A daily updated summary of security advisories from authoritative sources worldwide. Stay ahead of emerging threats with aggregated intelligence from government CERTs and security research organizations.
Our security experts can help you assess, prioritize, and remediate vulnerabilities before they become incidents. Get proactive protection for your organization.
Showing 110 advisories
A vulnerability categorized as problematic has been discovered in GitLab EE up to 19.1.7/19.2.5/19.3.1. This affects an unknown function of the component GraphQL Subscription. The manipulation of the argument subscription results in information disclosure. This vulnerability is identified as CVE-202
A vulnerability was found in GitLab up to 19.1.7/19.2.5/19.3.1. It has been rated as problematic. The impacted element is an unknown function of the component Repository Commits API. The manipulation leads to missing authentication. This vulnerability is referenced as CVE-2026-85706. Remote exploita
A vulnerability was found in cole aiosmtplib up to 5.1.2. It has been declared as problematic. The affected element is an unknown function. Executing a manipulation can lead to injection. The identification of this vulnerability is CVE-2026-90467. The attack may be launched remotely. There is no exp
A vulnerability was found in Webkul QloApps up to 1.7.0. It has been classified as problematic. Impacted is an unknown function of the component List Helper Template. Performing a manipulation results in cross site scripting. This vulnerability was named CVE-2026-89268. The attack may be initiated r
A vulnerability was found in jowilf starlette-admin up to 0.17.1 and classified as problematic. This issue affects some unknown processing of the file starlette_admin/views.py of the component Searchable Fields. Such manipulation of the argument where leads to improper privilege management. This vul
A vulnerability has been found in Shopper and classified as problematic. This vulnerability affects the function Action::make of the file packages/admin/src/Livewire/Components/Collection/CollectionProducts.php of the component CollectionProducts. This manipulation of the argument collection causes
A vulnerability, which was classified as critical, was found in FrontMCP 1.2.1. This affects the function OpenAPIToolGenerator.fromURL of the file libs/adapters/src/openapi/openapi.adapter.ts of the component OpenAPI Adapter. The manipulation of the argument url results in server-side request forger
A vulnerability, which was classified as problematic, has been found in Shopper. Affected by this issue is the function ZoneShippingOptions::deleteAction of the file packages/admin/src/Livewire/Components/Settings/Zones/ZoneShippingOptions.php of the component Settings. The manipulation of the argum
A vulnerability classified as critical was found in yayson up to 4.2.0. Affected by this vulnerability is the function Store.sync of the component Deserialization Logic. Executing a manipulation of the argument Type can lead to improperly controlled modification of object prototype attributes. This
A vulnerability classified as problematic has been found in Shopper Framework 2.8.1. Affected is an unknown function of the file vendor/shopper/cart/src/Discounts/DiscountCalculator.php of the component Discount Calculation. Performing a manipulation of the argument Value results in improper input v
A vulnerability described as problematic has been identified in Shopper. This impacts the function store of the file packages/admin/src/Livewire/Components/Products/Form/Media.php of the component Media. Such manipulation leads to improper authorization. This vulnerability is documented as CVE-2026-
A vulnerability marked as critical has been reported in shopperlabs Shopper up to 2.8.0. This affects the function togglePermission of the file packages/admin/src/Livewire/Components/Settings/Team/Permissions.php of the component Permissions. This manipulation of the argument ID causes improper auth
A vulnerability labeled as problematic has been found in Shopper. The impacted element is the function stockAction of the file packages/admin/src/Livewire/Components/Products/VariantStock.php of the component VariantStock. The manipulation of the argument variant results in improper privilege manage
A vulnerability identified as critical has been detected in MySQL MCP Server up to 0.4.1. The affected element is the function cursor.execute of the file src/mysql_mcp_server/server.py of the component SSE Transport. The manipulation of the argument Query leads to reliance on reverse dns resolution.
