ZeroHour

Source: Canadian Centre for Cyber Security

33 stories in the last 30d

Docker security advisory (AV26-925)

Canadian Cyber Centre advisory AV26-925 flags a vulnerability in Docker Sandboxes versions prior to 0.43.0 and urges users to apply updates.

The Canadian Centre for Cyber Security issued advisory AV26-925 on September 15, 2026, stating Docker is affected by a vulnerability in Docker Sandships prior to version 0.43.0. The advisory directs users and administrators to review Docker sbx-releases and security announcements and apply updates as they become available. No exploitation or technical details are provided.

Canadian Centre for Cyber Security · 20h agoAdvisory

Mozilla security advisory (AV26-924)

Canadian Cyber Centre advisory AV26-924 lists vulnerabilities in Firefox 156 and Firefox ESR 115.41, 140.16, and 153.3, urging users to update.

The Canadian Centre for Cyber Security issued advisory AV26-924 on September 15, 2026, covering vulnerabilities in Firefox versions prior to 156 and Firefox ESR versions prior to 115.41, 140.16, and 153.3. Users and administrators are encouraged to review Mozilla's security advisories and apply updates. No exploitation details are included in the advisory.

Canadian Centre for Cyber Security · 20h agoAdvisory

Android security advisory – September 2026 monthly rollup (AV26-920)

Canadian Cyber Centre relays Android's September 2026 security bulletin, urging users and administrators to apply device updates.

The Canadian Centre for Cyber Security issued advisory AV26-920 pointing to the Android security bulletin published September 8, 2026. Users and administrators are encouraged to review the linked bulletin and apply necessary updates as they become available. The alert itself lists no specific CVEs, affected components, or exploitation details.

Canadian Centre for Cyber Security · 1d agoAdvisory

Samsung mobile security advisory (AV26-919)

Canadian Cyber Centre relays Samsung's September 2026 mobile security update (SMR-SEP-2026) fixing multiple vulnerabilities; users urged to apply patches.

The Canadian Centre for Cyber Security issued advisory AV26-919 on September 14, 2026, relaying Samsung's September 8, 2026 security update for Samsung mobile devices. The update covers versions prior to SMR-SEP-2026 and resolves multiple identified vulnerabilities. Users and administrators are encouraged to review the Samsung bulletin and apply the necessary update.

Canadian Centre for Cyber Security · 2d agoAdvisory

Progress security advisory (AV26-915)

Canadian Cyber Centre advisory AV26-915 warns of a vulnerability in Progress Software Chef Automate prior to 4.13.520.

The Canadian Centre for Cyber Security issued advisory AV26-915 on September 11, 2026, flagging a vulnerability in Progress Software's Chef Automate for versions prior to 4.13.520. The advisory references Progress' Critical Security Bulletin from August 2026 and urges users and administrators to review the linked resources and apply available updates. No exploitation status, CVE identifiers, or technical details are provided.

Canadian Centre for Cyber Security · 4d agoAdvisory

WebPros security advisory (AV26-908)

Canada's Cyber Centre relays WebPros advisories for SQL injection (CVE-2026-67401) in cPanel and two ConfigServer Firewall flaws.

The Canadian Centre for Cyber Security published advisory AV26-908 covering vulnerabilities in WebPros products, including cPanel & WHM and ConfigServer Security & Firewall (CSF). Affected cPanel builds include versions prior to 11.110.0.143, 11.134.0.55, 11.136.0.39, 11.138.0.4 and WP2 11.138.1.9, while CSF versions 14.00-16.29 (CVE-2026-65638) and 2.15-16.29 (CVE-2026-65639) are also affected. CVE-2026-67401 describes SQL injection in cPanel's EmailTrack functionality. Users and administrators are encouraged to review the advisories and apply available updates.

Canadian Centre for Cyber Securityupdated · 5d agofirst · 5d agoAdvisory 3 sourcesCVE-2026-65638CVE-2026-65639CVE-2026-67401

HPE security advisory (AV26-909)

Canada's Cyber Centre relayed HPE advisories covering vulnerabilities in Aruba ClearPass Policy Manager and HPE IceWall products.

Canadian Centre for Cyber Security advisory AV26-909, dated September 10, 2026, flags vulnerabilities in HPE products disclosed on September 9, 2026. Affected products include Aruba ClearPass Policy Manager versions prior to or equal to 6.11.14 and 6.12.8, and multiple HPE IceWall versions and models. Bulletins cover multiple ClearPass vulnerabilities, a remote bypass of security restrictions in IceWall, and an IceWall denial-of-service vulnerability; administrators are urged to review the bulletins and apply updates.

