Announcements

CVE-2026-34084 (matched: php)

  • 26th July 2026
PhpSpreadsheet is a widely used software library that helps websites read, write, and edit spreadsheet files like Excel and CSV. A security vulnerability exists in multiple older versions of this library, but only impacts sites that let visitor input control which spreadsheet file the library loads. Attackers can exploit this flaw in two main ...
Continue reading

MA-1471.072026: MyCERT Advisory - Microsoft SharePoint Hardening After New Exploitations

  • 26th July 2026
On 20 July 2026, cybersecurity agency MyCERT released an advisory focused on securing Microsoft SharePoint, a common platform businesses use to store, share and collaborate on documents and team content. The advisory was issued after new exploitation methods targeting SharePoint installations were recently observed.These newly identified ...
Continue reading

MA-1472.072026: MyCERT Advisory - Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

  • 26th July 2026
A security advisory was published on 22 July 2026 regarding a vulnerability in Microsoft Active Directory Federation Services (AD FS), a tool many organizations use to manage secure access to connected applications, services, and internal resources.The flaw stems from AD FS having insufficiently fine-grained access control settings. This means the ...
Continue reading

MA-1473.072026: MyCERT Advisory - Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability

  • 26th July 2026
A security advisory published July 22, 2026 details a vulnerability affecting Microsoft SharePoint Server, a tool many web hosting clients use to run collaborative team sites, shared document hubs, and internal business portals. The flaw is classified as a missing authentication for critical function issue, meaning a key, protected feature of the ...
Continue reading