-
Vulnerabilities in KAON PG5298A/PG5298B routers
CERT Polska has received a report about 2 vulnerabilities (CVE-2025-63080 and CVE-2026-6017) found in KAON PG5298A/PG5298B routers.
Read more -
Vulnerabilities in ATutor software
CERT Polska has received a report about 13 vulnerabilities (from CVE-2026-64960 to CVE-2026-64972) found in ATutor software.
Read more -
Vulnerabilities in nnn software
CERT Polska has received a report about 4 vulnerabilities (from CVE-2026-65609 to CVE-2026-65612) found in nnn software.
Read more -
Vulnerability in Carbone software
Improper handling of highly compressed data (data amplification) vulnerability (CVE-2026-18929) has been found in Carbone software.
Read more -
Vulnerability in OutSystems Service Center software
DOM-based Cross-site Scripting vulnerability (CVE-2026-40126) has been found in OutSystems Service Center software.
Read more -
Vulnerability in Magnolia CMS software
Stored Cross-Site Scripting vulnerability (CVE-2026-18478) has been found in Magnolia CMS software.
Read more -
Vulnerability in entr software
Heap-based buffer overflow vulnerability (CVE-2026-18370) has been found in eradman entr software.
Read more -
Vulnerabilities in GNU cpio software
CERT Polska has received a report about 3 vulnerabilities (from CVE-2026-66484 to CVE-2026-66486) found in GNU cpio software.
Read more -
Vulnerabilities in GNU Emacs software
CERT Polska has received a report about 4 vulnerabilities (from CVE-2026-71391 to CVE-2026-71394) found in GNU Emacs software.
Read more -
Follow-Up Report of the December 2025 Energy Sector Incident
During the attacks against Poland's energy sector in late 2025, a second combined heat and power plant was also affected. We are publishing a report detailing an investigation that lasted more than three months and led to the discovery of a previously unobserved attack vector involving a private APN.
Read more