<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>Cyber Security Agency of Singapore — Alerts</title>
<link>https://www.csa.gov.sg/alerts-and-advisories/alerts/</link>
<description>Timely information about security issues, vulnerabilities, and exploits.</description>
<language>en</language>
<lastBuildDate>Fri, 02 Oct 2026 11:18:19 +0800</lastBuildDate>
<generator>Isomer (https://www.isomer.gov.sg)</generator>
<atom:link href="https://www.csa.gov.sg/alerts-and-advisories/alerts/rss.xml" rel="self" type="application/rss+xml" />
<item><title>High-Severity Vulnerability in Apple Products</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-130</link><guid isPermaLink="false">urn:isomer:resource:422675</guid><description>Attackers can exploit a high-severity vulnerability in Apple products to execute arbitrary code on affected devices. Patch immediately.</description><pubDate>Wed, 30 Sep 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Active Exploitation of Vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-129</link><guid isPermaLink="false">urn:isomer:resource:422064</guid><description>Attackers are exploiting multiple vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway. Patch immediately.</description><pubDate>Mon, 28 Sep 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Active Exploitation of High-Severity Vulnerability in WordPress</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-128</link><guid isPermaLink="false">urn:isomer:resource:421622</guid><description>Attackers are exploiting a high-severity vulnerability in WordPress to achieve remote code execution under specific conditions. Patch immediately.</description><pubDate>Thu, 24 Sep 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Multiple Vulnerabilities in Synology DiskStation Manager (DSM)</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-127</link><guid isPermaLink="false">urn:isomer:resource:421509</guid><description>Attackers can exploit multiple vulnerabilities in Synology DiskStation Manager (DSM) to read or write arbitrary files and conduct denial-of-service attacks. Patch immediately.</description><pubDate>Wed, 23 Sep 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Active Exploitation of Vulnerability in Cisco Identity Services Engine</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-126</link><guid isPermaLink="false">urn:isomer:resource:421060</guid><description>Attackers are exploiting a critical vulnerability in Cisco Identity Services Engine and Cisco Identity Services Engine Passive Identity Connector to bypass authentication and gain unauthorised access. Patch immediately.</description><pubDate>Mon, 21 Sep 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Active Exploitation of Critical Vulnerability in Cisco AsyncOS</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-125</link><guid isPermaLink="false">urn:isomer:resource:420785</guid><description>Attackers are exploiting a critical vulnerability in Cisco AsyncOS to execute arbitrary commands with root privileges. Patch immediately.</description><pubDate>Fri, 18 Sep 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Active Exploitation of Vulnerability in Vite Development Servers</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-124</link><guid isPermaLink="false">urn:isomer:resource:420630</guid><description>Attackers are exploiting a high severity vulnerability in Vite development servers to retrieve restricted system and configuration files over HTTP. Patch immediately.</description><pubDate>Thu, 17 Sep 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Active Exploitation of Critical Vulnerability in GitLab</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-123</link><guid isPermaLink="false">urn:isomer:resource:420565</guid><description>Attackers are exploiting a critical vulnerability in GitLab to read arbitrary files from the server. Patch immediately.</description><pubDate>Thu, 17 Sep 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>High-Severity Vulnerability in MongoDB Server</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-122</link><guid isPermaLink="false">urn:isomer:resource:407073</guid><description>Attackers can exploit a high-severity vulnerability in MongoDB Server to gain full unauthenticated administrative access to the affected database. Patch promptly.</description><pubDate>Tue, 15 Sep 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Critical Vulnerabilities in Check Point Quantum Security Gateway and Security Management Server</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-121</link><guid isPermaLink="false">urn:isomer:resource:406725</guid><description>Attackers can exploit critical vulnerabilities in Check Point Quantum Security Gateway and Security Management Server to perform remote code execution without authentication. Patch immediately.</description><pubDate>Mon, 14 Sep 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>High-Severity Vulnerability in PostgreSQL</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-120</link><guid isPermaLink="false">urn:isomer:resource:405927</guid><description>Attackers can exploit a high-severity vulnerability in PostgreSQL to execute arbitrary code on the affected system. Patch promptly.</description><pubDate>Wed, 09 Sep 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Critical Vulnerabilities in SAP Products</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-119</link><guid isPermaLink="false">urn:isomer:resource:405925</guid><description>Attackers can exploit multiple vulnerabilities in SAP Products to execute arbitrary commands, obtain sensitive credentials, replace or delete tenant data and perform unauthorised actions. Patch immediately.</description><pubDate>Wed, 09 Sep 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Active Exploitation of Vulnerability in Adobe Products</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-117</link><guid isPermaLink="false">urn:isomer:resource:405916</guid><description>Attackers are exploiting a critical vulnerability in Adobe Commerce, Adobe Commerce B2B and Adobe Magento to execute arbitrary code. Patch immediately.