● Live advisory feed
Security Advisory Fusion for CSIRTs, SOCs & Defenders
Security advisories from 24 sources — CISA, CERT-EU, NCSC-UK, BSI, CERT-FR, NCSC-NL, JPCERT/CC, JVN, HKCERT, the Canadian Cyber Centre, NVD, GitHub, Microsoft, Cisco, Fortinet, Palo Alto Networks and more — normalized, translated to English and flagged against the CISA KEV catalog. One global feed for CSIRTs, SOCs and defenders.
Summary
swagger-typescript-api interpolates OpenAPI path strings (the keys of the paths object, e.g. /users/{id}) directly into a JavaScript template literal inside the body of every generated API method, without escaping. A spec path containing ${ … } survives parseRouteName's …
Serial Number: AV26-756 Date: July 29, 2026 As of July 28, 2026, Adobe is affected by vulnerabilities in the following products: Adobe Bridge Prior to 15.1.7 Prior to 16.0.6 Format Plugins Prior to 2026.07 The Cyber Centre encourages users and administrators to review the provide…
Summary
swagger-typescript-api interpolates components.schemas.*.enum[i] string values into the body of generated TypeScript enum declarations without escaping. A malicious enum value can close the enclosing string literal, terminate the enum body, and inject a bare-block IIFE t…
Summary
swagger-typescript-api interpolates servers[0].url directly into a TypeScript string literal inside the HttpClient constructor body of the generated axios client (templates/base/http-clients/axios-http-client.ejs:71), without any escaping. A malicious URL containing a " …
Summary
swagger-typescript-api walks every $ref value in the input OpenAPI spec and, for any $ref whose target is an http(s):// URL, issues an HTTP GET to that URL during generation (warmUpRemoteSchemasCache). The only URL filter is a regex that matches ^https?:// — there is no …
Summary
swagger-typescript-api interpolates servers[0].url directly into a TypeScript class-body field initializer of the generated fetch HttpClient (templates/base/http-clients/fetch-http-client.ejs:75), without any escaping. A malicious URL containing a " closes the string lit…
Summary
When the developer supplies an --authorizationToken (commonly required to fetch a private spec behind authentication), swagger-typescript-api attaches that token to the Authorization header of every subsequent HTTP request it makes while resolving external $ref URLs in t…
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - Arm Firmware Framework for ARMv8-A(FFA); (CVE-2026-53354, CVE-2026-64520)
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - Arm Firmware Framework for ARMv8-A(FFA); (CVE-2026-53354, CVE-2026-64520)
VMware has fixed vulnerabilities in VMware vCenter and VMware ESX products. VMware vCenter contains a critical authentication-bypass vulnerability in the Directory Service identified by CVE-2026-59309. This vulnerability allows an attacker with network access to VMware vCenter to…
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-20316 Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability This type of vulnerability is a frequent attack ve…
Progress is being made, but too many network devices still remain difficult to investigate after compromise
CISA, the National Security Agency, the Federal Bureau of Investigation, and international partners released joint guidance, 2026 Minimum Elements for a Software Bill of Materials (SBOM) , that updates and replaces the minimum elements for an SBOM published by the National Teleco…
A remote, authenticated attacker can exploit multiple vulnerabilities in Keycloak to bypass security measures and manipulate data.
A remote, anonymous attacker can exploit a vulnerability in Apache Tomcat to conduct a Denial of Service attack.
A remote, anonymous attacker can exploit multiple vulnerabilities in Hashicorp Terraform MCP Server to bypass security measures, disclose confidential information, and manipulate data.
A local attacker can exploit multiple vulnerabilities in Linux Kernel to conduct a Denial of Service attack.
A remote, anonymous, or authenticated attacker can exploit multiple vulnerabilities in Checkmk to bypass security measures.
An attacker can exploit multiple vulnerabilities in BlackBerry UEM Management Console to conduct a Cross-Site Scripting attack, conduct a Denial of Service attack, and disclose information.
An attacker can exploit multiple vulnerabilities in Adobe Creative Cloud (Bridge and Format Plugins) to execute arbitrary code and escalate privileges.
An attacker can exploit multiple vulnerabilities in OX Dovecot Pro to perform SQL injection attacks, bypass security measures, manipulate or disclose data, or cause a denial-of-service condition.
A local attacker can exploit a vulnerability in libTIFF to execute arbitrary program code and to conduct a Denial of Service attack.
A local attacker can exploit multiple vulnerabilities in the Linux Kernel to conduct a Denial of Service attack.
An attacker from an adjacent network can exploit multiple vulnerabilities in Broadcom Brocade SANnav to disclose information, perform SQL injection, and manipulate data.
A remote, anonymous attacker can exploit multiple vulnerabilities in WebKitGTK to disclose information, cause a denial of service, manipulate data, and bypass security precautions.
An attacker from an adjacent network can exploit a vulnerability in CODESYS to conduct a Denial of Service attack.
A remote, anonymous attacker can exploit a vulnerability in Apache Airflow FAB provider to bypass security measures and obtain administrator rights.
A remote, anonymous attacker can exploit a vulnerability in Microsoft Edge to disclose and alter confidential information.
An attacker can exploit a vulnerability in the Linux Kernel to carry out a Denial of Service attack.
A remote, anonymous attacker can exploit multiple vulnerabilities in Google Chrome to execute code and bypass security mechanisms.
A remote, anonymous attacker can exploit multiple vulnerabilities in Google Chrome to execute arbitrary code, cause a denial of service, or bypass security measures.
A remote, anonymous attacker can exploit a vulnerability in Golang Go to bypass security measures.
An attacker can exploit a vulnerability in Python to manipulate HTTP requests.
A remote, anonymous attacker can exploit a vulnerability in GStreamer to disclose information.
A remote, authenticated attacker can exploit a vulnerability in Tanium Endpoint Management to conduct a SQL injection attack.
A remote, anonymous attacker can exploit a vulnerability in Gitea to execute arbitrary code.
A remote, anonymous attacker can exploit a vulnerability in MailPit to disclose information.
An attacker can exploit multiple vulnerabilities in Red Hat OpenShift for Windows Containers to gain administrative rights and disclose confidential information.
An attacker can exploit multiple vulnerabilities in Apache ActiveMQ to perform a denial of service attack, bypass security measures, and manipulate data.
A remote, anonymous attacker can exploit multiple vulnerabilities in Red Hat Enterprise Linux to conduct a Denial of Service attack and potentially bypass authentication.
An attacker can exploit multiple vulnerabilities in Google Chrome to conduct an unspecified attack.
An attacker can exploit multiple vulnerabilities in FreeRDP to execute arbitrary code, bypass security measures, disclose confidential information, manipulate data, or trigger a Denial-of-Service condition.
A local attacker can exploit a vulnerability in Samba to carry out a Denial of Service attack.
A remote, anonymous attacker can exploit multiple vulnerabilities in Perl to carry out a denial of service attack or disclose confidential information.
A remote, anonymous attacker can exploit a vulnerability in FreeRDP to execute arbitrary program code.
A remote, anonymous attacker can exploit a vulnerability in FreeRDP to execute arbitrary program code and to conduct a denial of service attack.
A remote, anonymous attacker can exploit multiple vulnerabilities in wget to conduct a denial of service attack.
An attacker can exploit multiple vulnerabilities in FreeRDP to execute arbitrary code, conduct a denial of service attack, and disclose information.
An attacker from an adjacent network can exploit a vulnerability in hostapd to conduct a denial of service attack.
A local attacker can exploit a vulnerability in the Linux Kernel to gain administrator rights.