Výsledky hledání

typ: zranitelnost× v celém archivu zrušit filtry

166 karet z 187 položek · strana 2 z 3 CZ · EN/orig

25

[Control systems] Schneider Electric security advisory (AV26-871)

Serial Number: AV26-871Date: September 2, 2026 As of September 1, 2026, Schneider Electric is affected by vulnerabilities in the following products: NetBotz 5 - 750/755 Versions prior to or equal to 5.5.2 PowerChute Serial Shutdown Versions prior to or equal to 1.5 The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates. Multiple Vulnerabilities on NetBotz 5 - 750/755 Products Improper Restriction…

Schneider Electric výroba a průmysl energetika CA

tg: zranitelnost tp: průmyslové systémy

Cyber Centre Kanada ·

CISA Adds Seven Known Exploited Vulnerabilities to Catalog

CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-9586 Sangoma Switchvox SQL Injection Vulnerability CVE-2026-48710 Kludex Starlette HTTP Request/Response Smuggling Vulnerability CVE-2026-49869 Kestra OSS OS Command Injection Vulnerability CVE-2026-59822 BerriAI LiteLLM Improper Authentication Vulnerability CVE-2026-82329 JFrog Artifactory Improper Authentication Vulnerability CVE-2026-83548…

KEV ✓ EPSS 0.02 CVE-2026-48710 CVE-2026-49869 CVE-2026-59822 CVE-2026-82329 CVE-2026-83548 CVE-2026-83549 CVE-2026-9586 Sangoma SonicWall JFrog Kestra veřejná správa US

tg: zneužíváno tg: zranitelnost

CISA Advisories ·

Závažná zranitelnost ohrožuje téměř 22 000 Microsoft Exchange serverů

Microsoft 11. srpna 2026 vydal opravu zranitelnosti CVE-2026-62911 (CVSS 8,0), přesto téměř 22 000 veřejně dostupných Exchange serverů zůstává zranitelných. V Česku Shadowserver eviduje přibližně 300 unikátních IP adres Exchange serverů, které vyhodnocuje jako zranitelné (na jednu či více zranitelností). Zranitelnost postihuje Exchange Server 2016, 2019 a Subscription Edition a může vést až k převzetí uživatelských e-mailových schránek. Exploit je již veřejně dostupný. Verze 2016 a 2019 jsou…

EPSS 0.01 CVSS 8.8 CVE-2026-62911 Microsoft finance veřejná správa CZ NL US 4 zdrojů

tg: zneužíváno tg: zranitelnost

CSIRT.CZ (CZ.NIC) · NCSC-NL · Microsoft Security · Zero Day Initiative

Two critical Chrome flaws put users at risk on malicious websites

Chrome is rolling out an update for its desktop browser. The update includes 26 security fixes, two of which Google rates as critical use-after-free vulnerabilities. The Stable channel has been updated to 152.0.7977.75/.76 for Windows and Mac, and 152.0.7977.75 for Linux. How to update Chrome If you don’t want to wait for the rollout to reach you, manually updating is easy. The easiest option is to allow Chrome to update automatically. But you can end up lagging behind if you never close your…

CVE-2026-84352 CVE-2026-84353 Google US

tg: zranitelnost

Malwarebytes Labs ·

Rilevate vulnerabilità in Erlang/OTP

Rilevate molteplici vulnerabilità di sicurezza, di cui 11 con gravità "alta", in diversi componenti di Erlang/OTP, piattaforma open source basata sul linguaggio Erlang e sul relativo set di librerie OTP, utilizzata per lo sviluppo di sistemi distribuiti ad alta disponibilità.

