<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>CERT Polska</title><link>https://cert.pl/en/</link><description>CERT.PL</description><atom:link href="https://cert.pl/rss.xml" rel="self"/><lastBuildDate>Fri, 24 Jul 2026 11:55:00 +0100</lastBuildDate><item><title>Vulnerability in Apereo CAS Client software</title><link>https://cert.pl/en/posts/2026/07/CVE-2026-15243/</link><description>Improper certificate validation vulnerability (CVE-2026-15243) has been found in Apereo CAS Client software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 24 Jul 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-07-24:/en/posts/2026/07/CVE-2026-15243/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in GNU coreutils software</title><link>https://cert.pl/en/posts/2026/07/CVE-2026-56391/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2026-56391 and CVE-2026-56392) found in GNU coreutils software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 24 Jul 2026 09:55:00 +0100</pubDate><guid>tag:cert.pl,2026-07-24:/en/posts/2026/07/CVE-2026-56391/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in GNU diffutils software</title><link>https://cert.pl/en/posts/2026/07/CVE-2026-53910/</link><description>Integer Overflow vulnerability (CVE-2026-53910) has been found in GNU diffutils software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Wed, 22 Jul 2026 14:55:00 +0100</pubDate><guid>tag:cert.pl,2026-07-22:/en/posts/2026/07/CVE-2026-53910/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Open Mercato software</title><link>https://cert.pl/en/posts/2026/07/CVE-2026-16270/</link><description>Denial of Service via unsafe regex vulnerability (CVE-2026-16270) has been found in Open Mercato software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Wed, 22 Jul 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-07-22:/en/posts/2026/07/CVE-2026-16270/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in Windu CMS software</title><link>https://cert.pl/en/posts/2026/07/CVE-2026-57309/</link><description>CERT Polska has received a report about 3 vulnerabilities (from CVE-2026-57309 to CVE-2026-57311) found in Windu CMS software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 20 Jul 2026 14:55:00 +0100</pubDate><guid>tag:cert.pl,2026-07-20:/en/posts/2026/07/CVE-2026-57309/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in ICU Scandinavia Boomerang software</title><link>https://cert.pl/en/posts/2026/07/CVE-2026-46458/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2026-46458 and CVE-2026-46459) found in ICU Scandinavia Boomerang software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Wed, 15 Jul 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-07-15:/en/posts/2026/07/CVE-2026-46458/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in 4real ThemisNETPanel software</title><link>https://cert.pl/en/posts/2026/07/CVE-2026-6847/</link><description>Unauthenticated Remote Code Execution (CVE-2026-6847) has been found in 4real ThemisNETPanel software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 13 Jul 2026 14:55:00 +0100</pubDate><guid>tag:cert.pl,2026-07-13:/en/posts/2026/07/CVE-2026-6847/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in GNU gawk software</title><link>https://cert.pl/en/posts/2026/07/CVE-2026-40467/</link><description>CERT Polska has received a report about 4 vulnerabilities (from CVE-2026-40467 to CVE-2026-40469 and CVE-2026-40553) found in GNU gawk software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 13 Jul 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-07-13:/en/posts/2026/07/CVE-2026-40467/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in BitWizard mtr software</title><link>https://cert.pl/en/posts/2026/07/CVE-2026-14461/</link><description>Out-of-bounds read vulnerability (CVE-2026-14461) has been found in BitWizard mtr software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 10 Jul 2026 12:55:00 +0100</pubDate><guid>tag:cert.pl,2026-07-10:/en/posts/2026/07/CVE-2026-14461/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in R-SOFT DMS software</title><link>https://cert.pl/en/posts/2026/07/CVE-2026-41876/</link><description>CERT Polska has received a report about 5 vulnerabilities (from CVE-2026-41876 to CVE-2026-41880) found in R-SOFT DMS software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 10 Jul 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-07-10:/en/posts/2026/07/CVE-2026-41876/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in SOPlanning software</title><link>https://cert.pl/en/posts/2026/07/CVE-2026-50644/</link><description>SQL Injection vulnerability (CVE-2026-50644) has been found in SOPlanning software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 09 Jul 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-07-09:/en/posts/2026/07/CVE-2026-50644/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in GNU patch software</title><link>https://cert.pl/en/posts/2026/07/CVE-2026-56288/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2026-56288 and CVE-2026-56289) found in GNU patch software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 09 Jul 2026 09:05:00 +0100</pubDate><guid>tag:cert.pl,2026-07-09:/en/posts/2026/07/CVE-2026-56288/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in OpenIDC liboauth2 software</title><link>https://cert.pl/en/posts/2026/07/CVE-2026-54430/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2026-54430 and CVE-2026-54431) found in OpenIDC liboauth2 software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 02 Jul 