ENISA EUVD · EUVD-2026-1465Official EUVD mappingReact Router is a router for React. In @remix-run/router version prior to 1.23.2 and react-router 7.0.0 through 7.11.0, React Router (and Remix v1/v2) SPA open navigation redirects originating from loaders or actions in Framework Mode, Data Mode, or the unstable RSC modes can result in unsafe URLs causing unintended javascript execution on the client. This is only an issue if you are creating redirect paths from untrusted content or via an open redirect. There is no impact if Declarative Mode (<BrowserRouter>) is being used. This issue has been patched in @remix-run/router version 1.23.2 and react-router version 7.12.0.
Official EUVD record ↗BSI · German · WID-SEC-2026-1608Atlassian Produkte (Bamboo, Bitbucket, Confluence, Crucible, Fisheye und Jira): Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Atlassian Bitbucket, Atlassian Confluence, Atlassian Crucible, Atlassian Fisheye und Atlassian Jira ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um einen Cross-Site Scripting Angriff durchzuführen, und um Sicherheitsvorkehrungen zu umgehen.
Official advisory ↗BSI · German · WID-SEC-2026-1229Atlassian Bamboo, Bitbucket, Confluence, Jira: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Atlassian Bitbucket, Atlassian Confluence und Atlassian Jira ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder offenzulegen oder Cross-Site-Scripting-Angriffe durchzuführen.
Official advisory ↗BSI · German · WID-SEC-2026-1007IBM App Connect Enterprise: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen, um einen SQL-Injection Angriff durchzuführen, und um beliebigen Programmcode auszuführen.
Official advisory ↗BSI · German · WID-SEC-2026-0752IBM SPSS: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in IBM SPSS ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen, um einen Denial of Service Angriff durchzuführen, und um Dateien zu manipulieren.
Official advisory ↗BSI · German · WID-SEC-2026-0553HCL BigFix: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in HCL BigFix ausnutzen, um Informationen offenzulegen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, und um Dateien zu manipulieren.
Official advisory ↗Cyber Security Agency of Singapore · English · CSA-SB-20260114Security Bulletin 14 Jan 2026The Cyber Security Agency of Singapore included this CVE in its official Security Bulletin 14 Jan 2026, published on 14 January 2026. Open the linked bulletin for the product, severity and reference information published in that issue.
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0901Multiples vulnérabilités dans les produits IBMd?id=CVE-2026-14501
Référence CVE CVE-2026-21441
https://www.cve.org/CVERecord?id=CVE-2026-21441
Référence CVE CVE-2026-21860
https://www.cve.org/CVERecord?id=CVE-2026-21860
Référence CVE CVE-2026-22007
https://www.cve.org/CVERecord?id=CVE-2026-22007
Référence CVE CVE-2026-22008
https://www.cve.org/CVERecord?id=CVE-2026-22008
Référence CVE CVE-2026-22013
https://www.cve.org/CVERecord?id=CVE-2026-22013
Référence CVE CVE-2026-22016
https://www.cve.org/CVERecord?id=CVE-2026-22016
Référence CVE CVE-2026-22018
https://www.cve.org/CVERecord?id=CVE-2026-22018
Référence CVE CVE-2026-22021
https://www.cve.org/CVERecord?id=CVE-2026-22021
Référence CVE CVE-2026-22029
https://www.cve.org/CVERecord?id=CVE-2026-22029
Référence CVE CVE-2026-2332
https://www.cve.org/CVERecord?id=CVE-2026-2332
Référence CVE CVE-2026-23479
