CERT-EU
cert-eu · A · active
https://cert.europa.eu/publications/security-advisories
Computer Emergency Response Team for EU institutions. URL CORRECTED 2026-05-08: /publications root is a navigation page only, sub-agents repeatedly returned a STUB. Drill into /publications/security-advisories/ (per-advisory entries with IDs like 2026-006) and /publications/threat-intelligence/ (monthly Cyber Briefs, e.g. cb26-05). Cite the per-advisory URL https://cert.europa.eu/publications/security-advisories/{YYYY-NNN}/ rather than the index. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → api: python3 tools/fetch_source.py cert-eu recent 5 (then webfetch per-advisory URL https://cert.europa.eu/publications/security-advisories/{YYYY-NNN}/ for body). AVOID: Do not cite /publications root; it is a navigation page. Use the per-advisory /security-advisories/{YYYY-NNN}/ URL.. | 2026-07-05 admiralty audit: A (primary-authority), EU governmental CERT publishing its own advisory series; live, api fetch clean. Status stays active. | 2026-08-23 audit: use the structured subcommand `python3 tools/fetch_source.py cert-eu recent N`, it returned 10 dated full-text advisories back to Jan 2026. The direct-URL bridge on /publications/security-advisories is the DEAD rung (JS-rendered listing, empty <main>). Also a content-type point that explains the long zero-contribution streak: CERT-EU's advisory series is exclusively vendor-vulnerability bulletins, so the incidents/regulator sweep will structurally never credit this source; it belongs to the vulnerability sweep.
Cited in 7 entries
Citation cadence
Citation days per ISO week (19 weeks of coverage span, total 6).
- SAP September 2026 Patch Day: OVERPASS (CVE-2026-44756, CVSS 10.0) and S4GET (CVE-2026-58240, CVSS 9.8), two unauthenticated pre-auth RCE flaws in shared SAP kernel components reachable through ports that cannot be firewalled without breaking normal SAP GUI/RFC use2026-09-10
- CVE-2026-19490, Citrix NetScaler: an authentication bypass on Gateway and AAA virtual servers (CVSS 9.3), and on older builds no SAML configuration is needed to be exposed2026-08-20
- The '2,500-organisation LiteLLM breach' was mostly not LiteLLM: 95% of the identified victims were collected before the poisoned packages existed, through the Trivy scanner their pipelines pulled unpinned2026-08-15
- Windows Netlogon RCE CVE-2026-41089 now confirmed exploited in the wild in the EU; CERT-EU issues advisory 2026-0072026-06-11
- CVE-2026-5027, Langflow: unauthenticated path traversal to arbitrary file write, exploited in the wild2026-06-11
- CVE-2026-10520 / CVE-2026-10523, Ivanti Sentry: pre-auth OS command injection to root (CVSS 10.0), public PoC published today2026-06-10
- CVE-2026-31431 "Copy Fail", CISA KEV deadline 2026-05-15 approaching; Microsoft documents Linux LPE cluster post-compromise chain2026-05-09