</description><pubDate>Wed, 09 Sep 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Active Exploitation of Vulnerability in N-Able N-Central</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-118</link><guid isPermaLink="false">urn:isomer:resource:405915</guid><description>Attackers are exploiting a critical vulnerability in N-Able N-Central remote management and monitoring tool to execute code remotely without authentication. Patch immediately.</description><pubDate>Wed, 09 Sep 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>September 2026 Monthly Patch</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-116</link><guid isPermaLink="false">urn:isomer:resource:405742</guid><description>Microsoft has released security patches to address multiple vulnerabilities in their software and products.</description><pubDate>Wed, 09 Sep 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Active Exploitation of Vulnerability in NetScaler ADC and NetScaler Gateway</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-115</link><guid isPermaLink="false">urn:isomer:resource:405286</guid><description>Attackers are exploiting a critical vulnerability in NetScaler ADC and NetScaler Gateway. Patch immediately.</description><pubDate>Mon, 07 Sep 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Active Exploitation of Vulnerabilities in SonicWall SMA1000 Series</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-114</link><guid isPermaLink="false">urn:isomer:resource:404776</guid><description>Attackers are exploiting vulnerabilities in SonicWall SMA1000 Series appliances to gain unauthorised access to sensitive functionalities and execute arbitrary operating system (OS) commands.</description><pubDate>Fri, 04 Sep 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Active Exploitation of Vulnerabilities in Microsoft SharePoint</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-113</link><guid isPermaLink="false">urn:isomer:resource:403311</guid><description>Attackers are exploiting multiple vulnerabilities in Microsoft SharePoint Server to bypass a security feature and run code over a network. Patch immediately.</description><pubDate>Fri, 28 Aug 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Critical Vulnerability in Apache Tomcat</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-112</link><guid isPermaLink="false">urn:isomer:resource:402990</guid><description>Attackers can exploit a critical vulnerability in Apache Tomcat to bypass security constraints and gain unauthorised access to protected resources. Patch immediately.</description><pubDate>Thu, 27 Aug 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Active Exploitation of Vulnerability in Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-In</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-111</link><guid isPermaLink="false">urn:isomer:resource:402298</guid><description>Attackers are exploiting a critical vulnerability in Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-In to access, change or delete critical data. Patch immediately.</description><pubDate>Wed, 26 Aug 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Vulnerabilities in Privileged Access Management Application “Admin By Request”</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-110</link><guid isPermaLink="false">urn:isomer:resource:402278</guid><description>Two vulnerabilities have been discovered in the privileged access management application “Admin By Request” (ABR). The product owner has rolled out fixes for both reported vulnerabilities. Special thanks to the researchers and ABR for coordinating through CSA&apos;s Responsible Vulnerability Disclosure Policy.</description><pubDate>Wed, 26 Aug 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>High-Severity Vulnerability in Zimbra Collaboration Suite</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-109</link><guid isPermaLink="false">urn:isomer:resource:401331</guid><description>Attackers can exploit a high-severity vulnerability in Zimbra Collaboration Suite to achieve remote code execution. Patch immediately.
</description><pubDate>Fri, 21 Aug 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Multiple Vulnerabilities in Zoom Products</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-108</link><guid isPermaLink="false">urn:isomer:resource:394142</guid><description>Attackers can exploit multiple vulnerabilities in Zoom products to perform remote code execution, denial of service or disclose sensitive information. Users and administrators of affected products are advised to apply the latest security updates promptly.</description><pubDate>Thu, 20 Aug 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Multiple Vulnerabilities in HPE Aruba Networking Private 5G Core</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-107</link><guid isPermaLink="false">urn:isomer:resource:393804</guid><description>Attackers can exploit multiple vulnerabilities in HPE Aruba Networking Private 5G Core affecting third-party components Traefik and Grafana to spoof identities and escalate privileges. Patch promptly.</description><pubDate>Tue, 18 Aug 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>High-Severity Vulnerability in Cisco Secure Firewall ASA and FTD</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-106</link><guid isPermaLink="false">urn:isomer:resource:393801</guid><description>Attackers are exploiting a vulnerability in Cisco Secure Firewall ASA and FTD to cause the affected device to reload unexpectedly, resulting in a denial of service condition. Patch immediately.</description><pubDate>Tue, 18 Aug 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Multiple Vulnerabilities in Fortinet FortiWeb, FortiClient Windows, FortiManager, and FortiManager Cloud</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-105</link><guid isPermaLink="false">urn:isomer:resource:393799</guid><description>Attackers can exploit multiple vulnerabilities in Fortinet FortiWeb, FortiClient Windows, FortiManager, and FortiManager Cloud to bypass authentication, gain unauthorised access or execute arbitrary code. Patch promptly.</description><pubDate>Tue, 18 Aug 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Multiple Vulnerabilities in SAP Products</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-104</link><guid isPermaLink="false">urn:isomer:resource:393797</guid><description>Attackers can exploit multiple vulnerabilities in SAP products to execute arbitrary code, disclose sensitive information or crash affected systems. Patch immediately.</description><pubDate>Tue, 18 Aug 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>August 2026 Monthly Patch</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-103</link><guid isPermaLink="false">urn:isomer:resource:392093</guid><description>Microsoft has released security patches to address multiple vulnerabilities in their software and products.</description><pubDate>Wed, 12 Aug 2026 00:00:00 +0800</pubDate><category domain="Category">Monthly Patch</category></item>
