Search/CERT EU
Source

CERT EU

Connections
32 relationships
2026-012: Critical Vulnerabilities in Check Point Products
Critical Vulnerabilities in Check Point Products History: 10/09/2026 --- v1.0 -- Initial publication Summary On 9 September 2026, Check Point released emergency security updates addressing two critical vulnerabilities affecting Check Point Security Gateway, Security Management Server, and Spark Firewall deployments configured to use Remote Access VPN or Site-to-Site VPN [1,2]. Both vulnerabilities carry a CVSS score of 9.8 and could allow an unauthenticated, remote attacker to execute arbitrary code on affected appliances [1,2]. CERT-EU strongly recommends applying the available hotfixes as soon as possible, prioritising internet-facing and perimeter appliances. Technical Details The vulnerability CVE-2026-85102, with a CVSS score of 9.8, is an improper certificate-data validation vulnerability in the VPN negotiation flow of Check Point Security Gateway that allows an unauthenticated, remote attacker to execute arbitrary code on the affected appliance [1]. The issue affects deployments using either Site-to-Site VPN or Remote Access VPN [1]. The vulnerability CVE-2026-85103, with a CVSS score of 9.8, is a heap overflow vulnerability in the VPN certificate ASN.1 decoding flow of Check Point Security Gateway and Security Management Server that allows a remote attacker to execute arbitrary code on the affected appliance [2]. Unlike CVE-2026-85102, this vulnerability affects both the Security Gateway and the Security Management Server [2]. Affected Products The following Check Point products and versions are affected [1,2]: Check Point Security Gateway — R80, R80.10, R80.20, R80.30, R80.40 (End of Support) Check Point Security Gateway — R81, R81.10 (End of Support) Check Point Security Gateway — R81.10.X Check Point Security Gateway — R81.20 Check Point Security Gateway — R82 Check Point Security Gateway — R82.00.X Check Point Security Gateway — R82.10 Check Point Security Management Server — all versions listed above Check Point Spark Firewall (Centrally Managed and Locally Managed) — all versions listed above Exploitation of CVE-2026-85102 requires the deployment to be configured with either Remote Access VPN or Site-to-Site VPN [1]. Exploitation of CVE-2026-85103 additionally affects the Security Management Server in such configurations [2]. Additional information is available in the vendor's advisories [1,2]. Recommendations CERT-EU strongly recommends that all organisations running affected Check Point products apply the available hotfixes immediately [1].
cert.europa.euSep 10, 2026source
2026-011: Critical Vulnerabilities in SAP Kernel and NetWeaver Message Server
Critical Vulnerabilities in SAP Kernel and NetWeaver Message Server History: 09/09/2026 --- v1.0 -- Initial publication. Summary On 8 September 2026, as part of its September Security Patch Day, SAP released Security Notes addressing two critical vulnerabilities affecting a broad range of SAP products [1][3]. The most severe, CVE-2026-44756 (CVSS 10.0), is a memory corruption vulnerability in SAP Extended Passport (EPP) processing, nicknamed "OVERPASS" by the Onapsis Research Labs (ORL), which discovered and responsibly disclosed it [2][3]. The second, CVE-2026-58240 (CVSS 9.8), nicknamed "S4GET", is a missing authentication check in the SAP NetWeaver Message Server [3][6]. Both are remotely exploitable without authentication. According to the reporting researchers, successful exploitation of either can result in arbitrary operating system command execution under the account that owns the SAP installation, leading to full compromise of the affected system and the business data it holds [2][6]. CERT-EU strongly recommends applying SAP Security Notes 3747649 and 3759472 as soon as possible [1]. Technical Details CVE-2026-44756 - "OVERPASS" (CVSS 10.0) CVE-2026-44756 is a memory corruption vulnerability in the SAP Kernel library that processes the Extended Passport (EPP), addressed by SAP Security Note 3747649 [1][4]. SAP's CVE record states that boundary validation is missing during the deserialisation of EPP data, and that an unauthenticated attacker can send a crafted network request containing a malformed EPP header, potentially resulting in undefined behaviour and abnormal program termination, with a high impact on confidentiality, integrity, and availability [2][3]. Onapsis, which reported the vulnerability, assesses that successful exploitation allows a remote attacker to execute arbitrary operating system commands on the SAP host with SAP administrative privileges, resulting in full compromise of the underlying SAP business data and processes [2]. CVE-2026-58240 - "S4GET" (CVSS 9.8) CVE-2026-58240 is a missing authentication check in the SAP NetWeaver Message Server (component BC-CST-MS), addressed by SAP Security Note 3759472 [1][5]. The Message Server does not sufficiently validate the authenticity of internal application server components during registration. Consequently, an unauthenticated attacker with network access can register unauthorised components and potentially perform unauthorised actions within the application environment, resulting in a high impact on the confidentiality, integrity, and availability of the affected system [3][5]. Onapsis, which also reported this vulnerability, states that an attacker can promote themselves to a trusted node inside an SAP cluster, that the Message Server propagates that trust to every application server in the cluster, and that a successful attack yields remote code execution as the operating-system user that runs SAP [6]. Onapsis notes the flaw is reachable through the same public port that SAP GUI clients connect to, which cannot be firewalled without breaking end-user logon [6]. Affected Products CVE-2026-44756 -- affected versions [1]: KRNL64NUC 7.22, 7.22EXT KRNL64UC 7.22, 7.22EXT, 7.53, 8.04 KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19, 9.20 WEBDISP 9.16, 9.18, 9.19, 9.20 CVE-2026-58240 -- affected versions [1]: KERNEL 9.16, 9.18, 9.19, 9.20 Recommendations CERT-EU strongly recommends following SAP Security Note 3747649 (CVE-2026-44756) and SAP Security Note 3759472 (CVE-2026-58240) to update the affected products to the relevant versions as soon as possible [1].
cert.europa.euSep 9, 2026source
2026-010: Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway
Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway History: 19/08/2026 --- v1.0 -- Initial publication Summary On 19 August 2026, Citrix published a security advisory addressing multiple critical vulnerabilities in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) [1]. CERT-EU recommends updating affected devices as soon as possible. Technical Details The vulnerability CVE-2026-19489 (CVSS: 8.8) is a memory overflow vulnerability that can lead to unpredictable behaviour or Denial of Service. The vulnerability CVE-2026-19490 (CVSS: 9.3) is an authentication bypass using an alternate path. Affected Products The following supported versions of NetScaler ADC and NetScaler Gateway are affected: NetScaler ADC and NetScaler Gateway version 14.1 before 14.1-73.32 NetScaler ADC and NetScaler Gateway version 13.1 before 13.1-63.21 NetScaler ADC FIPS before 14.1-73.32 FIPS NetScaler ADC FIPS and NDcPP before 13.1-37.277 The vulnerability CVE-2026-19489 requires SIP ALG(Session Initiation Protocol Application Layer Gateway) to be enabled on a Large Scale NAT (LSN) group configuration. Customers can determine if the appliance meets the precondition by inspecting their NetScaler configuration for the specified string: add lsn group.*sipalg.* The vulnerability CVE-2026-19490 requires the appliance to be configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or an AAA virtual server. On versions 14.1-43.56 or later and 13.1-61.28 or later, the issue is applicable only when a SAML action is configured; on earlier builds and 13.1 FIPS, Gateway or AAA virtual server configuration is sufficient. Customers can determine if the appliance meets the precondition by inspecting their NetScaler configuration for the specified string: SAML action configuration: add authentication samlAction.* Auth or VPN vserver: add authentication vserver .* OR add vpn vserver .* Recommendations CERT-EU recommends to install the relevant updated versions on affected devices as soon as possible [1].
