NCSC Switzerland, Cyber Security Hub (CSH) / GovCERT.ch
ncsc-ch-security-hub · A · active
https://security-hub.ncsc.admin.ch/#/dashboard
GovCERT.ch was MERGED INTO NCSC.ch in 2023; CSH replaces the legacy govcert.ch blog (frozen since 2023-09). The /govcert path on ncsc.admin.ch is a navigation page only. Substantive technical reports are now published on the CSH (TLP:CLEAR slice). The SPA at https://security-hub.ncsc.admin.ch/#/dashboard is JS-rendered (WebFetch returns only the 'CSH/Loading' shell). REQUIRED FETCH METHOD for both main agent AND every sub-agent: `python3 tools/fetch_source.py ncsc-csh recent 10` returns the listing + each post's full Markdown body in one call; `... ncsc-csh post <ID>` for one item. Cite the canonical SPA URL https://security-hub.ncsc.admin.ch/#/posts/{id}. Posts marked TLP:AMBER / TLP:RED MUST NEVER be fetched even if the API exposes them. (The legacy `govcert-ch` source ID was a duplicate of this entry and was removed 2026-05-08.) | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → api: python3 tools/fetch_source.py ncsc-csh recent 10 (returns listing + each TLP:CLEAR post's full Markdown body); python3 tools/fetch_source.py ncsc-csh post <ID> for one. Cite https://security-hub.ncsc.admin.ch/#/posts/{id}.. AVOID: WebFetch returns only the JS 'CSH/Loading' SPA shell, never WebFetch the dashboard. NEVER fetch TLP:AMBER/TLP:RED posts even if exposed.. | 2026-07-05 admiralty audit: A (HIGH->A) status active->active, GovCERT.ch/Swiss national CERT, home authority, current (03.07.2026) TLP:CLEAR advisories via API. Justified A: primary national CERT and the deployment's ground truth. | 2026-08-06 (run 2026-08-06T0411Z-intel): RECIPE FIXED. The unversioned /api/posts/** tree stopped serving GET, every path under it, including paths that never existed, returns HTTP 405 with `Allow: DELETE, PUT`, while unknown roots still 404 (an edge rule on the whole subtree, so probing sibling paths finds nothing). The public read API moved under /api/v1/: GET /api/v1/posts/dashboard?pageSize=N&pageIndex=0 and GET /api/v1/posts/{id}/details, both confirmed 200 with TLP:Clear content. tools/fetch_source.py ncsc-csh list|post|recent updated accordingly and re-tested. Route table is recoverable from the SPA bundle (main-*.js) if it moves again.
Cited in 66 entries
Citation cadence
Citation days per ISO week (20 weeks of coverage span, total 44).
- CVE-2026-81642 / CVE-2026-82717, NLnet Labs Unbound: a self-referencing DNSSEC compression pointer overflows the validator's digest buffer, reaching remote code execution (CVSS4.0 9.1 / 8.4)2026-09-19
- CVE-2026-85706, GitLab CE/EE: unauthenticated path traversal in the repository commits API reads arbitrary server files, and honeypots caught exploitation attempts one day after the patch (CVSS 10.0)2026-09-12
- BlueMoon: five separate state-nexus actor clusters independently weaponize a shared Chrome V8 + Windows kernel zero-day chain within one week2026-09-10
- CVE-2026-75650 ("StyleSmuggler"), Magento/Adobe Commerce: unauthenticated CVSS 10.0 RCE via template-engine injection, exploited three days before Adobe's hotfix existed2026-09-08
- CVE-2026-82329, JFrog Artifactory: an unauthenticated attacker gets administrative access under default configuration (CVSS 9.8)2026-09-01
- WatchGuard Fireware OS: two pre-auth RCEs in the iked IKE/VPN daemon plus a pre-auth stack overflow in the deprecated Mobile Security epm service2026-08-31
- Ubiquiti UniFi ecosystem: 22 CVEs in one bulletin, three at CVSS 10.0, unauthenticated CRLF-injection auth bypass, and unauthenticated command injection in UniFi Protect and UniFi Talk2026-08-28
- Oracle's August 2026 Critical Security Patch Update carries three unauthenticated CVSS 10.0 flaws, one of them in the LDAP server of Oracle Internet Directory2026-08-20