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-07-02:/en/posts/2026/07/CVE-2026-54430/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in MyComplianceOffice MCO software</title><link>https://cert.pl/en/posts/2026/07/CVE-2026-53902/</link><description>CERT Polska has received a report about 8 vulnerabilities (from CVE-2026-53902 to CVE-2026-53909) found in MyComplianceOffice MCO software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Wed, 01 Jul 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-07-01:/en/posts/2026/07/CVE-2026-53902/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in KTM System e-BOK software</title><link>https://cert.pl/en/posts/2026/06/CVE-2026-35095/</link><description>CERT Polska has received a report about 4 vulnerabilities (from CVE-2026-35095 to CVE-2026-35098) found in KTM System e-BOK software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 30 Jun 2026 15:55:00 +0100</pubDate><guid>tag:cert.pl,2026-06-30:/en/posts/2026/06/CVE-2026-35095/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in fzf software</title><link>https://cert.pl/en/posts/2026/06/CVE-2026-53432/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2026-53432 and CVE-2026-53433) found in fzf software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 30 Jun 2026 14:55:00 +0100</pubDate><guid>tag:cert.pl,2026-06-30:/en/posts/2026/06/CVE-2026-53432/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in Redeight CMS software</title><link>https://cert.pl/en/posts/2026/06/CVE-2026-53690/</link><description>CERT Polska has received a report about 3 vulnerabilities (from CVE-2026-53690 to CVE-2026-53692) found in Redeight CMS software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 30 Jun 2026 12:55:00 +0100</pubDate><guid>tag:cert.pl,2026-06-30:/en/posts/2026/06/CVE-2026-53690/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Raytha CMS software</title><link>https://cert.pl/en/posts/2026/06/CVE-2026-12076/</link><description>SQL Injection vulnerability (CVE-2026-12076) has been found in Raytha CMS software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 30 Jun 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-06-30:/en/posts/2026/06/CVE-2026-12076/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in libxml2 software</title><link>https://cert.pl/en/posts/2026/06/CVE-2026-11979/</link><description>Stack-based Buffer Overflow vulnerability (CVE-2026-11979) has been found in libxml2 software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 29 Jun 2026 14:20:00 +0100</pubDate><guid>tag:cert.pl,2026-06-29:/en/posts/2026/06/CVE-2026-11979/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in SzafirHost software</title><link>https://cert.pl/en/posts/2026/06/CVE-2026-13165/</link><description>Unrestricted Upload of File with Dangerous Type vulnerability (CVE-2026-13165) has been found in SzafirHost software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 29 Jun 2026 13:55:00 +0100</pubDate><guid>tag:cert.pl,2026-06-29:/en/posts/2026/06/CVE-2026-13165/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in gzip software</title><link>https://cert.pl/en/posts/2026/06/CVE-2026-41991/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2026-41991 and CVE-2026-41992) found in gzip software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 29 Jun 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-06-29:/en/posts/2026/06/CVE-2026-41991/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in DRIMO CMS software</title><link>https://cert.pl/en/posts/2026/06/CVE-2026-11772/</link><description>Reflected Cross-site Scripting vulnerability (CVE-2026-11772) has been found in DRIMO CMS software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 23 Jun 2026 12:55:00 +0100</pubDate><guid>tag:cert.pl,2026-06-23:/en/posts/2026/06/CVE-2026-11772/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Totolink EX1200L router software</title><link>https://cert.pl/en/posts/2026/06/CVE-2026-44089/</link><description>Stack-based Buffer Overflow vulnerability (CVE-2026-44089) has been found in Totolink EX1200L router software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 23 Jun 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-06-23:/en/posts/2026/06/CVE-2026-44089/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in UBB.threads software</title><link>https://cert.pl/en/posts/2026/06/CVE-2026-54219/</link><description>CERT Polska has received a report about 6 vulnerabilities (from CVE-2026-54219 to CVE-2026-54224) found in UBB.threads software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 18 Jun 2026 13:55:00 +0100</pubDate><guid>tag:cert.pl,2026-06-18:/en/posts/2026/06/CVE-2026-54219/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in LMS software</title><link>https://cert.pl/en/posts/2026/06/CVE-2026-40455/</link><description>CERT Polska has received a report about 3 vulnerabilities (from CVE-2026-40455 to CVE-2026-40457) found in LMS (LAN Management System) software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 18 Jun 2026 12:55:00 +0100</pubDate><guid>tag:cert.pl,2026-06-18:/en/posts/2026/06/CVE-2026-40455/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in 8cc compiler</title><link>https://cert.pl/en/posts/2026/06/CVE-2026-50643/</link><description>Out-of-bounds Read vulnerability (CVE-2026-50643) has been found in 8cc compiler.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 18 Jun 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-06-18:/en/posts/2026/06/CVE-2026-50643/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in jansi library</title><link>https://cert.pl/en/posts/2026/06/CVE-2026-8484/</link><description>Heap-based Buffer Overflow vulnerability (CVE-2026-8484) has been found in jansi library.