Canadian Centre for Cyber Security · 5d agoAdvisory

NVIDIA security advisory (AV26-900)

Canada's Cyber Centre flags NVIDIA Triton Inference Server versions through 26.03 and 26.06 as vulnerable, urging review of the September 2026 bulletin.

The Canadian Centre for Cyber Security issued advisory AV26-900 on September 9, 2026, noting that as of September 8, NVIDIA Triton Inference Server versions 0.0 to 26.03 and 0.0 to 26.06 are affected by vulnerabilities. The advisory includes no CVE identifiers or severity details and directs users to review NVIDIA's September 2026 Triton security bulletin and apply available updates.

Canadian Centre for Cyber Security · 7d agoAdvisory

Fortinet security advisory (AV26-898)

Canadian Cyber Centre advisory AV26-898 flags Fortinet vulnerabilities across FortiOS, FortiProxy, FortiPAM, FortiSandbox and FortiMonitorOnSight, urging administrators to apply updates

The Canadian Centre for Cyber Security relayed Fortinet PSIRT advisories (AV26-898) listing vulnerabilities affecting FortiOS 7.6.1-7.6.6, FortiProxy 7.6.2-7.6.6, FortiPAM Chrome extensions 7.4/8.0, FortiSandbox 4.4 and 5.0, FortiSandbox Cloud and PaaS 5.0.4-5.0.5, and FortiMonitorOnSight 7.2. The bulletin does not detail individual CVEs or exploitation. Administrators and users are encouraged to review the linked Fortinet advisories and apply the necessary updates.

Canadian Centre for Cyber Security · 7d agoAdvisory

Ivanti security advisory (AV26-897)

Canada's Cyber Centre relayed Ivanti's September 2026 security updates for Endpoint Manager Mobile, Neurons for ITSM, and Sentry, urging administrators to patch.

The Canadian Centre for Cyber Security forwarded Ivanti's September 2026 security updates covering Endpoint Manager Mobile, Neurons for ITSM (cloud/SaaS and on-prem), and Sentry. Affected releases include Endpoint Manager Mobile prior to 12.10.0.0, Sentry prior to R10.8.2, and Neurons for ITSM on-prem prior to 2026.2. The advisory references CVE-2026-18851 for Endpoint Manager Mobile and CVE-2026-83527 for Sentry, plus multiple CVEs in Neurons for ITSM. No exploitation is described in the advisory text.

Commvault security advisory (AV26-895)

Canada's Cyber Centre advisory AV26-895 warns Commvault Cloud builds before 11.36.123/11.40.72/11.44.20/11.46.20 are affected by a Command Center API authentication bypass.

The Canadian Centre for Cyber Security alerted users that Commvault Cloud versions 11.36, 11.40, 11.44 and 11.46, prior to fixed builds 11.36.123, 11.40.72, 11.44.20 and 11.46.20, are affected by issue CV_2026_07_1, a Command Center API authentication bypass. Administrators are encouraged to review the linked vendor advisories and apply the available updates.

Canadian Centre for Cyber Security · 7d agoAdvisory

SAP security advisory – September 2026 monthly rollup (AV26-894)

Canada's Cyber Centre relayed SAP's September 2026 Patch Day rollup covering vulnerabilities across NetWeaver, kernel components, CAP, and Integration Suite.

The Canadian Centre for Cyber Security published advisory AV26-894 noting that as of September 8, 2026, SAP is affected by vulnerabilities in multiple products, including SAP Extended Passport, NetWeaver Message Server, SAP Cloud Application Programming Model, SAP GUI for Java, Integration Suite Cloud Integration, NetWeaver Business Client, and NetWeaver AS for ABAP. The advisory corresponds to SAP Security Patch Day September 2026 and lists many affected kernel and web dispatcher versions. Administrators are urged to review the SAP advisory and apply updates as available.

Canadian Centre for Cyber Security · 7d agoAdvisory

[Control Systems] Inductive Automation security advisory (AV26-892)

Canada's Cyber Centre relayed a CISA ICS advisory for an Inductive Automation Ignition vulnerability affecting versions up to 8.1.53.

The Canadian Centre for Cyber Security published control systems advisory AV26-892, noting that as of September 4, 2026, Inductive Automation is affected by a vulnerability in Ignition versions prior to or equal to 8.1.53. The advisory references CISA's ICS advisory (ICSA-26-246-06) and its CSAF file, and encourages users and administrators to review the linked resources and apply necessary updates as they become available. Ignition is a widely deployed industrial automation platform, so affected OT operators should patch promptly.

