Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:deb/ubuntu/edk2

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

0

To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle

Join the discussion
0

CVE-2026-63074 is a vulnerability in OpenSSL affecting certain Ubuntu releases where OpenSSL incorrectly limits the growth of an internal certificate cache used during CMP operations. This flaw could allow a remote attacker to cause OpenSSL to consume excessive resources, potentially leading to a denial of service condition. The issue has been addressed by updates provided by Ubuntu for multiple LTS releases. The vulnerability is rated as low severity and no known exploits are reported in the wild.

Join the discussion

A vulnerability in OpenSSL related to QUIC ACK-only packet retention can cause excessive resource consumption, leading to denial of service. This issue affects Ubuntu 26.04 LTS and specific OpenSSL package versions. The vulnerability is identified as CVE-2026-63075 and is classified under CWE-770 (Allocation of Resources Without Limits or Throttling). A patch is available and should be applied to mitigate the risk.

Join the discussion

CVE-2026-63076 is a vulnerability in OpenSSL related to incorrect handling of CMP (Certificate Management Protocol) protection algorithm validation. This flaw can cause OpenSSL to crash, resulting in a denial of service. The issue affects multiple Ubuntu releases and OpenSSL package versions. Official patches are available from Ubuntu to address this vulnerability.

Join the discussion

To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle

Join the discussion

OpenSSL versions used in various Ubuntu releases contain a vulnerability in the EVP_Cipher() API for AEAD ciphers ChaCha20-Poly1305 and AES-OCB. When decrypting an empty ciphertext, the function may report success without verifying the authentication tag, potentially allowing acceptance of forged messages. This issue does not affect FIPS modules as the affected algorithms are not FIPS approved. The vulnerability has a high severity with a CVSS score of 9.1. Fixes are available in updated OpenSSL packages for Ubuntu 22.04 LTS, 24.04 LTS, and 26.04 LTS.

Join the discussion

A vulnerability in the Node.js QUIC server component could cause a double free condition when processing INITIAL packets, potentially leading to a denial of service. This issue affects specific Ubuntu package versions of Node.js and OpenSSL. The vulnerability has a CVSS score of 7.5, indicating a medium severity level. A patch is available from Ubuntu to address this issue.

Join the discussion

CVE-2025-2486 is a low-severity vulnerability in Ubuntu's edk2 UEFI firmware packages that allowed unintended access to the UEFI Shell in Secure Boot environments, potentially bypassing Secure Boot restrictions. The issue stems from active debug code that permitted the UEFI Shell to run despite Secure Boot protections. Versions 2024.05-2ubuntu0.3 and 2024.02-2ubuntu0.3 disable the Shell to mitigate this risk. This vulnerability builds on an incomplete fix for CVE-2023-48733. Exploitation requires local access and user interaction, with high attack complexity and no known exploits in the wild. The vulnerability primarily affects systems running Ubuntu with affected edk2 versions, and its impact on confidentiality, integrity, and availability is limited due to the constraints on exploitation.

Join the discussion

Showing 1 to 8 of 8 results

Filters:Package: pkg:deb/ubuntu/edk2
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses