National CERT advisories

A unified feed of security advisories published by European national CERTs and authorities, cross-referenced to CVEs. 5672 ingested.

CERT map
🇪🇸ESCCN-CERT2026-09-07 15:17
CVE-2026-86317

A vulnerability was detected in ggml-org llama.cpp up to 0.4.0. This impacts the function rpc_server::deserialize_tensor of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the component RPC Server. Performing a manipulation o…

🇳🇱NLNCSC-NL2026-09-07 14:35
NCSC-2026-0318 [1.01] [H/H] Kwetsbaarheden verholpen in Citrix NetScaler ADC en NetScaler Gateway

Citrix heeft kwetsbaarheden verholpen in NetScaler ADC en NetScaler Gateway. De kwetsbaarheid met kenmerk CVE-2026-19489 betreft een memory overflow in NetScaler ADC en NetScaler Gateway, wanneer de producten zijn geconf…

🇪🇸ESCCN-CERT2026-09-07 13:20
CVE-2026-80238

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Execution with Unnecessary Privileges vulnerability. An unauthenticated attacker with local acces…

🇪🇸ESCCN-CERT2026-09-07 13:20
CVE-2026-86429

The league/commonmark (thephpleague/commonmark) library in versions = 1.5.0 and

🇪🇸ESCCN-CERT2026-09-07 13:20
CVE-2026-86426

LibreNMS before 26.8.0 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to access protected endpoints by sending numeric values instead of string tokens. Attackers can…

🇭🇷HRCERT.hr2026-09-07 13:11
Upozorenj: kritična ranjivosti u MikroTik RouterOS-u. Preporučuje se hitna nadogradnja.

Poljski CERT (CERT Polska) identificirao je i koordinirao objavu šest ranjivosti u sustavu MikroTik RouterOS. Kombinacijom dviju od njih (CVE-2026-67276 i CVE-2026-86060), nazvanom “MikroTrick”, napadač može …

🇳🇱NLNCSC-NL2026-09-07 12:18
Kwetsbaarheid in N-central van N-able: update nu

Er is een ernstige kwetsbaarheid, CVE-2026-86218, gevonden in N-central van N-able met een CVSS-score van 10. Deze kwetsbaarheid maakt het voor onbevoegden mogelijk om op afstand, zonder inloggegevens, schadelijke code u…

🇪🇸ESINCIBE-CERT2026-09-07 10:52
Control de acceso incorrecto en PrestaShop

Control de acceso incorrecto en PrestaShop Lun, 07/09/2026 - 12:52 Aviso Recursos Afectados PrestaShop, versiones anteriores a la 9.1.5 y a la 8.2.8, según la rama. Descripción INCIBE ha coordinado la publicación de una …

🇪🇸ESCCN-CERT2026-09-07 09:17
CVE-2026-86332

A flaw was found in odh-dashboard in Red Hat OpenShift AI. The backend-for-frontend route GET /api/nim-serving/:nimResource reads Kubernetes Secrets using the dashboard service account and returns the full Secret object,…

🇪🇸ESINCIBE-CERT2026-09-07 08:37
Múltiples vulnerabilidades en productos de Cisco

Múltiples vulnerabilidades en productos de Cisco Lun, 07/09/2026 - 10:37 Aviso Recursos Afectados Cisco IOS XR Software:Todas las versiones de Cisco IOS XR Software, incluido Cisco IOS XR7 (LNT), independientemente de la…

🇪🇸ESCCN-CERT2026-09-07 08:17
CVE-2026-78254

The ftp and scp tasks of Apache Ant can download files from a remote server. A malicious server can provide relative paths that allow it to write outside of the dedicated target directory for the download, making it poss…

🇪🇸ESCCN-CERT2026-09-07 04:17
CVE-2026-86315

An out-of-bounds write caused by numeric truncation Samsung Open Source Escargot on Linux x86-64 allows an attacker who can supply JavaScript for execution to corrupt native memory and crash the host process via a crafte…

🇪🇸ESCCN-CERT2026-09-07 03:17
CVE-2026-86313

Out-of-bounds write vulnerability in Samsung Opensource Walrus allows Overflow Buffers. This issue affects Walrus: af80e665ea49d9003695a66502f841ed1d8397e7.

