NCSC-NL — Security Advisories (RSS)
advisories-ncsc-nl · A · active
https://advisories.ncsc.nl/rss/advisories
Dutch NCSC machine-readable advisory feed (added 2026-05-08). Returns CSAF/CVRF-style Cisco/Ivanti/Apache/MOVEit/PAN-OS advisories with publication and last-update dates. The HTML hub at https://www.ncsc.nl/actueel is navigation-only (STUB) so prefer this RSS. Cite advisories via https://advisories.ncsc.nl/advisory/{id}. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → feed https://advisories.ncsc.nl/rss/advisories 5 (listing) then `python3 tools/fetch_source.py ncsc-nl csaf <NCSC-ID>` for the full advisory body — the /advisory?id= URL is a JS client-side redirect shell, do NOT bridge it directly. AVOID: WebFetch / bridge `url https://advisories.ncsc.nl/advisory?id=...` returns a JS redirect stub, not the advisory; the redirect target /<year>/<id-lower>-<ver>.html also serves a JS index page. Use the `ncsc-nl csaf` API subcommand for the structured body.. | 2026-07-05 admiralty audit: A (HIGH->A) — Dutch national CERT, primary authority for its jurisdiction; keep active; body still via ncsc-nl csaf <ID> API subcommand. | 2026-08-03 weekly (recipe fix): for NCSC-NL NEWS (as opposed to advisories) use https://feeds.ncsc.nl/nieuws.rss — the www.ncsc.nl/rss/* paths fail.
Cited in 30 entries
Citation cadence
Citation days per ISO week (13 weeks of coverage span, total 22).
- Adobe Campaign Classic APSB26-120 — three more unauthenticated CVSS 10.0 code-execution flaws, and last week's build 9398 is the version they affect2026-08-07
- Veeam Service Provider Console and Veeam ONE — ten CVEs, headed by an unauthenticated CVSS 10.0 remote code execution on the Veeam ONE agent host2026-08-06
- BSI and NCSC-NL withdraw SQLite advisories built on LLM-fabricated CVEs — and GitHub's advisory database was still serving one of them2026-08-04
- VMSA-2026-0006 — VMware vCenter: unauthenticated Directory Service auth bypass and Syslog traversal RCE (both CVSS 9.8), plus a VMXNET3 guest-to-host escape2026-07-30
- 2026-W30 vulnerability status roll-up — five CVEs crossed into confirmed exploitation/KEV, three more carry public exploit code, and a dense CVSS-9-to-10 tail hit edge, ERP, OT and file-transfer2026-07-26
- 2026-W30 looking ahead — items already in motion: a nginx pre-auth RCE PoC on a ~21-day release clock, Oracle Fusion Middleware abuse assessed 'very likely', a public AD CS DCSync PoC, a Mitel CVE pending, and two EU compliance clocks tightening2026-07-26
- Internet-facing enterprise and admin software crossed into confirmed exploitation again this week — ServiceNow, SharePoint, Check Point management, Langflow and WordPress core all moved to under-attack, and several leave persistence the patch does not remove2026-07-26
- Oracle July 2026 CPU — nine unauthenticated CVSS 10.0 flaws in Fusion Middleware, with NCSC-NL assessing large-scale abuse as very likely in the short term2026-07-26
- Check Point Security Management: two more CVEs in the actively-exploited SmartConsole bundle — unauth management RCE (CVE-2026-62144) and Gaia Portal root escalation (CVE-2026-62145)2026-07-25
- CVE-2026-0770 — Langflow: CISA confirms active exploitation of an unauthenticated exec_globals RCE the same day a 15-CVE batch (incl. unauthenticated account creation) is patched in 1.10.12026-07-22
- CVE-2026-50522 — SharePoint Server pre-auth deserialization RCE moves to active exploitation via public PoC; attackers steal machine keys for persistent forged authentication2026-07-22
- 2026-W29 looking ahead — items already in motion: WordPress WP2Shell and Firefox public exploit code, a SharePoint Pwn2Own chain half-patched until August, a withheld ShareFile CVE, and two EU regulatory clocks running2026-07-19
- WP2Shell: pre-auth RCE chain in stock WordPress core (CVE-2026-63030 + CVE-2026-60137) — out-of-band 7.0.2 patch, exploitation expected short-term2026-07-18
- Firefox 152.0.6 — chained WebAssembly memory-safety and DOM-navigation site-isolation flaws with public exploit code (CVE-2026-15718, CVE-2026-15719)2026-07-17
- Ubiquiti UniFi SAB-066 — 25 vulnerabilities incl. unauthenticated CVSS 10.0 command injection in UniFi Connect (CVE-2026-50746)2026-07-08
- CVE-2026-8451 — Citrix NetScaler ADC/Gateway: pre-auth SAML memory overread (CitrixBleed lineage), public PoC2026-07-01
- Looking ahead — 2026-W262026-06-29
- CVE-2026-55200 / CVE-2026-55199 — libssh2 heap out-of-bounds write with public PoC2026-06-29
- CVE-2026-55200 — libssh2 heap out-of-bounds write in ssh2_transport_read() with public PoC; companion pre-auth DoS CVE-2026-551992026-06-28
- CVE-2026-50751 — Check Point Security Gateway IKEv1 VPN authentication bypass: public PoC, Qilin affiliate use2026-06-22
- Check Point IKEv1 CVE-2026-50751 — public PoC raises exploitation risk2026-06-17
- June 2026 Patch Tuesday: four CVSS ≥ 9.1 criticals — Windows kernel TCP/IP RCE, Nuance PowerScribe, Azure Stack Edge, Exchange Online2026-06-12
- CVE-2026-25089 — Fortinet FortiSandbox: unauthenticated OS command injection in the web UI's VNC-launch handler (CVSS 9.8)2026-06-12
- CVE-2026-48710 "BadHost" — Starlette (FastAPI / vLLM / LiteLLM / MCP SDK): Pre-Auth Auth Bypass via Malformed Host Header2026-05-30
- CVE-2026-4868 (+ five further CVEs) — GitLab 19.0.1 / 18.11.4 / 18.10.7 patch release: Duo AI identity impersonation, unauthenticated project enumeration2026-05-29
- CVE-2026-48710 "BadHost" — Starlette pre-auth host-header auth bypass across the Python AI/ASGI stack2026-05-25
- CVE-2026-41225 — F5 BIG-IP / BIG-IQ: iControl REST Manager-role authenticated RCE (CVSS 4.0 score 8.6 / CVSS 3.1 score 9.1) leading the May 2026 Quarterly Notification2026-05-17
- Microsoft Exchange CVE-2026-42897: Active Exploitation Without a Patch2026-05-16
- CVE-2026-42897 — Microsoft Exchange Server 2016 / 2019 / SE: stored XSS in OWA, actively exploited, no permanent patch2026-05-16
- AMD-SB-7052 / CVE-2025-54518 — AMD Zen 2 µop-cache corruption / SoC isolation failure: local privilege escalation (CVSS 7.3), microcode mitigation in May 2026 Windows update and Xen XSA-4902026-05-16