CERT VU advisories & alerts disclose current reported cyber security vulnerabilities and threats identified in Vanuatu. The advisories deliver provide a summary of the threat analysed. Descriptions of the threat reported and mitigation procedures are provided as part of the advisory on how to mitigate the threats to minimise their impacts. Finally, a Traffic Light Protocol (TLP: Colour – See guides page for more information) indicator to show the level or information security and sharing rights.

Advisory 38

Impact: High/Critical

TLP Rating: Clear

VMware Tools vulnerabilities (CVE-2023-34057 & CVE-2023-34058)

Release Date 30th of October 2023

Advisory 37

Impact: High

TLP Rating: Clear

HTTP/2 Rapid Reset Vulnerability, CVE-2023-44487

Release Date 12th of October 2023

Advisory 36

Impact: High

TLP Rating: Clear

CVE -2023-41991 – Apple Multiple Products Improper Certificate validation Vulnerability.

CVE -2023-41992 – Apple Multiple Products Kernel Privilege Escalation Vulnerability.

CVE -2023-41993 – Apple Multiple Products WebKit code Execution Vulnerability

Release Date 25th of September 2023

Advisory 35

Impact: High

TLP Rating: Clear

CERT Vanuatu (CERTVU) and the Office of the Chief Information Officer (OGCIO) provides the following advisory.

On the 16th of August 2023, CERT Vanuatu received an advisory from its collaborating partner, Cybersecurity Infrastructure Security Agency (CISA) of a vulnerability in Citrix systems.

Advisory 34

Impact: High

TLP Rating: Clear

CERT Vanuatu (CERTVU) and the Office of the Chief Information Officer (OGCIO) provides the following advisory.


On the 19th of July 2023, CERT Vanuatu received an advisory from its collaborating partner, Cybersecurity Infrastructure Security Agency (CISA) on multiple vulnerabilities discovered in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway).

Advisory 33

Impact: High

TLP Rating: Clear

CERT Vanuatu (CERTVU) and the Office of the Chief Information Officer (OGCIO) provide the following advisory.


Microsoft has addressed 130 vulnerability and provide instructions to fully resolve several bugs. IT administrators and personnels are required apply necessary patches and updates for these vulnerabilities.