ANSSI / CERT-FR
anssi-fr · A · active
French national cybersecurity agency. WebFetch on the root works; for machine-readable lists prefer the RSS feeds at https://www.cert.ssi.gouv.fr/avis/feed/ (advisories) and https://www.cert.ssi.gouv.fr/alerte/feed/ (active-exploitation alerts). Drill into per-advisory pages /avis/{id}/ to extract CVE lists and affected versions (CVSS scores generally absent in CERT-FR text). 2026-05-08 audit: WebFetch returned CERTFR-2026-AVI-0552 Ivanti EPMM 2026-05-07. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → api: python3 tools/fetch_source.py cert-fr avis-recent 5 (advisories) and cert-fr actu-recent 5 (alerts); then bridge `url https://www.cert.ssi.gouv.fr/avis/{id}/` per-advisory for CVE list + affected versions. WebFetch on the root also works.. AVOID: Don't expect CVSS scores in CERT-FR text; they cite CVE IDs and affected versions only. No need to WebFetch the root when the avis/alerte feeds are cleaner.. | 2026-06-30: CERT-FR actu feed returned only entries up to 2026-06-19 (S2 reports feed appears stale since Nov 2025 via bridge actu-recent). No in-window items; quiet-period++. National CERT — not demoted (transport 200, content stale); flag feed-staleness for investigation. | 2026-07-05 admiralty audit: A (HIGH->A) — French national CERT, primary authority; keep active. NB: actualite (actu) feed still stale (last item Nov 2025) as flagged 2026-06-30 — avis feed is fresh; flag actu-feed staleness for investigation, not a demotion. [2026-07-09] S2 observed fetch_source.py feed on CERT-FR actualite/avis feeds returns items ascending (oldest-first); N=20 surfaced Nov-2025 entries not the latest bulletin. Recheck raw feed order / consider reverse when assessing CERT-FR freshness. | 2026-07-11: KNOWN LIMIT — CERT-FR RSS feed renders a flat 00:00:00 +0000 timestamp for every item regardless of true publish time; for a "yesterday-dated" CERT-FR item the 24h recency floor is ambiguous, so corroborate the true publish time from the avis/actu page before dropping or including.
Cited in 31 entries
Citation cadence
Citation days per ISO week (14 weeks of coverage span, total 21).
- Veeam Service Provider Console and Veeam ONE — ten CVEs, headed by an unauthenticated CVSS 10.0 remote code execution on the Veeam ONE agent host2026-08-06
- CVE-2026-63455 / CVE-2026-63456 — HPE Aruba Networking SD-WAN Orchestrator: spoofed HTTP headers bypass REST API authentication (CVSS 9.8), with the vendor and CERT-FR scoping the affected branches differently2026-08-06
- Traefik 3.7.10 / 3.6.25 / 2.11.54 — a route identity built by joining names with hyphens lets one Kubernetes namespace silently take over another's traffic on a shared Gateway2026-08-05
- CVE-2026-18574 — Check Point Security Management: unauthenticated bypass of management authentication to arbitrary command execution, with no fix for seven end-of-support trains2026-08-05
- CVE-2026-66066 — Ruby on Rails Active Storage: an unauthenticated image upload reaches arbitrary file read through libvips' unfuzzed loaders, exposing every application secret (CVSS 4.0 9.5)2026-07-31
- Internet-facing enterprise and admin software crossed into confirmed exploitation again this week — ServiceNow, SharePoint, Check Point management, Langflow and WordPress core all moved to under-attack, and several leave persistence the patch does not remove2026-07-26
- Oracle July 2026 CPU — nine unauthenticated CVSS 10.0 flaws in Fusion Middleware, with NCSC-NL assessing large-scale abuse as very likely in the short term2026-07-26
