● Live advisory feed
Security Advisory Fusion for CSIRTs, SOCs & Defenders
Security advisories from 24 sources — CISA, CERT-EU, NCSC-UK, BSI, CERT-FR, NCSC-NL, JPCERT/CC, JVN, HKCERT, the Canadian Cyber Centre, NVD, GitHub, Microsoft, Cisco, Fortinet, Palo Alto Networks and more — normalized, translated to English and flagged against the CISA KEV catalog. One global feed for CSIRTs, SOCs and defenders.
CVE-2026-40378: Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.
CVE-2026-53345: KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying
CVE-2026-53332: slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd
CVE-2026-8927: env-set cross-proxy Digest auth state leak
CVE-2026-56001: libXfont2 BitmapScaleBitmaps Integer Overflow Heap Buffer Overflow
CVE-2026-56003: libXfont2 computeProps Property Buffer Heap Buffer Overflow
CVE-2026-56173: Windows WebView Elevation of Privilege Vulnerability
Use after free in Windows WebView allows an authorized attacker to elevate privileges locally.
CVE-2026-20213: ClamAV PE File Format Processing Out-of-Bounds Memory Corruption Vulnerability
CVE-2026-14739: DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders
CVE-2026-59928: Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions
CVE-2026-15308: Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations
CVE-2026-59871: node-tar: Process crash via PAX numeric path type confusion
CVE-2026-57216: RabbitMQ: AMQP 1.0, AMQP 0-9-1, Stream Protocol loopback enforcement can lead to remote guest sessions due to listener-address loopback checks
CVE-2026-57211: RabbitMQ: UNC SSRF affecting the management UI on Windows
CVE-2026-15709: Soupwebsocketextensiondeflate: libsoup: libsoup: websocket permessage-deflate unbounded decompression remote denial of service
CVE-2026-38755: A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.
CVE-2026-63834: batman-adv: tp_meter: restrict number of unacked list entries
CVE-2026-14404: Chromium: CVE-2026-14404 Inappropriate implementation in PDFium
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-14405: Chromium: CVE-2026-14405 Uninitialized Use in V8
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-60005: NGINX ngx_http_slice_module vulnerability
CVE-2026-53355: net: rds: clear i_sends on setup unwind
CVE-2026-14045: Chromium: CVE-2026-14045 Insufficient validation of untrusted input in Network
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-63805: crypto: nx - fix nx_crypto_ctx_exit argument
CVE-2026-13926: Chromium: CVE-2026-13926 Insufficient validation of untrusted input in Network
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-63823: keys: Pin request_key_auth payload in instantiate paths
CVE-2026-20244: ClamAV DMG File Processing Denial of Service Vulnerability
CVE-2026-58528: Windows USB Audio Class Driver Information Disclosure Vulnerability
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.
CVE-2026-53390: ksmbd: fix out-of-bounds read in smb_check_perm_dacl()
CVE-2026-53383: ksmbd: reject non-VALID session in compound request branch
CVE-2026-13845: Chromium: CVE-2026-13845 Use after free in DOM
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-50373: Windows Search Service Elevation of Privilege Vulnerability
Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
CVE-2026-50340: Windows Runtime Elevation of Privilege Vulnerability
Use after free in Windows Runtime allows an authorized attacker to elevate privileges over a network.
CVE-2026-64079: netfilter: x_tables: allocate hook ops while under mutex
CVE-2026-50425: Windows Internal System User Profile Elevation of Privilege Vulnerability
Use after free in Windows Internal System User Profile allows an authorized attacker to elevate privileges locally.
CVE-2026-13810: Chromium: CVE-2026-13810 Inappropriate implementation in Input
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-64160: netfs: Fix potential for tearing in ->remote_i_size and ->zero_point
CVE-2026-13821: Chromium: CVE-2026-13821 Use after free in Canvas
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-63959: usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT
CVE-2026-63999: ethtool: rss: fix indir_table and hkey leak on get_rxfh failure
CVE-2026-13321: DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field
CVE-2026-58628: Windows Wireless Network Manager Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Networking allows an authorized attacker to elevate privileges locally.
CVE-2026-41637: Degradation of resolution service from improperly accounted client-terminated DNS-over-QUIC queries
CVE-2026-12547: Libsoup: information disclosure in libsoup via soupauthmanager proxy credential leak on proxy switch
CVE-2026-47063: Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle
CVE-2026-50316: Windows Kernel Information Disclosure Vulnerability
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
CVE-2026-17914: Chromium: CVE-2026-17914 Side-channel information leakage in Skia
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-17933: Chromium: CVE-2026-17933 Inappropriate implementation in DOMStorage
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-58283: Microsoft Edge (Chromium-based) Spoofing Vulnerability
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-17966: Chromium: CVE-2026-17966 Inappropriate implementation in Views
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.