NCSC Switzerland — Cyber Security Hub (CSH) / GovCERT.ch
ncsc-ch-security-hub · A · active
https://security-hub.ncsc.admin.ch/#/dashboard
GovCERT.ch was MERGED INTO NCSC.ch in 2023; CSH replaces the legacy govcert.ch blog (frozen since 2023-09). The /govcert path on ncsc.admin.ch is a navigation page only. Substantive technical reports are now published on the CSH (TLP:CLEAR slice). The SPA at https://security-hub.ncsc.admin.ch/#/dashboard is JS-rendered (WebFetch returns only the 'CSH/Loading' shell). REQUIRED FETCH METHOD for both main agent AND every sub-agent: `python3 tools/fetch_source.py ncsc-csh recent 10` returns the listing + each post's full Markdown body in one call; `... ncsc-csh post <ID>` for one item. Cite the canonical SPA URL https://security-hub.ncsc.admin.ch/#/posts/{id}. Posts marked TLP:AMBER / TLP:RED MUST NEVER be fetched even if the API exposes them. (The legacy `govcert-ch` source ID was a duplicate of this entry and was removed 2026-05-08.) | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → api: python3 tools/fetch_source.py ncsc-csh recent 10 (returns listing + each TLP:CLEAR post's full Markdown body); python3 tools/fetch_source.py ncsc-csh post <ID> for one. Cite https://security-hub.ncsc.admin.ch/#/posts/{id}.. AVOID: WebFetch returns only the JS 'CSH/Loading' SPA shell — never WebFetch the dashboard. NEVER fetch TLP:AMBER/TLP:RED posts even if exposed.. | 2026-07-05 admiralty audit: A (HIGH->A) status active->active — GovCERT.ch/Swiss national CERT, home authority, current (03.07.2026) TLP:CLEAR advisories via API. Justified A: primary national CERT and the deployment's ground truth. | 2026-08-06 (run 2026-08-06T0411Z-intel): RECIPE FIXED. The unversioned /api/posts/** tree stopped serving GET — every path under it, including paths that never existed, returns HTTP 405 with `Allow: DELETE, PUT`, while unknown roots still 404 (an edge rule on the whole subtree, so probing sibling paths finds nothing). The public read API moved under /api/v1/: GET /api/v1/posts/dashboard?pageSize=N&pageIndex=0 and GET /api/v1/posts/{id}/details, both confirmed 200 with TLP:Clear content. tools/fetch_source.py ncsc-csh list|post|recent updated accordingly and re-tested. Route table is recoverable from the SPA bundle (main-*.js) if it moves again.
Cited in 80 entries
Citation cadence
Citation days per ISO week (14 weeks of coverage span, total 45).
- CVE-2026-58048 — cPanel & WHM: renaming a database drops the SQL mode that contains a tenant, handing any hosting customer database-root (CVSS 9.4)2026-08-06
- NCSC-CH advises its own constituency on the actively exploited Power Pages misconfiguration — anonymous web roles granted excessive Dataverse table permissions2026-08-05
- Two independently-operating Russian state clusters converged this week on the government user's mailbox and the government user's travel — and both leave persistence that a patch or a password reset does not remove2026-08-02
- CVE-2026-28323 — SolarWinds Web Help Desk: unauthenticated SAML 2.0 authentication bypass on a helpdesk portal (CVSS 9.8)2026-08-01
- CVE-2026-14512 / CVE-2026-14446 — IBM WebSphere Application Server: two pre-auth CVSS 9.8 flaws with no workaround and no fix pack until 3Q2026 (interim APARs only)2026-08-01
- CVE-2026-42897 — Exchange OWA stored XSS weaponised by TA488/LAUNDRY BEAR as a probable zero-day, delivering the browser-resident OWAReaper implant2026-07-31
- VMSA-2026-0006 — VMware vCenter: unauthenticated Directory Service auth bypass and Syslog traversal RCE (both CVSS 9.8), plus a VMXNET3 guest-to-host escape2026-07-30
