<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
  <channel>
    <title>Cyber Alert Feed</title>
    <link>https://digital.nhs.uk/</link>
    <description />
    <language>en-gb</language>
    <copyright />
    <managingEditor>enquiries@nhsdigital.nhs.uk (NHS Digital)</managingEditor>
    <webMaster>enquiries@nhsdigital.nhs.uk (NHS Digital)</webMaster>
    <generator />
    <category />
    <item>
      <title>CC-4776 - Active Exploitation of Local Privilege Escalation Vulnerability in the Linux Kernel</title>
      <category>Medium</category>
      <author>enquiries@nhsdigital.nhs.uk (NHS Digital)</author>
      <description>&lt;p&gt;Severity: Medium&lt;/p&gt; &lt;p&gt;CVE-2026-31431 (dubbed "Copy Fail") affects all Linux kernel builds since 2017, and could allow a local, unprivileged attacker to escalate privileges to root.&lt;/p&gt;&lt;p&gt; CVE-2026-31431 (dubbed "Copy Fail") affects all Linux kernel builds since 2017, and could allow a local, unprivileged attacker to escalate privileges to root.&lt;/p&gt;&lt;p&gt; Updated: 05 May 2026&lt;/p&gt;</description>
      <guid isPermaLink="false">eef1c9ea-044f-438a-8188-52d330528051</guid>
      <pubDate>Thu, 30 Apr 2026 15:32:00 GMT</pubDate>
      <link>https://digital.nhs.uk/cyber-alerts/2026/cc-4776</link>
    </item>
    <item>
      <title>CC-4775 - SonicWall Releases Security Updates for SonicOS</title>
      <category>Medium</category>
      <author>enquiries@nhsdigital.nhs.uk (NHS Digital)</author>
      <description>&lt;p&gt;Severity: Medium&lt;/p&gt; &lt;p&gt;CVE-2026-0204 could allow an unauthenticated attacker to access certain management interface functions&lt;/p&gt;&lt;p&gt; CVE-2026-0204 could allow an unauthenticated attacker to access certain management interface functions&lt;/p&gt;&lt;p&gt; Updated: 30 Apr 2026&lt;/p&gt;</description>
      <guid isPermaLink="false">9dd07394-e747-4a81-950a-3b1d1b6a1c53</guid>
      <pubDate>Thu, 30 Apr 2026 12:15:00 GMT</pubDate>
      <link>https://digital.nhs.uk/cyber-alerts/2026/cc-4775</link>
    </item>
    <item>
      <title>CC-4774 - Critical Vulnerability in cPanel and Web Host Manager (WHM)</title>
      <category>High</category>
      <author>enquiries@nhsdigital.nhs.uk (NHS Digital)</author>
      <description>&lt;p&gt;Severity: High&lt;/p&gt; &lt;p&gt;CVE-2026-41940 could allow unauthenticated remote attackers to gain unauthorised access to the affected cPanel management console&lt;/p&gt;&lt;p&gt; CVE-2026-41940 could allow unauthenticated remote attackers to gain unauthorised access on the affected cPanel management console&lt;/p&gt;&lt;p&gt; Updated: 30 Apr 2026&lt;/p&gt;</description>
      <guid isPermaLink="false">45a6cfb8-45f7-4bd3-9529-b739a2cc6369</guid>
      <pubDate>Thu, 30 Apr 2026 10:34:00 GMT</pubDate>
      <link>https://digital.nhs.uk/cyber-alerts/2026/cc-4774</link>
    </item>
    <item>
      <title>CC-4771 - Microsoft Releases April 2026 Security Updates</title>
      <category>Medium</category>
      <author>enquiries@nhsdigital.nhs.uk (NHS Digital)</author>
      <description>&lt;p&gt;Severity: Medium&lt;/p&gt; &lt;p&gt;Scheduled updates for Microsoft products address 165 vulnerabilities, including CVE‑2026‑32201, an exploited spoofing vulnerability affecting SharePoint Server&lt;/p&gt;&lt;p&gt; Scheduled updates for Microsoft products address 165 vulnerabilities, including CVE‑2026‑32201, an exploited spoofing vulnerability affecting SharePoint Server&lt;/p&gt;&lt;p&gt; Updated: 24 Apr 2026&lt;/p&gt;</description>
      <guid isPermaLink="false">1a57bc08-4592-4720-8500-e59cae44d044</guid>
      <pubDate>Wed, 15 Apr 2026 14:48:00 GMT</pubDate>
      <link>https://digital.nhs.uk/cyber-alerts/2026/cc-4771</link>
    </item>
    <item>
      <title>CC-4773 - Oracle Releases April 2026 Critical Patch Update Advisory</title>
      <category>Medium</category>
      <author>enquiries@nhsdigital.nhs.uk (NHS Digital)</author>
      <description>&lt;p&gt;Severity: Medium&lt;/p&gt; &lt;p&gt;Scheduled advisory includes 481&amp;nbsp;security updates across multiple Oracle product families&lt;/p&gt;&lt;p&gt; Scheduled advisory includes 481 security updates across multiple Oracle product families&lt;/p&gt;&lt;p&gt; Updated: 22 Apr 2026&lt;/p&gt;</description>
      <guid isPermaLink="false">0c425e17-13eb-4652-9e78-c07cc3df34f4</guid>
      <pubDate>Wed, 22 Apr 2026 12:16:00 GMT</pubDate>
