<?xml version="1.0" encoding="UTF-8"?><feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en"><id>https://cyber.gc.ca/api/cccs/atom/v1/get?feed=alerts_advisories&amp;lang=en</id><link rel="self" href="https://cyber.gc.ca/api/cccs/atom/v1/get?feed=alerts_advisories&amp;lang=en"/><title>Alerts and advisories</title><updated>2026-06-09T19:28:10Z</updated><entry><id>https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-551</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-551"/><title><![CDATA[Cisco security advisory (AV26-551) - Update 1]]></title><updated>2026-06-09T19:28:10Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7790" about="/en/alerts-advisories/cisco-security-advisory-av26-551" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-551<br /><strong>Date: </strong>June 5, 2026<br /><strong>Updated:</strong> June 9, 2026</p>

<p>On June 4, 2026, Cisco published a security advisory to address a vulnerability in the following product:</p>

<ul><li>Cisco Catalyst SD-WAN Manager</li>
</ul><h2 class="h3">Update 1</h2>

<p>On June 9, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20245 to their Known Exploited Vulnerabilities (KEV) Database.</p>

<p class="mrgn-bttm-md">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates, when available.</p>

<ul class="list-unstyled"><li><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx">Cisco Catalyst SD-WAN Manager Authenticated Privilege Escalation Vulnerability (CVE-2026-20245)</a></li>
	<li><a href="https://tools.cisco.com/security/center/publicationListing.x">Cisco Security Advisories</a></li>
	<li><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20245">CISA KEV: CVE-2026-20245</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/hpe-security-advisory-av26-571</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/hpe-security-advisory-av26-571"/><title><![CDATA[HPE security advisory (AV26-571)]]></title><updated>2026-06-09T19:03:41Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7818" about="/en/alerts-advisories/hpe-security-advisory-av26-571" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-571<br /><strong>Date: </strong>June 9, 2026</p>

<p>On June 9, 2026, HPE published a security advisory to address vulnerabilities in the following products:</p>

<ul><li>HPE Aruba Networking Management Software (Airwave) – version 8.3.0.6 and prior</li>
	<li>HPE Aruba Networking Private 5G Management Dashboard – all versions</li>
</ul><p class="mrgn-bttm-md">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05064en_us&amp;docLocale=en_US#hpesbnw05064-rev-1-status-of-nginx-ngx_http_rewrit-0">HPESBNW05064 rev.1 - Status of NGINX ngx_http_rewrite_module Vulnerability (CVE-2026-42945) in HPE Aruba Networking Products</a></li>
	<li><a href="https://support.hpe.com/connect/s/securitybulletinlibrary?language=en_US">HPE Security Bulletin Library</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/adobe-security-advisory-av26-570</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/adobe-security-advisory-av26-570"/><title><![CDATA[Adobe security advisory (AV26-570)]]></title><updated>2026-06-09T18:59:15Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7817" about="/en/alerts-advisories/adobe-security-advisory-av26-570" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-570<br /><strong>Date: </strong>June 9, 2026</p>

<p>On June 9, 2026, Adobe published security advisories to address critical vulnerabilities in the following products:</p>

<ul><li>Adobe Experience Manager (AEM) – version AEM Cloud Service (CS)</li>
	<li>Adobe Experience Manager (AEM) – version 6.5 LTS SP1 and prior</li>
	<li>Adobe Experience Manager (AEM) – version SP24 and prior</li>
	<li>Adobe Experience Manager 6.5 LTS – version SP1 and prior</li>
	<li>Adobe Experience Manager 6.5 – version 6.5.24.0 and prior</li>
	<li>Adobe InDesign – version ID21.3 and prior</li>
	<li>Adobe InDesign – version ID20.5.3 and prior</li>
	<li>Adobe InCopy – version 21.3 and prior</li>
	<li>Adobe InCopy – version 20.5.3 and prior</li>
	<li>Adobe Substance 3D Sampler – version 6.0.0 and prior</li>
	<li>Content Credentials JS SDK – version @contentauth/c2pa-web@0.8.3 and prior</li>
	<li>Content Credentials Rust SDK – version c2pa-v0.85.1 and prior</li>
	<li>Adobe Dreamweaver – version 21.7 and prior</li>
	<li>Adobe Acrobat – version 26.001.21651 and prior</li>
	<li>Adobe Reader – version 26.001.21651 and prior</li>
	<li>Adobe 2024 – version 24.001.30365 and prior</li>
	<li>Adobe ColdFusion 2025 – Update 8 and prior</li>
	<li>Adobe ColdFusion 2023 – Update 19 and prior</li>
	<li>Adobe Format Plugins – version 1.1.52 and prior</li>
	<li>Adobe Campaign Classic – version ACC v7: 7.4.3 build 9394 and prior</li>
</ul><p class="mrgn-bttm-md">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://helpx.adobe.com/security.html">Adobe Security Advisories</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/microsoft-security-advisory-june-2026-monthly-rollup-av26-569</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/microsoft-security-advisory-june-2026-monthly-rollup-av26-569"/><title><![CDATA[Microsoft security advisory – June 2026 monthly rollup (AV26-569)]]></title><updated>2026-06-09T18:53:14Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7816" about="/en/alerts-advisories/microsoft-security-advisory-june-2026-monthly-rollup-av26-569" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-569<br /><strong>Date: </strong>June 9, 2026</p>

<p>On June 9, 2026, Microsoft published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:</p>

<ul><li>.NET 10.0</li>
	<li>.NET 8.0</li>
	<li>.NET 9.0</li>
	<li>ASP.NET</li>
	<li>Azure Connected Machine Agent</li>
	<li>Azure HorizonDB</li>
	<li>Azure Kubernetes Service</li>
	<li>Azure Local</li>
	<li>Azure Logic Apps</li>
	<li>Azure Machine Learning</li>
	<li>Azure Monitor Agent</li>
	<li>Azure Monitor Agent Metrics Extension</li>
	<li>Azure Orbital Spatio</li>
	<li>Azure Privileged Identity Management (PIM)</li>
	<li>Azure Resource Manager</li>
	<li>Azure SDK</li>
	<li>Azure Stack Edge</li>
	<li>Azure Stack HCI</li>
	<li>Azure Virtual Network Gateway</li>
	<li>Copilot Chat</li>
	<li>Linux kernel - Microsoft MANA Network Driver</li>
	<li>M365 Copilot for Desktop</li>
	<li>Microsoft .NET Framework</li>
	<li>Microsoft 365</li>
	<li>Microsoft 365 Copilot</li>
	<li>Microsoft Authenticator</li>
	<li>Microsoft Bing</li>
	<li>Microsoft Confluence SAML SSO plugin</li>
	<li>Microsoft Data Formulator</li>
	<li>Microsoft Defender for Endpoint for Mac</li>
	<li>Microsoft Dynamics 365</li>
	<li>Microsoft Edge</li>
	<li>Microsoft Entra ID</li>
	<li>Microsoft Excel</li>
	<li>Microsoft Excel 2016</li>
	<li>Microsoft Exchange Online</li>
	<li>Microsoft Exchange Server</li>
	<li>Microsoft Global Secure Access (GSA)</li>
	<li>Microsoft Graph</li>
	<li>Microsoft JIRA SAML SSO plugin</li>
	<li>Microsoft Live Share Canvas SDK</li>
	<li>Microsoft Malware Protection Engine</li>
	<li>Microsoft Office</li>
	<li>Microsoft Office 2016</li>
	<li>Microsoft Office 2019</li>
	<li>Microsoft Office 365</li>
	<li>Microsoft Office LTSC</li>
	<li>Microsoft Outlook for iOS</li>
	<li>Microsoft PC Manager</li>
	<li>Microsoft Planetary Computer Pro (GeoCatalog)</li>
	<li>Microsoft Power Pages</li>
	<li>Microsoft PowerPoint for Android</li>
	<li>Microsoft PowerToys</li>
	<li>Microsoft SQL Server 2016</li>
	<li>Microsoft SQL Server 2017</li>
	<li>Microsoft SQL Server 2019</li>
	<li>Microsoft SQL Server 2022</li>
	<li>Microsoft SQL Server 2025</li>
	<li>Microsoft SharePoint Enterprise Server 2016</li>
	<li>Microsoft SharePoint Server 2019</li>
	<li>Microsoft Teams</li>
	<li>Microsoft Visual Studio</li>
	<li>Microsoft Visual Studio 2026</li>
	<li>Microsoft Word</li>
	<li>Microsoft Word 2016</li>
	<li>Nuance PowerScribe 360</li>
	<li>Nuance PowerScribe One</li>
	<li>Office Online Server</li>
	<li>Power Automate for Desktop</li>
	<li>PowerScribe One</li>
	<li>Remote Desktop client</li>
	<li>Visual Studio</li>
	<li>Visual Studio Code</li>
	<li>Windows 10</li>
	<li>Windows 11</li>
	<li>Windows Admin Center</li>
	<li>Windows Admin Center in Azure Portal</li>
	<li>Windows App Client</li>
	<li>Windows Narrator Braille</li>
	<li>Windows Server 2012</li>
	<li>Windows Server 2016</li>
	<li>Windows Server 2019</li>
	<li>Windows Server 2022</li>
	<li>Windows Server 2025</li>
</ul><p class="mrgn-bttm-md">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://msrc.microsoft.com/update-guide/releaseNote/2026-Jun ">June 2026 Security Updates</a></li>
</ul><p>&lt;</p>
</div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/google-chrome-security-advisory-av26-561</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/google-chrome-security-advisory-av26-561"/><title><![CDATA[Google Chrome security advisory (AV26-561) – Update 1]]></title><updated>2026-06-09T17:51:05Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7801" about="/en/alerts-advisories/google-chrome-security-advisory-av26-561" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-561<br /><strong>Date:</strong> June 9, 2026</p>

<p>On June 8, 2026, Google published a security advisory to address vulnerabilities in the following product:</p>

<ul><li>Stable Channel Chrome for Desktop – versions prior to 149.0.7827.102/.103 (Windows/Mac), and 149.0.7827.102 (Linux)</li>
</ul><p>Google is aware that an exploit for CVE-2026-11645 exists in the wild.</p>

