A daily updated summary of security advisories from authoritative sources worldwide. Stay ahead of emerging threats with aggregated intelligence from government CERTs and security research organizations.
Our security experts can help you assess, prioritize, and remediate vulnerabilities before they become incidents. Get proactive protection for your organization.
Showing 110 advisories
A vulnerability labeled as problematic has been found in YesWiki up to 4.6.5. Impacted is the function raw of the component Bazar. Such manipulation of the argument field.label/field.hint leads to cross site scripting. This vulnerability is documented as CVE-2026-52772. The attack can be executed re
A vulnerability identified as critical has been detected in YesWiki up to 4.6.5. This issue affects the function ApiController::deletePage of the component ApiController. This manipulation of the argument day causes sql injection. This vulnerability is registered as CVE-2026-52771. Remote exploitati
A vulnerability categorized as critical has been discovered in YesWiki up to 4.6.5. This vulnerability affects unknown code of the file /?BazaR of the component Bazar. The manipulation results in sql injection. This vulnerability is cataloged as CVE-2026-52770. The attack may be launched remotely. T
A vulnerability was found in YesWiki up to 4.6.5. It has been rated as problematic. This affects an unknown part of the file actions/EraseSpamedCommentsAction.php. The manipulation of the argument suppr leads to improper authorization. This vulnerability is listed as CVE-2026-52766. The attack may b
A vulnerability was found in YesWiki up to 4.6.5. It has been declared as critical. Affected by this issue is the function PageManager::getRecentlyChanged of the file actions/recentchanges.php of the component recentchanges. Executing a manipulation of the argument period can lead to sql injection.
A vulnerability was found in YesWiki up to 4.6.5. It has been classified as critical. Affected by this vulnerability is the function unserialize of the component BazarImportAction. Performing a manipulation results in deserialization. This vulnerability is identified as CVE-2026-52777. The attack ca
A vulnerability was found in YesWiki up to 4.6.5 and classified as critical. Affected is the function ReactionManager::deleteUserReaction of the component SQL LIKE Clause. Such manipulation of the argument idreaction/id leads to sql injection. This vulnerability is referenced as CVE-2026-52775. It i
A vulnerability has been found in YesWiki up to 4.6.5 and classified as problematic. This impacts the function strip_tags of the file /HomePage/widget of the component Bazar Widget Handler. This manipulation of the argument ID causes cross site scripting. The identification of this vulnerability is
A vulnerability, which was classified as problematic, was found in YesWiki up to 4.6.5. This affects an unknown function of the file handlers/page/show.php of the component Archived Revision View. The manipulation of the argument Time results in cross site scripting. This vulnerability was named CVE
A vulnerability, which was classified as problematic, has been found in YesWiki up to 4.6.5. The impacted element is an unknown function of the component Semantic Template Feature. The manipulation of the argument bn_sem_template leads to improper neutralization of special elements used in a templat
A vulnerability classified as critical was found in YesWiki up to 4.6.5. The affected element is the function HttpSignatureService::verifySignature of the component Signature Verification. Executing a manipulation can lead to unchecked return value. This vulnerability is handled as CVE-2026-52767. T
A vulnerability classified as problematic has been found in YesWiki up to 4.6.5. Impacted is the function HttpSignatureService::verifySignature of the file /api/forms/{formId}/actor/inbox of the component HttpSignatureService. Performing a manipulation of the argument keyId results in server-side re
A vulnerability described as critical has been identified in PX4 Autopilot up to 1.17.0. This issue affects the function TemperatureCalibration::start of the component TemperatureCalibration. Such manipulation leads to use after free. This vulnerability is traded as CVE-2026-86096. The attack may be
