Canadian Government Cyber Alerts.
- SUSE Linux security advisory (AV26-882)by Canadian Centre for Cyber Security on September 3, 2026 at 7:47 pm
<article data-history-node-id="8182" about="/en/alerts-advisories/suse-linux-security-advisory-av26-882" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial Number: </strong>AV26-882<br /><strong>Date: </strong>September 3, 2026</p> <p>As of September 3, 2026, SUSE is affected by vulnerabilities in the following product:</p> <ul><li>Rancher <ul><li>Prior to 2.15.1</li> </ul></li> </ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.</p> <ul class="list-unstyled"><li><a href="https://github.com/rancher/rancher/releases/tag/v2.15.1">Release v2.15.1 ¡ rancher/rancher ¡ GitHub </a></li> <li><a href="https://www.suse.com/support/update/">SUSE Update Advisories</a></li> </ul><!–CUT & PASTE the French version info –></div> </div> </div> </div> </div> </article>
- [Control Systems] Siemens security advisory (AV26-881)by Canadian Centre for Cyber Security on September 3, 2026 at 7:32 pm
<article data-history-node-id="8181" about="/en/alerts-advisories/control-systems-siemens-security-advisory-av26-881" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial Number: </strong>AV26-881<br /><strong>Date: </strong>September 3, 2026</p> <p>As of September 3, 2026, Siemens is affected by a vulnerability in the following products:</p> <ul><li>Mendix SAML (Mendix 10 compatible) <ul><li>Prior to V4.2.3</li> </ul></li> <li>Mendix SAML (Mendix 11 compatible) <ul><li>Prior to V4.2.3</li> </ul></li> <li>Mendix SAML (Mendix 9.24 compatible) <ul><li>Prior to V3.6.27</li> </ul></li> </ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.</p> <ul class="list-unstyled"><li><a href="https://cert-portal.siemens.com/productcert/html/ssa-887643.html">SSA-887643: Account Hijacking Vulnerability in Mendix SAML module</a></li> <li><a href="https://www.siemens.com/en-us/content/cert-services/">CERT Services | Siemens</a></li> </ul><!–CUT & PASTE the French version info –></div> </div> </div> </div> </div> </article>
- n8n security advisory (AV26-880)by Canadian Centre for Cyber Security on September 3, 2026 at 6:59 pm
<article data-history-node-id="8180" about="/en/alerts-advisories/n8n-security-advisory-av26-880" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial Number: </strong>AV26-880<br /><strong>Date: </strong>September 3, 2026</p> <p>As of September 3, 2026, n8n is affected by vulnerabilities in the following product:</p> <ul><li>n8n <ul><li>Prior to 1.123.76</li> <li>Prior to 2.35.4</li> <li>Prior to 2.36.2</li> <li>Prior to 2.37.7</li> <li>Prior to 2.38.2</li> </ul></li> </ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.</p> <ul class="list-unstyled"><li><a href="https://github.com/n8n-io/n8n/security">Overview ¡ n8n-io/n8n ¡ GitHub </a></li> </ul><!–CUT & PASTE the French version info –></div> </div> </div> </div> </div> </article>
- AMD security advisory (AV26-879)by Canadian Centre for Cyber Security on September 3, 2026 at 3:05 pm
<article data-history-node-id="8179" about="/en/alerts-advisories/amd-security-advisory-av26-879" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial Number: </strong>AV26-879<br /><strong>Date: </strong>September 3, 2026</p> <p>As of September 2, 2026, AMD is affected by vulnerabilities in the following products:</p> <ul><li>2nd Gen AMD EPYC⢠Processors <ul><li>all except RomePI 1.0.0.H</li> </ul></li> <li>3rd Gen AMD EPYC⢠Processors <ul><li>all except MilanPI 1.0.0.C</li> </ul></li> <li>4th Gen AMD EPYC⢠Processors <ul><li>all except GenoaPI 1.0.0.8</li> </ul></li> <li>AMD Athlon⢠3000 Series Desktop Processors with Radeon⢠Graphics <ul><li>all except ComboAM4 1.0.0.B</li> <li>all except ComboAM4v2 1.2.0.B</li> </ul></li> <li>AMD Athlon⢠3000 Series Mobile Processors with Radeon⢠Graphics <ul><li>all except PicassoPI-FP5 1.0.1.0</li> <li>all except PollockPI-FT5 1.0.0.6</li> </ul></li> <li>AMD EPYC⢠Embedded 3000 <ul><li>all except Snowyowl PI 1.1.0.B</li> </ul></li> <li>AMD EPYC⢠Embedded 7002 <ul><li>all except EmbRomePI-SP3 1.0.0.B</li> </ul></li> <li>AMD EPYC⢠Embedded 7003 <ul><li>all except EmbMilanPI-SP3 1.0.0.8</li> </ul></li> <li>AMD EPYC⢠Embedded 9003 <ul><li>all except EmbGenoaPI-SP5 1.0.0.3</li> </ul></li> <li>AMD Instinct⢠MI300A <ul><li>all except MI300 SR5 PI 1.0.0.1</li> </ul></li> <li>AMD Radeon⢠PRO V620 Graphics Products <ul><li>all except Contact your AMD Customer Engineering representative</li> </ul></li> <li>AMD Ryzen⢠3000 Series Desktop Processors <ul><li>all except ComboAM4 1.0.0.B</li> <li>all except ComboAM4v2 1.2.0.B</li> </ul></li> <li>AMD Ryzen⢠3000 Series Mobile Processor with Radeon⢠Graphics <ul><li>all except PicassoPI-FP5 1.0.1.0</li> </ul></li> <li>AMD Ryzen⢠3000 Series Processors with Radeon⢠Graphics <ul><li>all except CezannePI-FP6 1.0.0.F</li> </ul></li> <li>AMD Ryzen⢠4000 Series Desktop Processors with Radeon⢠Graphics <ul><li>all except ComboAM4v2 1.2.0.B</li> </ul></li> <li>AMD Ryzen⢠4000 Series Mobile Processors with Radeon⢠Graphics <ul><li>all except RenoirPI-FP6 1.0.0.D</li> </ul></li> <li>AMD Ryzen⢠5000 Series Desktop Processors <ul><li>all except ComboAM4v2 1.2.0.B</li> <li>all except ComboAM4v2v 1.2.0.B</li> </ul></li> <li>AMD Ryzen⢠5000 Series Desktop Processors with Radeon⢠Graphics <ul><li>all except ComboAM4v2 1.2.0.B</li> </ul></li> <li>AMD Ryzen⢠5000 Series Mobile Processors with Radeon⢠Graphics <ul><li>all except CezannePI-FP6 1.0.0.F</li> </ul></li> <li>AMD Ryzen⢠5000 Series Processors with Radeon⢠Graphics <ul><li>all except CezannePI-FP6 1.0.0.F</li> </ul></li> <li>AMD Ryzen⢠6000 Series Processors with Radeon⢠Graphics <ul><li>all except RembrandtPI-FP7 1.0.0.9b</li> </ul></li> <li>AMD Ryzen⢠7000 Series Processors <ul><li>all except ComboAM5 1.0.0.7b</li> </ul></li> <li>AMD Ryzen⢠7020 Series Processors with Radeon⢠Graphics <ul><li>all except MendocinoPI-FT6 1.0.0.6</li> </ul></li> <li>AMD Ryzen⢠7035 Series Processors with Radeon⢠Graphics <ul><li>all except RembrandtPI-FP7 1.0.0.9b</li> </ul></li> <li>AMD Ryzen⢠7040 Series Processors with Radeon⢠Graphics <ul><li>all except PhoenixPI-FP8-FP7 1.0.0.2</li> </ul></li> <li>AMD Ryzen⢠7045 Series Mobile Processors <ul><li>all except DragonRangeFL1PI 1.0.0.3a</li> </ul></li> <li>AMD Ryzen⢠Embedded 5000 <ul><li>all except EmbAM4PI 1.0.0.4</li> </ul></li> <li>AMD Ryzen⢠Embedded R1000 <ul><li>all except EmbeddedPI-FP5 1.2.0.A</li> </ul></li> <li>AMD Ryzen⢠Embedded R2000 <ul><li>all except EmbeddedPI-FP5 1.0.0.2</li> </ul></li> <li>AMD Ryzen⢠Embedded V1000 <ul><li>all except EmbeddedPI-FP5 1.2.0.A</li> </ul></li> <li>AMD Ryzen⢠Embedded V2000 <ul><li>all except EmbeddedPI-FP6 1.0.0.9</li> </ul></li> <li>AMD Ryzen⢠Embedded V3000 <ul><li>all except EmbeddedPI-FP7r2 1.0.0.8</li> </ul></li> <li>AMD Ryzen⢠Threadripper⢠3000 Series Processors <ul><li>all except CastlePeakPI-SP3r3 1.0.0.A</li> </ul></li> <li>AMD Ryzen⢠Threadripper⢠PRO 3000WX Series Processors <ul><li>all except CastlePeakWSPI-sWRX8 1.0.0.C</li> <li>all except ChagallWSPI-sWRX8 1.0.0.7</li> </ul></li> <li>AMD Ryzen⢠Threadripper⢠PRO 5000WX Processors <ul><li>all except ChagallWSPI-sWRX8 1.0.0.7</li> </ul></li> </ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.