search
CVSS
Trends
- 1Oracle PeopleSoft flaw mass-exploited by ShinyHuntersโ๐ค Oracle PeopleSoft CVE-2026-35273 (CVSS 9.8, unauthenticated RCE) is being mass-exploited again by ShinyHunters. Attack
Attackers are mass-exploiting a critical Oracle PeopleSoft vulnerability, CVE-2026-35273, rated CVSS 9.8 as an unauthenticated remote code execution flaw. The ShinyHunters group is reportedly using URL-encoding tricks to bypass WAF rules before deploying web shells. Google has warned of global targeting across multiple sectors, and renewed exploitation waves are drawing fresh attention from security teams.
- 2Citrix patches two actively exploited NetScaler zero-daysโ๐จ CVE-2026-88771 & CVE-2026-88772: Citrix has patched two exploited NetScaler zero-days (CVSS 9.5). Update to 14.1-73.37
Citrix has released fixes for two NetScaler vulnerabilities, CVE-2026-88771 and CVE-2026-88772, both rated critical at CVSS 9.5 and both reportedly already exploited in the wild. Administrators are urged to update to NetScaler 14.1-73.37 or 13.1-64.23 and to check their systems for signs of compromise. Security teams worldwide are discussing the patch as urgent.
- 3D-Link DIR-895L routers hit by unpatched critical flawโผD-Link DIR-895L routers hit by CVE-2026-100740, a CVSS 9.9 vulnerability. No patch coming: the series reached end-of-lif
A critical vulnerability, CVE-2026-100740 with a CVSS score of 9.9, has been reported in D-Link DIR-895L routers. The company will not release a fix because the product line reached end-of-life in 2019. Security watchers are warning that affected devices remain exposed, with no vendor support available, and are urging users of the model to consider replacement or mitigation.
- 4Cross-site scripting flaw found in Greek Open eClass platformโผ๐จ EUVD-2024-55777 ๐ Score: 5.4/10 (CVSS v3.1) ๐ Published: 2026-09-29 | Updated: 2026-09-30 ๐ Cross Site Scripting vulne
A cross-site scripting vulnerability, tracked as EUVD-2024-55777, has been disclosed in the Greek Universities Network (GUnet) Open eClass Platform version 3.15. The flaw, rated 5.4 out of 10 on the CVSS v3.1 scale, could let a remote attacker execute arbitrary code through user name fields. The advisory was published on 29 September and updated the following day.
- 5Three unpatched critical flaws disclosed in LightLLMโผ๐จ LightLLM Mass Disclosure โ 3 CVEs, no patch CVE-2026-103040 (CVSS 9.8) โ unauthenticated RCE, router profiler RPyC CVE
Three vulnerabilities in LightLLM, an open-source large language model serving framework, have been disclosed without an available patch. The most serious, CVE-2026-103040, is rated 9.8 and allows unauthenticated remote code execution via the router profiler RPyC interface. A similar flaw, CVE-2026-103041, also rated 9.8, affects the embed cache RPyC service, while CVE-2026-103042, rated 7.5, enables memory exhaustion through the NCCL control channel. Security researchers are urging exposed deployments to restrict network access.
- 6Critical LightLLM flaw exposes AI servers to remote code executionโ๐จ CVE-2026-103041 โ CVSS 9.3 CRITICAL LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache
A critical vulnerability, CVE-2026-103041, has been disclosed affecting LightLLM through version 1.2.0. In multimodal deployments, the software exposes an unauthenticated RPyC cache service with pickle deserialization enabled on all interfaces. Security researchers warn attackers can send crafted serialized objects to exposed cache methods to execute arbitrary code remotely. With a CVSS score of 9.3, admins running LightLLM are being urged to review exposed services and update as soon as possible.
- 7Kilo Code vulnerability lets local attackers run codeโผ๐จ EUVD-2026-89423 ๐ Score: 8.4/10 (CVSS v3.1) ๐ Published: 2026-09-29 | Updated: 2026-09-30 ๐ An issue in Kilo Code befo
A high-severity flaw tracked as EUVD-2026-89423 affects Kilo Code versions before v7.4.1, scoring 8.4 out of 10 under CVSS v3.1. The issue, published on 29 September 2026 and updated a day later, allows a local attacker to execute arbitrary code through the permission or allow-everything endpoint. Users are urged to update to v7.4.1 or later.
