<?xml version="1.0" encoding="UTF-8"?><feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en"><id>https://cyber.gc.ca/api/cccs/atom/v1/get?feed=alerts_advisories&amp;lang=en</id><link rel="self" href="https://cyber.gc.ca/api/cccs/atom/v1/get?feed=alerts_advisories&amp;lang=en"/><title>Alerts and advisories</title><updated>2026-06-12T19:27:44Z</updated><entry><id>https://cyber.gc.ca/en/alerts-advisories/freepbx-security-advisory-av26-596</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/freepbx-security-advisory-av26-596"/><title><![CDATA[FreePBX security advisory (AV26–596)]]></title><updated>2026-06-12T19:27:44Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7867" about="/en/alerts-advisories/freepbx-security-advisory-av26-596" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26–596<br /><strong>Date: </strong>June 12, 2026</p>

<p>On June 12, 2026, FreePBX published security advisories to address vulnerabilities in the following products:</p>

<ul><li>FreePBX Security-Reporting ucp (FreePBX 16) – versions prior to 0.39</li>
	<li>FreePBX Security-Reporting ucp (FreePBX 17) – versions prior to 0.7</li>
	<li>FreePBX Security-Reporting superfecta (FreePBX 16) – versions prior to 16.0.40</li>
	<li>FreePBX Security-Reporting superfecta (FreePBX 17) – versions prior to 17.0.7</li>
</ul><p>The Cyber Centre encourages users and administrators to review the web links provided, apply the necessary updates and perform the suggested mitigations.</p>

<ul class="list-unstyled"><li><a href="https://github.com/FreePBX/security-reporting/security/advisories/GHSA-4jjr-8g5r-wv66">Authenticated Command Injection in FreePBX UCP Interface</a></li>
	<li><a href="https://github.com/FreePBX/security-reporting/security/advisories/GHSA-j53p-5m8r-j3p6">Authenticated Superfecta Arbitrary PHP Code Execution (RCE via Unsafe File Inclusion)</a></li>
	<li><a href="https://github.com/FreePBX/security-reporting/security/advisories?state=published">FreePBX Security Advisories</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/geoserver-security-advisory-av26-595</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/geoserver-security-advisory-av26-595"/><title><![CDATA[GeoServer security advisory (AV26-595)]]></title><updated>2026-06-12T19:12:40Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7866" about="/en/alerts-advisories/geoserver-security-advisory-av26-595" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-595<br /><strong>Date: </strong>June 12, 2026</p>

<p>On June 11, 2026, GeoServer published a security advisory to address vulnerabilities in the following products:</p>

<ul><li>GeoServer – versions prior to 3.0.0</li>
	<li>GeoTools – versions prior to 35.0</li>
	<li>GeoWebCache – versions prior to 2.0.0</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://geoserver.org/announcements/vulnerability/2026/06/11/geoserver-3-0-0-released.html">GeoServer 3.0.0 Release </a></li>
	<li><a href="https://geoserver.org/">GeoServer</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/oracle-security-advisory-av26-587</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/oracle-security-advisory-av26-587"/><title><![CDATA[Oracle security advisory (AV26-587) – Update 1]]></title><updated>2026-06-12T18:03:41Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7858" about="/en/alerts-advisories/oracle-security-advisory-av26-587" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number:</strong> AV26-587<br /><strong>Date:</strong> June 11, 2026<br /><strong>Updated:</strong> June 12, 2026</p>

<p>On June 10, 2026, Oracle published a security advisory to address a critical vulnerability in the following product:</p>

<ul><li>PeopleSoft Enterprise PeopleTools – versions 8.61 and 8.62</li>
</ul><p>Open-source reporting indicates that CVE-2026-35273 is being exploited in the wild.</p>

<h2 class="h3">Update 1</h2>

<p>On June 12, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-35273 to their Known Exploited Vulnerabilities (KEV) Database.</p>

<p class="mrgn-tp-lg">The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.</p>

<ul class="list-unstyled"><li><a href="https://www.oracle.com/security-alerts/alert-cve-2026-35273.html">Oracle Security Alert Advisory - CVE-2026-35273</a></li>
	<li><a href="https://www.oracle.com/security-alerts/">Oracle Critical Patch Updates, Security Alerts and Bulletins</a></li>
	<li><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-35273">CISA KEV: CVE-2026-35273</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/control-systems-moxa-security-advisory-av26-594</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/control-systems-moxa-security-advisory-av26-594"/><title><![CDATA[[Control Systems] Moxa security advisory (AV26-594)]]></title><updated>2026-06-12T14:09:11Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7865" about="/en/alerts-advisories/control-systems-moxa-security-advisory-av26-594" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-594<br /><strong>Date: </strong>June 12, 2026</p>

<p>On June 12, 2026, Moxa published a security advisory to address vulnerabilities in the following products:</p>

<ul><li>UC-1200A / UC-2200A /UC-3400A /UC-4400A /UC-8200 series– multiple versions and models</li>
	<li>V1200 Series – version v1.2.0 and prior</li>
	<li>V3200 / V3400 series – version v1.1 and prior</li>
	<li>V2406C WL Models – version v1.2 and prior</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates. </p>

<ul class="list-unstyled"><li><a href="https://www.moxa.com/en/support/product-support/security-advisory/mpsa-266240-cve-2026-9266-missing-required-cryptographic-step-vulnerability-in-industrial-computers">CVE-2026-9266: Missing Required Cryptographic Step Vulnerability in Industrial Computers</a></li>
	<li><a href="https://www.moxa.com/en/support/product-support/security-advisory">Moxa Security Advisories</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/google-chrome-security-advisory-av26-593</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/google-chrome-security-advisory-av26-593"/><title><![CDATA[Google Chrome security advisory (AV26-593)]]></title><updated>2026-06-12T13:55:51Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7864" about="/en/alerts-advisories/google-chrome-security-advisory-av26-593" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-593<br /><strong>Date:</strong> June 12, 2026</p>

<p>On June 11, 2026, Google published a security advisory to address vulnerabilities in the following product:</p>

<ul><li>Stable Channel Chrome for Desktop – versions prior to 149.0.7827.114/115 (Windows/Mac), and 149.0.7827.114 (Linux)</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.</p>

<ul class="list-unstyled"><li><a href="https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_01962725236.html">Google Chrome Security Advisory</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/spring-security-advisory-av26-592</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/spring-security-advisory-av26-592"/><title><![CDATA[Spring security advisory (AV26-592)]]></title><updated>2026-06-12T13:46:17Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7863" about="/en/alerts-advisories/spring-security-advisory-av26-592" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-592<br /><strong>Date: </strong>June 12, 2026</p>

<p>Between June 10 and 11, 2026, Spring published security advisories to address vulnerabilities in the following products:</p>

<ul><li>Spring Cloud Sleuth – versions 3.1.0 to 3.1.13</li>
	<li>Spring Statemachine – multiple versions</li>
	<li>Spring Cloud Gateway – multiple versions</li>
	<li>Spring Integration – multiple versions</li>
	<li>Spring for GraphQL – multiple versions</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://spring.io/security">Spring Security Advisories</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/microsoft-edge-security-advisory-av26-591</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/microsoft-edge-security-advisory-av26-591"/><title><![CDATA[Microsoft Edge security advisory (AV26-591)]]></title><updated>2026-06-12T13:37:46Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7862" about="/en/alerts-advisories/microsoft-edge-security-advisory-av26-591" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-591<br /><strong>Date:</strong> June 12, 2026</p>

<p>On June 9, 2026, Microsoft published a security update to address vulnerabilities in the following product:</p>

<ul><li>Microsoft Edge Stable Channel – versions prior to 149.0.4022.62</li>
</ul><p>Microsoft has indicated that CVE-2026-11645 has an available exploit.</p>

<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.</p>

<ul class="list-unstyled"><li><a href="https://learn.microsoft.com/en-us/DeployEdge/microsoft-edge-relnotes-security#june-9-2026">Microsoft Edge Stable Channel Release Notes</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/ivanti-security-advisory-av26-567</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/ivanti-security-advisory-av26-567"/><title><![CDATA[Ivanti security advisory (AV26-567) – Update 1]]></title><updated>2026-06-11T19:07:06Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7807" about="/en/alerts-advisories/ivanti-security-advisory-av26-567" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-567<br /><strong>Date: </strong>June 9, 2026<br /><strong>Updated: </strong>June 11, 2026</p>