🇪🇸ESCCN-CERT2026-09-07 03:17
CVE-2026-86314

Integer overflow in the source-bounds check in Memory::init() (src/runtime/Memory.cpp) in Samsung walrus on all platforms allows a remote attacker to cause an out-of-bounds heap read and denial of service via a crafted W…

🇪🇸ESCCN-CERT2026-09-06 22:17
CVE-2026-86225

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is the function mysqli_query of the file /admin/modal_add_room.php. The manipulation of the argument …

🇪🇸ESCCN-CERT2026-09-06 21:17
CVE-2026-86224

A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected is the function mysqli_query of the file /admin/modal_add_product.php. Executing a manipulation of the argument fname can l…

🇪🇸ESCCN-CERT2026-09-06 20:17
CVE-2026-86222

A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. This affects the function mysqli_query of the file /admin/modal_add_course2.php. Such manipulation of the argument course leads to s…

🇪🇸ESCCN-CERT2026-09-06 20:17
CVE-2026-86223

A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This impacts the function mysqli_query of the file /admin/modal_add_coursea.php. Performing a manipulation of the argument course results…

🇪🇸ESCCN-CERT2026-09-06 19:17
CVE-2026-86221

A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is the function mysqli_query of the file /admin/modal_add_course1.php. This manipulation of the argument course causes s…

🇪🇸ESCCN-CERT2026-09-06 18:17
CVE-2026-86220

A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. The affected element is the function mysqli_query of the file /admin/modal_add_course.php. The manipulation of the argument course res…

🇪🇸ESCCN-CERT2026-09-06 18:17
CVE-2026-80229

When performing transfers via libcurl’s multi interface, pooled TLS connections can outlive their originating easy handles. In OpenSSL 3 provider configurations, libcurl attaches an allocated library context to the easy …

🇮🇹ITCSIRT Italia2026-09-06 16:48
MikroTik: rilevato sfruttamento in rete di nuove vulnerabilità

MikroTik ha rilasciato aggiornamenti di sicurezza al fine di correggere 6 nuove vulnerabilità, di cui 2 con gravità “critica” e 2 con gravità “alta”. Tra queste, si evidenzia lo sfruttamento attivo in rete delle vulnerab…

🇪🇸ESCCN-CERT2026-09-06 16:16
CVE-2026-19633

PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted expressions. When these objects a…

🇪🇸ESCCN-CERT2026-09-06 16:16
CVE-2026-19634

PostgreSQL Anonymizer contains a SQL injection vulnerability in two import functions. A user can create a malicious JSON document containing specially crafted object names. If a superuser subsequently calls anon.import_d…

🇪🇸ESCCN-CERT2026-09-06 13:17
CVE-2026-86213

A vulnerability was found in Mstfakts College-Management-System. This issue affects the function mysqli_query of the file Front-end/university.php of the component Search Handler. The manipulation of the argument book_na…

🇪🇸ESCCN-CERT2026-09-06 12:17
CVE-2026-86242

Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL through unauthenticated POST /api/plugins when management authentication is disabled (the default, governance.auth_config.is_…

🇵🇱PLCERT Polska2026-09-05 13:05
Podatności w oprogramowaniu Mikrotik RouterOS

Zespół CERT Polska znalazł 6 podatności (od CVE-2026-67276 do CVE-2026-67279, CVE-2026-67281 oraz CVE-2026-86060) w oprogramowaniu Mikrotik RouterOS.

🇵🇱PLCERT Polska2026-09-05 13:05
Vulnerabilities in Mikrotik RouterOS software

CERT Polska has found 6 vulnerabilities (from CVE-2026-67276 to CVE-2026-67279, CVE-2026-67281 and CVE-2026-86060) in Mikrotik RouterOS software.

🇪🇸ESCCN-CERT2026-09-05 06:17
CVE-2026-13447

The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to missing cryptographic signature verification in the FirebasePhoneAuthHelp…

🇫🇮FINCSC-FI2026-09-05 02:00
Google Chrome Stable Channel Update

Classification: Severe, Solution: Official Fix, Exploit Maturity: High, CVSSv3.1: None, CVEs: CVE-2026-85046, CVE-2026-85052, CVE-2026-85043, CVE-2026-85048, CVE-2026-85045, CVE-2026-85050, CVE-2026-85053, CVE-2026-85042…

🇪🇸ESCCN-CERT2026-09-05 00:17
CVE-2026-52773

YesWiki is a wiki system written in PHP. From version 4.1.0 to before version 4.6.6, YesWiki's archived-revision view reflects the time GET parameter into a hidden HTML input in handlers/page/show.php without escaping. B…

🇪🇸ESCCN-CERT2026-09-05 00:17
CVE-2026-52767

YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, HttpSignatureService::verifySignature() checks the result of PHP's openssl_verify() with a loose boolean negation - if (!openssl_verify…

🇦🇹ATCERT.at2026-09-04 17:20
Tageszusammenfassung - 04.09.2026

End-of-Day report Timeframe: Donnerstag 03-09-2026 18:00 - Freitag 04-09-2026 18:00 Handler: Michael Schlagenhaufer Co-Handler: Alexander Riepl News Critical Citrix NetScaler auth bypass now leveraged in attacks Tracked …

🇪🇸ESCCN-CERT2026-09-04 16:17
CVE-2026-19301

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery.

🇪🇸ESCCN-CERT2026-09-04 16:17
CVE-2026-19645

IBM MQ Agent CD: v1.0.0, v1.0.1, v2.0.0, v2.0.1 An authenticated user with a valid session cookie can submit arbitrarily large or computationallyexpensive requests that cause the LLM agent workers to be held for extended…

🇪🇸ESCCN-CERT2026-09-04 16:17
CVE-2026-19304

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information from internal services due to a URL parser discrepancy.