- 8Two memory flaws found in CTranslate2 inference engineโผ๐จ CTranslate2 CVE-2026-102566 & CVE-2026-102567 The inference engine behind Whisper & OpenNMT has two memory flaws in it
Security researchers have disclosed two vulnerabilities in CTranslate2, the machine learning inference engine used by Whisper and OpenNMT. CVE-2026-102566, rated CVSS 7.8, is a heap buffer overflow in the model loader that could allow arbitrary code execution, while CVE-2026-102567, rated 6.1, is an out-of-bounds read enabling memory disclosure or crashes. Developers running speech recognition or translation services are being urged to patch.
- 9RaspAP hit with three unpatched CVE disclosuresโผ๐จ RaspAP Mass Disclosure โ 3 CVEs, no patch CVE-2026-101860 (CVSS 8.8) โ privilege escalation via sudoers manipulation โ
Security researchers have disclosed three vulnerabilities in RaspAP, the popular router software for Raspberry Pi, with no patches available. The most severe, CVE-2026-101860 with a CVSS score of 8.8, allows privilege escalation to root via sudoers manipulation. Two further flaws, CVE-2026-101859 (5.4) and CVE-2026-101858 (4.7), involve OS command injection, including through the OpenVPN handler and WiFiManager SSID handling.
- 10CPython vulnerability EUVD-2026-89183 disclosed with moderate severityโผ๐จ EUVD-2026-89183 ๐ Score: 5.9/10 (CVSS v3.1) ๐ฆ Product: CPython ๐ข Vendor: Python Software Foundation ๐ Updated: 2026-09
A vulnerability tracked as EUVD-2026-89183 has been disclosed in CPython, the reference implementation of the Python language maintained by the Python Software Foundation. The flaw concerns cleanup of tempfile.TemporaryDirectory, where a race condition could let an attacker who can modify the directory tree during cleanup swap in a directory in place of the intended one. It is rated 5.9 out of 10 on the CVSS v3.1 scale, a moderate severity score.
- 11ArgusMonitor Driver Vulnerability Flagged With Medium Severityโผ๐จ EUVD-2026-89424 ๐ Score: 5.3/10 (CVSS v3.1) ๐ Published: 2026-09-29 | Updated: 2026-09-30 ๐ Improper Access Control in
A newly tracked vulnerability, EUVD-2026-89424, describes improper access control in the ArgusMonitor.sys driver used by Argotronic eGbR's hardware monitoring tool ArgusMonitor, affecting version 7.4.02 and earlier. With a CVSS v3.1 score of 5.3, the flaw reportedly allows local, low-privileged users to bypass device handle access restrictions. Published on 29 September and updated the next day, it is drawing attention from security watchers tracking Windows driver weaknesses.
- 12Fastify vulnerability EUVD-2026-70998 rated 7.5 publishedโผ๐จ EUVD-2026-70998 ๐ Score: 7.5/10 (CVSS v3.1) ๐ฆ Product: fastify ๐ข Vendor: fastify ๐ Updated: 2026-09-30 ๐ fastify vulne
A new vulnerability, EUVD-2026-70998, has been recorded for Fastify, the popular Node.js web framework. The flaw, rated 7.5 out of 10 on CVSS v3.1, allows a header validation bypass caused by incomplete schema case normalization. The entry in the European vulnerability database was updated on 30 September 2026. Security teams using Fastify are expected to review the advisory and check whether their deployments are affected.
- 13Critical RCE vulnerability disclosed in LightLLMโ๐จ CVE-2026-103040 โ CVSS 9.3 CRITICAL LightLLM through 1.2.0 contains a remote code execution vulnerability in the route
A critical remote code execution flaw, tracked as CVE-2026-103040 with a CVSS score of 9.3, has been disclosed in LightLLM through version 1.2.0. The vulnerability sits in the router profiler service when launched with the --enable_profiling flag, which exposes an unauthenticated RPyC server with pickle deserialization enabled, letting attackers run arbitrary code. Security teams are being urged to check whether their deployments are affected.
