● Live advisory feed
Security Advisory Fusion for CSIRTs, SOCs & Defenders
Security advisories from 24 sources — CISA, CERT-EU, NCSC-UK, BSI, CERT-FR, NCSC-NL, JPCERT/CC, JVN, HKCERT, the Canadian Cyber Centre, NVD, GitHub, Microsoft, Cisco, Fortinet, Palo Alto Networks and more — normalized, translated to English and flagged against the CISA KEV catalog. One global feed for CSIRTs, SOCs and defenders.
CVE-2026-64455: USB: chaoskey: Fix slab-use-after-free in chaoskey_release()
CVE-2026-64382: smb: client: fix double-free in SMB2_open() replay
CVE-2026-66034: libssh2 Heap Out-of-Bounds Read via publickey subsystem
CVE-2026-13937: Chromium: CVE-2026-13937 Insufficient policy enforcement in Passwords
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-64469: binder: fix UAF in binder_thread_release()
CVE-2026-64399: ksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE
CVE-2026-64387: smb: client: fix query directory replay double-free
CVE-2026-64412: netfilter: ebtables: module names must be null-terminated
CVE-2026-64390: ksmbd: track the connection owning a byte-range lock
CVE-2026-13952: Chromium: CVE-2026-13952 Inappropriate implementation in PerformanceAPIs
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-64514: userfaultfd: gate must_wait writability check on pte_present()
CVE-2026-64401: smb: client: resolve SWN tcon from live registrations
CVE-2026-49808: Windows Kernel Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50325: Win32k Elevation of Privilege Vulnerability
Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-53354: arm64: errata: Mitigate TLBI errata on various Arm CPUs
CVE-2026-64192: bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized
CVE-2026-13968: Chromium: CVE-2026-13968 Insufficient validation of untrusted input in DevTools
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-15125: Chromium: CVE-2026-15125 Inappropriate implementation in Forms
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-54891: Plaintext APPLICATION_DATA injected during TLS handshake delivered to client application post-handshake in ssl
CVE-2026-40469: Heap buffer overflow in gawk
CVE-2026-13221: Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk
CVE-2026-15043: DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted = SQL operators on text
CVE-2026-54171: Excon: redact additional sensitive/risky headers when following redirects
CVE-2026-50397: Windows Kernel Elevation of Privilege Vulnerability
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-63793: ntfs: serialize volume label accesses
CVE-2026-53377: drm/msm: always recover the gpu
CVE-2026-53368: f2fs: fix fsck inconsistency caused by incorrect nat_entry flag usage
CVE-2026-41106: Microsoft 365 Copilot Elevation of Privilege Vulnerability
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-63798: irqchip/imgpdc: Fix resource leak, add missing chained handler cleanup on remove
CVE-2026-64434: Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref
CVE-2026-64038: hwmon: (lm90) Stop work before releasing hwmon device
CVE-2026-15116: Chromium: CVE-2026-15116 Use after free in Actor
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-14037: Chromium: CVE-2026-14037 Insufficient policy enforcement in GPU
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-64036: cgroup/rstat: validate cpu before css_rstat_cpu() access
CVE-2026-14414: Chromium: CVE-2026-14414 Insufficient validation of untrusted input in Skia
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-64138: ksmbd: validate SID in parent security descriptor during ACL inheritance
CVE-2026-63958: usb: typec: ucsi: validate connector number in ucsi_connector_change()
CVE-2026-26199: Buffer underflow in `H5Iget_name `/`H5G_get_name` if size is zero
CVE-2026-64187: xfs: fail recovery on a committed log item with no regions
CVE-2026-53397: nfsd: fix posix_acl leak on SETACL decode failure
CVE-2026-14401: Chromium: CVE-2026-14401 Insufficient validation of untrusted input in ANGLE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-56002: libXfont2 PCF Font Parsing Heap Buffer Overflow
CVE-2026-59884: pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs
CVE-2026-54998: Microsoft Exchange Online Elevation of Privilege Vulnerability
Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.
CVE-2026-54120: Microsoft Surface Remote Code Execution Vulnerability
Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.
CVE-2026-56192: Microsoft Office Information Disclosure Vulnerability
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-49175: Windows DNS Client Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.
CVE-2026-49172: Windows FTP Service Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.