Canadian Centre for Cyber Security Alerts & Advisories.
The Canadian Cyber Centre issues alerts and advisories on potential, imminent or actual cyber threats, vulnerabilities or incidents affecting Canada’s critical infrastructure.
- WordPress security advisory (AV26-723)by Canadian Centre for Cyber Security on July 20, 2026 at 7:01 pm
<article data-history-node-id="8011" about="/en/alerts-advisories/wordpress-security-advisory-av26-723" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial number:</strong> AV26-723<br /><strong>Date:</strong> July 20, 2026</p> <p>On July 17, 2026, WordPress published a security advisory to address vulnerabilities in the following product:</p> <ul><li>WordPress 7.0 – versions prior to 7.0.2</li> <li>WordPress 6.9 – versions prior to 6.9.5</li> <li>WordPress 6.8 – versions prior to 6.8.6</li> <li>WordPress 7.1 beta – versions prior to 7.1 beta2</li> </ul><p>Open-source reporting indicates that CVE-2026-60137 and CVE-2026-63030 are being exploited in the wild.</p> <p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.</p> <ul class="list-unstyled"><li><a href="https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-fpp7-x2x2-2mjf">Facilitated SQL injection vulnerability in the `author__not_in` parameter of `WP_Query`</a></li> <li><a href="https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-ff9f-jf42-662q">REST API batch-route confusion and SQL injection issue leading to Remote Code Execution</a></li> <li><a href="https://wordpress.org/news/2026/07/wordpress-7-0-2-release/">WordPress 7.0.2 Release</a></li> <li><a href="https://wordpress.org/news/category/releases/">WordPress Releases</a></li> </ul></div> </div> </div> </div> </div> </article>
- HPE security advisory (AV26-722)by Canadian Centre for Cyber Security on July 20, 2026 at 4:02 pm
<article data-history-node-id="8010" about="/en/alerts-advisories/hpe-security-advisory-av26-722" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial number:</strong> AV26-722<br /><strong>Date:</strong> July 20, 2026</p> <p>On July 20, 2026, HPE published a security advisory to address vulnerabilities in the following product:</p> <ul><li>HPE Telco Automated Assurance – version v1.4 and prior</li> </ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.</p> <ul class="list-unstyled"><li><a href="https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05082en_us&docLocale=en_US">HPESBNW05082 rev.1 – HPE Telco Automated Assurance, Multiple Vulnerabilities</a></li> <li><a href="https://support.hpe.com/connect/s/securitybulletinlibrary?language=en_US">HPE Security Bulletin Library</a></li> </ul></div> </div> </div> </div> </div> </article>
- ServiceNow security advisory (AV26-693) – Update 1by Canadian Centre for Cyber Security on July 20, 2026 at 3:57 pm
<article data-history-node-id="7977" about="/en/alerts-advisories/servicenow-security-advisory-av26-693" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial number: </strong>AV26-693<br /><strong>Date: </strong>July 14, 2026<br /><strong>Updated:</strong> July 20, 2026</p> <p>On July 13, 2026, ServiceNow published a security advisory to address a critical vulnerability in the following products:</p> <ul><li>Brazil – versions prior to Brazil EA and Brazil GA</li> <li>Australia – versions prior to Australia Patch 2</li> <li>Zurich – versions prior to Zurich Patch 7b and Zurich Patch 9</li> <li>Yokohama – versions prior to Yokohama Patch 12 Hot Fix 1b and Yokohama Patch 13</li> </ul><h2 class="h3">Update 1</h2> <p>Open-source reporting indicates that CVE-2026-6875 is being exploited in the wild.</p> <p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.</p> <ul class="list-unstyled"><li><a href="https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB3137947">[Security Advisory] CVE-2026-6875 – Sandbox Escape in ServiceNow AI Platform</a></li> <li><a href="https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1226057">ServiceNow security advisories</a></li> </ul></div> </div> </div> </div> </div> </article>
