Overview : Microsoft has released an emergency out-of-band security update to remediate CVE-2026-21509, a high-severity zero-day vulnerability actively exploited in the wild. The flaw affects all supported Microsoft Office versions, including Microsoft 365 Apps for Enterprise, Office LTSC 2024, Office LTSC 2021, Office 2019, and Office 2016. It enables attackers…
Overview CVE‑2026‑21986 is a high‑severity vulnerability identified in the core component of Oracle VM VirtualBox, a widely used virtualization platform. The issue allows an unauthenticated attacker with local access to the host infrastructure where VirtualBox executes to cause a denial‑of‑service condition in affected VirtualBox instances. This advisory outlines the technical…
Risk: High UgCERT issues this high-severity advisory to alert stakeholders to active campaigns involving the ViperSoftX Remote Access Trojan (RAT), a sophisticated malware threat targeting various systems in Uganda. Platforms Affected:Windows; Linux, Chromium-based browsers, MacOS Summary:ViperSoftX is an information stealer focusing on cryptocurrency theft and credential harvesting, often delivered via…
Risk: High UgCERT has observed the possible spread of Android Vo1D malware infections on several networks in Uganda. Platforms Affected:Android (AOSP-based TV boxes and uncertified devices) Summary:Android.Vo1d is a persistent backdoor malware that primarily targets Android-based TV boxes and uncertified AOSP devices lacking Google Play Protect. The malware is commonly…
Colville Street, Communications House
P.O. Box 7376
Kampala, Uganda
Tel: + 256 414 339000/ 312 339000
Fax: + 256 414 348832
E-mail: cert@ucc.co.ug