A daily updated summary of security advisories from authoritative sources worldwide. Stay ahead of emerging threats with aggregated intelligence from government CERTs and security research organizations.
Our security experts can help you assess, prioritize, and remediate vulnerabilities before they become incidents. Get proactive protection for your organization.
Showing 110 advisories
A vulnerability was found in ggml-org llama.cpp up to b9060. It has been classified as critical. The affected element is the function GRAPH_RECOMPUTE handler of the component RPC server GRAPH_RECOMPUTE handler. This manipulation causes use after free. This vulnerability is tracked as CVE-2026-39909.
A vulnerability was found in Linux Kernel up to 6.6.151/6.12.103/6.18.44/7.1.8 and classified as very critical. Impacted is the function packet_snd/packet_sendmsg_spkt of the component packet. The manipulation results in out-of-bounds write. This vulnerability is identified as CVE-2026-74582. The at
A vulnerability has been found in Linux Kernel up to 7.1.7 and classified as very critical. This issue affects the function fib6_rule_suppress of the component IPv6. The manipulation leads to use after free. This vulnerability is referenced as CVE-2026-74581. Remote exploitation of the attack is pos
A vulnerability, which was classified as very critical, was found in Linux Kernel up to 7.1.8. This vulnerability affects the function vq_meta_prefetch of the component vhost. Executing a manipulation can lead to out-of-bounds read. The identification of this vulnerability is CVE-2026-74580. The att
A vulnerability, which was classified as problematic, has been found in Volcengine OpenViking up to 0.3.3. This affects an unknown part of the file /api/v1/resources of the component Resources API Endpoint. Performing a manipulation results in server-side request forgery. This vulnerability was name
A vulnerability classified as critical was found in Jet Admin. Affected by this issue is some unknown functionality. Such manipulation leads to improper authentication. This vulnerability is uniquely identified as CVE-2026-75932. The attack can be launched remotely. No exploit exists. This product o
A vulnerability classified as problematic has been found in ONNX up to 1.20.x. Affected by this vulnerability is the function save_external_data of the component External Data. This manipulation causes symlink following. This vulnerability is handled as CVE-2026-49114. It is possible to launch the a
A vulnerability described as problematic has been identified in Jet Admin. Affected is an unknown function of the component Sign-in Page. The manipulation results in cross site scripting. This vulnerability is known as CVE-2026-75933. It is possible to launch the attack remotely. No exploit is avail
A vulnerability marked as problematic has been reported in OpenIDC mod_auth_openidc 2.4.15.2/2.4.16.11. This impacts an unknown function of the component State-Cookie Parser. The manipulation leads to out-of-bounds write. This vulnerability is traded as CVE-2026-54789. It is possible to initiate the
A vulnerability labeled as problematic has been found in Brushfire Online Experience. This affects an unknown function. Executing a manipulation can lead to information disclosure. This vulnerability appears as CVE-2026-75928. The attack may be performed from remote. There is no available exploit. T
A vulnerability identified as critical has been detected in paperclipai Paperclip up to 0.3.0. The impacted element is an unknown function. Performing a manipulation results in reliance on reverse dns resolution. This vulnerability is reported as CVE-2026-77087. The attack is possible to be carried
A vulnerability categorized as problematic has been discovered in InternationalColorConsortium iccDEV up to 2.3.1.6. The affected element is the function CIccEmbedIO::Read8. Such manipulation leads to integer coercion error. This vulnerability is documented as CVE-2026-50278. The attack can be execu
A vulnerability was found in zanllp infinite-image-browsing up to 1.8.0. It has been rated as problematic. Impacted is the function to_abs_path of the file scripts/iib/tool.py of the component Path Normalization. This manipulation causes symlink following. This vulnerability is registered as CVE-202