- Zimbra security advisory (AV26-721)by Canadian Centre for Cyber Security on July 20, 2026 at 3:36 pm
<article data-history-node-id="8009" about="/en/alerts-advisories/zimbra-security-advisory-av26-721" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial number:</strong> AV26-721<br /><strong>Date:</strong> July 20, 2026</p> <p>On July 20, 2026, Zimbra published a security advisory to address vulnerabilities in the following product:</p> <ul><li>Zimbra Collaboration Suite (ZCS) Classic Web Client – versions prior to v10.1.20</li> </ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.</p> <ul class="list-unstyled"><li><a href="https://blog.zimbra.com/2026/07/patch-release-update-zimbra-10-1-20/">Patch Release Update: Zimbra 10.1.20</a></li> <li><a href="https://blog.zimbra.com/">Zimbra Patch Release Updates</a></li> </ul></div> </div> </div> </div> </div> </article>
- GitHub security advisory (AV26-720)by Canadian Centre for Cyber Security on July 20, 2026 at 3:31 pm
<article data-history-node-id="8007" about="/en/alerts-advisories/github-security-advisory-av26-720" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial number:</strong> AV26-720<br /><strong>Date:</strong> July 20, 2026</p> <p>On July 16, 2026, GitHub published security advisories to address vulnerabilities in the following products:</p> <ul><li>GitHub Enterprise Server – versions 3.21.x prior to 3.21.3</li> <li>GitHub Enterprise Server – versions 3.20.x prior to 3.20.5</li> <li>GitHub Enterprise Server – versions 3.19.x prior to 3.19.9</li> <li>GitHub Enterprise Server – versions 3.18.x prior to 3.18.12</li> <li>GitHub Enterprise Server – versions 3.17.x prior to 3.17.18</li> </ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.</p> <ul class="list-unstyled"><li><a href="https://docs.github.com/en/enterprise-server@3.21/admin/release-notes">Enterprise Server 3.21.3</a></li> <li><a href="https://docs.github.com/en/enterprise-server@3.20/admin/release-notes">Enterprise Server 3.20.5</a></li> <li><a href="https://docs.github.com/en/enterprise-server@3.19/admin/release-notes">Enterprise Server 3.19.9</a></li> <li><a href="https://docs.github.com/en/enterprise-server@3.18/admin/release-notes">Enterprise Server 3.18.12</a></li> <li><a href="https://docs.github.com/en/enterprise-server@3.17/admin/release-notes">Enterprise Server 3.17.18</a></li> </ul></div> </div> </div> </div> </div> </article>
- Red Hat security advisory (AV26-719)by Canadian Centre for Cyber Security on July 20, 2026 at 3:28 pm
<article data-history-node-id="8006" about="/en/alerts-advisories/red-hat-security-advisory-av26-719" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial number: </strong>AV26-719<br /><strong>Date: </strong>July 20, 2026</p> <p>Between July 13 and 19, 2026, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:</p> <ul><li>Red Hat CodeReady Linux Builder – multiple versions and platforms</li> <li>Red Hat Enterprise Linux – multiple versions and platforms</li> <li>Red Hat Enterprise Linux Server – multiple versions and platforms</li> <li>Red Hat Enterprise Linux for Real Time – multiple versions and platforms</li> </ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.</p> <ul class="list-unstyled"><li><a href="https://access.redhat.com/security/security-updates/security-advisories">Red Hat Security Advisories</a></li> </ul></div> </div> </div> </div> </div> </article>
- [Control systems] CISA ICS security advisories (AV26-718)by Canadian Centre for Cyber Security on July 20, 2026 at 3:23 pm
