CERT Polska / NASK
cert-pl · A · active
Polish CERT, strong on Russia-adjacent threats and OT incidents. 2026-05-08 audit: WebFetch returned 5 dated posts incl. 'Annual report 2025' 2026-04-08. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → webfetch https://cert.pl/en/news/ (listing) then webfetch the per-post cert.pl/en/posts/... URL for body. AVOID: No issues, WebFetch returns clean dated listing and substantive detail pages. No bridge needed.. | 2026-07-05 admiralty audit: A (primary-authority), Polish national CERT (NASK), original first-hand research; live, WebFetch clean. Status stays active. | 2026-08-04 run: RECIPE FIX; the tracked /en/news/ path does NOT list CERT-PL coordinated-disclosure CVE advisories (newest /news/ item was 2026-06-12 while the 2026-07-27 cJSON advisory existed). Advisories live at https://cert.pl/en/posts/<YYYY>/<MM>/<CVE-ID>/ and the per-advisory page carries a "Publication date" TABLE ROW (an HTML-tag strip collapses it, read the raw body around the label). FETCH → drill /en/posts/ per advisory; an essential-tier source was effectively dark for advisory discovery through /news/ alone. | 2026-08-05: RECIPE DRIFT, https://cert.pl/en/posts/ now returns HTTP 403 to WebFetch, the bridge AND the reader, so the per-advisory drill path recorded above is currently blocked. https://cert.pl/en/news/ still returns HTTP 200 via the bridge, so the source is alive and /news/ is the working discovery surface again. Do NOT demote on the 403 (transport block, not death); re-probe /en/posts/ each run and restore the drill recipe when it clears. | 2026-08-05: RSS RECIPE, with both HTML listings unusable this run (/en/posts/ 403, /en/news/ no drillable dated rows), the feeds https://cert.pl/en/rss.xml (English) and https://cert.pl/rss.xml (Polish) both return HTTP 200 with dated advisory items linking to /en/posts/<YYYY>/<MM>/<CVE-ID>/. Prefer the feed for discovery.
Cited in 14 entries
Citation cadence
Citation days per ISO week (17 weeks of coverage span, total 11).
- CVE-2026-67276 / CVE-2026-86060, MikroTik RouterOS "MikroTrick": a forged-signature SSH authentication bypass chained with a crafted-username privilege escalation reaches unauthenticated full device takeover, actively exploited2026-09-06
- Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, administrators included2026-08-21
- CERT Polska: a second Polish CHP plant was shut down on 29 December 2025 through the distribution operator's private APN, the first real-world use of that path into an OT network2026-08-09
- FSB Centre 16 (Static Tundra) router-hijacking campaign: 19-agency joint advisory, formal Poland energy-grid attribution and first joint EU/UK cyber sanctions2026-07-13
- CERT Polska: UNC1151/Ghostwriter shifts to Gmail with real-time 2FA-relay phishing against officials and public administration2026-07-09
- CERT Polska discloses a JAR parser-confusion RCE in the SzafirHost e-signature client (CVE-2026-13165)2026-06-30
- CVE-2026-34906 / CVE-2026-34907, Simple SA "Wirtualna Uczelnia": unauthenticated SSTI-to-RCE in the student-administration platform used across Polish public universities2026-06-05
- CVE-2026-35087 / CVE-2026-35089 / CVE-2026-35090, Slican PBX telephony exchanges, triple pre-authentication admin bypass (CERT Polska)2026-05-28
- CVE-2026-9058, Szafir SDK (KIR): signature-verification routine reports success on an untrusted certificate chain, enabling auth bypass in Polish e-government2026-05-26
- CVE-2026-5426, Digital Knowledge KnowledgeDeliver LMS: pre-shared ASP.NET machineKey enables ViewState deserialization RCE, exploited as a zero-day2026-05-26
- vm2 Node.js sandbox, 12 critical CVEs (CVE-2026-43997 / 43999 / 44005 / 44006 / 44008 / 44009 et al.), sandbox escape to host RCE, upgrade to ≥ 3.11.42026-05-20
- Sparx Enterprise Architect / Pro Cloud Server, five-CVE chain (pre-auth SQL injection + WebEA race-condition RCE), public PoC, no vendor patch2026-05-20
- CVE-2026-41553, DHTMLX PDF Export Module: unauthenticated server-side JavaScript injection RCE (CVSS 4.0 score 10.0), with CVE-2026-41552 and CVE-2026-7182 path-traversal companions2026-05-17
- CERT-PL CVE-2026-44088, SzafirHost JAR zip-polyglot bypass in Poland's qualified e-signature browser helper2026-05-17