- CVE-2026-19478; GitLab ships an out-of-band critical patch for a GraphQL directive flaw that lets an unauthenticated caller modify or delete public projects and user data (CVSS 9.4)2026-08-19
- CVE-2026-15826, User Profile Builder: a 61-to-70-character username makes WordPress return an error object, absint() turns it into the integer 1, and the plugin logs the caller in as user ID 1 (CVSS 9.8)2026-08-19
- CVE-2026-15748, Forminator Forms (600,000+ WordPress sites): a forged Select-field value overrides the upload allow-list, and the root cause went public seventeen days after the patch (CVSS 9.8)2026-08-19
- GeoServer: an unauthenticated SQL injection in the jsonArrayContains filter is being exploited with no CVE and no patch, and NCSC-CH has put it in front of Swiss operators2026-08-15
- ShieldBreak, a public proof-of-concept defeats Microsoft's July fix for the RoguePlanet Defender flaw, claims 100% reliability where the original was a coin flip, and now covers Windows Server 20252026-08-12
- CVE-2026-58231, SAP Commerce Cloud: an unauthenticated request to the Data Hub Adapter import endpoint reaches arbitrary code execution (CVSS 10.0), and the fix needs a rebuild and redeploy2026-08-12
- CVE-2026-58048, cPanel & WHM: renaming a database drops the SQL mode that contains a tenant, handing any hosting customer database-root (CVSS 9.4)2026-08-06
- CVE-2026-28323, SolarWinds Web Help Desk: unauthenticated SAML 2.0 authentication bypass on a helpdesk portal (CVSS 9.8)2026-08-01
- CVE-2026-14512 / CVE-2026-14446, IBM WebSphere Application Server: two pre-auth CVSS 9.8 flaws with no workaround and no fix pack until 3Q2026 (interim APARs only)2026-08-01
- UK Department for Education confirms a breach of two public-facing portals and a police legal database, claimed by ExfilSquad, a five-day-old extortion brand whose other 14 claims look fabricated2026-07-31
- VMSA-2026-0006, VMware vCenter: unauthenticated Directory Service auth bypass and Syslog traversal RCE (both CVSS 9.8), plus a VMXNET3 guest-to-host escape2026-07-30
- SolarWinds Serv-U 2026.3, 15 critical IDOR flaws let authenticated users escalate to root RCE on the file-transfer server (CVSS 9.1)2026-07-23
- Zimbra Collaboration Suite 10.1.20, permanent fix for an SNMP command-injection RCE plus four stored-XSS bugs; NCSC-CH and BSI both flag the release2026-07-22
- Abacus ERP: unauthenticated RCE (CVSS 9.8, no CVE) and authenticated path traversal in a widely-deployed Swiss ERP platform, flagged by NCSC-CH2026-07-17
- SAP July 2026 Security Patch Day: three CVSS ≥9.1 flaws in NetWeaver AS ABAP, Approuter and Commerce Cloud, two reachable without authentication2026-07-14
- Microsoft July 2026 Patch Tuesday ships two actively-exploited zero-days, AD FS local EoP (CVE-2026-56155) and unauthenticated SharePoint EoP (CVE-2026-56164)2026-07-14
- CVE-2026-6875, ServiceNow AI Platform sandbox escape lets an unauthenticated request execute code on the platform (CVSS 9.5)2026-07-13
- Zimbra Classic Web Client: crafted-email code execution fixed in ZCS 10.1.19, surfaced by NCSC-CH (no CVE, exploitation unknown)2026-07-10
- CVE-2026-50656, Microsoft Defender engine 'RoguePlanet' local privilege escalation now patched; NCSC-CH tracks the ongoing 'Nightmare Eclipse' zero-day series2026-07-09
- CVE-2026-40138/-40139/-40140/-40141, BeyondTrust Remote Support / Privileged Remote Access: critical pre-auth bypass, flagged by NCSC-CH2026-07-08
- CVE-2026-8451, Citrix NetScaler ADC/Gateway: pre-auth SAML memory overread (CitrixBleed lineage), public PoC2026-07-01
- CVE-2026-20896, Gitea (Docker): trust-all reverse-proxy default lets an unauthenticated attacker impersonate any user via X-WEBAUTH-USER2026-06-23