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 16 Jun 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-06-16:/en/posts/2026/06/CVE-2026-8484/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Responsive FileManager software</title><link>https://cert.pl/en/posts/2026/06/CVE-2026-5482/</link><description>Remote Code Execution via Unrestricted File Upload vulnerability (CVE-2026-5482) has been found in Responsive FileManager software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 15 Jun 2026 12:55:00 +0100</pubDate><guid>tag:cert.pl,2026-06-15:/en/posts/2026/06/CVE-2026-5482/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Quick.CMS software</title><link>https://cert.pl/en/posts/2026/06/CVE-2026-11860/</link><description>Deserialization of Untrusted Data vulnerability (CVE-2026-11860) has been found in Quick.CMS software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 15 Jun 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-06-15:/en/posts/2026/06/CVE-2026-11860/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>UNC1151/Ghostwriter phishing campaign targeting Gmail accounts</title><link>https://cert.pl/en/posts/2026/06/UNC1151-gmail-campaign/</link><description>Recently, we have been observing attacks by the UNC1151/Ghostwriter group targeting Gmail accounts. This group has been regularly attacking the mailboxes of Polish citizens for several years, although in the past these attacks focused on other email providers. The techniques used evolve over time, but the core theme of the messages and their objective remain unchanged.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 12 Jun 2026 12:00:00 +0100</pubDate><guid>tag:cert.pl,2026-06-12:/en/posts/2026/06/UNC1151-gmail-campaign/</guid><category>News</category><category>phishing</category><category>threat</category><category>unc1151</category></item><item><title>Vulnerability in Golem OEE MES software</title><link>https://cert.pl/en/posts/2026/06/CVE-2026-8464/</link><description>Path Traversal vulnerability (CVE-2026-8464) has been found in Golem OEE MES software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 11 Jun 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-06-11:/en/posts/2026/06/CVE-2026-8464/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Aix-DB software</title><link>https://cert.pl/en/posts/2026/06/CVE-2026-8335/</link><description>Missing Authentication for Critical Function vulnerability (CVE-2026-8335) has been found in Aix-DB software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Wed, 10 Jun 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-06-10:/en/posts/2026/06/CVE-2026-8335/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in Logseq software</title><link>https://cert.pl/en/posts/2026/06/CVE-2026-9279/</link><description>CERT Polska has received a report about 4 vulnerabilities (CVE-2026-9279 and from CVE-2026-47899 to CVE-2026-47901) found in Logseq software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 09 Jun 2026 14:55:00 +0100</pubDate><guid>tag:cert.pl,2026-06-09:/en/posts/2026/06/CVE-2026-9279/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in school-management-system software</title><link>https://cert.pl/en/posts/2026/06/CVE-2026-47324/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2026-47324 and CVE-2026-47325) found in school-management-system software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Wed, 03 Jun 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-06-03:/en/posts/2026/06/CVE-2026-47324/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in Wirtualna Uczelnia software</title><link>https://cert.pl/en/posts/2026/06/CVE-2026-34906/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2026-34906 and CVE-2026-34907) found in Wirtualna Uczelnia software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 02 Jun 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-06-02:/en/posts/2026/06/CVE-2026-34906/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in KS-SOMED software</title><link>https://cert.pl/en/posts/2026/06/CVE-2026-42251/</link><description>Use of Hard-coded Credentials vulnerability (CVE-2026-42251) has been found in KS-SOMED software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 01 Jun 2026 13:55:00 +0100</pubDate><guid>tag:cert.pl,2026-06-01:/en/posts/2026/06/CVE-2026-42251/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in SOPlanning software</title><link>https://cert.pl/en/posts/2026/06/CVE-2026-40543/</link><description>CERT Polska has received a report about 7 vulnerabilities (from CVE-2026-40543 to CVE-2026-40549) found in SOPlanning software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 01 Jun 2026 09:55:00 +0100</pubDate><guid>tag:cert.pl,2026-06-01:/en/posts/2026/06/CVE-2026-40543/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in QuickCMS software</title><link>https://cert.pl/en/posts/2026/05/CVE-2026-33384/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2026-33384 and CVE-2026-33386) found in QuickCMS software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 29 May 2026 15:15:00 +0100</pubDate><guid>tag:cert.pl,2026-05-29:/en/posts/2026/05/CVE-2026-33384/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Kidsview application</title><link>https://cert.pl/en/posts/2026/05/CVE-2026-8990/</link><description>Authentication Bypass vulnerability (CVE-2026-8990) has been found in Kidsview software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 28 May 2026 14:55:00 +0100</pubDate><guid>tag:cert.pl,2026-05-28:/en/posts/2026/05/CVE-2026-8990/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in bzip2 software</title><link>https://cert.pl/en/posts/2026/05/CVE-2026-42250/</link><description>Out-of-bounds Write vulnerability (CVE-2026-42250) has been found in bzip2 software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 28 May 2026 13:15:00 +0100</pubDate><guid>tag:cert.pl,2026-05-28:/en/posts/2026/05/CVE-2026-42250/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in D-Link DWR-X1820 router</title><link>https://cert.pl/en/posts/2026/05/CVE-2026-4377/</link><description>Use of Weak Credentials vulnerability (CVE-2026-4377) has been found in DWR-X1820 router.