The Canadian Centre for Cyber Security published three security advisories on 2026-07-17 covering critical vulnerabilities in FreePBX (unauthenticated RCE and SQL injection), VMware Avi Load Balancer (seven CVEs under VMSA-2026-0005), and Google Chrome for Desktop. All advisories urge immediate patching to the latest versions.
Vulnerability Disclosure
50 posts
Cyber Centre Daily Advisory Digest — 2026-07-17 (3 advisories) Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy A chained exploit comprising three zero-day vulnerabilities in Siemens ROX II OT switches allows an attacker to escalate from arbitrary file disclosure to full persistent root-level access. CVE-2025-40948 leverages a root-privileged xz utility to read any file on the filesystem, CVE-2025-40947 exploits unsanitized input in the feature key signature verification to achieve command injection as root, and CVE-2025-40949 enables persistent code execution by injecting commands into the root cron table via the web management task scheduler. Siemens has released firmware V2.17.1 to address all three vulnerabilities.
13th July – Threat Intelligence Report This weekly threat intelligence bulletin covers multiple significant incidents including autonomous LLM-driven ransomware (JadePuffer), a cryptocurrency supply chain compromise via malicious npm packages, and three critical CVEs affecting Langflow, Tenda routers, and Linux KVM. Iran-linked Cavern Manticore and China-linked UAT-7810 were profiled targeting Israeli and networking infrastructure respectively. The report also highlights risks in AI development tools where hidden malicious instructions in open-source files could achieve RCE through Claude Code and OpenAI Codex.
WolfSSL, GeoVision, VTK vulnerabilities Cisco Talos disclosed vulnerabilities across three products: WolfSSL (3 CVEs involving improper input validation and integer underflow), GeoVision (37 CVEs across 14 advisories covering memory corruption, command injection, buffer overflows, privilege escalation, XSS, weak encryption, and authentication flaws), and VTK-DICOM (1 heap-based buffer overflow). All vulnerabilities have been patched by their respective vendors. Snort coverage is available for exploitation detection.
CVE-2026-48282: Mitigating a Critical Vulnerability in Adobe ColdFusion CVE-2026-48282 is a critical unauthenticated path traversal vulnerability in Adobe ColdFusion's RDS FILEIO handler, exploitable via the /CFIDE/main/ide.cfm?ACTION=FILEIO endpoint. An attacker can send crafted HTTP requests with traversal sequences to read or write arbitrary files on the server, potentially achieving remote code execution by writing malicious .cfm files into web-accessible directories. Adobe has released patches under bulletin APSB26-68 for affected versions (2025.9 and earlier, 2023.20 and earlier).
Cyber Centre Daily Advisory Digest — 2026-07-08 (4 advisories) The Canadian Centre for Cyber Security published four security advisories on 2026-07-08 covering Langflow, Ubiquiti UniFi, n8n, and Tanium Server. Notably, CVE-2026-55255 (an IDOR vulnerability in Langflow) has been added to CISA's KEV Database, confirming active exploitation. Ubiquiti's advisory addresses critical vulnerabilities across a broad range of UniFi hardware and software products. n8n and Tanium Server also received patches for undisclosed vulnerabilities across multiple release versions.
Rogue Agent: How a Single Code Block Could Hijack Your AI Conversations in Google’s DialogFlow Varonis Threat Labs discovered a critical vulnerability in Google Cloud Platform's Dialogflow CX service that allowed attackers with only the dialogflow.playbooks.update permission to inject persistent malicious code into the shared Cloud Run execution environment. The vulnerability enabled silent exfiltration of conversation data, bypassing VPC Service Controls, and injection of phishing prompts into chatbot conversations. Additional weaknesses included IMDS credential exposure and unrestricted outbound network access from the Cloud Run environment.
Cyber Centre Daily Advisory Digest — 2026-07-06 (8 advisories) The Canadian Centre for Cyber Security published a daily advisory digest on 2026-07-06 compiling eight security advisories from Red Hat, Ubuntu, Dell, CISA ICS, IBM, Roundcube, OpenSSH, and Microsoft Edge. The advisories address vulnerabilities across a broad range of products including Linux kernels, industrial control systems, enterprise software suites, webmail, SSH, and browser software. No specific CVEs, IOCs, or threat actor details are provided in the digest; administrators are directed to vendor advisories for patching guidance.
