Výsledky hledání

téma: DDoS× v celém archivu zrušit filtry

74 karet z 74 položek · strana 1 z 2 CZ · EN/orig

1

Synology DSM — Multiple Critical Vulnerabilities

Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8, CVEs: CVE-2026-13684, CVE-2026-13639, CVE-2026-13673, CVE-2026-6205, CVE-2026-13635, CVE-2026-13623, CVE-2026-13666, CVE-2026-13683, Summary: Synology released a security update for DSM on 18 September 2026 addressing multiple vulnerabilities, including two CVSS 9.8 flaws that can allow remote attackers to read/write arbitrary files and cause denial of service.

EPSS 0.01 CVSS 9.8 CVE-2026-13623 CVE-2026-13635 CVE-2026-13639 CVE-2026-13666 CVE-2026-13673 CVE-2026-13683 CVE-2026-13684 CVE-2026-6205 Synology FI

tg: zranitelnost tp: DDoS

· NCSC-FI · Synology DSM — Multiple Critical Vulnerabilities

4

Mitsubishi Electric CC-Link IE TSN Communication Protocol (Update A)

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker with access to the same network segment to tamper with communication data in the affected product by sending specially crafted packets under specific timing conditions. This could allow the attacker to cause a denial-of-service (DoS) condition in the affected product by interfering with its control function or causing it to operate incorrectly. The following versions of Mitsubishi Electric CC-Link IE TSN…

EPSS 0.00 CVE-2026-13584 Mitsubishi Electric výroba a průmysl US

tg: zranitelnost tp: DDoS tp: průmyslové systémy

· CISA Advisories · Mitsubishi Electric CC-Link IE TSN Communication Protocol (Update A)

Risolte vulnerabilità in ISC BIND 9

ISC ha rilasciato aggiornamenti di sicurezza per BIND 9 e BIND Supported Preview Edition, software per la gestione e la risoluzione delle richieste DNS, che sanano alcune vulnerabilità, di cui 7 con gravità "alta". Tali vulnerabilità possono causare la terminazione anomala di alcuni processi o un consumo eccessivo delle risorse, fino a compromettere la disponibilità del servizio sui sistemi interessati.

EPSS 0.00 CVE-2026-19666 CVE-2026-19667 CVE-2026-76163 CVE-2026-77692 CVE-2026-80274 CVE-2026-81563 CVE-2026-81736 ISC IT

tg: zranitelnost tp: DDoS

· CSIRT Itálie (ACN) · Risolte vulnerabilità in ISC BIND 9

Multiples vulnérabilités dans ISC BIND (17 septembre 2026)

De multiples vulnérabilités ont été découvertes dans ISC BIND. Elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à l'intégrité des données et un contournement de la politique de sécurité.

EPSS 0.00 CVE-2026-75029 CVE-2026-76163 CVE-2026-77119 CVE-2026-77692 CVE-2026-78301 CVE-2026-80274 CVE-2026-81563 CVE-2026-81736 ISC FR

tg: zranitelnost tp: DDoS

· CERT-FR – avis · Multiples vulnérabilités dans ISC BIND (17 septembre 2026)

10

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software SSL VPN Denial of Service Vulnerability

Update for September 16, 2026: The original 1.0 version of this advisory was specific to the Cisco Adaptive Security Virtual Appliance (ASAv) and Cisco Secure Firewall Threat Defense Virtual (FTDv) models. However, it was later found that this vulnerability affects all Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software platforms. A vulnerability in the VPN and management web servers of the Cisco Secure Firewall ASA Software…

EPSS 0.01 CVE-2024-20260 Cisco US

tg: zranitelnost tp: DDoS

· Cisco PSIRT · Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software SSL VPN Denial of Service Vulnerability

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Logging Denial of Service Vulnerability

A vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause high CPU utilization on an affected device, resulting in a denial of service (DoS) condition. This vulnerability is due to improper rate limiting for syslog message 419002. An attacker could exploit this vulnerability by sending a flood of…

EPSS 0.00 CVE-2026-20154 Cisco US

tg: zranitelnost tp: DDoS

· Cisco PSIRT · Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Logging Denial of Service Vulnerability

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software EIGRP Denial of Service Vulnerability

A vulnerability in the EIGRP implementation in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper resource management when handling EIGRP update messages. An attacker could exploit this vulnerability by sending crafted EIGRP updates at a high rate…

EPSS 0.00 CVE-2026-20222 Cisco US

tg: zranitelnost tp: DDoS

· Cisco PSIRT · Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software EIGRP Denial of Service Vulnerability

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software TCP DNS Denial of Service Vulnerability

A vulnerability in the DNS over TCP implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the TCP DNS response handler to unexpectedly restart, causing the device to reload. This vulnerability is due to a logic error when parsing a DNS query and tracking the size of the incoming buffers. An attacker could exploit this vulnerability by formatting a crafted…