      <link>https://digital.nhs.uk/cyber-alerts/2026/cc-4773</link>
    </item>
    <item>
      <title>CC-4772 - Cisco Releases Security Advisories for Critical Vulnerabilities in Identity Services Engine</title>
      <category>Medium</category>
      <author>enquiries@nhsdigital.nhs.uk (NHS Digital)</author>
      <description>&lt;p&gt;Severity: Medium&lt;/p&gt; &lt;p&gt;An authenticated attacker could exploit the vulnerabilities to achieve remote code execution&lt;/p&gt;&lt;p&gt; An authenticated attacker could exploit the vulnerabilities to achieve remote code execution&lt;/p&gt;&lt;p&gt; Updated: 16 Apr 2026&lt;/p&gt;</description>
      <guid isPermaLink="false">f477d07c-4a4b-4ec2-9c3c-741e09e1cfd5</guid>
      <pubDate>Thu, 16 Apr 2026 13:03:00 GMT</pubDate>
      <link>https://digital.nhs.uk/cyber-alerts/2026/cc-4772</link>
    </item>
    <item>
      <title>CC-4770 - Axios Releases Security Update to Address Critical Vulnerability</title>
      <category>Medium</category>
      <author>enquiries@nhsdigital.nhs.uk (NHS Digital)</author>
      <description>&lt;p&gt;Severity: Medium&lt;/p&gt; &lt;p&gt;CVE‑2026‑40175 could be used in an attack chain to allow for remote code execution or full cloud compromise&lt;/p&gt;&lt;p&gt; CVE‑2026‑40175 could be used in an attack chain to allow for remote code execution or full cloud compromise&lt;/p&gt;&lt;p&gt; Updated: 14 Apr 2026&lt;/p&gt;</description>
      <guid isPermaLink="false">1e24f3b3-9e2f-415e-8b68-e3f62de3d961</guid>
      <pubDate>Tue, 14 Apr 2026 10:47:00 GMT</pubDate>
      <link>https://digital.nhs.uk/cyber-alerts/2026/cc-4770</link>
    </item>
    <item>
      <title>CC-4769 - Adobe Releases Security Update to Address a Vulnerability in Acrobat and Reader</title>
      <category>Medium</category>
      <author>enquiries@nhsdigital.nhs.uk (NHS Digital)</author>
      <description>&lt;p&gt;Severity: Medium&lt;/p&gt; &lt;p&gt;CVE‑2026‑34621 could allow arbitrary code execution via malicious PDF files opened in vulnerable Adobe Acrobat or Reader installations.&lt;/p&gt;&lt;p&gt; CVE‑2026‑34621 could allow arbitrary code execution via malicious PDF files opened in vulnerable Adobe Acrobat or Reader installations.&lt;/p&gt;&lt;p&gt; Updated: 13 Apr 2026&lt;/p&gt;</description>
      <guid isPermaLink="false">00caa41c-19b6-486c-994b-687d9415e19a</guid>
      <pubDate>Mon, 13 Apr 2026 13:37:00 GMT</pubDate>
      <link>https://digital.nhs.uk/cyber-alerts/2026/cc-4769</link>
    </item>
    <item>
      <title>CC-4768 - Mitel Releases Security Advisory for MiCollab</title>
      <category>Medium</category>
      <author>enquiries@nhsdigital.nhs.uk (NHS Digital)</author>
      <description>&lt;p&gt;Severity: Medium&lt;/p&gt; &lt;p&gt;A critical SQL injection vulnerability could allow a remote unauthenticated attacker to access system information and execute arbitrary SQL database commands&lt;/p&gt;&lt;p&gt; A critical SQL injection vulnerability could allow a remote unauthenticated attacker to access system information and execute arbitrary SQL database commands&lt;/p&gt;&lt;p&gt; Updated: 09 Apr 2026&lt;/p&gt;</description>
      <guid isPermaLink="false">0860387a-08f8-48b5-a8ad-3faeeab62225</guid>
      <pubDate>Thu, 09 Apr 2026 12:20:00 GMT</pubDate>
      <link>https://digital.nhs.uk/cyber-alerts/2026/cc-4768</link>
    </item>
    <item>
      <title>CC-4767 - Progress Releases Security Updates for ShareFile Storage Zones Controller (SZC)</title>
      <category>Medium</category>
      <author>enquiries@nhsdigital.nhs.uk (NHS Digital)</author>
      <description>&lt;p&gt;Severity: Medium&lt;/p&gt; &lt;p&gt;Successful exploitation could allow an unauthenticated remote attacker to access on-prem storage zones controller’s configuration pages, potentially leading to changes in system configuration and remote code execution&lt;/p&gt;&lt;p&gt; Successful exploitation could allow an unauthenticated remote attacker to access on-prem storage zones controller’s configuration pages, potentially leading to changes in system configuration and remote code execution&lt;/p&gt;&lt;p&gt; Updated: 07 Apr 2026&lt;/p&gt;</description>
      <guid isPermaLink="false">e3d1a751-77e3-437b-8520-91eb55cd08db</guid>
      <pubDate>Tue, 07 Apr 2026 15:03:00 GMT</pubDate>
      <link>https://digital.nhs.uk/cyber-alerts/2026/cc-4767</link>
    </item>
  </channel>
</rss>