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 28 May 2026 12:55:00 +0100</pubDate><guid>tag:cert.pl,2026-05-28:/en/posts/2026/05/CVE-2026-4377/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in Slican telephone exchanges software</title><link>https://cert.pl/en/posts/2026/05/CVE-2026-35087/</link><description>CERT Polska has received a report about 3 vulnerabilities (CVE-2026-35087, CVE-2026-35089 and CVE-2026-35090) found in Slican telephone exchanges software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Wed, 27 May 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-05-27:/en/posts/2026/05/CVE-2026-35087/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Szafir SDK software</title><link>https://cert.pl/en/posts/2026/05/CVE-2026-9058/</link><description>Improper Certificate Verification vulnerability (CVE-2026-9058) has been found in Szafir SDK software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 25 May 2026 15:55:00 +0100</pubDate><guid>tag:cert.pl,2026-05-25:/en/posts/2026/05/CVE-2026-9058/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Kenik cameras software</title><link>https://cert.pl/en/posts/2026/05/CVE-2026-7766/</link><description>Path Traversal vulnerability (CVE-2026-7766) has been found in Kenik cameras software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 25 May 2026 12:55:00 +0100</pubDate><guid>tag:cert.pl,2026-05-25:/en/posts/2026/05/CVE-2026-7766/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Lifetime software</title><link>https://cert.pl/en/posts/2026/05/CVE-2026-40127/</link><description>Authorization Bypass Through User-Controlled Key vulnerability (CVE-2026-40127) has been found in OutSystems Lifetime software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 25 May 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-05-25:/en/posts/2026/05/CVE-2026-40127/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in vifm software</title><link>https://cert.pl/en/posts/2026/05/CVE-2026-8997/</link><description>Heap-based Buffer Overflow vulnerability (CVE-2026-8997) has been found in vifm software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 22 May 2026 14:55:00 +0100</pubDate><guid>tag:cert.pl,2026-05-22:/en/posts/2026/05/CVE-2026-8997/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in STER software</title><link>https://cert.pl/en/posts/2026/05/CVE-2026-25606/</link><description>CERT Polska has received a report about 3 vulnerabilities (from CVE-2026-25606 to CVE-2026-25608) found in STER software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 22 May 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-05-22:/en/posts/2026/05/CVE-2026-25606/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Autonomous fuzzing process under LLM supervision</title><link>https://cert.pl/en/posts/2026/05/autonomous-fuzzing/</link><description>&lt;p&gt;&lt;em&gt;The CCN project is co-financed by the European Regional Development Fund and the State Budget under the European Funds for Digital Development Programme 2021-2027.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;img alt="European Funds logo bar" src="https://cert.pl/en/uploads/2026/05/Belka_FE_RP_UE_CCN_poziom.png"&gt;&lt;/p&gt;
&lt;p&gt;Fuzzing is an automated software testing technique that involves feeding random or deliberately malformed input data to detect bugs and security vulnerabilities. For years it has …&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 21 May 2026 13:37:00 +0100</pubDate><guid>tag:cert.pl,2026-05-21:/en/posts/2026/05/autonomous-fuzzing/</guid><category>News</category><category>fuzzing</category></item><item><title>Vulnerability in Request Tracker software</title><link>https://cert.pl/en/posts/2026/05/CVE-2026-6841/</link><description>Cross-site Scripting vulnerability (CVE-2026-6841) has been found in Request Tracker software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 21 May 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-05-21:/en/posts/2026/05/CVE-2026-6841/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in Sparx Systems products</title><link>https://cert.pl/en/posts/2026/05/CVE-2026-42096/</link><description>CERT Polska has received a report about 5 vulnerabilities (from CVE-2026-42096 to CVE-2026-42100) found in Sparx Systems products: Pro Cloud Server and Enterprise Architect.