Canadian Centre for Cyber Security · 7d agoAdvisory

Dell security advisory (AV26-886)

Canada's Cyber Centre flags September 2026 Dell vulnerabilities across iDRAC9/iDRAC10, OpenManage, PowerEdge, Avamar, NetWorker VE, PowerProtect, IDPA and PowerScale OneFS.

Canadian Centre for Cyber Security advisory AV26-886 lists Dell vulnerabilities across iDRAC9, iDRAC10, OpenManage Network Integration, PowerEdge servers, the OpenManage Python SDK, Avamar, NetWorker Virtual Edition, PowerProtect DP Series, IDPA and PowerScale OneFS. Fixed versions include iDRAC9 7.30.10.50, iDRAC10 1.30.30.50 and OpenManage Network Integration 3.10. No CVE identifiers or exploitation status are provided; administrators are urged to apply the vendor updates.

Canadian Centre for Cyber Security · 8d agoAdvisory

F5 security advisory (AV26-878)

Canada's Cyber Centre relayed an F5 advisory (AV26-878) covering vulnerabilities in BIG-IP, BIG-IQ, NGINX components, and APM clients.

The Canadian Centre for Cyber Security published advisory AV26-878 noting F5 vulnerabilities affecting BIG-IP all modules prior to 17.1.3.4, 17.5.1.8, 21.0.0.3, and 21.1.0.1, plus BIG-IQ prior to 8.4.2.1, NGINX Gateway Fabric, NGINX Ingress Controller, NGINX JavaScript 9.9, and APM clients. F5 issued an out-of-band security notification (K000162872) on September 2, 2026. Administrators are encouraged to review the linked advisory and apply updates as they become available.

Canadian Centre for Cyber Security · 13d agoAdvisory

Jenkins security advisory (AV26-877)

Canada's Cyber Centre relayed a Jenkins advisory (AV26-877) covering core and numerous plugin vulnerabilities fixed in 2.568.3/2.580.

The Canadian Centre for Cyber Security published advisory AV26-877 for the Jenkins security advisory dated September 2, 2026. Affected products include Jenkins releases other than 2.568.3 and 2.580, plus plugins such as GitLab, LDAP, Microsoft Entra ID, SAML, Script Security, Pipeline Build Step, and others. Administrators are encouraged to review the linked advisory and apply necessary updates.

Canadian Centre for Cyber Security · 13d agoAdvisory

Cisco security advisory (AV26-876)

Canada's Cyber Centre relayed Cisco advisories covering a Nexus 9000 Silicon One RCE, IOS XR hardening, and denial-of-service flaws across IP phone lines.

The Canadian Centre for Cyber Security advisory AV26-876 lists Cisco vulnerabilities affecting IOS XR, Nexus 9000 Series switches, and several IP phone series. Included are a Nexus 9000 Silicon One remote code execution vulnerability, a September 2026 IOS XR security hardening release, and SIP software denial-of-service flaws in Desk Phone 9800, IP Phone 7800/8800, and Video Phone 8875. The Cyber Centre urges users and administrators to review the Cisco advisories and apply updates as they become available. No active exploitation is reported in the advisory.

Canadian Centre for Cyber Security · 13d agoAdvisory

Progress Software security advisory (AV26-875)

Canada's Cyber Centre warns Progress Telerik UI for ASP.NET AJAX before 2026.3.812 is affected by path traversal and upload tampering flaws, urging updates.

The Canadian Centre for Cyber Security issued advisory AV26-875 on September 2, 2026, covering vulnerabilities in Progress Software Telerik UI for ASP.NET AJAX prior to version 2026.3.812. Two flaws are listed: CVE-2026-18672, a path traversal in the Telerik Web Forms RadImageEditor, and CVE-2026-19219, a DialogHandler UploadPaths tampering vulnerability. Administrators are encouraged to review the provided links and apply available updates.

Erlang security advisory (AV26-870)

Canada's Cyber Centre warns that multiple Erlang/OTP versions are affected by vulnerabilities and urges administrators to apply updates.

The Canadian Centre for Cyber Security issued advisory AV26-870 on September 1, 2026, noting vulnerabilities affecting Erlang OTP across multiple versions. The bulletin contains no CVE identifiers or exploitation details and directs users and administrators to Erlang's own security advisories to apply necessary updates.

Canadian Centre for Cyber Security · 14d agoAdvisory

Rockwell Automation security advisory (AV26-869)

Canada's Cyber Centre flags vulnerabilities across multiple Rockwell Automation ICS products including ControlLogix 5580 and RSLinx Classic.