A vulnerability was found in zanllp infinite-image-browsing up to 1.8.0. It has been declared as problematic. This issue affects the function is_path_trusted of the file scripts/iib/api.py. The manipulation of the argument path results in path traversal. This vulnerability is cataloged as CVE-2026-7
A vulnerability was found in LXC Incus up to 7.2.x. It has been classified as very critical. This vulnerability affects unknown code of the file metadata.yaml of the component Instance Metadata API. The manipulation leads to link following. This vulnerability is listed as CVE-2026-63343. The attack
A vulnerability was found in LXC Incus up to 7.1.x and classified as problematic. This affects an unknown part. Executing a manipulation can lead to improper authorization. This vulnerability is tracked as CVE-2026-55622. The attack can be launched remotely. No exploit exists. It is suggested to upg
A vulnerability has been found in LXC Incus up to 7.1.x and classified as problematic. Affected by this issue is some unknown functionality. Performing a manipulation results in improper privilege management. This vulnerability is identified as CVE-2026-55621. The attack can be initiated remotely. T
A vulnerability, which was classified as very critical, was found in LXC Incus up to 7.1.x. Affected by this vulnerability is an unknown functionality of the component Backup Compression Algorithm. Such manipulation leads to improper input validation. This vulnerability is referenced as CVE-2026-487
A vulnerability, which was classified as critical, has been found in Calix EXOS up to 6.6.47. Affected is an unknown function of the component UPnP WANIPConnection service. This manipulation causes missing authentication. The identification of this vulnerability is CVE-2026-75501. It is possible to
A vulnerability classified as very critical was found in LXC Incus up to 7.2.x. This impacts an unknown function of the file backup.yaml of the component Backup File Handler. The manipulation results in symlink following. This vulnerability was named CVE-2026-63125. The attack may be performed from
Serial Number: AV26-840Date: August 21, 2026 As of August 18, 2026, Mozilla is affected by vulnerabilities in the following products: Firefox versions prior to 154 Firefox ESR versions prior to 115.39 versions prior to 140.14 versions prior to 153.1 Thunderbird versions prior to 140.14 versions prio
Serial Number: AV26-839Date: August 21, 2026 As of August 18, 2026, Apple is affected by vulnerabilities in the following products: Safari Prior to 26.6.1 iOS and iPadOS Prior to 18.7.10 Prior to 26.6.1 MacOS Tahoe Prior to 26.6.2 The Cyber Centre encourages users and administrators to review the pr
Serial Number: AV26-838Date: August 21, 2026 As of August 19, 2026, Splunk is affected by vulnerabilities in the following products: Cisco Talos Intelligence for Enterprise Security Cloud Prior to 1.0.3 Splunk Enterprise Prior to 10.0.9 Prior to 10.2.6 Prior to 10.4.1 Prior to 10.4.2 Prior to 9.4.14
Serial Number: AV26-837Date: August 19, 2026 As of August 13, 2026, Johnson Controls is affected by vulnerabilities in the following products: Airwall Prior to 4.1.0 Metasys 12 all versions Metasys 13 all versions Metasys 14 all versions prior to v14.1.5 Metasys 15 all versions prior to v15.0.1 TL28
Serial Number: AV26-836Date: August 20, 2026 As of August 20, 2026, n8n is affected by vulnerabilities in the following product: n8n Prior to 1.123.69 Prior to 2.33.4 Prior to 2.34.1 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates
Serial Number: AV26-835Date: August 20, 2026 As of August 19, 2026, TrueConf is affected by a vulnerability in the following product: TrueConf Server 5.3.x versions prior to 5.3.9 5.4.x versions prior to 5.4.9 5.5.x versions prior to 5.5.5 On August 20, 2026, Cybersecurity and Infrastructure Securit
Serial Number: AV26-834Date: August 20, 2026 As of August 19, 2026, Cisco is affected by vulnerabilities in the following products: BroadWorks Application Delivery Platform Prior to RI.2026.07 BroadWorks Application Server Prior to RI.2026.07 BroadWorks Profile Server Prior to RI.2026.07 BroadWorks
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-72529 TrueConf Server Missing Authentication for Critical Function Vulnerability CVE-2026-72530 TrueConf Server Code Injection Vulnerability These types of