cert.europa.euAug 19, 2026source
2026-009: Critical Vulnerability in Microsoft SharePoint
Critical Vulnerabilities in Microsoft SharePoint History: 22/07/2026 --- v1.0 -- Initial publication 22/07/2026 --- v1.1 -- Updated to include additional actively exploited vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644) Summary [UPDATED] On 14 July 2026, Microsoft released security updates addressing critical remote code execution (RCE) vulnerabilities in Microsoft SharePoint Server [1]. On 20 July 2026, WatchTowr identified a proof-of-concept exploit code and subsequently observed active exploitation of CVE-2026-50522 [2], a vulnerability part of an ongoing series of actively exploited flaws [3] affecting on-premise SharePoint Server instances, including CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644. CERT-EU strongly recommends updating affected servers immediately, rotating credentials for any assets that may have been exposed to the internet, and conducting a compromise assessment. Technical Details [UPDATED] The vulnerability CVE-2026-50522 (CVSS: 9.8) is a critical deserialisation vulnerability in Microsoft SharePoint that allows a remote attacker to execute arbitrary code on affected systems. While Microsoft indicates that exploitation requires some level of authentication [1], recent findings suggest this may not be the case [2, 4]. [NEW] Over the past month, Microsoft also fixed the following vulnerabilities affecting Microsoft SharePoint Server: CVE-2026-32201: An improper input validation flaw enabling spoofing attacks by an unauthorised user (CVSS: 6.5) [5]. Fixed in April 2026. CVE-2026-45659: A deserialisation of untrusted data vulnerability allowing authenticated remote code execution (CVSS: 8.8) [6]. Fixed in May 2026. CVE-2026-56164: Missing authentication for a critical function, allowing unauthenticated privilege escalation (CVSS: 9.8) [7]. Fixed in July 2026. CVE-2026-58644: A deserialisation vulnerability enabling unauthenticated remote code execution (CVSS: 9.8) [8]. Fixed in July 2026. Affected Products [UPDATED] The vulnerability CVE-2026-50522 affects the following Microsoft SharePoint products. Refer to the respective Microsoft advisories [5–8] for the full list of affected products for the other vulnerabilities. Microsoft SharePoint Server Subscription Edition Microsoft SharePoint Server 2019 Microsoft SharePoint Enterprise Server 2016 Recommendations CERT-EU strongly recommends updating affected servers as soon as possible, rotating credentials for any assets that may have been vulnerable and exposed to the internet, and conducting a compromise assessment to identify potentially affected SharePoint instances. Given the number of recent critical vulnerabilities affecting SharePoint, organisations should reconsider exposing any Microsoft SharePoint Server directly to the internet.
cert.europa.euJul 22, 2026source
2026-006: Critical Vulnerability in PAN-OS
History: 06/05/2026 --- v1.0 -- Initial publication Summary On 6 May 2026, Palo Alto published a security advisory addressing a critical vulnerability affecting PAN-OS [1]. This vulnerability allows an unauthenticated attacker to execute arbitrary code with root privileges. Palo Alto observed limited exploitation of this vulnerability. It is strongly recommended updating affected appliances as soon as patches will be available, and to apply workarounds and mitigation in the meantime. Technical Details The vulnerability CVE-2026-0300, with the CVSS score of 9.3, is a buffer overflow in the User-ID Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software. [1] An unauthenticated attacker could execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. [1] Affected Products This issue is applicable only to PA-Series and VM-Series firewalls that are configured to use User-ID Authentication Portal. The following PAN-OS versions are affected: Versions prior to 12.1.4-h5 Versions prior to 12.1.7 Versions prior to 11.2.4-h17 Versions prior to 11.2.7-h13 Versions prior to 11.2.10-h6 Versions prior to 11.2.12 Versions prior to 11.1.4-h33 Versions prior to 11.1.6-h32 Versions prior to 11.1.7-h6 Versions prior to 11.1.10-h25 Versions prior to 11.1.13-h5 Versions prior to 11.1.15 Versions prior to 10.2.7-h34 Versions prior to 10.2.10-h36 Versions prior to 10.2.13-h21 Versions prior to 10.2.16-h7 Versions prior to 10.2.18-h6 Additional information is available in the vendor’s advisory [1]. Recommendations The patches are not available at the time of writing, but are scheduled to be released in the near future. It is recommended updating affected devices as soon as the patches will be released. Mitigation It is possible to mitigate the risk of this flaw by taking either of the following actions [1]: Restrict User-ID Authentication Portal access to only trusted zones. Disable User-ID Authentication Portal if not required.
cert.europa.euMay 6, 2026source
2026-005: High Vulnerability in the Linux Kernel ("Copy Fail")
High Vulnerability in the Linux Kernel ("Copy Fail") History: 29/04/2026 --- v1.0 -- Initial publication Summary On 29 April 2026, a high local privilege escalation vulnerability in the Linux kernel, tracked as CVE-2026-31431 and named "Copy Fail", was publicly disclosed [1]. The vulnerability affects every mainstream Linux distributions shipping a kernel built since 2017. A public proof-of-concept exploit has been released. As of the date of this advisory, no distribution has shipped a fixed kernel package. The mainline fix was committed on 1 April 2026, but vendor updates are still pending across all major distributions. CERT-EU strongly recommends applying the interim mitigation immediately, prioritising Kubernetes nodes, and CI/CD runners exposed to untrusted workloads. Technical Details The vulnerability CVE-2026-31431, with a CVSS score of 7.8, is a local privilege escalation flaw in the Linux kernel's algif_aead module, the AEAD socket interface of the kernel's userspace crypto API (AF_ALG). The flaw originates from an in-place optimisation introduced in 2017 (commit 72548b093ee3), which allows page-cache pages to be placed into a writable destination scatterlist. By chaining an AF_ALG socket operation with splice(), an unprivileged local user can perform a controlled 4-byte write to an arbitrary page-cache-backed page, targeting a setuid binary such as /usr/bin/su to obtain a root shell [1]. The upstream fix is mainline commit a664bf3d603d, which reverts the 2017 optimisation. It was committed on 1 April 2026 [1]. Affected Products The vulnerability affects every mainstream Linux distribution shipping a kernel built between 2017 and the availability of the patch. The following distributions were directly verified by the researchers [1]: Other distributions running kernels in the affected range are implicitly affected, including Debian, Arch Linux, Fedora, Rocky Linux, AlmaLinux, Oracle Linux, and embedded Linux distributions. Patch availability by distribution (as of 30 April 2026): Note: Ubuntu 26.04 (Resolute) and later kernels are not affected [2]. Additional information is available in the researcher's advisory [1] and in vendor security trackers [2,3,4]. Recommendations CERT-EU strongly recommends applying the relevant kernel update as soon as possible once vendor patches become available, prioritising Kubernetes nodes and CI/CD runners. Temporary Mitigation Disable the algif_aead kernel module persistently on all affected systems until a patched kernel is available: echo "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif.conf rmmod algif_aead 2>/dev/null || true This workaround does not affect dm-crypt/LUKS, kTLS, IPsec/XFRM, OpenSSL, GnuTLS, NSS, or SSH. It may affect applications explicitly configured to use the afalg engine or that bind aead/skcipher/hash sockets directly. Exposure can be assessed with lsof | grep AF_ALG. Hardening Containerised Environments and Pipelines CERT-EU recommends blocking AF_ALG socket creation via seccomp policies on all containerised workloads and pipelines, regardless of patch status [1]. This applies to Docker and Podman-based environments [5] as well as Kubernetes clusters [6]. Since the exploit requires opening an AF_ALG socket as a first step, this measure effectively prevents exploitation even on unpatched kernels.
cert.europa.euApr 30, 2026source
2026-004: Critical Vulnerability in SharePoint Exploited
Critical Vulnerability in SharePoint Exploited History: 25/03/2026 --- v1.0 -- Initial publication Summary On 17 March 2026, Microsoft updated one of its January 2026 security advisories related to a remote code execution vulnerability in Microsoft SharePoint [1]. Specifically, Microsoft raised the CVSS score and changed the FAQ section to indicate that the vulnerability could be exploited by an unauthenticated attacker. This vulnerability was added in the CISA's Known Exploited Vulnerabilities (KEV) catalogue on 18 March 2026 [2]. Additionally, three further RCE flaws affecting Microsoft SharePoint were addressed in the March 2026 release [3,4,5]. CERT-EU strongly recommends updating SharePoint servers as soon as possible, prioritising internet-facing assets. CERT-EU also encourages IT administrators to take necessary remediation actions. Technical Details The vulnerability CVE-2026-20963, with a CVSS score of 9.8, is an unauthenticated remote code execution vulnerability in Microsoft SharePoint. The flaw is due to deserialisation of untrusted data [1]. Affected Products The vulnerability affects Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019 and Microsoft SharePoint Enterprise Server 2016. Additional information is available in the vendor's advisories [1,3,4,5]. Recommendations CERT-EU strongly recommends updating SharePoint servers as soon as possible, prioritising internet-facing assets. While no additional information is available and considering the Sharepoint exploitation campaign in 2025 for which we have issued a security advisory 2025-027 [9], CERT-EU recommends IT administrators, as a precautionary measure, to apply the same remediation steps once the concerned servers are up-to-date, namely: Enable the Antimalware Scan Interface (AMSI) in enable Full Mode [7]. Deploy an EDR solution. Rotate SharePoint Server ASP.NET machine keys [8] and restart IIS using iisreset.exe . It is also advised to conduct a compromise assessment on internet-facing assets.