CVE-2026-55951 CVE-2026-66357 CVE-2026-66835 CVE-2026-69664 CVE-2026-70399 CVE-2026-71380 CVE-2026-73270 CVE-2026-73276 CVE-2026-73812 CVE-2026-74835 CVE-2026-75538 Erlang/OTP IT

tg: zranitelnost

CSIRT Itálie (ACN) ·

NCSC-2026-0337 [1.00] [H/H] Zero-Day kwetsbaarheden verholpen in SMA1000 Appliance van SonicWall

SonicWall heeft kwetsbaarheden verholpen in de SMA1000 Appliance. De SMA1000 Appliance bevat twee kwetsbaarheden. De eerste is een pre-authenticatie Server-Side Request Forgery (SSRF) in de Work Place interface, waarmee een externe, niet-geauthenticeerde aanvaller ongeautoriseerde acties kan uitvoeren. De tweede kwetsbaarheid betreft post-authenticatie remote code execution, waarbij een aanvaller met geldige inloggegevens willekeurige code op afstand kan uitvoeren. Beide kwetsbaarheden zijn als…

SonicWall NL

tg: zneužíváno tg: zranitelnost

NCSC-NL ·

Aggiornamenti di sicurezza Dell Technologies

Dell Technologies ha rilasciato aggiornamenti di sicurezza per risolvere 17 vulnerabilità, di cui 3 con gravità "critica" e 13 con gravità "alta", presenti in Dell PowerStore.

EPSS 0.01 CVE-2026-58566 CVE-2026-58567 CVE-2026-58569 CVE-2026-58571 CVE-2026-58572 CVE-2026-58574 CVE-2026-58575 CVE-2026-67262 CVE-2026-67271 CVE-2026-70415 CVE-2026-76111 CVE-2026-79682 CVE-2026-79683 CVE-2026-79684 CVE-2026-79686 CVE-2026-79687 Dell Technologies IT

tg: zranitelnost

CSIRT Itálie (ACN) ·

NCSC-2026-0336 [1.00] [M/H] Kwetsbaarheid verholpen in JFrog Artifactory

JFrog heeft een kwetsbaarheid verholpen in JFrog Artifactory. De kwetsbaarheid bevindt zich in de standaardconfiguratie van JFrog Artifactory, waarbij onvoldoende authenticatiecontroles aanwezig zijn. Hierdoor kan een niet-geauthenticeerde aanvaller met netwerktoegang de privileges escaleren naar administratief niveau. Dit kan leiden tot volledige administratieve controle over het systeem.

JFrog NL

tg: zranitelnost

NCSC-NL ·

Multiples vulnérabilités dans Curl (02 septembre 2026)

De multiples vulnérabilités ont été découvertes dans Curl. Certaines d'entre elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, une atteinte à l'intégrité des données et un contournement de la politique de sécurité.

CVE-2026-13608 CVE-2026-18924 CVE-2026-19931 CVE-2026-80229 CVE-2026-80230 CVE-2026-80231 CVE-2026-80255 CVE-2026-82208 CVE-2026-82209 Curl FR

tg: zranitelnost

CERT-FR – avis ·

22

Erlang security advisory (AV26-870)

Serial number: AV26-870Date: September 1, 2026 As of September 1, 2026, Erlang is affected by vulnerabilities in the following product: OTP - Multiple versions The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates. Erlang Security Advisories

Erlang CA

tg: zranitelnost

Cyber Centre Kanada ·

Rockwell Automation security advisory (AV26-869)

Serial number: AV26-869Date: September 1, 2026 As of September 1, 2026, Rockwell Automation is affected by vulnerabilities in the following products: 1756-ENBT Module All versions ArmorStart LT Prior to or equal to v2.001 CompactLogix 5380 / ControlLogix 5580 Prior to or equal to V33 V34.011 to V34.014 V35.011 to V35.013 V36.011 to V36.012 RSLinx Classic Prior to or equal to V4.50 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary…

Rockwell Automation výroba a průmysl CA

tg: zranitelnost tp: průmyslové systémy

Cyber Centre Kanada ·

Mozilla security advisory (AV26-868)

Serial number: AV26-868Date: September 1, 2026 As of September 1, 2026, Mozilla is affected by vulnerabilities in the following products: Firefox ESR Versions prior to 115.40 Versions prior to 140.15 Versions prior to 153.2 Firefox Versions prior to 155 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Security Vulnerabilities fixed in Firefox ESR 115.40 — Mozilla Security Vulnerabilities fixed in…