- 14High-severity vulnerability disclosed in Capgo update serviceโผ๐จ EUVD-2026-87707 ๐ Score: 8.6/10 (CVSS v3.1) ๐ฆ Product: capgo.app ๐ข Vendor: Cap-go ๐ Published: 2026-09-26 | Updated: 2
A security advisory published as EUVD-2026-87707 describes a vulnerability in Capgo, the over-the-air update service for Capacitor apps, rated 8.6 out of 10 on the CVSS scale. Versions up to 12.261.0 reportedly contain an incomplete access-control fix for the public.sso_providers table, meaning earlier mitigation efforts did not fully close the flaw. The advisory was published on 26 September 2026 and updated on 30 September, prompting developers who rely on Capgo to check whether they need to update.
- 15Critical missing-authentication flaw reported in PTZOptics camerasโผ๐จ CVE-2026-75969 โ CVSS 9.1 CRITICAL Missing authentication for critical function vulnerability for all PTZOptics camera
A new critical vulnerability, tracked as CVE-2026-75969 with a CVSS score of 9.1, has been disclosed affecting all PTZOptics cameras and the Firmware Upgrade Tool's Firmware Update modules. The flaw is a missing authentication issue in the firmware update mechanism, meaning critical functions could be triggered without proper credentials. Security watchers are flagging the severity and the breadth of affected devices.
- 16Themeum WordPress plugins flagged over 33 unpatched vulnerabilitiesโผThemeum: 33 CVEs, max CVSS 10, and 100% unpatched. Trust score C. WordPress sites running these plugins carry real risk.
WordPress plugin developer Themeum is being flagged for 33 known CVEs with a maximum CVSS score of 10, all reportedly unpatched, earning the vendor a trust score of C. Security commentary warns that sites running its plugins carry real risk and urges administrators to review whether they depend on this software.
- 17Critical Kiteworks Email Gateway Flaw Tracked as CVE-2026-102149โ๐จ CVE-2026-102149 โ CVSS 9.4 CRITICAL Kiteworks Email Protection Gateway did not sufficiently restrict which account a c
A critical vulnerability, CVE-2026-102149, with a CVSS score of 9.4 has been disclosed in Kiteworks' Email Protection Gateway. The flaw stems from insufficient restrictions on which account a certificate could be assigned to, potentially letting an attacker associate a certificate with another user's account and compromising confidentiality. Security observers are flagging the issue and urging organizations using the gateway to review exposure and apply fixes.
- 18Fastify vulnerability EUVD-2026-70989 scores 7.5โผ๐จ EUVD-2026-70989 ๐ Score: 7.5/10 (CVSS v3.1) ๐ฆ Product: fastify ๐ข Vendor: fastify ๐ Updated: 2026-09-30 ๐ fastify vulne
A medium-high severity vulnerability, EUVD-2026-70989, has been catalogued in Fastify, the popular Node.js web framework. Rated 7.5 under CVSS v3.1, the flaw allows request validation bypass when boolean false schemas are skipped, potentially letting malformed requests through unchecked. The advisory was updated on 30 September 2026, and security teams using Fastify are being urged to review their validation logic and apply patches.
- 19Critical CVSS 9.8 flaw reported in OAuth SSO pluginโผ๐จ CVE-2026-97274 โ CVSS 9.8 CRITICAL Unauthenticated Bypass Vulnerability in OAuth Single Sign On โ SSO (OAuth Client) ๐
A critical vulnerability, CVE-2026-97274, has been disclosed in the OAuth Single Sign On โ SSO (OAuth Client) plugin, carrying a CVSS score of 9.8. The flaw is described as an unauthenticated authentication bypass, meaning attackers would not need credentials to exploit it. Security communities are circulating the advisory as organisations using OAuth-based single sign-on assess their exposure.
- 20Kiteworks Email Protection Gateway vulnerability logged with moderate severityโผ๐จ EUVD-2026-90275 ๐ Score: 6.5/10 (CVSS v3.1) ๐ฆ Product: Email Protection Gateway ๐ข Vendor: Kiteworks ๐ Updated: 2026-09
A new vulnerability, EUVD-2026-90275, has been recorded for Kiteworks' Email Protection Gateway, with a CVSS v3.1 score of 6.5 out of 10. The flaw concerns an authorization check in the large file exchange feature that failed to correctly verify whether the requesting user was entitled to access the resource. The entry was updated on 30 September 2026. Security teams monitoring Kiteworks deployments are expected to review the advisory and patch guidance.
