<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>CERT Polska</title><link>https://cert.pl/en/</link><description>CERT.PL</description><atom:link href="https://cert.pl/rss.xml" rel="self"/><lastBuildDate>Fri, 29 May 2026 15:15:00 +0100</lastBuildDate><item><title>Vulnerabilities in QuickCMS software</title><link>https://cert.pl/en/posts/2026/05/CVE-2026-33384/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2026-33384 and CVE-2026-33386) found in QuickCMS software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 29 May 2026 15:15:00 +0100</pubDate><guid>tag:cert.pl,2026-05-29:/en/posts/2026/05/CVE-2026-33384/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Kidsview application</title><link>https://cert.pl/en/posts/2026/05/CVE-2026-8990/</link><description>Authentication Bypass vulnerability (CVE-2026-8990) has been found in Kidsview software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 28 May 2026 14:55:00 +0100</pubDate><guid>tag:cert.pl,2026-05-28:/en/posts/2026/05/CVE-2026-8990/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in bzip2 software</title><link>https://cert.pl/en/posts/2026/05/CVE-2026-42250/</link><description>Out-of-bounds Write vulnerability (CVE-2026-42250) has been found in bzip2 software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 28 May 2026 13:15:00 +0100</pubDate><guid>tag:cert.pl,2026-05-28:/en/posts/2026/05/CVE-2026-42250/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in D-Link DWR-X1820 router</title><link>https://cert.pl/en/posts/2026/05/CVE-2026-4377/</link><description>Use of Weak Credentials vulnerability (CVE-2026-4377) has been found in DWR-X1820 router.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 28 May 2026 12:55:00 +0100</pubDate><guid>tag:cert.pl,2026-05-28:/en/posts/2026/05/CVE-2026-4377/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in Slican telephone exchanges software</title><link>https://cert.pl/en/posts/2026/05/CVE-2026-35087/</link><description>CERT Polska has received a report about 3 vulnerabilities (CVE-2026-35087, CVE-2026-35089 and CVE-2026-35090) found in Slican telephone exchanges software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Wed, 27 May 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-05-27:/en/posts/2026/05/CVE-2026-35087/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Szafir SDK software</title><link>https://cert.pl/en/posts/2026/05/CVE-2026-9058/</link><description>Improper Certificate Verification vulnerability (CVE-2026-9058) has been found in Szafir SDK software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 25 May 2026 15:55:00 +0100</pubDate><guid>tag:cert.pl,2026-05-25:/en/posts/2026/05/CVE-2026-9058/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Kenik cameras software</title><link>https://cert.pl/en/posts/2026/05/CVE-2026-7766/</link><description>Path Traversal vulnerability (CVE-2026-7766) has been found in Kenik cameras software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 25 May 2026 12:55:00 +0100</pubDate><guid>tag:cert.pl,2026-05-25:/en/posts/2026/05/CVE-2026-7766/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Lifetime software</title><link>https://cert.pl/en/posts/2026/05/CVE-2026-40127/</link><description>Authorization Bypass Through User-Controlled Key vulnerability (CVE-2026-40127) has been found in OutSystems Lifetime software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 25 May 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-05-25:/en/posts/2026/05/CVE-2026-40127/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in vifm software</title><link>https://cert.pl/en/posts/2026/05/CVE-2026-8997/</link><description>Heap-based Buffer Overflow vulnerability (CVE-2026-8997) has been found in vifm software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 22 May 2026 14:55:00 +0100</pubDate><guid>tag:cert.pl,2026-05-22:/en/posts/2026/05/CVE-2026-8997/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in STER software</title><link>https://cert.pl/en/posts/2026/05/CVE-2026-25606/</link><description>CERT Polska has received a report about 3 vulnerabilities (from CVE-2026-25606 to CVE-2026-25608) found in STER software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 22 May 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-05-22:/en/posts/2026/05/CVE-2026-25606/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Autonomous fuzzing process under LLM supervision</title><link>https://cert.pl/en/posts/2026/05/autonomous-fuzzing/</link><description>&lt;p&gt;&lt;em&gt;The CCN project is co-financed by the European Regional Development Fund and the State Budget under the European Funds for Digital Development Programme 2021-2027.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;img alt="European Funds logo bar" src="https://cert.pl/en/uploads/2026/05/Belka_FE_RP_UE_CCN_poziom.png"&gt;&lt;/p&gt;