https://www.cve.org/CVERecord?id=CVE-2026-23479
Référence CVE CVE-2026-23490
https://www.cve.org/CVERecord?id=CVE-2026-23490
Référence CVE CVE-2026-2359
https://www.cve.org/CVERecord?id=CVE-2026-2359
Référence CVE CVE-2026-23631
https://www.cve.org/CVERecord?id=CVE-2026-23631
Référence CVE CVE-2026-23745
https://www.cve.org/CVERecord?id=CVE-2026-23745
Référence CVE CVE-2026-23865
https://www.cve.org/CVERecord?id=CVE-2026-23865
Référence CVE CVE-2026-2391
https://www.cve.org/CVERecord?id=CVE-2
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0834Multiples vulnérabilités dans les produits IBMERecord?id=CVE-2026-11595
Référence CVE CVE-2026-11707
https://www.cve.org/CVERecord?id=CVE-2026-11707
Référence CVE CVE-2026-11708
https://www.cve.org/CVERecord?id=CVE-2026-11708
Référence CVE CVE-2026-11712
https://www.cve.org/CVERecord?id=CVE-2026-11712
Référence CVE CVE-2026-11714
https://www.cve.org/CVERecord?id=CVE-2026-11714
Référence CVE CVE-2026-1352
https://www.cve.org/CVERecord?id=CVE-2026-1352
Référence CVE CVE-2026-13772
https://www.cve.org/CVERecord?id=CVE-2026-13772
Référence CVE CVE-2026-1577
https://www.cve.org/CVERecord?id=CVE-2026-1577
Référence CVE CVE-2026-1718
https://www.cve.org/CVERecord?id=CVE-2026-1718
Référence CVE CVE-2026-22029
https://www.cve.org/CVERecord?id=CVE-2026-22029
Référence CVE CVE-2026-2327
https://www.cve.org/CVERecord?id=CVE-2026-2327
Référence CVE CVE-2026-2391
https://www.cve.org/CVERecord?id=CVE-2026-2391
Référence CVE CVE-2026-24001
https://www.cve.org/CVERecord?id=CVE-2026-24001
Référence CVE CVE-2026-24040
https://www.cve.org/CVERecord?id=CVE-2026-24040
Référence CVE CVE-2026-24043
https://www.cve.org/CVERecord?id=CVE-2026-24043
Référence CVE CVE-2026-24133
https://www.cve.org/CVERecord?id=CVE-2026-24133
Référence CVE CVE-2026-24737
https://www.cve.org/CVERecord?id=CVE-2026-24737
Référence CVE CVE-2026-25535
https://www.cve.org/CVERecord?id=CVE-
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0621Multiples vulnérabilités dans les produits AtlassianDe multiples vulnérabilités ont été découvertes dans les produits Atlassian. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0523Multiples vulnérabilités dans les produits IBMord?id=CVE-2024-31033
Référence CVE CVE-2025-13465
https://www.cve.org/CVERecord?id=CVE-2025-13465
Référence CVE CVE-2025-15284
https://www.cve.org/CVERecord?id=CVE-2025-15284
Référence CVE CVE-2025-15599
https://www.cve.org/CVERecord?id=CVE-2025-15599
Référence CVE CVE-2025-66035
https://www.cve.org/CVERecord?id=CVE-2025-66035
Référence CVE CVE-2025-66412
https://www.cve.org/CVERecord?id=CVE-2025-66412
Référence CVE CVE-2025-67030
https://www.cve.org/CVERecord?id=CVE-2025-67030
Référence CVE CVE-2025-68470
https://www.cve.org/CVERecord?id=CVE-2025-68470
Référence CVE CVE-2026-0540
https://www.cve.org/CVERecord?id=CVE-2026-0540
Référence CVE CVE-2026-22029
https://www.cve.org/CVERecord?id=CVE-2026-22029
Référence CVE CVE-2026-22610
https://www.cve.org/CVERecord?id=CVE-2026-22610
Référence CVE CVE-2026-22735
https://www.cve.org/CVERecord?id=CVE-2026-22735
Référence CVE CVE-2026-22737
https://www.cve.org/CVERecord?id=CVE-2026-22737
Référence CVE CVE-2026-2391
https://www.cve.org/CVERecord?id=CVE-2026-2391
Référence CVE CVE-2026-24051
https://www.cve.org/CVERecord?id=CVE-2026-24051
Référence CVE CVE-2026-26278
https://www.cve.org/CVERecord?id=CVE-2026-26278
Référence CVE CVE-2026-27601
https://www.cve.org/CVERecord?id=CVE-2026-27601
