The Canadian Centre for Cyber Security published three security advisories on 2026-07-31 covering vulnerabilities in SolarWinds Web Help Desk (SAML authentication bypass), Rails Active Storage (arbitrary file read and RCE), and Google Chrome (unspecified). Administrators should review the referenced advisories and apply updates to affected versions as soon as possible.
Vulnerability
50 posts
Cyber Centre Daily Advisory Digest — 2026-07-31 (3 advisories) Cyber Centre Daily Advisory Digest — 2026-07-22 (1 advisories) The Canadian Centre for Cyber Security issued advisory AV26-728 notifying administrators of critical vulnerabilities in SolarWinds Serv-U versions 15.5.4 HF1 and earlier. SolarWinds released patches on July 21, 2026. No specific CVE identifiers, exploit techniques, or indicators of compromise are detailed in this digest; the advisory directs users to the vendor's security advisory for patch details.
Cyber Centre Daily Advisory Digest — 2026-06-23 (1 advisories) The Canadian Centre for Cyber Security issued an advisory regarding critical vulnerabilities across multiple Broadcom VMware Tanzu products, including RabbitMQ, Greenplum, and GemFire. Organizations are advised to review the Broadcom security advisories and apply the patched versions to mitigate potential exploitation risks.
Cyber Centre Daily Advisory Digest — 2026-06-22 (5 advisories) The Canadian Centre for Cyber Security published a daily digest summarizing security advisories from IBM, Ubuntu, Dell, CISA (ICS), and Red Hat. The advisories cover a wide range of enterprise software, Linux kernels, and industrial control systems requiring immediate patching to address newly disclosed vulnerabilities.
Cyber Centre Daily Advisory Digest — 2026-06-17 (3 advisories) The Canadian Centre for Cyber Security released a daily digest highlighting critical security updates from Oracle, JetBrains, and Microsoft. The advisories cover Oracle's June 2026 quarterly rollup affecting numerous enterprise products, a vulnerability in JetBrains GoLand, and an Elevation of Privilege flaw in the Microsoft Malware Protection Engine (CVE-2026-50656).
Cyber Centre Daily Advisory Digest — 2026-06-16 (3 advisories) The Canadian Centre for Cyber Security released a daily digest highlighting critical vulnerabilities across Cisco, Fortinet, and Zyxel products. Notably, CVE-2026-20262 in Cisco Catalyst SD-WAN Manager and multiple Fortinet CVEs (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) are actively being exploited in the wild, prompting immediate patching requirements.
Cyber Centre Daily Advisory Digest — 2026-06-15 (5 advisories) The Canadian Centre for Cyber Security released a daily digest summarizing five security advisories for vulnerabilities patched between June 8 and 14, 2026. The advisories cover a wide range of enterprise software, infrastructure, Linux kernels, and industrial control systems from vendors including IBM, Dell, Ubuntu, Red Hat, and various ICS manufacturers. Organizations are strongly encouraged to review the specific vendor advisories and apply necessary updates.
CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-35273) CISA has added CVE-2026-35273, a missing authentication vulnerability in Oracle PeopleSoft Enterprise PeopleTools, to its Known Exploited Vulnerabilities (KEV) catalog based on evidence of active exploitation. Federal agencies are mandated to remediate this high-risk vulnerability on publicly exposed assets under BOD 26-04, and all organizations are strongly encouraged to prioritize patching and investigate for prior compromise.
Cyber Centre Daily Advisory Digest — 2026-06-12 (4 advisories) The Canadian Centre for Cyber Security released a daily digest highlighting critical security updates for Microsoft Edge, Spring framework components, Google Chrome, and Moxa industrial computers. Notably, the Microsoft Edge update addresses CVE-2026-11645, a vulnerability with a known exploit available in the wild, necessitating urgent patching.
Naxclow IoT Platform (CVE-2026-42947, CVE-2026-50108, CVE-2026-50101 +4 more) Seven vulnerabilities, including critical flaws, have been identified in the Naxclow IoT Platform affecting various smart home devices. These vulnerabilities stem from hard-coded cryptographic keys, missing authorization, predictable identifiers, and exposed UART consoles, enabling attackers to perform device takeovers, intercept communications, and extract sensitive network credentials.
