Výsledky hledání

sektor: veřejná správa× v celém archivu zrušit filtry

214 karet z 216 položek · strana 2 z 4 CZ · EN/orig

3

SPOJENO PŘES CVE Ke zeužití kritické chyby ve Windows stačí poslat škodlivé packety

Americká CISA upozornila na aktivní zneužívání zranitelnosti CVE-2026-33824 (CVSS 9,8) ve Windows Internet Key Exchange (IKE). Ke zneužití této zranitelnosti stačí na neaktualizovaný počítač se systémem Windows odeslat speciálně upravené síťové pakety přes UDP porty 500 nebo 4 500. Zranitelnost se týká podporovaných verzí Windows 10, Windows 11 a Windows Serveru. Microsoft opravu vydal již v dubnu, takže je nezbytné neprodleně aktualizovat. Pokud to z nějakého důvodu není možné, doporučuje se…

KEV ✓ EPSS 0.73 CVSS 9.8 CVE-2026-33824 Microsoft veřejná správa CZ US

· CSIRT.CZ (CZ.NIC) · Ke zeužití kritické chyby ve Windows stačí poslat škodlivé packety · BleepingComputer · Critical RCE flaw in Windows IKE Extension now actively exploited · CISA KEV · Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability (CVE-2026-33824) · ZDI Blog · CVE-2026-33824: Remote Code Execution in Windows IKEv2 · Microsoft Security · CVE-2026-33824 Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability

5

Who Has Admin Rights in your Entra ID Directory?, (Wed, Aug 26th)

A common thing that folks should "worry" about in Entra (or any platform really) is "who has rights to administer"? Who can delete or change key things, or modify them in ways that might not be obvious (accidentally or on purpose). Yes, we trust our people, but if they've moved on to other roles or to other organizations, they change from "our people" to "used to be our people". Also, it's common to have too many admins. For instance, entry level support folks might need rights to change…

veřejná správa US

· SANS Internet Storm Ctr. · Who Has Admin Rights in your Entra ID Directory?, (Wed, Aug 26th)

SPOJENO PŘES CVE Rilevato sfruttamento di vulnerabilità in Gitea

Rilevato lo sfruttamento attivo in rete di una vulnerabilità con gravità “critica” - già sanata dal vendor - relativa a Gitea, piattaforma collaborativa open source per la gestione del codice sorgente e lo sviluppo di applicazioni software.

KEV ✓ EPSS 0.87 CVE-2026-60004 Gitea veřejná správa IT CA US

· CSIRT Itálie (ACN) · Rilevato sfruttamento di vulnerabilità in Gitea · Cyber Centre Kanada · Gitea security advisory (AV26-845) · CISA Advisories · CISA Adds One Known Exploited Vulnerability to Catalog · CISA KEV · Gitea Code Injection Vulnerability (CVE-2026-60004)

CISA Adds Six Known Exploited Vulnerabilities to Catalog

CISA has added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2015-3246 Red Hat Libuser Race Condition Vulnerability CVE-2015-5287 Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability CVE-2019-1068 Microsoft SQL Server Remote Code Execution Vulnerability CVE-2021-23758 Ajax.NET Professional Deserialization of Untrusted Data Vulnerability CVE-2022-0995 Linux Kernel Out-of-Bounds Write Vulnerability…

KEV ✓ EPSS 0.84 CVE-2015-3246 CVE-2015-5287 CVE-2019-1068 CVE-2021-23758 CVE-2022-0995 CVE-2026-8452 Red Hat Microsoft Citrix veřejná správa US

· CISA Advisories · CISA Adds Six Known Exploited Vulnerabilities to Catalog

SPOJENO PŘES CVE Linux Kernel Out-of-Bounds Write Vulnerability (CVE-2022-0995)

CISA added CVE-2022-0995 to the Known Exploited Vulnerabilities catalog. Affected product: Linux Kernel. Remediation due date: 2026-09-09.