A vulnerability categorized as problematic has been discovered in therawdev Shopper. Impacted is the function DeleteBulkAction::make/BulkAction::make of the file packages/admin/src/Livewire/Pages/Attribute/Browse.php of the component groupedBulkActions. Executing a manipulation can lead to improper
A vulnerability was found in Linux Kernel up to 7.2.3. It has been rated as critical. This issue affects the function nfsd4_cancel_copy_by_sb of the file /proc/fs/nfsd/unlock_filesystem of the component NFSD. Performing a manipulation results in use after free. This vulnerability is identified as CV
A vulnerability was found in Linux Kernel up to 6.18.50/7.2.3. It has been declared as problematic. This vulnerability affects the function cifs_setattr_unix/cifs_setattr_nounix of the file cifs.ko of the component CIFS Client. Such manipulation of the argument ia_valid leads to improper privilege m
A vulnerability was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. It has been classified as very critical. This affects the function hid_sensor_custom_add_attributes of the component Sysfs Group Cleanup. This manipulation causes use after free. The identification of this vulnerability is CVE-2
A vulnerability was found in Linux Kernel up to 6.18.49/7.2.3 and classified as very critical. Affected by this issue is the function nfsd_open_local_fh of the file filecache.c of the component nfsd. The manipulation results in use after free. This vulnerability was named CVE-2026-89670. The attack
A vulnerability has been found in Linux Kernel up to 6.12.108/6.18.49/7.2.3 and classified as problematic. Affected by this vulnerability is the function __build_xattrs of the component Ceph. The manipulation of the argument val_len leads to out-of-bounds read. This vulnerability is uniquely identif
Serial Number: AV26-917Date: September 11, 2026 As of September 10, 2026, GitLab is affected by vulnerabilities in the following product: GitLab Prior to 19.1.8 Prior to 19.2.6 Prior to 19.3.2 On September 11, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-85706 to thei
Serial number: AV26-867Date: September 1, 2026Updated: September 11, 2026 As of August 28, 2026, JFrog is affected by a vulnerability in the following product: Artifactory Prior to 7.111.21 Prior to 7.117.28 Prior to 7.125.20 Prior to 7.133.29 Prior to 7.146.38 Prior to 7.161.20 Open-source reportin
Serial Number: AV26-916Date: September 11, 2026 As of September 8, 2026, n8n is affected by a vulnerability in the following product: n8n Prior to 2.37.7 Prior to 2.38.2 Prior to 1.123.76 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary up
Serial number: AV26-903Date: September 9, 2026Updated: September 11, 2026 As of September 8, 2026, ConnectWise is affected by a vulnerability in the following product: ScreenConnect versions prior to 26.6.5 Open-source reporting indicates that CVE-2026-84869 is being exploited in the wild. Update 1
Serial Number: AV26-915Date: September 11, 2026 As of September 11, 2026, Progress Software is affected by a vulnerability in the following product: Chef Automate Prior to 4.13.520 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates a
Serial number: AV26-914Date: September 11, 2026 As of September 10, 2026, National Instruments is affected by vulnerabilities in the following products: SystemLink Prior to or equal to 2026 Q3 Patch 1 SystemLink Server Prior to or equal to 2026 Q3 Patch 1 The Cyber Centre encourages users and admini
Serial number: AV26-913Date: Septembre 11, 2026 As of September 10, 2026, GeoVision is affected by vulnerabilities in the following product:: GV-LPC2011/LPC2211 Firmware version 1.13 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates
Serial number: AV26-912Date: September 11, 2026 As of September 9, 2026, Schneider Electric is affected by vulnerabilities in the following products: EcoStruxure™ IT Data Center Expert (Formerly known as StruxureWare Data Center Expert) Versions 9.1.2 and prior PowerLogic T300 Versions 2.9.8-5620 an
Serial Number: AV26-911Date: September 11, 2026 As of September 10, 2026, MongoDB is affected by vulnerabilities in the following products: Java Driver Prior to 5.11.1 Laravel MongoDB (PHP) Prior to 5.11.0 The Cyber Centre encourages users and administrators to review the provided web links and appl
Serial Number: AV26-910Date: September 11, 2026 As of September 10, 2026, HashiCorp is affected by vulnerabilities in the following products: Consul Prior to 2.0.4 Consul Enterprise 1.0 Prior to 1.21.18 21.0 Prior to 1.21.18 9.0 Prior to 1.21.18 consul-template Prior to 0.43.0 The Cyber Centre encou
