Serial Number: AV26-882Date: September 3, 2026 As of September 3, 2026, SUSE is affected by vulnerabilities in the following product: Rancher Prior to 2.15.1 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Release v2.15.1 · rancher/rancher · GitHub SUSE Update Advisories
Serial Number: AV26-881Date: September 3, 2026 As of September 3, 2026, Siemens is affected by a vulnerability in the following products: Mendix SAML (Mendix 10 compatible) Prior to V4.2.3 Mendix SAML (Mendix 11 compatible) Prior to V4.2.3 Mendix SAML (Mendix 9.24 compatible) Prior to V3.6.27 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. SSA-887643: Account Hijacking Vulnerability in Mendix SAML…
Serial Number: AV26-880Date: September 3, 2026 As of September 3, 2026, n8n is affected by vulnerabilities in the following product: n8n Prior to 1.123.76 Prior to 2.35.4 Prior to 2.36.2 Prior to 2.37.7 Prior to 2.38.2 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. Overview · n8n-io/n8n · GitHub
Hewlett Packard Enterprise (HPE) has patched a critical vulnerability in the ArubaOS-CX network operating system that could lead to remote code execution. [...]
Serial Number: AV26-879Date: September 3, 2026 As of September 2, 2026, AMD is affected by vulnerabilities in the following products: 2nd Gen AMD EPYC™ Processors all except RomePI 1.0.0.H 3rd Gen AMD EPYC™ Processors all except MilanPI 1.0.0.C 4th Gen AMD EPYC™ Processors all except GenoaPI 1.0.0.8 AMD Athlon™ 3000 Series Desktop Processors with Radeon™ Graphics all except ComboAM4 1.0.0.B all except ComboAM4v2 1.2.0.B AMD Athlon™ 3000 Series Mobile Processors with Radeon™ Graphics all except…
A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a webshell payload and execute arbitrary commands on the server. [...]
Aruba Networks heeft meerdere kwetsbaarheden verholpen in het AOS-CX netwerk besturingssysteem en de bijbehorende componenten, waaronder de command line interface, API endpoints en web-based management interface. De kwetsbaarheden in AOS-CX betreffen onder andere onbevoegde toegang via bypass van authenticatie, remote code execution door onjuiste verwerking van input zoals format strings en command injection, privilege escalatie door onjuiste toegang tot systeemfuncties, en denial-of-service…
Serial Number: AV26-878Date: September 3, 2026 As of September 2, 2026, F5 is affected by vulnerabilities in the following products: BIG-IP (all modules) Prior to 17.1.3.4 Prior to 17.5.1.8 Prior to 21.0.0.3 Prior to 21.1.0.1 BIG-IQ Prior to 8.4.2.1 NGINX Gateway Fabric Prior to 2.6.8 NGINX Ingress Controller Prior to 2026-lts-r5 Prior to 5.6.0 NGINX JavaScript 9.9 Prior to 1.0.1 APM Clients Prior to 7.2.6 BIG-IP APM Multiple versions The Cyber Centre encourages users and administrators to…
Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
Improper neutralization of special elements in data query logic in Microsoft Discovery Studio allows an unauthorized attacker to disclose information over a network.
Serial Number: AV26-877Date: September 3, 2026 As of September 2, 2026, Jenkins Project is affected by vulnerabilities in the following products: Jenkins ALL except 2.568.3 ALL except 2.580 Jenkins Allure Plugin Prior to or equal to 2.35.2 Jenkins Customizable Header Plugin Prior to or equal to 295.v2544b_ca_19b_97 Jenkins File Parameter Plugin Prior to or equal to 425.v3fa_801681b_5e Jenkins GitLab Plugin Prior to or equal to 1.9.16 Jenkins LDAP Plugin Prior to or equal to 807.809.vd3a…
HPE heeft meerdere kwetsbaarheden verholpen in HPE Networking Fabric Composer. De kwetsbaarheden in HPE Networking Fabric Composer betreffen onder andere authenticatiebypasses, privilege-escalaties, remote code execution, command injection, cross-site scripting (XSS), denial-of-service, arbitrary file write, path traversal, en onbevoegde toegang tot gevoelige informatie. Sommige kwetsbaarheden kunnen door ongeauthenticeerde aanvallers op afstand worden misbruikt, terwijl andere exploitatie…
Rilevate 14 vulnerabilità di sicurezza, di cui una con gravità “critica” e 8 con gravità "alta", in Craft CMS, noto sistema di gestione dei contenuti utilizzato per la realizzazione di siti web.