Mozilla CA

tg: zranitelnost

Cyber Centre Kanada ·

WebPros security advisory (AV26-866)

Serial number: AV26-866Date: September 1, 2026 As of September 1, 2026, WebPros is affected by vulnerabilities in the following product: Plesk Prior to 18.0.79.9 Prior to 18.0.80.5 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. CVE-2026-67394: Vulnerability in Plesk allows privilege escalation to root

CVE-2026-67394 WebPros Plesk CA IT 2 zdrojů

tg: zranitelnost

Cyber Centre Kanada · CSIRT Itálie (ACN)

NCSC-2026-0335 [1.00] [M/H] Kwetsbaarheden verholpen in WatchGuard Fireware OS

WatchGuard heeft kwetsbaarheden verholpen in WatchGuard Fireware OS, specifiek in het iked-proces en de epm-service van het Mobile Security onderdeel. De kwetsbaarheden bevinden zich in het iked-proces en de epm-service van WatchGuard Fireware OS. Het iked-proces bevat een stack-based buffer overflow, een type confusion kwetsbaarheid en een heap overflow. Deze kwetsbaarheden kunnen worden misbruikt door een ongeauthenticeerde aanvaller door speciaal vervaardigd netwerkverkeer te verzenden. Dit…

WatchGuard NL

tg: zranitelnost

NCSC-NL ·

Rockwell Automation FactoryTalk Activation Manager

View CSAF Summary The following versions of Rockwell Automation FactoryTalk Activation Manager are affected: FactoryTalk Activation Manager V5.02_and_below (CVE-2026-16675) CVSS Vendor Equipment Vulnerabilities v3 7.8 Rockwell Automation Rockwell Automation FactoryTalk Activation Manager Improper Restriction of Excessive Authentication Attempts Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States…

CVSS 7.8 CVE-2026-16675 Rockwell Automation výroba a průmysl US

tg: zranitelnost

CISA Advisories ·

Rockwell Automation Redundancy Module Configuration Tool

View CSAF Summary Successful exploitation of these vulnerabilities could allow for an attacker to escalate and execute processes with administrator privileges. The following versions of Rockwell Automation Redundancy Module Configuration Tool are affected: Redundancy Module Configuration Tool 10.00.00 (CVE-2026-9633) Redundancy Module Configuration Tool >=9.00.00|<=10.00.00 (CVE-2026-9634) CVSS Vendor Equipment Vulnerabilities v3 7.3 Rockwell Automation Rockwell Automation Redundancy Module…

CVSS 7.3 CVE-2026-9633 CVE-2026-9634 Rockwell Automation výroba a průmysl energetika vodárenství doprava US

tg: zranitelnost tp: průmyslové systémy

CISA Advisories ·

Rockwell Automation Logix Platform

View CSAF Summary The following versions of Rockwell Automation Logix Platform are affected: ControlLogix 5580 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637) CompactLogix 5380 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637) GuardLogix 5580 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637)…

CVSS 7.5 CVE-2026-9637 Rockwell Automation výroba a průmysl US

tg: zranitelnost tp: průmyslové systémy

CISA Advisories ·

Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix

View CSAF Summary The following versions of Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix are affected: ControlLogix 5580 <34.015, <35.014, <36.013, <37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260) GuardLogix 5580 <34.015, <35.014, <36.013, <37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260) CompactLogix 5380 <34.015, <35.014, <36.013, <37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE…

EPSS 0.03 CVSS 7.5 CVE-2021-42260 Rockwell Automation výroba a průmysl US

tg: zranitelnost tp: průmyslové systémy

CISA Advisories ·

Rockwell Automation Historian ME

View CSAF Summary Successful exploitation of these vulnerabilities could crash the device being accessed; an out-of-bounds write condition may allow remote code execution. The following versions of Rockwell Automation Historian ME are affected: Series B 5.202 (CVE-2025-12768, CVE-2026-12661) Series C 7.101 (CVE-2025-12768, CVE-2026-12661) CVSS Vendor Equipment Vulnerabilities v3 8 Rockwell Automation Rockwell Automation Historian ME Out-of-bounds Write, Stack-based Buffer Overflow Background…

