ANSSI / CERT-FR
anssi-fr · A · active
French national cybersecurity agency. WebFetch on the root works; for machine-readable lists prefer the RSS feeds at https://www.cert.ssi.gouv.fr/avis/feed/ (advisories) and https://www.cert.ssi.gouv.fr/alerte/feed/ (active-exploitation alerts). Drill into per-advisory pages /avis/{id}/ to extract CVE lists and affected versions (CVSS scores generally absent in CERT-FR text). 2026-05-08 audit: WebFetch returned CERTFR-2026-AVI-0552 Ivanti EPMM 2026-05-07. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → api: python3 tools/fetch_source.py cert-fr avis-recent 5 (advisories) and cert-fr actu-recent 5 (alerts); then bridge `url https://www.cert.ssi.gouv.fr/avis/{id}/` per-advisory for CVE list + affected versions. WebFetch on the root also works.. AVOID: Don't expect CVSS scores in CERT-FR text; they cite CVE IDs and affected versions only. No need to WebFetch the root when the avis/alerte feeds are cleaner.. | 2026-06-30: CERT-FR actu feed returned only entries up to 2026-06-19 (S2 reports feed appears stale since Nov 2025 via bridge actu-recent). No in-window items; quiet-period++. National CERT, not demoted (transport 200, content stale); flag feed-staleness for investigation. | 2026-07-05 admiralty audit: A (HIGH->A), French national CERT, primary authority; keep active. NB: actualite (actu) feed still stale (last item Nov 2025) as flagged 2026-06-30; avis feed is fresh; flag actu-feed staleness for investigation, not a demotion. [2026-07-09] S2 observed fetch_source.py feed on CERT-FR actualite/avis feeds returns items ascending (oldest-first); N=20 surfaced Nov-2025 entries not the latest bulletin. Recheck raw feed order / consider reverse when assessing CERT-FR freshness. | 2026-07-11: KNOWN LIMIT, CERT-FR RSS feed renders a flat 00:00:00 +0000 timestamp for every item regardless of true publish time; for a "yesterday-dated" CERT-FR item the 24h recency floor is ambiguous, so corroborate the true publish time from the avis/actu page before dropping or including.
Cited in 39 entries
Citation cadence
Citation days per ISO week (20 weeks of coverage span, total 30).
- CVE-2026-91843, Check Point Security Management / Multi-Domain Security Management / Log Server: unauthenticated stack overflow in the login process reaches root RCE (CVSS 9.8)2026-09-18
- CVE-2026-76460 (+ CVE-2026-76423), Cisco Identity Services Engine: unauthenticated API authentication bypass to root, found while resolving a customer support case, no workaround beyond ACLs (CVSS 10.0)2026-09-17
- CVE-2026-85706, GitLab CE/EE: unauthenticated path traversal in the repository commits API reads arbitrary server files, and honeypots caught exploitation attempts one day after the patch (CVSS 10.0)2026-09-12
- Apereo CAS: an embargoed remote-code-execution disclosure affects every 7.3.x deployment regardless of configuration, patched to 7.3.8.3, no CVE or technical detail published yet2026-09-11
- CVE-2026-87491, Google Chrome: V8 out-of-bounds write exploited in the wild, patched in Chrome 153 (seventh exploited Chrome zero-day of 2026)2026-09-10
- HPE Networking Fabric Composer and ArubaOS-CX: two unauthenticated CVSS 10.0 RCEs in the fabric-management plane, plus a CVSS 9.8 unauthenticated buffer-overflow RCE in the switch OS2026-09-04
- CVE-2026-20212, Cisco Nexus 9000 Series: unauthenticated root RCE via the Silicon One hardware-abstraction layer on TCP 43210/432112026-09-04
- CVE-2026-82078 / CVE-2026-81578, PaperCut NG/MF: an Apache Tapestry request-routing confusion chains an unauthenticated config rewrite to arbitrary code execution, exploited before a patch existed2026-08-29
- SPIP shipped two emergency releases in three days, each fixing an unconditional pre-authentication RCE the vendor says is already being exploited, and only the first one has a CVE2026-08-22
- CVE-2026-73570, Zimbra Collaboration: a pre-auth command injection patched without a CVE in July is now recorded as actively exploited, four weeks after the fix shipped2026-08-20
- CVE-2026-19478; GitLab ships an out-of-band critical patch for a GraphQL directive flaw that lets an unauthenticated caller modify or delete public projects and user data (CVSS 9.4)2026-08-19