</p> <ul class="list-unstyled"><li><a href="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7009.html">AMD <span lang="en" xml:lang="en" xml:lang="en">Processor Vulnerabilities</span></a></li> <li><a href="https://www.amd.com/en/resources/product-security.html">AMD <span lang="en" xml:lang="en" xml:lang="en">Product Security</span></a></li> </ul><!–CUT & PASTE the French version info –><p><strong>NumĂŠro de sĂŠrie : </strong>AV26-879<br /><strong>Date : </strong>3 septembre 2026</p> <p>En date du 2 septembre 2026, AMD est touchĂŠ par des vulnĂŠrabilitĂŠs dans les produits suivants :</p> <ul><li><span lang="en" xml:lang="en" xml:lang="en">2nd Gen</span> AMD EPYC⢠<span lang="en" xml:lang="en" xml:lang="en">Processors</span> <ul><li>TOUS sauf <span lang="en" xml:lang="en" xml:lang="en">Rome</span>PI 1.0.0.H</li> </ul></li> <li>3<span lang="en" xml:lang="en" xml:lang="en">rd Gen</span> AMD EPYC⢠<span lang="en" xml:lang="en" xml:lang="en">Processors</span> <ul><li>TOUS sauf <span lang="en" xml:lang="en" xml:lang="en">Milan</span>PI 1.0.0.C</li> </ul></li> <li><span lang="en" xml:lang="en" xml:lang="en">4th Gen</span> AMD EPYC⢠<span lang="en" xml:lang="en" xml:lang="en">Processors</span> <ul><li>TOUS sauf <span lang="en" xml:lang="en" xml:lang="en">Genoa</span>PI 1.0.0.8</li> </ul></li> <li>AMD <span lang="en" xml:lang="en" xml:lang="en">Athlon</span>⢠3000 <span lang="en" xml:lang="en" xml:lang="en">Series Desktop Processors with Radeon⢠Graphics</span> <ul><li>TOUS sauf <span lang="en" xml:lang="en" xml:lang="en">Combo</span>AM4 1.0.0.B</li> <li>TOUS sauf <span lang="en" xml:lang="en" xml:lang="en">Combo</span>AM4v2 1.2.0.B</li> </ul></li> <li>AMD <span lang="en" xml:lang="en" xml:lang="en">Athlon</span>⢠3000 <span lang="en" xml:lang="en" xml:lang="en">Series Mobile Processors with Radeon⢠Graphics</span> <ul><li>TOUS sauf <span lang="en" xml:lang="en" xml:lang="en">Picasso</span>PI-FP5 1.0.1.0</li> <li>TOUS sauf <span lang="en" xml:lang="en" xml:lang="en">Pollock</span>PI-FT5 1.0.0.6</li> </ul></li> <li>AMD EPYC⢠<span lang="en" xml:lang="en" xml:lang="en">Embedded</span> 3000 <ul><li>TOUS sauf <span lang="en" xml:lang="en" xml:lang="en">Snowyowl</span> PI 1.1.0.B</li> </ul></li> <li>AMD EPYC⢠<span lang="en" xml:lang="en" xml:lang="en">Embedded</span> 7002 <ul><li>TOUS sauf E<span lang="en" xml:lang="en" xml:lang="en">mbRome</span>PI-SP3 1.0.0.B</li> </ul></li> <li>AMD EPYCâ˘<span lang="en" xml:lang="en" xml:lang="en"> Embedded</span> 7003 <ul><li>TOUS sauf <span lang="en" xml:lang="en" xml:lang="en">EmbMilan</span>PI-SP3 1.0.0.8</li> </ul></li> <li>AMD EPYC⢠<span lang="en" xml:lang="en" xml:lang="en">Embedded</span> 9003 <ul><li>TOUS sauf <span lang="en" xml:lang="en" xml:lang="en">EmbGenoa</span>PI-SP5 1.0.0.3</li> </ul></li> <li>AMD <span lang="en" xml:lang="en" xml:lang="en">Instinct</span>⢠MI300A <ul><li>TOUS sauf MI300 SR5 PI 1.0.0.1</li> </ul></li> <li>AMD <span lang="en" xml:lang="en" xml:lang="en">Radeon</span>⢠PRO V620 <span lang="en" xml:lang="en" xml:lang="en">Graphics Products</span> <ul><li>TOUS <span lang="en" xml:lang="en" xml:lang="en">sauf Contact your</span> AMD <span lang="en" xml:lang="en" xml:lang="en">\Customer Engineering representative</span></li> </ul></li> <li>AMD <span lang="en" xml:lang="en" xml:lang="en">Ryzen</span>⢠3000 <span lang="en" xml:lang="en" xml:lang="en">Series Desktop Processors</span> <ul><li>TOUS sauf <span lang="en" xml:lang="en" xml:lang="en">Combo</span>AM4 1.0.0.B</li> <li>TOUS sauf <span lang="en" xml:lang="en" xml:lang="en">Combo</span>AM4v2 1.2.0.B</li> </ul></li> <li>AMD <span lang="en" xml:lang="en" xml:lang="en">Ryzen</span>⢠3000 <span lang="en" xml:lang="en" xml:lang="en">Series Mobile Processor with Radeon⢠Graphics</span> <ul><li>TOUS sauf <span lang="en" xml:lang="en" xml:lang="en">Picasso</span>PI-FP5 1.0.1.0</li> </ul></li> <li>AMD <span lang="en" xml:lang="en" xml:lang="en">Ryzen</span>⢠3000 <span lang="en" xml:lang="en" xml:lang="en">Series Processors with Radeon⢠Graphics</span> <ul><li>TOUS sauf <span lang="en" xml:lang="en" xml:lang="en">Cezanne</span>PI-FP6 1.0.0.F</li> </ul></li> <li>AMD <span lang="en" xml:lang="en" xml:lang="en">Ryzen</span>⢠4000 <span lang="en" xml:lang="en" xml:lang="en">Series Desktop Processors with Radeon</span>⢠<span lang="en" xml:lang="en" xml:lang="en">Graphics</span> <ul><li>TOUS sauf <span lang="en" xml:lang="en" xml:lang="en">Combo</span>AM4v2 1.2.0.B</li> </ul></li> <li>AMD <span lang="en" xml:lang="en" xml:lang="en">Ryzenâ˘</span> 4000 <span lang="en" xml:lang="en" xml:lang="en">Series Mobile Processors with Radeon⢠Graphics</span> <ul><li>TOUS <span lang="en" xml:lang="en" xml:lang="en">sauf Renoir</span>PI-FP6 1.0.0.D</li> </ul></li> <li>AMD <span lang="en" xml:lang="en" xml:lang="en">Ryzenâ˘</span> 5000 <span lang="en" xml:lang="en" xml:lang="en">Series Desktop Processors</span> <ul><li>TOUS sauf <span lang="en" xml:lang="en" xml:lang="en">Combo</span>AM4v2 1.2.0.B</li> <li>TOUS sauf <span lang="en" xml:lang="en" xml:lang="en">Combo</span>AM4v2v 1.2.0.B</li> </ul></li> <li>AMD <span lang="en" xml:lang="en" xml:lang="en">Ryzenâ˘</span> 5000 <span lang="en" xml:lang="en" xml:lang="en">Series Desktop Processors with Radeon⢠Graphics</span> <ul><li>TOUS sauf <span lang="en" xml:lang="en" xml:lang="en">Combo</span>AM4v2 1.2.0.B</li> </ul></li> <li>AMD <span lang="en" xml:lang="en" xml:lang="en">Ryzenâ˘</span> 5000 <span lang="en" xml:lang="en" xml:lang="en">Series Mobile Processors with Radeon⢠Graphics</span> <ul><li>TOUS sauf <span lang="en" xml:lang="en" xml:lang="en">Cezanne</span>PI-FP6 1.0.0.F</li> </ul></li> <li>AMD <span lang="en" xml:lang="en" xml:lang="en">Ryzenâ˘</span> 5000 <span lang="en" xml:lang="en" xml:lang="en">Series Processors with Radeon⢠Graphics</span> <ul><li>TOUS sauf <span lang="en" xml:lang="en" xml:lang="en">Cezanne</span>PI-FP6 1.0.0.F</li> </ul></li> <li>AMD <span lang="en" xml:lang="en" xml:lang="en">Ryzenâ˘</span> 6000 <span lang="en" xml:lang="en" xml:lang="en">Series Processors with Radeon⢠Graphics</span> <ul><li>TOUS sauf <span lang="en" xml:lang="en" xml:lang="en">Rembrandt</span>PI-FP7 1.0.0.9b</li> </ul></li> <li>AMD <span lang="en" xml:lang="en" xml:lang="en">Ryzenâ˘</span> 7000 <span lang="en" xml:lang="en" xml:lang="en">Series Processors</span> <ul><li>TOUS sauf <span lang="en" xml:lang="en" xml:lang="en">Combo</span>AM5 1.0.0.7b</li> </ul></li> <li>AMD <span lang="en" xml:lang="en" xml:lang="en">Ryzenâ˘</span> 7020 <span lang="en" xml:lang="en" xml:lang="en">Series Processors with Radeon⢠Graphics</span> <ul><li>TOUS sauf <span lang="en" xml:lang="en" xml:lang="en">Mendocino</span>PI-FT6 1.0.0.6</li> </ul></li> <li>AMD <span lang="en" xml:lang="en" xml:lang="en">Ryzenâ˘</span> 7035 <span lang="en" xml:lang="en" xml:lang="en">Series