/// All advisories are PGP-signed
Advisories
Published when something needs action from member institutions. Verify the signature against our key before acting on anything that claims to come from us.
Subscribe your security contactGet notified the moment an advisory affects your institution.
WordPress Core Page Template Local File Inclusion Leading to Remote Code Execution (Actively Exploited)
An unauthenticated path traversal vulnerability in WordPress core page-template resolution allows a remote attacker to make `get_page_template()` include an arbitrary readable local `.php` file from outside the active theme directories. On servers where additional preconditions are met, this escalates to remote code execution. The flaw affects every WordPress release from 4.7.0 through 7.1.1.
GitLab Repository Commits API Path Traversal Vulnerability (Actively Exploited)
An unauthenticated path traversal vulnerability in the GitLab repository commits API allows a remote attacker to read arbitrary files from a self-managed GitLab server
MikroTik RouterOS Exploit Chain and Related Vulnerabilities (Actively Exploited)
CERT Polska has disclosed six vulnerabilities in MikroTik RouterOS. Two of them : CVE-2026-67276 (SSH authentication bypass) and CVE-2026-86060 (SSH privilege escalation via crafted username)
PaperCut NG/MF Zero-Day Exploit Chain — Authentication Bypass and Remote Code Execution (Actively Exploited)
PaperCut has disclosed two vulnerabilities in PaperCut NG and PaperCut MF that chain into an unauthenticated remote code execution attack against the PaperCut Application Server.
Cisco Secure Firewall ASA/FTD Remote Access SSL VPN Denial of Service Vulnerability (Actively Exploited)
Unauthenticated denial-of-service vulnerability in the Remote Access SSL VPN service of Cisco Secure Firewall ASA and FTD software. A remote attacker can send a single crafted HTTP request to the RA VPN endpoint and force the appliance to reload, dropping every active VPN session and briefly taking the perimeter offline. Cisco PSIRT confirmed in-the-wild exploitation in August 2026 and CISA added CVE-2026-20349 to the Known Exploited Vulnerabilities catalog on 11 August 2026. There is no workaround.
VMware vCenter Server Remote Code Execution Vulnerability (Actively Exploited)
Critical directory-traversal vulnerability in the VMware vCenter Server Syslog service. An unauthenticated attacker with network access to vCenter can execute arbitrary code on the appliance. Broadcom disclosed the flaw in VMSA-2026-0006 on 29 July 2026; incident responders at QUIRSO GmbH observed in-the-wild exploitation five days later and to date have identified 361 compromised vCenter IPs across 47 countries. Broadcom confirms no workaround is available and patching is the only remediation.
Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query