<p>On June 9, 2026, Ivanti published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:</p>

<ul><li>Ivanti Sentry – versions 10.5.1, 10.6.1, 10.7.0 and prior</li>
	<li>Ivanti Endpoint Manager Mobile – versions 12.9.0, 12.8.0.2, 12.7.0.1 and prior</li>
</ul><h2 class="h4">Update 1</h2>

<p>On June 11, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-10520 to their Known Exploited Vulnerabilities (KEV) Database.</p>

<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US">Security Advisory Ivanti Sentry (CVE-2026-10520, CVE-2026-10523)</a></li>
	<li><a href="https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-6973-CVE-2026-10727?language=en_US">Security Advisory Ivanti Endpoint Manager Mobile (EPMM) (CVE-2026-6973 and CVE-2026-10727)</a></li>
	<li><a href="https://forums.ivanti.com/s/searchallcontent?language=en_US#tab=All&amp;sortCriteria=date%20descending&amp;f-sfkbknowledgearticletypec=Security%20Advisory">Ivanti Security Advisories</a></li>
	<li><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-10520 ">CISA KEV: CVE-2026-10520</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/check-point-security-advisory-av26-590</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/check-point-security-advisory-av26-590"/><title><![CDATA[Check Point security advisory (AV26-590)]]></title><updated>2026-06-11T18:32:02Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7861" about="/en/alerts-advisories/check-point-security-advisory-av26-590" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-590<br /><strong>Date: </strong>June 11, 2026</p>

<p>On June 11, 2026, Check Point published a security advisory to address a vulnerability in the following product:</p>

<ul><li>Identity Agent – versions prior to 81.087.0000</li>
</ul><p class="mrgn-bttm-md">The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.</p>

<ul class="list-unstyled"><li><a href="https://support.checkpoint.com/results/sk/sk185052">Check Point Response to CVE-2026-10847- Identity Agent Local Privilege Escalation Vulnerability</a></li>
	<li><a href="Check Point Security">Check Point Security</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/ubiquiti-security-advisory-av26-589</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/ubiquiti-security-advisory-av26-589"/><title><![CDATA[Ubiquiti security advisory (AV26-589)]]></title><updated>2026-06-11T18:28:15Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7860" about="/en/alerts-advisories/ubiquiti-security-advisory-av26-589" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-589<br /><strong>Date: </strong>June 11, 2026</p>

<p>On June 10, 2026, Ubiquiti published a security advisory to address vulnerabilities in the following products. Included were critical updates for the following:</p>

<ul><li>UID Enterprise Agent – version 1.61.3 and prior</li>
	<li>UDM, UDM-Pro, UDM-SE, UDM-Pro-Max, EFG, UDW, UDR, UDR7, UDR-5G, Express 7, UCK, UCKP, UCK-Enterprise, UNVR, UNVR-Pro, UNVR-Instant, ENVR, ENVR-Core, UNVR-G2, UNVR-G2-Pro, UCG-Ultra, UCG-Max, UCG-Industrial and UCG-Fiber – version 5.1.12 and prior</li>
	<li>UniFi OS Server – version 5.0.8 and prior</li>
	<li>UDM-Beast – version 5.1.11 and prior</li>
	<li>UNAS-2, UNAS-4, UNAS-Pro, UNAS-Pro-4 and UNAS-Pro-8 – version 5.1.10 and prior</li>
	<li>Express – version 4.0.14 and prior</li>
</ul><p class="mrgn-bttm-md">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://community.ui.com/releases/Security-Advisory-Bulletin-065-065/aa46a22b-fc43-4eae-9382-6fc8feda967a">Ubiquiti UniFi - Security Advisory Bulletin 065</a></li>
	<li><a href="https://community.ui.com/releases">Ubiquiti UniFi Security Releases</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/gitlab-security-advisory-av26-588</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/gitlab-security-advisory-av26-588"/><title><![CDATA[GitLab security advisory (AV26-588)]]></title><updated>2026-06-11T14:11:00Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7859" about="/en/alerts-advisories/gitlab-security-advisory-av26-588" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number:</strong> AV26-588<br /><strong>Date:</strong> June 11, 2026</p>

<p>On June 10, 2026, GitLab published a security advisory to address vulnerabilities in the following products:</p>

<ul><li>GitLab Community Edition (CE) – versions prior to 19.0.2, 18.11.5 and 18.10.8</li>
	<li>GitLab Enterprise Edition (EE) – versions prior to 19.0.2, 18.11.5 and 18.10.8</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-0-2-released/">GitLab Patch Release: 19.0.2, 18.11.5, 18.10.8</a></li>
	<li><a href="https://about.gitlab.com/releases/categories/releases/">GitLab Releases</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/splunk-security-advisory-av26-586</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/splunk-security-advisory-av26-586"/><title><![CDATA[Splunk security advisory (AV26-586)]]></title><updated>2026-06-10T19:12:32Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7857" about="/en/alerts-advisories/splunk-security-advisory-av26-586" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-586<br /><strong>Date: </strong>June 10, 2026</p>

<p>On June 10, 2026, Splunk published security advisories to address vulnerabilities in the following products:</p>

<ul><li>Splunk SOAR – versions prior to 8.5.0</li>
	<li>Splunk Enterprise – multiple versions and platforms</li>
	<li>Splunk Cloud Platform – multiple versions and platforms</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://advisory.splunk.com/">Splunk Security Advisories</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/broadcom-vmware-security-advisory-av26-585</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/broadcom-vmware-security-advisory-av26-585"/><title><![CDATA[Broadcom VMware security advisory (AV26-585)]]></title><updated>2026-06-10T18:41:12Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7855" about="/en/alerts-advisories/broadcom-vmware-security-advisory-av26-585" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number:</strong> AV26-585<br /><strong>Date:</strong> June 10, 2026</p>

<p>On June 9, 2026, Broadcom published a security advisory to address vulnerabilities in the following product. Included was a critical update for the following:</p>

<ul><li>VMware Tanzu for Valkey on Kubernetes – versions prior to 3.4.1</li>
</ul><p>The Cyber Centre encourages users and administrators to review the web links provided and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37636">Product Release Advisory - VMware Tanzu for Valkey on Kubernetes 3.4.1</a></li>
	<li><a href="https://support.broadcom.com/web/ecx/security-advisory?segment=VT">Security Advisories - Tanzu</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/n8n-security-advisory-av26-584</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/n8n-security-advisory-av26-584"/><title><![CDATA[n8n security advisory (AV26-584)]]></title><updated>2026-06-10T18:12:08Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7854" about="/en/alerts-advisories/n8n-security-advisory-av26-584" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number:</strong> AV26-584<br /><strong>Date:</strong> June 10, 2026</p>

<p>On June 10, 2026, n8n published security advisories to address vulnerabilities in multiple products:</p>

<ul><li>n8n (Credential Exfiltration) – multiple versions</li>
	<li>n8n (Cross-Tenant Credential) – multiple versions</li>
	<li>n8n (n8n MCP Browser) – versions 2.26.2 to 2.25.7</li>
	<li>n8n(SecurityScorecard Node) – multiple versions</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.</p>

<ul class="list-unstyled"><li><a href="https://github.com/n8n-io/n8n/security/advisories/GHSA-pmqw-72cg-wx85">Credential Exfiltration via Permission Bypass</a></li>
	<li><a href="https://github.com/n8n-io/n8n/security/advisories/GHSA-2j5h-858j-5mpf">Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints</a></li>
	<li><a href="https://github.com/n8n-io/n8n/security/advisories/GHSA-qrx8-25qr-5r7v">n8n MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions</a></li>
	<li><a href="https://github.com/n8n-io/n8n/security/advisories/GHSA-rm2v-h48j-895m">SecurityScorecard Node Leaks API Token to User-Controlled Host</a></li>
	<li><a href="https://github.com/n8n-io/n8n/security">n8n Security</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/palo-alto-networks-security-advisory-av26-583</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/palo-alto-networks-security-advisory-av26-583"/><title><![CDATA[Palo Alto Networks security advisory (AV26-583)]]></title><updated>2026-06-10T18:06:32Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7853" about="/en/alerts-advisories/palo-alto-networks-security-advisory-av26-583" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number:</strong> AV26-483<br /><strong>Date:</strong> June 10, 2026</p>

<p>On June 10, 2026, Palo Alto Networks published security advisories to address vulnerabilities in the following products:</p>