🇪🇸ESCCN-CERT2026-09-04 16:17
CVE-2026-18887

IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to obtain sensitive information in PASE. An attacker could exploit this vulnerability to access information about process they shouldn't be permitted to …

🇪🇸ESCCN-CERT2026-09-04 16:17
CVE-2026-18905

IBM ContextForge MCP Gateway (`mcp-contextforge-gateway`)

🇪🇸ESCCN-CERT2026-09-04 16:17
CVE-2026-18658

IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An unauthenticated attacker can execute arbitrary SQL statements and leverage database…

🇪🇸ESCCN-CERT2026-09-04 16:17
CVE-2026-19300

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to incomplete scrubbing of sensitive credential fields.

🇪🇸ESCCN-CERT2026-09-04 16:17
CVE-2026-19302

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links.

🇪🇸ESCCN-CERT2026-09-04 16:17
CVE-2026-18858

IBM i 7.6, and 7.5 could allow a local authenticated attacker to obtain information from a privileged file when using SSH.

🇪🇸ESCCN-CERT2026-09-04 16:17
CVE-2026-19303

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to delete arbitrary local files or directories due to improper limitation of a pathname to a restricted directory.

🇪🇸ESCCN-CERT2026-09-04 16:17
CVE-2026-19298

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to execute arbitrary code due to an authorization bypass in the flow build process.

🇪🇸ESCCN-CERT2026-09-04 16:17
CVE-2026-19306

IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files from the server filesystem — including server secret material (secret_key, JWT signing keys, the application database, /proc/…

🇪🇸ESCCN-CERT2026-09-04 16:17
CVE-2026-19299

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to path traversal.

🇪🇸ESCCN-CERT2026-09-04 16:17
CVE-2026-19274

IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated Kubernetes tenant to hijack or permanently destroy another tenant's cluster-level RBAC permissi…

🇪🇸ESCCN-CERT2026-09-04 16:17
CVE-2026-19283

IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated remote attacker to obtain sensitive information, caused by missing destination namespace valida…

🇪🇸ESCCN-CERT2026-09-04 16:17
CVE-2026-19305

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to server-side request forgery.

🇪🇸ESCCN-CERT2026-09-04 16:17
CVE-2026-18567

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a local attacker to obtain information due to a race condition involving a predictable Unix domain socket path in a world-writable directory.

🇪🇸ESCCN-CERT2026-09-04 15:17
CVE-2026-9186

IBM Langflow OSS 1.0.0 through 1.11.2 allows remote authenticated attackers to bypass localhost-only MCP configuration installation by spoofing X-Forwarded-For: 127.0.0.1 header, enabling arbitrary writes to IDE config f…

🇪🇸ESCCN-CERT2026-09-04 15:17
CVE-2026-8447

IBM Langflow OSS 1.0.0 through 1.11.2 suffer from a stored cross-site scripting vulnerability in the Playground chat interface.

🇪🇸ESCCN-CERT2026-09-04 15:17
CVE-2026-9138

IBM Langflow OSS 1.0.0 through 1.11.2 Langflow could allow an authenticated attacker to write arbitrary files to the server due to improper input validation in the SaveToFileComponent. The application constructs local fi…

🇱🇻LVCERT.LV2026-09-04 14:17
Uzbrukumos izmantota ievainojamība Google Chrome

Google Chrome pārlūkprogrammā ir atklāta ievainojamība CVE-2026-85046, kas jau pirms drošības "ielāpa" publicēšanas tika aktīvi izmantota uzbrukumos. Ievainojamība var ļaut izpildīt uzbrucēja kontrolētu kodu Chrome pārlū…

🇳🇱NLNCSC-NL2026-09-04 14:05
Kwetsbaarheden in Google Chrome – voer updates uit

Er zijn meerdere kwetsbaarheden gevonden in Google Chrome, specifiek in versie 152.0.7977.82. Deze kwetsbaarheden, waaronder CVE-2026-85042 en CVE-2026-85047, betreffen verschillende onderdelen van de browser. Het advies…

🇳🇱NLNCSC-NL2026-09-04 13:20
NCSC-2026-0341 [1.00] [M/H] Kwetsbaarheden verholpen in Google Chrome

Google heeft meerdere kwetsbaarheden verholpen in Google Chrome, specifiek in versies voor 152.0.7977.82. De kwetsbaarheden bevinden zich in verschillende componenten van Google Chrome, waaronder DevTools, Network, V8 Ja…

🇮🇹ITCSIRT Italia2026-09-04 10:06
Google: rilevato sfruttamento di vulnerabilità zero-day in Chrome

Google ha rilasciato un aggiornamento per il browser Chrome al fine di correggere 12 nuove vulnerabilità di sicurezza, di cui 2 con gravità “critica” e 7 con gravità “alta”. Tra queste, si evidenzia lo sfruttamento attiv…

