Announcements

Microsoft Internet Key Exchange (IKE) Service Extensions: Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability

  • 20th August 2026
A security vulnerability has been identified in Microsoft Internet Key Exchange (IKE) Service Extensions, a Microsoft component used to manage secure network connections. This flaw is a type of memory error called a double free vulnerability.If successfully exploited by a remote attacker, this vulnerability could allow the attacker to run ...
Continue reading

MLflow MLflow: MLflow Server-Side Request Forgery Vulnerability

  • 20th August 2026
A security vulnerability has been discovered in MLflow, a tool some hosting clients use to track and manage machine learning project workflows. The flaw is classified as a server-side request forgery (SSRF) issue.When exploited, this vulnerability could allow unauthorized attackers to trick the MLflow tool into sending requests to private internal ...
Continue reading

MA-1471.072026: MyCERT Advisory - Microsoft SharePoint Hardening After New Exploitations

  • 20th August 2026
A new security advisory (reference number MA-1471.072026) from cybersecurity agency MyCERT was published on 20 July 2026 at 9:43am. It addresses newly identified exploits targeting Microsoft SharePoint, a popular platform many organizations use for team collaboration, file sharing, and managing content on public websites or private internal ...
Continue reading

MA-1472.072026: MyCERT Advisory - Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

  • 20th August 2026
On 22 July 2026, cybersecurity agency MyCERT released an advisory for a security vulnerability affecting Microsoft Active Directory Federation Services (AD FS), a tool many organizations use to manage user logins and access permissions for business applications and services. The flaw is categorized as insufficient granularity of access control, ...
Continue reading