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-42016 JFrog Artifactory Incorrect Authorization Vulnerability CVE-2026-42018 JFrog Artifactory Improper Authentication Vulnerability CVE-2026-84869 Connec
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-85706 GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber
Serial Number: AV26-887Date: September 8, 2026Updated: September 10, 2026 As of September 3, 2026, Mikrotik is affected by vulnerabilities in the following product: RouterOS Prior to 6.49.21 Prior to 7.23.4 Prior to 7.24.2 Prior to 7.25 beta 3 Open-source reporting indicates that CVE-2026-67276, CVE
Number: AL26-020Date: September 10, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipie
Serial number: AV26-909Date: September 10, 2026 As of September 9, 2026, Hewlett Packard Enterprise (HPE) is affected by vulnerabilities in the following products: ClearPass Policy Manager (CPPM) Prior to or equal to 6.11.14 Prior to or equal to 6.12.8 HPE IceWall products Multiple versions and mode
Serial number: AV26-908Date: September 10, 2026 As of September 10, 2026, WebPros is affected by vulnerabilities in the following products: cPanel & WebHost Manager (WHM) software Prior to 11.110.0.143 Prior to 11.134.0.55 Prior to 11.136.0.39 Prior to 11.138.0.4 Prior to WP2: 11.138.1.9 ConfigServe
Serial number: AV26-808Date: August 12, 2026Updated: September 10, 2026 As of August 11, 2026, Adobe is affected by vulnerabilities in the following products: Adobe Campaign Classic Prior to or equal to ACC v7: 7.4.3 build 9399 Adobe Commerce Prior to or equal to 2.4.9-2026-jul, 2.4.8-2026-aug, 2.4.
Serial number: AV26-907Date: September 10, 2026 As of September 10, 2026, Advantech is affected by vulnerabilities in the following product: Advantech WISE-6610 industrial gateway Multiple versions and models The Cyber Centre encourages users and administrators to review the provided web links and a
Serial number: AV26-906Date: September 10, 2026 As of September 9, 2026, Fortra is affected by a vulnerability in the following product: GoAnywhere MFT Endpoint Prior to 7.10.2 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as th
Serial number: AV26-905Date: September 10, 2026 As of September 10, 2026, Palo Alto Networks is affected by vulnerabilities in the following products: Cloud NGFW All on AWS*, All on Azure* PAN-OS Multiple versions Prisma Access Multiple versions Prisma Browser Prior to 151.26.5.170 The Cyber Centre
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-67277 MikroTik RouterOS Missing Authentication for Critical Function Vulnerability CVE-2026-86060 MikroTik RouterOS Improper Neutralization of Argument Deli
View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated remote attacker to write past the end of a heap allocation when Orthanc decodes an attacker-supplied PNG or JPEG image, resulting in a crash of the Orthanc process and a denial-of-service condition. The foll
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to disclose information, brute-force hashes, or run arbitrary code in a browser session. The following versions of AVEVA Pipeline Integrity Monitor are affected: AVEVA Pipeline Integrity Monitor <=2025_SP1_P1_
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to device information or cause a denial-of-service condition. The following versions of ST Engineering iDirect iQ-Series Terminals (Update A) are affected: Evolution iQ‑Series termi
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to exfiltrate date or cause a denial-of-service condition. The following versions of NextGen Healthcare Mirth Connect are affected: Mirth Connect <=v4.7.1 (CVE-2026-82583, CVE-2026-78224, CVE-2026-82578) CVSS
Number: AL26-019Date: September 4, 2026Updated: September 9, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mit
Serial Number: AV26-833Date: August 19, 2026Updated: September 9, 2026 As of August 19, 2026, Citrix is affected by vulnerabilities in the following products: NetScaler ADC and NetScaler Version 13.1 prior to 13.1-63.21 Version 14.1 prior to 14.1-73.32 NetScaler ADC FIPS Prior to 14.1-73.32 FIPS Net
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-25249 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability CVE-2026-19490 Citrix NetScaler Authentication Bypass Using an Alternate Path or
De multiples vulnérabilités ont été découvertes dans Google Chrome. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur. Google indique que la vulnérabilité CVE-2026-87491 est activement exploitée.