🇪🇸ESINCIBE-CERT2026-09-04 09:42
Múltiples vulnerabilidades en productos de ABB

Múltiples vulnerabilidades en productos de ABB Vie, 04/09/2026 - 11:42 Aviso SCI Recursos Afectados Las siguientes herramientas y servicios de ABB están afectados por estas vulnerabilidades:Automation Builder versiones a…

🇪🇸ESINCIBE-CERT2026-09-04 08:48
Permisos incorrectos en Ignition de Inductive Automation

Permisos incorrectos en Ignition de Inductive Automation Vie, 04/09/2026 - 10:48 Aviso SCI Recursos Afectados Inductive Automation Ignition: versión 8.1.53 y anteriores. Descripción Inductive Automation ha publicado 1 vu…

🇪🇸ESINCIBE-CERT2026-09-04 08:16
Neutralización incorrecta de secuencias en VPN Client de IXON

Neutralización incorrecta de secuencias en VPN Client de IXON Vie, 04/09/2026 - 10:16 Aviso SCI Recursos Afectados Cliente VPN IXON: versiones anteriores a la 1.4.7. Descripción Luuk van Rheden y Stan van Duijnhoven, de …

🇪🇸ESINCIBE-CERT2026-09-04 08:05
Verificación incorrecta de firma criptográfica en Mendix SAML de Siemens

Verificación incorrecta de firma criptográfica en Mendix SAML de Siemens Vie, 04/09/2026 - 10:05 Aviso SCI Recursos Afectados Mendix SAML (Mendix 9.24 compatible): versiones anteriores a la V3.6.27;Mendix SAML (Mendix 10…

🇪🇸ESINCIBE-CERT2026-09-04 07:55
Múltiples vulnerabilidades en productos de VMware

Múltiples vulnerabilidades en productos de VMware Vie, 04/09/2026 - 09:55 Aviso Recursos Afectados VMware Workstation, versiones 25H2 y 26H1;VMware Fusion, versiones 25H2 y 26H1. Descripción h4urek, de secsys lab, Y² &nb…

🇪🇸ESINCIBE-CERT2026-09-04 07:53
Desbordamiento de búfer en NetStaX EtherNet/IP Stack de Pyramid Solutions

Desbordamiento de búfer en NetStaX EtherNet/IP Stack de Pyramid Solutions Vie, 04/09/2026 - 09:53 Aviso SCI Recursos Afectados Los siguientes productos con versión anterior a la 5.6.1:EtherNet/IP Adapter DLL Kit (EIPA);E…

🇫🇮FINCSC-FI2026-09-04 02:00
Casdoor authentication server is vulnerable to authorization bypass

Classification: Critical, Solution: Temporary Fix, Exploit Maturity: Not Defined, CVSSv3.1: None, CVEs: CVE-2026-15630, Summary: Casdoor is an open-source Access Management (IAM) platform used to manage web applications.…

🇫🇮FINCSC-FI2026-09-04 02:00
Multiple Vulnerabilities in HPE Aruba Networking ArubaOS-CX (AOS-CX)

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8, CVEs: CVE-2026-73749, CVE-2026-73750, CVE-2026-73751, CVE-2026-73752, CVE-2026-73753, CVE-2026-73782, CVE-2026-73781, CVE-20…

🇫🇷FRCERT-FR2026-09-04 00:00
Multiples vulnérabilités dans Google Chrome (04 septembre 2026)

De multiples vulnérabilités ont été découvertes dans Google Chrome. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur. Google indique que la vulnérabilité CVE-2026-85046 est …

🇪🇸ESCCN-CERT2026-09-03 19:17
CVE-2026-85028

Creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Kit (aws-fpga) before 2.3.4 might allow local users to execute arbitrary co…

🇪🇸ESCCN-CERT2026-09-03 18:17
CVE-2026-84968

An out-of-bounds read in the BSON decoding component of the MongoDB PHP driver may allow an unauthenticated party who supplies specially formed input to have a small amount of adjacent process memory copied into an error…

🇦🇹ATCERT.at2026-09-03 17:17
Tageszusammenfassung - 03.09.2026

End-of-Day report Timeframe: Mittwoch 02-09-2026 18:00 - Donnerstag 03-09-2026 18:00 Handler: Michael Schlagenhaufer Co-Handler: n/a News Critical Elementor Pro flaw exploited to take over WordPress sites A recently patc…

🇪🇸ESCCN-CERT2026-09-03 16:18
CVE-2026-84964

A double free in the OpenSSL-based TLS certificate revocation checking path of the MongoDB C Driver can be reached by a TLS endpoint that the client already trusts. During the handshake, specially formed certificate data…

🇪🇸ESCCN-CERT2026-09-03 16:18
CVE-2026-84966

An incorrect numeric type conversion in the BSON document building component of the MongoDB C++ Driver may cause a length value to be interpreted incorrectly. When an application supplies an extremely large, non-terminat…

