<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Vendor Advisories</title>
	<atom:link href="https://advisoryloom.com/almain/category/vendor-advisories/feed/" rel="self" type="application/rss+xml" />
	<link>https://advisoryloom.com/almain</link>
	<description>Weaving cybersecurity advisories into one clear view</description>
	<lastBuildDate>Thu, 03 Sep 2026 20:12:03 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1</generator>

<image>
	<url>https://advisoryloom.com/almain/wp-content/uploads/2026/04/cropped-ChatGPT-Image-Apr-17-2026-03_10_38-PM-32x32.png</url>
	<title>Vendor Advisories</title>
	<link>https://advisoryloom.com/almain</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>USN-8724-1: rabbitmq-c vulnerabilities</title>
		<link>https://ubuntu.com/security/notices/USN-8724-1</link>
		
		<dc:creator><![CDATA[Advisoryloom Editor]]></dc:creator>
		<pubDate>Thu, 03 Sep 2026 20:12:03 +0000</pubDate>
				<category><![CDATA[Linux Advisories]]></category>
		<category><![CDATA[Vendor Advisories]]></category>
		<category><![CDATA[Advisories]]></category>
		<category><![CDATA[Linux]]></category>
		<guid isPermaLink="false">https://advisoryloom.com/almain/usn-8724-1-rabbitmq-c-vulnerabilities/</guid>

					<description><![CDATA[Confirmed Zero-Day AlertPaperCut NG/MF zero-day exploit chain used in data-theft attacksVerified September 1, 2026 8:00 amView verified coverage]]></description>
										<content:encoded><![CDATA[<div>It was discovered that the rabbitmq-c command-line tools only accepted<br />
credentials on the command line, making them visible to other local users<br />
through the process list. An attacker could possibly use this to obtain<br />
sensitive credentials. This issue only affected Ubuntu 14.04 LTS, Ubuntu<br />
16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2023-35789)</p>
<p>It was discovered that rabbitmq-c did not correctly compute AMQP frame<br />
lengths, leading to a size_t underflow. A remote attacker could possibly<br />
use this to cause rabbitmq-c to crash, resulting in a denial of service, or<br />
possibly expose sensitive information. This issue only affected Ubuntu<br />
14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS.<br />
(CVE-2026-44235)</p>
<p>It was discovered that rabbitmq-c did not properly validate the frame size<br />
during the AMQP login handshake. A remote attacker could possibly use this<br />
to cause a heap buffer overflow, resulting in a denial of service or<br />
possibly the execution of arbitrary code. This issue only affected Ubuntu<br />
14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS.<br />
(CVE-2026-44236)</p>
<p>It was discovered that rabbitmq-c did not correctly validate the length of<br />
decoded bytes fields, leading to an integer overflow in a bounds check on<br />
32-bit systems. A remote attacker controlling a broker, or able to<br />
intercept an unencrypted connection, could possibly use this to cause an<br />
out-of-bounds read, resulting in a denial of service or the exposure of<br />
sensitive information. (CVE-2026-59986)</p>
<p>It was discovered that rabbitmq-c did not validate the body fragment length<br />
when serialising an AMQP body frame with the amqp_send_frame() API. An<br />
attacker could possibly use this to cause a heap buffer overflow, resulting<br />
in a denial of service (application crash) or possibly the execution of<br />
arbitrary code. This issue did not affect Ubuntu 14.04 LTS.<br />
(CVE-2026-61547)</p></div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>DSA-6482-1 chromium &#8211; security update</title>
		<link>https://lists.debian.org/debian-security-announce/2026/msg00393.html</link>
		
		<dc:creator><![CDATA[Advisoryloom Editor]]></dc:creator>
		<pubDate>Thu, 03 Sep 2026 20:12:00 +0000</pubDate>
				<category><![CDATA[Linux Advisories]]></category>
		<category><![CDATA[Vendor Advisories]]></category>
		<category><![CDATA[Advisories]]></category>
		<category><![CDATA[Linux]]></category>
		<guid isPermaLink="false">https://advisoryloom.com/almain/dsa-6482-1-chromium-security-update/</guid>

					<description><![CDATA[https://security-tracker.debian.org/tracker/DSA-6482-1]]></description>
										<content:encoded><![CDATA[<div><a href="https://security-tracker.debian.org/tracker/DSA-6482-1">https://security-tracker.debian.org/tracker/DSA-6482-1</a></div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>RHSA-2026:63302: Important: Red Hat Build of Apache Camel 4.18 for Quarkus 3.33 update is now available (RHBQ 3.33.3.SP1)</title>
		<link>https://access.redhat.com/errata/RHSA-2026:63302</link>
		