<ul><li>Cortex XSIAM CommvaultSecurityIQ Marketplace 1.1.0 – versions prior to 1.2.0</li>
	<li>Cortex XSOAR CommvaultSecurityIQ Marketplace 1.1.0 – versions prior to 1.2.0</li>
	<li>Prisma Browser – versions prior to 148.18.4.217</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://security.paloaltonetworks.com/CVE-2026-0274">CVE-2026-0274 Cortex XSOAR: Improper Validation of Credentials in CommvaultSecurityIQ integration</a></li>
	<li><a href="https://security.paloaltonetworks.com/PAN-SA-2026-0008">PAN-SA-2026-0008 Chromium: Monthly Vulnerability Update (June 2026)</a></li>
	<li><a href="https://security.paloaltonetworks.com/">Palo Alto Network Security Advisories</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/hpe-security-advisory-av26-582</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/hpe-security-advisory-av26-582"/><title><![CDATA[HPE security advisory (AV26-582)]]></title><updated>2026-06-10T18:01:52Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7852" about="/en/alerts-advisories/hpe-security-advisory-av26-582" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number:</strong> AV26-582<br /><strong>Date:</strong> June 10, 2026</p>

<p>On June 10, 2026, HPE published a security advisory to address vulnerabilities in the following products:</p>

<ul><li>HPE Telco Suite – multiple versions and models</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05061en_us&amp;docLocale=en_US">HPESBNW05061 rev.1 - HPE Telco Suite, Multiple Vulnerabilities</a></li>
	<li><a href="https://support.hpe.com/connect/s/securitybulletinlibrary?language=en_US">HPE Security Bulletin Library</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/erlang-security-advisory-av26-581</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/erlang-security-advisory-av26-581"/><title><![CDATA[Erlang security advisory (AV26-581)]]></title><updated>2026-06-10T17:39:07Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7844" about="/en/alerts-advisories/erlang-security-advisory-av26-581" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number:</strong> AV26-581<br /><strong>Date:</strong> June 10, 2026</p>

<p>On June 10, 2026, Erlang published security advisories to address vulnerabilities in the following products:</p>

<ul><li>OTP – versions prior to 27.3.4.13, 28.5.0.2 and 29.0.2</li>
	<li>erts (OTP) – versions prior to 15.2.7.9, 16.4.0.2 and 17.0.2</li>
	<li>inets (otp) – versions prior to 9.7.1, 9.6.2.2 and 9.3.2.6</li>
	<li>ssl (OTP) – versions prior to 11.7.2, 11.6.0.2 and 11.2.12.9</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://github.com/erlang/otp/security/advisories/GHSA-6f4f-chj5-5g97">Unbounded Stack Buffer Overflow in SCTP Error Cause Parsing in inet_drv</a></li>
	<li><a href="https://github.com/erlang/otp/security/advisories/GHSA-gp7x-mfv6-52cv">Distribution-over-TLS LAN Allowlist is Silently Bypassed</a></li>
	<li><a href="https://github.com/erlang/otp/security/advisories/GHSA-m75x-4vwg-ggjh">httpc leaks Authorization header to cross-origin redirect targets</a></li>
	<li><a href="https://github.com/erlang/otp/security">Erlang Security</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/control-systems-abb-security-advisory-av26-580</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/control-systems-abb-security-advisory-av26-580"/><title><![CDATA[[Control systems] ABB security advisory (AV26-580)]]></title><updated>2026-06-10T17:29:34Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7843" about="/en/alerts-advisories/control-systems-abb-security-advisory-av26-580" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number:</strong> AV26-580<br /><strong>Date:</strong> June 10, 2026</p>

<p>On June 10, 2026, ABB published a security advisory to address a vulnerability in the following products:</p>

<ul><li>PPC3100 – versions prior to 1.8.1</li>
	<li>C50 – versions prior to 1.8.0</li>
	<li>C80 – versions prior to 1.8.0</li>
	<li>FT50 – versions prior to 1.8.1</li>
	<li>MT50 – versions prior to 1.8.1</li>
	<li>T30 – versions prior to 1.8.0</li>
	<li>T80 – versions prior to 1.8.0</li>
	<li>T50 – versions prior to 1.8.1</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.</p>

<ul class="list-unstyled"><li><a href="https://br-cws-assets.de-fra-1.linodeobjects.com/SA26P009-b2b4dd6d.pdf">XZ Utils vulnerability impacting B&amp;R Products CVE ID: CVE-2025-31115 (PDF)</a></li>
	<li><a href="https://global.abb/group/en/technology/cyber-security/alerts-and-notifications">ABB Cyber security alerts and notifications</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/freepbx-security-advisory-av26-579</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/freepbx-security-advisory-av26-579"/><title><![CDATA[FreePBX security advisory (AV26–579)]]></title><updated>2026-06-10T17:24:19Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7842" about="/en/alerts-advisories/freepbx-security-advisory-av26-579" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number:</strong> AV26–579<br /><strong>Date:</strong> June 10, 2026</p>

<p>On June 10, 2026, FreePBX published a security advisory to address a vulnerability in the following product:</p>

<ul><li>FreePBX Security-Reporting music (FreePBX 16) – versions 16.0.4 and prior</li>
	<li>FreePBX Security-Reporting music (FreePBX 17) – versions 17.0.6 and prior</li>
</ul><p>The Cyber Centre encourages users and administrators to review the web links provided, apply the necessary updates and perform the suggested mitigations.</p>

<ul class="list-unstyled"><li><a href="https://github.com/FreePBX/security-reporting/security/advisories/GHSA-4g6v-whq9-944g">Authenticated Remote Code Execution in FreePBX Music on Hold (MoH) Module</a></li>
	<li><a href="https://github.com/FreePBX/security-reporting/security/advisories?state=published">FreePBX Security Advisories</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/jenkins-security-advisory-av26-578</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/jenkins-security-advisory-av26-578"/><title><![CDATA[Jenkins security advisory (AV26-578)]]></title><updated>2026-06-10T17:20:18Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7841" about="/en/alerts-advisories/jenkins-security-advisory-av26-578" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number:</strong> AV26-578<br /><strong>Date:</strong> June 10, 2026</p>

<p>On June 10, 2026, Jenkins published a security advisory to address vulnerabilities in the following products:</p>

<ul><li>Jenkins weekly – version 2.567 and prior</li>
	<li>Jenkins LTS – version 2.555.2 and prior</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://www.jenkins.io/security/advisory/2026-06-10/">Jenkins Security Advisory 2026-06-10</a></li>
	<li><a href="https://www.jenkins.io/security/advisories/">Jenkins Security Advisories</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/amd-security-advisory-av26-577</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/amd-security-advisory-av26-577"/><title><![CDATA[AMD security advisory (AV26-577)]]></title><updated>2026-06-10T14:54:16Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7833" about="/en/alerts-advisories/amd-security-advisory-av26-577" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-577<br /><strong>Date: </strong>June 10, 2026</p>

<p>On June 9, 2025, AMD published security advisories to address vulnerabilities in multiple products.</p>

<ul><li>Versal Prime Series Gen 2</li>
	<li>Versal AI Edge Series Gen 2</li>
	<li>AMD Management Console (AMC) – versions prior to 14.0.0</li>
	<li>AMD Ryzen Master – versions prior to 2.14.3</li>
	<li>AMD µProf – versions prior to 5.3</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-8021.html">ARM CPU Vulnerability: Bypass of Stage 1 translation, Stage-2 translation, or GPT Protection</a></li>
	<li><a href="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-9027.html">AMD Auto Updater Vulnerability</a></li>
	<li><a href="https://www.amd.com/en/resources/product-security.html">AMD Product Security</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/freebsd-security-advisory-av26-576</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/freebsd-security-advisory-av26-576"/><title><![CDATA[FreeBSD security advisory (AV26-576)]]></title><updated>2026-06-10T14:43:44Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7832" about="/en/alerts-advisories/freebsd-security-advisory-av26-576" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-576<br /><strong>Date: </strong>June 10, 2026</p>

<p>On June 9, 2026, FreeBSD published security advisories to address vulnerabilities in the following product:</p>

<ul><li>FreeBSD – all supported versions</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://www.freebsd.org/security/advisories/">FreeBSD Security Advisories</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/mozilla-security-advisory-av26-575</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/mozilla-security-advisory-av26-575"/><title><![CDATA[Mozilla security advisory (AV26-575)]]></title><updated>2026-06-10T14:34:58Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7831" about="/en/alerts-advisories/mozilla-security-advisory-av26-575" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-575<br /><strong>Date: </strong>June 10, 2026</p>

