Live advisories, alerts and public warnings published by CISA, the FBI's IC3, the UK NCSC and ENISA/CERT-EU — merged into one filterable, exportable feed for your risk and patching conversations.
Advisories in view
65
Total items retrieved
98
Distinct CVEs referenced
8
Agency feeds responding
8 / 8
Last retrieved 11 Sept 2026 at 9:38:05 pm
Filter
Search the aggregated agency feeds
Filter by publishing agency, advisory category, publication window or any keyword, CVE or vendor name, then export exactly what you see.
<p>CISA has added three new vulnerabilities to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation.</p> <ul> <li><a href="https://www.cve.org/CVERecord?id=CVE-2026-42016" target="_blank">CVE-2026-42016</a> JFrog Artifactory Incorrect Authorization Vulnerability </li> <li><a href="https://www.cve.org
<p>CISA has added one new vulnerability to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation.</p> <ul> <li><a href="https://www.cve.org/CVERecord?id=CVE-2026-85706" target="_blank">CVE-2026-85706</a> GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability</li> </ul> <p>This type of
<p>CISA has added two new vulnerabilities to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation.</p> <ul> <li><a href="https://www.cve.org/CVERecord?id=CVE-2026-67277" target="_blank">CVE-2026-67277</a> MikroTik RouterOS Missing Authentication for Critical Function Vulnerability</li> <li><a href="https:
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsma-26-253-02.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability could allow an authenticated remote attacker to write past the end of a heap allocation when Orthanc decodes an attacker-supplied PNG or JPEG image, resulting in a crash of the Orthanc process and a denial-o
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-253-01.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could allow an attacker to disclose information, brute-force hashes, or run arbitrary code in a browser session.</strong></p> <p>The following versions of AVEVA Pipeline Integrity Monitor are affected:</p>
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-183-01.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to device information or cause a denial-of-service condition.</strong></p> <p>The following versions of ST Engineering iDirect iQ-Series Terminals (Updat
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsma-26-253-01.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could allow an attacker to exfiltrate date or cause a denial-of-service condition.</strong></p> <p>The following versions of NextGen Healthcare Mirth Connect are affected:</p> <ul> <li>Mirth Connect <=v4.
<p>CISA has added four new vulnerabilities to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. </p> <ul> <li><a href="https://www.cve.org/CVERecord?id=CVE-2025-25249" target="_blank">CVE-2025-25249</a> Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability</li> <li><a href="https:/
<h2><strong>Executive summary</strong></h2> <p>China-based artificial intelligence (AI) companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns that form the core—not merely a supplement—of their AI development strategy. While “distillation” is recognized as a legitimate and useful technique i
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-251-01.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability could allow an attacker to take full control of the device.</strong></p> <p>The following versions of CareCam Pro IP Cameras are affected:</p> <ul> <li>ANJIA AJL33PC0801 Firmware linux_linux_202008261138_svn1
<p>CISA has added four new vulnerabilities to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. </p> <ul> <li><a href="https://www.cve.org/CVERecord?id=CVE-2026-75650" target="_blank">CVE-2026-75650</a> Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Eng
<p>CISA has added one new vulnerability to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. </p> <ul> <li><a href="https://www.cve.org/CVERecord?id=CVE-2026-85046" target="_blank">CVE-2026-85046</a> Google Chromium V8 Type Confusion Vulnerability</li> </ul> <p>This type of vulnerability is a fr
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-246-02.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability could allow an attacker to perform remote code execution on the computer running the client with elevated privileges.</strong></p> <p>The following versions of IXON VPN Client are affected:</p> <ul> <li>VPN C
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-246-06.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability could allow any authenticated user to create projects.</strong></p> <p>The following versions of Inductive Automation Ignition are affected:</p> <ul> <li>Ignition <=8.1.53 (CVE-2026-77393)</li> </ul> <div cla
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-246-04.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could result in a loss of webserver availability or allow an attacker to inject malicious scripts that will be executed when other users access the affected page.</strong></p> <p>The following versions of
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-169-07.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Schneider Electric is aware of a vulnerability in the following products: The Easergy C5 is a scalable and interoperable bay controller, protection and merging unit for large and critical infrastructure electrical distribution systems. The Easergy MiCOM
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-246-01.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability could allow an attacker to take control of a high-privilege terminal during installation and run arbitrary commands.</strong></p> <p>The following versions of OPCFoundation OPC UA LocalDiscoveryServer (LDS) a
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-246-03.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability could give an attacker the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level.</strong></p> <p>The following versions of Rockwe
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-246-05.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability could crash the module. The device requires a restart to recover.</strong></p> <p>The following versions of Rockwell Automation 1756-ENBT Module are affected:</p> <ul> <li>1756-ENBT module vers:all/* (CVE-202
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-246-07.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability could result in memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed.</strong></p> <p>
<p>CISA and the Group of Seven (G7) Cyber Security Working Group released <a href="https://urldefense.us/v3/__https:/cyber.gouv.fr/en/publications/jointly-led-international-publications/preparing-for-the-post-quantum-era-a-call-to-action/__;!!BClRuOV5cvtbuNI!A4T2ayZfcpa7J25BSkxtB9A-AHREvqT8FQmzhRjVarx8w3J-Vs-CBcKQcElRqsqsZqtIztYiIMY01My3HFmonToxreu7Z35ka6L8naw5xg$" target="_blank"><em>Preparing for the Post-Quantum E
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-01.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk.</strong></p> <p>The followi
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-246-08.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could allow for an attacker to perform a man-in-the-middle (MitM) attack, cause a factory reset, wipe credentials, or retrieve sensitive information.</strong></p> <p>The following versions of Tycon Systems
<p>Developed by CISA, the Federal Bureau of Investigation, and international partners, this <a href="https://www.cisa.gov/sites/default/files/2026-09/joint-guidance-communicating-under-pressure-508c.pdf" title="Communicating Under Pressure: Best Practices for Service Providers">guidance</a> describes how organizations can plan and execute clear, timely, accurate, and audience-appropriate communications during IT and
<p>CISA has added seven new vulnerabilities to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. </p> <div class="ListContainerWrapper SCXW190820602 BCX8"> <ul type="disc"> <li><a href="https://www.cve.org/CVERecord?id=CVE-2026-9586" target="_blank"><u>CVE-2026-9586</u></a> Sangoma Switchvox SQL
GCHQ’s National Cyber Security Centre and international partners issue warning as ‘LAUNDRY BEAR’ cyber threat group exposed for targeted phishing campaign