&lt;p&gt;Fuzzing is an automated software testing technique that involves feeding random or deliberately malformed input data to detect bugs and security vulnerabilities. For years it has …&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 21 May 2026 13:37:00 +0100</pubDate><guid>tag:cert.pl,2026-05-21:/en/posts/2026/05/autonomous-fuzzing/</guid><category>News</category><category>fuzzing</category></item><item><title>Vulnerability in Request Tracker software</title><link>https://cert.pl/en/posts/2026/05/CVE-2026-6841/</link><description>Cross-site Scripting vulnerability (CVE-2026-6841) has been found in Request Tracker software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 21 May 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-05-21:/en/posts/2026/05/CVE-2026-6841/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in Sparx Systems products</title><link>https://cert.pl/en/posts/2026/05/CVE-2026-42096/</link><description>CERT Polska has received a report about 5 vulnerabilities (from CVE-2026-42096 to CVE-2026-42100) found in Sparx Systems products: Pro Cloud Server and Enterprise Architect.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 19 May 2026 10:55:00 +0100</pubDate><guid>tag:cert.pl,2026-05-19:/en/posts/2026/05/CVE-2026-42096/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in DHTMLX software</title><link>https://cert.pl/en/posts/2026/05/CVE-2026-7182/</link><description>CERT Polska has received a report about 3 vulnerabilities (CVE-2026-7182, CVE-2026-41552 and CVE-2026-41553) found in DHTMLX software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 15 May 2026 12:55:00 +0100</pubDate><guid>tag:cert.pl,2026-05-15:/en/posts/2026/05/CVE-2026-7182/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in SzafirHost software</title><link>https://cert.pl/en/posts/2026/05/CVE-2026-44088/</link><description>Unrestricted Upload of File with Dangerous Type vulnerability (CVE-2026-44088) has been found in SzafirHost software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 15 May 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-05-15:/en/posts/2026/05/CVE-2026-44088/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Verint Verba software</title><link>https://cert.pl/en/posts/2026/05/CVE-2026-21730/</link><description>Cross-site Scripting vulnerability (CVE-2026-21730) has been found in Verba software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 14 May 2026 15:00:00 +0100</pubDate><guid>tag:cert.pl,2026-05-14:/en/posts/2026/05/CVE-2026-21730/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in WEBCON BPS software</title><link>https://cert.pl/en/posts/2026/05/CVE-2026-1630/</link><description>Cross-site Scripting vulnerability (CVE-2026-1630) has been found in WEBCON BPS software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 14 May 2026 14:55:00 +0100</pubDate><guid>tag:cert.pl,2026-05-14:/en/posts/2026/05/CVE-2026-1630/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in Comarch ERP Optima software</title><link>https://cert.pl/en/posts/2026/05/CVE-2025-68420/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2025-68420 and CVE-2025-68421) found in Comarch ERP Optima software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 14 May 2026 13:55:00 +0100</pubDate><guid>tag:cert.pl,2026-05-14:/en/posts/2026/05/CVE-2025-68420/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in simdjson library</title><link>https://cert.pl/en/posts/2026/05/CVE-2026-8295/</link><description>Integer Overflow vulnerability (CVE-2026-8295) has been found in simdjson library.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 14 May 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-05-14:/en/posts/2026/05/CVE-2026-8295/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Code Runner MCP Server project</title><link>https://cert.pl/en/posts/2026/05/CVE-2026-5029/</link><description>Missing Authentication for Critical Function vulnerability (CVE-2026-5029) has been found in Code Runner MCP Server software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 12 May 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-05-12:/en/posts/2026/05/CVE-2026-5029/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in ATutor software</title><link>https://cert.pl/en/posts/2026/05/CVE-2026-6909/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2026-6909 and CVE-2026-6956) found in ATutor software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 11 May 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-05-11:/en/posts/2026/05/CVE-2026-6909/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in GW1101-1D(RS-485)-TB-P modbus gateways</title><link>https://cert.pl/en/posts/2026/05/CVE-2025-13605/</link><description>OS Command Injection vulnerability (CVE-2025-13605) has been found in 3onedata GW1101-1D(RS-485)-TB-P modbus gateways.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 04 May 2026 15:55:00 +0100</pubDate><guid>tag:cert.pl,2026-05-04:/en/posts/2026/05/CVE-2025-13605/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in LEX Baza Dokumentów software</title><link>https://cert.pl/en/posts/2026/04/CVE-2026-1493/</link><description>Cross-site Scripting vulnerability (CVE-2026-1493) has been found in LEX Baza Dokumentów software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 30 Apr 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-04-30:/en/posts/2026/04/CVE-2026-1493/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in Ollama software</title><link>https://cert.pl/en/posts/2026/04/CVE-2026-42248/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2026-42248 and CVE-2026-42249) found in Ollama software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Wed, 29 Apr 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-04-29:/en/posts/2026/04/CVE-2026-42248/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in mpGabinet software</title><link>https://cert.pl/en/posts/2026/04/CVE-2026-40550/</link><description>CERT Polska has received a report about 3 vulnerabilities (from CVE-2026-40550 to CVE-2026-40552) found in mpGabinet software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 28 Apr 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-04-28:/en/posts/2026/04/CVE-2026-40550/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in AdaptiveGRC software</title><link>https://cert.pl/en/posts/2026/04/CVE-2026-4313/</link><description>Cross-site Scripting