A vulnerability marked as critical has been reported in owen2345 Camaleon CMS up to 2.9.1. This vulnerability affects unknown code of the component Upload from URL media feature. This manipulation causes server-side request forgery. This vulnerability appears as CVE-2026-86100. The attack may be ini
A vulnerability labeled as critical has been found in ntop nDPI up to 5.x. This affects the function ndpi_json_string_escape. The manipulation results in heap-based buffer overflow. This vulnerability is reported as CVE-2026-86098. The attack can be launched remotely. No exploit exists. The affected
A vulnerability identified as problematic has been detected in PX4 Autopilot up to 1.17.0. Affected by this issue is the function param_set_default_file/param_set_backup_file of the component Param. The manipulation leads to null pointer dereference. This vulnerability is documented as CVE-2026-8609
A vulnerability categorized as problematic has been discovered in Unidata NetCDF-C up to 4.10.1. Affected by this vulnerability is the function NC4_HDF5_inq_attname of the component HDF5 Attribute Handler. Executing a manipulation can lead to out-of-bounds write. This vulnerability is registered as
A vulnerability was found in Laravel up to 12.59.x/13.9.x. It has been rated as critical. Affected is an unknown function of the component Email Validation. Performing a manipulation results in crlf injection. This vulnerability is cataloged as CVE-2026-48019. It is possible to initiate the attack r
A vulnerability was found in twigphp Twig up to 3.26.x. It has been declared as critical. This impacts the function SecurityPolicy::checkMethodAllowed of the component SecurityPolicy. Such manipulation leads to improper privilege management. This vulnerability is listed as CVE-2026-46636. The attack
A vulnerability was found in ntop ntopng up to 6.7.260716. It has been classified as problematic. This affects an unknown function of the component Pools Bulk-Delete Endpoint. This manipulation causes improper privilege management. This vulnerability is tracked as CVE-2026-86091. The attack is possi
Number: AL26-019Date: September 4, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipien
Serial Number: AV26-883Date: September 4, 2026 As of September 3, 2026, Google is affected by vulnerabilities in the following product: Chrome Prior to 152.0.7977.82 Google is aware that an exploit for CVE-2026-85046 exists in the wild. Update 1 On September 4, 2026, Cybersecurity and Infrastructure
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-85046 Google Chromium V8 Type Confusion Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant
Serial Number: AV26-882Date: September 3, 2026 As of September 3, 2026, SUSE is affected by vulnerabilities in the following product: Rancher Prior to 2.15.1 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available
Serial Number: AV26-881Date: September 3, 2026 As of September 3, 2026, Siemens is affected by a vulnerability in the following products: Mendix SAML (Mendix 10 compatible) Prior to V4.2.3 Mendix SAML (Mendix 11 compatible) Prior to V4.2.3 Mendix SAML (Mendix 9.24 compatible) Prior to V3.6.27 The Cy
Serial Number: AV26-880Date: September 3, 2026 As of September 3, 2026, n8n is affected by vulnerabilities in the following product: n8n Prior to 1.123.76 Prior to 2.35.4 Prior to 2.36.2 Prior to 2.37.7 Prior to 2.38.2 The Cyber Centre encourages users and administrators to review the provided web l
Serial Number: AV26-879Date: September 3, 2026 As of September 2, 2026, AMD is affected by vulnerabilities in the following products: 2nd Gen AMD EPYC™ Processors all except RomePI 1.0.0.H 3rd Gen AMD EPYC™ Processors all except MilanPI 1.0.0.C 4th Gen AMD EPYC™ Processors all except GenoaPI 1.0.0.8
Serial Number: AV26-878Date: September 3, 2026 As of September 2, 2026, F5 is affected by vulnerabilities in the following products: BIG-IP (all modules) Prior to 17.1.3.4 Prior to 17.5.1.8 Prior to 21.0.0.3 Prior to 21.1.0.1 BIG-IQ Prior to 8.4.2.1 NGINX Gateway Fabric Prior to 2.6.8 NGINX Ingress
Serial Number: AV26-877Date: September 3, 2026 As of September 2, 2026, Jenkins Project is affected by vulnerabilities in the following products: Jenkins ALL except 2.568.3 ALL except 2.580 Jenkins Allure Plugin Prior to or equal to 2.35.2 Jenkins Customizable Header Plugin Prior to or equal to 295.
