadian Cyber Centre, NVD, GitHub, Microsoft, Cisco, Fortinet, Palo Alto Networks and more — normalized, translated to English and flagged against the CISA KEV catalog. One global feed for CSIRTs, SOCs and defenders.
CVE-2026-14048: Chromium: CVE-2026-14048 Use after free in Chromecast
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-40422: Windows File Explorer Information Disclosure Vulnerability
Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.
CVE-2026-50298: Windows Spaceport.sys Elevation of Privilege Vulnerability
Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a physical attack.
CVE-2026-42955: Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-time 'ghost domain' delegation renewal via glue records
CVE-2026-50329: Microsoft DWM Core Library Elevation of Privilege Vulnerability
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-59922: Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert)
CVE-2026-64402: coresight: ultrasoc-smb: Fix OOB write in smb_sync_perf_buffer()
CVE-2026-50347: Windows Data.dll Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows Data dll allows an unauthorized attacker to execute code locally.
CVE-2026-64212: wifi: iwlwifi: mld: don't dereference a pointer before NULL checking it
CVE-2026-50434: Windows Push Notification Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.
CVE-2026-54986: Windows Win32k Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-50428: Windows Container Isolation FS Filter Driver (unionfs.sys) Information Disclosure Vulnerability
Out-of-bounds read in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally.
CVE-2026-55002: Microsoft SQL Server Elevation of Privilege Vulnerability
External control of file name or path in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-64476: vfio/pci: Latch disable_idle_d3 per device
CVE-2026-64437: ksmbd: fix use-after-free of a deferred file_lock on SMB2_CLOSE then SMB2_CANCEL
Header injection in captive portal authentication form
CVSSv3 Score: 3.1 An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy captive portal may allow an attacker able to intercept and modify a user's authentication request to inject arbitrary heade…
CVE-2026-13960: Chromium: CVE-2026-13960 Inappropriate implementation in Passwords
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-59846: Libssh: libssh: information disclosure via proxycommand %r username expansion
CVE-2026-53353: hsr: Remove WARN_ONCE() in hsr_addr_is_self().
CVE-2026-9079: stale proxy password leak
CVE-2026-64273: Input: iforce - bound the device-reported force-feedback effect index
CVE-2026-13986: Chromium: CVE-2026-13986 Inappropriate implementation in Media UI
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-64496: iio: event: Fix event FIFO reset race
CVE-2026-14024: Chromium: CVE-2026-14024 Use after free in Ozone
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-64268: RDMA/siw: bound Read Response placement to the RREAD length
CVE-2026-64483: ALSA: firewire: isight: bound the sample count to the packet payload
CVE-2026-14145: Chromium: CVE-2026-14145 Inappropriate implementation in CSS
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-15709: Soupwebsocketextensiondeflate: libsoup: libsoup: websocket permessage-deflate unbounded decompression remote denial of service
CVE-2026-41109: GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability
Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-14146: Chromium: CVE-2026-14146 Inappropriate implementation in CSS
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-63831: mac802154: llsec: add skb_cow_data() before in-place crypto
CVE-2026-56186: Windows Secure Channel Information Disclosure Vulnerability
Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network.
CVE-2026-64336: USB: serial: keyspan_pda: fix information leak
CVE-2026-64305: crypto: qat - protect service table iterations with service_lock
CVE-2026-64368: mm/slab: do not limit zeroing to orig_size when only red zoning is enabled
CVE-2026-64448: smb: client: restrict implied bcc[0] exemption to responses without data area
CVE-2026-13809: Chromium: CVE-2026-13809 Side-channel information leakage in Safe Browsing
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-64322: udf: validate sparing table length as an entry count, not a byte count
CVE-2026-58547: Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability
Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges locally.
CVE-2026-58541: Microsoft DWM Core Library Elevation of Privilege Vulnerability
Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized attacker to elevate privileges locally.
CVE-2026-58596: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Untrusted pointer dereference in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-62994: CoreDNS `k8s_external` headless AXFR can emit an empty transfer batch that panics the `transfer` plugin
CVE-2026-57989: Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
CVE-2026-50012: Squid: Memory corruption in cache_digest reply handling
CVE-2026-17654: Chromium: CVE-2026-17654 Race in Updater
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-17666: Chromium: CVE-2026-17666 Cryptographic Flaw in Enterprise
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-45488: Microsoft Edge (Chromium-based) Spoofing Vulnerability
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-17651: Chromium: CVE-2026-17651 Insufficient validation of untrusted input in Dawn
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-14040: Chromium: CVE-2026-14040 Use after free in BrowserTag
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.