Access publications and alerts / Alerts and advisories / Archived alerts and advisories / Remote code execution vulnerability present in certain versions of Palo Alto firewalls utilising the GlobalProtect VPN component Remote code execution vulnerability present in certain versions of Palo Alto firewalls utilising the GlobalProtect VPN component 11 Nov 2021 Alert Alert on a vulnerability in certain Palo Alto firewalls using GlobalProtect VPN. Affected organisations should apply available updates as soon as possible.
Access publications and alerts / Alerts and advisories / Archived alerts and advisories / Active exploitation of vulnerable Sitecore Experience Platform content management systems Active exploitation of vulnerable Sitecore Experience Platform content management systems 05 Nov 2021 Alert Alert on active exploitation of vulnerability occurring in certain versions of Sitecore Experience Platform systems.
Access publications and alerts / Alerts and advisories / Archived alerts and advisories / Critical vulnerability present in certain versions of Apple iOS and iPadOS Critical vulnerability present in certain versions of Apple iOS and iPadOS 13 Oct 2021 Alert A vulnerability has been identified in certain Apple products which could allow an actor to install malware or perform other actions on a vulnerable device.
Access publications and alerts / Alerts and advisories / Archived alerts and advisories / Multiple key vulnerabilities identified in Microsoft products Multiple key vulnerabilities identified in Microsoft products 13 Oct 2021 Alert Alert on patches for critical Remote Desktop and Windows flaws. The ACSC urges urgent patching to prevent network compromise by attackers.
Access publications and alerts / Alerts and advisories / Archived alerts and advisories / Critical vulnerability in certain versions of Apache HTTP Server Critical vulnerability in certain versions of Apache HTTP Server 07 Oct 2021 Alert Alert on Apache HTTP Server 2.4.49 vulnerability allowing arbitrary code execution and potential remote compromise; organisations should apply patches immediately.
Access publications and alerts / Alerts and advisories / Archived alerts and advisories / Critical vulnerability in ManageEngine ADSelfService Plus exploited by cyber actors Critical vulnerability in ManageEngine ADSelfService Plus exploited by cyber actors 24 Sep 2021 Alert Alert on a vulnerability in ManageEngine ADSelfService Plus that could allow arbitrary code execution and host compromise; apply the available security update.