Cyber Centre Daily Advisory Digest — 2026-07-03 (1 advisories) The Canadian Centre for Cyber Security issued advisory AV26-649 referencing WatchGuard security advisories published on July 2, 2026. The advisories cover a race condition and use-after-free vulnerability in Mobile VPN with IKEv2 LDAP Authentication on Firebox appliances, as well as a local privilege escalation in the Mobile VPN with SSL Windows client. Multiple Fireware OS branches and the Windows VPN client are affected through several recent versions. No CVE IDs, exploit details, or IOCs are provided in the advisory digest.
Cyber Centre Daily Advisory Digest — 2026-07-02 (1 advisories) A critical deserialization vulnerability (CVE-2026-45659) in Microsoft SharePoint Server is being actively exploited, enabling remote code execution by low-privileged attackers. The flaw affects SharePoint Enterprise Server 2016, Server 2019, and Subscription Edition, with fixed versions available. CISA added this CVE to its KEV catalog on July 1, 2026, and the Canadian Cyber Centre urges immediate patching, especially for internet-exposed on-premises deployments.
Enterprise Tech In, Shell Out (Progress Kemp LoadMaster Uninitialized Heap to Pre-Auth RCE CVE-2026-8037) CVE-2026-8037 is a pre-authentication Remote Code Execution vulnerability in Progress Kemp LoadMaster caused by an uninitialized heap buffer and missing null terminator in the escape_quotes() function. When the API is enabled, an unauthenticated attacker can send a crafted POST request to /accessv2 with JSON key/value pairs that spray command injection payloads onto the heap, then use single-quote expansion in the apiuser field to overwrite adjacent allocator metadata, causing the unescaped payload to be read and executed via system().
CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451) A new pre-auth memory overread vulnerability, CVE-2026-8451 (CVSS 8.8), has been disclosed in Citrix NetScaler ADC and Gateway appliances configured as SAML Identity Providers. The flaw resides in the custom XML parser handling SAML AuthnRequest messages, where unquoted attribute values terminated by newlines cause the parser to read beyond the buffer boundaries. This leaked memory, which may include sensitive data or pointers, is returned to the attacker via the NSC_TASS cookie, and the issue can also be triggered to crash the nsppe process.
Cyber Centre Daily Advisory Digest — 2026-06-30 (4 advisories) The Canadian Centre for Cyber Security published a daily advisory digest on 2026-06-30 covering four security advisories for SimpleHelp, wolfSSL, Mozilla Firefox, and Citrix NetScaler ADC/Gateway. The most urgent item is CVE-2026-48558 in SimpleHelp, which has been added to CISA's KEV Database, indicating active exploitation. Citrix NetScaler ADC and Gateway also have multiple critical vulnerabilities across versions 13.1 and 14.1 that require immediate attention.
Cyber Centre Daily Advisory Digest — 2026-06-29 (8 advisories) The Canadian Centre for Cyber Security published a daily advisory digest on 2026-06-29 containing 8 security advisories covering Ubuntu, Red Hat, CISA ICS, Dell, IBM, Microsoft Edge, Oracle, and Apple products. The most critical item is Oracle CVE-2026-46817, which open-source reporting indicates is being actively exploited, affecting Oracle Database Server, E-Business Suite, Communications Unified Assurance, Hospitality OPERA 5, and REST Data Services. Organizations should prioritize patching Oracle products and review all applicable advisories for their environment.
Cyber Centre Daily Advisory Digest — 2026-06-26 (1 advisories) The Canadian Centre for Cyber Security issued advisory AV26-634 referencing a Google Chrome security advisory published on June 25, 2026. The advisory addresses vulnerabilities in Chrome for Desktop Stable Channel on Windows, Mac, and Linux. No specific CVE IDs, exploit details, or threat actor attribution were included in the digest; the primary action is to apply Chrome updates when available.
Cyber Centre Daily Advisory Digest — 2026-06-23 (1 advisories) The Canadian Centre for Cyber Security issued an advisory regarding critical vulnerabilities across multiple Broadcom VMware Tanzu products, including RabbitMQ, Greenplum, and GemFire. Organizations are advised to review the Broadcom security advisories and apply the patched versions to mitigate potential exploitation risks.
Cyber Centre Daily Advisory Digest — 2026-06-19 (1 advisories) The Canadian Centre for Cyber Security issued an advisory regarding multiple Denial-of-Service (DoS) vulnerabilities affecting Mitsubishi Electric MELSEC iQ-F Series EtherNet/IP and Ethernet modules. Organizations utilizing these industrial control systems should review the vendor advisories and apply the recommended updates to prevent potential operational disruptions.