Processors with Radeon⢠Graphics</span> <ul><li>TOUS sauf <span lang="en" xml:lang="en" xml:lang="en">Rembrandt</span>PI-FP7 1.0.0.9b</li> </ul></li> <li>AMD <span lang="en" xml:lang="en" xml:lang="en">Ryzenâ˘</span> 7040 <span lang="en" xml:lang="en" xml:lang="en">Series Processors with Radeon⢠Graphics</span> <ul><li>TOUS sauf <span lang="en" xml:lang="en" xml:lang="en">Phoenix</span>PI-FP8-FP7 1.0.0.2</li> </ul></li> <li>AMD <span lang="en" xml:lang="en" xml:lang="en">Ryzenâ˘</span> 7045 <span lang="en" xml:lang="en" xml:lang="en">Series Mobile Processors</span> <ul><li>TOUS sauf <span lang="en" xml:lang="en" xml:lang="en">DragonRange</span>FL1PI 1.0.0.3a</li> </ul></li> <li>AMD <span lang="en" xml:lang="en" xml:lang="en">Ryzen⢠Embedded</span> 5000 <ul><li>TOUS sauf EmbAM4PI 1.0.0.4</li> </ul></li> <li>AMD <span lang="en" xml:lang="en" xml:lang="en">Ryzen⢠Embedded</span> R1000 <ul><li>TOUS sauf <span lang="en" xml:lang="en" xml:lang="en">Embedded</span>PI-FP5 1.2.0.A</li> </ul></li> <li>AMD <span lang="en" xml:lang="en" xml:lang="en">Ryzen⢠Embedded</span> R2000 <ul><li>TOUS sauf <span lang="en" xml:lang="en" xml:lang="en">Embedded</span>PI-FP5 1.0.0.2</li> </ul></li> <li>AMD <span lang="en" xml:lang="en" xml:lang="en">Ryzen⢠Embedded</span> V1000 <ul><li>TOUS sauf <span lang="en" xml:lang="en" xml:lang="en">Embedded</span>PI-FP5 1.2.0.A</li> </ul></li> <li>AMD <span lang="en" xml:lang="en" xml:lang="en">Ryzen⢠Embedded</span> V2000 <ul><li>TOUS sauf EmbeddedPI-FP6 1.0.0.9</li> </ul></li> <li>AMD <span lang="en" xml:lang="en" xml:lang="en">Ryzen⢠Embedded</span> V3000 <ul><li>TOUS sauf EmbeddedPI-FP7r2 1.0.0.8</li> </ul></li> <li>AMD <span lang="en" xml:lang="en" xml:lang="en">Ryzen⢠Threadripperâ˘</span> 3000 <span lang="en" xml:lang="en" xml:lang="en">Series Processors</span> <ul><li>TOUS sauf <span lang="en" xml:lang="en" xml:lang="en">CastlePeak</span>PI-SP3r3 1.0.0.A</li> </ul></li> <li>AMD <span lang="en" xml:lang="en" xml:lang="en">Ryzen⢠Threadripperâ˘</span> PRO 3000WX <span lang="en" xml:lang="en" xml:lang="en">Series Processors</span> <ul><li>TOUS sauf <span lang="en" xml:lang="en" xml:lang="en">CastlePeak</span>WSPI-sWRX8 1.0.0.C</li> <li>TOUS sauf <span lang="en" xml:lang="en" xml:lang="en">Chagall</span>WSPI-sWRX8 1.0.0.7</li> </ul></li> <li>AMD <span lang="en" xml:lang="en" xml:lang="en">Ryzen⢠Threadripperâ˘</span> PRO 5000WX <span lang="en" xml:lang="en" xml:lang="en">Processors</span> <ul><li>TOUS sauf <span lang="en" xml:lang="en" xml:lang="en">Chagall</span>WSPI-sWRX8 1.0.0.7</li> </ul></li> </ul><p>Le Centre pour la cybersĂŠcuritĂŠ encourage les utilisateurs et les administrateurs Ă consulter les liens fournis et Ă installer les mises Ă jour nĂŠcessaires, dès qu’elles sont disponibles.</p> <ul class="list-unstyled"><li><a href="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7009.html">AMD <span lang="en" xml:lang="en" xml:lang="en">Processor Vulnerabilities</span> (en anglais seulement)</a></li> <li><a href="https://www.amd.com/en/resources/product-security.html">AMD <span lang="en" xml:lang="en" xml:lang="en">Product Security</span> (en anglais seulement)</a></li> </ul></div> </div> </div> </div> </div> </article>
- F5 security advisory (AV26-878)by Canadian Centre for Cyber Security on September 3, 2026 at 2:05 pm
<article data-history-node-id="8178" about="/en/alerts-advisories/f5-security-advisory-av26-878" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial Number: </strong>AV26-878<br /><strong>Date: </strong>September 3, 2026</p> <p>As of September 2, 2026, F5 is affected by vulnerabilities in the following products:</p> <ul><li>BIG-IP (all modules) <ul><li>Prior to 17.1.3.4</li> <li>Prior to 17.5.1.8</li> <li>Prior to 21.0.0.3</li> <li>Prior to 21.1.0.1</li> </ul></li> </ul><ul><li>BIG-IQ <ul><li>Prior to 8.4.2.1</li> </ul></li> </ul><ul><li>NGINX Gateway Fabric <ul><li>Prior to 2.6.8</li> </ul></li> </ul><ul><li>NGINX Ingress Controller <ul><li>Prior to 2026-lts-r5</li> <li>Prior to 5.6.0</li> </ul></li> </ul><ul><li>NGINX JavaScript <ul><li>9.9</li> <li>Prior to 1.0.1</li> </ul></li> <li>APM Clients <ul><li>Prior to 7.2.6</li> </ul></li> </ul><ul><li>BIG-IP APM <ul><li>Multiple versions</li> </ul></li> </ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.</p> <ul class="list-unstyled"><li><a href="https://my.f5.com/manage/s/article/K000162872">K000162872: Out-of-band Security Notification (September 2, 2026)</a></li> </ul><!–CUT & PASTE the French version info –></div> </div> </div> </div> </div> </article>
- Jenkins security advisory (AV26-877)by Canadian Centre for Cyber Security on September 3, 2026 at 1:54 pm
<article data-history-node-id="8177" about="/en/alerts-advisories/jenkins-security-advisory-av26-877" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial Number: </strong>AV26-877<br /><strong>Date: </strong>September 3, 2026</p> <p>As of September 2, 2026, Jenkins Project is affected by vulnerabilities in the following products:</p> <ul><li>Jenkins <ul><li>ALL except 2.568.3</li> <li>ALL except 2.580</li> </ul></li> </ul><ul><li>Jenkins Allure Plugin <ul><li>Prior to or equal to 2.35.2</li> </ul></li> </ul><ul><li>Jenkins Customizable Header Plugin <ul><li>Prior to or equal to 295.v2544b_ca_19b_97</li> </ul></li> </ul><ul><li>Jenkins File Parameter Plugin <ul><li>Prior to or equal to 425.v3fa_801681b_5e</li> </ul></li> </ul><ul><li>Jenkins GitLab Plugin <ul><li>Prior to or equal to 1.9.16</li> </ul></li> </ul><ul><li>Jenkins LDAP Plugin <ul><li>Prior to or equal to 807.809.vd3a_4e5e4ec98</li> </ul></li> </ul><ul><li>Jenkins Microsoft Entra ID (previously Azure AD) Plugin <ul><li>Prior to or equal to 710.v0b_ff8e9cc2d2</li> </ul></li> </ul><ul><li>Jenkins Parameterized Remote Trigger Plugin <ul><li>Prior to or equal to 3.2.2</li> </ul></li> </ul><ul><li>Jenkins Performance Plugin <ul><li>Prior to or equal to 1015.v09ca_52b_3370e</li> </ul></li> </ul><ul><li>Jenkins Pipeline: Build Step Plugin <ul><li>Prior to or equal to 599.v4b_67ea_11b_152</li> </ul></li> </ul><ul><li>Jenkins SAML Plugin <ul><li>Prior to or equal to 4.618.v441a_27fa_46d2</li> </ul></li> </ul><ul><li>Jenkins Script Security Plugin <ul><li>Prior to or equal to 1412.v7737b_3405f86</li> </ul></li> </ul><ul><li>Jenkins TICS Plugin <ul><li>Prior to or equal to 2025.1.1</li> </ul></li> </ul><ul><li>Jenkins ThinBackup Plugin <ul><li>Prior to or equal to 2.1.4</li> </ul></li> </ul><ul><li>Jenkins XebiaLabs XL Deploy Plugin <ul><li>Prior to or equal to 26.1.0</li> </ul></li> </ul><ul><li>Jenkins update-center2 <ul><li>Prior to or equal to 3.18.3</li> </ul></li> </ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.</p> <ul class="list-unstyled"><li><a href="https://www.jenkins.io/security/advisory/2026-09-02/">Jenkins Security Advisory 2026-09-02</a></li> <li><a href="https://www.jenkins.io/security/advisories/">Security Advisories</a></li> </ul><!–CUT & PASTE the French version info –></div> </div> </div> </div> </div> </article>