vulnerability (CVE-2026-4313) has been found in AdaptiveGRC software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 24 Apr 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-04-24:/en/posts/2026/04/CVE-2026-4313/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in GNU sed software</title><link>https://cert.pl/en/posts/2026/04/CVE-2026-5958/</link><description>Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability (CVE-2026-5958) has been found in GNU sed software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 20 Apr 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-04-20:/en/posts/2026/04/CVE-2026-5958/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Fudo Enterprise software</title><link>https://cert.pl/en/posts/2026/04/CVE-2025-13480/</link><description>Incorrect Authorization vulnerability (CVE-2025-13480) has been found in Fudo Enterprise software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 20 Apr 2026 10:55:00 +0100</pubDate><guid>tag:cert.pl,2026-04-20:/en/posts/2026/04/CVE-2025-13480/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in PAC4J software</title><link>https://cert.pl/en/posts/2026/04/CVE-2026-40458/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2026-40458, CVE-2026-40459) found in PAC4J software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 17 Apr 2026 14:55:00 +0100</pubDate><guid>tag:cert.pl,2026-04-17:/en/posts/2026/04/CVE-2026-40458/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in GREENmod software</title><link>https://cert.pl/en/posts/2026/04/CVE-2026-5131/</link><description>Server-Side Request Forgery (SSRF) vulnerability (CVE-2026-5131) has been found in GREENmod software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 17 Apr 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-04-17:/en/posts/2026/04/CVE-2026-5131/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in MCPHub software</title><link>https://cert.pl/en/posts/2026/04/CVE-2025-13822/</link><description>Authorization bypass vulnerability (CVE-2025-13822) has been found in MCPHub project.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 14 Apr 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-04-14:/en/posts/2026/04/CVE-2025-13822/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in Hydrosystem Control System software</title><link>https://cert.pl/en/posts/2026/04/CVE-2026-4901/</link><description>CERT Polska has received a report about 3 vulnerabilities (CVE-2026-4901, CVE-2026-34184, CVE-2026-34185) found in Hydrosystem Control System software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 09 Apr 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-04-09:/en/posts/2026/04/CVE-2026-4901/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Annual report from the actions of CERT Polska 2025</title><link>https://cert.pl/en/posts/2026/04/annual-report-2025/</link><description>Another year of CERT Polska’s activities is behind us. It was a special one, as it marked the end of the third decade of our operations – we are celebrating our 30th anniversary! The year 2025 was a time full of challenges, growth, and a comprehensive approach to shaping cybersecurity – from proactive threat detection, through handling reports and responding to incidents, to sharing knowledge and building public awareness.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Wed, 08 Apr 2026 09:00:00 +0200</pubDate><guid>tag:cert.pl,2026-04-08:/en/posts/2026/04/annual-report-2025/</guid><category>News</category><category>annual report</category><category>report</category></item><item><title>Vulnerabilities in Mlflow software</title><link>https://cert.pl/en/posts/2026/04/CVE-2026-33865/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2026-33865, CVE-2026-33866) found in Mlflow software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 07 Apr 2026 13:55:00 +0100</pubDate><guid>tag:cert.pl,2026-04-07:/en/posts/2026/04/CVE-2026-33865/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Bludit software</title><link>https://cert.pl/en/posts/2026/04/CVE-2026-4420/</link><description>CERT Polska has received a report about a Stored Cross-site Scripting vulnerability found in Bludit software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 07 Apr 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-04-07:/en/posts/2026/04/CVE-2026-4420/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Analysis of cifrat: could this be an evolution of a mobile RAT?</title><link>https://cert.pl/en/posts/2026/04/cifrat-analysis/</link><description>CERT Polska analyzed a Booking themed Android malware chain delivered through phishing and a fake update website. The sample is a multistage dropper that installs a hidden accessibility controlled RAT with WebSocket C2.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Kacper Ratajczak</dc:creator><pubDate>Fri, 03 Apr 2026 12:00:00 +0200</pubDate><guid>tag:cert.pl,2026-04-03:/en/posts/2026/04/cifrat-analysis/</guid><category>News</category><category>android</category><category>analysis</category><category>booking</category><category>banker</category><category>rat</category></item><item><title>Vulnerabilities in Szafir software</title><link>https://cert.pl/en/posts/2026/04/CVE-2026-26927/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2026-26927, CVE-2026-26928) found in Szafir software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 02 Apr 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-04-02:/en/posts/2026/04/CVE-2026-26927/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Analysis of FvncBot campaign</title><link>https://cert.pl/en/posts/2026/03/fvncbot-analysis/</link><description>CERT Polska has analyzed an SGB-branded Android malware sample from the FvncBot campaign targeting Poland. The app installs a second-stage implant, coerces the victim into enabling accessibility, and registers the device to a backend that issues per-device credentials.