Skip to the content.
Home
/
DIVD CSIRT
Making the internet safer through Coordinated Vulnerability Disclosure
Menu
Home
DIVD
CSIRT
Cases
DIVD-2026-00015 - Vulnerabilities in Zammad during investigation of case DI
Multiple vulnerabilities found in Zammad including a Undisclosed RCE in Zam...
DIVD-2026-00014 - When, not if...
DIVD got hacked through AI agents....
DIVD-2026-00012 - MikroTik RouterOS MikroTrick vulnerabilities
Multiple vulnerabilities in MikroTik RouterOS can be combined to obtain una...
DIVD-2026-00010 - Improper Access Control in Hashtopolis Server
An improper access control vulnerability in the Hashtopolis server chunk ac...
DIVD-2026-00007 - Victim Notification Operation Endgame - S03E03 & S03E04
The DIVD is notifying victims of the SocGholish malware and the StealC and ...
DIVD-2026-00006 - Vulnerability found in DIVD App VerySecureApp
The VerySecureApp made by DIVD using Mendix Studio Pro 11.8.0 Beta allows u...
DIVD-2026-00005 - Salesforce Experience Cloud – Data Exposure via Misconfig
DIVD is researching Salesforce Experience Cloud applications exposing sensi...
DIVD-2026-00003 - Mendix Applications – Data Exposure due to Authorization
DIVD is researching Mendix applications exposing sensitive data due to auth...
DIVD-2026-00002 - DIVD-2026-00002 – Ivanti Endpoint Manager Mobile Vulnerab
Two critical vulnerabilities in Ivanti Endpoint Manager Mobile allow unauth...
DIVD-2026-00001 - DIVD-2026-00001 – EVbee Service App and DC Quick Charging
Multiple vulnerabilities in EVbee Service App and DC Quick Charging Station...
DIVD-2025-00042 - React2shell vulnerability
A vulnerability in React Server components allow unauthorized access via Re...
DIVD-2025-00041 - Victim Notification Operation Endgame S03E01
DIVD is notifying victims of the various infostealer malware strains from i...
DIVD-2025-00040 - Oracle E-Business Suite Vulnerabilities
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Busin...
DIVD-2025-00039 - Cisco ASA WebVPN Vulnerabilities
Multiple vulnerabilities in Cisco ASA WebVPN could allow attackers to bypas...
DIVD-2025-00038 - Found webshells in FreePBX due to RCE vulnerability
FreePBX has assigned CVE-2025-57819 to vulnerabilities in its administrator...
DIVD-2025-00037 - Critical vulnerabilities in Citrix ADC and Gateway system
Citrix has released security updates for vulnerabilities in NetScaler ADC a...
DIVD-2025-00035 - Sharepoint Mass-Exploitation (ToolShell) through CVE-2025
Threat actors are targeting Sharepoint installations with CVE-2025-53770. I...
DIVD-2025-00034 - Remote Code Execution in IBM WebSphere version 8.5 and 9.
A critical vulnerability in IBM WebSphere was discovered in versions 8.5 an...
DIVD-2025-00033 - Remote Code Execution in GeoServer versions below 2.27.0,
A critical vulnerability in GeoServer was discovered in versions below 2.27...
DIVD-2025-00032 - Unauthenticated Arbitrary Remote Code Execution in Pterod
A critical vulnerability in Pterodactyl was discovered in versions below 1....
All cases
CVEs
CVE-2026-22104 - Improper access control in Hashtopolis server chunk activity...
CVE-2026-22103 - Command injection in NPC start web endpoint...
CVE-2026-22102 - Arbitrary file overwrite through certificate update function...
CVE-2026-22101 - Sensitive information leak through hidden menu...
CVE-2026-22100 - Comnand injection in OCPP ReserveLogin message...
CVE-2026-22099 - Missing authentication for Bluetooth communication...
CVE-2026-22098 - Sensitive information is written to logs...
CVE-2026-22097 - Missing firmware validation allows remote code execution...
CVE-2026-22096 - Missing authentication for webserver endpoints...
CVE-2026-22095 - Command injection in diagnosis web endpoint...
More...
CNA
Stolen credentials
Blog
2026-09-24 : It was a matter of when, not if......
2026-08-19 : Sungrow web portal full disclosure...
2026-07-31 : CyberAuditWeb and videx-legacy-ssl full disclosure...
2026-07-30 : Visioweb.js...
2026-07-30 : Cloudflow...
2026-07-27 : Six vulnerabilities in Enphase IQ Gateway devices...
2026-07-17 : White Rabbit Switch full disclosure...
2026-07-17 : Axiell Iguana CMS full disclosure...
2026-07-16 : Mennekes Smart - charging stations full disclosure...
2026-07-16 : SOPlanning Online Planning tool full disclosure...
More...
Donate
Search...
RSS
Contact
Search