cert.europa.euMar 25, 2026source
2026-003: Multiple Vulnerabilities in Citrix NetScaler and Citrix ADC
Multiple Vulnerabilities in Citrix NetScaler and Citrix ADC History: 23/03/2026 --- v1.0 -- Initial publication Summary On 23 March 2026, Citrix published a security advisory addressing multiple vulnerabilities affecting NetScaler ADC and NetScaler Gateway [1]. These vulnerabilities may lead to sensitive information disclosure and user session mix-up under specific configurations. At the time of writing, there is no public evidence of active exploitation. It is strongly recommended updating affected gateways, prioritising internet-facing assets. It is also recommended to preserve evidence for further investigation. Technical Details The advisory describes two vulnerabilities: The vulnerability CVE-2026-3055, with a CVSS score of 9.3, is an out-of-bounds read vulnerability that may result in memory overread. Successful exploitation could allow an attacker to access sensitive information from memory. This issue affects systems configured as a SAML Identity Provider (IdP) [1]. The vulnerability CVE-2026-4368, with a CVSS score of 7.7, is a race condition that may lead to user session mix-up. Exploitation could allow one user to gain access to another user’s session. This issue affects systems configured as a Gateway (e.g. SSL VPN, ICA Proxy, CVPN, RDP proxy) or AAA virtual server [1]. Affected Products The vulnerabilities affect NetScaler ADC and NetScaler Gateway versions: prior to 14.1-66.59 prior to 13.1-62.23 prior to 13.1-37.262 (FIPS and NDcPP) - only for NetScaler ADC Citrix also identified a known issue in builds 14.1-66.54 and 14.1-66.59 affecting STA server binding configuration. When the STA server is configured using the full path (/scripts/ctxsta.dll), binding may fail, impacting authentication flows [2]. Additional information is available in the vendor’s advisory [1]. Recommendations CERT-EU strongly recommends taking the following actions: restrict access to NetScaler Gateway and AAA virtual servers using network-level controls (e.g. IP allowlisting) until updates are deployed; where possible, apply Global Deny List (GDL) mitigation which enables mitigation without reboot and can help protect appliances [2]; identify internet-facing appliances configured as SAML Identity Provider (IdP) or Gateway or AAA virtual server and prioritise their remediation due to exposure to CVE-2026-3055 and CVE-2026-4368; take snapshots of the appliances before patching them, as these may be needed later for investigating possible exploitation attempts; update vulnerable appliances; terminate all active and persistent sessions after patching to prevent attackers from reusing potentially compromised session tokens: kill aaa session -all kill icaconnection -all kill rdp connection -all kill pcoipConnection -all clear lb persistentSessions
cert.europa.euMar 23, 2026source
2026-002: Multiple Vulnerabilities in Cisco Products
History: 25/02/2026 --- v1.0 -- Initial publication Summary On 25 February 2026, Cisco released security advisories addressing multiple high and critical severity vulnerabilities in Cisco Catalyst SD-WAN controllers and Cisco SD-WAN Manager [1,2]. If exploited, these vulnerabilities could allow attackers to gain administrative access to compromised systems. It is recommended to capture forensic evidence, hunt for indicators of compromise, and apply updates as soon as possible. One of the vulnerabilities, CVE-2026-20127, is exploited in the wild since 2023. [4] Technical Details Vulnerabilities Affecting Cisco Catalyst SD-WAN Controller The vulnerability CVE-2026-20127, with the CVSS score of 10, is an authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vManager. Successful exploitation allows a remote, unauthenticated attacker to obtain administrative privileges on the device. [1] An attacker could then modify configurations, add rogue devices to the SD-WAN fabric, extract sensitive configuration data, or establish persistent access. [1] This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric. [1] Vulnerabilities Affecting Cisco Catalyst SD-WAN Manager Multiple vulnerabilities in Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an attacker to access an affected system, elevate privileges to root, gain access to sensitive information, and overwrite arbitrary files. [2] The vulnerabilities are not dependent on one another. Exploitation of one of the vulnerabilities is not required to exploit another vulnerability. The vulnerability CVE-2026-20129, with a CVSS score of 9.8, is an authentication bypass vulnerability in the API user authentication of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain access to an affected system as a user who has the netadmin role. [2] The vulnerability CVE-2026-20126, with a CVSS score of 7.8, is a privilege escalation vulnerability which could allow an authenticated, local attacker with low privileges to gain root privileges on the underlying operating system. This vulnerability is due to an insufficient user authentication mechanism in the REST API. An attacker could exploit this vulnerability by sending a request to the REST API of the affected system. A successful exploit could allow the attacker to gain root privileges on the underlying operating system. [2] The vulnerability CVE-2026-20133, with a CVSS score of 7.5, is an information disclosure vulnerability which could allow an unauthenticated, remote attacker to view sensitive information on an affected system. This vulnerability is due to insufficient file system access restrictions. An attacker could exploit this vulnerability by accessing the API of an affected system. [2] The vulnerability CVE-2026-20122, with a CVSS score of 7.1, is an arbitrary file overwrite vulnerability in the API which could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. To exploit this vulnerability, the attacker must have valid read-only credentials with API access on the affected system. This vulnerability is due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmanage user privileges. [2] The vulnerability CVE-2026-20128, with a CVSS score of 5.5, is an information disclosure vulnerability in the Data Collection Agent (DCA) feature which could allow an authenticated, local attacker to gain DCA user privileges on an affected system. To exploit this vulnerability, the attacker must have valid vmanage credentials on the affected system. This vulnerability is due to the presence of a credential file for the DCA user on an affected system. An attacker could exploit this vulnerability by accessing the file system as a low-privileged user and reading the file that contains the DCA password from that affected system. [2] Affected Products The following versions of the Cisco Catalyst SD-WAN Controller and Cisco Catalyst SD-WAN Manager are affected: all versions earlier than 20.9 (end of software maintenance); all versions 20.9 up until 20.9.8.2; all versions 20.11 (end of software maintenance); all versions 20.12.5 up until 20.12.5.3; all versions 20.12.6 up until 20.12.6.1; all versions 20.13 (end of software maintenance); all versions 20.14 (end of software maintenance); all versions 20.15 up until 20.15.4.2; all versions 20.16 (end of software maintenance); all versions 20.18 up until 20.18.2.1. Organisations are encouraged to consult the Cisco Catalyst SD-WAN Upgrade Matrix. Recommendations CERT-EU recommends the following immediate actions: Securing forensic evidence to detect any signs of exploitation as well as reviewing SD-WAN configuration to find any unauthorised changes, following the hunting guide. [4] Update affected devices to the appropriate fixed latest version of Cisco Catalyst SD-WAN Manager and Cisco Catalyst SD-WAN Controller as detailed in their respective advisories. [1,2] Identify and restrict external access to SD-WAN management (HTTPS, SSH, API) and control plane interfaces. Remove direct internet exposure and limit access to dedicated management networks by following Cisco's hardening guide. [6] The hunting guide [4] further notes that, in observed exploitation cases, threat actors downgraded SD-WAN Manager to a software version vulnerable to CVE-2022-20775 in order to facilitate privilege escalation and establish persistence by creating local accounts. [3,4] If a compromise is suspected, and after ensuring that forensic evidence is secured, contact the relevant cybersecurity authority. Indicators of Compromise Organisations are encouraged perform the following checks to identify possible exploitation of the vulnerability CVE-2026-20127: Audit authentication logs in the auth.log file, located at /var/log/auth.log, for entries that are related to Accepted publickey for vmanage-admin from unknown or unauthorised IP addresses, as shown in the following example: 2026-02-10T22:51:36+00:00 vm sshd[804]: Accepted publickey for vmanage-admin from port [REDACTED PORT] ssh2: RSA SHA256:[REDACTED KEY] - Validate peering events against the following checklist: - Verify the timestamp of each peering event against known maintenance windows, scheduled configuration changes, and normal operational hours. - Confirm the public IP address corresponds to infrastructure owned or operated by authorised organisation or partners by cross-referencing against asset inventories and authorised IP ranges. - Validate that the peer system IP matches documented device assignments within the SD-WAN topology. - Review the peer type (vmanage, vsmart, vedge, vbond) to ensure it aligns with expected device roles in the related deployment. - Correlate multiple events from the same source IP or system IP to identify patterns of reconnaissance or persistent access attempts. - Cross-reference event timing with authentication logs, change management records, and user activity to establish whether the connection was initiated by authorised personnel. Jul 26 22:03:33 vSmart-01 VDAEMON_0[2571]: %Viptela-vSmart-VDAEMON_0-5-NTCE-1000001: control-connection-state-change new-state:up peer-type:vmanagepeer-system-ip:[PRIVATE IP] public-ip:[PUBLIC IP] public-port:[PUBLIC PORT] domain-id:1 site-id:1005 More information and indicators of compromise are available in the hunting guide. [4]
cert.europa.euFeb 26, 2026source
2025-042: Critical Vulnerability in Cisco Secure Email and Web Manager
Critical Vulnerability in Cisco Secure Email and Web Manager History: 18/12/2025 --- v1.0 -- Initial publication Summary On December 17, 2025, Cisco released a security advisory for a critical vulnerability affecting Cisco Secure Email Gateway and Cisco Secure Email and Web Manager products [1]. It is recommended to follow Cisco's recommendations to check whether vulnerable appliances have been compromised, and to remediate the issue. There is no patch available for this vulnerability yet. Technical Details While there is not much technical details about the vulnerability CVE-2025-20393, with a CVSS score of 10, Cisco reveals that it allows attackers to execute arbitrary commands with root privileges on the underlying operating system of an affected appliance. Affected Products This vulnerability affects Cisco Secure Email Gateway, both physical and virtual, and Cisco Secure Email and Web Manager appliances, both physical and virtual, when both of the following conditions are met [1]: The appliance is configured with the Spam Quarantine feature. The Spam Quarantine feature is exposed to and reachable from the internet. Recommendations It is recommended to check if Cisco Secure Email Gateway and Cisco Secure Email and Web Manager appliances are configured with the Spam Quarantine feature, and if they are, that the feature is not reachable from the internet. If it is the case, it is recommended to open a Cisco Technical Assistance Center (TAC) case to verify whether an appliance has been compromised [1]. It is also recommended to follow Cisco's recommendations to remediate the issue [1]: Restore the appliance to a secure configuration when possible. Restrict access to the appliance and implement robust access control mechanisms. In case the appliance was found to be compromised, it is recommended to investigate further any lateral movement that may have occurred within the network.