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Kacper Ratajczak</dc:creator><pubDate>Mon, 30 Mar 2026 14:00:00 +0100</pubDate><guid>tag:cert.pl,2026-03-30:/en/posts/2026/03/fvncbot-analysis/</guid><category>News</category><category>android</category><category>analysis</category><category>fvncbot</category></item><item><title>Vulnerability in Robolinho Update Software</title><link>https://cert.pl/en/posts/2026/03/CVE-2026-1612/</link><description>Use of Hard-coded Credentials vulnerability (CVE-2026-1612) has been found in Robolinho Update Software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 30 Mar 2026 09:55:00 +0100</pubDate><guid>tag:cert.pl,2026-03-30:/en/posts/2026/03/CVE-2026-1612/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in Bludit software</title><link>https://cert.pl/en/posts/2026/03/CVE-2026-25099/</link><description>CERT Polska has received a report about 3 vulnerabilities (from CVE-2026-25099 to CVE-2026-25101) found in Bludit software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 27 Mar 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-03-27:/en/posts/2026/03/CVE-2026-25099/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in KlinikaXP and KlinikaXP Insertino software</title><link>https://cert.pl/en/posts/2026/03/CVE-2026-1958/</link><description>Use of Hard-coded Credentials vulnerability (CVE-2026-1958) has been found in KlinikaXP and KlinikaXP Insertino software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 23 Mar 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-03-23:/en/posts/2026/03/CVE-2026-1958/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Befree SDK software</title><link>https://cert.pl/en/posts/2026/03/CVE-2025-12518/</link><description>Cross-site Scripting vulnerability (CVE-2025-12518) has been found in Befree SDK software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Wed, 18 Mar 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-03-18:/en/posts/2026/03/CVE-2025-12518/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in Raytha software</title><link>https://cert.pl/en/posts/2026/03/CVE-2025-69236/</link><description>CERT Polska has received a report about 11 vulnerabilities (CVE-2025-15540 and from CVE-2025-69236 to CVE-2025-69243 and from CVE-2025-69245 to CVE-2025-69246) found in Raytha software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 16 Mar 2026 13:55:00 +0100</pubDate><guid>tag:cert.pl,2026-03-16:/en/posts/2026/03/CVE-2025-69236/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in multiple tinycontrol devices</title><link>https://cert.pl/en/posts/2026/03/CVE-2025-11500/</link><description>CERT Polska has received reports about 2 vulnerabilities (CVE-2025-11500 and CVE-2025-15587) found in multiple tinycontrol devices (tcPDU and LAN Controllers: LK3.5, LK3.9 and LK4).</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 16 Mar 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-03-16:/en/posts/2026/03/CVE-2025-11500/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Streamsoft Prestiż software</title><link>https://cert.pl/en/posts/2026/03/CVE-2026-0809/</link><description>Weak Token Encoding vulnerability (CVE-2026-0809) has been found in Streamsoft Prestiż software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 12 Mar 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-03-12:/en/posts/2026/03/CVE-2026-0809/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Coppermine Photo Gallery software</title><link>https://cert.pl/en/posts/2026/03/CVE-2026-3013/</link><description>Path Traversal vulnerability (CVE-2026-3013) has been found in Coppermine Photo Gallery software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Wed, 11 Mar 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-03-11:/en/posts/2026/03/CVE-2026-3013/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in QuickCMS software</title><link>https://cert.pl/en/posts/2026/03/CVE-2026-1468/</link><description>Cross-Site Request Forgery (CSRF) vulnerability (CVE-2026-1468) has been found in QuickCMS software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 06 Mar 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-03-06:/en/posts/2026/03/CVE-2026-1468/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in DobryCMS software</title><link>https://cert.pl/en/posts/2026/03/CVE-2025-12462/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2025-12462 and CVE-2025-14532) found in DobryCMS software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 02 Mar 2026 13:55:00 +0100</pubDate><guid>tag:cert.pl,2026-03-02:/en/posts/2026/03/CVE-2025-12462/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in CGM CLININET and CGM NETRAAD software</title><link>https://cert.pl/en/posts/2026/03/CVE-2025-10350/</link><description>CERT Polska has received reports about 8 vulnerabilities found in CGM CLININET and CGM NETRAAD software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 02 Mar 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-03-02:/en/posts/2026/03/CVE-2025-10350/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Pro3W CMS software</title><link>https://cert.pl/en/posts/2026/02/CVE-2025-15498/</link><description>SQL Injection vulnerability (CVE-2025-15498) has been found in Pro3W CMS software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 27 Feb 2026 13:55:00 +0100</pubDate><guid>tag:cert.pl,2026-02-27:/en/posts/2026/02/CVE-2025-15498/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in PluXml CMS software</title><link>https://cert.pl/en/posts/2026/02/CVE-2026-24350/</link><description>CERT Polska has received a report about 3 vulnerabilities (from CVE-2026-24350 to CVE-2026-24352) found in PluXml CMS software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 27 Feb 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-02-27:/en/posts/2026/02/CVE-2026-24350/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Omega-PSIR software</title><link>https://cert.pl/en/posts/2026/02/CVE-2026-1434/</link><description>Reflected XSS vulnerability (CVE-2026-1434) has been found in Omega-PSIR software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 26 Feb 2026 12:55:00 +0100</pubDate><guid>tag:cert.pl,2026-02-26:/en/posts/2026/02/CVE-2026-1434/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Simple.ERP software</title><link>https://cert.pl/en/posts/2026/02/CVE-2026-1198/</link><description>SQL Injection vulnerability (CVE-2026-1198) has been found in Simple.ERP software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 26 Feb 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-02-26:/en/posts/2026/02/CVE-2026-1198/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in multiple Finka applications</title><link>https://cert.pl/en/posts/2026/02/CVE-2025-13776/</link><description>Use of Hard-coded Credentials vulnerability (CVE-2025-13776) has been found in Finka-FK, Finka-KPR, Finka-Płace, Finka-Faktura, Finka-Magazyn, Finka-STW applications.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 24 Feb 2026 15:55:00 +0100</pubDate><guid>tag:cert.pl,2026-02-24:/en/posts/2026/02/CVE-2025-13776/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in multiple Slican devices</title><link>https://cert.pl/en/posts/2026/02/CVE-2025-14577/</link><description>Missing Authentication for Critical Function vulnerability (CVE-2025-14577) has been found in in multiple Slican devices.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 24 Feb 2026 12:55:00 +0100</pubDate><guid>tag:cert.pl,2026-02-24:/en/posts/2026/02/CVE-2025-14577/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>ClickFix in action: how fake captcha can lead to a company-wide infection</title><link>https://cert.pl/en/posts/2026/02/fake-captcha-in-action/</link><description>We assisted a large organisation in the investigation and remediation of a live malware infection caused by a successful Fake Captcha attack. In this report, we summarize our observations and publish an in-depth malware analysis.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Jarosław Jedynak</dc:creator><pubDate>Tue, 17 Feb 2026 10:00:00 +0200</pubDate><guid>tag:cert.pl,2026-02-17:/en/posts/2026/02/fake-captcha-in-action/</guid><category>News</category><category>malware</category><category>analysis</category><category>dfir</category></item><item><title>Vulnerabilities in Quick.Cart software</title><link>https://cert.pl/en/posts/2026/02/CVE-2026-23796/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2026-23796 and CVE-2026-23797) found in Quick.Cart software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 05 Feb 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-02-05:/en/posts/2026/02/CVE-2026-23796/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in mObywatel application for iOS</title><link>https://cert.pl/en/posts/2026/02/CVE-2025-11598/</link><description>Exposure of Private Personal Information to an Unauthorized Actor vulnerability (CVE-2025-11598) has been found in mObywatel application for iOS.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 03 Feb 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-02-03:/en/posts/2026/02/CVE-2025-11598/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in EAP Legislator software</title><link>https://cert.pl/en/posts/2026/02/CVE-2026-1186/</link><description>A vulnerability has been found in EAP Legislator software that allows a file archive to be extracted outside the target directory (CVE-2026-1186).</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 02 Feb 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-02-02:/en/posts/2026/02/CVE-2026-1186/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Energy Sector Incident Report - 29 December 2025</title><link>https://cert.pl/en/posts/2026/01/incident-report-energy-sector-2025/</link><description>CERT Polska presents a report on the analysis of an incident in the energy sector that occurred on 29 December 2025. The attacks were destructive in nature and targeted wind and photovoltaic farms, a large combined heat and power plant, and a company from the manufacturing sector. The publication aims to raise awareness of the risks associated with sabotage in cyberspace.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 30 Jan 2026 11:00:00 +0100</pubDate><guid>tag:cert.pl,2026-01-30:/en/posts/2026/01/incident-report-energy-sector-2025/</guid><category>News</category><category>report</category><category>incident</category><category>energy</category></item><item><title>Vulnerabilities in firmware of Pix-Link LV-WR21Q routers</title><link>https://cert.pl/en/posts/2026/01/CVE-2025-12386/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2025-12386 and CVE-2025-12387) found in LV-WR21Q firmware.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 27 Jan 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-01-27:/en/posts/2026/01/CVE-2025-12386/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>TCC Bypass vulnerability in Inkscape application for MacOS</title><link>https://cert.pl/en/posts/2026/01/CVE-2025-15523/</link><description>TCC Bypass vulnerability (CVE-2025-15523) has been found in Inkscape application for MacOS.