CISA reports SignalRGB SignalIo.sys IOCTL flaws and fix
SignalRGB’s SignalIo.sys has improper access control and NULL-pointer IOCTL flaws fixed in driver version 1.3.7.0.
Decision Insights Threat Desk • June 17, 2026
SignalRGB’s SignalIo.sys has improper access control and NULL-pointer IOCTL flaws fixed in driver version 1.3.7.0.
Decision Insights Threat Desk • June 11, 2026
CISA guidance describes a crypton-x509-validation NameConstraints enforcement failure in Haskell TLS, tracked as CVE-2026-9648, where a sub-CA can validate certificates outside permitted SAN scopes for full session visibility. The fix is version 1.9.1.
Decision Insights Threat Desk • June 9, 2026
Microsoft-signed UEFI shim bootloaders from version 0.9 and earlier were found vulnerable to Secure Boot bypass via BYOVD-style early-boot execution.
Decision Insights Threat Desk • June 3, 2026
CISA’s advisory on the Securly Chrome Extension describes version 3.0.7 vulnerabilities in data transmission, encryption, and access control that could expose filtering rules, enable configuration manipulation, and allow unauthorized data access.
Decision Insights Threat Desk • June 2, 2026
Collibra Platform Agent issues CVE-2026-10622 and CVE-2026-10621 enable unauthenticated chaining to remote code execution via crafted ZIP restore.
Decision Insights Threat Desk • June 2, 2026
Stored XSS in Appsmith’s SQL editor autocomplete can execute JavaScript in other users’ browsers, tracked as CVE-2026-7299.