🇪🇸ESCCN-CERT2026-09-03 16:18
CVE-2026-84963

An incorrect numeric conversion in the JSON parsing component of the MongoDB C Driver's BSON library may cause an unusually large text value to be silently shortened, or the corresponding field to be omitted, while the p…

🇪🇸ESCCN-CERT2026-09-03 16:18
CVE-2026-84967

A component of the MongoDB extension for Visual Studio Code does not neutralize special characters in a connection string before that value is placed into a command line the extension composes for an integrated terminal.…

🇪🇸ESCCN-CERT2026-09-03 15:17
CVE-2026-84970

A numeric truncation weakness exists in the JSON parsing component of the MongoDB C++ Driver's BSON library. An actor who controls the text that an embedding application hands to the library's public JSON parsing interfa…

🇪🇸ESCCN-CERT2026-09-03 15:17
CVE-2026-84969

A memory-handling error in the BSON-to-JSON conversion helpers of the MongoDB C Driver can write a small number of bytes past the end of a heap buffer when a binary field is encoded and the output is cut short at a calle…

🇳🇱NLNCSC-NL2026-09-03 13:44
NCSC-2026-0339 [1.00] [M/H] Kwetsbaarheden verholpen in HPE Networking Fabric Composer

HPE heeft meerdere kwetsbaarheden verholpen in HPE Networking Fabric Composer. De kwetsbaarheden in HPE Networking Fabric Composer betreffen onder andere authenticatiebypasses, privilege-escalaties, remote code execution…

🇪🇸ESCCN-CERT2026-09-03 13:06
CVE-2026-85084

Out-of-bounds Write and Improper Validation of Array Index vulnerability in Samsung Open Source TizenFX Samsung/TizenFX allows Overflow Buffers.

🇮🇹ITCSIRT Italia2026-09-03 12:13
Cleo Harmony: disponibile PoC per la CVE-2026-84115

Disponibile un Proof of Concept (PoC) per lo sfruttamento della CVE-2026-84115 – già sanata dal vendor – presente in Cleo Harmony.

🇵🇱PLCERT Polska2026-09-03 10:55
Vulnerability in OptimiDoc Server (On-Premise) software

Plaintext Storage of a Password vulnerability (CVE-2026-15933) has been found in OptimiDoc Server (On-Premise) software.

🇵🇱PLCERT Polska2026-09-03 10:55
Podatność w oprogramowaniu OptimiDoc Server (On-Premise)

W oprogramowaniu OptimiDoc Server (On-Premise) wykryto podatność polegającą na przechowywaniu poświadczeń w jawnej formie (CVE-2026-15933).

🇪🇸ESINCIBE-CERT2026-09-03 08:00
Múltiples vulnerabilidades en Ocsreports de OCS Inventory NG

Múltiples vulnerabilidades en Ocsreports de OCS Inventory NG Jue, 03/09/2026 - 10:00 Aviso Recursos Afectados Ocsreports 2.12.4. Descripción INCIBE ha coordinado la publicación de 5 vulnerabilidades, 1 de severidad críti…

🇪🇸ESINCIBE-CERT2026-09-03 07:50
Múltiples vulnerabilidades en productos de SonicWall

Múltiples vulnerabilidades en productos de SonicWall Jue, 03/09/2026 - 09:50 Aviso Recursos Afectados Modelos SMA1000 - 6210, 7210, 8200v: versión 12.4.3-03453 (platform-hotfix) y anteriores, y versión 12.5.0-02835 (plat…

🇫🇮FINCSC-FI2026-09-03 02:00
Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Denial of Service Vulnerability

Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 7.5, CVEs: CVE-2026-20281, Summary: A vulnerability in Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Ci…

🇫🇮FINCSC-FI2026-09-03 02:00
Multiple vulnerabilities in SOY series

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8, CVEs: CVE-2026-73827, CVE-2026-77838, CVE-2026-78238, CVE-2026-78032, Summary: SOY series provided by Tsuyoshi Saito contain…

🇫🇮FINCSC-FI2026-09-03 02:00
Hugging Face Transformers library writes remote code to disk prior to consent check

Classification: Critical, Solution: Unavailable, Exploit Maturity: Not Defined, CVSSv3.1: None, CVEs: CVE-2026-80047, Summary: A vulnerability in the Hugging Face Transformers library (versions 4.49.0 through 5.8.1) allo…

🇫🇮FINCSC-FI2026-09-03 02:00
Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8, CVEs: CVE-2026-20212, Summary: A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could all…

🇫🇮FINCSC-FI2026-09-03 02:00
Cisco IOS XR Software Security Hardening Release: September 2026

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8, CVEs: CVE-2026-20274, CVE-2026-20275, CVE-2026-20276, CVE-2026-20277, CVE-2026-20278, CVE-2026-20279, CVE-2026-20280, Summar…