- CVE-2026-58115; Siemens SIMATIC IoT2050 Advanced ships a Node-RED interface with no authentication, so one unauthenticated HTTP request runs code as root on an OT edge gateway (CVSS 10.0)2026-08-13
- ShieldBreak, a public proof-of-concept defeats Microsoft's July fix for the RoguePlanet Defender flaw, claims 100% reliability where the original was a coin flip, and now covers Windows Server 20252026-08-12
- WALLIX Bastion's REST API hands full appliance administration to an unauthenticated caller (CVSS 4.0 10.0), the credential vault and session recordings included, with public technical details due in September2026-08-09
- CVE-2026-16443, Keycloak: importing SAML metadata without key-usage attributes silently disables response signature validation, so an unauthenticated attacker forges a login as any known user2026-08-07
- Veeam Service Provider Console and Veeam ONE, ten CVEs, headed by an unauthenticated CVSS 10.0 remote code execution on the Veeam ONE agent host2026-08-06
- CVE-2026-63455 / CVE-2026-63456, HPE Aruba Networking SD-WAN Orchestrator: spoofed HTTP headers bypass REST API authentication (CVSS 9.8), with the vendor and CERT-FR scoping the affected branches differently2026-08-06
- Traefik 3.7.10 / 3.6.25 / 2.11.54, a route identity built by joining names with hyphens lets one Kubernetes namespace silently take over another's traffic on a shared Gateway2026-08-05
- CVE-2026-18574, Check Point Security Management: unauthenticated bypass of management authentication to arbitrary command execution, with no fix for seven end-of-support trains2026-08-05
- CVE-2026-66066, Ruby on Rails Active Storage: an unauthenticated image upload reaches arbitrary file read through libvips' unfuzzed loaders, exposing every application secret (CVSS 4.0 9.5)2026-07-31
- Oracle July 2026 CPU, nine unauthenticated CVSS 10.0 flaws in Fusion Middleware, with NCSC-NL assessing large-scale abuse as very likely in the short term2026-07-26
- Mitel MiCollab AWV: unauthenticated command injection to full system compromise (CVSS 9.8, MTLVULN-1694, CVE pending)2026-07-24
- GLPI 11.0.8 / 10.0.26, critical RCE via form import and complete MFA bypass in the public-sector ITSM platform2026-07-23
- CVE-2026-16232, Check Point SmartConsole: authentication bypass to full admin, exploited in the wild (CVSS 9.1)2026-07-23
- FSB Centre 16 (Static Tundra) router-hijacking campaign: 19-agency joint advisory, formal Poland energy-grid attribution and first joint EU/UK cyber sanctions2026-07-13
- Progress MOVEit Transfer: pre-auth SFTP DoS (CVE-2026-10699), admin table-scope bypass (CVE-2026-10698) and stored XSS (CVE-2026-11903), patched 2026.0.22026-07-11
- Siemens SICAM 8 (A8000/EGS/S8000) grid RTUs: firmware-signature-validation bypass + OPC-UA-off-by-default among four CVEs (SSA-229470)2026-07-10
- CVE-2026-4408 & CVE-2026-4480, Samba: unauthenticated RCE in SAMR RPC and print-command subsystems (CVSS 10.0)2026-05-29
- CVE-2026-32996 & CVE-2026-32997, Veeam Backup & Replication KB4852: LPE in Windows Agent, arbitrary file write in Linux appliance2026-05-29
- Apereo CAS version 7.3.7.1 patches an OIDC-provider flaw reported by Coop Switzerland; CERT-FR issues advisory CERTFR-2026-AVI-06542026-05-29
- ANSSI / CERT-FR publishes CERTFR-2026-AVI-0635 on SPIP < 4.4.15, security-policy bypass in the dominant French public-administration CMS2026-05-23
- CVE-2026-8043 Ivanti Xtraction external file control (CVSS 9.6) plus EPM SQL-injection-to-RCE and vTM admin OS-command injection, May 2026 advisory batch, no ITW2026-05-14
- CERTFR-2026-AVI-0572, Centreon Infra Monitoring: RCE / SQLi / XSS cluster (April 2026 bulletin)2026-05-13
- CERTFR-2026-AVI-0564, SPIP < 4.4.14: multiple RCEs (public and private area)2026-05-13
- GTIG AI Threat Tracker (May 2026): First Confirmed AI-Generated Zero-Day Exploit ITW and the Behavioural Class of AI-Augmented Malware2026-05-12
- CVE-2026-40982, Spring Cloud Config Server: pre-authentication path traversal, CVSS 9.8; all actively-maintained branches affected2026-05-09
- GLPI CERTFR-2026-AVI-0551, Seven CVEs including SSRF and XSS in EU ITSM platform (advisory 2026-04-29)2026-05-08
- CVE-2026-5787 / CVE-2026-6973, Ivanti EPMM pre-auth certificate impersonation → admin RCE (CISA KEV deadline 2026-05-10)2026-05-08
- CERT-FR CERTFR-2026-ACT-016: Agentic AI tools introduce prompt-injection and supply-chain attack surfaces2026-05-08