<h2 class="h4">Update 1</h2>

<p>On June 9, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-11645 to their Known Exploited Vulnerabilities (KEV) Database.</p>

<p class="mrgn-bttm-md">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates, when available.</p>

<ul class="list-unstyled"><li><a href="https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0153744567.html">Google Chrome Security Advisory</a></li>
	<li><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-11645 ">CISA KEV: CVE-2026-11645</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/fortinet-security-advisory-av26-568</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/fortinet-security-advisory-av26-568"/><title><![CDATA[Fortinet security advisory (AV26-568)]]></title><updated>2026-06-09T15:35:07Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7809" about="/en/alerts-advisories/fortinet-security-advisory-av26-568" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-568<br /><strong>Date: </strong>June 9, 2026</p>

<p>On June 9, 2026, Fortinet published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:</p>

<ul><li>FortiSandbox 5.0 – versions 5.0.0 to 5.0.5</li>
	<li>FortiSandbox 4.4 – versions 4.4.0 to 4.4.8</li>
	<li>FortiSandbox Cloud 5.0 – versions 5.0.4 to 5.0.5</li>
	<li>FortiSandbox PaaS 5.0 – versions 5.0.4 through 5.0.5</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://fortiguard.fortinet.com/psirt/FG-IR-26-141">Second-Order OS Command Injection via JSON Input on start vnc feature</a></li>
	<li><a href="https://www.fortiguard.com/psirt?filter=1&amp;version=&amp;severity=5&amp;severity=4&amp;severity=3&amp;severity=2">Fortinet PSIRT Advisories</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/ivanti-security-advisory-av26-567</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/ivanti-security-advisory-av26-567"/><title><![CDATA[Ivanti security advisory (AV26-567)]]></title><updated>2026-06-09T15:30:20Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7807" about="/en/alerts-advisories/ivanti-security-advisory-av26-567" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-567<br /><strong>Date: </strong>June 9, 2026</p>

<p>On June 9, 2026, Ivanti published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:</p>

<ul><li>Ivanti Sentry – versions 10.5.1, 10.6.1, 10.7.0 and prior</li>
	<li>Ivanti Endpoint Manager Mobile – versions 12.9.0, 12.8.0.2, 12.7.0.1 and prior</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US">Security Advisory Ivanti Sentry (CVE-2026-10520, CVE-2026-10523)</a></li>
	<li><a href="https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-6973-CVE-2026-10727?language=en_US">Security Advisory Ivanti Endpoint Manager Mobile (EPMM) (CVE-2026-6973 and CVE-2026-10727)</a></li>
	<li><a href="https://forums.ivanti.com/s/searchallcontent?language=en_US#tab=All&amp;sortCriteria=date%20descending&amp;f-sfkbknowledgearticletypec=Security%20Advisory">Ivanti Security Advisories</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/control-systems-siemens-security-advisory-av26-566</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/control-systems-siemens-security-advisory-av26-566"/><title><![CDATA[[Control systems] Siemens security advisory (AV26-566)]]></title><updated>2026-06-09T14:18:59Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7806" about="/en/alerts-advisories/control-systems-siemens-security-advisory-av26-566" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-566<br /><strong>Date:</strong> June 9, 2026</p>

<p>On June 9, 2026, Siemens published a security advisory to address vulnerabilities in the following products. Included were updates for the following products:</p>

<ul><li>SINEC INS – versions prior to V1.0 SP2 Update 6</li>
	<li>Siemens Products – multiple versions and models</li>
	<li>SIPROTEC 5 - CP100 / CP150 / CP200 / CP300 / Devices – all versions</li>
	<li>SIPROTEC 5 Compact 7SX800 (CP050) – all versions</li>
	<li>Totally Integrated Automation Portal (TIA Portal) – all versions</li>
</ul><p>The Cyber Centre encourages users and administrators to review the web links provided, perform the suggested mitigations and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://cert-portal.siemens.com/productcert/html/ssa-860189.html">SSA-860189: Multiple Vulnerabilities in SINEC INS Before V1.0 SP2 Update 6</a></li>
	<li><a href="https://cert-portal.siemens.com/productcert/html/ssa-434797.html">SSA-434797: Buffer Overflow Vulnerability in OpenSSL affecting Siemens Products</a></li>
	<li><a href="https://cert-portal.siemens.com/productcert/html/ssa-139483.html">SSA-139483: File Upload Vulnerability in SIPROTEC 5 Using DIGSI5 Protocol</a></li>
	<li><a href="https://cert-portal.siemens.com/productcert/html/ssa-063511.html">SSA-063511: Insufficient protection of key material in WinCC Certificate Manager</a></li>
	<li><a href="https://www.siemens.com/global/en/products/services/cert.html#SecurityPublications">Siemens Security Advisories</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/misp-security-advisory-av26-565</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/misp-security-advisory-av26-565"/><title><![CDATA[MISP security advisory (AV26-565)]]></title><updated>2026-06-09T13:03:17Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7805" about="/en/alerts-advisories/misp-security-advisory-av26-565" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-565<br /><strong>Date: </strong>June 9, 2026</p>

<p>On June 4, 2026, MISP published a security advisory to address vulnerabilities in the following product:</p>

<ul><li>MISP (Malware Information Sharing Platform) – versions prior to v2.5.39</li>
</ul><p class="mrgn-bttm-md">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://github.com/MISP/MISP/commit/1be8c413b7104a889dfd30c5b1986e3ab17238e8">MISP</a></li>
	<li><a href="https://github.com/MISP/MISP/releases/tag/v2.5.39">MISP 2.5.39: New Dashboard Experience, Stronger STIX, Sharper Analyst Workflows</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/veeam-security-advisory-av26-564</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/veeam-security-advisory-av26-564"/><title><![CDATA[Veeam security advisory (AV26-564)]]></title><updated>2026-06-09T12:59:00Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7804" about="/en/alerts-advisories/veeam-security-advisory-av26-564" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-564<br /><strong>Date: </strong>June 9, 2026</p>

<p>On June 9, 2026, Veeam published a security advisor to address a critical vulnerability in the following product:</p>

<ul><li>Veeam Backup and Replication – versions prior to 12.3.2.4854</li>
</ul><p class="mrgn-bttm-md">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://www.veeam.com/kb4869">Vulnerability Resolved in Veeam Backup and Replication 12.3.2.4854</a></li>
	<li><a href="https://www.veeam.com/knowledge-base.html">Veeam Knowledge Base</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/apache-security-advisory-av26-563</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/apache-security-advisory-av26-563"/><title><![CDATA[Apache security advisory (AV26-563)]]></title><updated>2026-06-09T12:54:52Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7803" about="/en/alerts-advisories/apache-security-advisory-av26-563" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-563<br /><strong>Date: </strong>June 9, 2026</p>

<p>On June 8, 2026, Apache published a security advisory to address vulnerabilities in the following product:</p>

<ul><li>Apache HTTP Server – versions prior to 2.4.68</li>
</ul><p class="mrgn-bttm-md">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://httpd.apache.org/security/vulnerabilities_24.html">Apache HTTP Server 2.4 vulnerabilities</a></li>
	<li><a href="https://httpd.apache.org/">Apache http Server Project</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/sap-security-advisory-june-2026-monthly-rollup-av26-562</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/sap-security-advisory-june-2026-monthly-rollup-av26-562"/><title><![CDATA[SAP security advisory – June 2026 monthly rollup (AV26-562)]]></title><updated>2026-06-09T12:49:53Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7802" about="/en/alerts-advisories/sap-security-advisory-june-2026-monthly-rollup-av26-562" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-562<br /><strong>Date:</strong> June 9, 2026</p>

<p>On June 9, 2026, SAP published security advisories to address vulnerabilities in the following products:</p>

<ul><li>SAP NetWeaver AS ABAP and ABAP Platform – versions SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 816, SAP_BASIS 918, SAP_BASIS 919</li>
	<li>SAP NetWeaver AS ABAP and ABAP Platform – versions KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 722EXT, 7.53, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 9.16, 9.18, 91.9</li>
	<li>SAP Commerce Cloud and SAP Data Hub – versions HY_COM 2205, HY_DHUB 2205, COM_CLOUD 2211, 2211-JDK21, DHUB_CLOUD 2211</li>
	<li>SAP NetWeaver Application Server Java (Web Container) – version ENGINEAPI 7.50</li>
	<li>SAP Commerce Cloud – versions HY_COM 2205, COM_CLOUD 2211, 2211-JDK21</li>
	<li>SAP NetWeaver AS ABAP and ABAP Platform – versions SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 816</li>
	<li>ODP Data Replication APIs – versions DW4CORE 200, 300, 400, PI_BASIS 2006_1_700, 701, 702, 731, 740, SAP_BW 750, 816</li>
	<li>SAP S/4HANA – versions S4FND 102, 103, 104, 105, 106, 107, 108, 109</li>
	<li>SAP NetWeaver AS Java (JDBC Test Servlet) – version BI_UDI 7.50</li>
	<li>SAP Wily Introscope Enterprise Manager – version WILY_INTRO_ENTERPRISE 10.8</li>
	<li>SAP MDG (Review Match Groups Application) – versions S4CORE 108, SAP_BASIS 916, SAP_BASIS 917, SAP_ABA 816</li>
	<li>SAP Business Objects Business Intelligence Platform – versions ENTERPRISE 430, 2025, 2027</li>
	<li>SAP Fiori (launchpad) – versions SAP_UI 754, 755, 756, 757, 758, 816</li>
	<li>SAP Business Objects – versions ENTERPRISE 430, 2025, 2027</li>
	<li>SAP NetWeaver AS Java – versions SERVERCORE 7.50, CORE-TOOLS 7.50, J2EE-APPS 7.50</li>
</ul><p class="mrgn-bttm-md">The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations, and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news/june-2026.html">SAP Security Patch Day - June 2026</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/check-point-security-advisory-av26-559</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/check-point-security-advisory-av26-559"/><title><![CDATA[Check Point security advisory (AV26-559) - Update 1]]></title><updated>2026-06-09T12:06:36Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7798" about="/en/alerts-advisories/check-point-security-advisory-av26-559" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number:</strong> AV26-559<br /><strong>Date:</strong> June 8, 2026<br /><strong>Updated:</strong> June 9, 2026</p>

