Meldingen
420 meldingen uit primaire bronnen. Filter op ernst, type of vendor, of zoek op een CVE-nummer of productnaam. Bulkpublicaties (BSI-updates, Patch Tuesday) staan als één regel.
Koppelen
Zet de feed in je RSS-lezer, of in Slack (/feed subscribe) of Teams (RSS-connector), dan komen nieuwe meldingen vanzelf in je teamkanaal.
Liever zelf bouwen? Dezelfde selectie als JSON, of de volledige API-specificatie (OpenAPI).
Case update: DIVD-2026-00010 - Improper Access Control in Hashtopolis Server
Last event: 16 Jul 2026 - CVE-2026-22093 published. DIVD publishes casefile.
0laagCase update: DIVD-2024-00024 - Multiple vulnerabilities found in the SOPlanning tool
Last event: 16 Jul 2026 - Full disclosure published.
0laagMennekes Smart - charging stations full disclosure
DIVD received a vulnerability report about the firmware of Mennekes Smart charging stations. The vulnerabilities were discovered by Wilco van Beijnum and analysed together with DIVD researchers Harm…
0laagSOPlanning Online Planning tool full disclosure
DIVD researchers discovered multiple vulnerabilities in the SOPlanning Online Planning tool (versions < 1.52.02). The vulnerabilities were found by researchers Wietse Boonstra and Hidde Smit, with…
0laagJuly 2026 Security Update
Ivanti releases standard security patches on the second Tuesday of every month. In today’s rapidly evolving technology and threat landscape, we believe responsible transparency should be a…
0laagUnauthenticated VNC access exposed on all interfaces
CVSSv3 Score: 7.7 An Exposure of Resource to Wrong Sphere vulnerability [CWE-668] in FortiSandbox may allow an unauthenticated attacker to access the VNC server of VMs performing scanning via…
0laagSupers override fails to properly override supervisor address
CVSSv3 Score: 6.9 An Improper Restriction of Communication Channel to Intended Endpoints [CWE-923] vulnerability in FortiSIEM Windows Agent may allow an unauthorized attacker on the same local…
0laagStack Buffer Overflow in Log Report
CVSSv3 Score: 5.9 A Stack-based Buffer Overflow vulnerability [CWE-121] in FortiOS, FortiProxy and FortiPAM may allow a privileged authenticated attacker who can bypass stack protection and ASLR to…
0laagBuffer overread in authd and wad daemon
CVSSv3 Score: 4.1 A buffer over-read vulnerability [CWE-126] in FortiOS, FortiProxy, and FortiSASE may allow an authenticated remote attacker to return a portion of device memory in the redirect…
0laagHeader injection in captive portal authentication form
CVSSv3 Score: 3.1 An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy captive portal may allow an attacker able…
0laagSSL-VPN Reflected XSS
CVSSv3 Score: 6.1 An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiOS, FortiProxy, FortiPAM and FortiSwitch-Manager Agentless…
0laagPath traversal in CLI command allows deletion of root file system
CVSSv3 Score: 5.0 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiOS, FortiPAM, FortiProxy and FortiSwitch Manager may allow a…
0laagCross-Site Scripting in Domain parameter
CVSSv3 Score: 5.3 An Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability [CWE-80] in FortiSIEM may allow a privileged administrator to execute unauthorized…
0laagOut of bounds read in GUI
CVSSv3 Score: 7.0 An out of bounds read [CWE-125] vulnerability in FortiAuthenticator may allow a remote unauthenticated attacker to retrieve sensitive information via a specially crafted request.…
0laagMissed certificate verification in AD Connector communication with FortiClient EMS
CVSSv3 Score: 6.7 An Improper Certificate Validation vulnerability [CWE-295] in FortiClient EMS may allow a remote unauthenticated attacker to impersonate an AD Connector via a valid API Key.…
0laagHeader injection in Web Filter warning page
CVSSv3 Score: 3.4 An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy may allow an attacker in possession of a…
0laagUK and Allies urge critical sectors to improve defences against Russian intelligence targeting
New advisory highlights Russian state cyber actors’ global exploitation of poorly configured routers
0laag- 0laag
- 0laag
- 0laag
AI vergroot gevaren van cyberaanvallen
De snelle groei van artificiële intelligentie (AI) vergroot de gevaren van cyberaanvallen. Er ontstaan meer risico’s op phishing en datalekken. Daarvoor waarschuwt de Autoriteit Persoonsgegevens…
0laagThe AI shift in cyber risk: why leaders must act now
Five Eyes cyber security agencies urge organisations to act on rapidly transforming cyber risk.
0laagAlert: NCSC issues advice following global targeting of Fortinet firewalls and VPN gateways
Organisations using Fortinet services are being urged to take action following a campaign affecting firewalls and VPN gateways.
0laagNCSC CEO: Hostile states linked to three-quarters of cyber attacks affecting UK's critical systems
Dr Richard Horne highlighted the scale of cyber threats against the UK’s critical infrastructure at RUSI’s Annual Security Lecture.
0laag2026-008: Critical vulnerabilities in Ivanti Sentry
On 9 June 2026, Ivanti released a security advisory addressing two critical vulnerabilities in their Sentry products[1]. An attacker could exploit those flaws to achieve unauthenticated remote code execution on the vulnerable device.
0laag2026-007: Critical Vulnerability in Windows Netlogon
On 12 May 2026, Microsoft published a security advisory addressing a critical vulnerability affecting Windows Server when acting as a domain controller. This vulnerability allows an unauthenticated attacker to execute arbitrary code over a network. According to The Centre for Cybersecurity Belgium (CCB), this vulnerab
0laagJune 2026 Security Update
Ivanti releases standard security patches on the second Tuesday of every month. In today’s rapidly evolving technology and threat landscape, we believe responsible transparency should be a…
0laagSecond-Order OS Command Injection via JSON Input on start vnc feature
CVSSv3 Score: 9.1 An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an…
0laagImproper access control in API endpoints
CVSSv3 Score: 6.2 An improper access control vulnerability [CWE-284] in FortiPortal API endpoints may allow a remote privileged attacker with organization user role to obtain sensitive network…
0laagRestricted CLI escape using Lua
CVSSv3 Score: 6.0 An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] in FortiOS and FortiProxy may allow an authenticated admin to execute lua scripts via…
0laag