<item><title>Missing Encryption Vulnerability in Apache Tomcat</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-102</link><guid isPermaLink="false">urn:isomer:resource:390568</guid><description>Attackers can exploit a missing encryption vulnerability in Apache Tomcat to bypass the EncryptInterceptor, potentially exposing sensitive data transmitted between cluster nodes. Patch immediately.</description><pubDate>Fri, 07 Aug 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Multiple Vulnerabilities in Cisco IOS XE Software</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-101</link><guid isPermaLink="false">urn:isomer:resource:390567</guid><description>Multiple vulnerabilities have been identified in Cisco IOS XE Software that could allow attackers to execute arbitrary commands, bypass security controls, gain unauthorised access, disclose sensitive information, or affect the operation of vulnerable systems. Patch immediately.</description><pubDate>Fri, 07 Aug 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Multiple Vulnerabilities in Cisco Catalyst SD-WAN Software</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-100</link><guid isPermaLink="false">urn:isomer:resource:390530</guid><description>Attackers can exploit multiple vulnerabilities in Cisco Catalyst SD-WAN Software to bypass security controls, gain unauthorised access, access or manipulate files, and disclose sensitive information. Patch immediately.</description><pubDate>Fri, 07 Aug 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>CatchPulse – Multiple Vulnerabilities including Improper Access Control, Unprivileged SYSTEM-Level Operations and Denial of Service </title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-098</link><guid isPermaLink="false">urn:isomer:resource:389561</guid><description>Multiple vulnerabilities have been discovered in CatchPulse. SecureAge, the product owner, has rolled out fixes for all reported vulnerabilities. Special thanks to the informer and SecureAge for coordinating through CSA&apos;s Responsible Vulnerability Disclosure Policy.</description><pubDate>Thu, 06 Aug 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Active exploitation of Critical Vulnerability in IBM Langflow OSS </title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-099</link><guid isPermaLink="false">urn:isomer:resource:389921</guid><description>Attackers are actively exploiting a critical vulnerability in IBM Langflow OSS to achieve unauthenticated remote code execution (RCE). Users and administrators of affected products are advised to apply the latest security updates immediately. </description><pubDate>Thu, 06 Aug 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Critical Vulnerability in cPanel &amp; WHM</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-097</link><guid isPermaLink="false">urn:isomer:resource:388886</guid><description>Authenticated attackers can exploit a critical vulnerability in cPanel &amp; WHM to gain database root privileges and potentially compromise other customers hosted on the same server. Patch immediately.</description><pubDate>Wed, 05 Aug 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Multiple Critical Vulnerabilities in VMware Products</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-096</link><guid isPermaLink="false">urn:isomer:resource:388798</guid><description>Attackers can exploit multiple vulnerabilities in VMware products to bypass authentication, execute arbitrary code, access sensitive information or cause denial-of-service. Patch immediately.</description><pubDate>Wed, 05 Aug 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Active Exploitation of Vulnerability in Cisco Secure Firewall Management Center</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-095</link><guid isPermaLink="false">urn:isomer:resource:386957</guid><description>Attackers are exploiting a medium-severity vulnerability in Cisco Secure Firewall Management Center to log in and access sensitive data. Patch immediately.</description><pubDate>Fri, 31 Jul 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Koollab LMS - Multiple Vulnerabilities including Remote Code Execution, SQL Injection, and Authentication Bypass</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-094</link><guid isPermaLink="false">urn:isomer:resource:383197</guid><description>Multiple vulnerabilities have been discovered in Koollab&apos;s Learning Management System (LMS). Three Learning, the product owner, has rolled out fixes for all reported vulnerabilities across all cloud-hosted instances of the LMS. Special thanks to the researchers from Centre for Strategic Infocomm Technologies (CSIT) and Three Learning for coordinating through CSA&apos;s Responsible Vulnerability Disclosure Policy.</description><pubDate>Wed, 29 Jul 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Vulnerability in EShare Application</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-093</link><guid isPermaLink="false">urn:isomer:resource:370176</guid><description>A vulnerability has been discovered in EShare’s application. Special thanks to the informer and EShare for their involvement as part of CSA&apos;s Responsible Vulnerability Disclosure Policy.