-
Vulnerability in Magnolia CMS software
Stored Cross-Site Scripting vulnerability (CVE-2026-18478) has been found in Magnolia CMS software.
Read more -
Vulnerability in entr software
Heap-based buffer overflow vulnerability (CVE-2026-18370) has been found in eradman entr software.
Read more -
Vulnerabilities in GNU cpio software
CERT Polska has received a report about 3 vulnerabilities (from CVE-2026-66484 to CVE-2026-66486) found in GNU cpio software.
Read more -
Vulnerabilities in GNU Emacs software
CERT Polska has received a report about 4 vulnerabilities (from CVE-2026-71391 to CVE-2026-71394) found in GNU Emacs software.
Read more -
Follow-Up Report of the December 2025 Energy Sector Incident
During the attacks against Poland's energy sector in late 2025, a second combined heat and power plant was also affected. We are publishing a report detailing an investigation that lasted more than three months and led to the discovery of a previously unobserved attack vector involving a private APN.
Read more -
Vulnerabilities in PHP Jabbers scripts
CERT Polska has received a report about 5 vulnerabilities (from CVE-2025-67649 to CVE-2025-67651 and from CVE-2026-46593 to CVE-2026-46594) found in PHP Jabbers scripts.
Read more -
Vulnerabilities in MWDB Core software
Two vulnerabilities (CVE-2026-66723 and CVE-2026-66724) were found in CERT.PL MWDB Core software.
Read more -
Vulnerability in Streamsoft Business Intelligence software
Plaintext Storage of a Password vulnerability (CVE-2026-50641) has been found in Streamsoft Business Intelligence software.
Read more -
Vulnerability in Quick.CMS software
SQL Injection vulnerability (CVE-2026-33385) has been found in OpenSolution Quick.CMS software.
Read more -
Vulnerability in diff-so-fancy software
Improper Encoding or Escaping of Output vulnerability (CVE-2026-50642) has been found in diff-so-fancy software.
Read more