cert.europa.euDec 18, 2025source
2025-041: Critical Security Vulnerability in React Server Components
Critical Security Vulnerability in React Server Components History: 04/12/2025 --- v1.0 -- Initial publication Summary On December 3, 2025, the React Team publicly disclosed a critical security vulnerability affecting React Server Components (RSC) and related packages. The vulnerability allows for unauthenticated remote code execution (RCE) via maliciously crafted HTTP requests [1]. It is recommended to update all affected component packages and any frameworks that integrate them. Technical Details The vulnerability CVE-2025-55182, with a CVSS score of 10, is due to unsafe deserialisation of payloads from HTTP requests to React Server Function endpoints. It allows for unauthenticated remote code execution (RCE) via maliciously crafted HTTP requests [1]. React Server Functions allow a client to call a function on a server. React provides integration points and tools that frameworks and bundlers use to help React code run on both the client and the server. React translates requests on the client into HTTP requests which are forwarded to a server. On the server, React translates the HTTP request into a function call and returns the needed data to the client [1]. Affected Products The vulnerability is present in versions 19.0, 19.1.0, 19.1.1, and 19.2.0 of the following React Server Components packages: react-server-dom-webpack react-server-dom-parcel react-server-dom-turbopack Any framework or tool that integrates React Server Components using the affected packages may inherit the vulnerability. Confirmed affected ecosystem components include: Next.js App Router (multiple impacted versions) RSC plugin for Vite RSC plugin for Parcel React Router’s unstable RSC APIs Redwood SDK Waku Any third-party project bundling vulnerable react-server-dom-* packages Recommendations It is recommended updating affected React Server Components packages to a fixed version (19.0.1, 19.1.2, or 19.2.1) as soon as possible. Depending on the affected ecosystem in use, the React Team provided additional instruction [1].
cert.europa.euDec 4, 2025source
2025-038: Critical Vulnerabilities in Veeam Backup
History: 15/10/2025 --- v1.0 -- Initial publication Summary On October 14, 2025, Veeam released a security advisory addressing multiple vulnerabilities including 2 critical in its Veeam Backup product [1]. CERT-EU recommends updating affected software as soon as possible and following Veeam implementation best practices [2]. Technical Details The vulnerability CVE-2025-48983, with a CVSS score of 9.9, resides in the Mount service of Veeam Backup & Replication and allows an authenticated domain user to execute arbitrary code on backup infrastructure hosts. The vulnerability CVE-2025-48984, with a CVSS score of 9.9, allows an authenticated domain user to execute arbitrary code remote code execution (RCE) on the Backup Server. The vulnerability CVE-2025-48982, with a CVSS score of 7.3, resides in Veeam Agent for Microsoft Windows and allows for Local Privilege Escalation if a system administrator is tricked into restoring a malicious file. Affected Products The vulnerabilities CVE-2025-48983 and CVE-2025-48984 impact Veeam Backup & Replication 12.3.2.3617 and all earlier version 12 builds. They only impact domain-joined backup servers. The vulnerability CVE-2025-48982 impacts Veeam Agent for Microsoft Windows 6.3.2.1205 and all earlier version 6 builds. The vendor mentions that unsupported product versions are not tested, but are likely affected and should be considered vulnerable. Recommendations It is recommended updating affected products as soon as possible and following Veeam implementation best practices [2].
cert.europa.euOct 15, 2025source
2025-037: Multiple Vulnerabilities in F5 Products
History: 15/10/2025 --- v1.0 -- Initial publication Summary On October 15, 2025, F5 disclosed that a sophisticated nation-state actor breached its systems and maintained long-term persistent access into F5's infrastructure [1]. This included access to BIG-IP product development source code and to information related to security vulnerabilities that had not yet been disclosed nor patched. F5 released patches on the same day to address the vulnerabilities [2]. There is currently no known exploitation of these vulnerabilities. CERT-EU strongly recommends to patch affected F5 products as soon as possible. Technical Details The vulnerability CVE-2025-53868, with a CVSS score of 8.5, is affecting all modules of BIG-IP and could allow a highly privileged authenticated attacker with access to Secure Copy (SCP) protocol and SFTP to bypass Appliance mode restrictions using undisclosed commands. [3] The vulnerability CVE-2025-61955 and CVE-2025-57780, with a CVSS score of 8.5, are affecting F5OS and could allow an authenticated attacker with local access to escalate their privileges. A successful exploit may allow the attacker to cross a security boundary. [4,5] The exhaustive list of vulnerabilities can be found in the F5 Quarterly Security Notification. Affected Products BIG-IP, F5OS, BIG-IP Next for Kubernetes, BIG-IQ, and APM are affected by the vulnerabilities [1]. Refer to F5's advisory for the list of all affected products. [2] Recommendations CERT-EU recommends to apply updates on affected F5 products as soon as possible.
cert.europa.euOct 15, 2025source
2025-036: Critical Vulnerabilities in Cisco ASA and FTD
History: 26/09/2025 --- v1.0 -- Initial publication 26/09/2025 --- v1.1 -- Added information about vulnerable configuration Summary On September 25, 2025, Cisco released several security advisories addressing 3 vulnerabilities, 2 of which are critical [1,2,3,4]. Cisco warns that some of those vulnerabilities are exploited in the wild and assesses with high confidence that this new activity is related to the same threat actor as the ArcaneDoor attack campaign that Cisco reported in early 2024 [4]. It is recommended running compromise assessment on Internet facing vulnerable devices, and update as soon as possible. Technical Details The vulnerability CVE-2025-20333, with a CVSS score of 9.9, is due to improper validation of user-supplied input in HTTP(S) requests. An attacker with valid VPN user credentials could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as root, possibly resulting in the complete compromise of the affected device. This vulnerability affects the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software [1]. The Cisco PSIRT is aware of attempted exploitation of this vulnerability. The vulnerability CVE-2025-20363, with a CVSS score of 9.0, is due to improper validation of user-supplied input in HTTP requests. An attacker could exploit this vulnerability by sending crafted HTTP requests to a targeted web service on an affected device after obtaining additional information about the system, overcoming exploit mitigations, or both. A successful exploit could allow the attacker to execute arbitrary code as root, which may lead to the complete compromise of the affected device. This vulnerability affects the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software [2]. The Cisco PSIRT is not aware of any public announcements or malicious use of this vulnerability. The vulnerability CVE-2025-20362, with a CVSS score of 6.5, is due to improper validation of user-supplied input in HTTP(S) requests. An attacker could exploit this vulnerability by sending crafted HTTP requests to a targeted web server on a device. A successful exploit could allow the attacker to access a restricted URL without authentication. This vulnerability affects the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software [3]. The Cisco PSIRT is aware of attempted exploitation of this vulnerability. Affected Products [UPDATED] The following versions of Cisco ASA and FTD are affected by all 3 vulnerabilities (refer to the [[NEW] Vulnerable configurations] subsection for more information): Cisco ASA: - version 9.16 before 9.16.4.85 - version 9.17 - version 9.18 before 9.18.4.67 - version 9.19 - version 9.20 before 9.20.4.10 - version 9.22 before 9.22.2.14 - version 9.23 before 9.23.1.19 Cisco FTD: - version 7.0 before 7.0.8.1 - version 7.1 - version 7.2 before 7.2.10.2 - version 7.3 - version 7.4 before 7.4.2.4 - version 7.6 before 7.6.2.1 - version 7.7 before 7.7.10.1 The IOS, IOS XE, and IOS XR Software are also vulnerable to CVE-2025-20363 [2] (refer to the [[NEW] Vulnerable configurations] subsection for more information). Customers should use the Cisco Software Checker to determine the appropriate patched release for their specific software train. [NEW] Vulnerable Configurations CVE-2025-20333 and CVE-2025-20362 Please refer to the Cisco's advisory for CVE-2025-20333 and the Cisco's advisory for CVE-2025-20362 for more detailed information on how to check device configuration. Cisco Secure Firewall ASA Software Vulnerable Configurations Cisco lists the following Cisco Secure Firewall ASA Software features as potentially vulnerable: AnyConnect IKEv2 Remote Access (with client services) Mobile User Security (MUS) SSL VPN Cisco Secure Firewall FTD Software Vulnerable Configurations Cisco lists the following Cisco Secure Firewall FTP Software features as potentially vulnerable: AnyConnect IKEv2 Remote Access (with client services) AnyConnect SSL VPN CVE-2025-20363 Please refer to Cisco's advisory for more detailed information on how to check device configuration. Cisco Secure Firewall ASA Software Vulnerable Configurations Cisco lists the following Cisco Secure Firewall ASA Software features as potentially vulnerable: Mobile User Security (MUS) SSL VPN Cisco Secure Firewall FTD Software Vulnerable Configurations Cisco lists the following Cisco Secure Firewall FTP Software features as potentially vulnerable: AnyConnect SSL VPN Cisco IOS and IOS XE Software Vulnerable Configurations Cisco lists the following Cisco Secure Firewall FTP Software features as potentially vulnerable: Remote Access SSL VPN IOS XR Software Cisco lists the following Cisco Secure Firewall FTP Software features and configuration as potentially vulnerable: 32-bit version Running on Cisco ASR 9001 Routers HTTP server enabled Recommendations It is recommended running compromise assessment on Internet facing vulnerable devices, and update as soon as possible.