- 2026-W30 vulnerability status roll-up — five CVEs crossed into confirmed exploitation/KEV, three more carry public exploit code, and a dense CVSS-9-to-10 tail hit edge, ERP, OT and file-transfer2026-07-26
- Internet-facing enterprise and admin software crossed into confirmed exploitation again this week — ServiceNow, SharePoint, Check Point management, Langflow and WordPress core all moved to under-attack, and several leave persistence the patch does not remove2026-07-26
- SolarWinds Serv-U 2026.3 — 15 critical IDOR flaws let authenticated users escalate to root RCE on the file-transfer server (CVSS 9.1)2026-07-23
- Zimbra Collaboration Suite 10.1.20 — permanent fix for an SNMP command-injection RCE plus four stored-XSS bugs; NCSC-CH and BSI both flag the release2026-07-22
- CVE-2026-6875 — ServiceNow AI Platform: pre-auth sandbox-escape RCE now under active exploitation (CVSS 9.5)2026-07-21
- Abacus ERP: unauthenticated RCE (CVSS 9.8, no CVE) and authenticated path traversal in a widely-deployed Swiss ERP platform — flagged by NCSC-CH2026-07-17
- SAP July 2026 Security Patch Day: three CVSS ≥9.1 flaws in NetWeaver AS ABAP, Approuter and Commerce Cloud — two reachable without authentication2026-07-14
- Vulnerability status roll-up — 2026-W28: what moved into exploitation, what reached KEV, and what to patch out-of-band2026-07-12
- Confirmed in-the-wild exploitation of internet-facing enterprise software converged this week — ColdFusion, Citrix NetScaler and Gitea all moved from 'at risk' to 'under attack'2026-07-12
- Zimbra Classic Web Client: crafted-email code execution fixed in ZCS 10.1.19, surfaced by NCSC-CH (no CVE, exploitation unknown)2026-07-10
- CVE-2026-20896 — NCSC-CH escalates the Gitea Docker reverse-proxy auth bypass to 'actively exploited'2026-07-10
- CVE-2026-50656 — Microsoft Defender engine 'RoguePlanet' local privilege escalation now patched; NCSC-CH tracks the ongoing 'Nightmare Eclipse' zero-day series2026-07-09
- CVE-2026-40138/-40139/-40140/-40141 — BeyondTrust Remote Support / Privileged Remote Access: critical pre-auth bypass, flagged by NCSC-CH2026-07-08
- CVE-2026-20245 — Cisco Catalyst SD-WAN Manager: Mandiant reconstructs the full zero-day chain2026-06-29
- Mandiant documents the full Cisco Catalyst SD-WAN exploitation chain — CSV-injection to a root backdoor2026-06-27
- CVE-2026-12569 — PTC Windchill / FlexPLM pre-auth deserialization RCE, exploited, BSI calling admins at 02:302026-06-22
- CVE-2026-0647 et al. — Rockwell Automation FLEX I/O unauthenticated password reset (9.4) and Logix CIP DoS, flagged by NCSC-CH2026-06-22
- CVE-2026-0257 — Palo Alto Networks PAN-OS GlobalProtect: authentication bypass under active exploitation2026-06-22
- PTC Windchill CVE-2026-12569: unauthenticated Java deserialization to RCE on the PLM management plane2026-06-20
- CVE-2026-40624 — AVer PTC-series conference cameras: unauthenticated RCE via the management web interface2026-06-20
- CVE-2026-0647 et al. — Rockwell Automation FLEX I/O unauthenticated password reset (CVSS 9.4) and Logix CIP denial-of-service, flagged by NCSC-CH2026-06-18
- PAN-OS GlobalProtect CVE-2026-0257 — exploitation wave with Impacket post-compromise, NCSC-CH refreshes advisory2026-06-17
- CVE-2026-49261 — MariaDB Galera cluster: pre-auth lateral RCE via wsrep_notify_cmd2026-06-14
- MariaDB CVE-2026-49261: Galera wsrep_notify_cmd shell injection (CVSS 10.0)2026-06-12
- "GreatXML": unpatched BitLocker bypass via crafted XML on the recovery partition — PoC public, practical severity contested2026-06-12
