Announcements

CVE-2026-34084 (matched: php)

  • 26th July 2026
PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.2 and earlier, 2.0.0 through 2.1.14, 2.2.0 through 2.4.3, 3.3.0 through 3.10.3, and 4.0.0 through 5.5.0, when the filename argument to IOFactory::load() is user-controlled, an attacker can supply a PHP stream wrapper path (such as phar://, ftp://, or ...
Continue reading

MA-1471.072026: MyCERT Advisory - Microsoft SharePoint Hardening After New Exploitations

  • 26th July 2026
A security advisory (reference MA-1471.072026) from MyCERT was published on 20 July 2026 highlighting newly identified active exploitation of Microsoft SharePoint. SharePoint is a common tool used by organizations for document sharing, team collaboration, and internal business workflows, and is often integrated with hosted websites and business ...
Continue reading

MA-1472.072026: MyCERT Advisory - Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

  • 26th July 2026
On July 22, 2026, cybersecurity authority MyCERT published an advisory detailing a security vulnerability in Microsoft Active Directory Federation Services (AD FS), a common tool used to manage user access to websites, applications, and other online services. The flaw relates to AD FS having insufficiently fine-grained access control settings, ...
Continue reading

MA-1473.072026: MyCERT Advisory - Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability

  • 26th July 2026
A security advisory was released on July 22, 2026, identifying a vulnerability in Microsoft SharePoint Server. The flaw is classified as missing authentication for a critical function, meaning a key component of the software does not require proper user verification before granting access to its features.For clients who use Microsoft SharePoint ...
Continue reading