● Live advisory feed
Security Advisory Fusion for CSIRTs, SOCs & Defenders
Security advisories from 24 sources — CISA, CERT-EU, NCSC-UK, BSI, CERT-FR, NCSC-NL, JPCERT/CC, JVN, HKCERT, the Canadian Cyber Centre, NVD, GitHub, Microsoft, Cisco, Fortinet, Palo Alto Networks and more — normalized, translated to English and flagged against the CISA KEV catalog. One global feed for CSIRTs, SOCs and defenders.
CVE-2026-17744: Chromium: CVE-2026-17744 Inappropriate implementation in File Input
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-64277: Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count
CVE-2026-64333: USB: serial: digi_acceleport: fix write buffer corruption
CVE-2026-64340: USB: legousbtower: fix use-after-free on disconnect race
CVE-2026-64316: crypto: caam - use print_hex_dump_devel to guard key hex dumps
CVE-2026-14084: Chromium: CVE-2026-14084 Insufficient validation of untrusted input in Chromoting
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-64504: iio: accel: bmc150: clamp the device-reported FIFO frame count
CVE-2026-64269: RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg
CVE-2026-64392: ksmbd: use opener credentials for delete-on-close
CVE-2026-64456: hwrng: virtio: clamp device-reported used.len at copy_data()
CVE-2026-64511: ACPI: NFIT: core: Fix possible NULL pointer dereference
CVE-2026-14091: Chromium: CVE-2026-14091 Use after free in DevTools
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-64458: mm/damon/ops-common: handle extreme intervals in damon_hot_score()
CVE-2026-64385: smb: client: fix double-free in SMB2_ioctl() replay
CVE-2026-64391: ksmbd: use opener credentials for ADS I/O
CVE-2026-14143: Chromium: CVE-2026-14143 Incorrect security UI in Passwords
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-64335: USB: serial: digi_acceleport: fix broken rx after throttle
CVE-2026-53332: slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd
CVE-2026-55999: xorg-server / xwayland glamor font atlas Heap Buffer Overflow
CVE-2026-14739: DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders
CVE-2026-14152: Chromium: CVE-2026-14152 Out of bounds write in ANGLE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-15308: Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations
CVE-2026-59871: node-tar: Process crash via PAX numeric path type confusion
CVE-2026-57211: RabbitMQ: UNC SSRF affecting the management UI on Windows
CVE-2026-13911: Chromium: CVE-2026-13911 Insufficient data validation in Spellcheck
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-13922: Chromium: CVE-2026-13922 Side-channel information leakage in Paint
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-53402: fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font()
CVE-2026-53368: f2fs: fix fsck inconsistency caused by incorrect nat_entry flag usage
CVE-2026-63872: esp: fix page frag reference leak on skb_to_sgvec failure
CVE-2026-63832: wifi: mt76: add wcid publish check in mt76_sta_add
CVE-2026-53387: iio: light: veml6075: add bounds check to veml6075_it_ms index
CVE-2026-63807: KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level
CVE-2026-17891: Chromium: CVE-2026-17891 Use after free in ANGLE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-64070: powerpc/hv-gpci: fix preempt count leak in sysfs show paths
CVE-2026-64117: wifi: mac80211: capture fast-RX rate before mesh reuses skb->cb
CVE-2026-64111: lsm: hold cred_guard_mutex for lsm_set_self_attr()
CVE-2026-14155: Chromium: CVE-2026-14155 Insufficient policy enforcement in StorageAccessAPI
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
CVE-2026-64154: drm/msm/adreno: Fix a reference leak in a6xx_gpu_init()
CVE-2026-49162: Microsoft Brokering File System Elevation of Privilege Vulnerability
Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
CVE-2026-63979: net/handshake: hand off the pinned file reference to accept_doit
CVE-2026-26199: Buffer underflow in `H5Iget_name `/`H5G_get_name` if size is zero
CVE-2026-41637: Degradation of resolution service from improperly accounted client-terminated DNS-over-QUIC queries
CVE-2026-13321: DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field
CVE-2026-54111: Universal Print Management Service Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-12547: Libsoup: information disclosure in libsoup via soupauthmanager proxy credential leak on proxy switch
CVE-2026-54995: Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.
CVE-2026-55008: Microsoft Exchange Server Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.