<article data-history-node-id="8005" about="/en/alerts-advisories/control-systems-cisa-ics-security-advisories-av26-718" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial number: </strong>AV26–718<br /><strong>Date: </strong>July 20, 2026</p> <p>Between July 13 and 19, 2026, CISA published ICS advisories to address vulnerabilities in the following products:</p> <ul><li>ABB 800xA for Advant Master – multiple versions</li> <li>ABB Ability Edgenius – multiple versions and models</li> <li>ABB Control Builder A – version 1.4/4 and prior</li> <li>ABB T-MAC Plus – version 4.0-24</li> <li>AutomationDirect Productivity Suite – version v4.6.2.2 and prior</li> <li>NASA Core Flight System (cFS) Health & Safety (HS) Application – versions prior to v7.0.1</li> <li>Rockwell Automation 1715-AENTR EtherNet/IP Adapter – version 3.003 and prior</li> <li>Rockwell Automation 1756-EN2 – version V12.001 and prior</li> <li>Rockwell Automation 1756-EN3 – version V12.001 and prior</li> <li>Rockwell Automation 1756-ENBT – version V6.006</li> <li>Rockwell Automation Arena – version V17.00.00 and prior</li> <li>Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix – multiple versions and models</li> <li>Rockwell Automation FactoryTalk DataMosaix Private Cloud – version 8.02 and prior</li> <li>Rockwell Automation Flex 5000 Adapter – version 6.011</li> <li>SALTO ProAccess Space – versions prior to 6.13</li> <li>Siemens SICAM 8 CPCI85 Central Processing/Communication – versions prior to 26.20</li> <li>Siemens SICAM 8 SICORE Base system – versions prior to 26.20.0</li> </ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations, and apply the necessary updates if available.</p> <ul class="list-unstyled"><li><a href="https://www.cisa.gov/news-events/cybersecurity-advisories">CISA ICS Advisories</a></li> </ul></div> </div> </div> </div> </div> </article>
- Ubuntu security advisory (AV26-717)by Canadian Centre for Cyber Security on July 20, 2026 at 3:21 pm
<article data-history-node-id="8004" about="/en/alerts-advisories/ubuntu-security-advisory-av26-717" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial number: </strong>AV26-717<br /><strong>Date:</strong> July 20, 2026</p> <p>Between July 13 and 19, 2026, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:</p> <ul><li>Ubuntu 14.04 LTS</li> <li>Ubuntu 16.04 LTS</li> <li>Ubuntu 20.04 LTS</li> <li>Ubuntu 24.04 LTS</li> <li>Ubuntu 25.10</li> </ul><p>The Cyber Centre encourages users and administrators to review the web link provided and apply the necessary updates.</p> <ul class="list-unstyled"><li><a href="https://ubuntu.com/security/notices">Ubuntu Security Notices</a></li> </ul></div> </div> </div> </div> </div> </article>
- Dell security advisory (AV26-716)by Canadian Centre for Cyber Security on July 20, 2026 at 3:18 pm
<article data-history-node-id="8003" about="/en/alerts-advisories/dell-security-advisory-av26-716" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial number: </strong>AV26-716<br /><strong>Date:</strong> July 20, 2026</p> <p>Between July 13 and 19, 2026, Dell published security advisories to address vulnerabilities in multiple products:</p> <ul><li>Dell DRAC9 – versions prior to 7.00.00.184</li> <li>Dell PowerEdge Server – multiple versions and models</li> <li>Dell PowerProtect Data Manager – versions prior to 20.2.0.0</li> <li>Dell SmartFabric Manager – versions prior to 2.2.1</li> <li>Dell Storage Monitoring and Reporting – versions prior to 6.1.1.0</li> <li>Dell Storage Resource Manager – versions prior to 6.1.1.0</li> <li>Dell ThinOS 10 – multiple versions and models</li> <li>Dell iDRAC9 – versions prior to 7.30.30.51</li> </ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.</p> <ul class="list-unstyled"><li><a href="https://www.dell.com/support/security/en-ca">Dell Security advisories and notices</a></li> </ul></div> </div> </div> </div> </div> </article>
- IBM security advisory (AV26-715)by Canadian Centre for Cyber Security on July 20, 2026 at 3:14 pm