Cyber Centre Daily Advisory Digest — 2026-06-10 (6 advisories) The Canadian Centre for Cyber Security (CCCS) published a daily digest on June 10, 2026, highlighting security advisories for OpenSSL, HPE, Spring, Mozilla, FreeBSD, and AMD. Organizations are advised to review the specific product advisories and apply necessary patches to mitigate potential vulnerabilities.
Microsoft Patch Tuesday for June 2026 — Snort rules and prominent vulnerabilities Microsoft's June 2026 Patch Tuesday addresses 206 vulnerabilities, including 32 critical flaws primarily involving Remote Code Execution (RCE). Four critical vulnerabilities affecting the Remote Desktop Client, HTTP Protocol Stack, and Windows Graphics component are highlighted as more likely to be exploited, prompting immediate patching and the deployment of updated network intrusion rules.
CISA Adds Three Known Exploited Vulnerabilities to Catalog (CVE-2026-7473, CVE-2026-11645, CVE-2026-20245) CISA has added three actively exploited vulnerabilities (CVE-2026-7473, CVE-2026-11645, CVE-2026-20245) affecting Arista EOS, Google Chromium V8, and Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV) Catalog. Organizations are strongly urged to prioritize patching these systems to reduce their exposure to ongoing cyberattacks.
CISA Adds Two Known Exploited Vulnerabilities to Catalog (CVE-2026-42271, CVE-2026-50751) CISA has added CVE-2026-42271 (BerriAI LiteLLM Command Injection) and CVE-2026-50751 (Check Point Security Gateway Improper Authentication) to the Known Exploited Vulnerabilities (KEV) catalog due to active exploitation. Organizations are strongly urged to prioritize remediation of these vulnerabilities to reduce exposure to cyberattacks.
Cyber Centre Daily Advisory Digest — 2026-06-04 (2 advisories) The Canadian Centre for Cyber Security issued advisories regarding Denial of Service vulnerabilities in SolarWinds Serv-U and Web Help Desk, as well as an unspecified vulnerability in Docker Desktop. Organizations are advised to apply the latest vendor patches to mitigate potential risks.
Cyber Centre Daily Advisory Digest — 2026-06-02 (3 advisories) The Canadian Centre for Cyber Security released a daily digest highlighting security updates for Samsung mobile devices, Android devices, and HP Poly voice products. Notably, the Android June 2026 monthly rollup addresses CVE-2025-48595, which is reportedly under limited, targeted exploitation.
Cyber Centre Daily Advisory Digest — 2026-05-29 (2 advisories) The Canadian Centre for Cyber Security issued a daily digest highlighting recent security updates from Microsoft and Oracle. The advisories cover vulnerabilities in Microsoft Edge and critical flaws across several Oracle enterprise products, urging administrators to apply the latest patches to prevent potential exploitation.
Cyber Centre Daily Advisory Digest — 2026-05-28 (4 advisories) The Canadian Centre for Cyber Security released a daily digest highlighting critical security updates for Drupal, Veeam, Zimbra, and Notepad++. Notably, a highly critical arbitrary PHP code execution vulnerability (SA-CONTRIB-2026-038) was patched in the Drupal AlternativeCommerce module, requiring immediate attention from administrators.
Cyber Centre Daily Advisory Digest — 2026-05-27 (8 advisories) The Canadian Centre for Cyber Security published a daily digest of 8 security advisories on May 27, 2026. The digest highlights critical updates across multiple enterprise platforms, notably including an out-of-band patch from Microsoft for a SharePoint Remote Code Execution vulnerability (CVE-2026-45659) and a mandatory signing key rotation for GitHub Enterprise Server.
MediaArea heap-based buffer overflow vulnerabilities Cisco Talos disclosed four heap-based buffer overflow vulnerabilities in MediaArea MediaInfoLib version 26.01. These flaws (CVE-2026-25104, CVE-2026-25713, CVE-2026-28764, CVE-2026-22554) can be triggered by processing a malicious media file, potentially leading to arbitrary code execution on the host system.