cert.europa.euSep 26, 2025source
2025-035: High Vulnerability in Cisco IOS and IOS XE Software
High Vulnerability in Cisco IOS and IOS XE Software History: 26/09/2025 --- v1.0 -- Initial publication Summary On September 24, 2025, Cisco released a security advisory regarding a high severity vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software. The vulnerability is being exploited in the wild [1]. It is recommended updating as soon as possible and conduct a compromise assessment on devices that are exposing SNMP on the Internet. It is also recommended not allowing access to SNMP over untrusted network (i.e. on the Internet). Technical Details The vulnerability CVE-2025-20352, with a CVSS score of 7.7, lies in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software and is due to a stack overflow condition in the SNMP subsystem. An attacker could exploit this vulnerability by sending a crafted SNMP packet to an affected device over IPv4 or IPv6 networks [1]. Exploitation of the vulnerability could allow the following: An authenticated, remote attacker with low privileges could cause a denial of service (DoS) condition on an affected device that is running Cisco IOS Software or Cisco IOS XE Software. To cause the DoS, the attacker must have the SNMPv2c or earlier read-only community string or valid SNMPv3 user credentials. An authenticated, remote attacker with high privileges could execute code as the root user on an affected device that is running Cisco IOS XE Software. To execute code as the root user, the attacker must have the SNMPv1 or v2c read-only community string or valid SNMPv3 user credentials and administrative or privilege 15 credentials on the affected device. An attacker could exploit this vulnerability by sending a crafted SNMP packet to an affected device over IPv4 or IPv6 networks. Affected Products This vulnerability affects Cisco devices if they are running a vulnerable release of Cisco IOS Software or Cisco IOS XE Software. Customers should use the Cisco Software Checker to determine the appropriate patched release for their specific software train [1]. Meraki MS390 and Cisco Catalyst 9300 Series Switches that are running Meraki CS 17 and earlier are also affected. This is fixed in Cisco IOS XE Software Release 17.15.4a [1]. Recommendations It is recommended updating as soon as possible and conduct a compromise assessment on devices that are exposing SNMP on the Internet. It is also recommended not allowing access to SNMP over untrusted network (i.e. on the Internet) [1].
cert.europa.euSep 26, 2025source
2025-033: Critical Vulnerabilities in Citrix NetScaler Products
Critical Vulnerabilities in Citrix NetScaler Products History: 26/08/2025 --- v1.0 -- Initial publication Summary On 26 August 2025, Citrix released a security advisory addressing one critical and two high severity vulnerabilities in NetScaler ADC and NetScaler Gateway [1]. Citrix warns that exploits of the critical vulnerability, CVE-2025-7775, have been observed on unmitigated appliances. It is recommended to update affected assets as soon as possible. Technical Details The vulnerability CVE-2025-7775, with a CVSS score of 9.2, is due to improper restriction of operations within the bounds of a memory buffer, leading to Remote Code Execution (RCE) and/or Denial of Service [1]. To be exploitable, NetScaler must have one of the following configurations: Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB virtual servers of type (HTTP, SSL or HTTP_QUIC) bound with IPv6 services or servicegroups bound with IPv6 servers NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB virtual servers of type (HTTP, SSL or HTTP_QUIC) bound with DBS IPv6 services or servicegroups bound with IPv6 DBS servers CR virtual server with type HDX The vulnerability CVE-2025-7776, with a CVSS score of 8.8, is due to improper restriction of operations within the bounds of a memory buffer, leading to unpredictable or erroneous behaviour and Denial of Service. To be exploitable, NetScaler must be configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) with PCoIP Profile bounded to it. The vulnerability CVE-2025-8424, with a CVSS score of 8.7, is due to improper access control. To exploit this vulnerability, it is necessary for an attacker to have access to the NSIP address, the Cluster Management IP or the local GSLB Site IP, or SNIP with Management Access. Affected Products The following products are affected by the vulnerabilities [1]: NetScaler ADC and NetScaler Gateway 14.1 BEFORE 14.1-47.48 NetScaler ADC and NetScaler Gateway 13.1 BEFORE 13.1-59.22 NetScaler ADC 13.1-FIPS and NDcPP BEFORE 13.1-37.241-FIPS and NDcPP NetScaler ADC 12.1-FIPS and NDcPP BEFORE 12.1-55.330-FIPS and NDcPP Note: NetScaler ADC and NetScaler Gateway versions 12.1 and 13.0 are now End Of Life (EOL) and remain vulnerable. Recommendations It is recommended updating as soon as possible to the latest version of NetScaler ADC and NetScaler Gateway. CVE-2025-7775 Customers can determine if they have an appliance configured as one of the following by inspecting their NetScaler Configuration for the specified strings An Auth Server (AAA Vserver): add authentication vserver .* A Gateway (VPN Vserver, ICA Proxy, CVPN, RDP Proxy): add vpn vserver .* LB vserver of Type HTTP_QUIC|SSL|HTTP bound with IPv6 services or servicegroups bound with IPv6 servers: enable ns feature lb.* add serviceGroup .* (HTTP_QUIC|SSL|HTTP) .* add server .* bind servicegroup .* add lb vserver .* (HTTP_QUIC|SSL|HTTP) .* bind lb vserver .* LB vserver of Type HTTP_QUIC|SSL|HTTP bound with DBS IPv6 services or servicegroups bound with IPv6 DBS servers: enable ns feature lb.* add serviceGroup .* (HTTP_QUIC | SSL | HTTP) .* add server .* -queryType AAAA add service .* bind servicegroup .* add lb vserver .* (HTTP_QUIC | SSL | HTTP) .* bind lb vserver .* CR vserver with type HDX: add cr vserver .* HDX .* CVE-2025-7776 Customers can determine if they have an appliance configured as Gateway (VPN vserver) with PCoIP Profile bounded to it, by inspecting their ns.conf file for the specified strings: add vpn vserver .* -pcoipVserverProfileName .*
cert.europa.euAug 26, 2025source
2025-032: Multiple Vulnerabilities in Microsoft Products
Multiple Vulnerabilities in Microsoft Products History: 18/08/2025 --- v1.0 -- Initial publication Summary On August 13, 2025, Microsoft released its August 2025 Patch Tuesday advisory addressing 111 security flows in various products among which 16 are rated as critical [1]. It is recommended updating as soon as possible, prioritising public facing and critical assets. Technical Details Below are listed the notable vulnerabilities among those rated as critical by Microsoft: The vulnerability CVE-2025-50176, with a CVSS score of 7.8, is due to a type confusion flaw in the DirectX Graphics Kernel allowing an authenticated attacker to execute code locally [2]. The vulnerability CVE-2025-50165, with a CVSS score of 9.8, is due to the use of untrusted pointer dereference in Microsoft Graphics Component allowing an authenticated attacker to execute code over a network without user interaction [3]. The vulnerabilities CVE-2025-53740 and CVE-2025-53731, with a CVSS score of 8.4, are use after free security flaws in Microsoft Office, and allow a remote attacker to execute code locally. Microsoft confirmed that the Preview Pane is also an attack vector [4,5]. The vulnerabilities CVE-2025-53784 and CVE-2025-53733, with a CVSS score of 8.4, are use after free security flaws in Microsoft Word, and allow a remote attacker to execute code locally. Microsoft confirmed that the Preview Pane is also an attack vector [6,7]. The vulnerability CVE-2025-48807, with a CVSS score of 7.5, is due to improper restriction of communication channel to intended endpoints in Windows Hyper-V allowing an authenticated attacker to execute code locally. The vulnerable endpoint is only available over the local VM interface as all external communication is blocked. This means an attacker needs to execute code from the local machine to exploit the vulnerability. This vulnerability also requires an interaction from an administrator [8]. The vulnerability CVE-2025-53766, with a CVSS score of 9.8, is a heap-based buffer overflow flaw in Windows GDI+ an unauthenticated attacker to execute code over a network. An attacker doesn't require any privileges on the systems hosting the web services. Successful exploitation of this vulnerability could cause Remote Code Execution or Information Disclosure on web services that are parsing documents that contain a specially crafted metafile, without the involvement of a victim user. An attacker could trigger this vulnerability by convincing a victim to download and open a document that contains a specially crafted metafile. In the worst-case scenario, an attacker could trigger this vulnerability on web services by uploading documents containing a specially crafted metafile without user interaction [9]. The vulnerability CVE-2025-50177, with a CVSS score of 8.1, is a use after free vulnerability in Windows Message Queuing allowing an unauthenticated attacker to execute code over a network. To exploit this vulnerability, an attacker would need to send a series of specially crafted MSMQ packets in a rapid sequence over HTTP to a MSMQ server. This could result in remote code execution on the server side [10]. The vulnerability CVE-2025-53778, with a CVSS score of 8.8, is due to improper authentication in Windows NTLM and allows an authenticated attacker to elevate privileges over a network. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges [11]. Affected Products Microsoft Office, Office Word and Microsoft Windows are affected by the vulnerabilities described above. For the list of all products affected, refer to Microsoft's advisory [1]. Recommendations It is recommended updating as soon as possible, prioritising public facing and critical assets.
