As part of our ongoing research and consulting efforts, we frequently discover vulnerabilities in third-party products. Committed to enhancing the security of the digital ecosystem, we publish detailed security advisories according our vulnerability disclosure policy. You can find the full security advisories with complete details in our Github repository.
Below is an overview of our latest security advisories:
-
SWUpdate Untrusted Script Execution via Signed Update TOCTOU (CVE-2025-41259)
-
DFIR-IRIS Alerts Can be Falsely Attributed to Customers (CVE-2026-42547)
-
DFIR-IRIS Cross-Site Request Forgery (CSRF) (CVE-2026-42543)
-
DFIR-IRIS Mass Assignment (CVE-2026-42540)
-
DFIR-IRIS Excessive Data Exposure (CVE-2026-42439)
-
DFIR-IRIS Insecure File Upload (CVE-2026-42538)
-
DFIR-IRIS Open Redirect (CVE-2026-42329)
-
GoAnywhere MFT Email HTML Injection (CVE-2026-0972)