Serial Number: AV26-876Date: September 3, 2026 As of September 2, 2026, Cisco is affected by vulnerabilities in the following products: Cisco IOS XR Software Multiple versions Cisco Nexus 9000 Series Switches Multiple products Cisco Desk Phone 9800 Series and Video Phone 8875 Prior to 5.0(1) IP Phon
View CSAF Summary Successful exploitation of these vulnerabilities could allow for an attacker to perform a man-in-the-middle (MitM) attack, cause a factory reset, wipe credentials, or retrieve sensitive information. The following versions of Tycon Systems TPDIN-Monitor-WEB3 are affected: TPDIN-Moni
View CSAF Summary Successful exploitation of this vulnerability could result in memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed. The following versions of Pyramid Solutions
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to perform remote code execution on the computer running the client with elevated privileges. The following versions of IXON VPN Client are affected: VPN Client <1.4.7 (CVE-2026-75925) CVSS Vendor Equipment Vulne
CISA and the Group of Seven (G7) Cyber Security Working Group released Preparing for the Post-Quantum Era: A Call to Action highlighting the urgent need for organizations and governments to begin transitioning to post-quantum cryptography (PQC) to protect sensitive data, authentication systems, and
View CSAF Summary Successful exploitation of these vulnerabilities could result in a loss of webserver availability or allow an attacker to inject malicious scripts that will be executed when other users access the affected page. The following versions of Rockwell Automation ArmorStart LT are affect
View CSAF Summary Successful exploitation of this vulnerability could give an attacker the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level. The following versions of Rockwell Automation ControlFLASH are affected: ControlFLASH
View CSAF Summary Schneider Electric is aware of a vulnerability in the following products: The Easergy C5 is a scalable and interoperable bay controller, protection and merging unit for large and critical infrastructure electrical distribution systems. The Easergy MiCOM P30 is a family of multifunc
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to take control of a high-privilege terminal during installation and run arbitrary commands. The following versions of OPCFoundation OPC UA LocalDiscoveryServer (LDS) are affected: UA-LDS-Installers <1.04.420 (CV
View CSAF Summary Successful exploitation of this vulnerability could allow any authenticated user to create projects. The following versions of Inductive Automation Ignition are affected: Ignition <=8.1.53 (CVE-2026-77393) CVSS Vendor Equipment Vulnerabilities v3 8.8 Inductive Automation Inductive
View CSAF Summary Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk. The following versions of Tycon Systems TPDIN-Monitor-W
View CSAF Summary Successful exploitation of this vulnerability could crash the module. The device requires a restart to recover. The following versions of Rockwell Automation 1756-ENBT Module are affected: 1756-ENBT module vers:all/* (CVE-2025-10478) CVSS Vendor Equipment Vulnerabilities v3 7.5 Roc
Serial number: AV26-867Date: September 1, 2026Updated: September 2, 2026 As of August 28, 2026, JFrog is affected by a vulnerability in the following product: Artifactory Prior to 7.111.21 Prior to 7.117.28 Prior to 7.125.20 Prior to 7.133.29 Prior to 7.146.38 Prior to 7.161.20 Open-source reporting
Serial Number: AV26-872Date: September 2, 2026 As of September 1, 2026, SonicWall is affected by a vulnerability in the following product: SMA1000 - 6210, 7210, 8200v 12.4.3-03453 (platform-hotfix) and older versions 12.5.0-02835 (platform-hotfix) and older versions SonicWall indicates that CVE-2026
Serial number: AV26-875Date: September 2, 2026 As of September 2, 2026, Progress Software is affected by vulnerabilities in the following product: Telerik UI for ASP.NET AJAX Prior to 2026.3.812 The Cyber Centre encourages users and administrators to review the provided web links and apply any neces
Serial number: AV26-874Date: September 2, 2026 As of September 2, 2026, Google is affected by vulnerabilities in the following product: Chrome Prior to 152.0.7977.75 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become av
Serial number: AV26-873Date: September 2, 2026 As of September 1, 2026, Hewlett Packard Enterprise (HPE) is affected by vulnerabilities in the following products: HPE Networking AOS-CX Prior to or equal to 10.10.1180 Prior to or equal to 10.13.1180 Prior to or equal to 10.16.1051 Prior to or equal t