<p>On June 8, 2026, Check Point published a security advisory to address a critical vulnerability in the following products:</p>

<ul><li>Mobile Access / SSL VPN, Remote Access VPN, Spark Firewall – multiple versions</li>
	<li>Security Gateways, Spark Firewall – multiple versions</li>
</ul><p>Check Point has observed active exploitation of this vulnerability.</p>

<h2 class="h4">Update 1</h2>

<p>On June 8, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-50751 to their Known Exploited Vulnerabilities (KEV) Database.</p>

<p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.</p>

<ul class="list-unstyled"><li><a href="https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/">Security Advisory – Action Required – Active Exploitation of Check Point VPN Authentication Bypass (CVE-2026-50751)</a></li>
	<li><a href="https://blog.checkpoint.com/security/">Check Point Security</a></li>
	<li><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-50751">CISA KEV: CVE-2026-50751</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/broadcom-vmware-security-advisory-av26-560</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/broadcom-vmware-security-advisory-av26-560"/><title><![CDATA[Broadcom VMware security advisory (AV26-560)]]></title><updated>2026-06-08T17:24:16Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7799" about="/en/alerts-advisories/broadcom-vmware-security-advisory-av26-560" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-560<br /><strong>Date: </strong>June 8, 2026</p>

<p>On June 8, 2026, Broadcom published a security advisory to address vulnerabilities in the following products:</p>

<ul><li>VMware Cloud Foundation – versions prior to 9.1.0.0</li>
	<li>VMware vSphere Foundation – versions prior to 9.1.0.0</li>
	<li>VMware Cloud Foundation – versions prior to 9.0.2.0 EP2</li>
	<li>VMware vSphere Foundation – versions prior to 9.0.2.0 EP2</li>
	<li>VMware Aria Operations – versions prior to 8.18.7</li>
	<li>VMware Aria Operations – versions prior to 8.18.6</li>
	<li>VMware Cloud Foundation – versions prior to 5.x</li>
	<li>VMware Telco Cloud Platform – versions prior to 5.x</li>
</ul><p>The Cyber Centre encourages users and administrators to review the web links provided and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37513">VMSA-2026-0004: VMware Cloud Foundation Operations updates address multiple vulnerabilities (CVE-2026-41722, CVE-2026-41723 and CVE-2026-41724)</a></li>
	<li><a href="https://support.broadcom.com/web/ecx/security-advisory?segment=VC">Security Advisories - VMware Cloud Foundation</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/spring-security-advisory-av26-558</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/spring-security-advisory-av26-558"/><title><![CDATA[Spring security advisory (AV26-558)]]></title><updated>2026-06-08T14:18:37Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7797" about="/en/alerts-advisories/spring-security-advisory-av26-558" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-558<br /><strong>Date: </strong>June 9, 2026</p>

<p>On June 8, 2026, Spring published security advisories to address vulnerabilities in the following products:</p>

<ul><li>Micrometer / Micrometer-core / jetty11 / jetty12 – multiple versions</li>
	<li>Spring LDAP – multiple versions</li>
	<li>Spring Framework – multiple versions</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://spring.io/security/cve-2026-40984">CVE-2026-40984: Micrometer HTTP server instrumentations DoS vulnerability</a></li>
	<li><a href="https://spring.io/security/cve-2026-40983">CVE-2026-40983: Micrometer gRPC server instrumentation DoS vulnerability</a></li>
	<li><a href="https://spring.io/security/cve-2026-41720">CVE-2026-41720: Authentication Bypass with Empty Password in Spring LDAP</a></li>
	<li><a href="https://spring.io/security/cve-2026-41842">CVE-2026-41842: Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux</a></li>
	<li><a href="https://spring.io/security">Spring Security Advisories</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/red-hat-security-advisory-av26-557</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/red-hat-security-advisory-av26-557"/><title><![CDATA[Red Hat security advisory (AV26-557)]]></title><updated>2026-06-08T14:12:47Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7796" about="/en/alerts-advisories/red-hat-security-advisory-av26-557" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number:</strong> AV26-557<br /><strong>Date:</strong> June 8, 2026</p>

<p>Between June 1 and 7, 2026, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:</p>

<ul><li>Red Hat CodeReady Linux Builder – multiple versions and platforms</li>
	<li>Red Hat Enterprise Linux – multiple versions and platforms</li>
	<li>Red Hat Enterprise Linux Server – multiple versions and platforms</li>
	<li>Red Hat Enterprise Linux for Real Time – multiple versions and platforms</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a class="external-link" href="https://access.redhat.com/security/security-updates/security-advisories" rel="nofollow noopener" target="_blank">Red Hat Security Advisories</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/control-systems-cisa-ics-security-advisories-av26-556</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/control-systems-cisa-ics-security-advisories-av26-556"/><title><![CDATA[[Control systems] CISA ICS security advisories (AV26–556)]]></title><updated>2026-06-08T14:06:51Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7795" about="/en/alerts-advisories/control-systems-cisa-ics-security-advisories-av26-556" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26–556<br /><strong>Date: </strong>June 8, 2026</p>

<p>Between June 1 and 7, 2026, CISA published ICS advisories to address vulnerabilities in the following products:</p>

<ul><li>B&amp;R Industrial Automation GmbH PPT30 Operating System – versions prior to 1.8.0</li>
	<li>Hitachi Energy ITT600 Explorer – version prior to 2.1 SP6</li>
	<li>Hitachi Energy MACH HiDraw – version 9.22 and prior</li>
	<li>Hitachi Energy RTU500 – multiple versions</li>
	<li>NAVTOR NavBox – version 4.16.1.20</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.</p>

<ul class="list-unstyled"><li><a href="https://www.cisa.gov/news-events/ics-advisories">CISA ICS Advisories</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/ubuntu-security-advisory-av26-555</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/ubuntu-security-advisory-av26-555"/><title><![CDATA[Ubuntu security advisory (AV26-555)]]></title><updated>2026-06-08T14:01:50Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7794" about="/en/alerts-advisories/ubuntu-security-advisory-av26-555" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-555<br /><strong>Date:</strong> June 8, 2026</p>

<p>Between June 1 and 7, 2026, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:</p>

<ul><li>Ubuntu 14.04 LTS</li>
	<li>Ubuntu 16.04 LTS</li>
	<li>Ubuntu 18.04 LTS</li>
	<li>Ubuntu 20.04 LTS</li>
	<li>Ubuntu 22.04 LTS</li>
	<li>Ubuntu 24.04 LTS</li>
	<li>Ubuntu 25.10</li>
	<li>Ubuntu 26.04 LTS</li>
</ul><p>The Cyber Centre encourages users and administrators to review the web link provided and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://ubuntu.com/security/notices">Ubuntu Security Notices</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/dell-security-advisory-av26-554</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/dell-security-advisory-av26-554"/><title><![CDATA[Dell security advisory (AV26-554)]]></title><updated>2026-06-08T13:58:08Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7793" about="/en/alerts-advisories/dell-security-advisory-av26-554" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-554<br /><strong>Date:</strong> June 8, 2026</p>

<p>Between June 1 and 7, 2026, Dell published security advisories to address vulnerabilities in multiple products:</p>

<ul><li>Dell Private Cloud -VMware – versions prior to 01.04.00.00</li>
	<li>PowerSwitch Z9864F-ON – versions prior to v3.5.0</li>
	<li>Dell Automation Platform – versions prior to 2.1.0.0</li>
	<li>Dell VxRail Appliance – versions prior to 8.0.390</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://www.dell.com/support/kbdoc/en-ca/000472451/dsa-2026-242-security-update-for-dell-private-cloud---vmware-for-multiple-third-party-component-vulnerabilities">DSA-2026-242: Security Update for Dell Private Cloud - VMware for Multiple Third-Party Component Vulnerabilities</a></li>
	<li><a href="https://www.dell.com/support/kbdoc/en-ca/000472774/dsa-2026-252-security-update-for-dell-networking-products-for-ami-megarac-spx13">DSA-2026-252: Security Update for Dell Networking Products for AMI MegaRAC SPx13</a></li>
	<li><a href="https://www.dell.com/support/kbdoc/en-ca/000473583/dsa-2026-244-security-update-for-dell-automation-platform-for-multiple-third-party-component-vulnerabilities">DSA-2026-244: Security Update for Dell Automation Platform for Multiple Third-Party Component Vulnerabilities</a></li>
	<li><a href="https://www.dell.com/support/kbdoc/en-ca/000473635/dsa-2026-245-security-update-for-dell-vxrail-for-multiple-third-party-component-vulnerabilities">DSA-2026-245: Security Update for Dell VxRail for Multiple Third-Party Component Vulnerabilities</a></li>
	<li><a href="https://www.dell.com/support/security/en-ca">Dell Security advisories and notices</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/ibm-security-advisory-av26-553</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/ibm-security-advisory-av26-553"/><title><![CDATA[IBM security advisory (AV26-553)]]></title><updated>2026-06-08T13:50:54Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7792" about="/en/alerts-advisories/ibm-security-advisory-av26-553" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-553<br /><strong>Date: </strong>June 8, 2026</p>

<p>Between June 1 and 7, 2026, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:</p>

