The Canadian Centre for Cyber Security published three security advisories on 2026-07-31 covering vulnerabilities in SolarWinds Web Help Desk (SAML authentication bypass), Rails Active Storage (arbitrary file read and RCE), and Google Chrome (unspecified). Administrators should review the referenced advisories and apply updates to affected versions as soon as possible.
SolarWinds
4 posts
Cyber Centre Daily Advisory Digest — 2026-07-31 (3 advisories) Cyber Centre Daily Advisory Digest — 2026-07-22 (1 advisories) The Canadian Centre for Cyber Security issued advisory AV26-728 notifying administrators of critical vulnerabilities in SolarWinds Serv-U versions 15.5.4 HF1 and earlier. SolarWinds released patches on July 21, 2026. No specific CVE identifiers, exploit techniques, or indicators of compromise are detailed in this digest; the advisory directs users to the vendor's security advisory for patch details.
CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-28318) CISA has added CVE-2026-28318, an uncontrolled resource consumption vulnerability in SolarWinds Serv-U, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. Organizations are strongly urged to prioritize timely remediation to reduce exposure to cyberattacks.
Cyber Centre Daily Advisory Digest — 2026-06-04 (2 advisories) The Canadian Centre for Cyber Security issued advisories regarding Denial of Service vulnerabilities in SolarWinds Serv-U and Web Help Desk, as well as an unspecified vulnerability in Docker Desktop. Organizations are advised to apply the latest vendor patches to mitigate potential risks.