Serial Number: AV26-871Date: September 2, 2026 As of September 1, 2026, Schneider Electric is affected by vulnerabilities in the following products: NetBotz 5 - 750/755 Versions prior to or equal to 5.5.2 PowerChute Serial Shutdown Versions prior to or equal to 1.5 The Cyber Centre encourages users
Developed by CISA, the Federal Bureau of Investigation, and international partners, this guidance describes how organizations can plan and execute clear, timely, accurate, and audience-appropriate communications during IT and operational technology (OT) outages. Whether caused by cyber threat actors
CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-9586 Sangoma Switchvox SQL Injection Vulnerability CVE-2026-48710 Kludex Starlette HTTP Request/Response Smuggling Vulnerability CVE-2026-49869 Kestra OSS
Serial number: AV26-870Date: September 1, 2026 As of September 1, 2026, Erlang is affected by vulnerabilities in the following product: OTP - Multiple versions The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates. Erlang Security Adviso
Serial number: AV26-869Date: September 1, 2026 As of September 1, 2026, Rockwell Automation is affected by vulnerabilities in the following products: 1756-ENBT Module All versions ArmorStart LT Prior to or equal to v2.001 CompactLogix 5380 / ControlLogix 5580 Prior to or equal to V33 V34.011 to V34.
Serial number: AV26-868Date: September 1, 2026 As of September 1, 2026, Mozilla is affected by vulnerabilities in the following products: Firefox ESR Versions prior to 115.40 Versions prior to 140.15 Versions prior to 153.2 Firefox Versions prior to 155 The Cyber Centre encourages users and administ
Serial number: AV26-866Date: September 1, 2026 As of September 1, 2026, WebPros is affected by vulnerabilities in the following product: Plesk Prior to 18.0.79.9 Prior to 18.0.80.5 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as
View CSAF Summary Successful exploitation of these vulnerabilities could crash the device being accessed; an out-of-bounds write condition may allow remote code execution. The following versions of Rockwell Automation Historian ME are affected: Series B 5.202 (CVE-2025-12768, CVE-2026-12661) Series
View CSAF Summary The following versions of Rockwell Automation FactoryTalk Activation Manager are affected: FactoryTalk Activation Manager V5.02_and_below (CVE-2026-16675) CVSS Vendor Equipment Vulnerabilities v3 7.8 Rockwell Automation Rockwell Automation FactoryTalk Activation Manager Improper Re
View CSAF Summary The following versions of Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix are affected: ControlLogix 5580 <34.015, <35.014, <36.013, <37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260) GuardLogix 5580 <34.015, <
View CSAF Summary Successful exploitation of these vulnerabilities could allow for an attacker to escalate and execute processes with administrator privileges. The following versions of Rockwell Automation Redundancy Module Configuration Tool are affected: Redundancy Module Configuration Tool 10.00.
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the affected product. The following versions of Rockwell Automation RSLinx Classic are affected: RSLinx Classic <=4.50 (CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CV
View CSAF Summary The following versions of Rockwell Automation Logix Platform are affected: ControlLogix 5580 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637) CompactLogix 5380 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.
De multiples vulnérabilités ont été découvertes dans SPIP. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance et un problème de sécurité non spécifié par l'éditeur.
Une vulnérabilité a été découverte dans Mozilla Firefox pour iOS. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité.
Une vulnérabilité a été découverte dans Kaspersky Endpoint Security Windows. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité.
De multiples vulnérabilités ont été découvertes dans Mattermost Server. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.
De multiples vulnérabilités ont été découvertes dans JFrog Artifactory. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, une falsification de requêtes côté serveur (SSRF) et un contournement de la politique de sécurité.
Serial Number: AV26-865Date: August 31, 2026 As of August 27, 2026, WatchGuard is affected by vulnerabilities in the following products: Dimension Prior to 2.3.1 Fireware OS Prior to 12.12.2 Prior to 12.5.20 Prior to 2026.2.2 The Cyber Centre encourages users and administrators to review the provide
Ce bulletin d'actualité du CERT-FR revient sur les vulnérabilités significatives de la semaine passée pour souligner leurs criticités. Il ne remplace pas l'analyse de l'ensemble des avis et alertes publiés par le CERT-FR dans le cadre d'une analyse de risques pour prioriser l'application des...