</description><pubDate>Tue, 28 Jul 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Critical Vulnerability in Langflow</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-092</link><guid isPermaLink="false">urn:isomer:resource:367887</guid><description>Attackers are exploiting a critical severity vulnerability in Langflow to execute arbitrary code. Users and administrators of affected products are advised to apply the latest security updates immediately.</description><pubDate>Fri, 24 Jul 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Multiple Critical Vulnerabilities in SolarWinds Serv-U</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-091</link><guid isPermaLink="false">urn:isomer:resource:367609</guid><description>Attackers can exploit two critical vulnerabilities in SolarWinds Serv-U to perform remote code execution. Patch immediately.</description><pubDate>Thu, 23 Jul 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Critical Vulnerability in Zoom Products</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-090</link><guid isPermaLink="false">urn:isomer:resource:351126</guid><description>Attackers can exploit a critical-severity vulnerability in Zoom to conduct an account takeover via network access. Users and administrators of affected products are advised to apply the latest security updates immediately</description><pubDate>Thu, 16 Jul 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Critical Vulnerabilities in SAP NetWeaver, SAP Approuter and SAP Commerce Cloud</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-087</link><guid isPermaLink="false">urn:isomer:resource:349759</guid><description>Attackers can exploit critical vulnerabilities in SAP NetWeaver, SAP Approuter and SAP Commerce Cloud to gain unauthorised access, modify data and cause denial of service to affected systems. Patch immediately.</description><pubDate>Wed, 15 Jul 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>July 2026 Monthly Patch</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-089</link><guid isPermaLink="false">urn:isomer:resource:349787</guid><description>Microsoft has released security patches to address multiple vulnerabilities in their software and products.</description><pubDate>Wed, 15 Jul 2026 00:00:00 +0800</pubDate><category domain="Category">Monthly Patch</category></item>
<item><title>Multiple Vulnerabilities in SonicWall SMA1000 Series</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-088</link><guid isPermaLink="false">urn:isomer:resource:349773</guid><description>Attackers are exploiting two zero-day vulnerabilities in the SMA1000 series appliances to perform server-side request forgery and execute arbitrary operating system commands. Patch immediately.</description><pubDate>Wed, 15 Jul 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Vulnerability in Windows File System Proxy (WinFsp)</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-086</link><guid isPermaLink="false">urn:isomer:resource:347234</guid><description>CSA has issued a CVE ID to a vulnerability reported in WinFsp as part of CSA’s Responsible Vulnerability Disclosure Policy. Users and administrators of the affected product versions are advised to update to the latest version immediately. </description><pubDate>Mon, 13 Jul 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Active Exploitation of Critical Vulnerabilities in Joomla Extensions</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-085</link><guid isPermaLink="false">urn:isomer:resource:346931</guid><description>Attackers are exploiting critical vulnerabilities in Joomla&apos;s SP Page Builder and Page Builder CK extensions to upload malicious files and execute arbitrary code. Patch immediately.</description><pubDate>Fri, 10 Jul 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Multiple Vulnerabilities in BeyondTrust Products</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-084</link><guid isPermaLink="false">urn:isomer:resource:346729</guid><description>Attackers can exploit multiple vulnerabilities in BeyondTrust&apos;s Remote Support and Privileged Remote Access products to bypass access controls and gain unauthorised access, cause a denial of service, or access unintended resources. Patch immediately.</description><pubDate>Thu, 09 Jul 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Critical Vulnerability in Gitea Docker</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-083</link><guid isPermaLink="false">urn:isomer:resource:346656</guid><description>Attackers are exploiting a critical vulnerability in Gitea Docker images to gain unauthorised access to Gitea instances. Patch immediately.</description><pubDate>Wed, 08 Jul 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Multiple Vulnerabilities in NetScaler Products</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-082</link><guid isPermaLink="false">urn:isomer:resource:342848</guid><description>Attackers can exploit multiple vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway to read arbitrary files, trigger denial-of-service conditions, and disclose sensitive memory contents. Patch immediately.</description><pubDate>Thu, 02 Jul 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>High-Severity Vulnerabilities in NGINX</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-080</link><guid isPermaLink="false">urn:isomer:resource:307732</guid><description>Attackers can exploit high-severity vulnerabilities in NGINX to cause worker process crashes and, under certain conditions, achieve remote code execution. Patch immediately.</description><pubDate>Fri, 19 Jun 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Multiple Vulnerabilities in Cisco Identity Services Engine</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-081</link><guid isPermaLink="false">urn:isomer:resource:307755</guid><description>Attackers can exploit multiple vulnerabilities in Cisco Identity Services Engine to execute arbitrary commands on the underlying operating system and disclose sensitive information. Patch immediately.</description><pubDate>Fri, 19 Jun 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Multiple Vulnerabilities in Oracle Solaris</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-079</link><guid isPermaLink="false">urn:isomer:resource:307706</guid><description>Attackers can exploit multiple vulnerabilities in Oracle Solaris to compromise affected systems, gain unauthorised access to critical data and cause denial of service. Patch immediately.</description><pubDate>Thu, 18 Jun 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Critical Vulnerabilities in MariaDB Community Server</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-078</link><guid isPermaLink="false">urn:isomer:resource:307425</guid><description>Attackers can exploit critical vulnerabilities in MariaDB Community Server to execute arbitrary shell commands on the affected system. Patch immediately.</description><pubDate>Wed, 17 Jun 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Multiple Vulnerabilities in GitLab Products</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-076</link><guid isPermaLink="false">urn:isomer:resource:306674</guid><description>Attackers can exploit multiple high-severity vulnerabilities in GitLab to achieve account takeover, cause denial of service, add unauthorised email addresses and execute arbitrary client-side code. Patch immediately.</description><pubDate>Tue, 16 Jun 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Vulnerability in Cisco Catalyst SD-WAN Manager</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-077</link><guid isPermaLink="false">urn:isomer:resource:306787</guid><description>Attackers are exploiting a vulnerability in Cisco Catalyst SD-WAN Manager to overwrite files on the underlying filesystem and escalate privileges to root. Patch immediately.</description><pubDate>Tue, 16 Jun 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Critical Vulnerabilities in Ivanti Sentry</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-074</link><guid isPermaLink="false">urn:isomer:resource:305818</guid><description>Attackers can exploit OS command injection (CVE-2026-10520) and authentication bypass (CVE-2026-10523) vulnerabilities in Ivanti Sentry to execute commands as root, create unauthorised administrative accounts, and gain full system administrative control without authentication. Patch immediately.</description><pubDate>Fri, 12 Jun 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Critical Vulnerabilities in SAP NetWeaver and SAP Commerce Cloud</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-075</link><guid isPermaLink="false">urn:isomer:resource:305820</guid><description>Attackers can exploit critical vulnerabilities in SAP NetWeaver and SAP Commerce Cloud to gain unauthorised access and compromise affected systems. Users and administrators are advised to patch immediately.</description><pubDate>Fri, 12 Jun 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Critical Vulnerability in Fortinet FortiSandbox</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-073</link><guid isPermaLink="false">urn:isomer:resource:305817</guid><description>Attackers can exploit a critical vulnerability in Fortinet FortiSandbox via HTTP requests to execute unauthorised commands on the affected system. Patch immediately. </description><pubDate>Fri, 12 Jun 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Critical Vulnerability in Oracle PeopleSoft Enterprise PeopleTools</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-072</link><guid isPermaLink="false">urn:isomer:resource:305814</guid><description>Oracle has released security updates to address a critical vulnerability in Oracle PeopleSoft Enterprise PeopleTools that could allow unauthenticated attackers to perform remote code execution and fully compromise the affected system. Patch immediately.</description><pubDate>Fri, 12 Jun 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>June 2026 Monthly Patch </title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-071</link><guid isPermaLink="false">urn:isomer:resource:291576</guid><description>Microsoft has released security patches to address multiple vulnerabilities in their software and products.</description><pubDate>Wed, 10 Jun 2026 00:00:00 +0800</pubDate><category domain="Category">Monthly Patch</category></item>
<item><title>Critical Vulnerability in Check Point VPN</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-070</link><guid isPermaLink="false">urn:isomer:resource:289550</guid><description>Attackers are actively exploiting a critical vulnerability in Check Point VPN to bypass authentication and gain unauthorised remote access. Apply security updates immediately.</description><pubDate>Tue, 09 Jun 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>High-Severity Vulnerability in SolarWinds Serv-U</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-069</link><guid isPermaLink="false">urn:isomer:resource:283995</guid><description>Attackers are exploiting a vulnerability in SolarWinds Serv-U to crash the file transfer service without authentication, causing a denial of service condition. Patch immediately.</description><pubDate>Tue, 09 Jun 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Critical Vulnerability in Cisco Unified Communications Manager</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-067</link><guid isPermaLink="false">urn:isomer:resource:270374</guid><description>Cisco released security updates to fix a critical vulnerability in Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition. Attackers can gain root privileges by exploiting the vulnerabilities. Users of affected products are advised to update to the latest versions immediately.</description><pubDate>Fri, 05 Jun 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Critical Vulnerability in Mirasvit Full Page Cache Warmer for Magento 2</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-066</link><guid isPermaLink="false">urn:isomer:resource:270372</guid><description>Mirasvit released a security update addressing a critical vulnerability in the Full Page Cache Warmer extension for Magento 2. Users and administrators of affected products are advised to update to the latest versions immediately.</description><pubDate>Fri, 05 Jun 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>High-Severity Vulnerability in Linux Kernel</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-068</link><guid isPermaLink="false">urn:isomer:resource:270394</guid><description>Attackers are exploiting a 2022 vulnerability in the Linux kernel to escalate privileges and escape containerised environments to compromise underlying hosts. Patch immediately.</description><pubDate>Fri, 05 Jun 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Multiple Critical Vulnerabilities in Oracle Products</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-065</link><guid isPermaLink="false">urn:isomer:resource:269973</guid><description>Oracle has released security updates to address multiple vulnerabilities across several Oracle products that could allow unauthenticated attackers to compromise and take over affected systems. Users and administrators of affected products are advised to update to the latest versions immediately.</description><pubDate>Wed, 03 Jun 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Critical Vulnerability in Palo Alto Networks Products</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-064</link><guid isPermaLink="false">urn:isomer:resource:264511</guid><description>Palo Alto Networks has identified a critical vulnerability affecting the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS software and Prisma Access that allows attackers to establish unauthorised VPN connections. Users and administrators of affected product versions are advised to update to the latest versions immediately. </description><pubDate>Sun, 31 May 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Critical Vulnerability in Langflow</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-062</link><guid isPermaLink="false">urn:isomer:resource:264367</guid><description>A critical vulnerability in Langflow discovered in December 2025 is now under active exploitation. Users and administrators are advised to update to the latest version immediately.  </description><pubDate>Fri, 29 May 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>High-Severity Vulnerability in Microsoft SharePoint</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-063</link><guid isPermaLink="false">urn:isomer:resource:264368</guid><description>Microsoft has released security updates addressing a remote code execution vulnerability in SharePoint. Users and administrators of affected products are advised to update to the latest versions immediately. </description><pubDate>Fri, 29 May 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Critical Vulnerability in Drupal Core</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-060</link><guid isPermaLink="false">urn:isomer:resource:263934</guid><description>Drupal security team has released a security update to address a critical Structured Query Language (SQL) Injection vulnerability in Drupal core affecting multiple supported branches. Users and administrators of affected versions are advised to update to the latest patched versions immediately.</description><pubDate>Tue, 26 May 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Critical Vulnerability in LiteSpeed User-End cPanel Plugin</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-061</link><guid isPermaLink="false">urn:isomer:resource:263935</guid><description>LiteSpeed Technologies has released security updates addressing an Incorrect Privilege Assignment vulnerability in the LiteSpeed User-End cPanel Plugin. Users and administrators of affected versions are advised to update to the latest version immediately. </description><pubDate>Tue, 26 May 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Multiple Critical Vulnerabilities in Ubiquiti UniFi OS</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-059</link><guid isPermaLink="false">urn:isomer:resource:263923</guid><description>Ubiquiti has released security updates to address multiple critical vulnerabilities in UniFi OS. Users and administrators of affected products are advised to update to the latest versions immediately.</description><pubDate>Tue, 26 May 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Multiple Vulnerabilities in Cisco Products</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-058</link><guid isPermaLink="false">urn:isomer:resource:263371</guid><description>Cisco has released security updates addressing multiple vulnerabilities affecting multiple Cisco products. Users and administrators of affected products are advised to update to the latest versions immediately.</description><pubDate>Fri, 22 May 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Multiple Vulnerabilities in n8n Platform</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-057</link><guid isPermaLink="false">urn:isomer:resource:263277</guid><description>n8n has released security updates to address multiple vulnerabilities in n8n open-source workflow automation platform. Users and administrators of affected products are advised to update to the latest versions immediately.</description><pubDate>Fri, 22 May 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Multiple Vulnerabilities in F5 NGINX, BIG-IP and BIG-IQ</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-056</link><guid isPermaLink="false">urn:isomer:resource:253415</guid><description>F5 has released security updates to address multiple vulnerabilities in NGINX, BIG-IP, and BIG-IQ. Users and administrators of affected products are advised to update to the latest versions immediately.</description><pubDate>Mon, 18 May 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Active Exploitation of Critical Vulnerability in Cisco Catalyst SD-WAN</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-055</link><guid isPermaLink="false">urn:isomer:resource:252857</guid><description>Cisco has released security updates to address a critical vulnerability in Cisco Catalyst SD-WAN Controller. Users and administrators of affected products are advised to update to the latest versions immediately.</description><pubDate>Fri, 15 May 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Critical Vulnerabilities in Fortinet FortiAuthenticator and FortiSandbox</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-054</link><guid isPermaLink="false">urn:isomer:resource:252835</guid><description>Fortinet has released security updates to address critical vulnerabilities in FortiAuthenticator and FortiSandbox. Users and administrators of affected products are advised to update to the latest versions immediately.</description><pubDate>Fri, 15 May 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Critical Vulnerabilities in Palo Alto Networks PAN-OS</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-053</link><guid isPermaLink="false">urn:isomer:resource:252723</guid><description>Palo Alto Networks has released security updates to address critical vulnerabilities in PAN-OS. Users and administrators of affected products are advised to update to the latest versions immediately.</description><pubDate>Thu, 14 May 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Critical Vulnerabilities in SAP Commerce Cloud and SAP S/4HANA</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-051</link><guid isPermaLink="false">urn:isomer:resource:249192</guid><description>SAP has released security updates to address critical vulnerabilities in SAP Commerce Cloud and SAP S/4HANA. Users and administrators of affected products are advised to update to the latest versions immediately.</description><pubDate>Wed, 13 May 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>May 2026 Monthly Patch</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-052</link><guid isPermaLink="false">urn:isomer:resource:250026</guid><description>Microsoft has released security patches to address multiple vulnerabilities in their software and products.</description><pubDate>Wed, 13 May 2026 00:00:00 +0800</pubDate><category domain="Category">Monthly Patch</category></item>
<item><title>Vulnerability in Advantech Products</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-050</link><guid isPermaLink="false">urn:isomer:resource:247282</guid><description>CSA has issued a CVE ID to a vulnerability reported in Advantech products as part of CSA’s Responsible Vulnerability Disclosure Policy. Users and administrators of affected product versions are advised to update to the latest versions immediately. </description><pubDate>Wed, 13 May 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>High Severity Vulnerability in Apache HTTP Server</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-049</link><guid isPermaLink="false">urn:isomer:resource:230898</guid><description>Apache Software Foundation has released security updates to address a high severity vulnerability in the Apache HTTP Server. Users and administrators of the affected product are advised to update to the latest version immediately.</description><pubDate>Thu, 07 May 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Active Exploitation of Palo Alto Networks PAN-OS software</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-048</link><guid isPermaLink="false">urn:isomer:resource:230815</guid><description>Palo Alto Networks has identified a critical vulnerability affecting User-ID Authentication Portal (also known as Captive Portal) service of Palo Alto Networks PAN-OS software. Users and administrators of affected product versions are advised to restrict or disable portal access until security updates are available.</description><pubDate>Wed, 06 May 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Active Exploitation of Critical Vulnerability in cPanel, WebHost Manager (WHM) and WordPress Squared (WP2)</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-046</link><guid isPermaLink="false">urn:isomer:resource:227656</guid><description>cPanel has released security updates to address a critical vulnerability in cPanel, WebHost Manager (WHM) and Wordpress Squared (WP2). Users and administrators of affected products are advised to update to the latest versions immediately.</description><pubDate>Mon, 04 May 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>High Severity Vulnerability in Linux Kernel</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-047</link><guid isPermaLink="false">urn:isomer:resource:227733</guid><description>A security update has been released to address a high severity vulnerability in the Linux kernel. Users and administrators of affected products are advised to update to the latest versions immediately.</description><pubDate>Mon, 04 May 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>High Severity Vulnerability in OpenSSH</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-045</link><guid isPermaLink="false">urn:isomer:resource:218825</guid><description>Open SecureShell (OpenSSH) has released a security update to address a high severity vulnerability in OpenSSH. The vulnerability has a Common Vulnerability Scoring System (CVSS v3.1) score of 8.1 out of 10. Users and administrators of affected products are advised to update to the latest versions immediately.</description><pubDate>Thu, 30 Apr 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Vulnerability in Notepad++</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-044</link><guid isPermaLink="false">urn:isomer:resource:216128</guid><description>CSA has issued a CVE ID to a vulnerability reported in Notepad++ as part of CSA&apos;s Responsibility Vulnerability Disclosure Policy. Users and administrators of the affected product version are advised to update to the latest version 8.9.4 immediately. </description><pubDate>Mon, 27 Apr 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Vulnerability in Windows File System Proxy (WinFsp)</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-043</link><guid isPermaLink="false">urn:isomer:resource:216124</guid><description>CSA has issued a CVE ID to a vulnerability reported in WinFsp as part of CSA’s Responsible Vulnerability Disclosure Policy. Users and administrators of the affected product version are advised to update to the latest version immediately. </description><pubDate>Mon, 27 Apr 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Vulnerability in Koollab Learning Management System (LMS)</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-042</link><guid isPermaLink="false">urn:isomer:resource:202794</guid><description>CSA has issued a CVE ID to a vulnerability reported in Koollab LMS as part of CSA’s Responsible Vulnerability Disclosure Policy. Users and administrators of the affected product version are advised to update to the latest version 5.4.0 immediately. </description><pubDate>Thu, 23 Apr 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Critical Vulnerability in protobuf.js</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-041</link><guid isPermaLink="false">urn:isomer:resource:202655</guid><description>A critical vulnerability has been identified in protobuf.js, a JavaScript implementation of Google’s Protocol Buffers. Users and administrators of affected products are advised to update to the latest versions immediately.