View CSAF Summary Successful exploitation of this vulnerability could allow a local attacker with low privileges to extract user credentials (passwords and authentication tokens) from system memory, potentially leading to unauthorized access to the application and connected systems. The following ve
Serial Number: AV26-833Date: August 19, 2026 As of August 19, 2026, Citrix is affected by vulnerabilities in the following products: NetScaler ADC and NetScaler Version 13.1 prior to 13.1-63.21 Version 14.1 prior to 14.1-73.32 NetScaler ADC FIPS Prior to 14.1-73.32 FIPS NetScaler ADC FIPS and NDcPP
Serial Number: AV26-832Date: August 19, 2026 As of August 17, 2026, MLflow is affected by vulnerabilities in the following product: MLflow Prior to 3.15.0 On August 19, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-64849 to their Known Exploited Vulnerabilities (KEV) D
Serial Number: AV26-831Date: August 19, 2026 As of August 18, 2026, Oracle Corporation is affected by vulnerabilities in the following products: Oracle Database Server Oracle Autonomous Health Framework Oracle Essbase Oracle Application Testing Suite Oracle Commerce Oracle Communications Oracle Cons
Serial Number: AV26-830Date: August 19, 2026 As of August 18, 2026, NVIDIA is affected by vulnerabilities in the following products: Triton Inference Server Versions prior to 0.0-26.05 Cumulus Linux GA/LTS Multiple versions NVOS Versions prior to 25.0.2.4438 and 25.0.2.6077 The Cyber Centre encourag
Serial Number: AV26-829Date: August 19, 2026 As of August 18, 2026, Atlassian is affected by vulnerabilities in the following products: Bamboo Data Center and Server multiple versions Bitbucket Data Center and Server multiple versions Confluence Data Center and Server multiple versions Crowd Data Ce
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-64849 MLflow Server-Side Request Forgery Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant
Executive summary Note: This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs). However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply relevant mitigations to reduce the risk to their devices and s
De multiples vulnérabilités ont été découvertes dans les produits Axis. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
De multiples vulnérabilités ont été découvertes dans Oracle MySQL. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.
Une vulnérabilité a été découverte dans les produits Moxa. Elle permet à un attaquant de provoquer un déni de service à distance.
De multiples vulnérabilités ont été découvertes dans Python. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, un contournement de la politique de sécurité et un problème de sécurité non spécifié par l'éditeur.
De multiples vulnérabilités ont été découvertes dans Oracle Virtualization. Elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.
De multiples vulnérabilités ont été découvertes dans Oracle Database Server. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.
De multiples vulnérabilités ont été découvertes dans Oracle Java SE. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.
De multiples vulnérabilités ont été découvertes dans Oracle PeopleSoft. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, une atteinte à l'intégrité des données et un déni de service.
Une vulnérabilité a été découverte dans Apereo CAS. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité.
De multiples vulnérabilités ont été découvertes dans Oracle Weblogic. Elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.
De multiples vulnérabilités ont été découvertes dans les produits Mozilla. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, un déni de service à distance et une atteinte à la confidentialité des données.
De multiples vulnérabilités ont été découvertes dans Oracle Systems. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.
De multiples vulnérabilités ont été découvertes dans Synacor Zimbra Collaboration. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une falsification de requêtes côté serveur (SSRF) et une injection de code indirecte à distance (XSS)....
De multiples vulnérabilités ont été découvertes dans Google Chrome. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.
