Skip to main content
Griffin Technology PartnersGTP

Public security advisories

GTP Security Intelligence

Current vulnerabilities, known exploitation, Microsoft security updates, and practical guidance from Griffin Technology Partners.

Primary sources

Microsoft Security Response Center
CISA Known Exploited Vulnerabilities

Subscribe via RSS

Vulnerability intelligence

Security bulletins

Last collection: October 8, 2026
Six-hour refresh · Public-source information only

7,738 bulletins · Page 1 of 323

JSON feed
Severity not suppliedKnown exploited
CVE-2016-3081Apache

Apache Struts Command Injection Vulnerability

Apache Struts contains a command injection vulnerability that could allow remote attackers to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled.

CVSS
Not supplied
Update availability
Patch status unknown

Affected: Struts

Added to CISA KEV

Severity not suppliedKnown exploited
CVE-2023-22894Strapi

Strapi Cleartext Storage of Sensitive Information Vulnerability

Strapi contains a cleartext storage of sensitive information vulnerability that could allow attackers with access to the admin panel to discover sensitive user details via the query filter. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. This vulnerability can be chained with CVE-2023-22621 to achieve remote code execution.

CVSS
Not supplied
Update availability
Patch status unknown

Affected: Strapi

Added to CISA KEV

Medium
CVE-2026-37236Microsoft

grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control.

grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override header in ServeMux.ServeHTTP without restricting allowed methods. When a POST request with Content-Type application/x-www-form-urlencoded includes this header, the request method is rewritten to an arbitrary attacker-supplied value before routing. This allows bypassing method-based access controls enforced by upstream proxies or WAFs.

CVSS
5.3
Update availability
Security update available

Affected: azl3 cert-manager 1.12.15-11 on Azure Linux 3.0 · azl3 cert-manager 1.12.15-12 on Azure Linux 3.0 · +34 more

Updated

Sources & coverage

The collection starts with 90 days of Microsoft updates and CISA additions, plus older Microsoft vulnerabilities still listed by CISA. Older entries do not imply that a product remains supported. Counts describe this collection, not every vulnerability or any customer environment.

Microsoft Security Response Center (opens in a new tab)

Last successful check: October 8, 2026

CISA Known Exploited Vulnerabilities (opens in a new tab)

Last successful check: October 8, 2026

Managed by GTP?

Griffin Technology Partners managed customers may receive additional environment-specific security guidance and remediation assistance through their managed services relationship.

Security bulletins are provided for informational purposes and compiled from authoritative public sources. Vulnerability applicability varies by environment. Validate affected products, configuration, compatibility requirements, and vendor guidance before making production changes.