EPSS 0.00 CVE-2026-20248 Cisco US

tg: zranitelnost tp: DDoS

· Cisco PSIRT · Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software TCP DNS Denial of Service Vulnerability

Cisco Secure Firewall Management Center and Secure Firewall Threat Defense Software sftunnel Vulnerabilities

Multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated attacker to perform an sftunnel authentication bypass or sftunnel denial of service (DoS) attack. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This…

EPSS 0.01 CVE-2026-20295 CVE-2026-20323 Cisco US

tg: zranitelnost tp: DDoS tp: identita

· Cisco PSIRT · Cisco Secure Firewall Management Center and Secure Firewall Threat Defense Software sftunnel Vulnerabilities

Cisco Identity Services Engine RADIUS Denial of Service Vulnerability

A vulnerability in the RADIUS feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain RADIUS requests. An attacker could exploit this vulnerability by sending a crafted RADIUS request directly to an affected device. A successful exploit could allow the attacker to cause the ISE node to become unavailable. For single node…

EPSS 0.00 CVE-2026-20352 Cisco US

tg: zranitelnost tp: DDoS

· Cisco PSIRT · Cisco Identity Services Engine RADIUS Denial of Service Vulnerability

SPOJENO PŘES CVE Risolte vulnerabilità in Squid

Aggiornamenti di sicurezza Squid risolvono tre vulnerabilità, di cui una con gravità “alta”, in Squid, software open source utilizzato come caching proxy. Tale vulnerabilità potrebbe consentire ad un utente malintenzionato di eludere le funzionalità di sicurezza e di alterare il contenuto memorizzato nella cache mediante richieste HTTP opportunamente predisposte.

CVE-2026-61642 Squid IT FR

tg: zranitelnost tp: DDoS

· CSIRT Itálie (ACN) · Risolte vulnerabilità in Squid · CERT-FR – avis · Multiples vulnérabilités dans Squid (14 septembre 2026)

Multiples vulnérabilités dans Oracle Database Server (16 septembre 2026)

De multiples vulnérabilités ont été découvertes dans Oracle Database Server. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance et un déni de service à distance.

EPSS 0.00 CVE-2026-83088 CVE-2026-83156 CVE-2026-83160 CVE-2026-83271 CVE-2026-83272 CVE-2026-83333 CVE-2026-83347 CVE-2026-83348 CVE-2026-83349 CVE-2026-83350 CVE-2026-83351 Oracle FR

tg: zranitelnost tp: DDoS

· CERT-FR – avis · Multiples vulnérabilités dans Oracle Database Server (16 septembre 2026)

1

NCSC-2026-0369 [1.00] [M/H] Kwetsbaarheid verholpen in Palo Alto Networks PAN-OS

Palo Alto Networks heeft een kwetsbaarheid verholpen in PAN-OS software, specifiek voor VM-Series en PA-Series firewalls, evenals Panorama management software. De kwetsbaarheid betreft een buffer overflow in de XML-verwerkingsfunctionaliteit van PAN-OS. Ongeauthenticeerde aanvallers met netwerktoegang kunnen hierdoor een denial-of-service veroorzaken op VM-Series firewalls of willekeurige code uitvoeren met rootrechten op PA-Series firewalls. Ook Panorama management software is getroffen. De…

Palo Alto Networks NL

tg: zranitelnost tp: DDoS

· NCSC-NL · NCSC-2026-0369 [1.00] [M/H] Kwetsbaarheid verholpen in Palo Alto Networks PAN-OS

1

5

Multiples vulnérabilités dans les produits Fortinet (11 septembre 2026)

De multiples vulnérabilités ont été découvertes dans les produits Fortinet. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

EPSS 0.01 CVE-2026-22575 CVE-2026-26084 CVE-2026-84385 CVE-2026-84386 CVE-2026-84387 CVE-2026-84388 CVE-2026-84389 CVE-2026-84390 CVE-2026-84391 CVE-2026-84392 CVE-2026-84393 Fortinet FR

tg: zranitelnost tp: DDoS

· CERT-FR – avis · Multiples vulnérabilités dans les produits Fortinet (11 septembre 2026)

2

HPE security advisory (AV26-909)

Serial number: AV26-909Date: September 10, 2026 As of September 9, 2026, Hewlett Packard Enterprise (HPE) is affected by vulnerabilities in the following products: ClearPass Policy Manager (CPPM) Prior to or equal to 6.11.14 Prior to or equal to 6.12.8 HPE IceWall products Multiple versions and models The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. HPESBNW05130 rev.1 - Multiple Vulnerabilities in HPE…

HPE CA

tg: zranitelnost tp: DDoS

· Cyber Centre Kanada · HPE security advisory (AV26-909)

3

33