Serial number: AV26-823Date: August 17, 2026Updated: August 18, 2026 As of August 6, 2026, Apple is affected by vulnerabilities in the following products: macOS Tahoe Prior to 26.6.1 macOS Sequoia Prior to 15.7.9 macOS Sonoma Prior to 14.8.9 Open-source reporting indicates that CVE-2026-65400 is bei
Serial number: AV26-763Date: July 30, 2026Updated: August 18, 2026 As of July 30, 2026, VMware is affected by vulnerabilities in the following products: Cloud Foundation 5.x 9.0.x.x 9.1.x.x Prior to 5.2.3 ESX Prior to ESXi-9.0.2.0100-25595025 Prior to ESXi-9.1.0.0-25370933 Prior to ESXi-9.1.0.0200-2
Serial Number: AV26-804Date: August 11, 2026Updated: August 18, 2026 As of August 11, 2026, Microsoft is affected by vulnerabilities in the following products: .NET 10.0 installed on Linux .NET 10.0 installed on Mac OS .NET 10.0 installed on Windows .NET 8.0 installed on Linux .NET 8.0 installed on
Serial Number: AV26-828Date: August 18, 2026 As of August 17, 2026, Mattermost is affected by vulnerabilities in the following product: Mattermost Prior to or equal to 10.11.21 Prior to or equal to 11.7.6 Prior to or equal to 11.8.3 The Cyber Centre encourages users and administrators to review the
Serial Number: AV26-827Date: August 18, 2026 As of August 17, 2026, GitLab is affected by vulnerabilities in the following product: GitLab Prior to 18.11.11 Prior to 19.0.8 Prior to 19.1.6 Prior to 19.2.4 The Cyber Centre encourages users and administrators to review the provided web links and apply
Serial Number: AV26-826Date: August 18, 2026 As of August 17, 2026, BeyondTrust is affected by vulnerabilities in the following product: Endpoint Privilege Management (Windows deployment) Prior to 26.1.2 The Cyber Centre encourages users and administrators to review the provided web links and apply
Serial Number: AV26-825Date: August 18, 2026 As of August 17, 2026, JetBrains is affected by vulnerabilities in the following products: IntelliJ IDEA Prior to 2026.1.5 Prior to 2026.2.1 Ktor Prior to 3.4.1 PyCharm Prior to 2026.2.1 YouTrack Prior to 2025.3.156085 Prior to 2026.1.13901 Prior to 2026.
View CSAF Summary Simcenter Nastran is affected by a stack overflow vulnerability that could be triggered when an application binary reads arbitrary string as a file argument. If a user is tricked to run one of the impacted application binary with a malicious string, an attacker could leverage the v
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition or execute arbitrary code. The following versions of CISA Malcolm are affected: Malcolm <26.06.1 (CVE-2026-55676) Malcolm <26.07.0 (CVE-2026-63133, CVE-2026-63134, CVE-20
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-33824 Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability CVE-2026-55040 Microsoft SharePoint Weak Authentication Vulnerabil
De multiples vulnérabilités ont été découvertes dans GitLab. Certaines d'entre elles permettent à un attaquant de provoquer une atteinte à l'intégrité des données et une injection de requêtes illégitimes par rebond (CSRF).
De multiples vulnérabilités ont été découvertes dans Mattermost Desktop App. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données et un problème de sécurité non spécifié par l'éditeur.
De multiples vulnérabilités ont été découvertes dans Typo3. Elles permettent à un attaquant de provoquer un contournement de la politique de sécurité.
De multiples vulnérabilités ont été découvertes dans Zabbix. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.
De multiples vulnérabilités ont été découvertes dans les produits Apple. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, une élévation de privilèges et un déni de service à distance.
Serial number: AV26-824Date: August 17, 2026 As of August 17, 2026, Progress is affected by vulnerabilities in the following product: ShareFile Storage Zones Controller Prior to or equal to 5.12.5 Prior to or equal to 6.0.2 The Cyber Centre encourages users and administrators to review the provided
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-62593 Ray-Project Ray Code Injection Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant ris
View CSAF Summary Solid Edge is affected by multiple file parsing vulnerabilities that could be triggered when the application reads specially crafted files in PAR, PSM or DFT format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions f
View CSAF Summary Siemens License Server is affected by multiple vulnerabilities which could allow an attacker to elevate its privileges and read arbitrary files on the system. Siemens has released a new version for Siemens License Server (SLS) and recommends to update to the latest version. The fol
View CSAF Summary A vulnerability in Desigo DXR and PXC controllers has been identified that could allow an attacker to cause denial of service conditions by sending malformed BACnet packets. Recovery requires a device reset or reboot to restore normal functionality. Siemens has released new version
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to decrypt sensitive data, bypass authentication controls, gaining unauthorized access to read arbitrary files on the system, or gain unauthorized access to protected system resources. The following versions o