KEV ✓ EPSS 0.10 CVE-2022-0995 Linux Microsoft veřejná správa školství média US

tg: varování tg: rozbor tp: malware tp: podvod tp: únik dat tp: AI

· CISA KEV · Linux Kernel Out-of-Bounds Write Vulnerability (CVE-2022-0995) · Cisco Talos · UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations

5

A Tale of Two SOCs: Insights From Two Red Team Assessments

Advisory at a Glance Title A Tale of Two SOCs: Insights From Two Red Team Assessments Original Publication August 25, 2026 Executive Summary The Cybersecurity and Infrastructure Security Agency (CISA) conducted simultaneous red team assessments at two organizations and observed different defensive outcomes. In both environments, the red team achieved full domain compromise and accessed sensitive business systems (SBSs) and cloud resources. Organization A failed to detect or contain the activity…

veřejná správa vodárenství US

· CISA Advisories · A Tale of Two SOCs: Insights From Two Red Team Assessments

2

SPOJENO PŘES CVE Oracle security advisory – January 2026 quarterly rollup (AV26-042) – Update 2

Serial number: AV26-042Date: January 21, 2026Updated: August 24, 2026 On January 20, 2026, Oracle published a security advisory to address vulnerabilities in multiple products. Update 1 On January 21, 2026, a proof of concept (PoC) for the vulnerability CVE-2026-21962 became publicly available. CVE-2026-21962 is a vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware which may allow a remote attacker to obtain unauthorized access.…

KEV ✓ EPSS 0.42 CVE-2026-21962 Oracle veřejná správa CA US

· Cyber Centre Kanada · Oracle security advisory – January 2026 quarterly rollup (AV26-042) – Update 2 · CISA Advisories · CISA Adds One Known Exploited Vulnerability to Catalog · CISA KEV · Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability (CVE-2026-21962)

1

SPOJENO PŘES CVE Microsoft Entra ID Remote Code Execution Vulnerability

Classification: Critical, Solution: Official Fix, Exploit Maturity: Unproven, CVSSv3.1: 10.0, CVEs: CVE-2026-69836, Summary: Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network. This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency.

EPSS 0.02 CVSS 10.0 CVE-2026-69836 Microsoft veřejná správa FI IT US FR

· NCSC-FI · Microsoft Entra ID Remote Code Execution Vulnerability · CSIRT Itálie (ACN) · Rilevato sfruttamento di vulnerabilità in Microsoft Entra ID · CISA KEV · Microsoft Entra ID Deserialization of Untrusted Data Vulnerability (CVE-2026-69836) · CERT-FR – avis · Vulnérabilité dans Microsoft Entra ID (21 août 2026) · Microsoft Security · CVE-2026-69836 Microsoft Entra ID Remote Code Execution Vulnerability

3

SPOJENO PŘES CVE CISA Releases One Industrial Control Systems Advisory

Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 5.3, CVEs: CVE-2026-27875, Summary: CISA released one Industrial Control Systems (ICS) Advisory. This advisory provides timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-26-232-01 Johnson Controls Simplex Incident Manager

EPSS 0.00 CVSS 5.8 CVE-2026-27875 Johnson Controls výroba a průmysl energetika doprava veřejná správa FI US

· NCSC-FI · CISA Releases One Industrial Control Systems Advisory · CISA Advisories · Johnson Controls Simplex Incident Manager

7

SPOJENO PŘES CVE TrueConf security advisory (AV26-835)

Serial Number: AV26-835Date: August 20, 2026 As of August 19, 2026, TrueConf is affected by a vulnerability in the following product: TrueConf Server 5.3.x versions prior to 5.3.9 5.4.x versions prior to 5.4.9 5.5.x versions prior to 5.5.5 On August 20, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-72529 and CVE-2026-72530 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links…

KEV ✓ EPSS 0.02 CVE-2026-72529 CVE-2026-72530 TrueConf veřejná správa CA US

· Cyber Centre Kanada · TrueConf security advisory (AV26-835) · CISA Advisories · CISA Adds Two Known Exploited Vulnerabilities to Catalog

Is Cyber missing the Marque?