Canadian Centre for Cyber Security advisory AV26-869, dated September 1, 2026, lists vulnerabilities in Rockwell Automation products: 1756-ENBT Module (all versions), ArmorStart LT (v2.001 and earlier), CompactLogix 5380 / ControlLogix 5580 (V33 and earlier plus several V34-V36 releases), and RSLinx Classic (V4.50 and earlier). It references Rockwell advisories SD1792, SD1794, SD1797, and SD1798 and urges users to apply updates as available.

Canadian Centre for Cyber Security · 14d agoAdvisory

Mozilla security advisory (AV26-868)

Canada's Cyber Centre reports Mozilla vulnerabilities fixed in Firefox 155 and Firefox ESR 115.40, 140.15, and 153.2.

Canadian Centre for Cyber Security advisory AV26-868, dated September 1, 2026, notes vulnerabilities in Firefox (versions prior to 155) and Firefox ESR (prior to 115.40, 140.15, and 153.2). The bulletin links to Mozilla's security advisories and urges users and administrators to update. No CVE identifiers or exploitation details are provided.

Canadian Centre for Cyber Security · 14d agoAdvisory

WebPros security advisory (AV26-866)

Canada's Cyber Centre relays a WebPros advisory for CVE-2026-67394, a Plesk privilege escalation flaw to root, fixed in 18.0.79.9 and 18.0.80.5.

The Canadian Centre for Cyber Security issued alert AV26-866 relaying WebPros' security advisory for Plesk. CVE-2026-67394 allows privilege escalation to root and affects Plesk versions prior to 18.0.79.9 and 18.0.80.5. Administrators are encouraged to review the advisory and apply the available updates.

WatchGuard security advisory (AV26-865)

Canada's Cyber Centre warns WatchGuard Dimension and Fireware OS vulnerabilities affect multiple versions and urges administrators to apply available updates.

The Canadian Centre for Cyber Security issued advisory AV26-865 (August 31, 2026) noting that WatchGuard products are affected by vulnerabilities as of August 27, 2026. Affected products include Dimension prior to 2.3.1 and Fireware OS prior to 12.12.2, 12.5.20, and 2026.2.2. Users and administrators are encouraged to review the advisory link and apply updates as they become available.

Canadian Centre for Cyber Security · 15d agoAdvisory

Redis security advisory (AV26-859)

Canada's Cyber Centre flagged a use-after-free in Redis 8.0's TLS handling, fixed in versions 8.2.9, 8.4.6, 8.6.6, 8.8.2, and 8.10.1.

Canada's Cyber Centre issued advisory AV26-859 for a use-after-free bug in Redis's tlsProcessPendingData() pending-list iteration, affecting the Redis 8.0 series. Fixed releases include 8.2.9, 8.4.6, 8.6.6, 8.8.2, and 8.10.1. Users and administrators are encouraged to review vendor guidance and update. No CVE identifier or exploitation details were provided in the advisory text.

Canadian Centre for Cyber Security · 19d agoAdvisory

ServiceNow security advisory (AV26-857)

Canada's Cyber Centre relays ServiceNow advisories affecting Xanadu, Yokohama, Zurich and Australia releases, urging administrators to patch.

The Canadian Centre for Cyber Security advisory AV26-857 reports that multiple ServiceNow product lines are affected by vulnerabilities: Xanadu prior to Patch 11 Hot Fix 7a, Yokohama prior to Patch 12 Hot Fix 3b and Patch 13 Hot Fix 4, plus multiple Zurich and Australia versions. Administrators are encouraged to review the linked vendor advisories and apply available updates.

Canadian Centre for Cyber Security · 19d agoAdvisory

[Control Systems] National Instruments security advisory (AV26-856)

Canada's Cyber Centre relayed National Instruments advisories for memory corruption, out-of-bounds read, and out-of-bounds write flaws in LabVIEW versions.

The Canadian Centre for Cyber Security published control systems advisory AV26-856 covering National Instruments LabVIEW. Affected versions include releases before 23.0.0, 23.3.10, 24.3.7, 25.3.5, and 26.3.1. The flaws include memory corruption, an integer conversion out-of-bounds read, and an integer overflow out-of-bounds write. Users and administrators are urged to review the links and apply NI security updates.

Canadian Centre for Cyber Security · 19d agoAdvisory

Microsoft security advisory – August 2026 monthly rollup (AV26-804) – Update 2

Canada's Cyber Centre updated advisory AV26-804 relaying Microsoft's August 2026 monthly rollup of vulnerabilities across .NET and Azure products.

