Skip to content

other

CERT Polska

CERT Polska (CERT.PL), run by NASK, is Poland's national cyber incident response team, tracking threats and publishing vulnerability advisories.

Known aliases

  • CERT.PL
  • CERT Poland
  • Polish Computer Emergency Response Team

Relationships

No evidence-backed relationships are recorded.

Current stories

security3 publishers

CISA warns a single unauthenticated request can root MikroTik RouterOS below 7.24

CISA says an integer underflow in MikroTik RouterOS web management gives an unauthenticated attacker root with one crafted request on versions below 7.24. No exploitation has been reported, but MikroTik's fix advice sets a 7.23 floor that CISA's own affected range still covers.

Perspective Coverage

3 publishers
Builder
Builder 27%
Operator
Operator 66%
Investor
Investor 7%

Reality

Evidence64
Adoption70
Hype gap+8
Incentives
Insufficient
Confidence62
security4 publishers

Crafted emails give attackers shells on Zimbra servers running SNMP notifications

Microsoft says attackers are using CVE-2026-73570 to run commands on Zimbra mail servers with one crafted email and no login. Zimbra shipped the fix in 10.1.20 on July 20, 24 days before disclosure, so anyone who waited for the advisory to patch was already late.

Perspective Coverage

4 publishers
Builder
Builder 21%
Operator
Operator 68%
Investor
Investor 11%

Reality

Evidence80
Adoption40
Hype gap+5
Incentives
Insufficient
Confidence75
security3 publishers

SQL injection in Qbusoft's Medyc software exposed Polish patients' PESEL numbers

Qbusoft confirmed an attacker stole patient data from its Medyc clinic software through an SQL injection flaw that went unnoticed for about 17 days. It is the second Polish clinic-software supplier to lose ID numbers in weeks, after MyDr lost data on nearly 19 million people in August.

Perspective Coverage

3 publishers
Builder
Builder 28%
Operator
Operator 54%
Investor
Investor 18%

Reality

Evidence68
Adoption
Insufficient
Hype gap+5
Incentives55
Confidence72
security7 publishers

Default self-registration hands unauthenticated attackers Gitea's exploited RCE on 8,393 servers

Gitea shipped a fix for CVE-2026-60004 on July 27 and CISA gave federal agencies until August 28, yet a month later Shadowserver still counts 8,393 exposed instances, and on shipped defaults the bug needs no credentials.

Perspective Coverage

7 publishers
Builder
Builder 22%
Operator
Operator 67%
Investor
Investor 11%

Reality

Evidence62
Adoption40
Hype gap+20
Incentives
Insufficient
Confidence58
security8 publishers

Exposed MikroTik SSH hands over full administrative control without authentication

CERT Polska dated successful attacks to at least September 2 and published its warning on September 5, so operators who deferred the RouterOS update have three days of configuration changes to read as well as a patch to install.

Perspective Coverage

8 publishers
Builder
Builder 19%
Operator
Operator 73%
Investor
Investor 8%

Reality

Evidence78
Adoption45
Hype gap+18
Incentives30
Confidence72
security3 publishers

MikroTik's new RouterOS builds check whether the device was already compromised

MikroTik published RouterOS fixes in four branches with no CVE and no technical detail. The same upgrade runs a compromise check and writes a critical log entry marking the device Flagged.

Publishers:cert.plforum.mikrotik.comhelpnetsecurity.com

Perspective Coverage

3 publishers
Builder
Builder 22%
Operator
Operator 71%
Investor
Investor 7%

Reality

Evidence76
Adoption
Insufficient
Hype gap−40
Incentives45
Confidence72
security13 publishers

CISA sets a September 13 deadline for the MikroTrick RouterOS chain

Federal agencies now have three separate patch deadlines inside twelve days. The lowest-scoring pair of the five flaws added to KEV is the one with a documented 24-day intrusion campaign behind it.

Perspective Coverage

13 publishers
Builder
Builder 21%
Operator
Operator 76%
Investor
Investor 3%

Reality

Evidence68
Adoption
Insufficient
Hype gap+15
Incentives50
Confidence66