Welcome to this week’s edition of the Threat Source newsletter. Hello friend. I’m Mick. This is my first Threat Source newsletter, so I should probably introduce myself before I start telling you all the things I think you should be paying attention to. With assistance from an unnamed LLM, my bio reads like this: Mick Baccio is a globally recognized security strategist with a career spanning offensive operations, threat intelligence, and national-level incident response. He currently advises…

GitLab Apple Microsoft veřejná správa obrana US

· Cisco Talos · Is Cyber missing the Marque?

Frequently asked questions about the active threat to Siemens S7 Series PLCs

A joint cybersecurity advisory released by multiple U.S. government agencies warns that threat actors are using AI-generated exploitation scripts to target exposed Siemens S7 Series PLCs across critical infrastructure sectors.Key TakeawaysUnattributed threat actors are exploiting known weaknesses and unnecessary internet exposure to conduct reconnaissance and possible pre-positioning for future disruptive attacks against Siemens S7 Series PLCs.The attackers are leveraging AI to build and refine…

Siemens veřejná správa energetika vodárenství výroba a průmysl US

· Tenable Research · Frequently asked questions about the active threat to Siemens S7 Series PLCs

Going with the Flow(s): Distinct Clusters Target Individuals of Interest to Russia

Written by: Gabby Roncone, Wesley Shields Overview Google Threat Intelligence Group (GTIG) is tracking three distinct suspected Russian cyber espionage threat clusters abusing legitimate authentication flows to target individuals working in academia, aerospace and defense, governments and think tanks across Europe, as well as academia and think tanks within the United States. Examples of these techniques can be found in our previous blog on UNC6293’s phishing operations. We now track an…

Microsoft Google veřejná správa obrana školství US

· Mandiant / Google TI · Going with the Flow(s): Distinct Clusters Target Individuals of Interest to Russia

SPOJENO PŘES CVE CISA warns of hackers exploiting critical MLflow vulnerability

The Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies that threat actors are now exploiting a critical vulnerability in the MLflow open-source AI engineering platform. [...]

KEV ✓ EPSS 0.16 CVE-2026-64849 MLflow veřejná správa US CA

tg: zneužíváno tg: zranitelnost tg: regulace

· BleepingComputer · CISA warns of hackers exploiting critical MLflow vulnerability · Cyber Centre Kanada · MLflow security advisory (AV26-832) · CISA Advisories · CISA Adds One Known Exploited Vulnerability to Catalog · CISA KEV · MLflow Server-Side Request Forgery Vulnerability (CVE-2026-64849)

Múltiples vulnerabilidades en productos de T-Systems

Multiple vulnerabilities in T-Systems Products Thu, 08/20/2026 - 12:11 Aviso Affected Resources The following products in the TAO 2.0 suite, in versions prior to 2602.00, are affected:Conecta: versions prior to 2605.0.0;STA: versions prior to 2605.0.0 and 2605.0.1. Description INCIBE has coordinated the disclosure of four vulnerabilities—two high-severity and two medium-severity—that affect several products in the TAO 2.0 suite, a management platform for public administration. The…

CVSS 8.7 CVE-2026-18224 CVE-2026-18225 CVE-2026-18226 CVE-2026-18227 T-Systems veřejná správa ES

· INCIBE-CERT · Múltiples vulnerabilidades en productos de T-Systems

5

4

More than 200 victims of Medusa ransomware identified over the last year, CISA says

The Cybersecurity and Infrastructure Security Agency (CISA) and FBI updated an advisory on the group initially released in March 2025 — writing that as of April 2026, Medusa actors have hit more than 500 victims. CISA previously said 300 victims, many of which are in critical infrastructure sectors, were attacked as of 2025.