De multiples vulnérabilités ont été découvertes dans les produits Tenable. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance et une élévation de privilèges.
De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.
De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité des données et un déni de service.
De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, une atteinte à l'intégrité des données et un contournement de la politique de sécurité.
De multiples vulnérabilités ont été découvertes dans Tenable Enclave Security. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.
De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, une élévation de privilèges et un déni de service à distance.
De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.
De multiples vulnérabilités ont été découvertes dans Papercut. Elles permettent à un attaquant de contourner l'authentification et d'exécuter du code arbitraire à distance. Papercut indique que ces vulnérabilités sont activement exploitées. L'éditeur explique que le correctif bloque les requêtes...
De multiples vulnérabilités ont été découvertes dans Traefik. Elles permettent à un attaquant de provoquer un déni de service à distance et un contournement de la politique de sécurité.
Une vulnérabilité a été découverte dans CPython. Elle permet à un attaquant de provoquer un déni de service à distance.
De multiples vulnérabilités ont été découvertes dans GitLab. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.
De multiples vulnérabilités ont été découvertes dans SonicWall NetExtender. Elles permettent à un attaquant de provoquer un contournement de la politique de sécurité.
De multiples vulnérabilités ont été découvertes dans Redmine. Elles permettent à un attaquant de provoquer une injection de code indirecte à distance (XSS) et un contournement de la politique de sécurité.
On 19 August 2026, Citrix published a security advisory addressing multiple critical vulnerabilities in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway). CERT-EU recommends updating affected devices as soon as possible.
[UPDATED] On 14 July 2026, Microsoft released security updates addressing critical remote code execution (RCE) vulnerabilities in Microsoft SharePoint Server. On 20 July 2026, WatchTowr identified a proof-of-concept exploit code and subsequently observed active exploitation of CVE-2026-50522, a vuln
On 9 June 2026, Ivanti released a security advisory addressing two critical vulnerabilities in their Sentry products[1]. An attacker could exploit those flaws to achieve unauthenticated remote code execution on the vulnerable device.
On 12 May 2026, Microsoft published a security advisory addressing a critical vulnerability affecting Windows Server when acting as a domain controller. This vulnerability allows an unauthenticated attacker to execute arbitrary code over a network. According to The Centre for Cybersecurity Belgium (
On 6 May 2026, Palo Alto published a security advisory addressing a critical vulnerability affecting PAN-OS. This vulnerability allows an unauthenticated attacker to execute arbitrary code with root privileges. Palo Alto observed limited exploitation of this vulnerability. It is strongly recommended
On 29 April 2026, a high local privilege escalation vulnerability in the Linux kernel, tracked as CVE-2026-31431 and named "Copy Fail", was publicly disclosed. The vulnerability affects every mainstream Linux distributions shipping a kernel built since 2017. A public proof-of-concept exploit has bee
On 17 March 2026, Microsoft updated one of its January 2026 security advisories related to a remote code execution vulnerability in Microsoft SharePoint. Specifically, Microsoft raised the CVSS score and changed the FAQ section to indicate that the vulnerability could be exploited by an unauthentica
On 23 March 2026, Citrix published a security advisory addressing multiple vulnerabilities affecting NetScaler ADC and NetScaler Gateway. These vulnerabilities may lead to sensitive information disclosure and user session mix-up under specific configurations. At the time of writing, there is no publ
On 25 February 2026, Cisco released security advisories addressing multiple high and critical severity vulnerabilities in Cisco Catalyst SD-WAN controllers and Cisco SD-WAN Manager. If exploited, these vulnerabilities could allow attackers to gain administrative access to compromised systems. It is
On 29 January 2026, Ivanti released a security advisory addressing two critical vulnerabilities in their EPMM products. An attacker could exploit those flaws to achieve unauthenticated remote code execution on the vulnerable device. One of these vulnerabilities have been exploited in a limited numbe