Serial Number: AV26-845 Date: August 25, 2026 As of August 14, 2026, Gitea is affected by vulnerabilities in the following product: Gitea Prior to 1.27.1 On August 25, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-60004 to their Known Exploited Vuln…
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-60004 Gitea Code Injection Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses sign…
An attacker can exploit multiple vulnerabilities in the Linux Kernel to escalate their privileges, cause a denial of service condition, or achieve other unspecified effects.
A local attacker can exploit multiple vulnerabilities in Linux Kernel to conduct a Denial of Service attack and achieve unspecified effects.
A remote, anonymous or authenticated attacker can exploit multiple vulnerabilities in Oracle Fusion Middleware to compromise confidentiality, integrity and availability.
Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account.
Serial number: AV26-042 Date: January 21, 2026 Updated: August 24, 2026 On January 20, 2026, Oracle published a security advisory to address vulnerabilities in multiple products. Update 1 On January 21, 2026, a proof of concept (PoC) for the vulnerability CVE-2026-21962 became pu…
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-21962 Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability This type of vulnerability is a f…
Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle…
Multiple vulnerabilities have been discovered in Metabase. They allow an attacker to cause a breach of data confidentiality, SQL injection (SQLi) and a security issue not specified by the publisher.
Zimbra has fixed a vulnerability in Zimbra Collaboration Suite. The vulnerability is located in Zimbra Collaboration Suite, version prior to 10.1.20. Unauthenticated attackers can execute OS commands via specially crafted SMTP requests. This requires that the zimbra-snmp package …
Serial number: AV26-816 Date: August 14, 2026 Updated: August 21, 2026 As of August 13, 2026, Zimbra is affected by vulnerabilities in the following product: Collaboration - Prior to 10.1.20 The Cyber Centre encourages users and administrators to review the provided web links and…
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-73570 Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability This type of vulnerability is a frequent attack vector for mali…
Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
Multiple vulnerabilities have been discovered in IBM products. Some of them allow an attacker to cause remote arbitrary code execution, privilege escalation and remote denial of service.
Bulletin ID: 2026-026-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/05/06 17:30 PM PDT Description: Amazon is aware of an issue in the Linux kernel (CVE-2026-31431) that could potentially allow an authenticated local user to escalate privilege…
Bulletin ID: 2026-027-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/05/07 19:45 PM PDT Description: Amazon is aware of a class of issues in the Linux kernel related to the original issue (CVE-2026-31431). The issues commonly referred to as "Di…
Bulletin ID: 2026-030-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 05/13/2026 10:00 PM PDT This is an ongoing issue. This bulletin will be updated as more information becomes available. Description: AWS is aware of the copy.fail or DirtyFrag class…
Serial Number: AV26-835 Date: August 20, 2026 As of August 19, 2026, TrueConf is affected by a vulnerability in the following product: TrueConf Server 5.3.x versions prior to 5.3.9 5.4.x versions prior to 5.4.9 5.5.x versions prior to 5.5.5 On August 20, 2026, Cybersecurity and I…
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-72529 TrueConf Server Missing Authentication for Critical Function Vulnerability CVE-2026-72530 TrueConf Server Code Injection Vulnerab…
A remote, anonymous attacker can exploit a vulnerability in MLflow to bypass security measures and disclose or manipulate data.
A remote anonymous attacker can exploit multiple vulnerabilities in Apache HTTP Server to execute arbitrary code, cause a denial-of-service condition, bypass security measures, or disclose confidential information.
TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with network access via port 4307/TCP to execute an arbitrary script.
TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.
Serial Number: AV26-832 Date: August 19, 2026 As of August 17, 2026, MLflow is affected by vulnerabilities in the following product: MLflow Prior to 3.15.0 On August 19, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-64849 to their Known Exploited Vu…
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host sy…
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-64849 MLflow Server-Side Request Forgery Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors …
An attacker can exploit multiple vulnerabilities in Atlassian Bamboo, Atlassian Bitbucket, Atlassian Confluence, Atlassian Crucible, Atlassian Fisheye and Atlassian Jira to execute arbitrary code, conduct a denial of service attack, disclose information, manipulate files, conduct…
MLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or cloud metadata services and receive response_status and response_body.
Multiple vulnerabilities have been discovered in Oracle Weblogic. They allow an attacker to cause remote denial of service, data confidentiality breach and data integrity breach.
Multiple vulnerabilities have been discovered in Synacor Zimbra Collaboration. Some of them allow an attacker to cause remote arbitrary code execution, server-side request forgery (SSRF) and remote indirect code injection (XSS).
Serial number: AV26-823 Date: August 17, 2026 Updated: August 18, 2026 As of August 6, 2026, Apple is affected by vulnerabilities in the following products: macOS Tahoe Prior to 26.6.1 macOS Sequoia Prior to 15.7.9 macOS Sonoma Prior to 14.8.9 Open-source reporting indicates that…
Serial number: AV26-763 Date: July 30, 2026 Updated: August 18, 2026 As of July 30, 2026, VMware is affected by vulnerabilities in the following products: Cloud Foundation 5.x 9.0.x.x 9.1.x.x Prior to 5.2.3 ESX Prior to ESXi-9.0.2.0100-25595025 Prior to ESXi-9.1.0.0-25370933 Prio…
Serial Number: AV26-804 Date: August 11, 2026 Updated: August 18, 2026 As of August 11, 2026, Microsoft is affected by vulnerabilities in the following products: .NET 10.0 installed on Linux .NET 10.0 installed on Mac OS .NET 10.0 installed on Windows .NET 8.0 installed on Linux …
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-33824 Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability CVE-2026-55040 Microsoft SharePoint Weak Auth…
Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.
Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.
Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.
Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the original…
Summary
The default MLflow Tracking Server (mlflow server, no authentication, default SQLite backend) exposes the model-registry webhooks API unauthenticated, including a synchronous POST /api/2.0/mlflow/webhooks/{id}/test endpoint that returns the upstream response status and bo…
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2025-62593 Ray-Project Ray Code Injection Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and …
Ray-Project Ray contains a code injection vulnerability that could allow remote code execution. Developers using Ray as a development tool may be exposed to this vulnerability exploitable through Firefox and Safari.
A remote, anonymous attacker can exploit a vulnerability in various http/2 implementations to carry out a denial of service attack.
Multiple vulnerabilities have been discovered in IBM products. Some of them allow an attacker to cause remote arbitrary code execution, privilege escalation, and remote denial of service.
Multiple vulnerabilities have been discovered in SUSE Linux kernel. Some of them allow an attacker to cause privilege escalation, remote denial of service and data confidentiality breach.
Number: AL26-018 Date: August 13, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation…