CVE-2026-68489 CVE-2026-68489 — Static Code Injection in Plesk extensions "Ruby" befo... · 2 days ago CVE-2026-19583 [CRITICAL] CVE-2026-19583 — Velociraptor allows some sensitive artifacts to be ga... · 6 days ago CVE-2026-67277 [CRITICAL] CVE-2026-67277 — MikroTik RouterOS Missing Authentication for Critical... · 6 days ago CVE-2026-86060 [CRITICAL] CVE-2026-86060 — MikroTik RouterOS Improper Neutralization of Argument... · 6 days ago CVE-2025-25249 [CRITICAL] CVE-2025-25249 — Fortinet Multiple Products Heap-based Buffer Overflow... · 1 week ago CVE-2026-69412 CVE-2026-69412 — Stack-based buffer overflow in Windows DHCP Server al... · 1 week ago CVE-2026-69266 CVE-2026-69266 — Integer overflow or wraparound in Windows DHCP Server... · 1 week ago CVE-2026-85880 [CRITICAL] CVE-2026-85880 — Microsoft Windows Heap-Based Buffer Overflow Vulnerab... · 1 week ago CVE-2026-81963 [CRITICAL] CVE-2026-81963 — Microsoft Windows Link Following Vulnerability · 1 week ago ZTNA Portal Improper Certificate Validation · 1 week ago CVE-2026-68489 CVE-2026-68489 — Static Code Injection in Plesk extensions "Ruby" befo... · 2 days ago CVE-2026-19583 [CRITICAL] CVE-2026-19583 — Velociraptor allows some sensitive artifacts to be ga... · 6 days ago CVE-2026-67277 [CRITICAL] CVE-2026-67277 — MikroTik RouterOS Missing Authentication for Critical... · 6 days ago CVE-2026-86060 [CRITICAL] CVE-2026-86060 — MikroTik RouterOS Improper Neutralization of Argument... · 6 days ago CVE-2025-25249 [CRITICAL] CVE-2025-25249 — Fortinet Multiple Products Heap-based Buffer Overflow... · 1 week ago CVE-2026-69412 CVE-2026-69412 — Stack-based buffer overflow in Windows DHCP Server al... · 1 week ago CVE-2026-69266 CVE-2026-69266 — Integer overflow or wraparound in Windows DHCP Server... · 1 week ago CVE-2026-85880 [CRITICAL] CVE-2026-85880 — Microsoft Windows Heap-Based Buffer Overflow Vulnerab... · 1 week ago CVE-2026-81963 [CRITICAL] CVE-2026-81963 — Microsoft Windows Link Following Vulnerability · 1 week ago ZTNA Portal Improper Certificate Validation · 1 week ago
İdeal Çözümler // Infrastructure Security Intelligence

RADAR

Security intelligence for your infrastructure.
Ubuntu Server, Windows Server, Proxmox VE, Plesk, FortiGate / FortiOS and 6 more platforms — track vulnerabilities, critical patches and release news on a single screen. Stay a step ahead with verified, prioritised and actionable intelligence.

Active Advisories
0
Critical
0
Last 30 Days
0
Views
0
Search

Live Advisory Feed

RESET FILTERS ↺
FortiGate / FortiOS 14 Jul 2026
Low · 3.4

Header injection in Web Filter warning page

CVSSv3 Score: 3.4 An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy may allow an attacker in possession of a valid web filter override token to inject arbitrary headers via tricking a user into clicking on a crafted link. Revised on 2026-07-14 00:00:00

FG-IR-26-152 Vulnerability 34
FortiGate / FortiOS 14 Jul 2026
Medium · 5.3

Cross-Site Scripting in Domain parameter

CVSSv3 Score: 5.3 An Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability [CWE-80] in FortiSIEM may allow a privileged administrator to execute unauthorized commands via crafted requests. Revised on 2026-07-14 00:00:00

FG-IR-26-149 Vulnerability 35
FortiGate / FortiOS 14 Jul 2026
Medium · 4.1

Buffer overread in authd and wad daemon

CVSSv3 Score: 4.1 A buffer over-read vulnerability [CWE-126] in FortiOS, FortiProxy, and FortiSASE may allow an authenticated remote attacker to return a portion of device memory in the redirect response via submitting a specially crafted request. Revised on 2026-07-14 00:00:00

FG-IR-26-154 Vulnerability 31
Zabbix 08 Jul 2026
Release / Development

Zabbix 7.4.12

Zabbix 7.4.12 is available. The vendor release notes list the changes and fixes it contains.

27
Windows Server 07 Jul 2026
High · 8.1

CVE-2026-13020 — A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on

A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcGIS Administrators should configure an email server with ArcGIS Enterprise to facilitate user self-service password recovery. The ability for an administrator to reset a user’s password remains unchanged.

CVE-2026-13020 Vulnerability 32
Zabbix 07 Jul 2026
Release / Development

Zabbix 6.0.47

Zabbix 6.0.47 is available. The vendor release notes list the changes and fixes it contains.

22
Zabbix 07 Jul 2026
Release / Development

Zabbix 7.0.28

Zabbix 7.0.28 is available. The vendor release notes list the changes and fixes it contains.

22
Windows Server 06 Jul 2026
Critical · 9.8

CVE-2026-9182 — Esri ArcGIS Server contains an unrestricted file upload vulnerability.

Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endpoint. Successful exploitation could allow arbitrary file upload, potentially allowing for other attacks. This issue impacts all versions of ArcGIS Server on Windows and Linux 12.0 and prior. This issue does not impact ArcGIS Enterprise for Kubernetes.

CVE-2026-9182 Vulnerability 41
Windows Server 06 Jul 2026
Critical · 9.8

CVE-2026-9181 — Esri ArcGIS Server contains a directory traversal vulnerability.

Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An unauthenticated attacker could exploit this issue by sending crafted path parameters. Successful exploitation could allow overwriting sensitive files on the system. Abuse of this issue can allow full administrative access to ArcGIS Server, with high impact to confidentiality, integrity, and availability. This issue impacts all versions of ArcGIS Server on Windo

CVE-2026-9181 Vulnerability 40
Windows Server 22 Jun 2026
High · 8.7

CVE-2026-53779 — WebP Server Go through 0.14.4 contains a path traversal vulnerability on Windows that allows unauthenticated attackers t

WebP Server Go through 0.14.4 contains a path traversal vulnerability on Windows that allows unauthenticated attackers to read files outside the configured IMG_PATH directory by sending requests with percent-encoded backslashes (%5C) that bypass the path.Clean() sanitization in handler/router.go. Attackers can exploit the discrepancy between Go's forward-slash-only path normalization and Windows file system APIs that treat backslashes and forward slashes as equivalent to acce

CVE-2026-53779 Vulnerability 35

From the agenda

See all →