CVSS 8.0 CVE-2025-12768 CVE-2026-12661 Rockwell Automation výroba a průmysl energetika vodárenství zdravotnictví US

tg: zranitelnost tp: průmyslové systémy

CISA Advisories ·

Rockwell Automation RSLinx Classic

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the affected product. The following versions of Rockwell Automation RSLinx Classic are affected: RSLinx Classic <=4.50 (CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625) CVSS Vendor Equipment Vulnerabilities v3 8.6 Rockwell Automation Rockwell Automation RSLinx Classic Integer Overflow or Wraparound, Integer Underflow (Wrap or Wraparound), Buffer Copy…

CVSS 8.6 CVE-2026-9621 CVE-2026-9622 CVE-2026-9624 CVE-2026-9625 Rockwell Automation výroba a průmysl US

tg: zranitelnost tp: průmyslové systémy

CISA Advisories ·

Sanata vulnerabilità in libexpat

Aggiornamenti di sicurezza sanano una vulnerabilità in libexpat, nota libreria scritta in C per l'analisi di documenti XML. Tale vulnerabilità, qualora sfruttata, consentirebbe ad utente malintenzionato di innescare la corruzione della memoria o il crash dell'applicazione, portando alla compromissione della disponibilità del servizio sulle istanze interessate.

EPSS 0.00 CVE-2026-76641 libexpat IT

tg: zranitelnost

CSIRT Itálie (ACN) ·

Falta de autorización en OpenNebula de OpenNebula Systems

Lack of authorisation in OpenNebula by OpenNebula Systems Tue, 09/01/2026 - 12:12 Aviso Affected Resources OpenNebula 7.4. Description INCIBE has coordinated the publication of a high-severity vulnerability affecting OpenNebula by OpenNebula Systems, a platform for managing virtualised data. The vulnerability was discovered by Yonghwa Lee, Xint from Theori.This vulnerability has been assigned the following code, CVSS v4.0 base score, CVSS vector and CWE vulnerability type:CVE-2026-84165: CVSS…

CVSS 8.7 CVE-2026-84165 OpenNebula ES

tg: zranitelnost

INCIBE-CERT ·

Inyección de código en el Core de Lutece

Code injection in the Lutece Core Tue, 09/01/2026 - 11:44 Aviso Affected Resources Lutece Core: versión 7.1.7 y anteriores. Description INCIBE has coordinated the disclosure of a critical-severity vulnerability in Lutece Core, an open platform that enables local authorities to share, reuse and adapt digital services. The vulnerability was discovered by I Dorian Piette (Trachinus).This vulnerability has been assigned the following code, CVSS v4.0 base score, CVSS vector and CWE vulnerability…

CVSS 9.4 CVE-2026-4813 Lutece veřejná správa ES

tg: zranitelnost

INCIBE-CERT ·

13

WatchGuard security advisory (AV26-865)

Serial Number: AV26-865Date: August 31, 2026 As of August 27, 2026, WatchGuard is affected by vulnerabilities in the following products: Dimension Prior to 2.3.1 Fireware OS Prior to 12.12.2 Prior to 12.5.20 Prior to 2026.2.2 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. WatchGuard Security Advisories

WatchGuard CA

tg: zranitelnost

Cyber Centre Kanada ·

[Control Systems] Siemens security advisory (AV26-864)

Serial Number: AV26-864Date: August 31, 2026 As of August 27, 2026, Siemens is affected by a vulnerability in the following products: Element maps-ng V47 Prior to V47.12.3 Element maps-ng V48 Prior to V48.11.3 Element maps-ng V49 Prior to V49.16.1 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. SSA-682041 CERT Services | Siemens

Siemens energetika výroba a průmysl CA

tg: zranitelnost tp: průmyslové systémy

Cyber Centre Kanada ·

Dell security advisory (AV26-863)

Serial Number: AV26-863Date: August 31, 2026 As of August 28, 2026, Dell is affected by vulnerabilities in the following products: Dell PowerEdge Server for Intel Processor Firmware Multiple versions and models Dell AppSync Prior to or equal to 4.6.0.4 and 4.6.1.0 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. DSA-2026-356: Security Update for Dell PowerEdge Server for Intel® Processor Firmware…

