Announcements

CVE-2026-39932 (matched: php)

  • 3rd August 2026
A critical security flaw has been identified in OpenEMR, a common open-source electronic medical records platform, affecting all versions up to 8.2.0. The flaw exists in the software’s document category tree feature, and it allows users with administrative access to the OpenEMR system to sneak harmful executable code into the platform’s ...
Continue reading

N-able N-central: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

  • 3rd August 2026
A security vulnerability has been identified in the N-able N-central platform. The flaw allows attackers to bypass normal account login checks by using an alternate, unsecured access path in the system, which could enable them to take over user accounts associated with N-central.This issue stems from an incomplete fix for an earlier vulnerability ...
Continue reading

MA-1471.072026: MyCERT Advisory - Microsoft SharePoint Hardening After New Exploitations

  • 3rd August 2026
On July 20, 2026, Malaysia’s national cybersecurity agency MyCERT released an advisory focused on Microsoft SharePoint, a popular tool many businesses use for team collaboration, shared document storage, and internal workflows. The advisory centers on security hardening (strengthening system protections) for SharePoint deployments, following the ...
Continue reading

MA-1472.072026: MyCERT Advisory - Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

  • 3rd August 2026
MyCERT released an advisory on July 22, 2026, about a security vulnerability affecting Microsoft Active Directory Federation Services (AD FS). The flaw, called insufficient granularity of access control, means the system’s rules for granting access to resources are not precise enough. This could allow unauthorized users to access data, services, ...
Continue reading