cert.europa.euAug 18, 2025source
2025-031: Multiple Vulnerabilities in Fortinet Products
History: 13/08/2025 --- v1.0 -- Initial publication Summary On August 12, 2025, Fortinet released security advisories addressing several vulnerabilities, including a critical one exploited in the wild, and two high severity ones. It is recommended updating as soon as possible. Technical Details The vulnerability CVE-2025-25256, with a CVSS score of 9.8, is due to improper neutralisation of special elements used in an OS command and allows a remote unauthenticated attacker to execute unauthorised code or commands via crafted CLI requests. The vulnerability is known to be exploited in the wild [1]. The vulnerability CVE-2024-26009, with a CVSS score of 7.9, is an authentication bypass using an alternate path or channel vulnerability and may allow an unauthenticated attacker to seize control of a managed device via crafted FGFM requests, if the device is managed by a FortiManager, and if the attacker knows that FortiManager's serial number [2]. The vulnerability CVE-2025-52970, with a CVSS score of 7.7, is due to improper handling of parameters and allows an unauthenticated remote attacker in possession of non-public information (pertaining to both the device and to the targeted user) to log in as any existing user on the device via a specially crafted request [3]. Affected Products The vulnerability CVE-2025-25256 affects the following versions of FortiSIEM: 7.3.0 through 7.3.1 7.2.0 through 7.2.5 7.1.0 through 7.1.7 7.0.0 through 7.0.3 6.7.0 through 6.7.9 6.6, 6.5, 6.4, 6.3, 6.2 and 6.1 5.4 The vulnerability CVE-2024-26009 affects the following versions of FortiWeb: 7.6.0 through 7.6.3 7.4.0 through 7.4.7 7.2.0 through 7.2.10 7.0.0 through 7.0.10 The vulnerability CVE-2025-52970 affects the following versions FortiOS, FortiPAM, FortiProxy and FortSwitch Manager: FortiOS 6.4.0 through 6.4.15 FortiOS 6.2.0 through 6.2.16 FortiOS 6.0 all versions FortiPAM 1.2 all versions FortiPAM 1.1 all versions FortiPAM 1.0 all versions FortiProxy 7.4.0 through 7.4.2 FortiProxy 7.2.0 through 7.2.8 FortiProxy 7.0.0 through 7.0.15 FortiSwitchManager 7.2.0 through 7.2.3 FortiSwitchManager 7.0.0 through 7.0.3 Recommendations It is recommended updating vulnerable products as soon as possible. Workaround To mitigate the vulnerability CVE-2025-25256, it is possible to limit access to the phMonitor port (7900) of FortiSIEM.
cert.europa.euAug 13, 2025source
2025-030: High Severity Vulnerability in Microsoft Exchange
High Severity Vulnerability in Microsoft Exchange History: 08/08/2025 --- v1.0 -- Initial publication 08/08/2025 --- v1.1 -- Updated information Summary On August 6, 2025, Microsoft issued an advisory for a high-severity vulnerability affecting Microsoft Exchange hybrid environments [1]. The vulnerability tracked as CVE-2025-53786 allows an attacker with administrative access to an on-premises Exchange Server to escalate privileges into the connected Exchange Online environment. The vulnerability can impact the confidentiality, integrity, and availability of affected systems. Technical Details An attacker with admin privileges on an on-premise Exchange server can potentially forge or manipulate trusted tokens or API calls that the cloud side will accept as legitimate. This technique allows the attackers to spread laterally from the local network into the organisation's cloud environment, potentially compromising the organisation's entire active directory and infrastructure [6]. Products Affected The vulnerability affects the following Microsoft Exchange Servers in Hybrid Exchange Deployments: Microsoft Exchange Server 2016 Cumulative Update 23 versions earlier than 15.01.2507.055 Microsoft Exchange Server 2019 Cumulative Update 14 versions earlier than 15.02.1544.025 Microsoft Exchange Server 2019 Cumulative Update 15 versions earlier than 15.02.1748.024 Microsoft Exchange Server Subscription Edition RTM versions earlier than 15.02.2562.017 Recommendations It is strongly recommended to apply the follow the vendor guidance [1]: If using Exchange hybrid, review Microsoft's guidance to determine if your Microsoft hybrid deployments are potentially affected and available for a Cumulative Update (CU) [2]. Install Microsoft’s April 2025 Exchange Server Hotfix Updates [3] on the on-premise Exchange server and follow Microsoft's configuration instructions to deploy the dedicated Exchange hybrid app [4]. For organisations using Exchange hybrid (or have previously configured Exchange hybrid but no longer use it), review Microsoft's Service Principal Clean-Up Mode [4] for guidance on resetting the service principal's keyCredentials . Upon completion, run the Microsoft Exchange Health Checker [5] to determine if further steps are required. Threat Hunting The KQL query below detects potential abuse of the graph.windows.net API through impersonation — later fixed by Microsoft [7]. AuditLogs | where not(OperationName has "group") | where not(OperationName == "Set directory feature on tenant") | where InitiatedBy has_all ( "Office 365 Exchange Online","user") | where InitiatedBy.user.displayName == "Office 365 Exchange Online"
cert.europa.euAug 8, 2025source
2025-027: Critical Vulnerabilities in Microsoft SharePoint
Critical Vulnerabilities in Microsoft SharePoint History: 21/07/2025 --- v1.0 -- Initial publication 21/07/2025 --- v1.1 -- Updated information 22/07/2025 --- v1.2 -- Updated information from Microsoft 24/07/2025 --- v1.3 -- Further updated information from Microsoft Summary On July 19, 2025, Microsoft released an out-of-bound advisory addressing two vulnerabilities on Microsoft SharePoint, one of which being rated as critical and allowing unauthenticated remote attacker to execute arbitrary code on vulnerable systems [1,2]. These vulnerabilities apply to on-premises SharePoint Servers only. SharePoint Online in Microsoft 365 is not impacted. These critical flaws are actively being exploited in the wild since at least 18th of July 2025 [4]. It is recommended isolating vulnerable system from the Internet, but also from internal systems, and running a compromise assessment before updating. Technical Details The vulnerability CVE-2025-53770, with a CVSS score of 9.8, is due to the deserialisation of untrusted data. This flaw allows an unauthorised attacker to execute code over a network [2]. The vulnerability CVE-2025-53771, with a CVSS score of 6.3, is a spoofing vulnerability due to improper limitation of a path name to a restricted directory (path traversal) [3]. Affected Products The vulnerabilities CVE-2025-53770 and CVE-2025-53771 affect: Microsoft SharePoint Server Subscription Edition Microsoft SharePoint Server 2019 Microsoft SharePoint Enterprise Server 2016 [Updated] Note: All prior versions of SharePoint are no longer supported and should be considered vulnerable, but will not be patched by Microsoft. Recommendations It is recommended isolating vulnerable system from the Internet, but also from internal systems, and running a compromise assessment before updating. [Updated] After running a compromise assessment and updating affected servers, it is strongly recommended rotating SharePoint Server ASP.NET machine keys, before restarting the IIS service using iisreset.exe [1,5]. Mitigation The vendor strongly advises deploying Microsoft Defender for Endpoint protection, or equivalent threat solutions, as well as enabling and properly configuring the Antimalware Scan Interface [1]. Threat Hunting To identify possible exploitation of the vulnerabilities, it is possible to execute the following queries in the Microsoft 365 security centre's Advanced Hunting page [1,6]. Advanced Hunting in Microsoft Defender XDR NOTE: The following sample queries search for a week’s worth of events. For longer timespans, the default settings of Advanced Hunting would need to be adapted [1]. Successful exploitation using file creation Search for the creation of spinstall0.aspx, which indicates successful post-exploitation of CVE-2025-53770: DeviceFileEvents | where FolderPath has_any ("microsoft shared\\Web Server