- Cisco security advisory (AV26-876)by Canadian Centre for Cyber Security on September 3, 2026 at 1:13 pm
<article data-history-node-id="8176" about="/en/alerts-advisories/cisco-security-advisory-av26-876" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial Number: </strong>AV26-876<br /><strong>Date: </strong>September 3, 2026</p> <p>As of September 2, 2026, Cisco is affected by vulnerabilities in the following products:</p> <ul><li>Cisco IOS XR Software <ul><li>Multiple versions</li> </ul></li> </ul><ul><li>Cisco Nexus 9000 Series Switches <ul><li>Multiple products</li> </ul></li> </ul><ul><li>Cisco Desk Phone 9800 Series and Video Phone 8875 <ul><li>Prior to 5.0(1)</li> </ul></li> <li>IP Phone 7800 and 8800 <ul><li>Prior to 14.4(1)SR3</li> </ul></li> </ul><ul><li>IP Phone 8845 and 8865 <ul><li>Prior to14.4(1)SR4</li> </ul></li> </ul><ul><li>Wireless IP Phone 8821 <ul><li>Prior to 11.0(6)SR8</li> </ul></li> </ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.</p> <ul class="list-unstyled"><li><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-n9k-s1-rce-EH8dEtr">Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability</a></li> <li><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM">Cisco IOS XR Software Security Hardening Release: September 2026</a></li> <li><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-phone-dos-txMYNRzv">Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Denial of Service Vulnerability</a></li> <li><a href="https://sec.cloudapps.cisco.com/security/center/publicationListing.x">Cisco Security Advisories </a></li> </ul><!–CUT & PASTE the French version info –></div> </div> </div> </div> </div> </article>
- JFrog security advisory (AV26-867) â Update 1by Canadian Centre for Cyber Security on September 2, 2026 at 6:55 pm
<article data-history-node-id="8166" about="/en/alerts-advisories/jfrog-security-advisory-av26-867" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial number: </strong>AV26-867<br /><strong>Date: </strong>September 1, 2026<br /><strong>Updated: </strong>September 2, 2026</p> <p>As of August 28, 2026, JFrog is affected by a vulnerability in the following product:</p> <ul><li>Artifactory <ul><li>Prior to 7.111.21</li> <li>Prior to 7.117.28</li> <li>Prior to 7.125.20</li> <li>Prior to 7.133.29</li> <li>Prior to 7.146.38</li> <li>Prior to 7.161.20</li> </ul></li> </ul><p class="mrgn-bttm-md">Open-source reporting indicates that CVE-2026-82329 related to JFrog Artifactory is being exploited in the wild.</p> <p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.</p> <h2 class="h3">Update 1</h2> <p>On September 2, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-82329 to their Known Exploited Vulnerabilities (KEV) Database.</p> <ul class="list-unstyled"><li><a href="https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases">Artifactory Self-Managed Releases</a></li> <li><a href="https://docs.jfrog.com/releases/docs/jfrog-security-advisories">JFrog Security Advisories</a></li> <li><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-82329">CISA KEV: CVE-2026-82329</a></li> </ul></div> </div> </div> </div> </div> </article>
- SonicWall security advisory (AV26-872) â Update 1by Canadian Centre for Cyber Security on September 2, 2026 at 6:44 pm
<article data-history-node-id="8171" about="/en/alerts-advisories/sonicwall-security-advisory-av26-872" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial Number: </strong>AV26-872<br /><strong>Date: </strong>September 2, 2026</p> <p>As of September 1, 2026, SonicWall is affected by a vulnerability in the following product:</p> <ul><li>SMA1000 – 6210, 7210, 8200v <ul><li>12.4.3-03453 (platform-hotfix) and older versions</li> <li>12.5.0-02835 (platform-hotfix) and older versions</li> </ul></li> </ul><p>SonicWall indicates that CVE-2026-83548 and CVE-2026-83549 are being exploited.</p> <h2 class="h3">Update 1</h2> <p>On September 2, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-83548 and CVE-2026-83549 to their Known Exploited Vulnerabilities (KEV) Database.</p> <p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.</p> <ul class="list-unstyled"><li><a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016">Security Advisory</a></li> <li><a href="https://psirt.global.sonicwall.com/">SonicWall Security Advisories</a></li> <li><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-83548">CISA KEV: CVE-2026-83548</a></li> <li><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-83549">CISA KEV: CVE-2026-83549</a></li> </ul></div> </div> </div> </div> </div> </article>
- Progress Software security advisory (AV26-875)by Canadian Centre for Cyber Security on September 2, 2026 at 3:33 pm
<article data-history-node-id="8175" about="/en/alerts-advisories/progress-software-security-advisory-av26-875" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial number: </strong>AV26-875<br /><strong>Date: </strong>September 2, 2026</p> <p>As of September 2, 2026, Progress Software is affected by vulnerabilities in the following product:</p> <ul><li>Telerik UI for ASP.NET AJAX <ul><li>Prior to 2026.3.812</li> </ul></li> </ul><p class="mrgn-bttm-md">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.</p> <ul class="list-unstyled"><li><a href="https://www.telerik.com/products/aspnet-ajax/documentation/knowledge-base/kb-security-rie-path-traversal-cve-2026-18672">Telerik Web Forms RadImageEditor Path Traversal Vulnerability (CVE-2026-18672)</a></li> <li><a href="https://www.telerik.com/products/aspnet-ajax/documentation/knowledge-base/kb-security-dialoghandler-uploadpaths-tampering-cve-2026-19219">Telerik Web Forms DialogHandler UploadPaths Tampering Vulnerability (CVE-2026-19219)</a></li> </ul></div> </div> </div> </div> </div> </article>
- Google security advisory (AV26-874)by Canadian Centre for Cyber Security on September 2, 2026 at 2:27 pm
<article data-history-node-id="8173" about="/en/alerts-advisories/google-security-advisory-av26-874" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial number: </strong>AV26-874<br /><strong>Date: </strong>September 2, 2026</p> <p>As of September 2, 2026, Google is affected by vulnerabilities in the following product:</p> <ul><li>Chrome <ul><li>Prior to 152.0.7977.75</li> </ul></li> </ul><p class="mrgn-bttm-md">The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.</p> <ul class="list-unstyled"><li><a href="https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html">Stable Channel Update for Desktop</a></li> </ul></div> </div> </div> </div> </div> </article>
- HPE security advisory (AV26-873)by Canadian Centre for Cyber Security on September 2, 2026 at 1:38 pm