<ul><li>Decision Optimization for Cloud Pak for Data – version 5.0 to 5.3.1 - Patch 2 releases</li>
	<li>DevOps Test UI (Test UI) – versions Test UI 11.0 to 11.0.6</li>
	<li>DevOps Test UI (Test UI) – versions Test UI 11.0 to 11.0.7</li>
	<li>FileNet Content Manager – multiple versions</li>
	<li>IBM App Connect Enterprise Certified Containers Operands - multiple versions</li>
	<li>IBM App Connect Operator – multiple versions</li>
	<li>IBM Automation Assets in IBM Cloud Pak for Integration (CP4I) – multiple versions</li>
	<li>IBM Big SQL on Cloud Pak for Data – multiple versions</li>
	<li>IBM Bob – versions 1.0.0, 1.0.1 and 1.0.2</li>
	<li>IBM Business Automation Insights – multiple versions</li>
	<li>IBM Business Automation Workflow traditional and IBM Business Automation Workflow Enterprise Service Bus – multiple versions</li>
	<li>IBM Enterprise Content Management Text Search – multiple versions</li>
	<li>IBM ICP – Discovery – version 5.0.0 to 5.3.1</li>
	<li>IBM InfoSphere Optim Archive Viewer – versions 11.7.0.0 to 11.7.0.13</li>
	<li>IBM Maximo Application Suite - Visual Inspection Component – multiple versions</li>
	<li>IBM Maximo Application Suite – versions 9.0 and 9.1</li>
	<li>IBM Netezza Appliance – versions 1.0.0.0 and 1.0.0.1</li>
	<li>IBM Observability with Instana (OnPrem) – all versions</li>
	<li>IBM Platform Navigator in IBM Cloud Pak for Integration (CP4I) – multiple versions;</li>
	<li>IBM Security QRadar EDR – versions 3.12 to 3.12.24</li>
	<li>IBM Security SOAR – multiple versions</li>
	<li>IBM Sterling Connect:Direct Web Services – versions 6.3.0 to 6.3.0.18</li>
	<li>IBM Sterling Connect:Direct Web Services – versions 6.4.0 to 6.4.0.7</li>
	<li>IBM Sterling Connect:Direct for Microsoft Windows – versions 6.3.0.0 to 6.3.0.6_iFix050</li>
	<li>IBM Sterling Connect:Direct for Microsoft Windows – versions 6.4.0.0 to 6.4.0.4_iFix021</li>
	<li>IBM Storage Scale – versions 6.0.0.0 to 6.0.0.2</li>
	<li>IBM Storage Scale – versions 5.2.0.0 to 5.2.3.7</li>
	<li>IBM Verify Antenna – versions 25.05.0 to 26.03.0</li>
	<li>IBM Verify Identity Access Container – multiple versions</li>
	<li>IBM Verify Identity Access – multiple versions</li>
	<li>IBM WebSphere Application Server – versions 9.0 and 8.5</li>
	<li>IBM WebSphere Remote Server – versions 8.5, 9.0 and 9.1</li>
	<li>Jazz for Service Management – version 1.1.3 to 1.1.3.27</li>
	<li>Maximo AI Service – version 9.1.0</li>
	<li>QRadar AI Assistant – versions 1.0.0 to 1.5.0</li>
	<li>QRadar Log Source Management App – versions 1.0.0 to 7.0.14</li>
	<li>Rational Functional Tester (RFT) – multiple versions</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://www.ibm.com/support/pages/bulletin/">IBM Product Security Incident Response</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/solarwinds-security-advisory-av26-549</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/solarwinds-security-advisory-av26-549"/><title><![CDATA[SolarWinds security advisory (AV26-549) - Update 1]]></title><updated>2026-06-05T18:02:32Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7788" about="/en/alerts-advisories/solarwinds-security-advisory-av26-549" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-549<br /><strong>Date: </strong>June 4, 2026<br /><strong>Updated: </strong>June 5, 2026</p>

<p>Between June 2 and 3, 2026, SolarWinds published security advisories to address vulnerabilities in the following products:</p>

<ul><li>SolarWinds Serv-U – versions prior to 15.5.4 HF1</li>
	<li>SolarWinds Web Help Desk – versions prior to 2026.2</li>
</ul><h2 class="h4">Update 1</h2>

<p>On June 5, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-28318 to their Known Exploited Vulnerabilities (KEV) Database.</p>

<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28299">SolarWinds Web Help Desk Denial-of-Service Vulnerability (CVE-2026-28299)</a></li>
	<li><a href="https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28318">SolarWinds Serv-U Unauthenticated Denial of Service Vulnerability (CVE-2026-28318)</a></li>
	<li><a href="https://www.solarwinds.com/trust-center/security-advisories">SolarWinds Security Vulnerabilities</a></li>
	<li><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-28318">CISA KEV: CVE-2026-28318</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/progress-security-advisory-av26-552</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/progress-security-advisory-av26-552"/><title><![CDATA[Progress security advisory (AV26-552)]]></title><updated>2026-06-05T17:19:13Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7791" about="/en/alerts-advisories/progress-security-advisory-av26-552" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-552<br /><strong>Date: </strong>June 5, 2026</p>

<p>Between June 2 and 4, 2026, Progress published security advisories to address vulnerabilities in the following products. Included was a critical update for the following:</p>

<ul><li>Sitefinity CMS and Sitefinity Insight – multiple versions</li>
	<li>Progress Kemp LoadMaster – version GA v7.2.63.1 and prior</li>
	<li>Progress Kemp LoadMaster - version LTSF v7.2.54.17 and prior</li>
</ul><p class="mrgn-bttm-md">The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://community.progress.com/s/article/Sitefinity-Security-Advisory-for-Addressing-Security-Vulnerabilities-CVE-2026-7312-CVE-2026-7198-CVE-2026-7195-CVE-2026-7201-CVE-2026-7313-May-2026">Sitefinity Security Advisory for Addressing Security Vulnerabilities CVE-2026-7312, CVE-2026-7198, CVE-2026-7195, CVE-2026-7201, CVE-2026-7313, May 2026</a></li>
	<li><a href="https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-June-2026-CVE-2026-8037-CVE-2026-33691">LoadMaster Critical Security Bulletin – June 2026 – (CVE-2026-8037, CVE-2026-33691)</a></li>
	<li><a href="https://www.progress.com/trust-center">Progress Trust Center</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/docker-security-advisory-av26-550</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/docker-security-advisory-av26-550"/><title><![CDATA[Docker security advisory (AV26-550)]]></title><updated>2026-06-04T19:31:30Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7789" about="/en/alerts-advisories/docker-security-advisory-av26-550" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26–550<br /><strong>Date: </strong>June 4, 2026</p>

<p>On June 1, 2026, Docker published a security advisory to address a vulnerability in the following product:</p>

<ul><li>Docker Desktop – versions prior to 4.76.0</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://docs.docker.com/desktop/release-notes/#4760">Docker Desktop Release Notes</a></li>
	<li><a href="https://docs.docker.com/security/security-announcements/">Docker security announcements</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/broadcom-vmware-security-advisory-av26-548</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/broadcom-vmware-security-advisory-av26-548"/><title><![CDATA[Broadcom VMware security advisory (AV26-548)]]></title><updated>2026-06-03T19:49:24Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7787" about="/en/alerts-advisories/broadcom-vmware-security-advisory-av26-548" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-548<br /><strong>Date: </strong>June 3, 2026</p>

<p>On June 2, 2026, Broadcom published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:</p>

<ul><li>VMware Tanzu GemFire Management Console - versions prior to 1.4.5</li>
	<li>VMware Tanzu Data Lake - versions prior to 4.1.0</li>
	<li>VMware Tanzu for Postgres - versions prior to 18.4.0</li>
	<li>VMware Tanzu for Postgres - versions prior to 17.10.0</li>
	<li>VMware Tanzu for Postgres - versions prior to 16.14.0</li>
	<li>VMware Tanzu for Postgres - versions prior to 15.18.0</li>
	<li>VMware Tanzu for Postgres - versions prior to 14.23.0</li>
</ul><p>The Cyber Centre encourages users and administrators to review the web links provided and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37582">Product Release Advisory - VMware Tanzu GemFire Management Console</a></li>
	<li><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37581">Product Release Advisory - VMware Tanzu Data Lake 4.1.0</a></li>
	<li><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37580">Product Release Advisory - VMware Tanzu for Postgres 18.4.0, 17.10.0, 16.14.0, 15.18.0, 14.23.0</a></li>
	<li><a href="https://support.broadcom.com/web/ecx/security-advisory?segment=VT">Security Advisories - VMware Cloud Foundation</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-547</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-547"/><title><![CDATA[Cisco security advisory (AV26-547)]]></title><updated>2026-06-03T19:22:10Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7786" about="/en/alerts-advisories/cisco-security-advisory-av26-547" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-547<br /><strong>Date:</strong> June 3, 2026</p>

<p>On June 3, 2026, Cisco published security advisories to address vulnerabilities in multiple products. Included was a critical update for the following:</p>

<ul><li>Cisco Unified Communications Manager (CM) Release 14 – versions prior to 14SU6</li>
	<li>Cisco Unified Communications Manager (CM) Release 15 – versions prior to 15SU5 (Sep 2026) or COP</li>
	<li>Cisco Unified Communications Manager Session Management Edition (CM SME) release 14 – versions prior to 14SU6</li>
	<li>Cisco Unified Communications Manager Session Management Edition (CM SME) release 15 – versions prior to 15SU5 (Sep 2026) or COP</li>
</ul><p>Cisco has indicated that a proof-of-concept exploit code is available for CVE-2026-20230.</p>

<p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssrf-cXPnHcW">Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability</a></li>
	<li><a href="https://tools.cisco.com/security/center/publicationListing.x">Cisco Security Advisories</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/control-systems-phoenix-contact-security-advisory-av26-546</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/control-systems-phoenix-contact-security-advisory-av26-546"/><title><![CDATA[[Control Systems] Phoenix Contact Security Advisory (AV26-546)]]></title><updated>2026-06-03T15:39:58Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7785" about="/en/alerts-advisories/control-systems-phoenix-contact-security-advisory-av26-546" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Number: </strong>AV26-546<br /><strong>Date: </strong>June 3, 2026</p>

<p>On June 3, 2026, Phoenix Contact published a security advisory to address a vulnerability in the following products:</p>

<ul><li>CHARX SEC-3150 – firmware version prior to 1.9.0</li>
	<li>CHARX SEC-3050 – firmware version prior to 1.9.0</li>
	<li>CHARX SEC-3000 – firmware version prior to 1.9.0</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://assets.phoenixcontact.com/file/53de810a-f3f1-454e-b444-d215626d266c/media/original?pcsa-2026-00007_vde-2026-060.pdf ">VDE-2026-060: Phoenix Contact: Unauthenticated log download vulnerability in the firmware of CHARX SEC-3xxx charging controllers (PDF)</a></li>
	<li><a href="https://www.phoenixcontact.com/en-pc/service-and-support/psirt">Phoenix Contact Security Advisories</a></li>
</ul><!--CUT & PASTE the French version info --></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/control-systems-abb-security-advisory-av26-545</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/control-systems-abb-security-advisory-av26-545"/><title><![CDATA[[Control systems] ABB security advisory (AV26-545)]]></title><updated>2026-06-03T13:01:01Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7784" about="/en/alerts-advisories/control-systems-abb-security-advisory-av26-545" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-545<br /><strong>Date: </strong>June 3, 2026</p>