veřejná správa energetika vodárenství telekomunikace US

· The Record · More than 200 victims of Medusa ransomware identified over the last year, CISA says

New Report: AI threats are here. Why Q2 2026 signals the end of traditional patch cycles

You can’t patch everything. So what do you fix first? Findings in Q2 2026 have changed traditional answers.The latest Quarterly Threat Landscape Report from Rapid7 Labs shows vulnerability disclosures still surging while attackers use automation and AI-assisted tooling to compress the time between disclosure and exploitation. The gap that patch cycles were built to fill is closing. Speed and volume are overwhelming security teams that have relied on traditional patch cycles and reactive…

CVSS 7.0 Microsoft veřejná správa finance zdravotnictví výroba a průmysl US

tg: rozbor tp: ransomware tp: AI tp: špionáž tp: průmyslové systémy

· Rapid7 · New Report: AI threats are here. Why Q2 2026 signals the end of traditional patch cycles

CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-33824 Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability CVE-2026-55040 Microsoft SharePoint Weak Authentication Vulnerability CVE-2026-59310 Broadcom VMware vCenter Path Traversal Vulnerability CVE-2026-65400 Apple macOS Improper Authentication Vulnerability These types of vulnerabilities are a frequent attack vector…

KEV ✓ · ransomware EPSS 0.73 CVE-2026-33824 CVE-2026-55040 CVE-2026-59310 CVE-2026-65400 Microsoft Broadcom Apple veřejná správa US

· CISA Advisories · CISA Adds Four Known Exploited Vulnerabilities to Catalog

5

SPOJENO PŘES CVE Certighost and the Privilege Hiding in Your Certificate Authority

CVE-2026-54121 lets a standard domain user turn your Enterprise CA into a Domain Controller. The patch is the easy part. The lesson is standing privilege, implicit trust, and treating PKI as the Tier 0 identity infrastructure it has always been. [...]

EPSS 0.02 CVE-2026-54121 veřejná správa US

· BleepingComputer · Certighost and the Privilege Hiding in Your Certificate Authority · Microsoft Security · CVE-2026-54121 Active Directory Certificate Services Elevation of Privilege Vulnerability

17th August – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 17th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Colombia’s Ministry of Justice has experienced a ransomware attack that affected part of its technology infrastructure and disrupted public services related to illicit-drug monitoring and legal processes. Officials confirmed that some files were encrypted but stated that no data theft was detected during the incident. MyDr, Poland’s primary…

KEV ✓ EPSS 0.25 CVSS 9.8 CVE-2026-53413 CVE-2026-65400 CVE-2026-68820 CVE-2026-71362 Microsoft Apple Adobe Zoom veřejná správa zdravotnictví obrana energetika IL

· Check Point Research · 17th August – Threat Intelligence Report

SPOJENO PŘES CVE CISA Adds One Known Exploited Vulnerability to Catalog 

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-62593 Ray-Project Ray Code Injection Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive…

KEV ✓ EPSS 0.17 CVE-2025-62593 Ray-Project veřejná správa US

· CISA Advisories · CISA Adds One Known Exploited Vulnerability to Catalog  · CISA KEV · Ray-Project Ray Code Injection Vulnerability (CVE-2025-62593)

1

The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposure

Tenable’s Research Special Operations (RSO) team has been tracking a cluster of agentic AI threat activity since late July 2026. The Taiwan autonomous AI cyber attack confirmed what the cluster data already showed: near-autonomous offensive AI has crossed from theoretical risk to operational reality.Key TakeawaysTaiwan's Ministry of Digital Affairs confirmed a near-autonomous AI cyber attack in July 2026 in which autonomous agents mapped 21 connected government systems, compromised 85 accounts,…

KEV ✓ · ransomware EPSS 1.00 CVE-2025-3248 GitBook veřejná správa energetika US

tg: incident tg: varování tg: rozbor tp: únik dat tp: AI tp: identita tp: špionáž