🇫🇮FINCSC-FI2026-09-03 02:00
Google Chrome Stable Channel Update for Desktop

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: None, CVEs: CVE-2026-84353, CVE-2026-84352, CVE-2026-84354, CVE-2026-84359, CVE-2026-84357, CVE-2026-84324, CVE-2026-84349, CVE-2…

🇫🇮FINCSC-FI2026-09-03 02:00
SonicWall SMA1000 Series Appliances Affected By Multiple Vulnerabilities 10

Classification: Critical, Solution: Official Fix, Exploit Maturity: High, CVSSv3.0: 10.0, CVEs: CVE-2026-83548, CVE-2026-83549, Summary: 1) CVE-2026-83548 - Pre-authentication SSRF via unintended forward-proxy A Pre-auth…

🇫🇮FINCSC-FI2026-09-03 02:00
Haavoittuvuuksia Rockwell Automation -tuotteissa

Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.0: 8.6, CVEs: CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625, CVE-2026-9633, CVE-2026-9634, CVE-2026-9637, CVE-2026-16675,…

🇫🇮FINCSC-FI2026-09-03 02:00
Cisco Secure Email Secure/Multipurpose Internet Mail Extensions Ciphertext Decryption Vulnerabilities

Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 5.9, CVEs: CVE-2026-20354, CVE-2026-20355, Summary: Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions…

🇦🇹ATCERT.at2026-09-02 17:47
Tageszusammenfassung - 02.09.2026

End-of-Day report Timeframe: Dienstag 01-09-2026 18:00 - Mittwoch 02-09-2026 18:00 Handler: Michael Schlagenhaufer Co-Handler: n/a News Hackers abuse Faronics Deploy admin tool to install ScreenConnect Phishing actors ar…

🇪🇸ESCCN-CERT2026-09-02 16:17
CVE-2026-84652

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins does not rotate the session when a user is authenticated via the "remember me" cookie, allowing attackers able to serve content on the same site as Jenkins t…

🇪🇸ESCCN-CERT2026-09-02 16:17
CVE-2026-84653

Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly perform permission checks in the Appearance configuration page, allowing attackers with Overall/Manage permiss…

🇪🇸ESCCN-CERT2026-09-02 16:17
CVE-2026-84648

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log viewer does not escape log record metadata (source, level, and timestamp) resulting in a stored cross-site scripting (XSS) vulnerability exploitable b…

🇪🇸ESCCN-CERT2026-09-02 16:17
CVE-2026-84645

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as storing their configuration in independent top-level configuration files in Jenkins (such as the global configuration and jobs) can appear…

🇪🇸ESCCN-CERT2026-09-02 16:17
CVE-2026-84647

In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Stapler does not restrict the types of objects that can be instantiated via for…

🇪🇸ESCCN-CERT2026-09-02 16:17
CVE-2026-84649

In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive), except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.447 through 2.579 (both inclusive), LTS 2.452.1 through 2.568.2 (both inclusive), an H…

🇪🇸ESCCN-CERT2026-09-02 16:17
CVE-2026-84646

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user objects can appear as nested field values in other deserialized XML objects, allowing attackers with Overall/Read permission to create user objects by submittin…

🇪🇸ESCCN-CERT2026-09-02 16:17
CVE-2026-84651

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the REST API and CLI endpoints for updating agent configuration do not prevent a submitted configuration from overwriting a different agent by specifying that agent'…

🇪🇸ESCCN-CERT2026-09-02 16:17
CVE-2026-84654

In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, form data binding allows setting public static fields of the bound configuratio…

🇪🇸ESCCN-CERT2026-09-02 16:17
CVE-2026-84650

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from deserialization, allowing attackers able to submit configuration updates to specify the values of transient fields that will…

🇪🇸ESCCN-CERT2026-09-02 15:17
CVE-2026-10821

The Yoast SEO Premium WordPress plugin before 27.6.1 does not sanitize control characters from redirect origins before writing them to the site's Apache configuration file when the file-based redirect mode is enabled, an…

🇮🇹ITCSIRT Italia2026-09-02 09:51
SonicWall: rilevato sfruttamento in rete delle CVE-2026-83548 e CVE-2026-83549

Rilevato lo sfruttamento attivo in rete delle vulnerabilità CVE-2026-83548 e CVE-2026-83549 – già sanate dal vendor – presenti nel prodotto Secure Mobile Access (SMA) 1000 Series, soluzione per l'accesso remoto sicuro al…

🇦🇹ATCERT.at2026-09-02 09:46
Kritische Sicherheitslücken in SonicWall SMA1000 Series - aktiv ausgenutzt - Updates verfügbar

2.September 2026 Beschreibung In SonicWalls SMA1000 Series Appliances existieren zwei schwerwiegende Sicherheitslücken. Die schwerwiegendere der beiden Schwachstellen ermöglicht es Angreifer:innen aus der …

🇦🇹ATCERT.at2026-09-02 09:06
Kritische Sicherheitslücken in SonicWall SMA1000 Series - aktiv ausgenutzt - Updates verfügbar