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 19 May 2026 10:55:00 +0100</pubDate><guid>tag:cert.pl,2026-05-19:/en/posts/2026/05/CVE-2026-42096/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in DHTMLX software</title><link>https://cert.pl/en/posts/2026/05/CVE-2026-7182/</link><description>CERT Polska has received a report about 3 vulnerabilities (CVE-2026-7182, CVE-2026-41552 and CVE-2026-41553) found in DHTMLX software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 15 May 2026 12:55:00 +0100</pubDate><guid>tag:cert.pl,2026-05-15:/en/posts/2026/05/CVE-2026-7182/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in SzafirHost software</title><link>https://cert.pl/en/posts/2026/05/CVE-2026-44088/</link><description>Unrestricted Upload of File with Dangerous Type vulnerability (CVE-2026-44088) has been found in SzafirHost software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 15 May 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-05-15:/en/posts/2026/05/CVE-2026-44088/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Verint Verba software</title><link>https://cert.pl/en/posts/2026/05/CVE-2026-21730/</link><description>Cross-site Scripting vulnerability (CVE-2026-21730) has been found in Verba software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 14 May 2026 15:00:00 +0100</pubDate><guid>tag:cert.pl,2026-05-14:/en/posts/2026/05/CVE-2026-21730/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in WEBCON BPS software</title><link>https://cert.pl/en/posts/2026/05/CVE-2026-1630/</link><description>Cross-site Scripting vulnerability (CVE-2026-1630) has been found in WEBCON BPS software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 14 May 2026 14:55:00 +0100</pubDate><guid>tag:cert.pl,2026-05-14:/en/posts/2026/05/CVE-2026-1630/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in Comarch ERP Optima software</title><link>https://cert.pl/en/posts/2026/05/CVE-2025-68420/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2025-68420 and CVE-2025-68421) found in Comarch ERP Optima software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 14 May 2026 13:55:00 +0100</pubDate><guid>tag:cert.pl,2026-05-14:/en/posts/2026/05/CVE-2025-68420/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in simdjson library</title><link>https://cert.pl/en/posts/2026/05/CVE-2026-8295/</link><description>Integer Overflow vulnerability (CVE-2026-8295) has been found in simdjson library.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 14 May 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-05-14:/en/posts/2026/05/CVE-2026-8295/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Code Runner MCP Server project</title><link>https://cert.pl/en/posts/2026/05/CVE-2026-5029/</link><description>Missing Authentication for Critical Function vulnerability (CVE-2026-5029) has been found in Code Runner MCP Server software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 12 May 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-05-12:/en/posts/2026/05/CVE-2026-5029/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in ATutor software</title><link>https://cert.pl/en/posts/2026/05/CVE-2026-6909/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2026-6909 and CVE-2026-6956) found in ATutor software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 11 May 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-05-11:/en/posts/2026/05/CVE-2026-6909/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in GW1101-1D(RS-485)-TB-P modbus gateways</title><link>https://cert.pl/en/posts/2026/05/CVE-2025-13605/</link><description>OS Command Injection vulnerability (CVE-2025-13605) has been found in 3onedata GW1101-1D(RS-485)-TB-P modbus gateways.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 04 May 2026 15:55:00 +0100</pubDate><guid>tag:cert.pl,2026-05-04:/en/posts/2026/05/CVE-2025-13605/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in LEX Baza Dokumentów software</title><link>https://cert.pl/en/posts/2026/04/CVE-2026-1493/</link><description>Cross-site Scripting vulnerability (CVE-2026-1493) has been found in LEX Baza Dokumentów software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 30 Apr 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-04-30:/en/posts/2026/04/CVE-2026-1493/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in Ollama software</title><link>https://cert.pl/en/posts/2026/04/CVE-2026-42248/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2026-42248 and CVE-2026-42249) found in Ollama software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Wed, 29 Apr 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-04-29:/en/posts/2026/04/CVE-2026-42248/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in mpGabinet software</title><link>https://cert.pl/en/posts/2026/04/CVE-2026-40550/</link><description>CERT Polska has received a report about 3 vulnerabilities (from CVE-2026-40550 to CVE-2026-40552) found in mpGabinet software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 28 Apr 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-04-28:/en/posts/2026/04/CVE-2026-40550/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in AdaptiveGRC software</title><link>https://cert.pl/en/posts/2026/04/CVE-2026-4313/</link><description>Cross-site Scripting vulnerability (CVE-2026-4313) has been found in AdaptiveGRC software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 24 Apr 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-04-24:/en/posts/2026/04/CVE-2026-4313/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in GNU sed software</title><link>https://cert.pl/en/posts/2026/04/CVE-2026-5958/</link><description>Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability (CVE-2026-5958) has been found in GNU sed software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 20 Apr 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-04-20:/en/posts/2026/04/CVE-2026-5958/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Fudo Enterprise software</title><link>https://cert.pl/en/posts/2026/04/CVE-2025-13480/</link><description>Incorrect Authorization vulnerability (CVE-2025-13480) has been found in Fudo Enterprise