<article data-history-node-id="8002" about="/en/alerts-advisories/ibm-security-advisory-av26-715" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial number: </strong>AV26-715<br /><strong>Date: </strong>July 20, 2026</p> <p>Between July 13 and 19, 2026, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:</p> <ul><li>IBM API Connect V12 OnPrem – versions v12.1.0.0 to v12.1.1.0</li> <li>IBM Automation Decision Services – versions 24.0.0, 24.0.1 and 25.0.0</li> <li>IBM CICS Transaction Gateway Desktop Edition – versions prior to 10.1</li> <li>IBM CICS Transaction Gateway for Multiplatforms – versions prior to 10.1</li> <li>IBM Cloud Object Storage System – versions 3.20.0.0 to 3.20.1.66</li> <li>IBM Cloud Object Storage System – versions 3.8.1.54 to 3.19.5.56</li> <li>IBM Datacap Navigator – versions 9.1.7, 9.1.8 and 9.1.9</li> <li>IBM Datacap – versions 9.1.7, 9.1.8 and 9.1.9</li> <li>IBM Engineering AI Hub – versions 1.0.0, 1.1.0 and 1.2.0</li> <li>IBM Guardium Data Protection – version 12.1 and 12.2</li> <li>IBM Guardium Unified Discovery and Classification (GUDC) – versions 1.0.0 to 1.2.0</li> <li>IBM Installation Manager – versions prior to 1.10.1.4</li> <li>IBM Jazz Reporting Service – multiple versions</li> <li>IBM Packaging Utility – versions prior to 1.10.1.4</li> <li>IBM Process Automation Manager Open Edition Starter Kit for Banking – versions 9.3.1 to 9.4.1</li> <li>IBM QRadar Data Synchronization App – versions 1.0.0 to 3.3.0</li> <li>IBM QRadar User Behavior Analytics – versions 1.0.0 to 5.1.0</li> <li>IBM Rapid Network Automation – versions prior to 1.1.4 and 1.1.5</li> <li>IBM Sterling Secure Proxy – versions 6.1.0.0 to 6.1.0.4</li> <li>IBM Sterling Secure Proxy – versions 6.2.1.0 to 6.2.1.2 iFix01</li> <li>IBM Tivoli Netcool Configuration Manager – versions 6.4.2 GA to 6.4.2.24</li> <li>IBM WebSphere Service Registry and Repository – versions prior to 8.5</li> <li>IBM i – versions 7.6, 7.5, 7.4 and 7.3</li> <li>IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data – versions 4.8.4 to 4.8.5</li> <li>IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data – versions 5.0.0 to 5.3.3</li> </ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.</p> <ul class="list-unstyled"><li><a href="https://www.ibm.com/support/pages/bulletin/">IBM Product Security Incident Response</a></li> </ul></div> </div> </div> </div> </div> </article>
- Microsoft Edge security advisory (AV26-714)by Canadian Centre for Cyber Security on July 17, 2026 at 6:33 pm
<article data-history-node-id="8001" about="/en/alerts-advisories/microsoft-edge-security-advisory-av26-714" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial number: </strong>AV26-714<br /><strong>Date: </strong>July 17, 2026</p> <p>On July 16, 2026, Microsoft published a security update to address vulnerabilities in the following product:</p> <ul><li>Microsoft Edge Stable Channel – versions prior to 150.0.4078.80</li> </ul><p class="mrgn-bttm-md">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.</p> <ul class="list-unstyled"><li><a href="https://learn.microsoft.com/en-us/DeployEdge/microsoft-edge-relnotes-security#july-16-2026">Microsoft Edge Stable Channel Release Notes</a></li> </ul></div> </div> </div> </div> </div> </article>
- Google Chrome security advisory (AV26-713)by Canadian Centre for Cyber Security on July 17, 2026 at 3:21 pm
<article data-history-node-id="8000" about="/en/alerts-advisories/google-chrome-security-advisory-av26-713" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial number: </strong>AV26-713<br /><strong>Date: </strong>July 17, 2026</p> <p>On July 16, 2026, Google published a security advisory to address vulnerabilities in the following product:</p> <ul><li>Stable Channel Chrome for Desktop – versions prior to 150.0.7871.128/.129 (Windows/Mac), and 150.0.7871.128 (Linux)</li> </ul><p class="mrgn-bttm-md">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.</p> <ul class="list-unstyled"><li><a href="https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_049796704.html">Google Chrome Security Advisory</a></li> </ul></div> </div> </div> </div> </div> </article>