<article data-history-node-id="8172" about="/en/alerts-advisories/hpe-security-advisory-av26-873" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial number: </strong>AV26-873<br /><strong>Date: </strong>September 2, 2026</p> <p>As of September 1, 2026, Hewlett Packard Enterprise (HPE) is affected by vulnerabilities in the following products:</p> <ul><li>HPE Networking AOS-CX <ul><li>Prior to or equal to 10.10.1180</li> <li>Prior to or equal to 10.13.1180</li> <li>Prior to or equal to 10.16.1051</li> <li>Prior to or equal to 10.17.1021</li> <li>Prior to or equal to 10.18.0001</li> </ul></li> </ul><ul><li>HPE Networking Fabric Composer <ul><li>Prior to or equal to 7.3.3</li> </ul></li> </ul><p class="mrgn-bttm-md">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.</p> <ul class="list-unstyled"><li><a href="https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US#hpesbnw05133-rev-1-multiple-vulnerabilities-in-hpe-0">HPESBNW05133 rev.1 – Multiple Vulnerabilities in HPE Aruba Networking Fabric Composer</a></li> <li><a href="https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US#hpesbnw05134-rev-1-multiple-vulnerabilities-in-hpe-0">HPESBNW05134 rev.1 – Multiple Vulnerabilities in HPE Aruba Networking ArubaOS-CX (AOS-CX)</a></li> <li><a href="https://support.hpe.com/connect/s/securitybulletinlibrary?language=en_US">HPE Security Bulletin Library</a></li> </ul></div> </div> </div> </div> </div> </article>
- [Control systems] Schneider Electric security advisory (AV26-871)by Canadian Centre for Cyber Security on September 2, 2026 at 12:28 pm
<article data-history-node-id="8170" about="/en/alerts-advisories/control-systems-schneider-electric-security-advisory-av26-871" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial Number: </strong>AV26-871<br /><strong>Date: </strong>September 2, 2026</p> <p>As of September 1, 2026, Schneider Electric is affected by vulnerabilities in the following products:</p> <ul><li>NetBotz 5 – 750/755 <ul><li>Versions prior to or equal to 5.5.2</li> </ul></li> <li>PowerChute Serial Shutdown <ul><li>Versions prior to or equal to 1.5</li> </ul></li> </ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.</p> <ul class="list-unstyled"><li><a href="https://download.se.com/files?p_Doc_Ref=SEVD-2026-223-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-223-02.pdf">Multiple Vulnerabilities on NetBotz 5 – 750/755 Products</a></li> <li><a href="https://download.se.com/files?p_Doc_Ref=SEVD-2026-223-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-223-01.pdf ">Improper Restriction of Excessive Authentication Attempts vulnerability on PowerChute⢠Serial Shutdown</a></li> <li><a href="https://www.se.com/ww/en/work/support/cybersecurity/security-notifications.jsp">Schneider Electric Security Notifications</a></li> </ul></div> </div> </div> </div> </div> </article>
- Erlang security advisory (AV26-870)by Canadian Centre for Cyber Security on September 1, 2026 at 6:50 pm
<article data-history-node-id="8169" about="/en/alerts-advisories/erlang-security-advisory-av26-870" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial number: </strong>AV26-870<br /><strong>Date: </strong>September 1, 2026</p> <p>As of September 1, 2026, Erlang is affected by vulnerabilities in the following product:</p> <ul><li>OTPÂ – Multiple versions</li> </ul><p class="mrgn-bttm-md">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.</p> <ul class="list-unstyled"><li><a href="https://github.com/erlang/otp/security/advisories/">Erlang Security Advisories</a></li> </ul></div> </div> </div> </div> </div> </article>
- Rockwell Automation security advisory (AV26-869)by Canadian Centre for Cyber Security on September 1, 2026 at 6:45 pm
<article data-history-node-id="8168" about="/en/alerts-advisories/rockwell-automation-security-advisory-av26-869" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial number: </strong>AV26-869<br /><strong>Date: </strong>September 1, 2026</p> <p>As of September 1, 2026, Rockwell Automation is affected by vulnerabilities in the following products:</p> <ul><li>1756-ENBT Module <ul><li>All versions</li> </ul></li> <li>ArmorStart LT <ul><li>Prior to or equal to v2.001</li> </ul></li> <li>CompactLogix 5380 / ControlLogix 5580 <ul><li>Prior to or equal to V33</li> <li>V34.011 to V34.014</li> <li>V35.011 to V35.013</li> <li>V36.011 to V36.012</li> </ul></li> <li>RSLinx Classic <ul><li>Prior to or equal to V4.50</li> </ul></li> </ul><p class="mrgn-bttm-md">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.</p> <ul class="list-unstyled"><li><a href="https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1797.html">SD1797 | Security Advisory | Rockwell Automation | US</a></li> <li><a href="https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1798.html">SD1798 | Security Advisory | Rockwell Automation | US</a></li> <li><a href="https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1794.html">SD1794 | Security Advisory | Rockwell Automation | US</a></li> <li><a href="https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1792.html">SD1792 | Security Advisory | Rockwell Automation | US</a></li> </ul></div> </div> </div> </div> </div> </article>
- Mozilla security advisory (AV26-868)by Canadian Centre for Cyber Security on September 1, 2026 at 6:14 pm
<article data-history-node-id="8167" about="/en/alerts-advisories/mozilla-security-advisory-av26-868" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial number: </strong>AV26-868<br /><strong>Date: </strong>September 1, 2026</p> <p>As of September 1, 2026, Mozilla is affected by vulnerabilities in the following products:</p> <ul><li>Firefox ESR <ul><li>Versions prior to 115.40</li> <li>Versions prior to 140.15</li> <li>Versions prior to 153.2</li> </ul></li> <li>Firefox <ul><li>Versions prior to 155</li> </ul></li> </ul><p class="mrgn-bttm-md">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.</p> <ul class="list-unstyled"><li><a href="https://www.mozilla.org/en-US/security/advisories/mfsa2026-83/">Security Vulnerabilities fixed in Firefox ESR 115.40 â Mozilla</a></li> <li><a href="https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/">Security Vulnerabilities fixed in Firefox ESR 140.15 â Mozilla</a></li> <li><a href="https://www.mozilla.org/en-US/security/advisories/mfsa2026-85/">Security Vulnerabilities fixed in Firefox ESR 153.2 â Mozilla</a></li> <li><a href="https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/">Security Vulnerabilities fixed in Firefox 155 â Mozilla</a></li> <li><a href="https://www.mozilla.org/en-US/security/advisories/">Mozilla Foundation Security Advisories â Mozilla</a></li> </ul></div> </div> </div> </div> </div> </article>
- WebPros security advisory (AV26-866)by Canadian Centre for Cyber Security on September 1, 2026 at 1:34 pm
<article data-history-node-id="8165" about="/en/alerts-advisories/webpros-security-advisory-av26-866" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial number: </strong>AV26-866<br /><strong>Date: </strong>September 1, 2026</p> <p>As of September 1, 2026, WebPros is affected by vulnerabilities in the following product:</p> <ul><li>Plesk <ul><li>Prior to 18.0.79.9</li> <li>Prior to 18.0.80.5</li> </ul></li> </ul><p class="mrgn-bttm-md">The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.</p> <ul class="list-unstyled"><li><a href="https://support.plesk.com/hc/en-us/articles/42968165026967-CVE-2026-67394-Vulnerability-in-Plesk-allows-privilege-escalation-to-root">CVE-2026-67394: Vulnerability in Plesk allows privilege escalation to root</a></li> </ul></div> </div> </div> </div> </div> </article>