<p>On June 9, 2026, Mozilla published a security advisory to address vulnerabilities in the following products:</p>

<ul><li>Focus for iOS – versions prior to 151.3.1</li>
	<li>Klar for iOS – versions prior to 151.3.1</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://www.mozilla.org/en-US/security/advisories/mfsa2026-55/">Mozilla Foundation Security Advisory 2026-55</a></li>
	<li><a href="https://www.mozilla.org/en-US/security/advisories/">Mozilla Security Advisories</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/spring-security-advisory-av26-574</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/spring-security-advisory-av26-574"/><title><![CDATA[Spring security advisory (AV26-574)]]></title><updated>2026-06-10T14:29:05Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7830" about="/en/alerts-advisories/spring-security-advisory-av26-574" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-574<br /><strong>Date: </strong>June 10, 2026</p>

<p>Between June 9 and 10, 2026, Spring published security advisories to address vulnerabilities in the following products:</p>

<ul><li>Spring AMQP – multiple versions</li>
	<li>Spring Authorization Server – multiple versions</li>
	<li>Spring Web Services – multiple versions</li>
	<li>Spring Web Flow – multiple versions</li>
	<li>Spring REST Docs – multiple versions</li>
	<li>Spring Data Commons – multiple versions</li>
	<li>Spring Data Relational – multiple versions</li>
	<li>Spring Security – multiple versions</li>
	<li>Spring Data MongoDB – multiple versions</li>
	<li>Spring Data JDBC – multiple versions</li>
	<li>Spring Data KeyValue – multiple versions</li>
	<li>Spring Data R2DBC – multiple versions</li>
	<li>Spring Data Redis – multiple versions</li>
	<li>Spring Data REST – multiple versions</li>
	<li>Spring for Apache Kafka – multiple versions</li>
	<li>Spring for Apache Pulsar – multiple versions</li>
	<li>Spring Data Commons (transitively affects all Spring Data store modules) – multiple versions</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://spring.io/security">Spring Security Advisories</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/hpe-security-advisory-av26-573</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/hpe-security-advisory-av26-573"/><title><![CDATA[HPE security advisory (AV26-573)]]></title><updated>2026-06-10T14:23:28Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7829" about="/en/alerts-advisories/hpe-security-advisory-av26-573" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-573<br /><strong>Date: </strong>June 10, 2026</p>

<p>On June 9, 2026, HPE published a security advisory to address a vulnerability in the following product:</p>

<ul><li>HPE ProLiant RL300 Gen11 – versions prior to 1.84_04-02-2026</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbhf05057en_us&amp;docLocale=en_US">HPESBHF05057 rev.1 - HPE RL300 Server Using Arm Processors, Local Disclosure of Privileged Information</a></li>
	<li><a href="https://support.hpe.com/connect/s/securitybulletinlibrary?language=en_US">HPE Security Bulletin Library</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/openssl-security-advisory-av26-572</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/openssl-security-advisory-av26-572"/><title><![CDATA[OpenSSL security advisory (AV26-572)]]></title><updated>2026-06-10T14:18:42Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7828" about="/en/alerts-advisories/openssl-security-advisory-av26-572" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number:</strong> AV26-572<br /><strong>Date:</strong> June 10, 2026</p>

<p>On June 9, 2026, OpenSSL published security advisories to address vulnerabilities in the following product:</p>

<ul><li>OpenSSL – versions 4.0.0 to versions prior to 4.0.1</li>
	<li>OpenSSL – versions 3.6.0 to versions prior to 3.6.3</li>
	<li>OpenSSL – versions 3.5.0 to versions prior to 3.5.7</li>
	<li>OpenSSL – versions 3.4.0 to versions prior to 3.4.6</li>
	<li>OpenSSL – versions 3.0.0 to versions prior to 3.0.21</li>
	<li>OpenSSL – versions 1.1.1 to versions prior to 1.1.1zh</li>
	<li>OpenSSL – versions 1.0.2 to versions prior to 1.0.2zq</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://openssl-library.org/news/vulnerabilities/index.html">OpenSSL Vulnerabilities</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-551</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-551"/><title><![CDATA[Cisco security advisory (AV26-551) - Update 1]]></title><updated>2026-06-09T19:28:10Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7790" about="/en/alerts-advisories/cisco-security-advisory-av26-551" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-551<br /><strong>Date: </strong>June 5, 2026<br /><strong>Updated:</strong> June 9, 2026</p>

<p>On June 4, 2026, Cisco published a security advisory to address a vulnerability in the following product:</p>

<ul><li>Cisco Catalyst SD-WAN Manager</li>
</ul><h2 class="h3">Update 1</h2>

<p>On June 9, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20245 to their Known Exploited Vulnerabilities (KEV) Database.</p>

<p class="mrgn-bttm-md">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates, when available.</p>

<ul class="list-unstyled"><li><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx">Cisco Catalyst SD-WAN Manager Authenticated Privilege Escalation Vulnerability (CVE-2026-20245)</a></li>
	<li><a href="https://tools.cisco.com/security/center/publicationListing.x">Cisco Security Advisories</a></li>
	<li><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20245">CISA KEV: CVE-2026-20245</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/hpe-security-advisory-av26-571</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/hpe-security-advisory-av26-571"/><title><![CDATA[HPE security advisory (AV26-571)]]></title><updated>2026-06-09T19:03:41Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7818" about="/en/alerts-advisories/hpe-security-advisory-av26-571" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-571<br /><strong>Date: </strong>June 9, 2026</p>

<p>On June 9, 2026, HPE published a security advisory to address vulnerabilities in the following products:</p>

<ul><li>HPE Aruba Networking Management Software (Airwave) – version 8.3.0.6 and prior</li>
	<li>HPE Aruba Networking Private 5G Management Dashboard – all versions</li>
</ul><p class="mrgn-bttm-md">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05064en_us&amp;docLocale=en_US#hpesbnw05064-rev-1-status-of-nginx-ngx_http_rewrit-0">HPESBNW05064 rev.1 - Status of NGINX ngx_http_rewrite_module Vulnerability (CVE-2026-42945) in HPE Aruba Networking Products</a></li>
	<li><a href="https://support.hpe.com/connect/s/securitybulletinlibrary?language=en_US">HPE Security Bulletin Library</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/adobe-security-advisory-av26-570</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/adobe-security-advisory-av26-570"/><title><![CDATA[Adobe security advisory (AV26-570)]]></title><updated>2026-06-09T18:59:15Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7817" about="/en/alerts-advisories/adobe-security-advisory-av26-570" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-570<br /><strong>Date: </strong>June 9, 2026</p>

<p>On June 9, 2026, Adobe published security advisories to address critical vulnerabilities in the following products:</p>

<ul><li>Adobe Experience Manager (AEM) – version AEM Cloud Service (CS)</li>
	<li>Adobe Experience Manager (AEM) – version 6.5 LTS SP1 and prior</li>
	<li>Adobe Experience Manager (AEM) – version SP24 and prior</li>
	<li>Adobe Experience Manager 6.5 LTS – version SP1 and prior</li>
	<li>Adobe Experience Manager 6.5 – version 6.5.24.0 and prior</li>
	<li>Adobe InDesign – version ID21.3 and prior</li>
	<li>Adobe InDesign – version ID20.5.3 and prior</li>
	<li>Adobe InCopy – version 21.3 and prior</li>
	<li>Adobe InCopy – version 20.5.3 and prior</li>
	<li>Adobe Substance 3D Sampler – version 6.0.0 and prior</li>
	<li>Content Credentials JS SDK – version @contentauth/c2pa-web@0.8.3 and prior</li>
	<li>Content Credentials Rust SDK – version c2pa-v0.85.1 and prior</li>
	<li>Adobe Dreamweaver – version 21.7 and prior</li>
	<li>Adobe Acrobat – version 26.001.21651 and prior</li>
	<li>Adobe Reader – version 26.001.21651 and prior</li>
	<li>Adobe 2024 – version 24.001.30365 and prior</li>
	<li>Adobe ColdFusion 2025 – Update 8 and prior</li>
	<li>Adobe ColdFusion 2023 – Update 19 and prior</li>
	<li>Adobe Format Plugins – version 1.1.52 and prior</li>
	<li>Adobe Campaign Classic – version ACC v7: 7.4.3 build 9394 and prior</li>
</ul><p class="mrgn-bttm-md">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://helpx.adobe.com/security.html">Adobe Security Advisories</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/microsoft-security-advisory-june-2026-monthly-rollup-av26-569</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/microsoft-security-advisory-june-2026-monthly-rollup-av26-569"/><title><![CDATA[Microsoft security advisory – June 2026 monthly rollup (AV26-569)]]></title><updated>2026-06-09T18:53:14Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7816" about="/en/alerts-advisories/microsoft-security-advisory-june-2026-monthly-rollup-av26-569" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-569<br /><strong>Date: </strong>June 9, 2026</p>

