Canadian Centre for Cyber Security, alerts and advisories feed
cccs-alerts · A · candidate
https://www.cyber.gc.ca/en/alerts-advisories
Added 2026-10-08: S1 candidate; the Atom feed reads directly (40 items) and carries one-vendor-per-item advisories with affected-version lists and an Update marker when a status changes. Its AV26-1002 Update 1 of 2026-10-07 is how the Atlassian exploitation claim surfaced, and AV26-1017 relayed the SonicWall advisory; both are cited in published entries. Per-item pages read with `extract`; some come back as raw HTML with the text inside.
Cited in 7 entries
Citation cadence
Citation days per ISO week (23 weeks of coverage span, total 7).
- CVE-2026-102255, SonicWall SMA1000: a third unauthenticated CVSS 10.0 Work Place SSRF this year, and it affects the hotfix builds that closed the September zero-days (no exploitation reported)2026-10-08
- CVE-2026-21589, Atlassian Data Center: unauthenticated arbitrary file access in every version of eight self-managed products, patch or take them off the internet (CVSS 4.0 9.3)2026-10-06
- OpenAI-attributed agents ran 16,500+ scans against a UN statistics API over two months, using public URL-scanner services as blind proxies and double-URL-encoding to bypass a GET/POST access restriction2026-09-28
- CVE-2026-65660, Microsoft SharePoint: a SafeControls parser-desync lets an authenticated attacker forge a second Register directive and reach RCE via in-memory XAML deserialization, now confirmed exploited (CVSS 8.8)2026-09-26
- FIFA World Cup 2026 pre-event threat cluster: Android banking trojans in pirated streaming apps, plus a 13,000-domain fraud layer, ahead of the 11 June kick-off2026-06-08
- CVE-2026-48842, Roundcube Webmail pre-authentication SQL injection in virtuser_query plugin (CVSS 8.1)2026-05-28
- CVE-2026-6973: Ivanti EPMM admin-authenticated RCE exploited in limited attacks, fixed with four further EPMM flaws including unauthenticated Sentry certificate issuance (CVE-2026-5787)2026-05-08