Schneider Electric EasyLogic T150 and Saitel DP (CVE-2026-6865) Schneider Electric EasyLogic T150 and Saitel DP Remote Terminal Units are affected by a high-severity Path Traversal vulnerability (CVE-2026-6865, CVSS 7.1). This flaw allows authenticated attackers to access sensitive files on the device due to improper limitation of a pathname to a restricted directory. Firmware updates are available to patch the vulnerability.
Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT (CVE-2026-50034, CVE-2026-52866) Two vulnerabilities in the Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT allow an attacker within Bluetooth Low Energy (BLE) range to intercept sensitive health data in cleartext and perform a denial-of-service attack by monopolizing the device's connection slot. The vendor has not responded to coordination requests, meaning no official patch is currently available.
Cyber Centre Daily Advisory Digest — 2026-06-16 (3 advisories) The Canadian Centre for Cyber Security released a daily digest highlighting critical vulnerabilities across Cisco, Fortinet, and Zyxel products. Notably, CVE-2026-20262 in Cisco Catalyst SD-WAN Manager and multiple Fortinet CVEs (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) are actively being exploited in the wild, prompting immediate patching requirements.
Rockwell Automation FLEX I/O EtherNet/IP Adapters (CVE-2026-0646, CVE-2026-0647) Rockwell Automation FLEX I/O EtherNet/IP Adapters version 2.012 are affected by two vulnerabilities. CVE-2026-0647 allows unauthenticated account takeover via the embedded web server, while CVE-2026-0646 enables a denial-of-service condition through malformed CIP protocol requests.
Rockwell Automation RSLinx (CVE-2020-13573) Rockwell Automation RSLinx Classic versions 4.50.00 and prior contain an out-of-bounds read and stack-based buffer overflow vulnerability (CVE-2020-13573). Successful exploitation by a remote attacker can lead to a denial of service condition where the application becomes unresponsive, or potentially allow for remote code execution.
Rockwell Automation Logix 5370 & 5570 Controllers Vulnerable To Denial of Service Via CIP (CVE-2026-11317) Rockwell Automation Logix 5370 and 5570 controllers are affected by a high-severity denial-of-service vulnerability (CVE-2026-11317, CVSS 8.7) triggered by crafted Common Industrial Protocol (CIP) messages. Successful exploitation results in a major nonrecoverable fault (MNRF) due to improper resource shutdown or release, requiring a manual program download to restore operations.
Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE A critical vulnerability in the Google Cloud Vertex AI SDK for Python allows attackers to achieve cross-tenant Remote Code Execution (RCE) via bucket squatting. By predicting default staging bucket names and exploiting a lack of ownership verification, attackers can intercept model uploads and inject malicious pickle payloads, leading to the theft of highly privileged service account tokens.
CISA Adds Two Known Exploited Vulnerabilities to Catalog (CVE-2026-20262, CVE-2026-54420) CISA has added two actively exploited vulnerabilities, CVE-2026-20262 affecting Cisco Catalyst SD-WAN Manager and CVE-2026-54420 affecting the LiteSpeed cPanel Plugin, to its Known Exploited Vulnerabilities (KEV) catalog. Organizations are urged to prioritize remediation of these flaws, particularly on publicly exposed assets, and to investigate for potential pre-patch compromise in alignment with risk-based vulnerability management practices outlined in BOD 26-04.
SearchLeak: How We Turned M365 Copilot Into a One-Click Data Exfiltration Weapon Varonis Threat Labs discovered SearchLeak, a critical vulnerability chain in Microsoft 365 Copilot Enterprise Search (CVE-2026-42824). By chaining Parameter-to-Prompt (P2P) injection, an HTML rendering race condition, and a Server-Side Request Forgery (SSRF) via Bing's image search, attackers could exfiltrate sensitive organizational data via a single malicious link.
Cyber Centre Daily Advisory Digest — 2026-06-15 (5 advisories) The Canadian Centre for Cyber Security released a daily digest summarizing five security advisories for vulnerabilities patched between June 8 and 14, 2026. The advisories cover a wide range of enterprise software, infrastructure, Linux kernels, and industrial control systems from vendors including IBM, Dell, Ubuntu, Red Hat, and various ICS manufacturers. Organizations are strongly encouraged to review the specific vendor advisories and apply necessary updates.
AL25-019 - Vulnerabilities impacting Fortinet products - FortiCloud SSO Login Authentication Bypass - CVE-2025-59718 and CVE-2025-59719 - Update 2 Critical vulnerabilities in Fortinet products allow unauthenticated attackers to bypass FortiCloud SSO and SAML login authentication using crafted SAML response messages. Active exploitation has been observed in the wild, necessitating immediate patching or the disabling of the FortiCloud SSO feature and restriction of internet-facing administrative access.
CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-35273) CISA has added CVE-2026-35273, a missing authentication vulnerability in Oracle PeopleSoft Enterprise PeopleTools, to its Known Exploited Vulnerabilities (KEV) catalog based on evidence of active exploitation. Federal agencies are mandated to remediate this high-risk vulnerability on publicly exposed assets under BOD 26-04, and all organizations are strongly encouraged to prioritize patching and investigate for prior compromise.
Cyber Centre Daily Advisory Digest — 2026-06-12 (4 advisories) The Canadian Centre for Cyber Security released a daily digest highlighting critical security updates for Microsoft Edge, Spring framework components, Google Chrome, and Moxa industrial computers. Notably, the Microsoft Edge update addresses CVE-2026-11645, a vulnerability with a known exploit available in the wild, necessitating urgent patching.
Marking Your Own Homework (Check Point Remote Access VPN IKEv1 Authentication Bypass CVE-2026-50751) Check Point Remote Access VPNs are vulnerable to a critical authentication bypass (CVE-2026-50751, CVSS 9.3) within the IKEv1 key exchange process. By sending a crafted 'VPNExtFeatures' Vendor ID payload, an attacker can manipulate the negotiation state to skip certificate signature verification, allowing full network access using only a valid username and the gateway's public ICA organization string.
Cyber Centre Daily Advisory Digest — 2026-06-11 (2 advisories) The Canadian Centre for Cyber Security issued a daily digest highlighting two critical security advisories. Notably, Oracle PeopleSoft Enterprise PeopleTools is affected by CVE-2026-35273, a critical vulnerability currently being exploited in the wild, while GitLab has released patches for multiple versions of its Community and Enterprise Editions.
Brickcom Cameras (CVE-2026-50245, CVE-2026-50005) Brickcom IP cameras (version 3.2.3.5.6) contain two high-severity vulnerabilities (CVE-2026-50245 and CVE-2026-50005) involving missing authentication on the /ONVIF endpoint and the use of default credentials. Successful exploitation allows attackers with local network access to view live video feeds and potentially gain administrative control. The vendor has not responded to coordination requests, leaving the devices currently unpatched.
Naxclow IoT Platform (CVE-2026-42947, CVE-2026-50108, CVE-2026-50101 +4 more) Seven vulnerabilities, including critical flaws, have been identified in the Naxclow IoT Platform affecting various smart home devices. These vulnerabilities stem from hard-coded cryptographic keys, missing authorization, predictable identifiers, and exposed UART consoles, enabling attackers to perform device takeovers, intercept communications, and extract sensitive network credentials.
Yarbo Android/iOS Mobile Application and Cloud Infrastructure (CVE-2026-10557, CVE-2026-7368) Yarbo Android and iOS applications contain hard-coded MQTT credentials (CVE-2026-10557) that, combined with missing cloud authorization controls (CVE-2026-7368), allow attackers to access global robot telemetry and issue unauthorized commands to any device in the fleet.
From SQLi to RCE – Exploiting LangGraph’s Checkpointer Check Point Research discovered critical vulnerabilities in LangGraph's SQLite and Redis checkpointers that allow attackers to chain SQL injection with unsafe msgpack deserialization to achieve Remote Code Execution (RCE). The flaws occur when user-controlled input is passed to the getstatehistory() filter, enabling attackers to inject malicious serialized payloads that execute arbitrary OS commands upon deserialization.
Cyber Centre Daily Advisory Digest — 2026-06-10 (6 advisories) The Canadian Centre for Cyber Security (CCCS) published a daily digest on June 10, 2026, highlighting security advisories for OpenSSL, HPE, Spring, Mozilla, FreeBSD, and AMD. Organizations are advised to review the specific product advisories and apply necessary patches to mitigate potential vulnerabilities.
Security Advisory 2026-007 A critical stack-based buffer overflow vulnerability (CVE-2026-41089, CVSS 9.8) in Windows Netlogon allows unauthenticated attackers to execute arbitrary code with SYSTEM privileges on domain controllers via specially crafted packets. The vulnerability is actively being exploited in the wild, necessitating immediate patching of affected Windows Server environments.
Security Advisory 2026-008 Ivanti has disclosed two critical vulnerabilities in its Sentry products, including an OS command injection flaw (CVE-2026-10520) and an authentication bypass vulnerability (CVE-2026-10523). These vulnerabilities allow remote, unauthenticated attackers to achieve root-level remote code execution and create arbitrary administrative accounts on affected devices.