<p>On June 9, 2026, Microsoft published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:</p>

<ul><li>.NET 10.0</li>
	<li>.NET 8.0</li>
	<li>.NET 9.0</li>
	<li>ASP.NET</li>
	<li>Azure Connected Machine Agent</li>
	<li>Azure HorizonDB</li>
	<li>Azure Kubernetes Service</li>
	<li>Azure Local</li>
	<li>Azure Logic Apps</li>
	<li>Azure Machine Learning</li>
	<li>Azure Monitor Agent</li>
	<li>Azure Monitor Agent Metrics Extension</li>
	<li>Azure Orbital Spatio</li>
	<li>Azure Privileged Identity Management (PIM)</li>
	<li>Azure Resource Manager</li>
	<li>Azure SDK</li>
	<li>Azure Stack Edge</li>
	<li>Azure Stack HCI</li>
	<li>Azure Virtual Network Gateway</li>
	<li>Copilot Chat</li>
	<li>Linux kernel - Microsoft MANA Network Driver</li>
	<li>M365 Copilot for Desktop</li>
	<li>Microsoft .NET Framework</li>
	<li>Microsoft 365</li>
	<li>Microsoft 365 Copilot</li>
	<li>Microsoft Authenticator</li>
	<li>Microsoft Bing</li>
	<li>Microsoft Confluence SAML SSO plugin</li>
	<li>Microsoft Data Formulator</li>
	<li>Microsoft Defender for Endpoint for Mac</li>
	<li>Microsoft Dynamics 365</li>
	<li>Microsoft Edge</li>
	<li>Microsoft Entra ID</li>
	<li>Microsoft Excel</li>
	<li>Microsoft Excel 2016</li>
	<li>Microsoft Exchange Online</li>
	<li>Microsoft Exchange Server</li>
	<li>Microsoft Global Secure Access (GSA)</li>
	<li>Microsoft Graph</li>
	<li>Microsoft JIRA SAML SSO plugin</li>
	<li>Microsoft Live Share Canvas SDK</li>
	<li>Microsoft Malware Protection Engine</li>
	<li>Microsoft Office</li>
	<li>Microsoft Office 2016</li>
	<li>Microsoft Office 2019</li>
	<li>Microsoft Office 365</li>
	<li>Microsoft Office LTSC</li>
	<li>Microsoft Outlook for iOS</li>
	<li>Microsoft PC Manager</li>
	<li>Microsoft Planetary Computer Pro (GeoCatalog)</li>
	<li>Microsoft Power Pages</li>
	<li>Microsoft PowerPoint for Android</li>
	<li>Microsoft PowerToys</li>
	<li>Microsoft SQL Server 2016</li>
	<li>Microsoft SQL Server 2017</li>
	<li>Microsoft SQL Server 2019</li>
	<li>Microsoft SQL Server 2022</li>
	<li>Microsoft SQL Server 2025</li>
	<li>Microsoft SharePoint Enterprise Server 2016</li>
	<li>Microsoft SharePoint Server 2019</li>
	<li>Microsoft Teams</li>
	<li>Microsoft Visual Studio</li>
	<li>Microsoft Visual Studio 2026</li>
	<li>Microsoft Word</li>
	<li>Microsoft Word 2016</li>
	<li>Nuance PowerScribe 360</li>
	<li>Nuance PowerScribe One</li>
	<li>Office Online Server</li>
	<li>Power Automate for Desktop</li>
	<li>PowerScribe One</li>
	<li>Remote Desktop client</li>
	<li>Visual Studio</li>
	<li>Visual Studio Code</li>
	<li>Windows 10</li>
	<li>Windows 11</li>
	<li>Windows Admin Center</li>
	<li>Windows Admin Center in Azure Portal</li>
	<li>Windows App Client</li>
	<li>Windows Narrator Braille</li>
	<li>Windows Server 2012</li>
	<li>Windows Server 2016</li>
	<li>Windows Server 2019</li>
	<li>Windows Server 2022</li>
	<li>Windows Server 2025</li>
</ul><p class="mrgn-bttm-md">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://msrc.microsoft.com/update-guide/releaseNote/2026-Jun ">June 2026 Security Updates</a></li>
</ul><p>&lt;</p>
</div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/google-chrome-security-advisory-av26-561</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/google-chrome-security-advisory-av26-561"/><title><![CDATA[Google Chrome security advisory (AV26-561) – Update 1]]></title><updated>2026-06-09T17:51:05Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7801" about="/en/alerts-advisories/google-chrome-security-advisory-av26-561" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-561<br /><strong>Date:</strong> June 9, 2026</p>

<p>On June 8, 2026, Google published a security advisory to address vulnerabilities in the following product:</p>

<ul><li>Stable Channel Chrome for Desktop – versions prior to 149.0.7827.102/.103 (Windows/Mac), and 149.0.7827.102 (Linux)</li>
</ul><p>Google is aware that an exploit for CVE-2026-11645 exists in the wild.</p>

<h2 class="h4">Update 1</h2>

<p>On June 9, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-11645 to their Known Exploited Vulnerabilities (KEV) Database.</p>

<p class="mrgn-bttm-md">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates, when available.</p>

<ul class="list-unstyled"><li><a href="https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0153744567.html">Google Chrome Security Advisory</a></li>
	<li><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-11645 ">CISA KEV: CVE-2026-11645</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/fortinet-security-advisory-av26-568</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/fortinet-security-advisory-av26-568"/><title><![CDATA[Fortinet security advisory (AV26-568)]]></title><updated>2026-06-09T15:35:07Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7809" about="/en/alerts-advisories/fortinet-security-advisory-av26-568" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-568<br /><strong>Date: </strong>June 9, 2026</p>

<p>On June 9, 2026, Fortinet published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:</p>

<ul><li>FortiSandbox 5.0 – versions 5.0.0 to 5.0.5</li>
	<li>FortiSandbox 4.4 – versions 4.4.0 to 4.4.8</li>
	<li>FortiSandbox Cloud 5.0 – versions 5.0.4 to 5.0.5</li>
	<li>FortiSandbox PaaS 5.0 – versions 5.0.4 through 5.0.5</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://fortiguard.fortinet.com/psirt/FG-IR-26-141">Second-Order OS Command Injection via JSON Input on start vnc feature</a></li>
	<li><a href="https://www.fortiguard.com/psirt?filter=1&amp;version=&amp;severity=5&amp;severity=4&amp;severity=3&amp;severity=2">Fortinet PSIRT Advisories</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/control-systems-siemens-security-advisory-av26-566</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/control-systems-siemens-security-advisory-av26-566"/><title><![CDATA[[Control systems] Siemens security advisory (AV26-566)]]></title><updated>2026-06-09T14:18:59Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7806" about="/en/alerts-advisories/control-systems-siemens-security-advisory-av26-566" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-566<br /><strong>Date:</strong> June 9, 2026</p>

<p>On June 9, 2026, Siemens published a security advisory to address vulnerabilities in the following products. Included were updates for the following products:</p>