software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 20 Apr 2026 10:55:00 +0100</pubDate><guid>tag:cert.pl,2026-04-20:/en/posts/2026/04/CVE-2025-13480/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in PAC4J software</title><link>https://cert.pl/en/posts/2026/04/CVE-2026-40458/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2026-40458, CVE-2026-40459) found in PAC4J software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 17 Apr 2026 14:55:00 +0100</pubDate><guid>tag:cert.pl,2026-04-17:/en/posts/2026/04/CVE-2026-40458/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in GREENmod software</title><link>https://cert.pl/en/posts/2026/04/CVE-2026-5131/</link><description>Server-Side Request Forgery (SSRF) vulnerability (CVE-2026-5131) has been found in GREENmod software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 17 Apr 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-04-17:/en/posts/2026/04/CVE-2026-5131/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in MCPHub software</title><link>https://cert.pl/en/posts/2026/04/CVE-2025-13822/</link><description>Authorization bypass vulnerability (CVE-2025-13822) has been found in MCPHub project.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 14 Apr 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-04-14:/en/posts/2026/04/CVE-2025-13822/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in Hydrosystem Control System software</title><link>https://cert.pl/en/posts/2026/04/CVE-2026-4901/</link><description>CERT Polska has received a report about 3 vulnerabilities (CVE-2026-4901, CVE-2026-34184, CVE-2026-34185) found in Hydrosystem Control System software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 09 Apr 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-04-09:/en/posts/2026/04/CVE-2026-4901/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Annual report from the actions of CERT Polska 2025</title><link>https://cert.pl/en/posts/2026/04/annual-report-2025/</link><description>Another year of CERT Polska’s activities is behind us. It was a special one, as it marked the end of the third decade of our operations – we are celebrating our 30th anniversary! The year 2025 was a time full of challenges, growth, and a comprehensive approach to shaping cybersecurity – from proactive threat detection, through handling reports and responding to incidents, to sharing knowledge and building public awareness.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Wed, 08 Apr 2026 09:00:00 +0200</pubDate><guid>tag:cert.pl,2026-04-08:/en/posts/2026/04/annual-report-2025/</guid><category>News</category><category>annual report</category><category>report</category></item><item><title>Vulnerabilities in Mlflow software</title><link>https://cert.pl/en/posts/2026/04/CVE-2026-33865/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2026-33865, CVE-2026-33866) found in Mlflow software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 07 Apr 2026 13:55:00 +0100</pubDate><guid>tag:cert.pl,2026-04-07:/en/posts/2026/04/CVE-2026-33865/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Bludit software</title><link>https://cert.pl/en/posts/2026/04/CVE-2026-4420/</link><description>CERT Polska has received a report about a Stored Cross-site Scripting vulnerability found in Bludit software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 07 Apr 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-04-07:/en/posts/2026/04/CVE-2026-4420/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Analysis of cifrat: could this be an evolution of a mobile RAT?</title><link>https://cert.pl/en/posts/2026/04/cifrat-analysis/</link><description>CERT Polska analyzed a Booking themed Android malware chain delivered through phishing and a fake update website. The sample is a multistage dropper that installs a hidden accessibility controlled RAT with WebSocket C2.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Kacper Ratajczak</dc:creator><pubDate>Fri, 03 Apr 2026 12:00:00 +0200</pubDate><guid>tag:cert.pl,2026-04-03:/en/posts/2026/04/cifrat-analysis/</guid><category>News</category><category>android</category><category>analysis</category><category>booking</category><category>banker</category><category>rat</category></item><item><title>Vulnerabilities in Szafir software</title><link>https://cert.pl/en/posts/2026/04/CVE-2026-26927/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2026-26927, CVE-2026-26928) found in Szafir software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 02 Apr 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-04-02:/en/posts/2026/04/CVE-2026-26927/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Analysis of FvncBot campaign</title><link>https://cert.pl/en/posts/2026/03/fvncbot-analysis/</link><description>CERT Polska has analyzed an SGB-branded Android malware sample from the FvncBot campaign targeting Poland. The app installs a second-stage implant, coerces the victim into enabling accessibility, and registers the device to a backend that issues per-device credentials.