View CSAF Summary Successful exploitation of this vulnerability could allow a low-privilege user or attacker to inject a persistent malicious payload via a crafted URL that executes in the context of other users' sessions, including administrators, potentially leading to session hijacking and unauth
View CSAF Summary Siveillance Video Management Servers contains a vulnerability that could allow a Remote Code Execution attack. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Siveillance Video are affect
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker within Bluetooth range to manipulate brain stimulation parameters and override safety limits. The following versions of Flow Neuroscience FL-100 are affected: Flow Neuroscience FL-100 Halo Neuroscience FL-100 CVS
View CSAF Summary Siemens LOGO! Soft Comfort contains multiple vulnerabilities in its project-file encryption and password handling mechanisms. A local attacker could exploit these vulnerabilities to extract the master key, allowing them to decrypt project data or remove project passwords. The lack
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to read data from the device or gain access to affected workstations. The following versions of ANDRITZ HIPASE-250 and 250 SCALA are affected: HIPASE-250 <=7.20 (CVE-2026-65309, CVE-2026-65310, CVE-2026-65311,
View CSAF Summary Simcenter Femap contains two file parsing vulnerabilities that could be triggered when the application reads files in BMP file format. If a user is tricked to open a malicious file with the affected application, this could lead the application to crash or potentially lead to arbitr
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to tamper with serialized data, potentially resulting in code execution during deserialization. The following versions of AVEVA Enterprise SCADA are affected: Enterprise SCADA 2025 (CVE-2025-7639) Enterprise SCAD
View CSAF Summary Hitachi Energy is aware of Dirty Frag vulnerabilities that affect APM Edge product versions listed in this document. Successful exploitation of these vulnerabilities could result in impact on confidentiality, integrity and availability of the product. Please refer to the Recommende
De multiples vulnérabilités ont été découvertes dans Mattermost Desktop App. Elles permettent à un attaquant de provoquer un déni de service à distance et un problème de sécurité non spécifié par l'éditeur.
On 19 August 2026, Citrix published a security advisory addressing multiple critical vulnerabilities in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway). CERT-EU recommends updating affected devices as soon as possible.
[UPDATED] On 14 July 2026, Microsoft released security updates addressing critical remote code execution (RCE) vulnerabilities in Microsoft SharePoint Server. On 20 July 2026, WatchTowr identified a proof-of-concept exploit code and subsequently observed active exploitation of CVE-2026-50522, a vuln
On 9 June 2026, Ivanti released a security advisory addressing two critical vulnerabilities in their Sentry products[1]. An attacker could exploit those flaws to achieve unauthenticated remote code execution on the vulnerable device.
On 12 May 2026, Microsoft published a security advisory addressing a critical vulnerability affecting Windows Server when acting as a domain controller. This vulnerability allows an unauthenticated attacker to execute arbitrary code over a network. According to The Centre for Cybersecurity Belgium (
On 6 May 2026, Palo Alto published a security advisory addressing a critical vulnerability affecting PAN-OS. This vulnerability allows an unauthenticated attacker to execute arbitrary code with root privileges. Palo Alto observed limited exploitation of this vulnerability. It is strongly recommended
On 29 April 2026, a high local privilege escalation vulnerability in the Linux kernel, tracked as CVE-2026-31431 and named "Copy Fail", was publicly disclosed. The vulnerability affects every mainstream Linux distributions shipping a kernel built since 2017. A public proof-of-concept exploit has bee
On 17 March 2026, Microsoft updated one of its January 2026 security advisories related to a remote code execution vulnerability in Microsoft SharePoint. Specifically, Microsoft raised the CVSS score and changed the FAQ section to indicate that the vulnerability could be exploited by an unauthentica
On 23 March 2026, Citrix published a security advisory addressing multiple vulnerabilities affecting NetScaler ADC and NetScaler Gateway. These vulnerabilities may lead to sensitive information disclosure and user session mix-up under specific configurations. At the time of writing, there is no publ
On 25 February 2026, Cisco released security advisories addressing multiple high and critical severity vulnerabilities in Cisco Catalyst SD-WAN controllers and Cisco SD-WAN Manager. If exploited, these vulnerabilities could allow attackers to gain administrative access to compromised systems. It is
On 29 January 2026, Ivanti released a security advisory addressing two critical vulnerabilities in their EPMM products. An attacker could exploit those flaws to achieve unauthenticated remote code execution on the vulnerable device. One of these vulnerabilities have been exploited in a limited numbe