· Tenable Research · The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposure

4

Upozorenje: građani dobivaju lažne poruke koje se predstavljaju kao kazneni ili sudski postupak

Ministarstvo pravosuđa, uprave i digitalne transformacije upozorava građane na lažne poruke kojima se pokušava stvoriti dojam da se protiv primatelja vodi kazneni ili sudski postupak. “Trenutno se šire lažne poruke koje građani zaprimaju putem e-pošte. U privitku poruka nalaze se dokumenti koji izgledom pokušavaju djelovati službeno, pri čemu se koriste grbovi i logotipi različitih institucija, među ostalim i Ministarstva pravosuđa, uprave i digitalne transformacije. Građanima savjetujemo da ne…

veřejná správa HR

· CERT.hr · Upozorenje: građani dobivaju lažne poruke koje se predstavljaju kao kazneni ili sudski postupak

APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit

Introduction CoolClient is a backdoor family attributed to the HoneyMyte APT group (also known as Mustang Panda) that has been used in their cyber-espionage campaigns targeting organizations across Asia and Russia. It supports such capabilities as keylogging, clipboard theft, credential harvesting, file management, system reconnaissance, and plugin-based extensions. Since its first public disclosure by Sophos in 2022 and subsequent analysis by Trend Micro in 2023, CoolClient has continued to…

veřejná správa RU

· Securelist (Kaspersky) · APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit

Varovanie pred rizikami cestných meradiel

Národný bezpečnostný úrad varuje pred významnou kybernetickou hrozbou spojenou s používaním viacerých typov cestných rýchlomerov s kamerou. Bezpečnostná analýza identifikovala viaceré riziká a dotknutým subjektom odporúča predmetné produkty vo svojej infraštruktúre identifikovať. Národný bezpečnostný úrad podľa § 5 ods. 1 písm. q) v spojení s § 27 ods. 1 písm. a) a ods. 2 zákona... The post Varovanie pred rizikami cestných meradiel appeared first on SK-CERT.

doprava veřejná správa SK

· SK-CERT (NBÚ SR) · Varovanie pred rizikami cestných meradiel

5

SPOJENO PŘES CVE AL26-018 - Vulnerability affecting Cisco ASA and Secure Firewall Threat Defense Software Remote Access SSL VPN - CVE-2026-20349

Number: AL26-018Date: August 13, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested. Details The Canadian…

KEV ✓ EPSS 0.02 CVE-2026-20349 Cisco veřejná správa CA RO IT FR US

· Cyber Centre Kanada · AL26-018 - Vulnerability affecting Cisco ASA and Secure Firewall Threat Defense Software Remote Access SSL VPN - CVE-2026-20349 · DNSC Rumunsko · ALERTĂ: Vulnerabilitate exploatată activ în Cisco · CSIRT Itálie (ACN) · Rilevato sfruttamento di vulnerabilità in prodotti Cisco · CERT-FR – avis · Vulnérabilité dans les produits Cisco (12 août 2026) · Cisco PSIRT · Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability · CISA KEV · Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability (CVE-2026-20349)

Johnson Controls Metasys

View CSAF Summary Successful exploitation of this vulnerability could allow a low-privilege user or attacker to inject a persistent malicious payload via a crafted URL that executes in the context of other users' sessions, including administrators, potentially leading to session hijacking and unauthorized access. The following versions of Johnson Controls Metasys are affected: Metasys 12 vers:all/* (CVE-2026-34491) Metasys 13 vers:all/* (CVE-2026-34491) Metasys 14 Metasys 15 CVSS Vendor…

EPSS 0.00 CVSS 8.0 CVE-2026-34491 Johnson Controls energetika výroba a průmysl veřejná správa doprava US