<p>On June 3, 2026, ABB published a security advisory to address vulnerabilities in the following product:</p>

<ul><li>T-MAC <span lang="en" xml:lang="en" xml:lang="en">Plus</span> – versions prior to 4.0-24.</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.</p>

<ul class="list-unstyled"><li><a href="https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A7840&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch">Vulnerabilities in T-MAC Plus (CVE-2025-14771, CVE-2025-14772, CVE2025-14773, CVE-2025-14774)</a></li>
	<li><a href="https://global.abb/group/en/technology/cyber-security/alerts-and-notifications">ABB Cyber security alerts and notifications</a></li>
</ul><!--CUT & PASTE the French version info --></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/google-chrome-security-advisory-av26-544</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/google-chrome-security-advisory-av26-544"/><title><![CDATA[Google Chrome security advisory (AV26-544)]]></title><updated>2026-06-03T12:49:19Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7783" about="/en/alerts-advisories/google-chrome-security-advisory-av26-544" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-544<br /><strong>Date:</strong> June 3, 2026</p>

<p>On June 2, 2026, Google published a security advisory to address vulnerabilities in the following product:</p>

<ul><li>Stable Channel Chrome for Desktop – versions prior to 149.0.7827.53/54 (Windows/Mac), and 149.0.7827.53 (Linux)</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, when available.</p>

<ul class="list-unstyled"><li><a href="https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop.html">Google Chrome Security Advisory</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/hpe-security-advisory-av26-543</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/hpe-security-advisory-av26-543"/><title><![CDATA[HPE security advisory (AV26-543)]]></title><updated>2026-06-02T20:02:25Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7782" about="/en/alerts-advisories/hpe-security-advisory-av26-543" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-543<br /><strong>Date: </strong>June 2, 2026</p>

<p>On June 2, 2026, HPE published security advisories to address vulnerabilities, including some critical ones, in the following products:</p>

<ul><li>HPE Telco Network Function Virtualization Orchestrator – version 7.6.0 and prior</li>
	<li>HPE Aruba Networking ArubaOS-CX Switches – version 10.16.1000 and prior</li>
	<li>HPE Aruba Networking ArubaOS-CX Switches – version 10.15.0005 and prior</li>
	<li>HPE Aruba Networking ArubaOS-CX Switches – version 10.13.1080 and prior</li>
	<li>HPE Aruba Networking ArubaOS-CX Switches – version 10.16.1000 and prior</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05062en_us&amp;docLocale=en_US ">HPESBNW05062 rev.1 - Status of OpenSSH Keystroke Obfuscation Bypass (CVE-2024-39894) on Aruba OS-CX</a></li>
	<li><a href="https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05060en_us&amp;docLocale=en_US">HPESBNW05060 rev.1 - HPE Telco Network Function Virtualization Orchestrator, Multiple Vulnerabilities</a></li>
	<li><a href="https://support.hpe.com/connect/s/securitybulletinlibrary?language=en_US ">HPE Security Bulletin Library</a></li>
</ul><!--CUT & PASTE the French version info --></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/mozilla-security-advisory-av26-542</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/mozilla-security-advisory-av26-542"/><title><![CDATA[Mozilla security advisory (AV26-542)]]></title><updated>2026-06-02T18:35:44Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7781" about="/en/alerts-advisories/mozilla-security-advisory-av26-542" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-542<br /><strong>Date: </strong>June 2, 2026</p>

<p>On June 2, 2026, Mozilla published a security advisory to address vulnerabilities in the following product:</p>

<ul><li>Firefox – versions prior to 151.0.3</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://www.mozilla.org/en-US/security/advisories/mfsa2026-54/">Mozilla Foundation Security Advisory 2026-54 </a></li>
	<li><a href="https://www.mozilla.org/en-US/security/advisories/">Mozilla Security Advisories</a></li>
</ul><!--CUT & PASTE the French version info --></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/jetbrains-security-advisory-av26-541</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/jetbrains-security-advisory-av26-541"/><title><![CDATA[JetBrains security advisory (AV26-541)]]></title><updated>2026-06-02T18:22:12Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7780" about="/en/alerts-advisories/jetbrains-security-advisory-av26-541" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-541<br /><strong>Date: </strong>June 2, 2026</p>

<p>On May 29, 2026, JetBrains published security advisories to address vulnerabilities in the following products:</p>

<ul><li>JetBrains IntelliJ IDEA – versions prior to 2026.1.1</li>
	<li>JetBrains TeamCity – versions prior to 2026.1.1 and 2025.11.5</li>
	<li>JetBrains YouTrack – versions prior to 2026.1.13162</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.</p>

<p class="mrgn-bttm-md"> </p>

<ul class="list-unstyled"><li><a href="https://www.jetbrains.com/privacy-security/issues-fixed/"><span lang="en" xml:lang="en" xml:lang="en">JetBrains – Fixed security issues</span></a></li>
</ul><!--CUT & PASTE the French version info --></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/control-systems-siemens-security-advisory-av26-540</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/control-systems-siemens-security-advisory-av26-540"/><title><![CDATA[[Control systems] Siemens security advisory (AV26-540)]]></title><updated>2026-06-02T18:07:51Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7779" about="/en/alerts-advisories/control-systems-siemens-security-advisory-av26-540" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-540<br /><strong>Date:</strong> June 2, 2026</p>

<p>On June 2, 2026, Siemens published a security advisory to address critical vulnerabilities in the following product:</p>

<ul><li>RUGGEDCOM RST2428P (6GK6242-6PA00) – versions prior to V4.0</li>
</ul><p>The Cyber Centre encourages users and administrators to review the web links provided, perform the suggested mitigations and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://cert-portal.siemens.com/productcert/html/ssa-253495.html">SSA-253495: <span lang="en" xml:lang="en" xml:lang="en">Multiple Vulnerabilities in</span> SINEC OS <span lang="en" xml:lang="en" xml:lang="en">before</span> V4.0</a></li>
	<li><a href="https://www.siemens.com/global/en/products/services/cert.html">Siemens Security Advisories</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/android-security-advisory-june-2026-monthly-rollup-av26-538</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/android-security-advisory-june-2026-monthly-rollup-av26-538"/><title><![CDATA[Android security advisory – June 2026 monthly rollup (AV26-538) – Update 1]]></title><updated>2026-06-02T17:58:26Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7777" about="/en/alerts-advisories/android-security-advisory-june-2026-monthly-rollup-av26-538" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-538<br /><strong>Date: </strong>June 2, 2026</p>

<p>On June 1, 2026, Android published a security bulletin to address vulnerabilities affecting Android devices.</p>

<p>The vendor indicates that CVE-2025-48595 may be under limited, targeted exploitation.</p>

<p><strong>Update 1</strong><br />
On June 2, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-48595 to their Known Exploited Vulnerabilities (KEV) Database.</p>

<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://source.android.com/docs/security/bulletin/2026/2026-06-01">Android Security Bulletin</a></li>
	<li><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-48595">CISA KEV: CVE-2025-48595</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/hp-security-advisory-av26-539</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/hp-security-advisory-av26-539"/><title><![CDATA[HP security advisory (AV26-539)]]></title><updated>2026-06-02T15:24:01Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7778" about="/en/alerts-advisories/hp-security-advisory-av26-539" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-539<br /><strong>Date: </strong>June 2, 2026</p>

<p>On June 1, 2026, HP published a security advisory to address a critical vulnerability in the following products:</p>

<ul><li>HP Poly VVX – versions prior to UCS 6.4.8 – Pending</li>
	<li>HP Poly Trio 8300 – versions prior to UCS 8.1.7</li>
	<li>HP Poly Trio 8500 – versions prior to UCS 7.2.8</li>
	<li>HP Poly Trio 8800 – versions prior to UCS 7.2.8</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates, once available.</p>

<ul class="list-unstyled"><li><a href="https://support.hp.com/us-en/document/ish_15052661-15052687-16/hpsbpy04083">Poly Voice – Possible Remote Control of Certain Poly Devices</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/samsung-mobile-security-advisory-av26-537</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/samsung-mobile-security-advisory-av26-537"/><title><![CDATA[Samsung mobile security advisory (AV26-537)]]></title><updated>2026-06-02T15:09:15Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7776" about="/en/alerts-advisories/samsung-mobile-security-advisory-av26-537" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-537<br /><strong>Date:</strong> June 2, 2026</p>

<p>On June 2, 2026, Samsung published a security update to address vulnerabilities in the following product:</p>

<ul><li>Samsung mobile devices – versions prior to SMR-JUN-2026</li>
</ul><p>The most recent security update resolves multiple identified vulnerabilities.</p>

<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update.</p>

<ul class="list-unstyled"><li><a href="https://security.samsungmobile.com/securityUpdate.smsb?year=2026&amp;month=06">Samsung Security Updates</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/broadcom-vmware-security-advisory-av26-536</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/broadcom-vmware-security-advisory-av26-536"/><title><![CDATA[Broadcom VMware security advisory (AV26-536)]]></title><updated>2026-06-01T18:31:58Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7775" about="/en/alerts-advisories/broadcom-vmware-security-advisory-av26-536" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-536<br /><strong>Date: </strong>June 1, 2026</p>

<p>On May 29, 2026, Broadcom published a security advisory to address vulnerabilities in the following product. Included were critical updates for the following:</p>