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Kacper Ratajczak</dc:creator><pubDate>Mon, 30 Mar 2026 14:00:00 +0100</pubDate><guid>tag:cert.pl,2026-03-30:/en/posts/2026/03/fvncbot-analysis/</guid><category>News</category><category>android</category><category>analysis</category><category>fvncbot</category></item><item><title>Vulnerability in Robolinho Update Software</title><link>https://cert.pl/en/posts/2026/03/CVE-2026-1612/</link><description>Use of Hard-coded Credentials vulnerability (CVE-2026-1612) has been found in Robolinho Update Software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 30 Mar 2026 09:55:00 +0100</pubDate><guid>tag:cert.pl,2026-03-30:/en/posts/2026/03/CVE-2026-1612/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in Bludit software</title><link>https://cert.pl/en/posts/2026/03/CVE-2026-25099/</link><description>CERT Polska has received a report about 3 vulnerabilities (from CVE-2026-25099 to CVE-2026-25101) found in Bludit software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 27 Mar 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-03-27:/en/posts/2026/03/CVE-2026-25099/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in KlinikaXP and KlinikaXP Insertino software</title><link>https://cert.pl/en/posts/2026/03/CVE-2026-1958/</link><description>Use of Hard-coded Credentials vulnerability (CVE-2026-1958) has been found in KlinikaXP and KlinikaXP Insertino software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 23 Mar 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-03-23:/en/posts/2026/03/CVE-2026-1958/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Befree SDK software</title><link>https://cert.pl/en/posts/2026/03/CVE-2025-12518/</link><description>Cross-site Scripting vulnerability (CVE-2025-12518) has been found in Befree SDK software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Wed, 18 Mar 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-03-18:/en/posts/2026/03/CVE-2025-12518/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in Raytha software</title><link>https://cert.pl/en/posts/2026/03/CVE-2025-69236/</link><description>CERT Polska has received a report about 11 vulnerabilities (CVE-2025-15540 and from CVE-2025-69236 to CVE-2025-69243 and from CVE-2025-69245 to CVE-2025-69246) found in Raytha software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 16 Mar 2026 13:55:00 +0100</pubDate><guid>tag:cert.pl,2026-03-16:/en/posts/2026/03/CVE-2025-69236/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in multiple tinycontrol devices</title><link>https://cert.pl/en/posts/2026/03/CVE-2025-11500/</link><description>CERT Polska has received reports about 2 vulnerabilities (CVE-2025-11500 and CVE-2025-15587) found in multiple tinycontrol devices (tcPDU and LAN Controllers: LK3.5, LK3.9 and LK4).</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 16 Mar 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-03-16:/en/posts/2026/03/CVE-2025-11500/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Streamsoft Prestiż software</title><link>https://cert.pl/en/posts/2026/03/CVE-2026-0809/</link><description>Weak Token Encoding vulnerability (CVE-2026-0809) has been found in Streamsoft Prestiż software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 12 Mar 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-03-12:/en/posts/2026/03/CVE-2026-0809/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Coppermine Photo Gallery software</title><link>https://cert.pl/en/posts/2026/03/CVE-2026-3013/</link><description>Path Traversal vulnerability (CVE-2026-3013) has been found in Coppermine Photo Gallery software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Wed, 11 Mar 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-03-11:/en/posts/2026/03/CVE-2026-3013/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in QuickCMS software</title><link>https://cert.pl/en/posts/2026/03/CVE-2026-1468/</link><description>Cross-Site Request Forgery (CSRF) vulnerability (CVE-2026-1468) has been found in QuickCMS software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 06 Mar 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-03-06:/en/posts/2026/03/CVE-2026-1468/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in DobryCMS software</title><link>https://cert.pl/en/posts/2026/03/CVE-2025-12462/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2025-12462 and CVE-2025-14532) found in DobryCMS software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 02 Mar 2026 13:55:00 +0100</pubDate><guid>tag:cert.pl,2026-03-02:/en/posts/2026/03/CVE-2025-12462/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in CGM CLININET and CGM NETRAAD software</title><link>https://cert.pl/en/posts/2026/03/CVE-2025-10350/</link><description>CERT Polska has received reports about 8 vulnerabilities found in CGM CLININET and CGM NETRAAD software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 02 Mar 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-03-02:/en/posts/2026/03/CVE-2025-10350/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Pro3W CMS software</title><link>https://cert.pl/en/posts/2026/02/CVE-2025-15498/</link><description>SQL Injection vulnerability (CVE-2025-15498) has been found in Pro3W CMS software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 27 Feb 2026 13:55:00 +0100</pubDate><guid>tag:cert.pl,2026-02-27:/en/posts/2026/02/CVE-2025-15498/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in PluXml CMS software</title><link>https://cert.pl/en/posts/2026/02/CVE-2026-24350/</link><description>CERT Polska has received a report about 3 vulnerabilities (from CVE-2026-24350 to CVE-2026-24352) found in PluXml CMS software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 27 Feb 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-02-27:/en/posts/2026/02/CVE-2026-24350/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Omega-PSIR software</title><link>https://cert.pl/en/posts/2026/02/CVE-2026-1434/</link><description>Reflected XSS vulnerability (CVE-2026-1434) has been found in Omega-PSIR software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 26 Feb 2026 12:55:00 +0100</pubDate><guid>tag:cert.pl,2026-02-26:/en/posts/2026/02/CVE-2026-1434/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Simple.ERP software</title><link>https://cert.pl/en/posts/2026/02/CVE-2026-1198/</link><description>SQL Injection vulnerability (CVE-2026-1198) has been found in Simple.ERP software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 26 Feb 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-02-26:/en/posts/2026/02/CVE-2026-1198/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in multiple Finka applications</title><link>https://cert.pl/en/posts/2026/02/CVE-2025-13776/</link><description>Use of Hard-coded Credentials vulnerability (CVE-2025-13776) has been found in Finka-FK, Finka-KPR, Finka-Płace, Finka-Faktura, Finka-Magazyn, Finka-STW applications.