		<dc:creator><![CDATA[Advisoryloom Editor]]></dc:creator>
		<pubDate>Thu, 03 Sep 2026 19:17:11 +0000</pubDate>
				<category><![CDATA[Linux Advisories]]></category>
		<category><![CDATA[Vendor Advisories]]></category>
		<category><![CDATA[Advisories]]></category>
		<category><![CDATA[Linux]]></category>
		<guid isPermaLink="false">https://advisoryloom.com/almain/rhsa-202663302-important-red-hat-build-of-apache-camel-4-18-for-quarkus-3-33-update-is-now-available-rhbq-3-33-3-sp1/</guid>

					<description><![CDATA[An update for Red Hat Build of Apache Camel 4.18 for Quarkus 3.33 update is now available (RHBQ]]></description>
										<content:encoded><![CDATA[<div>An update for Red Hat Build of Apache Camel 4.18 for Quarkus 3.33 update is now available (RHBQ 3.33.3.SP1).The purpose of this text-only errata is to inform you about the enhancements that improve your developer experience and ensure the security and stability of your products.Red Hat Product Security has rated this update as having a security impact of Important.</div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>CVE-2026-9852</title>
		<link>https://www.tenable.com/cve/CVE-2026-9852</link>
		
		<dc:creator><![CDATA[Advisoryloom Editor]]></dc:creator>
		<pubDate>Thu, 03 Sep 2026 17:35:01 +0000</pubDate>
				<category><![CDATA[Vendor Advisories]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Vendors]]></category>
		<guid isPermaLink="false">https://advisoryloom.com/almain/cve-2026-9852/</guid>

					<description><![CDATA[Medium Severity Description A CSV injection vulnerability exists in SYS600. Injected malicious formulas can add or modify data]]></description>
										<content:encoded><![CDATA[<div>
<p>Medium Severity</p>
<h3>Description</h3>
<p>A CSV injection vulnerability exists in SYS600. Injected malicious formulas can add or modify data to the spreadsheet, insert links, exfiltrate data, and in some cases, depending on how the user has their environment configured, execute malicious code on the user’s machine. To exploit this issue attackers would need a way to create arbitrary log messages. This could be achieved through normal functionality via SCIL scripts, a log injection vulnerability, or via the SYS600 broker. This vulnerability affects all Windows users regardless of their privilege level who can run the Notify service and export the log.</p>
<p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-9852">https://www.tenable.com/cve/CVE-2026-9852</a></p>
</div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>CVE-2026-85172</title>
		<link>https://www.tenable.com/cve/CVE-2026-85172</link>
		
		<dc:creator><![CDATA[Advisoryloom Editor]]></dc:creator>
		<pubDate>Thu, 03 Sep 2026 17:35:00 +0000</pubDate>
				<category><![CDATA[Vendor Advisories]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Vendors]]></category>
		<guid isPermaLink="false">https://advisoryloom.com/almain/cve-2026-85172/</guid>

					<description><![CDATA[Medium Severity Description n8n versions before 2.34.1 contain a server-side request forgery vulnerability in the legacy request helper]]></description>
										<content:encoded><![CDATA[<div>
<p>Medium Severity</p>
<h3>Description</h3>
<p>n8n versions before 2.34.1 contain a server-side request forgery vulnerability in the legacy request helper function exposed to Code and Function nodes. The validation logic checks the uri property for SSRF safety while the underlying HTTP client uses the url property when both are present, allowing attackers to bypass validation by supplying a safe uri alongside a malicious url to access internal addresses.</p>
<p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-85172">https://www.tenable.com/cve/CVE-2026-85172</a></p>
</div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>CVE-2026-85175</title>
		<link>https://www.tenable.com/cve/CVE-2026-85175</link>
		
		<dc:creator><![CDATA[Advisoryloom Editor]]></dc:creator>
		<pubDate>Thu, 03 Sep 2026 17:35:00 +0000</pubDate>
				<category><![CDATA[Vendor Advisories]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Vendors]]></category>
		<guid isPermaLink="false">https://advisoryloom.com/almain/cve-2026-85175/</guid>

					<description><![CDATA[High Severity Description SiYuan versions Read more at https://www.tenable.com/cve/CVE-2026-85175]]></description>
										<content:encoded><![CDATA[<div>
<p>High Severity</p>
<h3>Description</h3>
<p>SiYuan versions </p>
<p>Read more at <a href="https://www.tenable.com/cve/CVE-2026-85175">https://www.tenable.com/cve/CVE-2026-85175</a></p>
</div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>RHSA-2026:59830: Important: OpenShift Container Platform 4.12.97 packages and security update</title>
		<link>https://access.redhat.com/errata/RHSA-2026:59830</link>
		
		<dc:creator><![CDATA[Advisoryloom Editor]]></dc:creator>
		<pubDate>Thu, 03 Sep 2026 15:26:21 +0000</pubDate>
				<category><![CDATA[Linux Advisories]]></category>
		<category><![CDATA[Vendor Advisories]]></category>
		<category><![CDATA[Advisories]]></category>
		<category><![CDATA[Linux]]></category>
		<guid isPermaLink="false">https://advisoryloom.com/almain/rhsa-202659830-important-openshift-container-platform-4-12-97-packages-and-security-update/</guid>