Cyber Centre Daily Advisory Digest — 2026-05-26 (2 advisories) The Canadian Centre for Cyber Security issued two advisories concerning control systems. Moxa addressed multiple Linux kernel vulnerabilities (Copy Fail and Dirty Frag) across various product series, while ABB mitigated a concurrent connection handling issue in its PPT30 OPC-UA Server.
ABB Ability Camera Connect ABB Ability Camera Connect versions 1.5.0.14 and earlier contain multiple critical and high-severity vulnerabilities due to an outdated bundled VLC media player component. These flaws, including buffer overflows and integer underflows, could allow an attacker to execute arbitrary code or cause a denial of service via crafted media files. The risk is significantly reduced as the application is typically deployed in isolated, air-gapped ICS environments.
Cyber Centre Daily Advisory Digest — 2026-05-25 (7 advisories) The Canadian Centre for Cyber Security released a daily advisory digest summarizing security updates from IBM, Roundcube, Dell, Ubuntu, CISA (ICS), Red Hat, and cPanel. Organizations are strongly encouraged to review the respective vendor advisories and apply available patches to mitigate potential vulnerabilities across enterprise, cloud, and industrial control systems.
ABB B&R Automation Studio ABB has disclosed multiple vulnerabilities in B&R Automation Studio versions prior to 6.5, stemming from an outdated third-party SQLite component. These flaws, which include heap-based buffer overflows and integer overflows, could potentially be exploited to achieve remote code execution, data exposure, or denial of service, though no active exploitation has been observed.
Cyber Centre Daily Advisory Digest — 2026-05-22 (6 advisories) The Canadian Centre for Cyber Security released a daily digest of six security advisories. Notably, a highly critical SQL injection vulnerability in Drupal Core (CVE-2026-9082) is currently being exploited in the wild, and F5 has disclosed a critical vulnerability (CVE-2026-9256) affecting multiple NGINX products.
TP-Link, Photoshop, OpenVPN, Norton VPN vulnerabilities Cisco Talos disclosed a series of vulnerabilities affecting TP-Link routers, Adobe Photoshop, OpenVPN, and Norton VPN. Notably, a privilege escalation flaw in Norton VPN (CVE-2025-58074) was exploited in the wild before a patch was available, while the TP-Link flaws allow for remote code execution via command injection and buffer overflows.
Cyber Centre Daily Advisory Digest — 2026-05-14 (3 advisories) The Canadian Centre for Cyber Security issued a daily digest highlighting critical security updates for GitLab, MongoDB, and VMware Fusion. Notably, MongoDB addressed an undefined behavior vulnerability (CVE-2026-8053) in timeseries collections, and Broadcom patched a privilege escalation flaw (CVE-2026-41702) in VMware Fusion.
May’s Patch Tuesday hauls out 132 CVEs Microsoft's May 2026 Patch Tuesday release addresses 132 CVEs, including 29 Critical vulnerabilities and 14 with a CVSS score of 9.0 or higher. Key threats include a critical authentication bypass in the Microsoft SSO Plugin for Jira & Confluence, unauthorized RCEs in Windows Netlogon and DNS Client, and multiple Office RCEs exploitable via the Preview Pane.
Cyber Centre Daily Advisory Digest — 2026-05-13 (1 advisories) The Canadian Centre for Cyber Security issued an advisory (AV26-457) highlighting multiple vulnerabilities in HPE Aruba Networking Operating Systems AOS-8 and AOS-10. Organizations utilizing affected ArubaOS versions are advised to review HPE's security bulletins (HPESBNW05048 and HPESBNW05049) and apply the recommended updates.
Intelligence Center Microsoft's May 2026 Patch Tuesday addresses 137 vulnerabilities, including 31 critical flaws, 16 of which are Remote Code Execution (RCE) vulnerabilities. While no active exploitation has been observed, critical flaws affect core services like Windows Netlogon, DNS Client, and Azure Managed Instances, prompting the release of Snort detection rules by Cisco Talos.