- PTC Windchill CVE-2026-12569: unauthenticated Java deserialization to RCE on the PLM management plane2026-06-20
- CVE-2026-40624, AVer PTC-series conference cameras: unauthenticated RCE via the management web interface2026-06-20
- CVE-2026-0647 et al. Rockwell Automation FLEX I/O unauthenticated password reset (CVSS 9.4) and Logix CIP denial-of-service, flagged by NCSC-CH2026-06-18
- MariaDB CVE-2026-49261: Galera wsrep_notify_cmd shell injection (CVSS 10.0)2026-06-12
- "GreatXML": unpatched BitLocker bypass via crafted XML on the recovery partition, PoC public, practical severity contested2026-06-12
- CVE-2026-25089, Fortinet FortiSandbox: unauthenticated OS command injection in the web UI's VNC-launch handler (CVSS 9.8)2026-06-12
- ServiceNow unauthenticated REST endpoint queried customer instance tables before a silent 5 June patch2026-06-11
- "RoguePlanet" Microsoft Defender zero-day: TOCTOU race in the scan engine yields a SYSTEM shell, no CVE, no patch2026-06-11
- "Ghost-Sender": Exchange Online accepts spoofed inbound mail bypassing SPF/DKIM/DMARC when a third-party MX fronts the tenant, no vendor patch2026-06-10
- CVE-2026-44748, SAP June Patch Day: SAML XML Signature Wrapping in NetWeaver AS ABAP (CVSS 9.9) plus an unauth RFC kernel memory-corruption (CVSS 9.8)2026-06-10
- CVE-2026-50751, Check Point Security Gateway: IKEv1 VPN authentication bypass, actively exploited by a Qilin affiliate2026-06-09
- Check Point IKEv1 VPN Authentication Bypass (CVE-2026-50751)2026-06-09
- CVE-2026-20245, Cisco Catalyst SD-WAN Manager: actively-exploited command-injection to root (no patch)2026-06-06
- CVE-2026-0257, Palo Alto PAN-OS GlobalProtect: Pre-Auth Authentication Bypass via Certificate Reuse2026-05-30
- CVE-2026-9170, IBM HTTP Server / WebSphere Application Server: pre-auth RCE via improper input validation (CVSS 9.8)2026-05-29
- ILIAS LMS, nine fixes shipped 2026-05-27, two critical access-control gaps (CVSS 9.8 + 9.3), NCSC.ch flags SOAP interface as primary unauthenticated attack surface2026-05-28
- CVE-2026-48842, Roundcube Webmail pre-authentication SQL injection in virtuser_query plugin (CVSS 8.1)2026-05-28
- CVE-2026-20223, Cisco Secure Workload: CVSS 10.0 zero-auth REST API grants Site Admin privileges across all tenants, no workaround2026-05-22
- Prepare emergency Drupal patch window for today 17:00–21:00 UTC2026-05-20
- Drupal core "highly critical" pre-patch warning, unauthenticated, zero-complexity, patch window today 17:00–21:00 UTC2026-05-20
- CVE-2026-42945 NGINX Rift, in-the-wild exploitation confirmed by VulnCheck honeypots2026-05-18
- CVE-2026-42897 Exchange OWA, EM Service auto-mitigation depends on outbound connectivity to officemitigations.microsoft.com2026-05-18
- Microsoft Exchange CVE-2026-42897: Active Exploitation Without a Patch2026-05-16
- CVE-2026-42897, Microsoft Exchange Server 2016 / 2019 / SE: stored XSS in OWA, actively exploited, no permanent patch2026-05-16
- Windows BitLocker "YellowKey" and CTFMON "GreenPlasma" zero-days: public PoC, no patch, TPM-only BitLocker bypassed2026-05-15
- CVE-2026-42945, NGINX Open Source / Plus / F5 WAF products: 18-year-old heap buffer overflow in rewrite module ("NGINX Rift"), PoC public2026-05-15
- Mini Shai-Hulud's GitHub Actions Pwn-Request → OIDC Token Theft Chain2026-05-13
- CVE-2026-44277 / CVE-2026-26083, Fortinet FortiAuthenticator and FortiSandbox unauthenticated RCE2026-05-13
- CVE-2026-34263 / CVE-2026-34260, SAP Commerce Cloud pre-auth RCE, S/4HANA Enterprise Search SQL injection2026-05-13
- cPanel/WHM second emergency TSR in 10 days, embargo lifted on CVE-2026-29202 (post-auth Perl RCE, CVSS 8.8), CVE-2026-29203 (CVSS 8.8), CVE-2026-29201 (CVSS 4.3)2026-05-10
- + 6 earlier entries