					<description><![CDATA[Red Hat OpenShift Container Platform release 4.12.97 is now available with updates to packages and images that fix]]></description>
										<content:encoded><![CDATA[<div>Red Hat OpenShift Container Platform release 4.12.97 is now available with<br />
updates to packages and images that fix several bugs and add enhancements.</p>
<p>This release includes a security update for Red Hat OpenShift Container<br />
Platform 4.12.</p>
<p>Red Hat Product Security has rated this update as having a security impact<br />
of  Low. A Common Vulnerability Scoring System (CVSS) base score, which<br />
gives a detailed severity rating, is available for each vulnerability from<br />
the CVE link(s) in the References section.</p></div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Crypto Agility: Why PQC Is Not a One-Time Upgrade</title>
		<link>https://blogs.cisco.com/security/crypto-agility-why-pqc-is-not-a-one-time-upgrade</link>
		
		<dc:creator><![CDATA[Advisoryloom Editor]]></dc:creator>
		<pubDate>Thu, 03 Sep 2026 15:26:04 +0000</pubDate>
				<category><![CDATA[Vendor Advisories]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Vendors]]></category>
		<guid isPermaLink="false">https://advisoryloom.com/almain/crypto-agility-why-pqc-is-not-a-one-time-upgrade/</guid>

					<description><![CDATA[Learn why crypto agility is essential for PQC-ready networks—and how adaptable infrastructure helps organizations keep pace with evolving]]></description>
										<content:encoded><![CDATA[<div>Learn why crypto agility is essential for PQC-ready networks—and how adaptable infrastructure helps organizations keep pace with evolving threats.</div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>USN-8720-1: GnuPG vulnerability</title>
		<link>https://ubuntu.com/security/notices/USN-8720-1</link>
		
		<dc:creator><![CDATA[Advisoryloom Editor]]></dc:creator>
		<pubDate>Thu, 03 Sep 2026 14:06:41 +0000</pubDate>
				<category><![CDATA[Linux Advisories]]></category>
		<category><![CDATA[Vendor Advisories]]></category>
		<category><![CDATA[Advisories]]></category>
		<category><![CDATA[Linux]]></category>
		<guid isPermaLink="false">https://advisoryloom.com/almain/usn-8720-1-gnupg-vulnerability/</guid>

					<description><![CDATA[It was discovered that GnuPG incorrectly validated authentication tag lengths when parsing CMS messages encrypted with AES-GCM. An]]></description>
										<content:encoded><![CDATA[<div>It was discovered that GnuPG incorrectly validated authentication tag<br />
lengths when parsing CMS messages encrypted with AES-GCM. An attacker could<br />
possibly use this issue to bypass message integrity checks.</div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>USN-8719-1: APR-util vulnerabilities</title>
		<link>https://ubuntu.com/security/notices/USN-8719-1</link>
		
		<dc:creator><![CDATA[Advisoryloom Editor]]></dc:creator>
		<pubDate>Thu, 03 Sep 2026 13:28:17 +0000</pubDate>
				<category><![CDATA[Linux Advisories]]></category>
		<category><![CDATA[Vendor Advisories]]></category>
		<category><![CDATA[Advisories]]></category>
		<category><![CDATA[Linux]]></category>
		<guid isPermaLink="false">https://advisoryloom.com/almain/usn-8719-1-apr-util-vulnerabilities/</guid>

					<description><![CDATA[It was discovered that APR-util incorrectly performed password hash comparisons in a way that was not constant-time. An]]></description>
										<content:encoded><![CDATA[<div>It was discovered that APR-util incorrectly performed password hash<br />
comparisons in a way that was not constant-time.<br />
An attacker could possibly use this issue to obtain sensitive information.<br />
(CVE-2025-49506)</p>
<p>It was discovered that APR-util incorrectly handled recursive XML element<br />
quoting. An attacker could possibly use this issue to cause applications<br />
using APR-util to crash, resulting in a denial of service.<br />
(CVE-2026-32327)</p>
<p>It was discovered that the APR-util Redis client incorrectly handled<br />
certain network data, resulting in a heap-based buffer overflow. A remote<br />
attacker could possibly use this issue to cause APR-util applications to<br />
crash or execute arbitrary code. This issue only affected Ubuntu 18.04 LTS,<br />
Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.<br />
(CVE-2026-34501)</p>
<p>It was discovered that the APR-util memcached client incorrectly handled<br />
certain network data, resulting in a heap-based buffer overflow. A remote<br />
attacker could possibly use this issue to cause APR-util applications to<br />
crash or execute arbitrary code. (CVE-2026-34502)</p></div>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