Référence CVE CVE-2026-27970
https://www.cve.org/CVERecord?id=CV
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0479Multiples vulnérabilités dans les produits AtlassianRecord?id=CVE-2022-1471
Référence CVE CVE-2023-1370
https://www.cve.org/CVERecord?id=CVE-2023-1370
Référence CVE CVE-2023-3635
https://www.cve.org/CVERecord?id=CVE-2023-3635
Référence CVE CVE-2023-48631
https://www.cve.org/CVERecord?id=CVE-2023-48631
Référence CVE CVE-2024-29371
https://www.cve.org/CVERecord?id=CVE-2024-29371
Référence CVE CVE-2024-45801
https://www.cve.org/CVERecord?id=CVE-2024-45801
Référence CVE CVE-2024-47875
https://www.cve.org/CVERecord?id=CVE-2024-47875
Référence CVE CVE-2025-48734
https://www.cve.org/CVERecord?id=CVE-2025-48734
Référence CVE CVE-2025-66020
https://www.cve.org/CVERecord?id=CVE-2025-66020
Référence CVE CVE-2026-22029
https://www.cve.org/CVERecord?id=CVE-2026-22029
Référence CVE CVE-2026-23745
https://www.cve.org/CVERecord?id=CVE-2026-23745
Référence CVE CVE-2026-23950
https://www.cve.org/CVERecord?id=CVE-2026-23950
Référence CVE CVE-2026-24842
https://www.cve.org/CVERecord?id=CVE-2026-24842
Référence CVE CVE-2026-25547
https://www.cve.org/CVERecord?id=CVE-2026-25547
Référence CVE CVE-2026-25639
https://www.cve.org/CVERecord?id=CVE-2026-25639
Référence CVE CVE-2026-26960
https://www.cve.org/CVERecord?id=CVE-2026-26960
Référence CVE CVE-2026-29063
https://www.cve.org/CVERecord?id=CVE-2026-29063
Référence CVE CVE-2026-31802
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0424Multiples vulnérabilités dans les produits IBMd?id=CVE-2020-12723
Référence CVE CVE-2025-12194
https://www.cve.org/CVERecord?id=CVE-2025-12194
Référence CVE CVE-2025-40909
https://www.cve.org/CVERecord?id=CVE-2025-40909
Référence CVE CVE-2025-68161
https://www.cve.org/CVERecord?id=CVE-2025-68161
Référence CVE CVE-2026-21884
https://www.cve.org/CVERecord?id=CVE-2026-21884
Référence CVE CVE-2026-21925
https://www.cve.org/CVERecord?id=CVE-2026-21925
Référence CVE CVE-2026-21932
https://www.cve.org/CVERecord?id=CVE-2026-21932
Référence CVE CVE-2026-21933
https://www.cve.org/CVERecord?id=CVE-2026-21933
Référence CVE CVE-2026-21945
https://www.cve.org/CVERecord?id=CVE-2026-21945
Référence CVE CVE-2026-22029
https://www.cve.org/CVERecord?id=CVE-2026-22029
Référence CVE CVE-2026-22030
https://www.cve.org/CVERecord?id=CVE-2026-22030
Référence CVE CVE-2026-2327
https://www.cve.org/CVERecord?id=CVE-2026-2327
Référence CVE CVE-2026-23950
https://www.cve.org/CVERecord?id=CVE-2026-23950
Référence CVE CVE-2026-24688
https://www.cve.org/CVERecord?id=CVE-2026-24688
Référence CVE CVE-2026-24842
https://www.cve.org/CVERecord?id=CVE-2026-24842
Référence CVE CVE-2026-25528
https://www.cve.org/CVERecord?id=CVE-2026-25528
Référence CVE CVE-2026-25639
https://www.cve.org/CVERecord?id=CVE-2026-25639
Référence CVE CVE-2026-26007
https://www.cve.org/CVERecord?id=CV
Official advisory ↗JVN iPedia · Japanese · JVNDB-2026-003109ShopifyのReact Router等の複数製品におけるクロスサイトスクリプティングの脆弱性React RouterはReact用のルーターです。@remix-run/routerのバージョン1.23.2未満およびreact-routerのバージョン7.0.0から7.11.0までにおいて、React Router(およびRemix v1/v2)のSPAオープンナビゲーションが、Framework Mode、Data Mode、または不安定なRSCモードのローダーやアクションから発生するリダイレクトで、クライアント側で意図しないJavaScriptが実行される安全でないURLを生成する可能性があります。これは信頼されていないコンテンツからリダイレクトパスを作成する場合やオープンリダイレクトを介する場合にのみ問題となります。Declarative Mode (BrowserRouter)を使用している場合は影響を受けません。この問題は@remix-run/routerのバージョン1.23.2およびreact-routerのバージョン7.12.0で修正されました。
Official advisory ↗