National cybersecurity authorities warned of a critical vulnerability in MISP (Malware Information Sharing Platform), affecting versions prior to v2.5.39. Belgium's Centre for Cybersecurity issued an urgent advisory telling organizations to patch immediately, while Canada's Centre for Cyber Security said MISP had published a security advisory covering the flaws and identified v2.5.39 as the fixed release.
The notices urge administrators and users running vulnerable MISP deployments to review the vendor's advisory and apply the update without delay. Organizations using MISP for threat-intelligence sharing face elevated risk until systems are upgraded, making prompt remediation and verification of deployed versions a priority.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security issued notice AV26-565 advising users and administrators to review MISP's advisory materials and apply the necessary updates for affected versions prior to v2.5.39. The notice points to MISP version 2.5.39 as the relevant updated release.
The Centre for Cybersecurity Belgium published an advisory warning of a critical vulnerability in MISP and telling users to patch immediately. The reference indicates the warning was published on June 8, 2026.
MISP published a security advisory on June 4, 2026 addressing vulnerabilities affecting MISP versions prior to v2.5.39. The advisory identifies version 2.5.39 as the updated release to remediate the issues.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecyber.gc.ca
Open sourceccb.belgium.be
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.