Serial Number: AV26-876Date: September 3, 2026 As of September 2, 2026, Cisco is affected by vulnerabilities in the following products: Cisco IOS XR Software Multiple versions Cisco Nexus 9000 Series Switches Multiple products Cisco Desk Phone 9800 Series and Video Phone 8875 Prior to 5.0(1) IP Phone 7800 and 8800 Prior to 14.4(1)SR3 IP Phone 8845 and 8865 Prior to14.4(1)SR4 Wireless IP Phone 8821 Prior to 11.0(6)SR8 The Cyber Centre encourages users and administrators to review the provided…
Rilasciati aggiornamenti di sicurezza per risolvere una vulnerabilità con gravità “alta” presente in prodotti Grafana, nota applicazione web per la visualizzazione e l’analisi interattiva di dati. Tale vulnerabilità, qualora sfruttata, potrebbe consentire ad un utente malintenzionato, in presenza di specifiche condizioni, di eludere i meccanismi di autenticazione sui sistemi interessati.
Cisco heeft kwetsbaarheden verholpen in Cisco Nexus 9000 Series Switches met Silicon One technologie, Cisco IOS XR Software en Cisco Secure Email. De ernstigste kwetsbaarheid betreft Nexus 9000-switches: als TCP 43210 of 43211 bereikbaar is, kan een aanvaller zonder authenticatie code met rootrechten uitvoeren en de switch laten herstarten. De IOS XR-kwetsbaarheden kunnen, afhankelijk van platform en configuratie, diverse beveiligingsfuncties ondermijnen. De Secure Email-kwetsbaarheden kunnen…
View CSAF Summary Successful exploitation of this vulnerability could result in memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed. The following versions of Pyramid Solutions NetStaX EtherNet/IP Stack are affected: EtherNet/IP Adapter DLL Kit (EIPA) EtherNet/IP Adapter DLL Kit with CIP Security (EIPA-SECURE) EtherNet/IP Adapter Development Kit (EADK) EtherNet/IP Adapter…
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to perform remote code execution on the computer running the client with elevated privileges. The following versions of IXON VPN Client are affected: VPN Client <1.4.7 (CVE-2026-75925) CVSS Vendor Equipment Vulnerabilities v3 9.6 IXON IXON VPN Client Improper Neutralization of CRLF Sequences ('CRLF Injection') Background Critical Infrastructure Sectors: Commercial Facilities, Critical Manufacturing, Energy,…
View CSAF Summary Successful exploitation of these vulnerabilities could result in a loss of webserver availability or allow an attacker to inject malicious scripts that will be executed when other users access the affected page. The following versions of Rockwell Automation ArmorStart LT are affected: ArmorStart LT <=v2.001 (CVE-2026-19471, CVE-2026-19472) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation ArmorStart LT Improper Neutralization of Input During…
View CSAF Summary Successful exploitation of this vulnerability could give an attacker the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level. The following versions of Rockwell Automation ControlFLASH are affected: ControlFLASH <=V15.07 (CVE-2026-12663) CVSS Vendor Equipment Vulnerabilities v3 7.3 Rockwell Automation Rockwell Automation ControlFLASH Missing Authentication for Critical Function Background Critical…