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 24 Feb 2026 15:55:00 +0100</pubDate><guid>tag:cert.pl,2026-02-24:/en/posts/2026/02/CVE-2025-13776/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in multiple Slican devices</title><link>https://cert.pl/en/posts/2026/02/CVE-2025-14577/</link><description>Missing Authentication for Critical Function vulnerability (CVE-2025-14577) has been found in in multiple Slican devices.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 24 Feb 2026 12:55:00 +0100</pubDate><guid>tag:cert.pl,2026-02-24:/en/posts/2026/02/CVE-2025-14577/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>ClickFix in action: how fake captcha can lead to a company-wide infection</title><link>https://cert.pl/en/posts/2026/02/fake-captcha-in-action/</link><description>We assisted a large organisation in the investigation and remediation of a live malware infection caused by a successful Fake Captcha attack. In this report, we summarize our observations and publish an in-depth malware analysis.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Jarosław Jedynak</dc:creator><pubDate>Tue, 17 Feb 2026 10:00:00 +0200</pubDate><guid>tag:cert.pl,2026-02-17:/en/posts/2026/02/fake-captcha-in-action/</guid><category>News</category><category>malware</category><category>analysis</category><category>dfir</category></item><item><title>Vulnerabilities in Quick.Cart software</title><link>https://cert.pl/en/posts/2026/02/CVE-2026-23796/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2026-23796 and CVE-2026-23797) found in Quick.Cart software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 05 Feb 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-02-05:/en/posts/2026/02/CVE-2026-23796/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in mObywatel application for iOS</title><link>https://cert.pl/en/posts/2026/02/CVE-2025-11598/</link><description>Exposure of Private Personal Information to an Unauthorized Actor vulnerability (CVE-2025-11598) has been found in mObywatel application for iOS.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 03 Feb 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-02-03:/en/posts/2026/02/CVE-2025-11598/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in EAP Legislator software</title><link>https://cert.pl/en/posts/2026/02/CVE-2026-1186/</link><description>A vulnerability has been found in EAP Legislator software that allows a file archive to be extracted outside the target directory (CVE-2026-1186).</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 02 Feb 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-02-02:/en/posts/2026/02/CVE-2026-1186/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Energy Sector Incident Report - 29 December 2025</title><link>https://cert.pl/en/posts/2026/01/incident-report-energy-sector-2025/</link><description>CERT Polska presents a report on the analysis of an incident in the energy sector that occurred on 29 December 2025. The attacks were destructive in nature and targeted wind and photovoltaic farms, a large combined heat and power plant, and a company from the manufacturing sector. The publication aims to raise awareness of the risks associated with sabotage in cyberspace.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 30 Jan 2026 11:00:00 +0100</pubDate><guid>tag:cert.pl,2026-01-30:/en/posts/2026/01/incident-report-energy-sector-2025/</guid><category>News</category><category>report</category><category>incident</category><category>energy</category></item><item><title>Vulnerabilities in firmware of Pix-Link LV-WR21Q routers</title><link>https://cert.pl/en/posts/2026/01/CVE-2025-12386/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2025-12386 and CVE-2025-12387) found in LV-WR21Q firmware.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 27 Jan 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-01-27:/en/posts/2026/01/CVE-2025-12386/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>TCC Bypass vulnerability in Inkscape application for MacOS</title><link>https://cert.pl/en/posts/2026/01/CVE-2025-15523/</link><description>TCC Bypass vulnerability (CVE-2025-15523) has been found in Inkscape application for MacOS.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 22 Jan 2026 13:55:00 +0100</pubDate><guid>tag:cert.pl,2026-01-22:/en/posts/2026/01/CVE-2025-15523/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in Quick.Cart software</title><link>https://cert.pl/en/posts/2026/01/CVE-2025-67683/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2025-67683 and CVE-2025-67684) found in Quick.Cart software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 22 Jan 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-01-22:/en/posts/2026/01/CVE-2025-67683/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item></channel></rss>