Skip to main content

Threat intelligence

Global threat intelligence feed

Live advisories, alerts and public warnings published by CISA, the FBI's IC3, the UK NCSC and ENISA/CERT-EU — merged into one filterable, exportable feed for your risk and patching conversations.

Advisories in view

65

Total items retrieved

98

Distinct CVEs referenced

8

Agency feeds responding

8 / 8

Last retrieved 11 Sept 2026 at 9:58:59 pm

Filter

Search the aggregated agency feeds

Filter by publishing agency, advisory category, publication window or any keyword, CVE or vendor name, then export exactly what you see.

Showing 65 of 98 published items

CISA
Advisory
United States·11 Sept 2026

CISA Adds Three Known Exploited Vulnerabilities to Catalog

<p>CISA has added three new vulnerabilities to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation.</p> <ul> <li><a href="https://www.cve.org/CVERecord?id=CVE-2026-42016" target="_blank">CVE-2026-42016</a> JFrog Artifactory Incorrect Authorization Vulnerability&nbsp;</li> <li><a href="https://www.cve.org

CVE-2026-42016
Read the CISA publication
CISA
Advisory
United States·11 Sept 2026

CISA Adds One Known Exploited Vulnerability to Catalog

<p>CISA has added one new vulnerability to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation.</p> <ul> <li><a href="https://www.cve.org/CVERecord?id=CVE-2026-85706" target="_blank">CVE-2026-85706</a> GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability</li> </ul> <p>This type of

CVE-2026-85706
Read the CISA publication
CISA
Advisory
United States·10 Sept 2026

CISA Adds Two Known Exploited Vulnerabilities to Catalog

<p>CISA has added two new vulnerabilities to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation.</p> <ul> <li><a href="https://www.cve.org/CVERecord?id=CVE-2026-67277" target="_blank">CVE-2026-67277</a> MikroTik RouterOS Missing Authentication for Critical Function Vulnerability</li> <li><a href="https:

CVE-2026-67277
Read the CISA publication
CISA
Advisory
United States·10 Sept 2026

Orthanc DICOM Server

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsma-26-253-02.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability could allow an authenticated remote attacker to write past the end of a heap allocation when Orthanc decodes an attacker-supplied PNG or JPEG image, resulting in a crash of the Orthanc process and a denial-o

Read the CISA publication
CISA
Advisory
United States·10 Sept 2026

AVEVA Pipeline Integrity Monitor

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-253-01.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could allow an attacker to disclose information, brute-force hashes, or run arbitrary code in a browser session.</strong></p> <p>The following versions of AVEVA Pipeline Integrity Monitor are affected:</p>

Read the CISA publication
CISA
Advisory
United States·10 Sept 2026

ST Engineering iDirect iQ-Series Terminals (Update A)

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-183-01.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to device information or cause a denial-of-service condition.</strong></p> <p>The following versions of ST Engineering iDirect iQ-Series Terminals (Updat

Read the CISA publication
CISA
Advisory
United States·10 Sept 2026

NextGen Healthcare Mirth Connect

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsma-26-253-01.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could allow an attacker to exfiltrate date or cause a denial-of-service condition.</strong></p> <p>The following versions of NextGen Healthcare Mirth Connect are affected:</p> <ul> <li>Mirth Connect <=v4.

Read the CISA publication
CISA
Advisory
United States·9 Sept 2026

CISA Adds Four Known Exploited Vulnerabilities to Catalog

<p>CISA has added four new vulnerabilities to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. &nbsp;</p> <ul> <li><a href="https://www.cve.org/CVERecord?id=CVE-2025-25249" target="_blank">CVE-2025-25249</a> Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability</li> <li><a href="https:/

CVE-2025-25249
Read the CISA publication
CISA
Advisory
United States·8 Sept 2026

China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies

<h2><strong>Executive summary</strong></h2> <p>China-based artificial intelligence (AI) companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns that form the core—not merely a supplement—of their AI development strategy. While “distillation” is recognized as a legitimate and useful technique i

Read the CISA publication
CISA
Advisory
United States·8 Sept 2026

CareCam Pro IP Cameras

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-251-01.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability could allow an attacker to take full control of the device.</strong></p> <p>The following versions of CareCam Pro IP Cameras are affected:</p> <ul> <li>ANJIA AJL33PC0801 Firmware linux_linux_202008261138_svn1

Read the CISA publication
CISA
Advisory
United States·8 Sept 2026

CISA Adds Four Known Exploited Vulnerabilities to Catalog

<p>CISA has added four new vulnerabilities to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. &nbsp;</p> <ul> <li><a href="https://www.cve.org/CVERecord?id=CVE-2026-75650" target="_blank">CVE-2026-75650</a> Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Eng

CVE-2026-75650
Read the CISA publication
CISA
Advisory
United States·4 Sept 2026

CISA Adds One Known Exploited Vulnerability to Catalog

<p>CISA has added one new vulnerability to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. &nbsp;</p> <ul> <li><a href="https://www.cve.org/CVERecord?id=CVE-2026-85046" target="_blank">CVE-2026-85046</a> Google Chromium V8 Type Confusion Vulnerability</li> </ul> <p>This type of vulnerability is a fr

CVE-2026-85046
Read the CISA publication
CISA
Advisory
United States·3 Sept 2026

IXON VPN Client

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-246-02.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability could allow an attacker to perform remote code execution on the computer running the client with elevated privileges.</strong></p> <p>The following versions of IXON VPN Client are affected:</p> <ul> <li>VPN C