- 21Critical vulnerability CVE-2026-62308 disclosed in Tugtainerโผ๐จ CVE-2026-62308 โ CVSS 9.1 CRITICAL Tugtainer is a self-hosted app for automating updates of Docker containers. Prior t
A critical vulnerability, CVE-2026-62308 with a CVSS score of 9.1, has been disclosed in Tugtainer, a self-hosted application for automating Docker container updates. Versions prior to 1.30.6 allow an authenticated user to make the backend server send outbound HTTP requests to arbitrary user-supplied URLs, a server-side request forgery flaw. Admins running affected versions are urged to update to 1.30.6 or later.
- 22Fastify vulnerability allows authentication bypass via malformed URLsโผ๐จ EUVD-2026-70988 ๐ Score: 7.5/10 (CVSS v3.1) ๐ฆ Product: fastify ๐ข Vendor: fastify ๐ Updated: 2026-09-30 ๐ fastify vulne
A newly catalogued vulnerability, EUVD-2026-70988, affects the Fastify web framework, rated 7.5 out of 10 on the CVSS v3.1 scale. The flaw allows authentication bypass when malformed URLs reach encapsulated not-found handlers, meaning requests intended to be blocked could slip through route protections. Fastify is a widely used Node.js framework, so developers running exposed services are being urged to review the advisory and update to a patched version.
- 23Critical flaw in Digiwin EasyFlow .NET exposes plaintext passwordsโ๐จ CVE-2026-102458 โ CVSS 9.3 CRITICAL EasyFlow .NET developed by Digiwin has a Missing Authentication vulnerability. Una
A critical vulnerability, CVE-2026-102458 with a CVSS score of 9.3, has been disclosed in EasyFlow .NET, enterprise software developed by Taiwanese vendor Digiwin. The flaw is a missing authentication issue: unauthenticated remote attackers can use a specific API to obtain other users' plaintext passwords. Security watchers are sharing details and urging affected organisations to review exposure and patch quickly.
- 24Kiteworks Core deserialization flaw logged as high-severity vulnerabilityโผ๐จ EUVD-2026-90276 ๐ Score: 8.1/10 (CVSS v3.1) ๐ฆ Product: core ๐ข Vendor: Kiteworks ๐ Updated: 2026-09-30 ๐ Kiteworks Core
Kiteworks Core versions before 9.5.0 are affected by a deserialization of untrusted data vulnerability, tracked as EUVD-2026-90276 with a CVSS v3.1 score of 8.1. Under certain conditions, the flaw could allow attackers to send crafted data that is deserialized unsafely, potentially leading to code execution. The advisory was updated on September 30, 2026, and users are advised to upgrade to version 9.5.0 or later.
- 25Security audit flags 57 vulnerabilities in Vim editorโผVim: 57 CVEs, max CVSS 9.2, 52% unpatched. Top flaws: heap overflow (CWE-122), code injection (CWE-94). Plugins widen th
A new security analysis reports 57 CVEs in the Vim text editor, with a maximum severity score of 9.2 and roughly 52% still unpatched. The most serious flaws are heap overflows and code injection bugs, and the report warns that third-party plugins expand the attack surface. Security practitioners are urging users to audit their Vim configurations and update promptly.
- 26Critical unauthenticated PHP object injection flaw flagged in Booking Activitiesโผ๐จ CVE-2026-97248 โ CVSS 9.8 CRITICAL Unauthenticated PHP Object Injection in Booking Activities ๐ Details: https:// stem
Security researchers are warning about CVE-2026-97248, a critical vulnerability in the Booking Activities plugin rated 9.8 on the CVSS scale. The flaw is an unauthenticated PHP object injection issue, meaning remote attackers could potentially exploit it without any credentials. Details are being circulated in infosec communities as administrators are urged to check their installations and patch promptly.
- 27Critical vulnerability disclosed in Docker update tool Tugtainerโผ๐จ CVE-2026-55494 โ CVSS 9.8 CRITICAL Tugtainer is a self-hosted app for automating updates of Docker containers. Prior t
A critical flaw, CVE-2026-55494 with a CVSS score of 9.8, has been disclosed in Tugtainer, a self-hosted application for automating Docker container updates. Versions before 1.30.4 expose unauthenticated access to Docker management APIs when the AGENT_SECRET setting is not configured. Self-hosting and security communities are urging users to update immediately, warning that unpatched instances could let attackers take control of containers.
