● Live advisory feed
Security Advisory Fusion for CSIRTs, SOCs & Defenders
Security advisories from 24 sources — CISA, CERT-EU, NCSC-UK, BSI, CERT-FR, NCSC-NL, JPCERT/CC, JVN, HKCERT, the Canadian Cyber Centre, NVD, GitHub, Microsoft, Cisco, Fortinet, Palo Alto Networks and more — normalized, translated to English and flagged against the CISA KEV catalog. One global feed for CSIRTs, SOCs and defenders.
CVE-2026-13978: Chromium: CVE-2026-13978 Insufficient policy enforcement in PageInfo
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-14006: Chromium: CVE-2026-14006 Use after free in Navigation
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-14019: Chromium: CVE-2026-14019 Inappropriate implementation in Passwords
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-14056: Chromium: CVE-2026-14056 Insufficient validation of untrusted input in Media
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-13796: Chromium: CVE-2026-13796 Integer overflow in Chromecast
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-14095: Chromium: CVE-2026-14095 Insufficient validation of untrusted input in Browser
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-13917: Chromium: CVE-2026-13917 Insufficient validation of untrusted input in Chrome for iOS
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-13974: Chromium: CVE-2026-13974 Integer overflow in Safe Browsing
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-13987: Chromium: CVE-2026-13987 Incorrect security UI in Mobile
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-14075: Chromium: CVE-2026-14075 Policy bypass in Chrome for iOS
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-13774: Chromium: CVE-2026-13774 Use after free in Extensions
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-14096: Chromium: CVE-2026-14096 Object lifecycle issue in Input
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-59925: inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs
CVE-2026-47301: Configuration Manager Elevation of Privilege Vulnerability
Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network.
CVE-2026-13908: Chromium: CVE-2026-13908 Insufficient validation of untrusted input in Omnibox
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-26197: Array full size, element count, and element size are not checked to make sure they match in H5Odtype.c
CVE-2026-63136: Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
CVE-2026-44687: Off-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward zone by a legitimate parent's NXDOMAIN
CVE-2026-13918: Chromium: CVE-2026-13918 Use after free in Chrome for iOS
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-50346: Netlogon RPC Elevation of Privilege Vulnerability
Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally.
CVE-2026-64510: ACPI: NFIT: core: Fix acpi_nfit_init() error cleanup
CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction
CVE-2026-64419: mm/shrinker: do not hold RCU lock in shrinker_debugfs_count_show()
CVE-2026-50479: Windows USB Hub Driver Elevation of Privilege Vulnerability
Untrusted pointer dereference in Windows USB Hub Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-64345: usb: gadget: f_printer: take kref only for successful open
CVE-2026-57101: Visual Studio Code Security Feature Bypass Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-14382: Chromium: CVE-2026-14382 Insufficient validation of untrusted input in ANGLE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-58290: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2026-63964: usb: typec: ucsi: ccg: reject firmware images without a ':' record header
CVE-2026-34349: Windows Media Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.
CVE-2026-8286: wrong STARTTLS connection reuse
CVE-2026-14647: onnx onnxruntime old.cc convPoolShapeInference_opset19 out-of-bounds
CVE-2026-14419: Chromium: CVE-2026-14419 Use after free in Skia
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-56434: NGINX ngx_http_ssi_module vulnerability
CVE-2026-50248: BOGUS configured primary hostname accepted for XFR in auth/rpz zones
CVE-2026-56392: Heap-based Buffer Overflow in GNU coreutils
CVE-2026-64275: Input: elan_i2c - prevent division by zero and arithmetic underflow
CVE-2026-59873: node-tar: Decompression/parse DoS via unlimited input
CVE-2026-55018: Microsoft Office Remote Code Execution Vulnerability
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-59875: node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records
CVE-2026-54117: Microsoft SQL Server Remote Code Execution Vulnerability
Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.
CVE-2026-15392: DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location
CVE-2026-63811: f2fs: read COW data with the original inode during atomic write
CVE-2026-15109: Chromium: CVE-2026-15109 Uninitialized Use in ANGLE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-13849: Chromium: CVE-2026-13849 Insufficient validation of untrusted input in Chromoting
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-15129: Chromium: CVE-2026-15129 Use after free in Views
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-13879: Chromium: CVE-2026-13879 Use after free in Bluetooth
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-66314: Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
CVE-2026-17789: Chromium: CVE-2026-17789 Insufficient validation of untrusted input in Chrome for iOS
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.