Read the CISA publication
CISA
Advisory
United States·3 Sept 2026

Inductive Automation Ignition

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-246-06.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability could allow any authenticated user to create projects.</strong></p> <p>The following versions of Inductive Automation Ignition are affected:</p> <ul> <li>Ignition <=8.1.53 (CVE-2026-77393)</li> </ul> <div cla

CVE-2026-77393
Read the CISA publication
CISA
Advisory
United States·3 Sept 2026

Rockwell Automation ArmorStart LT

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-246-04.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could result in a loss of webserver availability or allow an attacker to inject malicious scripts that will be executed when other users access the affected page.</strong></p> <p>The following versions of

Read the CISA publication
CISA
Advisory
United States·3 Sept 2026

Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products (Update A)

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-169-07.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Schneider Electric is aware of a vulnerability in the following products: The Easergy C5 is a scalable and interoperable bay controller, protection and merging unit for large and critical infrastructure electrical distribution systems. The Easergy MiCOM

Read the CISA publication
CISA
Advisory
United States·3 Sept 2026

OPCFoundation OPC UA LocalDiscoveryServer (LDS)

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-246-01.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability could allow an attacker to take control of a high-privilege terminal during installation and run arbitrary commands.</strong></p> <p>The following versions of OPCFoundation OPC UA LocalDiscoveryServer (LDS) a

Read the CISA publication
CISA
Advisory
United States·3 Sept 2026

Rockwell Automation ControlFLASH

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-246-03.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability could give an attacker the ability to run any commands or code of the attacker&#039;s choice on a target machine at the logged-in user&#039;s permission level.</strong></p> <p>The following versions of Rockwe

Read the CISA publication
CISA
Advisory
United States·3 Sept 2026

Rockwell Automation 1756-ENBT Module

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-246-05.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability could crash the module. The device requires a restart to recover.</strong></p> <p>The following versions of Rockwell Automation 1756-ENBT Module are affected:</p> <ul> <li>1756-ENBT module vers:all/* (CVE-202

Read the CISA publication
CISA
Advisory
United States·3 Sept 2026

Pyramid Solutions NetStaX EtherNet/IP Stack

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-246-07.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability could result in memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed.</strong></p> <p>

Read the CISA publication
CISA
Advisory
United States·3 Sept 2026

Preparing for the Post-Quantum Era: A Call to Action

<p>CISA and the Group of Seven (G7) Cyber Security Working Group released <a href="https://urldefense.us/v3/__https:/cyber.gouv.fr/en/publications/jointly-led-international-publications/preparing-for-the-post-quantum-era-a-call-to-action/__;!!BClRuOV5cvtbuNI!A4T2ayZfcpa7J25BSkxtB9A-AHREvqT8FQmzhRjVarx8w3J-Vs-CBcKQcElRqsqsZqtIztYiIMY01My3HFmonToxreu7Z35ka6L8naw5xg$" target="_blank"><em>Preparing for the Post-Quantum E

Read the CISA publication
CISA
Advisory
United States·3 Sept 2026

Tycon Systems TPDIN-Monitor-WEB2 (Update A)

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-01.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk.</strong></p> <p>The followi

Read the CISA publication
CISA
Advisory
United States·3 Sept 2026

Tycon Systems TPDIN-Monitor-WEB3

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-246-08.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could allow for an attacker to perform a man-in-the-middle (MitM) attack, cause a factory reset, wipe credentials, or retrieve sensitive information.</strong></p> <p>The following versions of Tycon Systems

Read the CISA publication
CISA
Advisory
United States·2 Sept 2026

Communicating Under Pressure: Best Practices for Service Providers

<p>Developed by CISA, the Federal Bureau of Investigation, and international partners, this <a href="https://www.cisa.gov/sites/default/files/2026-09/joint-guidance-communicating-under-pressure-508c.pdf" title="Communicating Under Pressure: Best Practices for Service Providers">guidance</a> describes how organizations can plan and execute clear, timely, accurate, and audience-appropriate communications during IT and

Read the CISA publication
CISA
Advisory
United States·2 Sept 2026

CISA Adds Seven Known Exploited Vulnerabilities to Catalog

<p>CISA has added seven new vulnerabilities to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. &nbsp;</p> <div class="ListContainerWrapper SCXW190820602 BCX8"> <ul type="disc"> <li><a href="https://www.cve.org/CVERecord?id=CVE-2026-9586" target="_blank"><u>CVE-2026-9586</u></a> Sangoma Switchvox SQL

CVE-2026-9586
Read the CISA publication

Sources

Exactly which agency feeds power this page

Every item is fetched at page load directly from the agency's own published feed. Nothing is modelled or synthesised.

Cybersecurity & Infrastructure Security Agency

United States · Advisory

25 items
Open the official source

Cybersecurity & Infrastructure Security Agency

United States · News

10 items
Open the official source

FBI Internet Crime Complaint Center (IC3)

United States · Public service announcement

5 items
Open the official source

FBI Internet Crime Complaint Center (IC3)

United States · Industry alert

5 items
Open the official source

National Cyber Security Centre

United Kingdom · Advisory

20 items
Open the official source

National Cyber Security Centre

United Kingdom · News

20 items
Open the official source

ENISA / CERT-EU

European Union · Advisory

10 items
Open the official source

ENISA / CERT-EU

European Union · Threat intelligence

10 items
Open the official source

Turn these advisories into action

Fast Emu maps global agency advisories against your environment, prioritises the patching that matters and monitors for exploitation attempts.