<ul><li>VMware Tanzu for Valkey – versions prior to 7.2.13</li>
	<li>VMware Tanzu for Valkey – versions prior to 8.0.9</li>
	<li>VMware Tanzu for Valkey – versions prior to 8.1.7</li>
	<li>VMware Tanzu for Valkey – versions prior to 9.0.4</li>
</ul><p>The Cyber Centre encourages users and administrators to review the web links provided and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37556">Product Release Advisory - VMware Tanzu for Valkey 7.2.13, 8.0.9, 8.1.7, 9.0.4</a></li>
	<li><a href="https://support.broadcom.com/web/ecx/security-advisory?segment=VT">Security Advisories - VMware Cloud Foundation</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/qualcomm-security-advisory-june-2026-monthly-rollup-av26-535</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/qualcomm-security-advisory-june-2026-monthly-rollup-av26-535"/><title><![CDATA[Qualcomm security advisory – June 2026 monthly rollup (AV26-535)]]></title><updated>2026-06-01T18:27:07Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7774" about="/en/alerts-advisories/qualcomm-security-advisory-june-2026-monthly-rollup-av26-535" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-535<br /><strong>Date: </strong>June 1, 2026</p>

<p>On June 1, 2026, Qualcomm published a security bulletin to address vulnerabilities affecting Qualcomm products.</p>

<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://docs.qualcomm.com/securitybulletin/june-2026-bulletin.html">Qualcomm Security Bulletin – June</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/oracle-security-advisory-july-2024-quarterly-rollup-av24-401</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/oracle-security-advisory-july-2024-quarterly-rollup-av24-401"/><title><![CDATA[Oracle security advisory – July 2024 quarterly rollup (AV24-401) - Update 1]]></title><updated>2026-06-01T17:39:35Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="5369" about="/en/alerts-advisories/oracle-security-advisory-july-2024-quarterly-rollup-av24-401" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><!--{C}%3C!%2D%2D***************************************************%20START%20ADVISORY%20-English-%20******************************************************%2D%2D%3E--></p>

<p><strong>Serial number: </strong>AV24-401<br /><!--{C}%3C!%2D%2D%20DATES%20Pick%20one%20update%20the%20day%20xx%2C%20delete%20the%20rest%20%2D%2D%3E--><strong>Date: </strong>July 17, 2024<br /><strong>Updated: </strong>June 1, 2026</p>

<p>On July 16, 2024, Oracle published a security advisory to address vulnerabilities in multiple products. Included were critical updates for the following:</p>

<ul><li>Oracle Analytics</li>
	<li>Oracle Communications Applications</li>
	<li>Oracle Communications</li>
	<li>Oracle Financial Services Application</li>
	<li>Oracle Fusion Middleware</li>
	<li>Oracle MySQL</li>
	<li>Oracle Siebel CRM</li>
</ul><h2 class="h3">Update 1</h2>

<p>On June 1, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2024-21182 to their Known Exploited Vulnerabilities (KEV) Database.</p>

<p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://www.oracle.com/security-alerts/cpujul2024.html">Oracle Critical Patch Update Advisory – July 2024</a></li>
	<li><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-21182">CISA KEV: CVE-2024-21182</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/plesk-security-advisory-av26-534</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/plesk-security-advisory-av26-534"/><title><![CDATA[Plesk security advisory (AV26-534)]]></title><updated>2026-06-01T14:56:27Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7772" about="/en/alerts-advisories/plesk-security-advisory-av26-534" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-534<br /><strong>Date:</strong> June 1, 2026</p>

<p>On May 27, 2026, Plesk published a security advisory to address a vulnerability in the following product:</p>

<ul><li>Plesk for Linux – versions prior to 18.0.75.1</li>
	<li>Plesk for Linux – versions prior to 18.0.76.2</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://support.plesk.com/hc/en-us/articles/38633651286679-Vulnerability-CVE-2026-44962-in-Plesk-s-APS-Catalog">Vulnerability CVE-2026-44962 in Plesk's APS Catalog</a></li>
	<li><a href="https://support.plesk.com/hc/en-us">Plesk Support</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/ivanti-security-advisory-av26-533</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/ivanti-security-advisory-av26-533"/><title><![CDATA[Ivanti security advisory (AV26-533)]]></title><updated>2026-06-01T14:50:50Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7771" about="/en/alerts-advisories/ivanti-security-advisory-av26-533" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-533<br /><strong>Date: </strong>June 1, 2026</p>

<p>On June 1, 2026, Ivanti published a security advisory to address a vulnerability in the following products:</p>

<ul><li>Ivanti Neurons for ITSM (On-Premises) – version 2025.4 and prior</li>
	<li>Ivanti Neurons for ITSM (Cloud) – version 2026.1 and prior</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-CVE-2026-9614?language=en_US">Security Advisory Ivanti Neurons for ITSM (CVE-2026-9614)</a></li>
	<li><a href="https://forums.ivanti.com/s/searchallcontent?language=en_US#tab=All&amp;sortCriteria=date%20descending&amp;f-sfkbknowledgearticletypec=Security%20Advisory">Ivanti Security Advisories</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/mozilla-security-advisory-av26-532</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/mozilla-security-advisory-av26-532"/><title><![CDATA[Mozilla security advisory (AV26-532)]]></title><updated>2026-06-01T13:25:32Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7770" about="/en/alerts-advisories/mozilla-security-advisory-av26-532" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-532<br /><strong>Date: </strong>June 1, 2026</p>

<p>On June 1, 2026, Mozilla published a security advisory to address vulnerabilities in the following product:</p>

<ul><li>Firefox for iOS – versions prior to 151.2</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://www.mozilla.org/en-US/security/advisories/mfsa2026-53/">Mozilla Foundation Security Advisory 2026-53</a></li>
	<li><a href="https://www.mozilla.org/en-US/security/advisories/">Mozilla Security Advisories</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/red-hat-security-advisory-av26-531</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/red-hat-security-advisory-av26-531"/><title><![CDATA[Red Hat security advisory (AV26-531)]]></title><updated>2026-06-01T13:19:43Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7769" about="/en/alerts-advisories/red-hat-security-advisory-av26-531" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-531<br /><strong>Date: </strong>June 1, 2026</p>

<p>Between May 25 and 31, 2026, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products:</p>

<ul><li>Red Hat CodeReady Linux Builder – multiple versions and platforms</li>
	<li>Red Hat Enterprise Linux – multiple versions and platforms</li>
	<li>Red Hat Enterprise Linux Server – multiple versions and platforms</li>
	<li>Red Hat Enterprise Linux for Real Time – multiple versions and platforms</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://access.redhat.com/security/security-updates/security-advisories">Red Hat Security Advisories</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/control-systems-cisa-ics-security-advisories-av26-530</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/control-systems-cisa-ics-security-advisories-av26-530"/><title><![CDATA[[Control systems] CISA ICS security advisories (AV26–530)]]></title><updated>2026-06-01T13:15:12Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7768" about="/en/alerts-advisories/control-systems-cisa-ics-security-advisories-av26-530" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number:</strong> AV26–530<br /><strong>Date:</strong> June 1, 2026</p>

<p>Between May 25 and 31, 2026, CISA published ICS advisories to address vulnerabilities in the following products:</p>

<ul><li>ABB AC500 V2 – versions prior to 2.5.2 and 2.5.3</li>
	<li>ABB Ability Camera Connect – versions prior to 1.5.0.14 and 1.5.0.15</li>
	<li>ABB Ability Zenon – versions 7.50 to 14</li>
	<li>ABB B&amp;R Automation Runtime – versions prior to 6.3 and Q4.93</li>
	<li>ABB EIBPORT V3 KNX (2CLA963710W1001) / (2CSM256242R2001) – versions prior to 3.9.2</li>
	<li>ABB EIBPORT V3 KNX GSM (2CLA963720W1001) – versions prior to 3.9.2</li>
	<li>ABB LVS MConfig – versions 1.4.9.21 and prior</li>
	<li>CP Plus 8 Ch. Network Video Recorder – multiple versions</li>
	<li>Eppendorf BioFlo 320 – all versions</li>
	<li>Frontier X Android application – versions prior to v15.0.0</li>
	<li>Frontier X IOS application– versions prior to v25.0.0</li>
	<li>Frontier X2 – all versions</li>
	<li>Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter – version 7.03T.07</li>
	<li>KMW CCTV Security Cameras – versions KM-IP521 IPCAM_V4.04.91.230307 and KM-IP421 IPCAM_V4.04.53.210416</li>
	<li>MacGregor Voyage Data Recorder (VDR) G4e – versions prior to V5.250</li>
	<li>Schneider Electric EcoStruxure Machine Expert HVAC – versions prior to 1.10.0</li>
	<li>Switch Actuator 4 DU – all versions</li>
	<li>Switch Actuator, door/light 4 DU – all versions</li>
	<li>Terra AC Wallbox – multiple versions and models</li>
	<li>XCharge C6 – version C6</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web link, perform the suggested mitigations and apply the necessary updates if available.</p>

<ul class="list-unstyled"><li><a href="https://www.cisa.gov/news-events/ics-advisories">CISA ICS Advisories</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/ubuntu-security-advisory-av26-529</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/ubuntu-security-advisory-av26-529"/><title><![CDATA[Ubuntu security advisory (AV26-529)]]></title><updated>2026-06-01T13:07:31Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7767" about="/en/alerts-advisories/ubuntu-security-advisory-av26-529" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number:</strong> AV26-529<br /><strong>Date:</strong> June 1, 2026</p>

<p>Between May 25 and 31, 2026, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products:</p>

<ul><li>Ubuntu 20.04 LTS</li>
	<li>Ubuntu 22.04 LTS</li>
	<li>Ubuntu 24.04 LTS</li>
	<li>Ubuntu 25.10</li>
</ul><p>The Cyber Centre encourages users and administrators to review the web links provided and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://ubuntu.com/security/notices/USN-8305-2">USN-8305-2: Linux kernel (Low Latency) vulnerabilities</a></li>
	<li><a href="https://ubuntu.com/security/notices/USN-8305-1">USN-8305-1: Linux kernel (Intel IoTG Real-time) vulnerabilities</a></li>
	<li><a href="https://ubuntu.com/security/notices/USN-8310-1">USN-8310-1: Linux kernel (Azure) vulnerabilities</a></li>
	<li><a href="https://ubuntu.com/security/notices">Ubuntu Security Notices</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/dell-security-advisory-av26-528</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/dell-security-advisory-av26-528"/><title><![CDATA[Dell security advisory (AV26-528)]]></title><updated>2026-06-01T13:01:54Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7766" about="/en/alerts-advisories/dell-security-advisory-av26-528" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number:</strong> AV26-528<br /><strong>Date:</strong> June 1, 2026</p>