The Canadian Centre for Cyber Security advisory AV26-804, updated August 27, 2026, relays Microsoft's August 2026 monthly security rollup originally issued August 11. Affected products include .NET 8.0, 9.0, and 10.0 on Linux, macOS, and Windows, plus many Azure services. Listed Azure components include Azure Kubernetes Service, Azure SQL Database, Azure Service Bus, Azure Active Directory, Azure Logic Apps, and Azure Monitor Agent.

Canadian Centre for Cyber Security · 19d agoAdvisory1

Veeam security advisory (AV26-855)

Canada's Cyber Centre advisory AV26-855 says Veeam Backup & Replication and Veeam ONE vulnerabilities are resolved in 13.0.3 and 13.1 updates.

Advisory AV26-855, dated August 27, 2026, states that as of August 25 Veeam is affected by vulnerabilities in Backup & Replication (prior to 13.0.3 build 13.0.3.63 and prior to 13.1 build 13.1.0.411) and Veeam ONE (prior to or equal to 13.0.2.6723 and 13.1.0.7034). Fixes are documented in KB4902 (Veeam Backup & Replication 13.1) and KB4905 (Veeam ONE 13.1 Patch 0). The Cyber Centre urges users and administrators to apply the available updates. No CVE identifiers or exploitation details are given.

Canadian Centre for Cyber Security · 20d agoAdvisory

WebPros security advisory (AV26-854)

Canadian Centre for Cyber Security relayed a WebPros advisory covering Plesk vulnerabilities CVE-2026-65642 and CVE-2026-65647 with fixed versions released.

WebPros released a security advisory affecting Plesk versions prior to 18.0.79.8 and 18.0.80.4, Plesk Migrator prior to 2.36.0, and Plesk Site Import prior to 1.12.1. The listed vulnerabilities are CVE-2026-65642 in Plesk's database management interface and CVE-2026-65647 in the Site Import and Migrator extensions. The Canadian Centre for Cyber Security (AV26-854) encourages users and administrators to apply the available updates.

TeamViewer security advisory (AV26-852)

Canada's Cyber Centre warns that multiple TeamViewer client products are affected by vulnerabilities, urging users to update to 15.64.7 or later.

Advisory AV26-852, dated August 26, 2026, reports vulnerabilities in TeamViewer Full Client, Host, and QuickSupport across multiple versions and platforms, and in Portable prior to 15.64.7. The Canadian Centre for Cyber Security encourages users and administrators to apply the necessary updates, referencing TeamViewer security bulletins TV-2026-1008 and TV-2026-1009. No exploitation details are provided in the advisory.

Canadian Centre for Cyber Security · 20d agoAdvisory

OpenSSL security advisory (AV26-846)

Canada's Cyber Centre relayed an OpenSSL advisory (AV26-846) covering vulnerabilities fixed across seven branches, urging users to update to patched releases.

Canadian Centre for Cyber Security bulletin AV26-846 states that OpenSSL is affected by vulnerabilities fixed in 1.0.2zr, 1.1.1zi, 3.0.22, 3.4.7, 3.5.8, 3.6.4, and 4.0.2. Given OpenSSL's ubiquity in TLS stacks, administrators should review the OpenSSL advisories and apply updates. The bulletin includes no exploitation details or CVE identifiers.

Canadian Centre for Cyber Security · 21d agoAdvisory

Google security advisory (AV26-844)

Canada's Cyber Centre relays a Google advisory urging updates for Chrome versions prior to 151.0.7922.173 to address vulnerabilities.

The Canadian Centre for Cyber Security issued advisory AV26-844, noting that as of August 20, 2026, Google Chrome prior to version 151.0.7922.173 is affected by vulnerabilities. The Cyber Centre encourages users and administrators to review Google's advisory and apply the necessary updates. No exploitation details or CVE identifiers are provided in the bulletin text.

Canadian Centre for Cyber Security · 22d agoAdvisory

Dell security advisory (AV26-843)

Canada's Cyber Centre issued advisory AV26-843 covering Dell vulnerabilities requiring updates across Alienware, PowerScale, PowerStore, and other products.

The Canadian Centre for Cyber Security published advisory AV26-843 on August 24, 2026, noting Dell products affected by vulnerabilities as of August 17, 2026. Affected products include Alienware Command Center prior to 6.14.20.0, Dell Command Update prior to 5.7.1, Dell Networking OS10 prior to 10.5.6.14, PowerScale OneFS prior to 14.1, PowerStore OS prior to 5.0.0.2, OpenManage Enterprise prior to 4.7.0, ObjectScale prior to 4.3.0.1, Metro Node prior to 4.6.0.4, and others. Users are directed to apply the vendor's updates.

Canadian Centre for Cyber Security · 23d agoAdvisory