ISC BIND contains a data processing errors vulnerability that could allow remote attackers to cause a denial of service via TKEY queries. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing…
Cyber theSIGNAL
Urgent advisories, exploited vulnerabilities and incidents. Current Signal data is server-rendered for readers and search engines, with source attribution and update timestamps.
Cyber theSIGNAL
Apache Struts contains a command injection vulnerability that could allow remote attackers to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD…
Strapi contains a cleartext storage of sensitive information vulnerability that could allow attackers with access to the admin panel to discover sensitive user details via the query filter. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS).…
ONLYOFFICE Docs contains a path traversal vulnerability that can occur when JWT is used, via a /.. sequence in an image upload parameter and could allow for remote code execution. Required action: Apply mitigations in accordance with vendor…
ProFTPD contains an improper access control vulnerability that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance…
Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for a denial of service. Required action: Apply…
Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489. Required action: Apply mitigations in accordance with vendor instructions, ensuring…
Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with…
What this theSIGNAL is seeing now
CVE-2015-5477 · ISC BIND Data Processing Errors Vulnerability
ISC BIND contains a data processing errors vulnerability that could allow remote attackers to cause a denial of service via TKEY queries. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing…
CISA Known Exploited Vulnerabilities Catalog · 3 days agoCVE-2016-3081 · Apache Struts Command Injection Vulnerability
Apache Struts contains a command injection vulnerability that could allow remote attackers to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD…
CISA Known Exploited Vulnerabilities Catalog · 3 days agoCVE-2023-22894 · Strapi Cleartext Storage of Sensitive Information Vulnerability
Strapi contains a cleartext storage of sensitive information vulnerability that could allow attackers with access to the admin panel to discover sensitive user details via the query filter. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS).…
CISA Known Exploited Vulnerabilities Catalog · 3 days agoCVE-2021-3199 · ONLYOFFICE Docs Server Path Traversal Vulnerability
ONLYOFFICE Docs contains a path traversal vulnerability that can occur when JWT is used, via a /.. sequence in an image upload parameter and could allow for remote code execution. Required action: Apply mitigations in accordance with vendor…
CISA Known Exploited Vulnerabilities Catalog · 3 days agoHow to read this theSIGNAL
theSIGNAL surfaces source-attributed information and ranks current items using freshness, severity, observed movement and source confidence where those measurements are available. A high ranking identifies attention or consequence; it does not convert an allegation into a fact or a market price into a guaranteed forecast.
Current feed: CISA. Last successful snapshot: October 11, 2026 5:23 am.
Subscribe to this theSIGNAL RSS →