Une vulnérabilité a été découverte dans Microsoft Edge. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance.
De multiples vulnérabilités ont été découvertes dans Xen. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, un déni de service à distance et un contournement de la politique de sécurité.
De multiples vulnérabilités ont été découvertes dans Citrix Workspace app. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.
De multiples vulnérabilités ont été découvertes dans les produits Adobe. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
Une vulnérabilité a été découverte dans les produits Cisco. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité.
De multiples vulnérabilités ont été découvertes dans Microsoft Office. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une atteinte à la confidentialité des données et un contournement de la politique de sécurité.
De multiples vulnérabilités ont été découvertes dans Microsoft Windows. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance. Microsoft indique que les vulnérabilités CVE-2026-81963...
Une vulnérabilité a été découverte dans les produits ESET. Elle permet à un attaquant de provoquer une élévation de privilèges.
De multiples vulnérabilités ont été découvertes dans Postfix. Elles permettent à un attaquant de provoquer un déni de service à distance et un contournement de la politique de sécurité.
De multiples vulnérabilités ont été découvertes dans Microsoft Azure. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et une atteinte à la confidentialité des données.
De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
De multiples vulnérabilités ont été découvertes dans Microsoft .Net. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
Executive summary China-based artificial intelligence (AI) companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns that form the core—not merely a supplement—of their AI deve
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to take full control of the device. The following versions of CareCam Pro IP Cameras are affected: ANJIA AJL33PC0801 Firmware linux_linux_202008261138_svn13796_/_Bootloader_U-Boot_2010.06_compiled_2020-08-26 (CVE
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability CVE-2026-81963 Microsoft Windows Link
Une vulnérabilité a été découverte dans les produits Adobe. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance. Adobe indique que la vulnérabilité CVE-2026-75650 est activement exploitée.
De multiples vulnérabilités ont été découvertes dans les produits Siemens. Elles permettent à un attaquant de provoquer une exécution de code arbitraire et une élévation de privilèges.
De multiples vulnérabilités ont été découvertes dans strongSwan. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et un contournement de la politique de sécurité.
De multiples vulnérabilités ont été découvertes dans Schneider Electric EcoStruxure. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance et une falsification de requêtes côté serveur (SSRF).
De multiples vulnérabilités ont été découvertes dans les produits SAP. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
De multiples vulnérabilités ont été découvertes dans Typo3. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données et un contournement de la politique de sécurité.