- Broadcom VMware security advisory (AV26-712)by Canadian Centre for Cyber Security on July 17, 2026 at 3:04 pm
<article data-history-node-id="7999" about="/en/alerts-advisories/broadcom-vmware-security-advisory-av26-712" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial number: </strong>AV26-712<br /><strong>Date: </strong>July 17, 2026</p> <p>On July 14, 2026, Broadcom published security advisories to address vulnerabilities in multiple products. Included was a critical update for the following:</p> <ul><li>VMware Avi Load Balancer – multiple versions</li> </ul><p class="mrgn-bttm-md">The Cyber Centre encourages users and administrators to review the web links provided and apply the necessary updates.</p> <ul class="list-unstyled"><li><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37926">VMSA-2026-0005: VMware Avi Load Balancer addresses multiple vulnerabilities (CVE-2026-47865, CVE-2026-47866, CVE-2026-47867, CVE-2026-47868, CVE-2026-47869, CVE-2026-47870, CVE-2026-47871) </a></li> <li><a href="https://support.broadcom.com/web/ecx/security-advisory?segment=VA">Security Advisories – Application Networking and Security</a></li> </ul></div> </div> </div> </div> </div> </article>
- FreePBX security advisory (AV26–711)by Canadian Centre for Cyber Security on July 17, 2026 at 2:16 pm
<article data-history-node-id="7998" about="/en/alerts-advisories/freepbx-security-advisory-av26-711" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial number: </strong>AV26-711<br /><strong>Date: </strong>July 17, 2026</p> <p>On July 17, 2026, FreePBX published security advisories to address vulnerabilities in the following products. Included were critical updates for the following:</p> <ul><li>FreePBX Security-Reporting ucp (FreePBX 17) – versions prior to 17.0.9</li> <li>FreePBX Security-Reporting missedcall (FreePBX 16) – versions prior to 16.0.11</li> <li>FreePBX Security-Reporting missedcall (FreePBX 16) – versions prior to 17.0.6</li> <li>FreePBX Security-Reporting tts (FreePBX 17) – versions prior to 17.0.6</li> <li>FreePBX Security-Reporting tts (FreePBX 16) – versions prior to 16.0.6</li> <li>FreePBX Security-Reporting music (FreePBX 17) – versions prior to 17.0.7</li> <li>FreePBX Security-Reporting framework (FreePBX 16) – versions prior to 16.0.47</li> <li>FreePBX Security-Reporting framework (FreePBX 17) – versions prior to 17.0.30</li> </ul><p class="mrgn-bttm-md">The Cyber Centre encourages users and administrators to review the web links provided, apply the necessary updates and perform the suggested mitigations.</p> <ul class="list-unstyled"><li><a href="https://github.com/FreePBX/security-reporting/security/advisories/GHSA-37j8-fhxx-9vhp ">Unauthenticated remote code execution in FreePBX UCP via socket.io namespace auth bypass and AMI action injection</a></li> <li><a href="https://github.com/FreePBX/security-reporting/security/advisories/GHSA-g27h-xf3q-h3rm ">Unauthenticated SQL injection in FreePBX missedcall via inbound Caller ID name leads to administrator takeover</a></li> <li><a href="https://github.com/FreePBX/security-reporting/security/advisories/GHSA-hg3v-m857-mvw9 ">Authenticated TTS AGI Command Injection Through TTS Name</a></li> <li><a href="https://github.com/FreePBX/security-reporting/security/advisories/GHSA-p97w-rq48-p8q2 ">Authenticated FreePBX Music RCE via mpg123 and Asterisk Call Files</a></li> <li><a href="https://github.com/FreePBX/security-reporting/security/advisories/GHSA-f6hc-rqxg-ch86 ">Authenticated Framework AUTHTYPE Can Be Restored From a Crafted Backup</a></li> <li><a href="https://github.com/FreePBX/security-reporting/security/advisories?state=published">FreePBX Security Advisories</a></li> </ul></div> </div> </div> </div> </div> </article>
