Announcements

CVE-2026-14484 (matched: wordpress)

  • 16th August 2026
A security flaw has been found in the RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress, affecting all versions up to and including 1.0.4. The plugin does not properly check file paths when handling requests to delete uploaded files, which means anyone (even visitors who are not logged into your WordPress admin area) ...
Continue reading

MA-1471.072026: MyCERT Advisory - Microsoft SharePoint Hardening After New Exploitations

  • 16th August 2026
MyCERT released a security advisory on 20 July 2026 at 9:43 am, focused on securing (or "hardening") Microsoft SharePoint after new methods of exploiting the platform were observed. The advisory outlines recommended steps to close security gaps that attackers are actively using to access SharePoint systems. Exploitation of these gaps could allow ...
Continue reading

MA-1472.072026: MyCERT Advisory - Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

  • 16th August 2026
On July 22, 2026, security advisory body MyCERT published a notice for a vulnerability impacting Microsoft Active Directory Federation Services (AD FS). The issue is categorized as an insufficient granularity of access control flaw. This means the system’s permission configuration options do not allow for fine enough control over who can access ...
Continue reading

MA-1473.072026: MyCERT Advisory - Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability

  • 16th August 2026
A security advisory was published by MyCERT on July 22, 2026, for a vulnerability discovered in Microsoft SharePoint Server. The flaw is categorized as missing authentication for a critical server function, which means the platform fails to properly require users to prove they are authorized before granting access to certain high-priority ...
Continue reading