NEW#0001
Canadian Centre for Cyber Securityabout 13 hours ago4 min▣LLM reportmedium The Canadian Centre for Cyber Security published four security advisories on 2026-08-18 covering vulnerabilities in JetBrains, BeyondTrust, GitLab, and Mattermost products. The advisories list specific vulnerable versions and encourage administrators to apply updates as they become available.
NEW#0002
Canadian Centre for Cyber Security1 day ago9 min▣LLM reportcritical The Canadian Centre for Cyber Security published 7 security advisories on 2026-08-17 covering vulnerabilities in Citrix NetScaler, Apple macOS, SAP, Microsoft Edge, IBM, Tenable, and Dell products. Four CVEs across Citrix (CVE-2026-8451, CVE-2026-8452), Apple (CVE-2026-65400), and SAP (CVE-2026-58231) are confirmed exploited in the wild. Immediate patching of NetScaler ADC/Gateway, macOS, and SAP NetWeaver/ABAP systems is recommended.
NEW#0003
Canadian Centre for Cyber Security5 days ago6 min▣LLM reportmedium The Canadian Centre for Cyber Security published two security advisories on 2026-08-14. The first advisory (AV26-816) covers unspecified vulnerabilities in Zimbra Collaboration prior to version 10.1.20. The second advisory (AV26-817) addresses an arbitrary file read vulnerability in HashiCorp Vault Secrets Operator prior to version 1.5.0, tracked as HCSEC-2026-28, exploitable via the AppRole secretIDPath parameter. No CVE IDs, IOCs, or threat actor details are provided.
NEW#0004
Canadian Centre for Cyber Security6 days ago5 min▣LLM reporthigh The Canadian Centre for Cyber Security published four security advisories on August 13, 2026. The most critical is CVE-2026-20349, a high-severity denial-of-service vulnerability in Cisco ASA and FTD SSL VPN services that is being actively exploited in the wild. Additional advisories cover vulnerabilities in AMD software, GitLab, and WebPros Plesk, the latter involving a privilege escalation flaw via database cloning.
NEW#0005
Canadian Centre for Cyber Security7 days ago7 min▣LLM reporthigh This digest compiles five vendor security advisories issued by the Canadian Centre for Cyber Security on August 12, 2026, covering Google Chrome, Cisco Secure Firewall ASA/FTD, Adobe (multiple products), SonicWall Email Security/GMS, and MongoDB Driver/Server. The most urgent item is CVE-2026-20349, a Remote Access SSL VPN denial of service vulnerability in Cisco ASA and FTD software that CISA added to its Known Exploited Vulnerabilities catalog, indicating active exploitation. The remaining advisories reference vendor-published vulnerabilities without additional exploitation or technical detail provided in this digest.
#0006
Canadian Centre for Cyber Security8 days ago4 min▣LLM reporthigh The Canadian Centre for Cyber Security published advisories for vulnerabilities in Grafana, HashiCorp Vault, SAP product suites, and AMD EPYC processors. The Grafana vulnerability is tracked as CVE-2026-19516. The AMD vulnerability allows extraction of VM secrets through power side channels on SEV-ES and SEV-SNP.
#0007
Canadian Centre for Cyber Security9 days ago7 min▣LLM reporthigh The Canadian Centre for Cyber Security published 7 security advisories on 2026-08-10 covering vulnerabilities in Dell, IBM, WebPros (Plesk), HashiCorp, WordPress, Roundcube, and Cisco products. The most critical item is CVE-2026-64638 affecting WordPress prior to 7.0.3, which is reportedly being exploited in the wild. Plesk Obsidian is affected by a blind SQL injection (CVE-2026-64636). The remaining advisories cover patch releases for Dell OpenManage, IBM product suite, HashiCorp Consul, Roundcube Webmail, and Cisco Secure Endpoint connectors.
#0008
Canadian Centre for Cyber Security12 days ago5 min▣LLM reporthigh The Canadian Centre for Cyber Security published two advisories on 2026-08-07. The first covers N-able N-central vulnerabilities CVE-2026-18577 and CVE-2026-18556, both listed in CISA's KEV Database, with Hotfix 2 now available. The second advisory addresses Google Chrome vulnerabilities in versions prior to 151.0.7922.109. Both advisories recommend immediate patching.
#0009
Canadian Centre for Cyber Security13 days ago8 min▣LLM reporthigh The Canadian Centre for Cyber Security published two advisories on 2026-08-06. The first covers Zyxel ZLD firewall path traversal and AP/Security Router command injection and improper authentication vulnerabilities across multiple product lines. The second addresses 10 CVEs in Progress MarkLogic Server requiring updates to versions 11.3.6 or 12.0.3. No specific IOCs or threat actor attribution are provided; both advisories are patch-focused.
#0010
Canadian Centre for Cyber Security14 days ago4 min▣LLM reportmedium The Canadian Centre for Cyber Security published advisory AV26-778 regarding multiple vulnerabilities in HPE Networking EdgeConnect Orchestrator 9.6 branch. Affected versions include those up to and including 9.6.2.40208 and 9.6.3.40137. No specific CVE IDs or technical exploitation details are provided in this digest; administrators are directed to HPE's security bulletin for patching guidance.
#0011
Canadian Centre for Cyber Security15 days ago8 min▣LLM reporthigh The Canadian Centre for Cyber Security published a daily advisory digest on 2026-08-04 containing six vendor security advisories. The most critical item is CVE-2026-18577 in N-able N-central, which has been added to CISA's Known Exploited Vulnerabilities Database, indicating active exploitation. Other advisories cover authentication bypass in Check Point management servers, HTTP request smuggling and database privilege escalation in cPanel, and vulnerabilities across a wide range of IBM enterprise products.
