Announcements

CVE-2026-34084 (matched: php)

  • 26th July 2026
A security flaw has been identified in PhpSpreadsheet, a widely used library that helps websites read and write spreadsheet files such as Excel or CSV exports. The vulnerability impacts all PhpSpreadsheet versions up to 1.30.2, 2.0.0 through 2.1.14, 2.2.0 through 2.4.3, 3.3.0 through 3.10.3, and 4.0.0 through 5.5.0.This issue only poses a risk if ...
Continue reading

MA-1471.072026: MyCERT Advisory - Microsoft SharePoint Hardening After New Exploitations

  • 26th July 2026
On 20 July 2026, Malaysia’s national cybersecurity response team MyCERT released security advisory MA-1471.072026, focused on securing Microsoft SharePoint after new methods for exploiting the platform were discovered. Microsoft SharePoint is a popular tool used by organizations to host shared team workspaces, store collaborative documents, and ...
Continue reading

MA-1472.072026: MyCERT Advisory - Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

  • 26th July 2026
A security advisory was published on July 22, 2026, for a vulnerability affecting Microsoft Active Directory Federation Services (AD FS). The issue is classified as insufficient granularity of access control, meaning the system’s permission settings are not precise enough to properly restrict who can access or modify its core functions.For ...
Continue reading

MA-1473.072026: MyCERT Advisory - Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability

  • 26th July 2026
A new security advisory from MyCERT, published on July 22, 2026, identifies a vulnerability in Microsoft SharePoint Server, a platform many website owners use for team collaboration, document sharing, and content management. The flaw involves a critical function of the server that does not require proper authentication to access. This means ...
Continue reading