View CSAF Summary Schneider Electric is aware of a vulnerability in the following products: The Easergy C5 is a scalable and interoperable bay controller, protection and merging unit for large and critical infrastructure electrical distribution systems. The Easergy MiCOM P30 is a family of multifunction protection and control relays designed for medium, high and extra high voltage electrical networks. The Easergy MiCOM P40 is a protection relay series for Medium Voltage, High Voltage and Extra…
View CSAF Summary Successful exploitation of these vulnerabilities could allow for an attacker to perform a man-in-the-middle (MitM) attack, cause a factory reset, wipe credentials, or retrieve sensitive information. The following versions of Tycon Systems TPDIN-Monitor-WEB3 are affected: TPDIN-Monitor-WEB3 <=2.2.9 (CVE-2026-77847, CVE-2026-82712, CVE-2026-82684) CVSS Vendor Equipment Vulnerabilities v3 8.8 Tycon Systems Tycon Systems TPDIN-Monitor-WEB3 Use of Hard-coded Credentials, Cross-Site…
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to take control of a high-privilege terminal during installation and run arbitrary commands. The following versions of OPCFoundation OPC UA LocalDiscoveryServer (LDS) are affected: UA-LDS-Installers <1.04.420 (CVE-2026-77477) CVSS Vendor Equipment Vulnerabilities v3 4.6 OPCFoundation OPCFoundation OPC UA LocalDiscoveryServer (LDS) Execution with Unnecessary Privileges Background Critical Infrastructure…
View CSAF Summary Successful exploitation of this vulnerability could allow any authenticated user to create projects. The following versions of Inductive Automation Ignition are affected: Ignition <=8.1.53 (CVE-2026-77393) CVSS Vendor Equipment Vulnerabilities v3 8.8 Inductive Automation Inductive Automation Ignition Incorrect Default Permissions Background Critical Infrastructure Sectors: Critical Manufacturing, Energy, Information Technology Countries/Areas Deployed: Worldwide Company…
View CSAF Summary Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk. The following versions of Tycon Systems TPDIN-Monitor-WEB2 (Update A) are affected: TPDIN-Monitor-WEB2 <2.4.5 (CVE-2026-61884, CVE-2026-55985) CVSS Vendor Equipment Vulnerabilities v3 9.8 Tycon Systems Tycon Systems TPDIN-Monitor-WEB2 Missing…
View CSAF Summary Successful exploitation of this vulnerability could crash the module. The device requires a restart to recover. The following versions of Rockwell Automation 1756-ENBT Module are affected: 1756-ENBT module vers:all/* (CVE-2025-10478) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation 1756-ENBT Module Improper Check for Unusual or Exceptional Conditions Background Critical Infrastructure Sectors: Critical Manufacturing, Food and Agriculture,…
Aggiornamenti di sicurezza Broadcom sanano due vulnerabilità, di cui una con gravità "critica" e una con gravità "alta", presenti in VMware Workstation e Fusion. Tali vulnerabilità, qualora sfruttate, potrebbero consentire ad un utente malintenzionato, con privilegi amministrativi locali su una macchina virtuale, di eseguire codice arbitrario sui sistemi interessati.
F5 ha rilasciato aggiornamenti di sicurezza che sanano 5 nuove vulnerabilità, di cui una con gravità "critica" e 4 con gravità “alta”, in prodotti NGINX, noto software per la gestione del traffico e degli applicativi web.
Cisco ha rilasciato aggiornamenti di sicurezza che risolvono 9 vulnerabilità, di cui 3 con gravità "critica" e 6 con gravità “alta”, che interessano diversi prodotti.