#0012
Canadian Centre for Cyber Security19 days ago6 min▣LLM reporthigh The Canadian Centre for Cyber Security published three security advisories on 2026-07-31 covering vulnerabilities in SolarWinds Web Help Desk (SAML authentication bypass), Rails Active Storage (arbitrary file read and RCE), and Google Chrome (unspecified). Administrators should review the referenced advisories and apply updates to affected versions as soon as possible.
#0013
Canadian Centre for Cyber Security20 days ago9 min▣LLM reporthigh The Canadian Centre for Cyber Security published 6 security advisories covering vulnerabilities in Cisco FMC, GitLab, Spring Tools, Adobe Campaign Classic, Plesk, and Phoenix Contact ICS devices. The most critical item is CVE-2026-20316 in Cisco Secure Firewall Management Center, which involves a static credential vulnerability and is being actively exploited with placement on CISA's KEV Database. Spring Tools also has 6 CVEs including an RCE and exposed debug ports, and Plesk has a blind SQL injection in its XML-RPC API.
#0014
Canadian Centre for Cyber Security21 days ago4 min▣LLM reportmedium The Canadian Centre for Cyber Security published a daily advisory digest referencing an Adobe security bulletin covering vulnerabilities in Adobe Bridge and Format Plugins. The advisory provides only affected version ranges and links to Adobe's official bulletins (APSB26-87 and APSB26-89), without disclosing specific CVE IDs, severity, or technical exploitation details.
#0015
Canadian Centre for Cyber Security22 days ago9 min▣LLM reporthigh This digest compiles five vendor security advisories published by the Canadian Centre for Cyber Security on 2026-07-28, spanning Apache Thrift, Arista VeloCloud Orchestrator, JetBrains TeamCity, Apple's OS/software ecosystem, and Vercel's Next.js framework. The most urgent item is CVE-2026-16812 affecting Arista VeloCloud Orchestrator On-Prem, which CISA added to its Known Exploited Vulnerabilities catalog on July 27, 2026, confirming active exploitation. The remaining advisories describe vendor-disclosed vulnerabilities (decompression bombs, integer overflow, out-of-bounds read, and unspecified fixed issues) without confirmed in-the-wild exploitation at the time of publication.
#0016
Canadian Centre for Cyber Security22 days ago6 min▣LLM reporthigh This is a compilation of four vulnerability advisories issued by the Canadian Centre for Cyber Security on 2026-07-27, covering Microsoft Edge (Chromium-based), Redis, multiple Fortinet products, and Erlang/OTP. The most significant item is an update to a prior Fortinet advisory (AV26-109) noting that CISA added CVE-2025-68686 to its Known Exploited Vulnerabilities database, confirming active exploitation of a vulnerability spanning FortiAuthenticator, FortiClientWindows, FortiOS, and FortiSandbox. No technical exploitation details, IOCs, or attack narratives are provided in the advisories; they primarily direct readers to vendor patch/update resources.
#0017
Canadian Centre for Cyber Security26 days ago6 min▣LLM reportmedium This is a compiled digest of three Canadian Centre for Cyber Security advisories issued on 2026-07-24, notifying administrators of vendor-released security updates for Microsoft Edge, Google Chrome, and multiple Moxa industrial/control system product families. The advisories are notification-only, directing readers to vendor release notes and patches without providing technical exploitation details, IOCs, or threat actor attribution, except for one named CVE (CVE-2026-46333) affecting a Linux kernel component used in Moxa devices.
#0018
Canadian Centre for Cyber Security27 days ago8 min▣LLM reportcritical The Canadian Centre for Cyber Security published a daily digest on 2026-07-23 containing three security advisories. Check Point addressed CVE-2026-16232 (actively exploited, CISA KEV-listed) affecting Security Management and Firewall products. Microsoft's July 2026 monthly rollup covers a broad product surface with four CVEs confirmed exploited in the wild (CVE-2026-56164, CVE-2026-56155, CVE-2026-58644, CVE-2026-50522). JetBrains also released fixes for GoLand, IntelliJ IDEA, and PhpStorm prior to version 2026.2.
#0019
Canadian Centre for Cyber Security28 days ago5 min▣LLM reportcritical The Canadian Centre for Cyber Security issued advisory AV26-728 notifying administrators of critical vulnerabilities in SolarWinds Serv-U versions 15.5.4 HF1 and earlier. SolarWinds released patches on July 21, 2026. No specific CVE identifiers, exploit techniques, or indicators of compromise are detailed in this digest; the advisory directs users to the vendor's security advisory for patch details.
#0020
Canadian Centre for Cyber Security29 days ago9 min▣LLM reportcritical The Canadian Centre for Cyber Security published a daily digest of 5 security advisories covering Tenable Security Center, Zyxel network devices, Microsoft July 2026 patch cycle, Mozilla Firefox, and WordPress. The most urgent items are two WordPress CVEs (CVE-2026-60137, CVE-2026-63030) enabling SQL injection and RCE that are actively exploited and in CISA KEV, and four Microsoft CVEs (CVE-2026-56164, CVE-2026-56155, CVE-2026-58644, CVE-2026-50522) that are also exploited in the wild. Organizations should prioritize patching WordPress, Microsoft products, Tenable Security Center, Zyxel devices, and Mozilla Firefox to the latest versions immediately.