● Live advisory feed
Security Advisory Fusion for CSIRTs, SOCs & Defenders
Security advisories from 24 sources — CISA, CERT-EU, NCSC-UK, BSI, CERT-FR, NCSC-NL, JPCERT/CC, JVN, HKCERT, the Canadian Cyber Centre, NVD, GitHub, Microsoft, Cisco, Fortinet, Palo Alto Networks and more — normalized, translated to English and flagged against the CISA KEV catalog. One global feed for CSIRTs, SOCs and defenders.
CVE-2026-55047: Microsoft Office Information Disclosure Vulnerability
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-55127: Microsoft Word Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-64450: tipc: fix out-of-bounds read in broadcast Gap ACK blocks
CVE-2026-63831: mac802154: llsec: add skb_cow_data() before in-place crypto
Supers override fails to properly override supervisor address
CVSSv3 Score: 6.9 An Improper Restriction of Communication Channel to Intended Endpoints [CWE-923] vulnerability in FortiSIEM Windows Agent may allow an unauthorized attacker on the same local network to execute arbitrary code via spoofing the supervisors hostname when the Window…
CVE-2026-55141: Microsoft Excel Remote Code Execution Vulnerability
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-55129: Microsoft Office Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-57220: RabbitMQ: Stream listener does not enforce configured frame-size limit during authentication, permitting unauth'd mem-exhaust DoS
CVE-2026-14146: Chromium: CVE-2026-14146 Inappropriate implementation in CSS
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-41109: GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability
Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-14145: Chromium: CVE-2026-14145 Inappropriate implementation in CSS
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-57217: RabbitMQ: Topic authorization can lead to cross-tenant routing-key bypass
CVE-2026-55058: Microsoft Excel Remote Code Execution Vulnerability
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-45784: rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
CVE-2026-53403: fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var
CVE-2026-13878: Chromium: CVE-2026-13878 Use after free in Bluetooth
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-64483: ALSA: firewire: isight: bound the sample count to the packet payload
CVE-2026-64268: RDMA/siw: bound Read Response placement to the RREAD length
CVE-2026-63800: pNFS: Fix use-after-free in pnfs_update_layout()
CVE-2026-14024: Chromium: CVE-2026-14024 Use after free in Ozone
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-63804: gfs2: fix use-after-free in gfs2_qd_dealloc
CVE-2026-56168: Windows SMB Server Denial of Service Vulnerability
Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network.
CVE-2026-64496: iio: event: Fix event FIFO reset race
CVE-2026-13986: Chromium: CVE-2026-13986 Inappropriate implementation in Media UI
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-64280: fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region()
CVE-2026-55898: Microsoft Excel Information Disclosure Vulnerability
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-55944: Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability
Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network.
CVE-2026-9079: stale proxy password leak
CVE-2026-64273: Input: iforce - bound the device-reported force-feedback effect index
CVE-2026-59846: Libssh: libssh: information disclosure via proxycommand %r username expansion
CVE-2026-56196: Windows Admin Center (WAC) Remote Code Execution Vulnerability
Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network.
CVE-2026-13960: Chromium: CVE-2026-13960 Inappropriate implementation in Passwords
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-53353: hsr: Remove WARN_ONCE() in hsr_addr_is_self().
CVE-2026-56197: Windows Admin Center (WAC) Remote Code Execution Vulnerability
Improper neutralization of special elements used in a command ('command injection') in Windows Admin Center allows an authorized attacker to execute code over a network.
CVE-2026-56642: Microsoft Fabric Data Warehouse Remote Code Execution Vulnerability
Stack-based buffer overflow in Microsoft Fabric Data Warehouse allows an authorized attacker to execute code over a network.
CVE-2026-57093: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2026-13912: Chromium: CVE-2026-13912 Incorrect security UI in Safe Browsing
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-57968: Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability
Buffer over-read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.
CVE-2026-58288: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2026-58292: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2026-58293: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2026-58298: Microsoft Edge (Chromium-based) Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-58299: Microsoft Edge for Android Remote Code Execution Vulnerability
Time-of-check time-of-use (toctou) race condition in Microsoft Edge for Android allows an unauthorized attacker to execute code over a network.
Header injection in captive portal authentication form
CVSSv3 Score: 3.1 An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy captive portal may allow an attacker able to intercept and modify a user's authentication request to inject arbitrary heade…
CVE-2026-58523: Microsoft Edge for Android Security Feature Bypass Vulnerability
Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-58530: Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.
CVE-2026-13939: Chromium: CVE-2026-13939 Insufficient validation of untrusted input in WebShare
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-58626: Windows Remote Desktop Services Remote Code Execution Vulnerability
Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.
CVE-2026-55002: Microsoft SQL Server Elevation of Privilege Vulnerability
External control of file name or path in SQL Server allows an authorized attacker to elevate privileges over a network.