Multiple vulnerabilities in Ocsreports for OCS Inventory NG Fri, 08/28/2026 - 12:18 Aviso Affected Resources Ocsreports 2.12.4. Description INCIBE has coordinated the publication of 5 vulnerabilities: 1 of critical severity and 4 of high severity, affecting Ocsreports in OCS Inventory NG, an open-source solution for the management and inventory of hardware and software assets within an IT infrastructure. The vulnerabilities were discovered by Marc Monfort Muñoz.These vulnerabilities have been…
We found a second delayed RCE in MECCHA CHAMELEON: a malicious custom map could write files anywhere on your system and run code after a restart. Now patched in 4.0.0. Category: Vulnerabilities & Threats
Classification: Critical, Solution: Official Fix, Exploit Maturity: High, CVSSv3.0: 10.0, CVEs: CVE-2026-83548, CVE-2026-83549, Summary: 1) CVE-2026-83548 - Pre-authentication SSRF via unintended forward-proxy A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform…
Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.0: 8.6, CVEs: CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625, CVE-2026-9633, CVE-2026-9634, CVE-2026-9637, CVE-2026-16675, Summary: Rockwell Automation FactoryTalk Activation Manager Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the affected product. The following versions of Rockwell Automation RSLinx Classic are affected: RSLinx…
Classification: Critical, Solution: Unavailable, Exploit Maturity: Not Defined, CVSSv3.1: None, CVEs: CVE-2026-80047, Summary: A vulnerability in the Hugging Face Transformers library (versions 4.49.0 through 5.8.1) allows remote, attacker‑controlled Python files to be written to the local disk without user authorization. The library performs a remote module fetch and local cache write before evaluating the trust_remote_code consent prompt, violating the security contract enforced across other…
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8, CVEs: CVE-2026-73827, CVE-2026-77838, CVE-2026-78238, CVE-2026-78032, Summary: SOY series provided by Tsuyoshi Saito contain multiple vulnerabilities listed below. Cross-site Scripting (CWE-79) - CVE-2026-73827, CVE-2026-77838, CVE-2026-78238 Deserialization of Untrusted Data (CWE-502) - CVE-2026-78032 An arbitrary script may be executed on the web browser of the user who is logging in to the product…
Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 5.9, CVEs: CVE-2026-20354, CVE-2026-20355, Summary: Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to insufficient validation of message integrity. An attacker could exploit these…
Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 7.5, CVEs: CVE-2026-20281, Summary: A vulnerability in Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 that are running Cisco Session Initiation Protocol (SIP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper memory management when an affected…
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8, CVEs: CVE-2026-20274, CVE-2026-20275, CVE-2026-20276, CVE-2026-20277, CVE-2026-20278, CVE-2026-20279, CVE-2026-20280, Summary: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered…
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8, CVEs: CVE-2026-20212, Summary: A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privileges. This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF). A successful exploit could allow the attacker to connect to…
De multiples vulnérabilités ont été découvertes dans les produits F5. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
De multiples vulnérabilités ont été découvertes dans SPIP. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance et une élévation de privilèges.
Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead to remote code execution. [...]
An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execute remote code and take control of affected websites. [...]
A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being exploited in attacks to create tokens that provide administrative access. [...]
Serial number: AV26-875Date: September 2, 2026 As of September 2, 2026, Progress Software is affected by vulnerabilities in the following product: Telerik UI for ASP.NET AJAX Prior to 2026.3.812 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Telerik Web Forms RadImageEditor Path Traversal Vulnerability (CVE-2026-18672) Telerik Web Forms DialogHandler UploadPaths Tampering Vulnerability (CVE-2026…
Serial number: AV26-874Date: September 2, 2026 As of September 2, 2026, Google is affected by vulnerabilities in the following product: Chrome Prior to 152.0.7977.75 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. Stable Channel Update for Desktop
Rilasciati aggiornamenti di sicurezza per risolvere 86 vulnerabilità, di cui 6 con gravità "critica" e 46 con gravità "alta", che interessano i prodotti HPE Aruba Networking AOS-CX e Fabric Composer.
Serial number: AV26-873Date: September 2, 2026 As of September 1, 2026, Hewlett Packard Enterprise (HPE) is affected by vulnerabilities in the following products: HPE Networking AOS-CX Prior to or equal to 10.10.1180 Prior to or equal to 10.13.1180 Prior to or equal to 10.16.1051 Prior to or equal to 10.17.1021 Prior to or equal to 10.18.0001 HPE Networking Fabric Composer Prior to or equal to 7.3.3 The Cyber Centre encourages users and administrators to review the provided web links and apply…