<p>Between May 25 and 31, 2026, Dell published security advisories to address vulnerabilities in multiple products:</p>

<ul><li>PowerEdge Server Chipset Driver – multiple applications and versions</li>
	<li>Data Lakehouse – versions prior to 1.8.0.0</li>
	<li>Dell Enterprise SONiC Distribution – versions prior to 4.5.2</li>
	<li>Dell Unity – versions prior to 5.5.4</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://www.dell.com/support/kbdoc/en-ca/000469673/dsa-2026-232-security-update-for-amd-based-poweredge-server-chipset-driver-vulnerabilities">DSA-2026-232: Security Update for AMD-based PowerEdge Server Chipset Driver Vulnerabilities</a></li>
	<li><a href="https://www.dell.com/support/kbdoc/en-ca/000469911/dsa-2026-199-security-update-for-dell-data-lakehouse-multiple-third-party-component-vulnerabilities">DSA-2026-199: Security Update for Dell Data Lakehouse Multiple Third-Party Component Vulnerabilities</a></li>
	<li><a href="https://www.dell.com/support/kbdoc/en-ca/000470137/dsa-2026-241-security-update-for-dell-enterprise-sonic-distribution-vulnerabilities">DSA-2026-241: Security Update for Dell Enterprise SONiC Distribution Vulnerabilities</a></li>
	<li><a href="https://www.dell.com/support/kbdoc/en-ca/000470814/dsa-2026-211---security-update-for-dell-unity-dell-unityvsa-and-dell-unity-xt-security-update-for-multiple-vulnerabilities">DSA-2026-211 -: Security Update for Dell Unity, Dell UnityVSA and Dell Unity XT Security Update for Multiple Vulnerabilities</a></li>
	<li><a href="https://www.dell.com/support/security/en-ca">Dell Security advisories and notices</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/ibm-security-advisory-av26-527</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/ibm-security-advisory-av26-527"/><title><![CDATA[IBM security advisory (AV26-527)]]></title><updated>2026-06-01T12:52:02Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7765" about="/en/alerts-advisories/ibm-security-advisory-av26-527" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-527<br /><strong>Date: </strong>June 1, 2026</p>

<p>Between May 25 and 31, 2026, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:</p>

<ul><li>IBM Aspera Enterprise WebApps – versions 1.0.0 to 1.0.2.1</li>
	<li>IBM Business Automation Workflow containers and traditional – multiple versions</li>
	<li>IBM Cloud Pak for Business Automation – multiple versions</li>
	<li>IBM Cloud Pak for Security – versions 1.10.0.0 to 1.10.11.0</li>
	<li>IBM Control Center – multiple versions</li>
	<li>IBM DataStax Enterprise – versions 5.1, 6.7, 6.8 and 6.9</li>
	<li>IBM Edge Application Manager – multiple versions</li>
	<li>IBM Engineering Lifecycle Management - Jazz Foundation – multiple versions</li>
	<li>IBM Library Support for Spring – version 3.3</li>
	<li>IBM License Metric Tool – versions 9.2.0 to 9.2.43</li>
	<li>IBM Maximo Application Suite - Monitor Component – version 9.1.0.0</li>
	<li>IBM Observability with Instana (Agent) – versions Build 1.0.303 to 1.0.318</li>
	<li>IBM Process Mining – versions 2.0.0 to 2.1.1 IF001</li>
	<li>IBM Security SOAR – multiple versions</li>
	<li>IBM Tivoli Application Dependency Discovery Manager – versions 7.3.0.0 to 7.3.0.12</li>
	<li>QRadar Suite Software – versions 1.10.12.0 to 1.11.10.0</li>
	<li>WebSphere Service Registry and Repository – version 8.5</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://www.ibm.com/support/pages/bulletin/">IBM Product Security Incident Response</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/microsoft-security-advisory-may-2026-monthly-rollup-av26-456</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/microsoft-security-advisory-may-2026-monthly-rollup-av26-456"/><title><![CDATA[Microsoft security advisory – May 2026 monthly rollup (AV26-456) – Update 2]]></title><updated>2026-06-01T12:34:39Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7686" about="/en/alerts-advisories/microsoft-security-advisory-may-2026-monthly-rollup-av26-456" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-456<br /><strong>Date: </strong>May 12, 2026<br /><strong>Updated:</strong> June 1, 2026</p>

<p>On May 12, 2026, Microsoft published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products:</p>

<ul><li>.NET 10.0 installed on Linux</li>
	<li>.NET 10.0 installed on Mac OS</li>
	<li>.NET 10.0 installed on Windows</li>
	<li>.NET 8.0 installed on Linux</li>
	<li>.NET 8.0 installed on Mac OS</li>
	<li>.NET 8.0 installed on Windows</li>
	<li>.NET 9.0 installed on Linux</li>
	<li>.NET 9.0 installed on Mac OS</li>
	<li>.NET 9.0 installed on Windows</li>
	<li>Azure AI Foundry</li>
	<li>Azure Cloud Shell</li>
	<li>Azure Connected Machine Agent</li>
	<li>Azure DevOps</li>
	<li>Azure Logic Apps</li>
	<li>Azure Machine Learning</li>
	<li>Azure Managed Instance for Apache Cassandra</li>
	<li>Azure Monitor Action Group notification system</li>
	<li>Azure Monitor Agent</li>
	<li>Azure Monitor Agent Metrics Extension</li>
	<li>Azure SDK for Java</li>
	<li>Copilot Chat (Microsoft Edge)</li>
	<li>Dynamics 365 Customer Insights</li>
	<li>M365 Copilot for Desktop</li>
	<li>Microsoft .NET Framework 3.5</li>
	<li>Microsoft .NET Framework 3.5 AND 4.7.2</li>
	<li>Microsoft .NET Framework 3.5 AND 4.8</li>
	<li>Microsoft .NET Framework 3.5 AND 4.8.1</li>
	<li>Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2</li>
	<li>Microsoft .NET Framework 4.8</li>
	<li>Microsoft 365</li>
	<li>Microsoft 365 Copilot for Android</li>
	<li>Microsoft 365 Copilot's Business Chat</li>
	<li>Microsoft Confluence SAML SSO plugin</li>
	<li>Microsoft Data Formulator</li>
	<li>Microsoft Dynamics 365</li>
	<li>Microsoft Dynamics 365 Business Central</li>
	<li>Microsoft Edge (Chromium-based)</li>
	<li>Microsoft Enterprise Security Token Service (ESTS)</li>
	<li>Microsoft Excel 2016</li>
	<li>Microsoft Excel for Android</li>
	<li>Microsoft JIRA SAML SSO plugin</li>
	<li>Microsoft Office 2016</li>
	<li>Microsoft Office 2019</li>
	<li>Microsoft Office LTSC 2021</li>
	<li>Microsoft Office LTSC 2024</li>
	<li>Microsoft Office LTSC for Mac 2021</li>
	<li>Microsoft Office LTSC for Mac 2024</li>
	<li>Microsoft Office for Android</li>
	<li>Microsoft Outlook for iOS</li>
	<li>Microsoft Partner Center</li>
	<li>Microsoft PowerPoint for Android</li>
	<li>Microsoft SQL Server 2016</li>
	<li>Microsoft SQL Server 2017</li>
	<li>Microsoft SQL Server 2019</li>
	<li>Microsoft SQL Server 2022</li>
	<li>Microsoft SQL Server 2025</li>
	<li>Microsoft SharePoint Enterprise Server 2016</li>
	<li>Microsoft SharePoint Server 2019</li>
	<li>Microsoft SharePoint Server Subscription Edition</li>
	<li>Microsoft Teams</li>
	<li>Microsoft Teams for Android</li>
	<li>Microsoft Visual Studio 2017</li>
	<li>Microsoft Visual Studio 2019</li>
	<li>Microsoft Visual Studio 2022</li>
	<li>Microsoft Visual Studio 2026</li>
	<li>Microsoft Word 2016</li>
	<li>Microsoft Word for Android</li>
	<li>Office Online Server</li>
	<li>Power Automate for Desktop</li>
	<li>Visual Studio Code</li>
	<li>Visual Studio Code - Live Preview extension</li>
	<li>Windows 10</li>
	<li>Windows 11</li>
	<li>Windows Admin Center</li>
	<li>Windows Admin Center in Azure Portal</li>
	<li>Windows Server 2012</li>
	<li>Windows Server 2016</li>
	<li>Windows Server 2019</li>
	<li>Windows Server 2025</li>
</ul><h2>Update 1</h2>

<p>On May 21, 2026, Microsoft published an out-of-band (OOB) security update to address CVE-2026-45659, an additional vulnerability impacting Microsoft SharePoint Enterprise Server 2019, Microsoft SharePoint Server 2016 and Microsoft SharePoint Server Subscription Edition. The CVE was inadvertently omitted from the May 2026 Security Updates.</p>

<h2>Update 2</h2>

<p>Open-source reporting indicates that CVE-2026-41089 is being exploited in the wild.</p>

<p class="mrgn-bttm-md">The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://msrc.microsoft.com/update-guide/releaseNote/2026-May">May 2026 Security Updates</a></li>
	<li><a href="https://msrc.microsoft.com/update-guide/en-us">Security Update Guide</a></li>
	<li><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659">Microsoft SharePoint Remote Code Execution Vulnerability CVE-2026-45659</a></li>
  <li><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41089">Windows Netlogon Remote Code Execution Vulnerability CVE-2026-41089</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/palo-alto-networks-security-advisory-av26-462</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/palo-alto-networks-security-advisory-av26-462"/><title><![CDATA[Palo Alto Networks security advisory (AV26-462) – Update 1]]></title><updated>2026-05-29T20:10:00Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7694" about="/en/alerts-advisories/palo-alto-networks-security-advisory-av26-462" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-462<br /><strong>Date: </strong>May 13, 2026<br /><strong>Updated:</strong> May 29, 2026</p>

<p>On May 13, 2026, Palo Alto Networks published security advisories to address vulnerabilities in the following products:</p>