</description><pubDate>Tue, 21 Apr 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Critical Vulnerabilities in Cisco ISE and Webex Services</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-040</link><guid isPermaLink="false">urn:isomer:resource:201940</guid><description>Cisco has released security updates to address multiple security vulnerabilities in two of its products: Identity Services Engine (ISE) and Webex Services. There are no indications that these vulnerabilities are being exploited in the wild when this alert is reported. However,successful exploitation of these vulnerabilities may result in gaining root access and remote code execution. Users and administrators of affected products are advised to update to the latest versions immediately.</description><pubDate>Fri, 17 Apr 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Critical Vulnerability in Nginx UI</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-039</link><guid isPermaLink="false">urn:isomer:resource:197835</guid><description>Nginx-UI has released a security advisory addressing a vulnerability affecting Nginx-UI with Model Context Protocol (MCP) support.This vulnerability is being exploited in the wild. Successful exploitation of this vulnerability can allow any network attacker to invoke all MCP tools without authentication and lead to a complete NGINX service takeover.
Users and administrators of affected products are advised to update to the latest version immediately.</description><pubDate>Fri, 17 Apr 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Critical Vulnerabilities in Fortinet Product</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-038</link><guid isPermaLink="false">urn:isomer:resource:193938</guid><description>Fortinet has released software updates addressing vulnerabilities in FortiSandbox.Users and administrators of affected products are advised to update to the latest versions immediately.</description><pubDate>Thu, 16 Apr 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Critical Vulnerability in Axios</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-037</link><guid isPermaLink="false">urn:isomer:resource:193931</guid><description>Axios has released a software patch to address a critical security vulnerability in the Axios library. Users and administrators of affected product versions are advised to update to the latest version immediately.</description><pubDate>Thu, 16 Apr 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>April 2026 Monthly Patch</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-036</link><guid isPermaLink="false">urn:isomer:resource:193773</guid><description>Microsoft has released security patches to address multiple vulnerabilities in their software and products.</description><pubDate>Wed, 15 Apr 2026 00:00:00 +0800</pubDate><category domain="Category">Monthly Patch</category></item>
<item><title>Active Exploitation of Critical Vulnerability in Adobe Acrobat and Reader</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-035</link><guid isPermaLink="false">urn:isomer:resource:193377</guid><description>Adobe has released a security update to address a critical vulnerability in Adobe Acrobat and Reader. Users and administrators of affected products are advised to update to the latest versions immediately.</description><pubDate>Mon, 13 Apr 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Critical Vulnerability in Apache ActiveMQ Classic</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-034</link><guid isPermaLink="false">urn:isomer:resource:193372</guid><description>Apache has released security updates to address a critical vulnerability in Apache ActiveMQ Classic. Users and administrators of affected products are advised to update to the latest versions immediately.</description><pubDate>Mon, 13 Apr 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Multiple Vulnerabilities in SonicWall SMA1000 Series</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-033</link><guid isPermaLink="false">urn:isomer:resource:193369</guid><description>SonicWall has released security updates to address multiple vulnerabilities in the SMA1000 series appliances. Users and administrators of affected products are advised to update to the latest version immediately.</description><pubDate>Mon, 13 Apr 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Active Exploitation of Critical Vulnerability in F5 BIG-IP Access Policy Manager</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-032</link><guid isPermaLink="false">urn:isomer:resource:184366</guid><description>F5 has released security updates to address a critical vulnerability in BIG‑IP Access Policy Manager (APM). Users and administrators of affected products are advised to update to the latest versions immediately.</description><pubDate>Mon, 06 Apr 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
<item><title>Active Exploitation of Critical Vulnerability in FortiClient EMS</title><link>https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-031</link><guid isPermaLink="false">urn:isomer:resource:183844</guid><description>Fortinet has released security updates to address a critical security vulnerability in FortiClient EMS. Users and administrators of affected versions are advised to install the hotfix immediately and update to the latest version once available.</description><pubDate>Mon, 06 Apr 2026 00:00:00 +0800</pubDate><category domain="Category">Alerts</category></item>
</channel>
</rss>