Extensions\\15\\TEMPLATE\\LAYOUTS", "microsoft shared\\Web Server Extensions\\16\\TEMPLATE\\LAYOUTS") | where FileName contains "spinstall" | project Timestamp, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, FileName, FolderPath, ReportId, ActionType, SHA256 | order by Timestamp desc Post-exploitation PowerShell dropping web shell Search for process creations, where w3wp.exe is spawning encoded PowerShell involving the spinstall0 file or the file paths it has been known to be written to: DeviceProcessEvents | where InitiatingProcessFileName has "w3wp.exe" and InitiatingProcessCommandLine !has "DefaultAppPool" and FileName =~ "cmd.exe" and ProcessCommandLine has_all ("cmd.exe", "powershell") and ProcessCommandLine has_any ("EncodedCommand", "-ec") | extend CommandArguments = split(ProcessCommandLine, " ") | mv-expand CommandArguments to typeof(string) | where CommandArguments matches regex "^[A-Za-z0-9+/=]{15,}$" | extend B64Decode = replace("\\x00", "", base64_decodestring(tostring(CommandArguments))) | where B64Decode contains "spinstall", @'C:\PROGRA~1\COMMON~1\MICROS~1\WEBSER~1\15\TEMPLATE\LAYOUTS', @'C:\PROGRA~1\COMMON~1\MICROS~1\WEBSER~1\16\TEMPLATE\LAYOUTS') Post-exploitation web shell dropped Search for the web shell dropped using the PowerShell command: DeviceFileEvents | where Timestamp >ago(7d) | where InitiatingProcessFileName=~"powershell.exe" | where FileName contains "spinstall" Exploitation detected by Defender Search at Microsoft Defender for Endpoint telemetry to determine if specific alerts fired in your environment: AlertEvidence | where Timestamp > ago(7d) | where Title has "SuspSignoutReq" | extend _DeviceKey = iff(isnotempty(DeviceId), bag_pack_columns(DeviceId, DeviceName),"") | summarize min(Timestamp), max(Timestamp), count_distinctif(DeviceId,isnotempty(DeviceId)), make_set(Title), make_set_if(_DeviceKey, isnotempty(_DeviceKey) ) Unified Advanced Hunting query Find exposed devices Search for devices vulnerable to the CVEs listed in blog [5]: DeviceTvmSoftwareVulnerabilities | where CveId in ("CVE-2025-49706","CVE-2025-53770") Web shell C2 communication Find devices that may have communicated with Storm-2603 web shell C2, that may indicate a compromised device beaconing to Storm-2603 controlled infrastructure: let domainList = "update.updatemicfosoft.com"; union ( DnsEvents | where QueryType has_any(domainList) or Name has_any(domainList) or QueryType matches regex @"^.*\.devtunnels\.ms$" or Name matches regex @"^.*\.devtunnels\.ms$" | project TimeGenerated, Domain = QueryType, SourceTable = "DnsEvents" ), ( IdentityQueryEvents | where QueryTarget has_any(domainList) or QueryType matches regex @"^.*\.devtunnels\.ms$" | project Timestamp, Domain = QueryTarget, SourceTable = "IdentityQueryEvents" ), ( DeviceNetworkEvents | where RemoteUrl has_any(domainList) or RemoteUrl matches regex @"^.*\.devtunnels\.ms$" | project Timestamp, Domain = RemoteUrl, SourceTable = "DeviceNetworkEvents" ), ( DeviceNetworkInfo | extend DnsAddresses = parse_json(DnsAddresses), ConnectedNetworks = parse_json(ConnectedNetworks) | mv-expand DnsAddresses, ConnectedNetworks | where DnsAddresses has_any(domainList) or ConnectedNetworks.Name has_any(domainList) or DnsAddresses matches regex @"^.*\.devtunnels\.ms$" or ConnectedNetworks .Name matches regex @"^.*\.devtunnels\.ms$" | project Timestamp, Domain = coalesce(DnsAddresses, ConnectedNetworks.Name), SourceTable = "DeviceNetworkInfo" ), ( VMConnection | extend RemoteDnsQuestions = parse_json(RemoteDnsQuestions), RemoteDnsCanonicalNames = parse_json(RemoteDnsCanonicalNames) | mv-expand RemoteDnsQuestions, RemoteDnsCanonicalNames | where RemoteDnsQuestions has_any(domainList) or RemoteDnsCanonicalNames has_any(domainList) or RemoteDnsQuestions matches regex @"^.*\.devtunnels\.ms$" or RemoteDnsCanonicalNames matches regex @"^.*\.devtunnels\.ms$" | project TimeGenerated, Domain = coalesce(RemoteDnsQuestions, RemoteDnsCanonicalNames), SourceTable = "VMConnection" ), ( W3CIISLog | where csHost has_any(domainList) or csReferer has_any(domainList) or csHost matches regex @"^.*\.devtunnels\.ms$" or csReferer matches regex @"^.*\.devtunnels\.ms$" | project TimeGenerated, Domain = coalesce(csHost, csReferer), SourceTable = "W3CIISLog" ), ( EmailUrlInfo | where UrlDomain has_any(domainList) or UrlDomain matches regex @"^.*\.devtunnels\.ms$" | project Timestamp, Domain = UrlDomain, SourceTable = "EmailUrlInfo" ), ( UrlClickEvents | where Url has_any(domainList) or Url matches regex @"^.*\.devtunnels\.ms$" | project Timestamp, Domain = Url, SourceTable = "UrlClickEvents" ) | order by TimeGenerated desc Hunting in Microsoft Sentinel Detect network indicators of compromise and file hashes using ASIM //IP list and domain list- _Im_NetworkSession let lookback = 30d; let ioc_ip_addr = dynamic(["131.226.2.6", "134.199.202.205", "104.238.159.149", "188.130.206.168"]); let ioc_domains = dynamic(["c34718cbb4c6.ngrok-free.app"]); _Im_NetworkSession(starttime=todatetime(ago(lookback)), endtime=now()) | where DstIpAddr in (ioc_ip_addr) or DstDomain has_any (ioc_domains) | summarize imNWS_mintime=min(TimeGenerated), imNWS_maxtime=max(TimeGenerated), EventCount=count() by SrcIpAddr, DstIpAddr, DstDomain, Dvc, EventProduct, EventVendor //IP list - _Im_WebSession let lookback = 30d; let ioc_ip_addr = dynamic(["131.226.2.6", "134.199.202.205", "104.238.159.149", "188.130.206.168"]); let ioc_sha_hashes =dynamic(["92bb4ddb98eeaf11fc15bb32e71d0a63256a0ed826a03ba293ce3a8bf057a514"]); _Im_WebSession(starttime=todatetime(ago(lookback)), endtime=now()) | where DstIpAddr in (ioc_ip_addr) or FileSHA256 in (ioc_sha_hashes) | summarize imWS_mintime=min(TimeGenerated), imWS_maxtime=max(TimeGenerated), EventCount=count() by SrcIpAddr, DstIpAddr, Url, Dvc, EventProduct, EventVendor // file hash list - imFileEvent let ioc_sha_hashes = dynamic(["92bb4ddb98eeaf11fc15bb32e71d0a63256a0ed826a03ba293ce3a8bf057a514"]); imFileEvent | where SrcFileSHA256 in (ioc_sha_hashes) or TargetFileSHA256 in (ioc_sha_hashes) | extend AccountName = tostring(split(User, @'')[1]), AccountNTDomain = tostring(split(User, @'')[0]) | extend AlgorithmType = "SHA256" Post exploitation C2 or file hashes Find devices that may have communicated with Storm-2603 post exploitation C2 or contain known Storm-2603 file hashes: //IP list - _Im_WebSession let lookback = 30d; let ioc_ip_addr = dynamic(["65.38.121.198"]); let ioc_sha_hashes =dynamic(["92bb4ddb98eeaf11fc15bb32e71d0a63256a0ed826a03ba293ce3a8bf057a514", "24480dbe306597da1ba393b6e30d542673066f98826cc07ac4b9033137f37dbf", "b5a78616f709859a0d9f830d28ff2f9dbbb2387df1753739407917e96dadf6b0", "c27b725ff66fdfb11dd6487a3815d1d1eba89d61b0e919e4d06ed3ac6a74fe94", "1eb914c09c873f0a7bcf81475ab0f6bdfaccc6b63bf7e5f2dbf19295106af192", "4c1750a14915bf2c0b093c2cb59063912dfa039a2adfe6d26d6914804e2ae928", "83705c75731e1d590b08f9357bc3b0f04741e92a033618736387512b40dab060", "f54ae00a9bae73da001c4d3d690d26ddf5e8e006b5562f936df472ec5e299441", "b180ab0a5845ed619939154f67526d2b04d28713fcc1904fbd666275538f431d", "6753b840cec65dfba0d7d326ec768bff2495784c60db6a139f51c5e83349ac4d", "7ae971e40528d364fa52f3bb5e0660ac25ef63e082e3bbd54f153e27b31eae68", "567cb8e8c8bd0d909870c656b292b57bcb24eb55a8582b884e0a228e298e7443", "445a37279d3a229ed18513e85f0c8d861c6f560e0f914a5869df14a74b679b86", "ffbc9dfc284b147e07a430fe9471e66c716a84a1f18976474a54bee82605fa9a", "6b273c2179518dacb1218201fd37ee2492a5e1713be907e69bf7ea56ceca53a5", "c2c1fec7856e8d49f5d49267e69993837575dbbec99cd702c5be134a85b2c139"]); _Im_WebSession(starttime=todatetime(ago(lookback)), endtime=now()) | where DstIpAddr in (ioc_ip_addr) or FileSHA256 in (ioc_sha_hashes) | summarize imWS_mintime=min(TimeGenerated), imWS_maxtime=max(TimeGenerated), EventCount=count() by SrcIpAddr, DstIpAddr, Url, Dvc, EventProduct, EventVendor Storm-2603 C2 communication Search for devices that may have communicated with Storm-2603 C2 infrastructure as part of this activity: //IP list and domain list- _Im_NetworkSession let lookback = 30d; let ioc_ip_addr = dynamic(["65.38.121.198"]); let ioc_domains = dynamic(["update.updatemicfosoft.com"]); _Im_NetworkSession(starttime=todatetime(ago(lookback)), endtime=now()) | where DstIpAddr in (ioc_ip_addr) or DstDomain has_any (ioc_domains) | summarize imNWS_mintime=min(TimeGenerated), imNWS_maxtime=max(TimeGenerated), EventCount=count() by SrcIpAddr, DstIpAddr, DstDomain, Dvc, EventProduct, EventVendor