More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520) Ivanti Sentry is affected by a critical pre-authenticated OS command injection vulnerability (CVE-2026-10520) and an authentication bypass vulnerability (CVE-2026-10523). The command injection flaw allows unauthenticated attackers to achieve root-level remote code execution by sending specially crafted XML payloads to the /mics/api/v2/sentry/mics-config/handleMessage endpoint.
Microsoft Patch Tuesday for June 2026 — Snort rules and prominent vulnerabilities Microsoft's June 2026 Patch Tuesday addresses 206 vulnerabilities, including 32 critical flaws primarily involving Remote Code Execution (RCE). Four critical vulnerabilities affecting the Remote Desktop Client, HTTP Protocol Stack, and Windows Graphics component are highlighted as more likely to be exploited, prompting immediate patching and the deployment of updated network intrusion rules.
Schneider Electric EcoStruxure Panel Server (CVE-2026-6866) Schneider Electric EcoStruxure Panel Servers contain an insecure default initialization vulnerability (CVE-2026-6866, CVSS 7.5) that can lead to unauthorized authentication. Under rare circumstances, credentials may revert to initial settings, allowing attackers to access sensitive information using known default credentials.
Siemens KACO Blueplanet Inverters (CVE-2025-40946, CVE-2026-41125) Siemens KACO Blueplanet Inverters contain two vulnerabilities, including a hard-coded cryptographic key issue (CVE-2025-40946) that allows attackers to derive device credentials from serial numbers, and an SQL injection (CVE-2026-41125) in the KACO Meteor server enabling privilege escalation. Siemens has released firmware updates for select models and recommends network isolation for affected devices.
CISA Adds Two Known Exploited Vulnerabilities to Catalog (CVE-2026-42271, CVE-2026-50751) CISA has added CVE-2026-42271 (BerriAI LiteLLM Command Injection) and CVE-2026-50751 (Check Point Security Gateway Improper Authentication) to the Known Exploited Vulnerabilities (KEV) catalog due to active exploitation. Organizations are strongly urged to prioritize remediation of these vulnerabilities to reduce exposure to cyberattacks.
8th June – Threat Intelligence Report This threat intelligence report highlights active exploitation of critical vulnerabilities, including a Windows Netlogon RCE (CVE-2026-41089) and an Android Framework flaw. It also details significant data breaches affecting DentaQuest and the UN WFP, emerging AI-driven threats such as EDR evasion labs, a supply chain compromise of the Hola browser, and Iranian state-sponsored espionage operations utilizing Dutch hosting infrastructure.
Cyber Centre Daily Advisory Digest — 2026-06-05 (1 advisories) The Canadian Centre for Cyber Security released an advisory highlighting an authenticated privilege escalation vulnerability (CVE-2026-20245) affecting Cisco Catalyst SD-WAN Manager. Administrators are advised to review Cisco's security advisories and apply the necessary updates to prevent unauthorized privilege elevation within the management infrastructure.
NAVTOR NavBox (CVE-2026-21404) NAVTOR NavBox versions 4.16.1.20 and prior contain a hard-coded credentials vulnerability (CVE-2026-21404) within the Windows Communication Foundation (SOAP) implementation. A local attacker can extract these credentials to authenticate against the SOAP interface, gaining access to privileged WCF methods to write or overwrite files within application-defined paths, potentially causing operational disruption.
Hitachi Energy MACH HiDraw (CVE-2026-7310) Hitachi Energy MACH HiDraw versions 9.22 and prior contain a heap-based buffer overflow vulnerability (CVE-2026-7310, CVSS 5.5) in their XML parser functionality. An authenticated local attacker can exploit this by tricking a user into opening a crafted XML file, potentially leading to denial of service or arbitrary code execution.
When "Moderate" Means "Sometimes" Researchers disclosed an unpatched NTLM coercion vulnerability in the Windows search: URI handler that allows attackers to steal Net-NTLMv2 hashes via a malicious link or command execution. Despite sharing the same severity and underlying mechanism as a recently patched Snipping Tool vulnerability (CVE-2026-33829), Microsoft declined to service this flaw. Defenders must rely on environmental mitigations like blocking outbound SMB and restricting NTLM traffic to prevent exploitation.
CISA Adds Two Known Exploited Vulnerabilities to Catalog (CVE-2022-0492, CVE-2025-48595) CISA has updated its Known Exploited Vulnerabilities (KEV) Catalog to include CVE-2022-0492, a Linux Kernel improper authentication vulnerability, and CVE-2025-48595, an Android Framework integer overflow vulnerability, citing evidence of active exploitation in the wild.