<ul><li>SINEC INS – versions prior to V1.0 SP2 Update 6</li>
	<li>Siemens Products – multiple versions and models</li>
	<li>SIPROTEC 5 - CP100 / CP150 / CP200 / CP300 / Devices – all versions</li>
	<li>SIPROTEC 5 Compact 7SX800 (CP050) – all versions</li>
	<li>Totally Integrated Automation Portal (TIA Portal) – all versions</li>
</ul><p>The Cyber Centre encourages users and administrators to review the web links provided, perform the suggested mitigations and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://cert-portal.siemens.com/productcert/html/ssa-860189.html">SSA-860189: Multiple Vulnerabilities in SINEC INS Before V1.0 SP2 Update 6</a></li>
	<li><a href="https://cert-portal.siemens.com/productcert/html/ssa-434797.html">SSA-434797: Buffer Overflow Vulnerability in OpenSSL affecting Siemens Products</a></li>
	<li><a href="https://cert-portal.siemens.com/productcert/html/ssa-139483.html">SSA-139483: File Upload Vulnerability in SIPROTEC 5 Using DIGSI5 Protocol</a></li>
	<li><a href="https://cert-portal.siemens.com/productcert/html/ssa-063511.html">SSA-063511: Insufficient protection of key material in WinCC Certificate Manager</a></li>
	<li><a href="https://www.siemens.com/global/en/products/services/cert.html#SecurityPublications">Siemens Security Advisories</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/misp-security-advisory-av26-565</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/misp-security-advisory-av26-565"/><title><![CDATA[MISP security advisory (AV26-565)]]></title><updated>2026-06-09T13:03:17Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7805" about="/en/alerts-advisories/misp-security-advisory-av26-565" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-565<br /><strong>Date: </strong>June 9, 2026</p>

<p>On June 4, 2026, MISP published a security advisory to address vulnerabilities in the following product:</p>

<ul><li>MISP (Malware Information Sharing Platform) – versions prior to v2.5.39</li>
</ul><p class="mrgn-bttm-md">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://github.com/MISP/MISP/commit/1be8c413b7104a889dfd30c5b1986e3ab17238e8">MISP</a></li>
	<li><a href="https://github.com/MISP/MISP/releases/tag/v2.5.39">MISP 2.5.39: New Dashboard Experience, Stronger STIX, Sharper Analyst Workflows</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/veeam-security-advisory-av26-564</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/veeam-security-advisory-av26-564"/><title><![CDATA[Veeam security advisory (AV26-564)]]></title><updated>2026-06-09T12:59:00Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7804" about="/en/alerts-advisories/veeam-security-advisory-av26-564" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-564<br /><strong>Date: </strong>June 9, 2026</p>

<p>On June 9, 2026, Veeam published a security advisor to address a critical vulnerability in the following product:</p>

<ul><li>Veeam Backup and Replication – versions prior to 12.3.2.4854</li>
</ul><p class="mrgn-bttm-md">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://www.veeam.com/kb4869">Vulnerability Resolved in Veeam Backup and Replication 12.3.2.4854</a></li>
	<li><a href="https://www.veeam.com/knowledge-base.html">Veeam Knowledge Base</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/apache-security-advisory-av26-563</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/apache-security-advisory-av26-563"/><title><![CDATA[Apache security advisory (AV26-563)]]></title><updated>2026-06-09T12:54:52Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7803" about="/en/alerts-advisories/apache-security-advisory-av26-563" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-563<br /><strong>Date: </strong>June 9, 2026</p>

<p>On June 8, 2026, Apache published a security advisory to address vulnerabilities in the following product:</p>

<ul><li>Apache HTTP Server – versions prior to 2.4.68</li>
</ul><p class="mrgn-bttm-md">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://httpd.apache.org/security/vulnerabilities_24.html">Apache HTTP Server 2.4 vulnerabilities</a></li>
	<li><a href="https://httpd.apache.org/">Apache http Server Project</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/sap-security-advisory-june-2026-monthly-rollup-av26-562</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/sap-security-advisory-june-2026-monthly-rollup-av26-562"/><title><![CDATA[SAP security advisory – June 2026 monthly rollup (AV26-562)]]></title><updated>2026-06-09T12:49:53Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7802" about="/en/alerts-advisories/sap-security-advisory-june-2026-monthly-rollup-av26-562" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-562<br /><strong>Date:</strong> June 9, 2026</p>

<p>On June 9, 2026, SAP published security advisories to address vulnerabilities in the following products:</p>

<ul><li>SAP NetWeaver AS ABAP and ABAP Platform – versions SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 816, SAP_BASIS 918, SAP_BASIS 919</li>
	<li>SAP NetWeaver AS ABAP and ABAP Platform – versions KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 722EXT, 7.53, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 9.16, 9.18, 91.9</li>
	<li>SAP Commerce Cloud and SAP Data Hub – versions HY_COM 2205, HY_DHUB 2205, COM_CLOUD 2211, 2211-JDK21, DHUB_CLOUD 2211</li>
	<li>SAP NetWeaver Application Server Java (Web Container) – version ENGINEAPI 7.50</li>
	<li>SAP Commerce Cloud – versions HY_COM 2205, COM_CLOUD 2211, 2211-JDK21</li>
	<li>SAP NetWeaver AS ABAP and ABAP Platform – versions SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 816</li>
	<li>ODP Data Replication APIs – versions DW4CORE 200, 300, 400, PI_BASIS 2006_1_700, 701, 702, 731, 740, SAP_BW 750, 816</li>
	<li>SAP S/4HANA – versions S4FND 102, 103, 104, 105, 106, 107, 108, 109</li>
	<li>SAP NetWeaver AS Java (JDBC Test Servlet) – version BI_UDI 7.50</li>
	<li>SAP Wily Introscope Enterprise Manager – version WILY_INTRO_ENTERPRISE 10.8</li>
	<li>SAP MDG (Review Match Groups Application) – versions S4CORE 108, SAP_BASIS 916, SAP_BASIS 917, SAP_ABA 816</li>
	<li>SAP Business Objects Business Intelligence Platform – versions ENTERPRISE 430, 2025, 2027</li>
	<li>SAP Fiori (launchpad) – versions SAP_UI 754, 755, 756, 757, 758, 816</li>
	<li>SAP Business Objects – versions ENTERPRISE 430, 2025, 2027</li>
	<li>SAP NetWeaver AS Java – versions SERVERCORE 7.50, CORE-TOOLS 7.50, J2EE-APPS 7.50</li>
</ul><p class="mrgn-bttm-md">The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations, and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news/june-2026.html">SAP Security Patch Day - June 2026</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/check-point-security-advisory-av26-559</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/check-point-security-advisory-av26-559"/><title><![CDATA[Check Point security advisory (AV26-559) - Update 1]]></title><updated>2026-06-09T12:06:36Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7798" about="/en/alerts-advisories/check-point-security-advisory-av26-559" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number:</strong> AV26-559<br /><strong>Date:</strong> June 8, 2026<br /><strong>Updated:</strong> June 9, 2026</p>

<p>On June 8, 2026, Check Point published a security advisory to address a critical vulnerability in the following products:</p>

<ul><li>Mobile Access / SSL VPN, Remote Access VPN, Spark Firewall – multiple versions</li>
	<li>Security Gateways, Spark Firewall – multiple versions</li>
</ul><p>Check Point has observed active exploitation of this vulnerability.</p>

<h2 class="h4">Update 1</h2>

<p>On June 8, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-50751 to their Known Exploited Vulnerabilities (KEV) Database.</p>

<p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.</p>

<ul class="list-unstyled"><li><a href="https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/">Security Advisory – Action Required – Active Exploitation of Check Point VPN Authentication Bypass (CVE-2026-50751)</a></li>
	<li><a href="https://blog.checkpoint.com/security/">Check Point Security</a></li>
	<li><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-50751">CISA KEV: CVE-2026-50751</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/broadcom-vmware-security-advisory-av26-560</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/broadcom-vmware-security-advisory-av26-560"/><title><![CDATA[Broadcom VMware security advisory (AV26-560)]]></title><updated>2026-06-08T17:24:16Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7799" about="/en/alerts-advisories/broadcom-vmware-security-advisory-av26-560" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-560<br /><strong>Date: </strong>June 8, 2026</p>

<p>On June 8, 2026, Broadcom published a security advisory to address vulnerabilities in the following products:</p>

<ul><li>VMware Cloud Foundation – versions prior to 9.1.0.0</li>
	<li>VMware vSphere Foundation – versions prior to 9.1.0.0</li>
	<li>VMware Cloud Foundation – versions prior to 9.0.2.0 EP2</li>
	<li>VMware vSphere Foundation – versions prior to 9.0.2.0 EP2</li>
	<li>VMware Aria Operations – versions prior to 8.18.7</li>
	<li>VMware Aria Operations – versions prior to 8.18.6</li>
	<li>VMware Cloud Foundation – versions prior to 5.x</li>
	<li>VMware Telco Cloud Platform – versions prior to 5.x</li>
</ul><p>The Cyber Centre encourages users and administrators to review the web links provided and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37513">VMSA-2026-0004: VMware Cloud Foundation Operations updates address multiple vulnerabilities (CVE-2026-41722, CVE-2026-41723 and CVE-2026-41724)</a></li>
	<li><a href="https://support.broadcom.com/web/ecx/security-advisory?segment=VC">Security Advisories - VMware Cloud Foundation</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/spring-security-advisory-av26-558</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/spring-security-advisory-av26-558"/><title><![CDATA[Spring security advisory (AV26-558)]]></title><updated>2026-06-08T14:18:37Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7797" about="/en/alerts-advisories/spring-security-advisory-av26-558" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-558<br /><strong>Date: </strong>June 9, 2026</p>

