● Live advisory feed
Security Advisory Fusion for CSIRTs, SOCs & Defenders
Security advisories from 24 sources — CISA, CERT-EU, NCSC-UK, BSI, CERT-FR, NCSC-NL, JPCERT/CC, JVN, HKCERT, the Canadian Cyber Centre, NVD, GitHub, Microsoft, Cisco, Fortinet, Palo Alto Networks and more — normalized, translated to English and flagged against the CISA KEV catalog. One global feed for CSIRTs, SOCs and defenders.
CVE-2026-63801: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done
CVE-2026-63808: exfat: fix potential use-after-free in exfat_find_dir_entry()
CVE-2026-44210: Kata Containers have VM Escape via virtiofsd Argument Injection through Default-Enabled Pod Annotations
CVE-2026-11331: Potential wildcard CNAME RPZ policy bypass
CVE-2026-50311: Windows Server Elevation of Privilege Vulnerability
Improper access control in Windows Server allows an authorized attacker to elevate privileges locally.
CVE-2026-50372: Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability
Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally.
CVE-2026-59847: Libssh: libssh: integrity downgrade via openssl aes-gcm tag verification
CVE-2026-16768: Gdk-pixbuf: out-of-bounds read in ico parser
CVE-2026-50363: Windows Push Notifications Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
CVE-2026-64446: staging: rtl8723bs: fix heap buffer overflow in rtw_cfg80211_set_wpa_ie()
CVE-2026-64287: KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU
CVE-2026-64465: usb: xhci: Fix sleep in atomic context in xhci_free_streams()
CVE-2026-64493: iio: pressure: mpl115: fix runtime PM leak on read error
CVE-2026-14461: Out-of-bound read in mtr
CVE-2026-15711: Libsoup: soupwebsocketconnection: libsoup: websocket remote denial of service via oversized control frame protocol violation
CVE-2026-50416: Win32k Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally.
CVE-2026-14015: Chromium: CVE-2026-14015 Inappropriate implementation in WebRTC
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-63827: apparmor: fix use-after-free in rawdata dedup loop
CVE-2026-50405: Windows Filtering Platform Elevation of Privilege Vulnerability
Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate privileges locally.
CVE-2026-50527: .NET Framework Denial of Service Vulnerability
Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-14057: Chromium: CVE-2026-14057 Insufficient policy enforcement in FedCM
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-50301: Microsoft Office Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-64272: Input: mms114 - fix touch indexing for MMS134S and MMS136
CVE-2026-64380: smb: client: harden POSIX SID length parsing
CVE-2026-55046: Microsoft Excel Information Disclosure Vulnerability
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-55049: Microsoft Office Remote Code Execution Vulnerability
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-55057: Microsoft Office Information Disclosure Vulnerability
Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-55040: Microsoft SharePoint Server Security Feature Bypass Vulnerability
Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-56175: Windows NTFS Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
CVE-2026-50503: Windows Runtime Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.
CVE-2026-58295: Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-58296: Microsoft Edge for Android Information Disclosure Vulnerability
Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.
CVE-2026-58545: Windows Kernel Security Feature Bypass Vulnerability
Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally.
CVE-2026-50504: Windows Remote Desktop Client Information Disclosure Vulnerability
Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
CVE-2026-13831: Chromium: CVE-2026-13831 Use after free in GPU
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-15772: Chromium: CVE-2026-15772 Use after free in GPU
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-15766: Chromium: CVE-2026-15766 Uninitialized Use in Skia
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-17667: Chromium: CVE-2026-17667 Uninitialized Use in ANGLE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-17786: Chromium: CVE-2026-17786 Insufficient validation of untrusted input in DevTools
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-14408: Chromium: CVE-2026-14408 Uninitialized Use in Dawn
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-17780: Chromium: CVE-2026-17780 Inappropriate implementation in Isolated Web Apps
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-17775: Chromium: CVE-2026-17775 Inappropriate implementation in PresentationAPI
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-17761: Chromium: CVE-2026-17761 Insufficient validation of untrusted input in Chrome for iOS
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-50453: Windows USB Audio Class Driver Information Disclosure Vulnerability
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.
CVE-2026-58609: Windows Graphics Component Remote Code Execution Vulnerability
Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to execute code locally.
CVE-2026-17752: Chromium: CVE-2026-17752 Use after free in Views
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-17749: Chromium: CVE-2026-17749 Insufficient validation of untrusted input in Extensions
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-17712: Chromium: CVE-2026-17712 Race in Skia
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-17710: Chromium: CVE-2026-17710 Inappropriate implementation in MHTML
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.