Feeding Frenzy: RCE on Azure Cosmos for PostgreSQL Varonis Threat Labs identified a Remote Code Execution (RCE) vulnerability in Azure Cosmos for PostgreSQL caused by improper input validation of the loglineprefix parameter within the Azure management API. By utilizing form feed and newline characters, attackers could bypass single-quote restrictions to inject arbitrary PostgreSQL configurations, such as archive_command, ultimately leading to arbitrary OS command execution on the underlying managed database node.
Cyber Centre Daily Advisory Digest — 2026-05-07 (5 advisories) The Canadian Centre for Cyber Security released a daily digest highlighting five security advisories. Notably, Ivanti Endpoint Manager Mobile (EPMM) contains an actively exploited vulnerability (CVE-2026-6973), and critical updates were issued for Spring Cloud Config, VM2 Node.js library, Mozilla Firefox, and multiple Broadcom VMware Tanzu products.
Cyber Centre Daily Advisory Digest — 2026-05-06 (3 advisories) The Canadian Centre for Cyber Security released a daily digest highlighting three security advisories. The most critical is an actively exploited, unauthenticated buffer overflow vulnerability (CVE-2026-0300) affecting the Palo Alto Networks PAN-OS User-ID Authentication Portal. Additional routine security updates were announced for Google Chrome and VMware Tanzu GemFire Management Console.
Cyber Centre Daily Advisory Digest — 2026-05-05 (3 advisories) The Canadian Centre for Cyber Security released a daily digest highlighting May 2026 security rollups for Qualcomm and Android, alongside a specific advisory for Apache HTTP Server versions 2.4.66 and prior. Organizations utilizing these technologies are advised to review the respective vendor bulletins and apply available patches to mitigate potential vulnerabilities.
Cyber Centre Daily Advisory Digest — 2026-05-04 (5 advisories) The Canadian Centre for Cyber Security released a daily digest of five security advisories covering critical vulnerabilities across IBM, Dell, FreeBSD, Ubuntu, and various ICS products. Notable flaws include a Remote Code Execution vulnerability in FreeBSD via malicious DHCP options (CVE-2026-42511) and a Local Privilege Escalation via execve() (CVE-2026-7270).
Cyber Centre Daily Advisory Digest — 2026-05-01 (1 advisories) The Canadian Centre for Cyber Security issued an advisory (AV26-411) regarding unspecified vulnerabilities in Microsoft Edge Stable Channel versions prior to 147.0.3912.98. Administrators are advised to review the Microsoft release notes and apply the necessary updates to mitigate potential exploitation.
Cyber Centre Daily Advisory Digest — 2026-04-30 (2 advisories) The Canadian Centre for Cyber Security issued a daily digest highlighting recent security advisories for GitLab and GNU InetUtils. Critical vulnerabilities were addressed in GitLab CE/EE (patched in 18.11.2 and 18.10.5) and GNU InetUtils (patched in version 2.8, fixing two CVEs), requiring immediate patching by administrators.
Cyber Centre Daily Advisory Digest — 2026-04-29 (1 advisories) The Canadian Centre for Cyber Security issued an advisory highlighting unspecified vulnerabilities in Google Chrome for Desktop. Administrators are urged to update Windows, Mac, and Linux clients to the latest stable channel releases to mitigate potential exploitation.
Cyber Centre Daily Advisory Digest — 2026-04-28 (4 advisories) The Canadian Centre for Cyber Security released a daily digest highlighting recent security advisories from SmarterTools, Zyxel, Citrix, and Mozilla. Notably, Zyxel addressed command injection vulnerabilities across various networking devices, while the other vendors released standard security updates for their respective software products.
Cyber Centre Daily Advisory Digest — 2026-04-27 (9 advisories) The Canadian Centre for Cyber Security released a daily digest of nine security advisories covering critical vulnerabilities across enterprise software, Linux kernels, and industrial control systems (ICS). Organizations are urged to apply patches for affected products from vendors including IBM, Dell, Ubuntu, Red Hat, Moxa, VMware, Notepad++, and Microsoft to prevent potential exploitation.