<p>On June 8, 2026, Spring published security advisories to address vulnerabilities in the following products:</p>

<ul><li>Micrometer / Micrometer-core / jetty11 / jetty12 – multiple versions</li>
	<li>Spring LDAP – multiple versions</li>
	<li>Spring Framework – multiple versions</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://spring.io/security/cve-2026-40984">CVE-2026-40984: Micrometer HTTP server instrumentations DoS vulnerability</a></li>
	<li><a href="https://spring.io/security/cve-2026-40983">CVE-2026-40983: Micrometer gRPC server instrumentation DoS vulnerability</a></li>
	<li><a href="https://spring.io/security/cve-2026-41720">CVE-2026-41720: Authentication Bypass with Empty Password in Spring LDAP</a></li>
	<li><a href="https://spring.io/security/cve-2026-41842">CVE-2026-41842: Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux</a></li>
	<li><a href="https://spring.io/security">Spring Security Advisories</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/red-hat-security-advisory-av26-557</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/red-hat-security-advisory-av26-557"/><title><![CDATA[Red Hat security advisory (AV26-557)]]></title><updated>2026-06-08T14:12:47Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7796" about="/en/alerts-advisories/red-hat-security-advisory-av26-557" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number:</strong> AV26-557<br /><strong>Date:</strong> June 8, 2026</p>

<p>Between June 1 and 7, 2026, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:</p>

<ul><li>Red Hat CodeReady Linux Builder – multiple versions and platforms</li>
	<li>Red Hat Enterprise Linux – multiple versions and platforms</li>
	<li>Red Hat Enterprise Linux Server – multiple versions and platforms</li>
	<li>Red Hat Enterprise Linux for Real Time – multiple versions and platforms</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a class="external-link" href="https://access.redhat.com/security/security-updates/security-advisories" rel="nofollow noopener" target="_blank">Red Hat Security Advisories</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/control-systems-cisa-ics-security-advisories-av26-556</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/control-systems-cisa-ics-security-advisories-av26-556"/><title><![CDATA[[Control systems] CISA ICS security advisories (AV26–556)]]></title><updated>2026-06-08T14:06:51Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7795" about="/en/alerts-advisories/control-systems-cisa-ics-security-advisories-av26-556" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26–556<br /><strong>Date: </strong>June 8, 2026</p>

<p>Between June 1 and 7, 2026, CISA published ICS advisories to address vulnerabilities in the following products:</p>

<ul><li>B&amp;R Industrial Automation GmbH PPT30 Operating System – versions prior to 1.8.0</li>
	<li>Hitachi Energy ITT600 Explorer – version prior to 2.1 SP6</li>
	<li>Hitachi Energy MACH HiDraw – version 9.22 and prior</li>
	<li>Hitachi Energy RTU500 – multiple versions</li>
	<li>NAVTOR NavBox – version 4.16.1.20</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.</p>

<ul class="list-unstyled"><li><a href="https://www.cisa.gov/news-events/ics-advisories">CISA ICS Advisories</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/ubuntu-security-advisory-av26-555</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/ubuntu-security-advisory-av26-555"/><title><![CDATA[Ubuntu security advisory (AV26-555)]]></title><updated>2026-06-08T14:01:50Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7794" about="/en/alerts-advisories/ubuntu-security-advisory-av26-555" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-555<br /><strong>Date:</strong> June 8, 2026</p>

<p>Between June 1 and 7, 2026, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:</p>

<ul><li>Ubuntu 14.04 LTS</li>
	<li>Ubuntu 16.04 LTS</li>
	<li>Ubuntu 18.04 LTS</li>
	<li>Ubuntu 20.04 LTS</li>
	<li>Ubuntu 22.04 LTS</li>
	<li>Ubuntu 24.04 LTS</li>
	<li>Ubuntu 25.10</li>
	<li>Ubuntu 26.04 LTS</li>
</ul><p>The Cyber Centre encourages users and administrators to review the web link provided and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://ubuntu.com/security/notices">Ubuntu Security Notices</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/dell-security-advisory-av26-554</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/dell-security-advisory-av26-554"/><title><![CDATA[Dell security advisory (AV26-554)]]></title><updated>2026-06-08T13:58:08Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7793" about="/en/alerts-advisories/dell-security-advisory-av26-554" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-554<br /><strong>Date:</strong> June 8, 2026</p>

<p>Between June 1 and 7, 2026, Dell published security advisories to address vulnerabilities in multiple products:</p>

<ul><li>Dell Private Cloud -VMware – versions prior to 01.04.00.00</li>
	<li>PowerSwitch Z9864F-ON – versions prior to v3.5.0</li>
	<li>Dell Automation Platform – versions prior to 2.1.0.0</li>
	<li>Dell VxRail Appliance – versions prior to 8.0.390</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://www.dell.com/support/kbdoc/en-ca/000472451/dsa-2026-242-security-update-for-dell-private-cloud---vmware-for-multiple-third-party-component-vulnerabilities">DSA-2026-242: Security Update for Dell Private Cloud - VMware for Multiple Third-Party Component Vulnerabilities</a></li>
	<li><a href="https://www.dell.com/support/kbdoc/en-ca/000472774/dsa-2026-252-security-update-for-dell-networking-products-for-ami-megarac-spx13">DSA-2026-252: Security Update for Dell Networking Products for AMI MegaRAC SPx13</a></li>
	<li><a href="https://www.dell.com/support/kbdoc/en-ca/000473583/dsa-2026-244-security-update-for-dell-automation-platform-for-multiple-third-party-component-vulnerabilities">DSA-2026-244: Security Update for Dell Automation Platform for Multiple Third-Party Component Vulnerabilities</a></li>
	<li><a href="https://www.dell.com/support/kbdoc/en-ca/000473635/dsa-2026-245-security-update-for-dell-vxrail-for-multiple-third-party-component-vulnerabilities">DSA-2026-245: Security Update for Dell VxRail for Multiple Third-Party Component Vulnerabilities</a></li>
	<li><a href="https://www.dell.com/support/security/en-ca">Dell Security advisories and notices</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/ibm-security-advisory-av26-553</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/ibm-security-advisory-av26-553"/><title><![CDATA[IBM security advisory (AV26-553)]]></title><updated>2026-06-08T13:50:54Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7792" about="/en/alerts-advisories/ibm-security-advisory-av26-553" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-553<br /><strong>Date: </strong>June 8, 2026</p>

<p>Between June 1 and 7, 2026, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:</p>