- Fortinet security advisory (AV26-351) – Update 2by Canadian Centre for Cyber Security on July 16, 2026 at 7:18 pm
<article data-history-node-id="7556" about="/en/alerts-advisories/fortinet-security-advisory-av26-351" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial number: </strong>AV26-351<br /><strong>Date: </strong>April 14, 2026<br /><strong>Updated:</strong> July 16, 2026</p> <p>On April 14, 2026, Fortinet published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:</p> <ul><li>FortiSandbox 4.4 – versions 4.4.0 to 4.4.8</li> <li>FortiSandbox 5.0 – versions 5.0.0 to 5.0.5</li> <li>FortiAnalyzer Cloud 7.6 – versions 7.6.2 to 7.6.4</li> <li>FortiManager Cloud 7.6 – versions 7.6.2 to 7.6.4</li> <li>FortiDDoS-F 7.2 – versions 7.2.1 to 7.2.2</li> </ul><h2 class="h3">Update 1</h2> <p>Open-source reporting indicates that CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089 have been exploited.</p> <h2 class="h3">Update 2</h2> <p>On July 16, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-39808 to their Known Exploited Vulnerabilities (KEV) Database.</p> <p class="mrgn-bttm-md">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.</p> <ul class="list-unstyled"><li><a href="https://fortiguard.fortinet.com/psirt/FG-IR-26-100">OS Command Injection through API endpoint</a></li> <li><a href="https://fortiguard.fortinet.com/psirt/FG-IR-26-112">Unauthenticated Authentication bypass and Privilege escalation in FortiSandbox</a></li> <li><a href="https://fortiguard.fortinet.com/psirt/FG-IR-26-121">Heap-based buffer overflow in oftpd daemon</a></li> <li><a href="https://fortiguard.fortinet.com/psirt/FG-IR-26-119">SQL Injection via API</a></li> <li><a href="https://www.fortiguard.com/psirt?filter=1&version=&severity=5&severity=4&severity=3&severity=2">Fortinet PSIRT Advisories</a></li> <li><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-39808">CISA KEV : CVE-2026-39808</a></li> </ul></div> </div> </div> </div> </div> </article>
- Fortinet security advisory (AV26-568) – Update 1by Canadian Centre for Cyber Security on July 16, 2026 at 7:01 pm
<article data-history-node-id="7809" about="/en/alerts-advisories/fortinet-security-advisory-av26-568" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial number: </strong>AV26-568<br /><strong>Date: </strong>June 9, 2026<br /><strong>Updated: </strong>July 16, 2026</p> <p>On June 9, 2026, Fortinet published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:</p> <ul><li>FortiSandbox 5.0 – versions 5.0.0 to 5.0.5</li> <li>FortiSandbox 4.4 – versions 4.4.0 to 4.4.8</li> <li>FortiSandbox Cloud 5.0 – versions 5.0.4 to 5.0.5</li> <li>FortiSandbox PaaS 5.0 – versions 5.0.4 through 5.0.5</li> </ul><h2 class="h3"> Update 1 </h2> <p> On July 16, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-25089 to their Known Exploited Vulnerabilities (KEV) Database. </p> <p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.</p> <ul class="list-unstyled"><li><a href="https://fortiguard.fortinet.com/psirt/FG-IR-26-141">Second-Order OS Command Injection via JSON Input on start vnc feature</a></li> <li><a href="https://www.fortiguard.com/psirt?filter=1&version=&severity=5&severity=4&severity=3&severity=2">Fortinet PSIRT Advisories</a></li> <li><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-25089">CISA KEV: CVE-2026-25089</a></li> </ul></div> </div> </div> </div> </div> </article>
- Microsoft security advisory – July 2026 monthly rollup (AV26-698) – Update 1by Canadian Centre for Cyber Security on July 16, 2026 at 6:41 pm