2.September 2026 Beschreibung In SonicWalls SMA1000 Series Appliances existieren zwei schwerwiegende Sicherheitslücken. Die schwerwiegendere der beiden Schwachstellen ermöglicht es Angreifer:innen aus der …

🇪🇸ESINCIBE-CERT2026-09-02 08:19
Condición de carrera en el firmware de Sauter

Condición de carrera en el firmware de Sauter Mié, 02/09/2026 - 10:19 Aviso SCI Recursos Afectados Las siguientes versiones de firmware están afectadas por esta vulnerabilidad:EY-RC504F*** (ecos504): EY-modulo 5 versión …

🇪🇸ESINCIBE-CERT2026-09-02 07:38
Múltiples vulnerabilidades en productos de Rockwell Automation

Múltiples vulnerabilidades en productos de Rockwell Automation Mié, 02/09/2026 - 09:38 Aviso SCI Recursos Afectados RSLinx® Clásico, versión 4.50 y anteriores (CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625);…

🇱🇻LVCERT.LV2026-09-02 06:40
Microsoft Exchange Server ievainojamība CVE-2026-62911

Konstatēta augstas bīstamības Microsoft Exchange Server ievainojamība (CVE-2026-62911). Ievainojamību izraisa autentifikācijas apiešanas nepilnība, kas ļauj atkārtoti izmantot iepriekš pārtvertus autentifikācijas datus (…

🇪🇸ESCCN-CERT2026-09-02 04:17
CVE-2026-19754

Baserow 2.3.3 contains a SQL injection vulnerability in the index() formula function. A low-privileged authenticated user who can create or modify formula fields can provide an undocumented fourth argument that is treate…

🇪🇸ESCCN-CERT2026-09-02 03:16
CVE-2026-84442

A vulnerability was identified in MapQuest Get Directions App 10.16.1 on Android. This vulnerability affects the function getDataColumn of the file ExpoShareIntentModule.kt of the component com.mapquest.android.ace. The …

🇪🇸ESCCN-CERT2026-09-02 02:17
CVE-2026-84431

A vulnerability was detected in AirAsia MOVE App up to 12.47.1 on Android. This issue affects the function com.airasia.core.utils.RealPathUtil.getRealPath of the component com.airasia.mobile. Performing a manipulation of…

🇪🇸ESCCN-CERT2026-09-02 01:17
CVE-2026-84694

Coolify before 4.2.0 fails to properly escape environment variable key names in Docker commands executed over SSH on managed servers. Authenticated attackers can inject shell metacharacters into environment variable keys…

🇪🇸ESCCN-CERT2026-09-02 00:18
CVE-2026-84330

UI misrepresentation in FullScreen in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)

🇪🇸ESCCN-CERT2026-09-02 00:18
CVE-2026-84353

Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Ch…

🇪🇸ESCCN-CERT2026-09-02 00:18
CVE-2026-84327

Incorrect authorization in Autofill in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium securit…

🇪🇸ESCCN-CERT2026-09-02 00:18
CVE-2026-84333

Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

🇪🇸ESCCN-CERT2026-09-02 00:18
CVE-2026-84352

Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

🇫🇷FRCERT-FR2026-09-02 00:00
Multiples vulnérabilités dans les produits SonicWall (02 septembre 2026)

De multiples vulnérabilités ont été découvertes dans les produits SonicWall. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance et une falsification de requêtes côté serveur (SSRF). …

🇪🇸ESCCN-CERT2026-09-01 21:18
CVE-2026-84366

Scrapy is a high-level web crawling and scraping framework for Python. Prior to 2.17.0, in scrapy/core/downloader/handlers/s3.py, Scrapy's S3DownloadHandler converts an S3-scheme bucket and key request into a plaintext H…

🇪🇸ESCCN-CERT2026-09-01 21:18
CVE-2026-84470

A flaw was found in Ansible Automation Platform's automation-controller (AWX). The Bulk Job Launch API (POST /api/v2/bulk/job_launch/) authorizes the requested instance_groups with only a read-level permission check, whe…

🇪🇸ESCCN-CERT2026-09-01 20:17
CVE-2026-19766

An authentication bypass vulnerability exists in the underlying operating system of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated adjacent attacker to execute arbitrary code as a …

🇪🇸ESCCN-CERT2026-09-01 20:17
CVE-2026-73703

A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated adjacent attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interfa…

🇪🇸ESCCN-CERT2026-09-01 20:17
CVE-2026-73704

A command sanitization bypass exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to escalate their permissions to those of an administrat…

🇪🇸ESCCN-CERT2026-09-01 20:17
CVE-2026-73700

A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to conduct a stored cross-site scripting (XSS) attack against an administra…

🇪🇸ESCCN-CERT2026-09-01 20:17
CVE-2026-73705

An arbitrary file write vulnerability in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to escalate privileges. Successful exploitation of this vulnerability may enable…