- 28Microsoft patches high-severity Visual Studio heap overflow flawโผ๐จ EUVD-2026-73170 ๐ Score: 8.8/10 (CVSS v3.1) ๐ฆ Product: .NET 10.0, Microsoft Visual Studio 2022 version 17.14, Microsof
Microsoft's Visual Studio 2022 version 17.14, .NET 10.0 and .NET Framework 4.8 are affected by a vulnerability tracked as EUVD-2026-73170, rated 8.8 out of 10 on the CVSS v3.1 scale. The flaw is a heap-based buffer overflow in Visual Studio, and the advisory was published on 8 September 2026 with an update issued on 29 September 2026. Security trackers are flagging the high severity rating, urging developers using affected Microsoft products to check whether they need to update.
- 29Google Chrome patches critical memory flawโผ๐จ EUVD-2026-89143 ๐ Score: 9.6/10 (CVSS v3.1) ๐ฆ Product: Chrome ๐ข Vendor: Google ๐ Published: 2026-09-29 | Updated: 2026
A critical vulnerability, EUVD-2026-89143, has been disclosed in Google Chrome with a CVSS score of 9.6. The flaw involves non-heap memory handling in the browser's Fonts component and could allow a remote attacker, working alongside social engineering, to potentially compromise systems. The fix is included in Chrome 154.0.8037.57, published 29 September 2026 and updated the following day. Security watchers are flagging the severity rating and urging users to update their browsers promptly.
- 30Critical CVSS 10 flaw CVE-2026-71379 allows unauthenticated data exportโ๐จ CVE-2026-71379 โ CVSS 10 CRITICAL The file export endpoint allows any unauthenticated attacker to export arbitrary dat
A vulnerability tracked as CVE-2026-71379, rated CVSS 10, is drawing attention in the cybersecurity community. The flaw lies in a file export endpoint that lets any unauthenticated attacker export arbitrary database tables via a crafted POST request. Security feeds are flagging it as maximum-severity, urging organizations to check whether their systems are affected and patch promptly.
- 31Critical Zimbra flaw CVE-2026-73570 actively exploitedโ๐ค CVE-2026-73570 (CVSS 8.9): unauthenticated OS command injection in Zimbra Collaboration Suite via its SNMP service, no
A critical vulnerability, CVE-2026-73570 with a CVSS score of 8.9, in Zimbra Collaboration Suite allowed unauthenticated attackers to run operating system commands through its SNMP service. According to Microsoft Security Research, attackers exploited the flaw to deploy web shells and steal mailbox credentials. A patch has been released, and security teams are urged to update affected servers promptly.
- 32IBM patches high-severity code execution flaw in DataStageโผ๐จ EUVD-2026-89197 ๐ Score: 8.8/10 (CVSS v3.1) ๐ฆ Product: DataStage on Cloud Pak for Data ๐ข Vendor: IBM ๐ Updated: 2026-0
A new vulnerability, tracked as EUVD-2026-89197, has been disclosed in IBM DataStage on Cloud Pak for Data 5.4.0.0. Rated 8.8 out of 10 on the CVSS v3.1 scale, the flaw could let a remote authenticated attacker execute arbitrary code because of improper path validation. Security teams monitoring IBM products are flagging the advisory as organisations assess whether their deployments are affected and await a fix.
- 33Medium-severity vulnerability found in Naichen ThinkCMFโผ๐จ EUVD-2026-89477 ๐ Score: 5.1/10 (CVSS v3.1) ๐ฆ Product: ThinkCMF, ThinkCMF, ThinkCMF (+5 more) ๐ข Vendor: Naichen ๐ Upda
A security vulnerability, tracked as EUVD-2026-89477, has been identified in Naichen's ThinkCMF content management framework in versions up to 8.0.7. The flaw carries a CVSS v3.1 score of 5.1 out of 10, marking it as moderate severity. The advisory was updated on 29 September 2026, and multiple ThinkCMF product entries are listed as affected. Details of the vulnerable function remain limited in the published notice.