- WatchGuard security advisory (AV26-865)by Canadian Centre for Cyber Security on August 31, 2026 at 7:00 pm
<article data-history-node-id="8164" about="/en/alerts-advisories/watchguard-security-advisory-av26-865" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial Number:</strong> AV26-865<br /><strong>Date:</strong> August 31, 2026</p> <p>As of August 27, 2026, WatchGuard is affected by vulnerabilities in the following products:</p> <ul><li>Dimension <ul><li>Prior to 2.3.1</li> </ul></li> <li>Fireware OS <ul><li>Prior to 12.12.2</li> <li>Prior to 12.5.20</li> <li>Prior to 2026.2.2</li> </ul></li> </ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.</p> <ul class="list-unstyled"><li><a href="https://psirt.watchguard.com/">WatchGuard Security Advisories</a></li> </ul></div> </div> </div> </div> </div> </article>
- PaperCut security advisory (AV26-858) â Update 2by Canadian Centre for Cyber Security on August 31, 2026 at 4:00 pm
<article data-history-node-id="8156" about="/en/alerts-advisories/papercut-security-advisory-av26-858" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial number: </strong>AV26-858<br /><strong>Date: </strong>August 28, 2026<br /><strong>Updated:</strong> August 31, 2026</p> <p>As of August 27, 2026, PaperCut is affected by vulnerabilities in the following products:</p> <ul><li>PaperCut MF <ul><li>Prior to v24 Emergency Patch Release 2</li> <li>Prior to v25 Emergency Patch Release 2</li> <li>Prior to v26 Emergency Patch Release 2</li> </ul></li> <li>PaperCut NG <ul><li>Prior to v24 Emergency Patch Release 2</li> <li>Prior to v25 Emergency Patch Release 2</li> <li>Prior to v26 Emergency Patch Release 2</li> </ul></li> </ul><h2 class="h3">Update 1</h2> <p>Open-source reporting indicates that CVE-2026-81578 and CVE-2026-82078 are related to PaperCut MF and PaperCut NG are being exploited in the wild.</p> <h2 class="h3">Update 2</h2> <p>On August 31, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-81578 and CVE-2026-82078 to their Known Exploited Vulnerabilities (KEV) Database.</p> <p class="mrgn-bttm-md">The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.</p> <ul class="list-unstyled"><li><a href="https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/">URGENT Security Advisory: PaperCut NG/MF Security Bulletin (27 Aug 2026)</a></li> <li><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-81578">CISA KEV: CVE-2026-81578</a></li> <li><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-82078">CISA KEV: CVE-2026-82078</a></li> </ul></div> </div> </div> </div> </div> </article>
- [Control Systems] Siemens security advisory (AV26-864)by Canadian Centre for Cyber Security on August 31, 2026 at 3:59 pm
<article data-history-node-id="8163" about="/en/alerts-advisories/control-systems-siemens-security-advisory-av26-864" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial Number:</strong> AV26-864<br /><strong>Date:</strong> August 31, 2026</p> <p>As of August 27, 2026, Siemens is affected by a vulnerability in the following products:</p> <ul><li>Element maps-ng V47 <ul><li>Prior to V47.12.3</li> </ul></li> <li>Element maps-ng V48 <ul><li>Prior to V48.11.3</li> </ul></li> <li>Element maps-ng V49 <ul><li>Prior to V49.16.1</li> </ul></li> </ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.</p> <ul class="list-unstyled"><li><a href="https://cert-portal.siemens.com/productcert/html/ssa-682041.html">SSA-682041</a></li> <li><a href="https://www.siemens.com/en-us/content/cert-services/">CERT Services | Siemens</a></li> </ul></div> </div> </div> </div> </div> </article>
- Dell security advisory (AV26-863)by Canadian Centre for Cyber Security on August 31, 2026 at 3:55 pm
<article data-history-node-id="8162" about="/en/alerts-advisories/dell-security-advisory-av26-863" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial Number:</strong> AV26-863<br /><strong>Date:</strong> August 31, 2026</p> <p>As of August 28, 2026, Dell is affected by vulnerabilities in the following products:</p> <ul><li>Dell PowerEdge Server for Intel Processor Firmware <ul><li>Multiple versions and models</li> </ul></li> <li>Dell AppSync <ul><li>Prior to or equal to 4.6.0.4 and 4.6.1.0</li> </ul></li> </ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.</p> <ul class="list-unstyled"><li><a href="https://www.dell.com/support/kbdoc/en-ca/000502468/dsa-2026-356-security-update-for-dell-poweredge-server-for-intel-processor-firmware-vulnerability">DSA-2026-356: Security Update for Dell PowerEdge Server for IntelÂŽ Processor Firmware Vulnerability</a></li> <li><a href="https://www.dell.com/support/kbdoc/en-ca/000502484/dsa-2026-165-security-update-for-dell-appsync-vulnerabilities">DSA-2026-165: Security Update for Dell AppSync Vulnerabilities</a></li> <li><a href="https://www.dell.com/support/security/en-ca?lwp=rt">Security Advisories, Notices and Resources | Dell Canada</a></li> </ul></div> </div> </div> </div> </div> </article>
- IBM security advisory (AV26-862)by Canadian Centre for Cyber Security on August 31, 2026 at 3:52 pm
<article data-history-node-id="8161" about="/en/alerts-advisories/ibm-security-advisory-av26-862" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial Number:</strong> AV26-862<br /><strong>Date:</strong> August 31, 2026</p> <p>As of August 28, 2026, IBM is affected by vulnerabilities in the following products:</p> <ul><li>SPSS Collaboration and Deployment Services <ul><li>Multiple versions</li> </ul></li> <li>IBM SPSS Analytic Server <ul><li>Multiple version</li> </ul></li> <li>IBM MQ Agent <ul><li>Multiple versions</li> </ul></li> <li>IBM Maximo Application Suite – Monitor Component <ul><li>Prior to or equal to 9.2, 9.1 and 9.0</li> </ul></li> <li>IBM Observability with Instana (Agent) <ul><li>Prior to or equal to 1.0.323</li> </ul></li> <li>IBM Financial Transaction Manager (FTM) for RedHat OpenShift <ul><li>Multiple versions</li> </ul></li> <li>IBM Engineering Test Management <ul><li>Prior to equal to 7.2, 7.1 and 7.0.3</li> </ul></li> <li>IBM Control Center <ul><li>Prior to or equal to v6.3.1.0</li> </ul></li> <li>IBM Concert Software <ul><li>Prior to or equal to 2.3.1</li> </ul></li> <li>IBM Tivoli System Automation Application Manager 4.1 <ul><li>Versions WebSphere Application Server 8.5 and 9.0</li> </ul></li> <li>SPSS Collaboration and Deployment Services <ul><li>Multiple versions</li> </ul></li> <li>IBM Sovereign Core <ul><li>Prior to or equal to 1.1</li> </ul></li> <li>IBM Maximo Application Suite – Cluster Performance Insights <ul><li>Prior to or equal to 9.2</li> </ul></li> <li>IBM Transformation Advisor <ul><li>Prior to or equal to 5.0.0</li> </ul></li> <li>IBM Application Modernization Accelerator <ul><li>Prior to or equal to 5.0.0</li> </ul></li> <li>IBM webMethods Integration (on prem) <ul><li>Prior to or equal to 10.15,11.1 and 12.1</li> </ul></li> </ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.</p> <ul class="list-unstyled"><li><a href="https://www.ibm.com/support/pages/bulletin/">IBM Product Security Incident Response</a></li> </ul></div> </div> </div> </div> </div> </article>