Dell CA

tg: zranitelnost

Cyber Centre Kanada ·

IBM security advisory (AV26-862)

Serial Number: AV26-862Date: August 31, 2026 As of August 28, 2026, IBM is affected by vulnerabilities in the following products: SPSS Collaboration and Deployment Services Multiple versions IBM SPSS Analytic Server Multiple version IBM MQ Agent Multiple versions IBM Maximo Application Suite - Monitor Component Prior to or equal to 9.2, 9.1 and 9.0 IBM Observability with Instana (Agent) Prior to or equal to 1.0.323 IBM Financial Transaction Manager (FTM) for RedHat OpenShift Multiple versions…

IBM CA

tg: zranitelnost

Cyber Centre Kanada ·

31th August – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 31st August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Manchester Airports Group, the UK operator of Manchester, London Stansted, and East Midlands airports, has disclosed a cyberattack that exposed data belonging to about 8.7 million customers. The compromised information includes contact details, vehicle registration numbers, and information collected through car park, lounge, fast-track, and Wi-Fi…

KEV ✓ CVSS 10.0 CVE-2026-18885 CVE-2026-18886 CVE-2026-74820 CVE-2026-75604 CVE-2026-81578 CVE-2026-82078 Check Point PaperCut Ubiquiti Vercel veřejná správa zdravotnictví doprava IL

tg: incident tg: zneužíváno tg: zranitelnost tg: přehled tp: malware tp: phishing tp: ransomware tp: únik dat tp: AI tp: špionáž tp: průmyslové systémy

Check Point Research ·

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-81578 PaperCut NG/MF Missing Authentication for Critical Function Vulnerability CVE-2026-82078 PaperCut NG/MF Unsafe Reflection Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates…

KEV ✓ CVSS 9.4 CVE-2026-81578 CVE-2026-82078 PaperCut veřejná správa US IT FI FR 4 zdrojů

tg: zneužíváno tg: zranitelnost

CISA Advisories · CSIRT Itálie (ACN) · NCSC-FI · CERT-FR – avis

Riasztás a CVE-2026-73570 Zimbra Collaboration Suite szoftvert érintő sérülékenységről

A Nemzetbiztonsági Szakszolgálat Nemzeti Kiberbiztonsági Intézet riasztást ad ki a Zimbra Collaboration Suite (ZCS) szoftvert érintő, CVE-2026-73570 azonosítón nyomon követett kritikus sérülékenység kapcsán. Intézetünkhöz megnövekedett számú bejelentés érkezett a CVE-2026-73570 sérülékenység aktív kihasználásáról. A sebezhetőség kihasználása hitelesítés nélküli támadók számára távoli kódfuttatást tehet lehetővé. A sérülékenység a Zimbra SNMP-monitorozási komponensét érinti, és akkor használható…

KEV ✓ EPSS 0.21 CVE-2026-73570 Zimbra Synacor veřejná správa HU US IT 5 zdrojů

tg: zneužíváno tg: zranitelnost tp: malware

NKI Maďarsko · BleepingComputer · CISA Advisories · CISA KEV · CSIRT Itálie (ACN)

Rilevata una nuova vulnerabilità in Sudo

Rilevata una vulnerabilità di sicurezza con gravità "alta" in Sudo, nota utility per sistemi operativi Unix-like che permette di delegare i privilegi utente. Tale vulnerabilità, qualora sfruttata, potrebbe consentire ad un utente locale autenticato di eludere i meccanismi di sicurezza e di eseguire programmi non autorizzati sul sistema interessato, ottenendo privilegi superiori rispetto a quelli previsti dalle policy configurate.

EPSS 0.00 CVE-2026-82474 Sudo IT

tg: zranitelnost

CSIRT Itálie (ACN) ·

ZDI-26-613: (0Day) pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.

CVSS 7.8 pdfforge US

tg: zneužíváno tg: zranitelnost

Zero Day Initiative ·