- CVE-2026-25089 — Fortinet FortiSandbox: unauthenticated OS command injection in the web UI's VNC-launch handler (CVSS 9.8)2026-06-12
- ServiceNow unauthenticated REST endpoint queried customer instance tables before a silent 5 June patch2026-06-11
- "RoguePlanet" Microsoft Defender zero-day: TOCTOU race in the scan engine yields a SYSTEM shell, no CVE, no patch2026-06-11
- "Ghost-Sender": Exchange Online accepts spoofed inbound mail bypassing SPF/DKIM/DMARC when a third-party MX fronts the tenant — no vendor patch2026-06-10
- CVE-2026-44748 — SAP June Patch Day: SAML XML Signature Wrapping in NetWeaver AS ABAP (CVSS 9.9) plus an unauth RFC kernel memory-corruption (CVSS 9.8)2026-06-10
- CVE-2026-50751 — Check Point Security Gateway: IKEv1 VPN authentication bypass, actively exploited by a Qilin affiliate2026-06-09
- Check Point IKEv1 VPN Authentication Bypass (CVE-2026-50751)2026-06-09
- CVE-2026-20245 — Cisco Catalyst SD-WAN Manager: actively-exploited command-injection to root (no patch)2026-06-06
- CVE-2026-49975 — HTTP/2 Bomb: HPACK amplification + Slowloris chains to single-connection RAM exhaustion, patch status split by server2026-06-01
- CVE-2026-20245 — Cisco Catalyst SD-WAN Manager: no-patch zero-day chain confirmed to push malicious configs to edge devices2026-06-01
- Ivanti Secure Access Client — NCSC.ch adds CVE-2026-8992 (local privilege escalation, CVSS 7.8) to May advisory2026-05-30
- CVE-2026-9170 — IBM HTTP Server / WebSphere Application Server: pre-auth RCE via improper input validation (CVSS 9.8)2026-05-29
- ILIAS LMS — nine fixes shipped 2026-05-27, two critical access-control gaps (CVSS 9.8 + 9.3), NCSC.ch flags SOAP interface as primary unauthenticated attack surface2026-05-28
- CVE-2026-48842 — Roundcube Webmail pre-authentication SQL injection in virtuser_query plugin (CVSS 8.1)2026-05-28
- Public administration & identity (CH / DACH lead) — the LMS, SSO and e-government estate under multi-product pressure2026-05-25
- CVE-2026-9170 — IBM HTTP Server / WebSphere Application Server: pre-auth RCE (CVSS 9.8)2026-05-25
- CVE-2026-48842 — Roundcube Webmail pre-authentication SQL injection2026-05-25
- Drupal CVE-2026-9082 — CISA KEV addition + active exploitation confirmed; NCSC.ch flips post 12584 to "Actively exploited"2026-05-23
- CVE-2026-20223 — Cisco Secure Workload: CVSS 10.0 zero-auth REST API grants Site Admin privileges across all tenants, no workaround2026-05-22
- Drupal SA-CORE-2026-004 / CVE-2026-9082 ships — "highly critical" pre-auth SQL injection in core database API, PostgreSQL-only2026-05-21
- Prepare emergency Drupal patch window for today 17:00–21:00 UTC2026-05-20
- Drupal core "highly critical" pre-patch warning — unauthenticated, zero-complexity, patch window today 17:00–21:00 UTC2026-05-20
- CVE-2026-42945 NGINX Rift — in-the-wild exploitation confirmed by VulnCheck honeypots2026-05-18
- Microsoft Exchange CVE-2026-42897: Active Exploitation Without a Patch2026-05-16
- CVE-2026-42897 — Microsoft Exchange Server 2016 / 2019 / SE: stored XSS in OWA, actively exploited, no permanent patch2026-05-16
- Windows BitLocker "YellowKey" and CTFMON "GreenPlasma" zero-days: public PoC, no patch, TPM-only BitLocker bypassed2026-05-15
- CVE-2026-42945 — NGINX Open Source / Plus / F5 WAF products: 18-year-old heap buffer overflow in rewrite module ("NGINX Rift"), PoC public2026-05-15
- Mini Shai-Hulud — TeamPCP worm hits TanStack, UiPath, Mistral AI, OpenSearch (160+ package versions)2026-05-13
- + 20 earlier entries