- WebPros security advisory (AV26-861)by Canadian Centre for Cyber Security on August 28, 2026 at 3:10 pm
<article data-history-node-id="8159" about="/en/alerts-advisories/webpros-security-advisory-av26-861" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial Number: </strong>AV26-861<br /><strong>Date: </strong>August 28, 2026</p> <p>As of August 27, 2026, WebPros is affected by vulnerabilities in the following products:</p> <ul><li>cPanel & WebHost Manager (WHM) software <ul><li>Prior to 11.110.0.141</li> <li>Prior to 11.134.0.53</li> <li>Prior to 11.136.0.37</li> <li>Prior to 11.138.0.2</li> <li>Prior to WP2: 11.138.1.7</li> </ul></li> </ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available</p> <ul class="list-unstyled"><li><a href="https://support.cpanel.net/hc/en-us/articles/42959571221527-Security-CVE-2026-65643-Vulnerability-in-cPanel-s-Domain-Parking-Functionality-August-27-2026">Security: CVE-2026-65643 Vulnerability in cPanelâs Domain Parking Functionality – August 27, 2026</a></li> <li><a href="https://support.cpanel.net/hc/en-us/sections/360007088193-Security">cPanel Security</a></li> </ul><!–CUT & PASTE the French version info –></div> </div> </div> </div> </div> </article>
- Grafana security advisory (AV26-860)by Canadian Centre for Cyber Security on August 28, 2026 at 2:58 pm
<article data-history-node-id="8158" about="/en/alerts-advisories/grafana-security-advisory-av26-860" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial Number: </strong>AV26-860<br /><strong>Date: </strong>August 28, 2026</p> <p>As of August 27, 2026, Grafana is affected by a vulnerability in the following product:</p> <ul><li>Alloy <ul><li>Prior to or equal to 1.18.1</li> </ul></li> </ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.</p> <ul class="list-unstyled"><li><a href="https://grafana.com/tags/security/">Grafana: The open and composable observability platform | Grafana Labs</a></li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2026-75889">CVE-2026-19516 CVE Record</a></li> </ul><!–CUT & PASTE the French version info –></div> </div> </div> </div> </div> </article>
- Redis security advisory (AV26-859)by Canadian Centre for Cyber Security on August 28, 2026 at 2:34 pm
<article data-history-node-id="8157" about="/en/alerts-advisories/redis-security-advisory-av26-859" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial Number: </strong>AV26-859<br /><strong>Date: </strong>August 28, 2026</p> <p>As of August 27, 2026, <span lang="en" xml:lang="en" xml:lang="en">Redis</span> is affected by a vulnerability in the following product:</p> <ul><li><span lang="en" xml:lang="en" xml:lang="en">Redis</span> <ul><li>8.0</li> <li>All except 8.10.1</li> <li>All except 8.2.9</li> <li>All except 8.4.6</li> <li>All except 8.6.6</li> <li>All except 8.8.2</li> </ul></li> </ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.</p> <ul class="list-unstyled"><li><a href="https://github.com/redis/redis/commit/6d088c335d5c3ec49a6c28486140b498e70b7834">Fix use-after-free in tlsProcessPendingData() pending-list iteration</a></li> <li><a href="https://github.com/redis/redis/releases">GitHub Releases</a></li> </ul></div> </div> </div> </div> </div> </article>
- ServiceNow security advisory (AV26-857)by Canadian Centre for Cyber Security on August 28, 2026 at 1:43 pm
<article data-history-node-id="8155" about="/en/alerts-advisories/servicenow-security-advisory-av26-857" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial number: </strong>AV26-857<br /><strong>Date: </strong>August 28, 2026</p> <p>As of August 27, 2026, ServiceNow is affected by vulnerabilities in the following products:</p> <ul><li>Xanadu <ul><li>Versions prior to Patch 11 Hot Fix 7a</li> </ul></li> <li>Yokohama <ul><li>Versions prior to Yokohama Patch 12 Hot Fix 3b</li> <li>Versions prior to Yokohama Patch 13 Hot Fix 4</li> </ul></li> <li>Zurich <ul><li>Multiple versions</li> </ul></li> <li>Australia <ul><li>Multiple versions</li> </ul></li> </ul><p class="mrgn-bttm-md">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.</p> <ul class="list-unstyled"><li><a href="https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB3152242">August 2026 CVE Advisory Notification</a></li> <li><a href="https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1226057 ">ServiceNow security advisories</a></li> </ul></div> </div> </div> </div> </div> </article>
- [Control Systems] National Instruments security advisory (AV26-856)by Canadian Centre for Cyber Security on August 28, 2026 at 12:16 pm
<article data-history-node-id="8154" about="/en/alerts-advisories/control-systems-national-instruments-security-advisory-av26-856" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial Number: </strong>AV26-856<br /><strong>Date: </strong>August 28, 2026</p> <p>As of August 25, 2026, National Instruments is affected by vulnerabilities in the following product:</p> <ul><li>LabVIEW <ul><li>Prior to 23.0.0</li> <li>Prior to 23.3.10</li> <li>Prior to 24.3.7</li> <li>Prior to 25.3.5</li> <li>Prior to 26.3.1</li> </ul></li> </ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.</p> <ul class="list-unstyled"><li><a href="https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/2026/memory-corruption-vulnerabilities-ni-labview.html">Memory Corruption Vulnerabilities in NI LabVIEW – NI</a></li> <li><a href="https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/2026/integer-conversion-vulnerability-resulting-in-an-out-of-bounds-read-in-ni-labview.html">Integer Conversion Vulnerability Resulting in an Out of Bounds Read in NI LabVIEW – NI</a></li> <li><a href="https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/2026/integer-overflow-vulnerability-resulting-in-an-out-of-bounds-write-in-ni-labview.html">Integer Overflow Vulnerability Resulting in an Out of Bounds Write in NI LabVIEW – NI</a></li> <li><a href="https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/2026.html">Available Security Updates for NI Software: 2026 – NI</a></li> </ul></div> </div> </div> </div> </div> </article>
- Microsoft security advisory â August 2026 monthly rollup (AV26-804) â Update 2by Canadian Centre for Cyber Security on August 27, 2026 at 5:23 pm