cert.europa.euJul 24, 2025source
2025-028: CrushFTP zero-day exploited in the wild
History: 24/07/2025 --- v1.0 -- Initial publication Summary CrushFTP is warning that threat actors are actively exploiting a zero-day vulnerability tracked as CVE-2025-54309, which allows attackers to gain administrative access via the web interface on vulnerable servers [2, 3]. Threat actors were first detected exploiting the vulnerability on July 18th at 9AM CST, though it may have begun in the early hours of the previous day [1]. Techincal details The attack occurs via the software's web interface in versions prior to CrushFTP v10.8.5 and CrushFTP v11.3.4_23. It is unclear when these versions were released, but CrushFTP says around July 1st [1]. Enterprise customers using a DMZ CrushFTP instance to isolate their main server are not believed to be affected by this vulnerability. Accoring to CrushFTP: We believe this bug was in builds prior to July 1st time period roughly... the latest versions of CrushFTP already have the issue patched. The attack vector was HTTP(S) for how they could exploit the server. We had fixed a different issue related to AS2 in HTTP(S) not realizing that prior bug could be used like this exploit was. Hackers apparently saw our code change, and figured out a way to exploit the prior bug. Affected products CrushFTP version 10 below 10.8.5 CrushFTP version 11 below 11.3.4_23 Recommendations Check if you may have been compromised. IoC include [1]: your MainUsers/default/user.XML containslast_logins the modified date on your default user.XML is recent default user has admin access long random userid's created you don't recognise - example: 7a0d26089ac528941bf8cb998d97f408m other usernames recently created with admin access. buttons from the end-user web interface disappeared, and formerly regular user now has Admin button In case of compromise [1]: Restore a prior default user from your backup folder from before the exploit. ( /backup/users/MainUsers/default/.. ). You can also just delete your default user and CrushFTP will re-create it for you, but you won't have any prior customizations you might have done. Restore it to your /users/MainUsers/default Review upload/download reports for anything transferred. Hackers re-used scripts from prior exploits to deploy things on CrushFTP servers. We recommend restoring to July 16th time period just to avoid anything that might have been done.
cert.europa.euJul 24, 2025source
2025-026: Critical Vulnerabilities in VMWare Products
History: 18/07/2025 --- v1.0 -- Initial publication Summary On July 15, 2025, VMware released a security advisory addressing 3 critical vulnerabilities in its products that would allow an attacker to execute code on vulnerable devices [1]. It is recommended updating affected products as soon as possible, prioritising the ones hosting virtual machines that are Internet facing. Note: These vulnerabilities were exploited as zero-days during the Pwn2Own Berlin 2025 hacking contest in May 2025. Technical Details The vulnerability CVE-2025-41236, with a CVSS score of 9.3, is an integer-overflow in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue. The vulnerability CVE-2025-41237, with a CVSS score of 9.3, is an integer-underflow in VMCI (Virtual Machine Communication Interface) that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed. The vulnerability CVE-2025-41238, with a CVSS score of 9.3, is a heap-overflow vulnerability in the PVSCSI (Paravirtualized SCSI) controller that leads to an out of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox and exploitable only with configurations that are unsupported. On Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed. Affected Products The following products are affected by at least one of the vulnerabilities: VMware Cloud Foundation (ESX component) VMware vSphere Foundation (ESX component) VMware ESXi VMware Workstation VMware Fusion VMware Telco Cloud Platform VMware Telco Cloud Infrastructure VMware Tools For a detailed list of the versions, please refer to the vendor's advisory [1]. Recommendations It is recommended updating affected products as soon as possible, prioritising the ones hosting virtual machines that are Internet facing.
cert.europa.euJul 18, 2025source
2025-025: Critical Vulnerabilities in Cisco ISE
History: 18/07/2025 --- v1.0 -- Initial publication Summary On June 25, Cisco released an advisory addressing 2 critical vulnerabilities affecting Cisco's Identity Services Engine (ISE) product that would allow an attacker to execute arbitrary code on vulnerable devices [1]. On July 16, Cisco updated this advisory adding a third critical vulnerability affecting Cisco's Identity Services Engine (ISE) product [1]. It is recommended updating affected product as soon as possible. Technical Details The vulnerabilities CVE-2025-20281 and CVE-2025-20337, both with a CVSS score of 10, are due to insufficient validation of user-supplied input in a specific API endpoint of the product. An attacker could exploit these vulnerabilities by submitting a crafted API request. A successful exploit could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The vulnerability CVE-2025-20282, with a CVSS score of 10, is due to a lack of file validation checks that would prevent uploaded files from being placed in privileged directories on an affected system. An attacker could exploit this vulnerability by uploading a crafted file to the affected device. A successful exploit could allow the attacker to store malicious files on the affected system and then execute arbitrary code or obtain root privileges on the system. Affected Products The following product versions are affected by the vulnerabilities: Cisco ISE or ISE-PIC Release 3.3 before Patch 7 Cisco ISE or ISE-PIC Release 3.4 before Patch 2 Note: Cisco warns that customers who applied the patches for CVE-2025-20281 and CVE-2025-20282 are not covered for CVE-2025-20337, and need to upgrade to ISE 3.3 Patch 7 or ISE 3.4 Patch 2. Recommendations It is recommended updating affected devices as soon as possible.
cert.europa.euJul 18, 2025source
2025-023: Critical Vulnerabilities in Microsoft Products
Critical Vulnerabilities in Microsoft Products History: 09/07/2025 --- v1.0 -- Initial publication Summary On July 8, 2025, as part of the Microsoft's Patch Tuesday, Microsoft released security updates addressing 137 flaws, including one zero-day vulnerability and fourteen critical vulnerabilities [1]. It is recommended updating as soon as possible, prioritising public facing and critical assets. Technical Details The zero-day vulnerability CVE-2025-49719, with a CVSS score of 7.5, is due to improper input validation in SQL Server and allows a remote, unauthenticated attacker to access data from uninitialized memory. Microsoft also fixed one important and one critical severity vulnerabilities in SQL Server. Microsoft fixed seven critical and eight high severity vulnerabilities in Microsoft Office, Microsoft Office Excel, Microsoft Office SharePoint, and Microsoft Office Words. These flaws are elevation of privilege, information disclosure, server spoofing, and remote code execution vulnerabilities. Microsoft finally fixed four critical vulnerabilities in the Windows Hyper-V role, Windows Imaging Component, Windows KDC Proxy Service (KPSSVC), and in the Windows SPNEGO Extended Negotiation Mechanism. Affected Products Microsoft SQL Server, Microsoft Office, Microsoft Office Excel, Microsoft Office SharePoint, Microsoft Office Words and Microsoft Windows are affected by the vulnerabilities described above. For the list of all products affected, refer to Microsoft's advisory [1]. Recommendations It is recommended updating as soon as possible, prioritising public facing and critical assets.
cert.europa.euJul 9, 2025source