<article data-history-node-id="7983" about="/en/alerts-advisories/microsoft-security-advisory-july-2026-monthly-rollup-av26-698" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial number: </strong>AV26–698<br /><strong>Date: </strong>July 14, 2026<br /><strong>Updated: </strong>July 16, 2026</p> <p>On July 14, 2026, Microsoft published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:</p> <ul><li>.NET 10.0 installed on Linux</li> <li>.NET 10.0 installed on Mac OS</li> <li>.NET 10.0 installed on Windows</li> <li>.NET 8.0 installed on Linux</li> <li>.NET 8.0 installed on Mac OS</li> <li>.NET 8.0 installed on Windows</li> <li>.NET 9.0 installed on Linux</li> <li>.NET 9.0 installed on Mac OS</li> <li>.NET 9.0 installed on Windows</li> <li>Age of Empires II: Definitive Edition Game</li> <li>Azure Active Directory</li> <li>Azure CycleCloud 8.9.1</li> <li>Azure Monitor Agent Metrics Extension</li> <li>Azure Open AI</li> <li>Azure Spring Apps</li> <li>Azure Synapse</li> <li>Fabric Data Warehouse</li> <li>GitHub Copilot Plugin for JetBrains IDEs</li> <li>Microsoft .NET Framework</li> <li>Microsoft .NET Framework 3.5</li> <li>Microsoft .NET Framework 4.8.1</li> <li>Microsoft 365 Apps</li> <li>Microsoft 365 Apps for Enterprise</li> <li>Microsoft 365 Copilot</li> <li>Microsoft 365 Copilot for Android</li> <li>Microsoft 365 Copilot for iOS</li> <li>Microsoft Bing Search for iOS</li> <li>Microsoft Defender for Endpoint for Mac</li> <li>Microsoft Dynamics NAV 2018</li> <li>Microsoft Edge (Chromium-based)</li> <li>Microsoft Entra Provisioning Service</li> <li>Microsoft Excel 2016</li> <li>Microsoft Exchange Online</li> <li>Microsoft Exchange Server 2016</li> <li>Microsoft Exchange Server 2019</li> <li>Microsoft Exchange Server Subscription Edition RTM</li> <li>Microsoft Malware Protection Engine</li> <li>Microsoft Office 2016</li> <li>Microsoft Office 2019</li> <li>Microsoft Office 365 for Mac</li> <li>Microsoft Office LTSC 2021</li> <li>Microsoft Office LTSC 2024</li> <li>Microsoft Office LTSC for Mac 2021</li> <li>Microsoft Office LTSC for Mac 2024</li> <li>Microsoft Office for Android</li> <li>Microsoft PC Manager</li> <li>Microsoft PowerPoint 2016</li> <li>Microsoft SQL Server 2016</li> <li>Microsoft SQL Server 2017</li> <li>Microsoft SQL Server 2019</li> <li>Microsoft SQL Server 2022</li> <li>Microsoft SQL Server 2025</li> <li>Microsoft SharePoint Enterprise Server 2016</li> <li>Microsoft SharePoint Server 2019</li> <li>Microsoft SharePoint Server Subscription Edition</li> <li>Microsoft Surface Go 2</li> <li>Microsoft Surface Go 3</li> <li>Microsoft Surface Hub</li> <li>Microsoft Surface Hub 2S</li> <li>Microsoft Surface Hub 3</li> <li>Microsoft Surface Laptop Go</li> <li>Microsoft Surface Laptop Go 2</li> <li>Microsoft Surface Laptop Go 3</li> <li>Microsoft Surface Pro 7+</li> <li>Microsoft Surface Pro 8</li> <li>Microsoft Visual Studio 2022</li> <li>Microsoft Visual Studio 2026</li> <li>Microsoft Word 2016</li> <li>AspNet.OData</li> <li>AspNetCore.OData</li> <li>Minecraft Bedrock Dedicated Server</li> <li>Office Online Server</li> <li>Power BI Report Server</li> <li>Surface Laptop 4 with AMD Processor</li> <li>Surface Laptop 4 with Intel Processor</li> <li>Surface Windows Dev Kit</li> <li>Visual Studio Code</li> <li>Windows 10</li> <li>Windows 11</li> <li>Windows 11 Version</li> <li>Windows Admin Center</li> <li>Windows Remote Help</li> <li>Windows Server 2012</li> <li>Windows Server 2012 R2</li> <li>Windows Server 2016</li> <li>Windows Server 2019</li> <li>Windows Server 2022</li> <li>Windows Server 2025</li> <li>Windows Subsystem for Linux (WSL2)</li> <li>Windows Terminal for Windows 10</li> <li>Windows Terminal for Windows 11</li> </ul><p>Microsoft has indicated that CVE-2026-56164 and CVE-2026-56155 are being exploited.</p> <p>On July 14, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-56164 and CVE-2026-56155 to their Known Exploited Vulnerabilities (KEV) Database.</p> <h2 class="h3">Update 1</h2> <p>On July 16, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-58644 to their Known Exploited Vulnerabilities (KEV) Database.</p> <p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.</p> <ul class="list-unstyled"><li><a href="https://msrc.microsoft.com/update-guide/releaseNote/2026-Jul">July 2026 Security Updates</a></li> <li><a href="https://msrc.microsoft.com/update-guide/en-us">Security Update Guide</a></li> <li><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-56164">CISA KEV: CVE-2026-56164</a></li> <li><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-56155 ">CISA KEV: CVE-2026-56155</a></li> <li><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-58644">CISA KEV: CVE-2026-58644</a></li> </ul><!–CUT & PASTE the French version info –></div> </div> </div> </div> </div> </article>