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 22 Jan 2026 13:55:00 +0100</pubDate><guid>tag:cert.pl,2026-01-22:/en/posts/2026/01/CVE-2025-15523/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in Quick.Cart software</title><link>https://cert.pl/en/posts/2026/01/CVE-2025-67683/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2025-67683 and CVE-2025-67684) found in Quick.Cart software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 22 Jan 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-01-22:/en/posts/2026/01/CVE-2025-67683/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Crazy Bubble Tea mobile application</title><link>https://cert.pl/en/posts/2026/01/CVE-2025-14317/</link><description>Exposure of Private Personal Information (CVE-2025-14317) has been identified in Crazy Bubble Tea mobile application.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Wed, 14 Jan 2026 12:55:00 +0100</pubDate><guid>tag:cert.pl,2026-01-14:/en/posts/2026/01/CVE-2025-14317/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Ysoft SafeQ 6 software</title><link>https://cert.pl/en/posts/2026/01/CVE-2025-13175/</link><description>Missing Password Field Masking vulnerability (CVE-2025-13175) has been found in Ysoft SafeQ 6 software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Wed, 14 Jan 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-01-14:/en/posts/2026/01/CVE-2025-13175/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in firmware of Vivotek IP7137 camera</title><link>https://cert.pl/en/posts/2026/01/CVE-2025-66049/</link><description>CERT Polska has received a report about 4 vulnerabilities (from CVE-2025-66049 to CVE-2025-66052) found in Vivotek IP7137 camera.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 09 Jan 2026 12:55:00 +0100</pubDate><guid>tag:cert.pl,2026-01-09:/en/posts/2026/01/CVE-2025-66049/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in firmware of KAON CG3000T/CG3000TC routers</title><link>https://cert.pl/en/posts/2026/01/CVE-2025-7072/</link><description>Use of Hard-coded Credentials vulnerability (CVE-2025-7072) has been found in firmware of KAON routers CG3000T and CG3000TC.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 09 Jan 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-01-09:/en/posts/2026/01/CVE-2025-7072/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Asseco AMDX software</title><link>https://cert.pl/en/posts/2026/01/CVE-2025-4596/</link><description>An issue allowing unauthorized access to medical records (CVE-2025-4596) was found in Asseco AMDX software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 08 Jan 2026 15:56:00 +0100</pubDate><guid>tag:cert.pl,2026-01-08:/en/posts/2026/01/CVE-2025-4596/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in Asseco InfoMedica Plus software</title><link>https://cert.pl/en/posts/2026/01/CVE-2025-8306/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2025-8306 and CVE-2025-8307) found in Asseco InfoMedica Plus software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 08 Jan 2026 13:55:00 +0100</pubDate><guid>tag:cert.pl,2026-01-08:/en/posts/2026/01/CVE-2025-8306/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Kieback&amp;Peter Neutrino-GLT software</title><link>https://cert.pl/en/posts/2026/01/CVE-2025-6225/</link><description>Command Injection vulnerability (CVE-2025-6225) has been found in Kieback&amp;Peter Neutrino-GLT software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Wed, 07 Jan 2026 11:55:00 +0100</pubDate><guid>tag:cert.pl,2026-01-07:/en/posts/2026/01/CVE-2025-6225/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in WODESYS WD-R608U router</title><link>https://cert.pl/en/posts/2025/12/CVE-2025-65007/</link><description>CERT Polska has received a report about 5 vulnerabilities (from CVE-2025-65007 to CVE-2025-65011) found in WODESYS WD-R608U router.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 18 Dec 2025 13:55:00 +0100</pubDate><guid>tag:cert.pl,2025-12-18:/en/posts/2025/12/CVE-2025-65007/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Govee devices with cloud connectivity firmware</title><link>https://cert.pl/en/posts/2025/12/CVE-2025-10910/</link><description>Authorization Bypass Through User-Controlled Key vulnerability (CVE-2025-10910) has been found in Govee devices with cloud connectivity firmware.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 18 Dec 2025 11:55:00 +0100</pubDate><guid>tag:cert.pl,2025-12-18:/en/posts/2025/12/CVE-2025-10910/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in WaveStore Server software</title><link>https://cert.pl/en/posts/2025/12/CVE-2025-65074/</link><description>CERT Polska has received a report about 3 vulnerabilities (from CVE-2025-65074 to CVE-2025-65076) found in WaveStore Server software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 16 Dec 2025 11:55:00 +0100</pubDate><guid>tag:cert.pl,2025-12-16:/en/posts/2025/12/CVE-2025-65074/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in OpenSolution QuickCMS software</title><link>https://cert.pl/en/posts/2025/12/CVE-2025-12465/</link><description>SQL Injection vulnerability (CVE-2025-12465) has been found in OpenSolution QuickCMS software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 02 Dec 2025 11:55:00 +0100</pubDate><guid>tag:cert.pl,2025-12-02:/en/posts/2025/12/CVE-2025-12465/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Simple SA Wirtualna Uczelnia software</title><link>https://cert.pl/en/posts/2025/11/CVE-2025-12140/</link><description>Remote Code Execution vulnerability (CVE-2025-12140) has been found in Wirtualna Uczelnia software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 27 Nov 2025 14:40:00 +0100</pubDate><guid>tag:cert.pl,2025-11-27:/en/posts/2025/11/CVE-2025-12140/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in SDMC NE6037 routers</title><link>https://cert.pl/en/posts/2025/11/CVE-2025-8890/</link><description>Authorized shell command injection vulnerability (CVE-2025-8890) has been found in SDMC NE6037 routers.