<ul><li>Decision Optimization for Cloud Pak for Data – version 5.0 to 5.3.1 - Patch 2 releases</li>
	<li>DevOps Test UI (Test UI) – versions Test UI 11.0 to 11.0.6</li>
	<li>DevOps Test UI (Test UI) – versions Test UI 11.0 to 11.0.7</li>
	<li>FileNet Content Manager – multiple versions</li>
	<li>IBM App Connect Enterprise Certified Containers Operands - multiple versions</li>
	<li>IBM App Connect Operator – multiple versions</li>
	<li>IBM Automation Assets in IBM Cloud Pak for Integration (CP4I) – multiple versions</li>
	<li>IBM Big SQL on Cloud Pak for Data – multiple versions</li>
	<li>IBM Bob – versions 1.0.0, 1.0.1 and 1.0.2</li>
	<li>IBM Business Automation Insights – multiple versions</li>
	<li>IBM Business Automation Workflow traditional and IBM Business Automation Workflow Enterprise Service Bus – multiple versions</li>
	<li>IBM Enterprise Content Management Text Search – multiple versions</li>
	<li>IBM ICP – Discovery – version 5.0.0 to 5.3.1</li>
	<li>IBM InfoSphere Optim Archive Viewer – versions 11.7.0.0 to 11.7.0.13</li>
	<li>IBM Maximo Application Suite - Visual Inspection Component – multiple versions</li>
	<li>IBM Maximo Application Suite – versions 9.0 and 9.1</li>
	<li>IBM Netezza Appliance – versions 1.0.0.0 and 1.0.0.1</li>
	<li>IBM Observability with Instana (OnPrem) – all versions</li>
	<li>IBM Platform Navigator in IBM Cloud Pak for Integration (CP4I) – multiple versions;</li>
	<li>IBM Security QRadar EDR – versions 3.12 to 3.12.24</li>
	<li>IBM Security SOAR – multiple versions</li>
	<li>IBM Sterling Connect:Direct Web Services – versions 6.3.0 to 6.3.0.18</li>
	<li>IBM Sterling Connect:Direct Web Services – versions 6.4.0 to 6.4.0.7</li>
	<li>IBM Sterling Connect:Direct for Microsoft Windows – versions 6.3.0.0 to 6.3.0.6_iFix050</li>
	<li>IBM Sterling Connect:Direct for Microsoft Windows – versions 6.4.0.0 to 6.4.0.4_iFix021</li>
	<li>IBM Storage Scale – versions 6.0.0.0 to 6.0.0.2</li>
	<li>IBM Storage Scale – versions 5.2.0.0 to 5.2.3.7</li>
	<li>IBM Verify Antenna – versions 25.05.0 to 26.03.0</li>
	<li>IBM Verify Identity Access Container – multiple versions</li>
	<li>IBM Verify Identity Access – multiple versions</li>
	<li>IBM WebSphere Application Server – versions 9.0 and 8.5</li>
	<li>IBM WebSphere Remote Server – versions 8.5, 9.0 and 9.1</li>
	<li>Jazz for Service Management – version 1.1.3 to 1.1.3.27</li>
	<li>Maximo AI Service – version 9.1.0</li>
	<li>QRadar AI Assistant – versions 1.0.0 to 1.5.0</li>
	<li>QRadar Log Source Management App – versions 1.0.0 to 7.0.14</li>
	<li>Rational Functional Tester (RFT) – multiple versions</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://www.ibm.com/support/pages/bulletin/">IBM Product Security Incident Response</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/solarwinds-security-advisory-av26-549</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/solarwinds-security-advisory-av26-549"/><title><![CDATA[SolarWinds security advisory (AV26-549) - Update 1]]></title><updated>2026-06-05T18:02:32Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7788" about="/en/alerts-advisories/solarwinds-security-advisory-av26-549" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-549<br /><strong>Date: </strong>June 4, 2026<br /><strong>Updated: </strong>June 5, 2026</p>

<p>Between June 2 and 3, 2026, SolarWinds published security advisories to address vulnerabilities in the following products:</p>

<ul><li>SolarWinds Serv-U – versions prior to 15.5.4 HF1</li>
	<li>SolarWinds Web Help Desk – versions prior to 2026.2</li>
</ul><h2 class="h4">Update 1</h2>

<p>On June 5, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-28318 to their Known Exploited Vulnerabilities (KEV) Database.</p>

<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28299">SolarWinds Web Help Desk Denial-of-Service Vulnerability (CVE-2026-28299)</a></li>
	<li><a href="https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28318">SolarWinds Serv-U Unauthenticated Denial of Service Vulnerability (CVE-2026-28318)</a></li>
	<li><a href="https://www.solarwinds.com/trust-center/security-advisories">SolarWinds Security Vulnerabilities</a></li>
	<li><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-28318">CISA KEV: CVE-2026-28318</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/progress-security-advisory-av26-552</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/progress-security-advisory-av26-552"/><title><![CDATA[Progress security advisory (AV26-552)]]></title><updated>2026-06-05T17:19:13Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7791" about="/en/alerts-advisories/progress-security-advisory-av26-552" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-552<br /><strong>Date: </strong>June 5, 2026</p>

<p>Between June 2 and 4, 2026, Progress published security advisories to address vulnerabilities in the following products. Included was a critical update for the following:</p>

<ul><li>Sitefinity CMS and Sitefinity Insight – multiple versions</li>
	<li>Progress Kemp LoadMaster – version GA v7.2.63.1 and prior</li>
	<li>Progress Kemp LoadMaster - version LTSF v7.2.54.17 and prior</li>
</ul><p class="mrgn-bttm-md">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://community.progress.com/s/article/Sitefinity-Security-Advisory-for-Addressing-Security-Vulnerabilities-CVE-2026-7312-CVE-2026-7198-CVE-2026-7195-CVE-2026-7201-CVE-2026-7313-May-2026">Sitefinity Security Advisory for Addressing Security Vulnerabilities CVE-2026-7312, CVE-2026-7198, CVE-2026-7195, CVE-2026-7201, CVE-2026-7313, May 2026</a></li>
	<li><a href="https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-June-2026-CVE-2026-8037-CVE-2026-33691">LoadMaster Critical Security Bulletin – June 2026 – (CVE-2026-8037, CVE-2026-33691)</a></li>
	<li><a href="https://www.progress.com/trust-center">Progress Trust Center</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/docker-security-advisory-av26-550</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/docker-security-advisory-av26-550"/><title><![CDATA[Docker security advisory (AV26-550)]]></title><updated>2026-06-04T19:31:30Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7789" about="/en/alerts-advisories/docker-security-advisory-av26-550" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26–550<br /><strong>Date: </strong>June 4, 2026</p>

<p>On June 1, 2026, Docker published a security advisory to address a vulnerability in the following product:</p>

<ul><li>Docker Desktop – versions prior to 4.76.0</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://docs.docker.com/desktop/release-notes/#4760">Docker Desktop Release Notes</a></li>
	<li><a href="https://docs.docker.com/security/security-announcements/">Docker security announcements</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/broadcom-vmware-security-advisory-av26-548</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/broadcom-vmware-security-advisory-av26-548"/><title><![CDATA[Broadcom VMware security advisory (AV26-548)]]></title><updated>2026-06-03T19:49:24Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7787" about="/en/alerts-advisories/broadcom-vmware-security-advisory-av26-548" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-548<br /><strong>Date: </strong>June 3, 2026</p>

<p>On June 2, 2026, Broadcom published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:</p>

<ul><li>VMware Tanzu GemFire Management Console - versions prior to 1.4.5</li>
	<li>VMware Tanzu Data Lake - versions prior to 4.1.0</li>
	<li>VMware Tanzu for Postgres - versions prior to 18.4.0</li>
	<li>VMware Tanzu for Postgres - versions prior to 17.10.0</li>
	<li>VMware Tanzu for Postgres - versions prior to 16.14.0</li>
	<li>VMware Tanzu for Postgres - versions prior to 15.18.0</li>
	<li>VMware Tanzu for Postgres - versions prior to 14.23.0</li>
</ul><p>The Cyber Centre encourages users and administrators to review the web links provided and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37582">Product Release Advisory - VMware Tanzu GemFire Management Console</a></li>
	<li><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37581">Product Release Advisory - VMware Tanzu Data Lake 4.1.0</a></li>
	<li><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37580">Product Release Advisory - VMware Tanzu for Postgres 18.4.0, 17.10.0, 16.14.0, 15.18.0, 14.23.0</a></li>
	<li><a href="https://support.broadcom.com/web/ecx/security-advisory?segment=VT">Security Advisories - VMware Cloud Foundation</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-547</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-547"/><title><![CDATA[Cisco security advisory (AV26-547)]]></title><updated>2026-06-03T19:22:10Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7786" about="/en/alerts-advisories/cisco-security-advisory-av26-547" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-547<br /><strong>Date:</strong> June 3, 2026</p>

<p>On June 3, 2026, Cisco published security advisories to address vulnerabilities in multiple products. Included was a critical update for the following:</p>

<ul><li>Cisco Unified Communications Manager (CM) Release 14 – versions prior to 14SU6</li>
	<li>Cisco Unified Communications Manager (CM) Release 15 – versions prior to 15SU5 (Sep 2026) or COP</li>
	<li>Cisco Unified Communications Manager Session Management Edition (CM SME) release 14 – versions prior to 14SU6</li>
	<li>Cisco Unified Communications Manager Session Management Edition (CM SME) release 15 – versions prior to 15SU5 (Sep 2026) or COP</li>
</ul><p>Cisco has indicated that a proof-of-concept exploit code is available for CVE-2026-20230.</p>

<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssrf-cXPnHcW">Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability</a></li>
	<li><a href="https://tools.cisco.com/security/center/publicationListing.x">Cisco Security Advisories</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry></feed>