· CISA Advisories · Johnson Controls Metasys

Johnson Controls Inc. Airwall

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to decrypt sensitive data, bypass authentication controls, gaining unauthorized access to read arbitrary files on the system, or gain unauthorized access to protected system resources. The following versions of Johnson Controls Inc. Airwall are affected: Airwall <=4.0.4 (CVE-2026-64887, CVE-2026-34492) CVSS Vendor Equipment Vulnerabilities v3 6.8 Johnson Controls Inc. Johnson Controls Inc. Airwall Use of…

EPSS 0.00 CVSS 6.8 CVE-2026-34492 CVE-2026-64887 Johnson Controls výroba a průmysl veřejná správa energetika doprava US

· CISA Advisories · Johnson Controls Inc. Airwall

Riasztás a Lazarus „Operation Dream Job” kampányról és a CVE‑2026‑68820 Windows sérülékenységről

A Nemzetbiztonsági Szakszolgálat Nemzeti Kiberbiztonsági Intézet riasztást ad ki a Windows kernelt érintő, észak-koreai kötődésű Lazarus csoport által végrehajtott célzott kampánnyal kapcsolatban, amelyben trójai PDF nézők, fejlett in‑memory moduláris kártevők és több zero‑day/exploittal támogatott támadási lánc kerül alkalmazásra. A kampány részeként a támadók a Microsoft Windows AFD.sys illesztőprogram egy korábban nem publikált (0-day) use‑after‑free típusú […]

Microsoft veřejná správa HU

· NKI Maďarsko · Riasztás a Lazarus „Operation Dream Job” kampányról és a CVE‑2026‑68820 Windows sérülékenységről

Armored Likho expands its cyber-espionage toolkit

In May 2026, we discovered a new cyber-espionage campaign by the Armored Likho group, also known as Eagle Werewolf, that targets private individuals and organizations across various industries in Russia, including major corporations, the public sector, IT, and education. The attackers used a fake app as bait that mimics a service for donations. However, the most interesting part of this campaign isn’t the initial infection method – it’s the malicious implants the attackers use for cyber…

Kaspersky veřejná správa školství RU

· Securelist (Kaspersky) · Armored Likho expands its cyber-espionage toolkit

2

Patch Tuesday: Update now to fix 421 flaws, including three zero-days

Microsoft’s August 2026 Patch Tuesday addresses 421 Microsoft vulnerabilities, including 62 rated Critical. One Windows vulnerability has been exploited in the wild by the Lazarus group to gain SYSTEM privileges. The August update is smaller than July’s record-breaking release, but it’s still among Microsoft’s largest Patch Tuesday batches. More importantly, it includes several flaws likely to attract attacker interest: a publicly disclosed Windows privilege escalation flaw with a proof-of…

EPSS 0.03 CVSS 9.8 CVE-2026-62832 CVE-2026-62893 Microsoft školství veřejná správa US

· Malwarebytes Labs · Patch Tuesday: Update now to fix 421 flaws, including three zero-days

Multiples vulnérabilités dans Microsoft Azure (12 août 2026)

De multiples vulnérabilités ont été découvertes dans Microsoft Azure. Elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité des données et un contournement de la politique de sécurité.

EPSS 0.01 CVE-2026-47299 CVE-2026-57104 CVE-2026-65806 CVE-2026-6726 CVE-2026-6727 CVE-2026-70340 Microsoft finance veřejná správa FR

· CERT-FR – avis · Multiples vulnérabilités dans Microsoft Azure (12 août 2026)

8

SPOJENO PŘES CVE CVE-2026-62893 Windows Deployment Services TFTP Server Remote Code Execution Vulnerability

Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.

EPSS 0.03 CVSS 7.5 CVE-2026-62893 Microsoft veřejná správa US

· Microsoft Security · CVE-2026-62893 Windows Deployment Services TFTP Server Remote Code Execution Vulnerability · Zero Day Initiative · ZDI-26-544: Microsoft Windows Deployment Services Use-After-Free Remote Code Execution Vulnerability