<article data-history-node-id="8100" about="/en/alerts-advisories/microsoft-security-advisory-august-2026-monthly-rollup-av26-804" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial Number:</strong> AV26-804<br /><strong>Date:</strong> August 11, 2026<br /><strong>Updated:</strong> August 27, 2026</p> <p>As of August 11, 2026, Microsoft is affected by vulnerabilities in the following products:</p> <ul><li>.NET 10.0 installed on Linux</li> <li>.NET 10.0 installed on Mac OS</li> <li>.NET 10.0 installed on Windows</li> <li>.NET 8.0 installed on Linux</li> <li>.NET 8.0 installed on Mac OS</li> <li>.NET 8.0 installed on Windows</li> <li>.NET 9.0 installed on Linux</li> <li>.NET 9.0 installed on Mac OS</li> <li>.NET 9.0 installed on Windows</li> <li>App Installer</li> <li>Application Insights Profiler</li> <li>Azure Active Directory</li> <li>Azure Confidential Ledger</li> <li>Azure CycleCloud</li> <li>Azure Kubernetes Service</li> <li>Azure Logic Apps</li> <li>Azure Monitor Agent Linux Extension</li> <li>Azure SQL Database</li> <li>Azure SQL Managed Instance</li> <li>Azure SRE Agent</li> <li>Azure Service Bus</li> <li>Azure Storage Explorer</li> <li>Microsoft .NET Framework 3.5</li> <li>Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2</li> <li>Microsoft .NET Framework 3.5 AND 4.7.2</li> <li>Microsoft .NET Framework 3.5 AND 4.8</li> <li>Microsoft .NET Framework 3.5 AND 4.8.1</li> <li>Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2</li> <li>Microsoft .NET Framework 4.8</li> <li>Microsoft .NET Framework 4.8.1</li> <li>Microsoft 365 Admin Center</li> <li>Microsoft 365 Apps for Enterprise</li> <li>Microsoft Access 2016</li> <li>Microsoft Defender for Endpoint for Mac</li> <li>Microsoft Dynamics 365 (on-premises)</li> <li>Microsoft Dynamics 365 Business Central 2024</li> <li>Microsoft Dynamics 365 Business Central 2026</li> <li>Microsoft Dynamics 365 Business Central Release Wave 1 2025</li> <li>Microsoft Dynamics 365 Business Central Release Wave 2 2025</li> <li>Microsoft Entra Connect</li> <li>Microsoft Entra ID</li> <li>Microsoft Entra Provisioning Service</li> <li>Microsoft Excel 2016</li> <li>Microsoft Exchange Server 2016</li> <li>Microsoft Exchange Server 2019</li> <li>Microsoft Exchange Server Subscription Edition RTM</li> <li>Microsoft Office 2016</li> <li>Microsoft Office 2019</li> <li>Microsoft Office 365 for Mac</li> <li>Microsoft Office LTSC 2021</li> <li>Microsoft Office LTSC 2024</li> <li>Microsoft Office LTSC for Mac 2021</li> <li>Microsoft Office LTSC for Mac 2024</li> <li>Microsoft Outlook 2016</li> <li>Microsoft Planetary Computer Pro (GeoCatalog)</li> <li>Microsoft Power Apps</li> <li>Microsoft PowerPoint 2016</li> <li>Microsoft Purview eDiscovery</li> <li>Microsoft SharePoint Enterprise Server 2016</li> <li>Microsoft SharePoint Online</li> <li>Microsoft SharePoint Server 2019</li> <li>Microsoft SharePoint Server Subscription Edition</li> <li>Microsoft Teams</li> <li>Microsoft Teams for Android</li> <li>Microsoft Teams for iOS</li> <li>Microsoft Visual Studio 2022</li> <li>Microsoft Visual Studio 2026</li> <li>Microsoft Visual Studio Code CoPilot Chat Extension</li> <li>Microsoft Word 2016</li> <li>OneDrive for MacOS</li> <li>Power BI Report Server</li> <li>PowerShell 7.4</li> <li>PowerShell 7.5</li> <li>PowerShell 7.6</li> <li>Python extension for Visual Studio Code</li> <li>Visual Studio Code</li> <li>Windows 10</li> <li>Windows 11</li> <li>Windows App Client for Windows Desktop</li> <li>Windows Server 2012</li> <li>Windows Server 2012 R2</li> <li>Windows Server 2016</li> <li>Windows Server 2019</li> <li>Windows Server 2022</li> <li>Windows Server 2025</li> </ul><p>The Cyber Centre encourages users and administrators to review the web link provided, perform the suggested mitigations, and apply the necessary updates.</p> <h2 class="h3">Update 1</h2> <p>On August 18, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-33824 and CVE-2026-55040 to their Known Exploited Vulnerabilities (KEV) Database.</p> <h2 class="h3">Update 2</h2> <p>Open-source reporting indicates that CVE-2026-63520 related to Microsoft SharePoint Server is being exploited in the wild.</p> <ul class="list-unstyled"><li><a href="https://msrc.microsoft.com/update-guide/releaseNote/2026-Aug">August 2026 Security Updates</a></li> <li><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-33824">CISA KEV: CVE-2026-33824</a></li> <li><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-55040">CISA KEV: CVE-2026-55040</a></li> </ul><!–CUT & PASTE the French version info –><p> </p> </div> </div> </div> </div> </div> </article>
- Veeam security advisory (AV26-855)by Canadian Centre for Cyber Security on August 27, 2026 at 2:03 pm
<article data-history-node-id="8153" about="/en/alerts-advisories/veeam-security-advisory-av26-855" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial Number: </strong>AV26-855<br /><strong>Date: </strong>August 27, 2026</p> <p>As of August 25, 2026, Veeam is affected by vulnerabilities in the following products:</p> <ul><li>Backup and Replication <ul><li>Prior to 13.0.3 (build 13.0.3.63)</li> <li>Prior to 13.1 (build 13.1.0.411)</li> </ul></li> <li>ONE <ul><li>Prior to or equal to 13.0.2.6723</li> <li>Prior to or equal to 13.1.0.7034</li> </ul></li> </ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.</p> <ul class="list-unstyled"><li><a href="https://www.veeam.com/kb4902">KB4902: Vulnerability Resolved in Veeam Backup & Replication 13.1</a></li> <li><a href="https://www.veeam.com/kb4905">KB4905: Vulnerability Resolved in Veeam ONE 13.1 Patch 0</a></li> <li><a href="https://www.veeam.com/knowledge-base.html?type=security">Veeam Support Knowledge Base</a></li> </ul><!–CUT & PASTE the French version info –></div> </div> </div> </div> </div> </article>
- WebPros security advisory (AV26-854)by Canadian Centre for Cyber Security on August 27, 2026 at 12:57 pm
<article data-history-node-id="8152" about="/en/alerts-advisories/webpros-security-advisory-av26-854" class="cccs-threats full clearfix"> <div class="content"> <div class="layout layout–onecol"> <div class="layout__region layout__region–content"> <div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix"> </div> <div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix"> <div class="field field–name-body field–type-text-with-summary field–label-hidden field–item"><p><strong>Serial number: </strong>AV26-854<br /><strong>Date: </strong>August 27, 2026</p> <p>As of August 26, 2026, WebPros is affected by vulnerabilities in the following products:</p> <ul><li>Plesk <ul><li>Prior to 18.0.79.8</li> <li>Prior to 18.0.80.4</li> </ul></li> <li>Plesk Migrator <ul><li>Prior to 2.36.0</li> </ul></li> <li>Plesk Site Import <ul><li>Prior to 1.12.1</li> </ul></li> </ul><p class="mrgn-bttm-md">The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.</p> <ul class="list-unstyled"><li><a href="https://support.plesk.com/hc/en-us/articles/42844242102679-Vulnerability-CVE-2026-65642-in-Plesk-s-database-management-interface">Vulnerability CVE-2026-65642 in Plesk’s database management interface</a></li> <li><a href="https://support.plesk.com/hc/en-us/articles/42871001389207-Vulnerability-CVE-2026-65647-in-Plesk-s-Site-Import-and-Migrator-extensions ">Vulnerability CVE-2026-65647 in Plesk’s Site Import and Migrator extensions</a></li> </ul></div> </div> </div> </div> </div> </article>