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-85046 Google Chromium V8 Type Confusion Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to perform remote code execution on the computer running the client with elevated privileges. The following versions of IXON VPN Client are affected: VPN Client <1.4.7 (CVE-2026-75925) CVSS Vendor Equipment Vulne
View CSAF Summary Successful exploitation of this vulnerability could allow any authenticated user to create projects. The following versions of Inductive Automation Ignition are affected: Ignition <=8.1.53 (CVE-2026-77393) CVSS Vendor Equipment Vulnerabilities v3 8.8 Inductive Automation Inductive
View CSAF Summary Successful exploitation of these vulnerabilities could result in a loss of webserver availability or allow an attacker to inject malicious scripts that will be executed when other users access the affected page. The following versions of Rockwell Automation ArmorStart LT are affect
View CSAF Summary Schneider Electric is aware of a vulnerability in the following products: The Easergy C5 is a scalable and interoperable bay controller, protection and merging unit for large and critical infrastructure electrical distribution systems. The Easergy MiCOM P30 is a family of multifunc
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to take control of a high-privilege terminal during installation and run arbitrary commands. The following versions of OPCFoundation OPC UA LocalDiscoveryServer (LDS) are affected: UA-LDS-Installers <1.04.420 (CV
View CSAF Summary Successful exploitation of this vulnerability could give an attacker the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level. The following versions of Rockwell Automation ControlFLASH are affected: ControlFLASH
View CSAF Summary Successful exploitation of this vulnerability could crash the module. The device requires a restart to recover. The following versions of Rockwell Automation 1756-ENBT Module are affected: 1756-ENBT module vers:all/* (CVE-2025-10478) CVSS Vendor Equipment Vulnerabilities v3 7.5 Roc
View CSAF Summary Successful exploitation of this vulnerability could result in memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed. The following versions of Pyramid Solutions
De multiples vulnérabilités ont été découvertes dans Roundcube. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une atteinte à la confidentialité des données et une falsification de requêtes côté serveur (SSRF).
On 9 September 2026, Check Point released emergency security updates addressing two critical vulnerabilities affecting Check Point Security Gateway, Security Management Server, and Spark Firewall deployments configured to use Remote Access VPN or Site-to-Site VPN. Both vulnerabilities carry a CVSS s
On 8 September 2026, as part of its September Security Patch Day, SAP released Security Notes addressing two critical vulnerabilities affecting a broad range of SAP products[3]. The most severe, CVE-2026-44756 (CVSS 10.0), is a memory corruption vulnerability in SAP Extended Passport (EPP) processin
On 19 August 2026, Citrix published a security advisory addressing multiple critical vulnerabilities in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway). CERT-EU recommends updating affected devices as soon as possible.
[UPDATED] On 14 July 2026, Microsoft released security updates addressing critical remote code execution (RCE) vulnerabilities in Microsoft SharePoint Server. On 20 July 2026, WatchTowr identified a proof-of-concept exploit code and subsequently observed active exploitation of CVE-2026-50522, a vuln
On 9 June 2026, Ivanti released a security advisory addressing two critical vulnerabilities in their Sentry products[1]. An attacker could exploit those flaws to achieve unauthenticated remote code execution on the vulnerable device.
On 12 May 2026, Microsoft published a security advisory addressing a critical vulnerability affecting Windows Server when acting as a domain controller. This vulnerability allows an unauthenticated attacker to execute arbitrary code over a network. According to The Centre for Cybersecurity Belgium (
On 6 May 2026, Palo Alto published a security advisory addressing a critical vulnerability affecting PAN-OS. This vulnerability allows an unauthenticated attacker to execute arbitrary code with root privileges. Palo Alto observed limited exploitation of this vulnerability. It is strongly recommended
On 29 April 2026, a high local privilege escalation vulnerability in the Linux kernel, tracked as CVE-2026-31431 and named "Copy Fail", was publicly disclosed. The vulnerability affects every mainstream Linux distributions shipping a kernel built since 2017. A public proof-of-concept exploit has bee
On 17 March 2026, Microsoft updated one of its January 2026 security advisories related to a remote code execution vulnerability in Microsoft SharePoint. Specifically, Microsoft raised the CVSS score and changed the FAQ section to indicate that the vulnerability could be exploited by an unauthentica
On 23 March 2026, Citrix published a security advisory addressing multiple vulnerabilities affecting NetScaler ADC and NetScaler Gateway. These vulnerabilities may lead to sensitive information disclosure and user session mix-up under specific configurations. At the time of writing, there is no publ