- 34Critical insecure deserialization flaw reported in Digiwin EasyFlow .NETโ๐จ CVE-2026-102455 โ CVSS 9.3 CRITICAL EasyFlow .NET developed by Digiwin has a Insecure Deserialization vulnerability. U
A critical vulnerability, tracked as CVE-2026-102455 with a CVSS score of 9.3, has been reported in EasyFlow .NET, software developed by Taiwanese vendor Digiwin. According to the advisory, unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content, exploiting insecure deserialization. Organizations running the software are being urged to review the details and apply fixes promptly.
- 35High-severity vulnerability disclosed in MobilityDBโผ๐จ EUVD-2026-89198 ๐ Score: 7.1/10 (CVSS v3.1) ๐ฆ Product: MobilityDB, MobilityDB, MobilityDB ๐ข Vendor: MobilityDB ๐ Updat
A security advisory, EUVD-2026-89198, flags an out-of-bounds read vulnerability in MobilityDB version 1.3.0 and earlier, located in the MEOS binary and library WKB deserialization logic. The flaw carries a CVSS v3.1 score of 7.1, marking it as high severity. The advisory was updated on 2026-09-29, and users of the open-source moving-object database extension are being urged to check for patched releases.
- 36High-severity command injection flaw fixed in Renovateโผ๐จ EUVD-2024-55728 ๐ Score: 8.4/10 (CVSS v3.1) ๐ฆ Product: renovate ๐ข Vendor: renovatebot ๐ Published: 2026-08-19 | Update
A high-severity vulnerability, EUVD-2024-55728, was published for Renovate, the popular open-source dependency update tool maintained by renovatebot. Versions 37.158.0 before 37.199.0 contain a command injection flaw in the helmv3 manager's registryAliases handling, rated 8.4 out of 10 on the CVSS v3.1 scale. Users are being urged to update to a patched release, as the bug could allow attackers to execute arbitrary commands through manipulated registry alias values.
- 37Critical unauthenticated SQL injection flaw reported in Books Galleryโ๐จ CVE-2026-96822 โ CVSS 9.3 CRITICAL Unauthenticated SQL Injection in Books Gallery ๐ Details: https:// stemshop.top/cve
Security researchers have flagged CVE-2026-96822, a critical vulnerability in the Books Gallery application, rated CVSS 9.3. The flaw is described as an unauthenticated SQL injection, meaning attackers need no credentials to exploit it remotely. Details and mitigation guidance are being circulated on security channels, with administrators urged to patch or isolate affected deployments quickly.
- 38Critical CVE-2026-70356 flagged in TMS file upload endpointโ๐จ CVE-2026-70356 โ CVSS 9.4 CRITICAL The TMS file upload endpoint fails to enforce server-side file type restrictions, a
A new critical vulnerability, CVE-2026-70356 with a CVSS score of 9.4, has been disclosed affecting a TMS file upload endpoint. The flaw allows attackers to bypass server-side file type restrictions and upload malicious PHP files that can then be executed on the web server. Security researchers are sharing details of the bug, urging administrators to review and patch affected systems.
- 39Critical Apache PLC4X vulnerability CVE-2026-102508 disclosedโ๐จ CVE-2026-102508 โ CVSS 9.2 CRITICAL Improper Verification of Cryptographic Signature and Improper Certificate Validati
A critical vulnerability, CVE-2026-102508 with a CVSS score of 9.2, has been disclosed in the OPC UA driver of Apache PLC4X (PLC4J). The flaw involves improper cryptographic signature verification and certificate validation, allowing a network attacker positioned between client and server to impersonate the OPC UA server. Security watchers are urging industrial users of the library to patch promptly.
- 40Medium-severity FTP flaw disclosed in Eclipse NetX Duoโผ๐จ EUVD-2026-89199 ๐ Score: 6.0/10 (CVSS v3.1) ๐ฆ Product: NetX Duo ๐ข Vendor: Eclipse Foundation ๐ Updated: 2026-09-29 ๐ F
A medium-severity vulnerability, EUVD-2026-89199, has been catalogued in Eclipse Foundation's NetX Duo embedded network stack. Rated 6.0 out of 10 under CVSS v3.1, the flaw lies in the FTP component, where passive data connections are not bound to the authenticated control peer, potentially allowing session mixing. The entry was updated on 29 September 2026 via the EU vulnerability database maintained by ENISA.