CISA Adds Four Known Exploited Vulnerabilities to Catalog CISA has updated its Known Exploited Vulnerabilities (KEV) Catalog with four new actively exploited vulnerabilities affecting Samsung MagicINFO 9 Server, SimpleHelp, and D-Link DIR-823X devices. Organizations are strongly urged to prioritize patching these flaws, which include path traversal and command injection vectors, to reduce their exposure to cyberattacks.
Cyber Centre Daily Advisory Digest — 2026-04-23 (2 advisories) The Canadian Centre for Cyber Security published a daily digest highlighting recent security advisories for Google Chrome and GitHub Enterprise Server. Organizations are advised to patch these products to their latest versions to mitigate undisclosed vulnerabilities.
Cyber Centre Daily Advisory Digest — 2026-04-22 (2 advisories) The Canadian Centre for Cyber Security issued a daily digest highlighting two major security advisories. Notably, Microsoft released an out-of-band update to patch a critical elevation of privilege vulnerability (CVE-2026-40372) in ASP.NET Core, and GitLab released updates to address vulnerabilities across its Community and Enterprise editions.
Cyber Centre Daily Advisory Digest — 2026-04-21 (1 advisories) The Canadian Centre for Cyber Security issued an advisory regarding multiple vulnerabilities in Mozilla Firefox and Firefox ESR. Organizations are urged to update their browser deployments to Firefox 150, Firefox ESR 115.35, or Firefox ESR 140.10 to ensure protection against potential security risks.
Cyber Centre Daily Advisory Digest — 2026-04-20 (6 advisories) The Canadian Centre for Cyber Security published a daily digest of six security advisories on April 20, 2026. The advisories cover critical vulnerabilities and updates for various IBM, Dell, Ubuntu, Red Hat, and ICS/SCADA products, including a specific NTP vulnerability (CVE-2020-11868) in Moxa Ethernet switches.
CISA Adds Eight Known Exploited Vulnerabilities to Catalog CISA has added eight actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, affecting various enterprise software including PaperCut, JetBrains TeamCity, Zimbra, and Cisco Catalyst SD-WAN Manager. Organizations are strongly urged to prioritize remediation of these flaws to reduce exposure to cyberattacks.
Microsoft addresses 163 CVEs, 88 advisories for April Patch Tuesday Microsoft's April 2026 Patch Tuesday addresses 163 CVEs across 17 product families, including 8 Critical vulnerabilities and one actively exploited zero-day (CVE-2026-32201 in SharePoint). Organizations should prioritize patching the exploited SharePoint flaw, the publicly disclosed Defender bug (CVE-2026-33825), and a highly critical 9.8 CVSS RCE in Windows IKE (CVE-2026-33824).
Cyber Centre Daily Advisory Digest — 2026-04-17 (3 advisories) The Canadian Centre for Cyber Security released a daily digest highlighting recent security updates for Microsoft Edge, HashiCorp Vault, and JetBrains YouTrack. Organizations are advised to apply the necessary patches to address vulnerabilities including Denial-of-Service and Server-Side Request Forgery.
Cyber Centre Daily Advisory Digest — 2026-04-15 (4 advisories) The Canadian Centre for Cyber Security issued a daily digest highlighting critical security advisories from AMD, Splunk, Cisco, and Google. Organizations are strongly encouraged to review the vendor advisories and apply necessary updates to mitigate potential remote code execution, path traversal, and hardware-level vulnerabilities.
Intelligence Center Microsoft's April 2026 Patch Tuesday addresses 165 vulnerabilities, including 8 critical flaws and one actively exploited zero-day vulnerability in Microsoft Office SharePoint (CVE-2026-32201). The update resolves critical Remote Code Execution (RCE) vulnerabilities across various components such as the Remote Desktop Client, Microsoft Office, Windows IKE, Active Directory, and TCP/IP.