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 27 Nov 2025 14:30:00 +0100</pubDate><guid>tag:cert.pl,2025-11-27:/en/posts/2025/11/CVE-2025-8890/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in SOPlanning software</title><link>https://cert.pl/en/posts/2025/11/CVE-2025-62293/</link><description>CERT Polska has received a report about 8 vulnerabilities (from CVE-2025-62293 to 62297 and from 2025-62729 to CVE-2025-62731) found in SOPlanning software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 20 Nov 2025 11:55:00 +0100</pubDate><guid>tag:cert.pl,2025-11-20:/en/posts/2025/11/CVE-2025-62293/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Times Software E-Payroll software</title><link>https://cert.pl/en/posts/2025/11/CVE-2025-9977/</link><description>An improper neutralization of input data has been detected in Times Software E-Payroll, resulting in the possibility of a DoS attack and (potentially) SQL Injection (CVE-2025-9977).</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 18 Nov 2025 14:55:00 +0100</pubDate><guid>tag:cert.pl,2025-11-18:/en/posts/2025/11/CVE-2025-9977/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in Windu CMS software</title><link>https://cert.pl/en/posts/2025/11/CVE-2025-59110/</link><description>CERT Polska has received a report about 8 vulnerabilities (from CVE-2025-59110 to CVE-2025-59117) found in Windu CMS software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 18 Nov 2025 11:55:00 +0100</pubDate><guid>tag:cert.pl,2025-11-18:/en/posts/2025/11/CVE-2025-59110/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in OpenSolution QuickCMS software</title><link>https://cert.pl/en/posts/2025/11/CVE-2025-9982/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2025-9982 and CVE-2025-10018) found in OpenSolution QuickCMS software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 14 Nov 2025 11:55:00 +0100</pubDate><guid>tag:cert.pl,2025-11-14:/en/posts/2025/11/CVE-2025-9982/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Analysis of NGate malware campaign (NFC relay)</title><link>https://cert.pl/en/posts/2025/11/analiza-ngate/</link><description>CERT Polska has observed new samples of mobile malware in recent months associated with an NFC Relay (NGate) attack targeting users of Polish banks.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Kacper Ratajczak</dc:creator><pubDate>Mon, 03 Nov 2025 10:37:00 +0100</pubDate><guid>tag:cert.pl,2025-11-03:/en/posts/2025/11/analiza-ngate/</guid><category>News</category><category>nfc</category><category>analysis</category><category>android</category><category>analiza</category></item><item><title>Vulnerability in Eveo URVE Smart Office software</title><link>https://cert.pl/en/posts/2025/10/CVE-2025-10348/</link><description>Cross-site Scripting vulnerability (CVE-2025-10348) has been found in Eveo URVE Smart Office software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 30 Oct 2025 13:55:00 +0100</pubDate><guid>tag:cert.pl,2025-10-30:/en/posts/2025/10/CVE-2025-10348/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in OpenSolution Quick.Cart software</title><link>https://cert.pl/en/posts/2025/10/CVE-2025-10317/</link><description>Cross-Site Request Forgery (CSRF) vulnerability (CVE-2025-10317) has been found in OpenSolution Quick.Cart software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 30 Oct 2025 11:55:00 +0100</pubDate><guid>tag:cert.pl,2025-10-30:/en/posts/2025/10/CVE-2025-10317/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Asseco Poland mMedica software</title><link>https://cert.pl/en/posts/2025/10/CVE-2025-9313/</link><description>Authentication Bypass Using an Alternate Path or Channel vulnerability (CVE-2025-9313) has been found in Asseco mMedica software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 28 Oct 2025 11:55:00 +0100</pubDate><guid>tag:cert.pl,2025-10-28:/en/posts/2025/10/CVE-2025-9313/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Studio Fabryka DobryCMS software</title><link>https://cert.pl/en/posts/2025/10/CVE-2025-8536/</link><description>SQL Injection vulnerability (CVE-2025-8536) has been found in Studio Fabryka DobryCMS software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 24 Oct 2025 11:55:00 +0100</pubDate><guid>tag:cert.pl,2025-10-24:/en/posts/2025/10/CVE-2025-8536/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Request Tracker software</title><link>https://cert.pl/en/posts/2025/10/CVE-2025-9158/</link><description>XSS vulnerability (CVE-2025-9158) has been found in Best Practical Request Tracker software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 24 Oct 2025 07:55:00 +0100</pubDate><guid>tag:cert.pl,2025-10-24:/en/posts/2025/10/CVE-2025-9158/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in firmware of Vilar VS-IPC1002 IP cameras</title><link>https://cert.pl/en/posts/2025/10/CVE-2025-53701/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2025-53701 and CVE-2025-53702) found in Vilar VS-IPC1002 software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 23 Oct 2025 11:55:00 +0100</pubDate><guid>tag:cert.pl,2025-10-23:/en/posts/2025/10/CVE-2025-53701/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in OpenSolution QuickCMS software</title><link>https://cert.pl/en/posts/2025/10/CVE-2025-9980/</link><description>CERT Polska has received a report about 2 vulnerabilities (from CVE-2025-9980 to CVE-2025-9981) found in OpenSolution QuickCMS software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 23 Oct 2025 11:55:00 +0100</pubDate><guid>tag:cert.pl,2025-10-23:/en/posts/2025/10/CVE-2025-9980/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in SIMPLE.ERP software</title><link>https://cert.pl/en/posts/2025/10/CVE-2025-9339/</link><description>SQL Injection vulnerability (CVE-2025-9339) has been found in SIMPLE.ERP software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 21 Oct 2025 11:55:00 +0100</pubDate><guid>tag:cert.pl,2025-10-21:/en/posts/2025/10/CVE-2025-9339/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in NetBird VPN software</title><link>https://cert.pl/en/posts/2025/10/CVE-2025-10678/</link><description>Use of Default Credentials vulnerability (CVE-2025-10678) has been found in NetBird VPN software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 20 Oct 2025 11:55:00 +0100</pubDate><guid>tag:cert.pl,2025-10-20:/en/posts/2025/10/CVE-2025-10678/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Strapi software</title><link>https://cert.pl/en/posts/2025/10/CVE-2025-3930/</link><description>Insufficient Session Expiration vulnerability (CVE-2025-3930) has been found in Strapi software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 16 Oct 2025 11:55:00 +0100</pubDate><guid>tag:cert.pl,2025-10-16:/en/posts/2025/10/CVE-2025-3930/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in PAD CMS software</title><link>https://cert.pl/en/posts/2025/09/CVE-2025-7063/</link><description>CERT Polska has coordinated disclousure of 9 vulnerabilities (CVE-2025-7063, CVE-2025-7065 and from CVE-2025-8116 to CVE-2025-8122) found in PAD CMS software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 30 Sep 2025 11:55:00 +0100</pubDate><guid>tag:cert.pl,2025-09-30:/en/posts/2025/09/CVE-2025-7063/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in CivetWeb software</title><link>https://cert.pl/en/posts/2025/09/CVE-2025-9648/</link><description>Improper Neutralization of NUL Character vulnerability (CVE-2025-9648) has been found in CivetWeb software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 29 Sep 2025 11:55:00 +0100</pubDate><guid>tag:cert.pl,2025-09-29:/en/posts/2025/09/CVE-2025-9648/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in GALAYOU G2 software</title><link>https://cert.pl/en/posts/2025/09/CVE-2025-9983/</link><description>Missing Authentication for Critical Function vulnerability (CVE-2025-9983) has been found in GALAYOU G2 software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 22 Sep 2025 11:55:00 +0100</pubDate><guid>tag:cert.pl,2025-09-22:/en/posts/2025/09/CVE-2025-9983/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in Sparkle software</title><link>https://cert.pl/en/posts/2025/09/CVE-2025-10015/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2025-10015 and CVE-2025-10016) found in Sparkle software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 16 Sep 2025 11:55:00 +0100</pubDate><guid>tag:cert.pl,2025-09-16:/en/posts/2025/09/CVE-2025-10015/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in SMSEagle devices</title><link>https://cert.pl/en/posts/2025/09/CVE-2025-10095/</link><description>SQL Injection (CVE-2025-10095) has been found in SMSEagle firmware.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Tue, 09 Sep 2025 11:55:00 +0100</pubDate><guid>tag:cert.pl,2025-09-09:/en/posts/2025/09/CVE-2025-10095/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in ITCube CRM software</title><link>https://cert.pl/en/posts/2025/09/CVE-2025-5993/</link><description>Path Traversal vulnerability (CVE-2025-5993) has been found in ITCube CRM software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Mon, 08 Sep 2025 11:55:00 +0100</pubDate><guid>tag:cert.pl,2025-09-08:/en/posts/2025/09/CVE-2025-5993/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerability in Concept Intermedia GOV CMS software</title><link>https://cert.pl/en/posts/2025/09/CVE-2025-7385/</link><description>SQL Injection vulnerability (CVE-2025-7385) has been found in Concept Intermedia GOV CMS software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 04 Sep 2025 13:55:00 +0100</pubDate><guid>tag:cert.pl,2025-09-04:/en/posts/2025/09/CVE-2025-7385/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in Payload CMS software</title><link>https://cert.pl/en/posts/2025/08/CVE-2025-4643/</link><description>CERT Polska has received a report about 2 vulnerabilities (CVE-2025-4643 and CVE-2025-4644).</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Fri, 29 Aug 2025 11:55:00 +0100</pubDate><guid>tag:cert.pl,2025-08-29:/en/posts/2025/08/CVE-2025-4643/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item><item><title>Vulnerabilities in OpenSolution QuickCMS software</title><link>https://cert.pl/en/posts/2025/08/CVE-2025-54540/</link><description>CERT Polska has received a report about 6 vulnerabilities (from CVE-2025-54540 to CVE-2025-55175) found in OpenSolution QuickCMS software.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CERT Polska</dc:creator><pubDate>Thu, 28 Aug 2025 11:55:00 +0100</pubDate><guid>tag:cert.pl,2025-08-28:/en/posts/2025/08/CVE-2025-54540/</guid><category>CVE</category><category>vulnerability</category><category>warning</category><category>cve</category></item></channel></rss>