Výsledky hledání

zdroj: Microsoft Security× v celém archivu zrušit filtry

2906 karet z 2906 položek · strana 17 z 49 CZ · EN/orig

10

ZDI-26-617: Microsoft Windows MIDI Service Incorrect Permission Assignment Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-66804.

EPSS 0.05 CVSS 7.8 CVE-2026-66804 Microsoft US 2 zdrojů

tg: zranitelnost

Zero Day Initiative · Microsoft Security

ZDI-26-618: Microsoft Windows UMPDDrvStretchBlt Improper Object Management Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-62712.

EPSS 0.00 CVSS 7.8 CVE-2026-62712 Microsoft US 2 zdrojů

tg: zranitelnost

Zero Day Initiative · Microsoft Security

ZDI-26-622: Microsoft Windows IKEv2 AES-GCM Decryption Integer Underflow Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows. Authentication is not required to exploit this vulnerability, but only systems with specific IPsec configurations are vulnerable. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2026-50696.

EPSS 0.01 CVSS 8.1 CVE-2026-50696 Microsoft US 2 zdrojů

tg: zranitelnost

Zero Day Initiative · Microsoft Security

8

1

Závažná zranitelnost ohrožuje téměř 22 000 Microsoft Exchange serverů

Microsoft 11. srpna 2026 vydal opravu zranitelnosti CVE-2026-62911 (CVSS 8,0), přesto téměř 22 000 veřejně dostupných Exchange serverů zůstává zranitelných. V Česku Shadowserver eviduje přibližně 300 unikátních IP adres Exchange serverů, které vyhodnocuje jako zranitelné (na jednu či více zranitelností). Zranitelnost postihuje Exchange Server 2016, 2019 a Subscription Edition a může vést až k převzetí uživatelských e-mailových schránek. Exploit je již veřejně dostupný. Verze 2016 a 2019 jsou…

EPSS 0.01 CVSS 8.8 CVE-2026-62911 Microsoft finance veřejná správa CZ NL US 4 zdrojů

tg: zneužíváno tg: zranitelnost tp: identita

CSIRT.CZ (CZ.NIC) · NCSC-NL · Microsoft Security · Zero Day Initiative

8

1

Ke zeužití kritické chyby ve Windows stačí poslat škodlivé packety

Americká CISA upozornila na aktivní zneužívání zranitelnosti CVE-2026-33824 (CVSS 9,8) ve Windows Internet Key Exchange (IKE). Ke zneužití této zranitelnosti stačí na neaktualizovaný počítač se systémem Windows odeslat speciálně upravené síťové pakety přes UDP porty 500 nebo 4 500. Zranitelnost se týká podporovaných verzí Windows 10, Windows 11 a Windows Serveru. Microsoft opravu vydal již v dubnu, takže je nezbytné neprodleně aktualizovat. Pokud to z nějakého důvodu není možné, doporučuje se…

KEV ✓ EPSS 0.73 CVSS 9.8 CVE-2026-33824 Microsoft veřejná správa CZ US 5 zdrojů

CSIRT.CZ (CZ.NIC) · BleepingComputer · CISA KEV · ZDI Blog · Microsoft Security

2

ZDI-26-605: Microsoft Windows Localized Filenames Improper Input Validation NTLM Response Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose NTLM responses on affected installations of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-50508.

EPSS 0.09 CVSS 3.3 CVE-2026-50508 Microsoft US 2 zdrojů

Zero Day Initiative · Microsoft Security

1

Microsoft Entra ID Remote Code Execution Vulnerability

Classification: Critical, Solution: Official Fix, Exploit Maturity: Unproven, CVSSv3.1: 10.0, CVEs: CVE-2026-69836, Summary: Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network. This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency.

EPSS 0.02 CVSS 10.0 CVE-2026-69836 Microsoft veřejná správa FI IT US FR 5 zdrojů

NCSC-FI · CSIRT Itálie (ACN) · CISA KEV · CERT-FR – avis · Microsoft Security

1

20

3

CVE-2026-68820 is in KEV. Here Is What CISA BOD 26-04 Actually Requires Now

Executive Summary CVE-2026-68820 is an actively exploited Windows vulnerability listed in CISA’s Known Exploited Vulnerabilities (KEV) Catalog, with a remediation deadline as suggested by CISA BOD 26-04. CISA BOD 26-04 introduces risk-based remediation timelines ranging from 3 to 14 days, increasing the pressure on teams to move quickly from patch availability to verified remediation. Installing the patch alone does not complete remediation, as the fix replaces a kernel driver and requires…

KEV ✓ EPSS 0.06 CVSS 7.0 CVE-2026-68820 Microsoft US FR 5 zdrojů

tg: zneužíváno tg: regulace tg: návod tg: propagace

Qualys · CERT-FR – avis · Tenable Research · Microsoft Security · CISA KEV

2

Microsoft Edge security advisory (AV26-822)

Serial Number: AV26-822Date: August 17, 2026 As of August 14, 2026, Microsoft is affected by a vulnerability in the following product: Microsoft Edge (Chromium-based) Prior to 151.0.4129.86 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Microsoft Edge Stable Channel Release Notes Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability CVE-2026-72970 (en anglais seulement)

EPSS 0.01 CVE-2026-72970 Microsoft CA US 2 zdrojů

Cyber Centre Kanada · Microsoft Security

2

ZDI-26-583: Clam AntiVirus 7z Archive Parsing Integer Overflow Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Clam AntiVirus. Interaction with this product is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 8.4. The following CVEs are assigned: CVE-2026-20215.

EPSS 0.01 CVSS 8.4 CVE-2026-20215 Clam AntiVirus ClamAV US 2 zdrojů

Zero Day Initiative · Microsoft Security

ZDI-26-584: dnsmasq DNSSEC NSEC/NSEC3 Type Bitmap Processing Infinite Loop Denial-of-Service Vulnerability

This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of dnsmasq. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-4890.

EPSS 0.09 CVSS 7.5 CVE-2026-4890 dnsmasq US 2 zdrojů

Zero Day Initiative · Microsoft Security

1

HTTP/2 Bomb CVE-2026-49975

CVSSv3 Score: 5.8 CVE-2026-49975Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67. Revised on 2026-08-12 00:00:00

EPSS 0.31 CVSS 5.8 CVE-2026-49975 Apache US 2 zdrojů

Fortinet PSIRT · Microsoft Security