NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-3055 and CVE-2026-4368

#citrix #vulnerabilitymanagement #vulnerability

https://vulnerability.circl.lu/bundle/1ae9c3df-c65f-4755-b3a9-4d76f8c0e772

Vulnerability-Lookup

Vulnerability-Lookup - Fast vulnerability lookup correlation from different sources.

⚠️ New security advisory:

CVE-2019-25578 affects multiple systems.

• Impact: Significant security breach potential
• Risk: Unauthorized access or data exposure
• Mitigation: Apply patches within 24-48 hours

Full breakdown:
https://www.yazoul.net/advisory/cve/cve-2019-25578-phptransformer-sql-injection

#InfoSec #VulnerabilityManagement #CyberSec

High: phpTransformer SQL Injection (CVE-2019-25578) - Update Required | Yazoul Security

High-severity SQL injection in phpTransformer 2016.9 allows remote attackers to execute arbitrary database queries via the idnews parameter. CVSS 8.2. Immediate action recommended.

Yazoul Security

🚨 New security advisory:

CVE-2019-25614 affects multiple systems.

• Impact: Remote code execution or complete system compromise possible
• Risk: Attackers can gain full control of affected systems
• Mitigation: Patch immediately or isolate affected systems

Full breakdown:
https://www.yazoul.net/advisory/cve/cve-2019-25614-free-float-ftp-buffer-overflow

#InfoSec #VulnerabilityManagement #CyberSec

Critical: Free Float FTP Buffer Overflow (CVE-2019-25614) - Patch Now | Yazoul Security

Critical buffer overflow in Free Float FTP 1.0 allows remote code execution via a crafted STOR command. CVSS 9.8. Authenticated attackers can fully compromise the server. Patch immediately.

Yazoul Security

🔶 New security advisory:

CVE-2026-33226 affects multiple systems.

• Impact: Significant security breach potential
• Risk: Unauthorized access or data exposure
• Mitigation: Apply patches within 24-48 hours

Full breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-33226-budibase-ssrf-vulnerability-restrict-access-immediately

#InfoSec #VulnerabilityManagement #CyberSec

High: Budibase SSRF Vulnerability (CVE-2026-33226) - Restrict Access Immediately | Yazoul Security

A high-severity SSRF flaw in Budibase allows admin users to query internal networks and cloud metadata, risking full cloud compromise. No patch is available; mitigation is required.

Yazoul Security

cpe-guesser 2.0 released - Multi-Source CPE Imports, Better Ranking, and Greater Autonomy Beyond NVD

Version 2.0 brings major improvements to CPE import, ranking, and CVE v5 data handling. This release focuses on better import performance, broader format support, improved search relevance, and more robust indexing for vendor and product matching.

A notable change in this release is that cpe-guesser is no longer limited to NVD as its only practical CPE source. In addition to the NVD feeds, it can also leverage the Vulnerability-Lookup dump available at https://vulnerability.circl.lu/dumps/ , providing additional CPE sources and more autonomy from the previously NVD-only source model.

This release lays an important foundation for improving the GCVE ecosystem, especially by strengthening vendor and product references through better CPE source diversity, indexing, and matching capabilities. If you have ideas for further improvements, additional data sources, or better ways to refine vendor and product identification, we would be very happy to hear your feedback.

https://www.vulnerability-lookup.org/2026/03/22/cpe-guesser-2.0-released/

https://github.com/vulnerability-lookup/cpe-guesser

@circl
@gcve

#gcve #cve #opensource #cpe #vulnerability #vulnerabilitymanagement

Vulnerability-Lookup JSON dumps

⛔ New security advisory:

CVE-2026-33186 affects multiple systems.

• Impact: Remote code execution or complete system compromise possible
• Risk: Attackers can gain full control of affected systems
• Mitigation: Patch immediately or isolate affected systems

Full breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-33186-grpc-go-authorization-bypass-patch-critical-flaw

#InfoSec #VulnerabilityManagement #CyberSec

Critical: gRPC-Go Authorization Bypass (CVE-2026-33186) - Patch Critical Flaw | Yazoul Security

Critical gRPC-Go vulnerability allows attackers to bypass path-based authorization rules. Affects servers with specific deny/allow policies. CVSS 9.1. Update to version 1.79.3 immediately.

Yazoul Security

🔴 New security advisory:

CVE-2026-21992 affects multiple systems.

• Impact: Remote code execution or complete system compromise possible
• Risk: Attackers can gain full control of affected systems
• Mitigation: Patch immediately or isolate affected systems

Full breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-21992-oracle-fusion-middleware-critical-vulnerability

#Cybersecurity #VulnerabilityManagement #CyberSec

Critical: Oracle Fusion Middleware Critical Vulnerability (CVE-2026-21992) - Patch Now | Yazoul Security

Critical 9.8 CVSS flaw in Oracle Identity Manager & Web Services Manager allows unauthenticated remote attackers to fully compromise systems via HTTP. Immediate patching is required.

Yazoul Security

🔴 New security advisory:

CVE-2026-21992 affects multiple systems.

• Impact: Remote code execution or complete system compromise possible
• Risk: Attackers can gain full control of affected systems
• Mitigation: Patch immediately or isolate affected systems

Full breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-21992-oracle-fusion-middleware-critical-vulnerability

#Cybersecurity #VulnerabilityManagement #CyberSec

Critical: Oracle Fusion Middleware Critical Vulnerability (CVE-2026-21992) - Patch Now | Yazoul Security

Critical 9.8 CVSS flaw in Oracle Identity Manager & Web Services Manager allows unauthenticated remote attackers to fully compromise systems via HTTP. Immediate patching is required.

Yazoul Security

gcve-eu-kev updated — a CISA KEV and ENISA CNW/EUVD to GCVE BCP-07 converter.

It now also includes a generic RSS/Atom exporter for any GCVE KEV BCP-07 feed.

@gcve

#cybersecurity #gcve #kev #cve #vulnerability #vulnerabilitymanagement

🔗 https://github.com/gcve-eu/gcve-eu-kev
🔗 https://gcve.eu/bcp/gcve-bcp-07/

GitHub - gcve-eu/gcve-eu-kev: CISA/ENISA KEV to GCVE BCP-07 Converter.

CISA/ENISA KEV to GCVE BCP-07 Converter. Contribute to gcve-eu/gcve-eu-kev development by creating an account on GitHub.

GitHub

🔴 New security advisory:

CVE-2026-32191 affects multiple systems.

• Impact: Remote code execution or complete system compromise possible
• Risk: Attackers can gain full control of affected systems
• Mitigation: Patch immediately or isolate affected systems

Full breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-32191-microsoft-bing-images-os-command-injection

#Cybersecurity #VulnerabilityManagement #CyberSec

Critical: Microsoft Bing Images OS Command Injection (CVE-2026-32191) - Critical Fix Required | Yazoul Security

Critical OS command injection vulnerability in Microsoft Bing Images (CVE-2026-32191, CVSS 9.8) allows remote attackers to execute arbitrary code. Immediate action is required.

Yazoul Security