- Grafana security advisory (AV26-710)by Canadian Centre for Cyber Security on July 16, 2026 at 6:13 pm
<article data-history-node-id="7997" about="/en/alerts-advisories/grafana-security-advisory-av26-710" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial number: </strong>AV26-710<br /><strong>Date: </strong>July 16, 2026</p> <p>On July 15, 2026, Grafana published security advisories to address vulnerabilities in the following products:</p> <ul><li>Grafana MCP Server – version 0.17.1 and prior</li> <li>Grafana Loki – version 3.7.0 and prior</li> </ul><p class="mrgn-bttm-md">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.</p> <ul class="list-unstyled"><li><a href="https://grafana.com/security/security-advisories/cve-2026-15583/">Grafana MCP server-side request forgery via X-Grafana-URL header</a></li> <li><a href="https://grafana.com/security/security-advisories/cve-2026-21729/">Loki detected_fields query limits results in unbounded memory allocation</a></li> <li><a href="https://grafana.com/blog/">Grafana Blog</a></li> </ul></div> </div> </div> </div> </div> </article>
- JetBrains security advisory (AV26-709)by Canadian Centre for Cyber Security on July 16, 2026 at 3:07 pm
<article data-history-node-id="7996" about="/en/alerts-advisories/jetbrains-security-advisory-av26-709" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial number: </strong>AV26-709<br /><strong>Date: </strong>July 16, 2026</p> <p>On July 14, 2026, JetBrains published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:</p> <ul><li>JetBrains TeamCity – versions prior to 2026.1.2</li> <li>JetBrains YouTrack – multiple versions</li> <li>JetBrains IntelliJ IDEA – versions prior to 2026.1.4 and 2026.2</li> </ul><p class="mrgn-bttm-md">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.</p> <ul class="list-unstyled"><li><a href="https://www.jetbrains.com/privacy-security/issues-fixed/">JetBrains – Fixed security issues</a></li> </ul></div> </div> </div> </div> </div> </article>
- Splunk security advisory (AV26-708)by Canadian Centre for Cyber Security on July 16, 2026 at 1:05 pm
<article data-history-node-id="7995" about="/en/alerts-advisories/splunk-security-advisory-av26-708" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial number: </strong>AV26-708<br /><strong>Date: </strong>July 16, 2026</p> <p>On July 15, 2026, Splunk published security advisories to address vulnerabilities in the following products. Included were critical updates for the following:</p> <ul><li>Splunk Enterprise – multiple versions and platforms</li> <li>Splunk Cloud Platform – multiple versions and platforms</li> </ul><p class="mrgn-bttm-md">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.</p> <ul class="list-unstyled"><li><a href="https://advisory.splunk.com/advisories/SVD-2026-0702">SPL Command Safeguards Bypass through Cross-Site Request Forgery (CSRF) in Deployment Server in Splunk Enterprise</a></li> <li><a href="https://advisory.splunk.com/advisories/SVD-2026-0703">Path Traversal through ‘explicit_appname’ in the App Install REST Endpoint in Splunk Enterprise</a></li> <li><a href="https://advisory.splunk.com/advisories/SVD-2026-0705">Third-Party Package Updates in Splunk Enterprise – July 2026</a></li> <li><a href="https://advisory.splunk.com/advisories">Splunk Security Advisories</a></li> </ul></div> </div> </div> </div> </div> </article>