<ul><li>PAN-OS 12.1 – versions prior to 12.1.4-h5</li>
	<li>PAN-OS 12.1 – versions prior to 12.1.7</li>
	<li>PAN-OS 11.2 – multiple versions</li>
	<li>PAN-OS 11.1 – multiple versions</li>
	<li>PAN-OS 10.2 – multiple versions</li>
</ul><p><strong>Update 1</strong></p>

<p>On May 29, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-0257 to their Known Exploited Vulnerabilities (KEV) Database.</p>

<p>Impacted products for CVE-2026-0257:</p>

<ul><li>PAN-OS 12.1 – versions prior to 12.1.4-h6</li>
	<li>PAN-OS 12.1 – versions prior to 12.1.7</li>
	<li>PAN-OS 11.2 – multiple versions</li>
	<li>PAN-OS 11.1 – multiple versions</li>
	<li>PAN-OS 10.2 – multiple versions</li>
	<li>Prisma Access 11.2.0 – versions prior to 11.2.7-h13</li>
	<li>Prisma Access 10.2.0 – versions prior to 10.2.10-h36</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates.</p>

<ul class="list-unstyled"><li><a href="https://security.paloaltonetworks.com/CVE-2026-0265">CVE-2026-0265 PAN-OS: Authentication Bypass with Cloud Authentication Service (CAS) enabled</a></li>
	<li><a href="https://security.paloaltonetworks.com/CVE-2026-0264">CVE-2026-0264 PAN-OS: Heap-Based Buffer Overflow in DNS Proxy and DNS Server Allows Unauthenticated Remote Code Execution</a></li>
	<li><a href="https://security.paloaltonetworks.com/CVE-2026-0263">CVE-2026-0263 PAN-OS: Remote Code Execution (RCE) in IKEv2 Processing</a></li>
	<li><a href="https://security.paloaltonetworks.com/">Palo Alto Network Security Advisories</a></li>
	<li><a href="https://security.paloaltonetworks.com/CVE-2026-0257">CVE-2026-0257 PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities</a></li>
	<li><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-0257">CISA KEV: CVE-2026-0257</a></li>
</ul></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/al26-013-security-incident-impacting-github-internal-repositories</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/al26-013-security-incident-impacting-github-internal-repositories"/><title><![CDATA[AL26-013 Security incident impacting GitHub internal repositories]]></title><updated>2026-05-29T16:11:50Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7763" about="/en/alerts-advisories/al26-013-security-incident-impacting-github-internal-repositories" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Number:</strong> AL26-013<br /><strong>Date:</strong> May 29, 2026</p>

<h2>Audience</h2>

<p>This Alert is intended for <abbr title="information technology">IT</abbr> professionals and managers.</p>

<h2>Purpose</h2>

<p>An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.</p>

<h2>Details</h2>

<p>On <span class="nowrap">May 18, 2026</span>, GitHub detected unauthorized access to its internal systems originating from a compromised employee device<sup id="fn1-rf"><a class="fn-lnk" href="#fn1"><span class="wb-inv">Footnote </span>1</a></sup>. The intrusion was facilitated by a maliciously modified version of the Nx Console Visual Studio Code extension (version 18.95.0)<sup id="fn2-rf"><a class="fn-lnk" href="#fn2"><span class="wb-inv">Footnote </span>2</a></sup>. The attacker successfully exfiltrated approximately <span class="nowrap">3,800</span> internal GitHub repositories, containing proprietary source code and internal configuration data. GitHub Enterprise Server customers are advised to follow vendors recommendations. No action is required for GitHub Enterprise Cloud clients.</p>

<p>In response to this security incident, and the release of the GitHub Security Notification, the Cyber Centre released <span class="nowrap">AV26-512</span> on <span class="nowrap">May 27, 2026<sup id="fn3-rf"><a class="fn-lnk" href="#fn3"><span class="wb-inv">Footnote </span>3</a></sup></span>.</p>

<p>The purpose of this alert is to increase awareness of the reported incident and to take necessary measures.</p>

<h2>Suggested actions</h2>

<p>The Cyber Centre suggests the following actions:</p>

<ul><li>Monitor for compromise by reviewing CI/CD (Continuous Integration/Continuous Deployment) logs for unexpected repository access/cloning, unauthorized admin actions, authentication/access control changes, unauthorized pushes or orphan commits, and suspicious commits after May 18, 2026 — especially from bot/service accounts (e.g., ci-bot, build-bot).</li>
	<li>Remove Nx Console v18.95.0 from all environments and downgrade/upgrade to a known good version (18.94.0 or 18.96.0+).</li>
	<li>If the malicious version of Nx Console is present:
	<ul><li>Check macOS systems for <code>~/.local/share/kitty/cat.py</code> and related persistence (launch agents)</li>
		<li>Immediately rotate all credentials (AWS, GCP, Azure, GitHub, npm) exposed on developer machines between <span class="nowrap">May 11–20, 2026.</span></li>
	</ul></li>
	<li>Strengthen controls by disabling IDE extension auto-updates in high-security environments and enforcing an approved allowlist of developer tools.</li>
	<li>Rotate GitHub Enterprise Server GPG (GNU Privacy Guard) public keys per vendor guidance, as future patches/releases require the new key before installation.</li>
</ul><p>In addition, the Cyber Centre strongly recommends that organizations review and implement the Cyber Centre’s Top 10 <abbr title="information technology">IT</abbr> Security Actions with an emphasis on the following topics<sup id="fn4-rf"><a class="fn-lnk" href="#fn4"><span class="wb-inv">Footnote </span>4</a></sup>.</p>

<ul><li>Patch operating systems and applications</li>
	<li>Harden operating systems and applications</li>
	<li>Isolate web-facing applications</li>
</ul><p>Should activity matching the content of this alert be discovered, recipients are encouraged to report via <a href="/en/incident-management">My Cyber Portal</a>, or email <a href="mailto:contact@cyber.gc.ca">contact@cyber.gc.ca</a>.</p>
<!--FOOTNOTE SECTION EN-->

<aside class="wb-fnote" role="note"><h2 id="reference">References</h2>

<dl><dt>Footnote 1</dt>
	<dd id="fn1">
	<p><a href="https://github.blog/security/investigating-unauthorized-access-to-githubs-internal-repositories/">Investigation update: GitHub Enterprise Server signing key rotation</a></p>

	<p class="fn-rtn"><a href="#fn1-rf"><span class="wb-inv">Return to footnote</span>1<span class="wb-inv"> referrer</span></a></p>
	</dd>
	<dt>Footnote 2</dt>
	<dd id="fn2">
	<p><a href="https://nx.dev/blog/nx-console-v18-95-0-postmortem">Postmortem: Nx Console v18.95.0 supply-chain compromise</a></p>

	<p class="fn-rtn"><a href="#fn2-rf"><span class="wb-inv">Return to footnote</span>2<span class="wb-inv"> referrer</span></a></p>
	</dd>
	<dt>Footnote 3</dt>
	<dd id="fn3">
	<p><a href="/en/alerts-advisories/github-security-advisory-av26-512">AV26-512 – GitHub security advisory</a></p>

	<p class="fn-rtn"><a href="#fn3-rf"><span class="wb-inv">Return to footnote</span>3<span class="wb-inv"> referrer</span></a></p>
	</dd>
	<dt>Footnote 4</dt>
	<dd id="fn4">
	<p><a href="/en/guidance/top-10-it-security-actions-protect-internet-connected-networks-and-information-itsm10089">Top 10 <abbr title="information technology">IT</abbr> security actions to protect Internet connected networks and information (ITSM.10.089)</a></p>

	<p class="fn-rtn"><a href="#fn4-rf"><span class="wb-inv">Return to footnote</span>4<span class="wb-inv"> referrer</span></a></p>
	</dd>
</dl></aside></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry><entry><id>https://cyber.gc.ca/en/alerts-advisories/oracle-security-advisory-av26-526</id><link rel="alternate" href="https://cyber.gc.ca/en/alerts-advisories/oracle-security-advisory-av26-526"/><title><![CDATA[Oracle security advisory (AV26-526)]]></title><updated>2026-05-29T13:36:26Z</updated><summary><![CDATA[]]></summary><content><![CDATA[<article data-history-node-id="7761" about="/en/alerts-advisories/oracle-security-advisory-av26-526" class="cccs-threats full clearfix">

  
    

  
  <div class="content">
      <div class="layout layout--onecol">
    <div  class="layout__region layout__region--content">
      
<div data-block-plugin-id="extra_field_block:node:cccs_threats:links" class="block block-layout-builder block-extra-field-blocknodecccs-threatslinks clearfix">
  
    

      
  </div>

<div data-block-plugin-id="field_block:node:cccs_threats:body" class="block block-layout-builder block-field-blocknodecccs-threatsbody clearfix">
  
    

      
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p><strong>Serial number: </strong>AV26-526 <br /><strong>Date:</strong> May 29, 2026</p>

<p>On May 28, 2026, Oracle published a security advisory to address critical vulnerabilities in the following products:</p>

<ul><li>Oracle Communications Unified Assurance - versions 6.1.1 to 7.0.0</li>
	<li>Oracle Database Server - versions 23.4.0 to 23.26.2</li>
	<li>Oracle E-Business Suite - versions 12.2.3 to 12.2.15</li>
	<li>Oracle Hospitality OPERA 5 Property Services - versions 5.6.19.24, 5.6.22, 5.6.25.19, 5.6.27.6 and 5.6.28</li>
	<li>Oracle REST Data Services - versions 24.2.0 to 26.1.0</li>
</ul><p>The Cyber Centre encourages users and administrators to review the provided web links and perform the suggested mitigations.</p>

<ul class="list-unstyled"><li><a href="https://www.oracle.com/security-alerts/cspumay2026.html">Oracle Critical Security Patch Update Advisory - May 2026</a></li>
	<li><a href="https://www.oracle.com/security-alerts/">Oracle Critical Patch Updates, Security Alerts and Bulletins</a></li>
</ul><!--CUT & PASTE the French version info --></div>
      
  </div>

    </div>
  </div>

  </div>

</article>
]]></content><author><name><![CDATA[Canadian Centre for Cyber Security]]></name></author></entry></feed>