🇪🇸ESCCN-CERT2026-09-01 20:17
CVE-2026-73702

A privilege escalation vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to escalate their permissions to those of an admi…

🇪🇸ESCCN-CERT2026-09-01 20:17
CVE-2026-73701

An unauthenticated remote code execution vulnerability exists in the underlying operating system of HPE Networking Fabric Composer and could be exploited if certain preconditions outside of the attacker's control are met…

🇪🇸ESCCN-CERT2026-09-01 19:17
CVE-2026-83551

Cleartext storage of sensitive information in the @step and @remote decorator pipeline component in Amazon SageMaker Python SDK before v3.11.0 and v2.256.0 might allow an authenticated remote user to extract the HMAC sig…

🇦🇹ATCERT.at2026-09-01 17:44
Tageszusammenfassung - 01.09.2026

End-of-Day report Timeframe: Montag 31-08-2026 18:00 - Dienstag 01-09-2026 18:00 Handler: Michael Schlagenhaufer Co-Handler: Alexander Riepl News Hackers push malicious Virtualizor update in BGP hijacking attack Hackers …

🇪🇸ESCCN-CERT2026-09-01 15:17
CVE-2026-58569

Dell PowerStore contains an Inclusion of Functionality from Untrusted Control Sphere vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary code wit…

🇪🇸ESCCN-CERT2026-09-01 15:17
CVE-2026-79686

Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to bypass access restrictions and gain escalated privilege…

🇪🇸ESCCN-CERT2026-09-01 15:17
CVE-2026-79685

Dell PowerStore contains an Argument Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to gain unauthorized access to sensitive sensitive system informati…

🇪🇸ESCCN-CERT2026-09-01 14:17
CVE-2026-58572

Dell PowerStore contains a Code Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary code with root privileges.

🇪🇸ESCCN-CERT2026-09-01 14:17
CVE-2026-79684

Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to bypass access restrictions and gain escalated privilege…

🇪🇸ESCCN-CERT2026-09-01 14:17
CVE-2026-58571

Dell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root privileges.

🇱🇻LVCERT.LV2026-09-01 14:05
Zimbra Collaboration Suite ievainojamības aktīva izmantošana uzbrukumos

Konstatēta Zimbra Collaboration Suite (ZCS) augstas bīstamības ievainojamības CVE-2026-73570 aktīva izmantošana uzbrukumos. Tā ļauj neautentificētam uzbrucējam attālināti izpildīt patvaļīgu kodu (RCE) ievainojamajā serve…

🇪🇸ESCCN-CERT2026-09-01 13:20
CVE-2026-84135

Other issue in Firefox Focus for Android. This vulnerability was fixed in Firefox 155.

🇪🇸ESCCN-CERT2026-09-01 13:20
CVE-2026-84117

Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 155.

🇪🇸ESCCN-CERT2026-09-01 13:20
CVE-2026-84127

Information disclosure in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 155.

🇪🇸ESCCN-CERT2026-09-01 13:19
CVE-2026-79683

Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to write attacker-controlled content to arbitrary filesyst…

🇪🇸ESCCN-CERT2026-09-01 13:19
CVE-2026-58575

Dell PowerStore contains an Authentication Bypass by Spoofing vulnerability. An authenticated attacker could potentially exploit this vulnerability to escalate privileges to Administrator.

🇪🇸ESCCN-CERT2026-09-01 12:17
CVE-2026-10420

Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 102d3dc75cf8e58e68e4bea54ae3c803992c91be.

🇪🇸ESCCN-CERT2026-09-01 12:17
CVE-2026-11873

An Apache-proxied Dogtag CA REST endpoint exposed by IdM (POST /ca/rest/certrequests) returns HTTP 500 with internal Java stack traces for unauthenticated malformed requests. The same unauthenticated error path emits lar…

🇪🇸ESCCN-CERT2026-09-01 12:17
CVE-2026-76111

Dell PowerStore contains an Incorrect Authorization vulnerability. An authenticated attacker with low privileges could potentially exploit this vulnerability to invoke administrator-only operations, leading to privilege …

🇪🇸ESCCN-CERT2026-09-01 11:16
CVE-2026-82927

Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 06994e303637512e39062f3e037c222e8448e57e.

🇪🇸ESCCN-CERT2026-09-01 11:16
CVE-2026-82926

NULL pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before afef59aa6f55c5d5ebf9b14bc020bf1c2c37489a.

🇪🇸ESINCIBE-CERT2026-09-01 07:54
Falta de autorización en OpenNebula de OpenNebula Systems

Falta de autorización en OpenNebula de OpenNebula Systems Mar, 01/09/2026 - 09:54 Aviso Recursos Afectados OpenNebula 7.4. Descripción INCIBE ha coordinado la publicación de una vulnerabilidad de severidad alta que afect…

Ingested from the RSS/Atom/JSON feeds catalogued on the European CERT map. Advisory titles and links belong to their issuing CERT; this is an index, not a republication.