Announcements

CVE-2026-34084 (matched: php)

  • 25th July 2026
PhpSpreadsheet is a popular library used by many web applications to read and write spreadsheet files, and older versions of it have a security flaw. This issue only impacts websites where users can submit the filename of a spreadsheet that the site loads using this library.If your site fits that scenario, an attacker could send a specially ...
Continue reading

Microsoft SharePoint: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

  • 25th July 2026
A security flaw has been identified in Microsoft SharePoint, the platform many teams use to store, share, and collaborate on work files and data. This flaw stems from how SharePoint processes incoming data that it rebuilds into a usable internal format, without first properly checking that the data comes from a trusted source.If an unauthorized ...
Continue reading

Check Point SmartConsole: Check Point SmartConsole Improper Authentication Vulnerability

  • 25th July 2026
A security vulnerability has been identified in Check Point SmartConsole, a tool some website operators use to manage security and access settings for their hosted services. The issue is an improper authentication flaw, meaning the tool does not properly verify that people attempting to log in are authorized. An attacker with no existing valid ...
Continue reading

MA-1471.072026: MyCERT Advisory - Microsoft SharePoint Hardening After New Exploitations

  • 25th July 2026
On 20 July 2026, MyCERT published an advisory focused on securing Microsoft SharePoint, following confirmed new exploitation activity targeting the platform. Microsoft SharePoint is a widely used tool that lets teams store, share, and collaborate on documents and internal business content. The newly identified exploitation activity poses a risk of ...
Continue reading