- Check Point Security Management: two more CVEs in the actively-exploited SmartConsole bundle — unauth management RCE (CVE-2026-62144) and Gaia Portal root escalation (CVE-2026-62145)2026-07-25
- Mitel MiCollab AWV: unauthenticated command injection to full system compromise (CVSS 9.8, MTLVULN-1694, CVE pending)2026-07-24
- GLPI 11.0.8 / 10.0.26 — critical RCE via form import and complete MFA bypass in the public-sector ITSM platform2026-07-23
- Russian state-nexus pre-positioning against European critical infrastructure reached a new attribution-and-consequence threshold this week — router hijacking, the Turla espionage cluster, the Poland grid attack and camera surveillance all named on the same day the EU and UK imposed their first joint cyber-sanctions2026-07-19
- France and the EU attribute the Turla intrusion set to FSB Centre 16, with French victimology, TTPs and EU/UK sanctions2026-07-13
- Progress MOVEit Transfer: pre-auth SFTP DoS (CVE-2026-10699), admin table-scope bypass (CVE-2026-10698) and stored XSS (CVE-2026-11903), patched 2026.0.22026-07-11
- Siemens SICAM 8 (A8000/EGS/S8000) grid RTUs: firmware-signature-validation bypass + OPC-UA-off-by-default among four CVEs (SSA-229470)2026-07-10
- CVE-2026-4408 & CVE-2026-4480 — Samba: unauthenticated RCE in SAMR RPC and print-command subsystems (CVSS 10.0)2026-05-29
- CVE-2026-32996 & CVE-2026-32997 — Veeam Backup & Replication KB4852: LPE in Windows Agent, arbitrary file write in Linux appliance2026-05-29
- Apereo CAS version 7.3.7.1 patches an OIDC-provider flaw reported by Coop Switzerland; CERT-FR issues advisory CERTFR-2026-AVI-06542026-05-29
- CVE-2026-4408 / CVE-2026-4480 — Samba dual unauthenticated RCE (CVSS 10.0), patch window closed mid-week2026-05-25
- ANSSI / CERT-FR publishes CERTFR-2026-AVI-0635 on SPIP < 4.4.15 — security-policy bypass in the dominant French public-administration CMS2026-05-23
- Public administration — web-CMS and identity estate under multi-vector pressure2026-05-18
- CVE-2026-8043 Ivanti Xtraction external file control (CVSS 9.6) plus EPM SQL-injection-to-RCE and vTM admin OS-command injection — May 2026 advisory batch, no ITW2026-05-14
- CERTFR-2026-AVI-0572 — Centreon Infra Monitoring: RCE / SQLi / XSS cluster (April 2026 bulletin)2026-05-13
- CERTFR-2026-AVI-0564 — SPIP < 4.4.14: multiple RCEs (public and private area)2026-05-13
- GTIG AI Threat Tracker (May 2026): First Confirmed AI-Generated Zero-Day Exploit ITW and the Behavioural Class of AI-Augmented Malware2026-05-12
- Ivanti EPMM CVE-2026-5787 / CVE-2026-6973 — KEV deadline TOMORROW (2026-05-10); EU victim organisations named; 508 internet-exposed EU instances2026-05-09
- CVE-2026-40982 — Spring Cloud Config Server: pre-authentication path traversal, CVSS 9.8; all actively-maintained branches affected2026-05-09
- GLPI CERTFR-2026-AVI-0551 — Seven CVEs including SSRF and XSS in EU ITSM platform (advisory 2026-04-29)2026-05-08
- CERT-FR CERTFR-2026-ACT-016: Agentic AI tools introduce prompt-injection and supply-chain attack surfaces2026-05-08
- CVE-2026-6973 + CVE-2026-5787 — Ivanti EPMM on-prem pre-auth chain to admin RCE; 508 EU instances internet-exposed; named EU victims include the European Commission2026-05-04
- CVE-2026-0300 — Palo Alto PAN-OS Captive Portal unauthenticated root RCE; CL-STA-1132 active since 2026-04-09; no patch until 2026-05-132026-05-04
- CERT-FR CERTFR-2026-ACT-016 — agentic AI three-risk-class advisory; defender obligations explicit2026-05-04