Výsledky hledání

typ: zranitelnost× v celém archivu zrušit filtry

1784 karet z 1914 položek · strana 2 z 30 CZ · EN/orig

42

Risolte vulnerabilità in Apache NiFi

Apache Software Foundation ha rilasciato aggiornamenti di sicurezza per Apache NiFi e Apache NiFi Registry, piattaforme open source per la gestione, l'elaborazione e il versionamento dei flussi di dati, che sanano alcune vulnerabilità, di cui 2 con gravità "alta". Tali vulnerabilità potrebbero consentire a un attaccante di effettuare operazioni sui file al di fuori della directory prevista, manipolare dati, eludere misure di sicurezza e, tramite richieste HTTP opportunamente predisposte, comprom

EPSS 0.00 CVE-2026-70469 CVE-2026-87976 Apache IT

tg: zranitelnost

· CSIRT Itálie (ACN) · Risolte vulnerabilità in Apache NiFi

Risolte vulnerabilità in prodotti HP

HP ha rilasciato aggiornamenti di sicurezza per risolvere diverse vulnerabilità, di cui 4 con gravità "critica" e 5 con gravità "alta", che interessano HP AC Print & Scan, HP Output Central e HP Linux Imaging and Printing Software (HPLIP), soluzioni software destinate alla gestione delle funzionalità di stampa e scansione.

EPSS 0.01 CVE-2026-89082 CVE-2026-89083 CVE-2026-89084 CVE-2026-91097 CVE-2026-91098 CVE-2026-91102 CVE-2026-91104 CVE-2026-91105 CVE-2026-91106 HP IT

tg: zranitelnost

· CSIRT Itálie (ACN) · Risolte vulnerabilità in prodotti HP

Mecanismo deficiente de recuperación de contraseñas olvidadas en MobiAPParc

Weak password recovery mechanism for forgotten password in MobiAPParc Thu, 09/17/2026 - 14:21 Aviso Affected Resources IOS MobiAPParc v0 – v2.28;Android MobiAPParc v0 – v2.42. Description INCIBE has coordinated the disclosure of a high-severity vulnerability affecting SMAP’s MobiAPParc, an app that enables users to pay for parking in regulated parking zones and in municipal car parks managed by Palma City Council. The vulnerability was discovered by Llorenç Romá.This vulnerability has been…

EPSS 0.00 CVSS 8.1 CVE-2026-14850 SMAP doprava ES

tg: zranitelnost tp: identita

· INCIBE-CERT · Mecanismo deficiente de recuperación de contraseñas olvidadas en MobiAPParc

SPOJENO PŘES CVE ABB Ability Edgenius

View CSAF Summary ABB is aware of public reports of a vulnerability CVE‑2026‑31431 (Copy Fail) in the product versions listed as affected in the advisory. An update is available that resolves a publicly reported vulnerability. CVE‑2026‑31431 (Copy Fail) is a Linux kernel vulnerability that may allow a locally authenticated user or compromised container workload to gain elevated (root) privileges on affected systems. Once root access is obtained, the attacker can effectively gain complete…

KEV ✓ EPSS 1.00 CVSS 7.8 CVE-2026-31431 ABB Linux výroba a průmysl energetika vodárenství US EU AT HU

tg: zneužíváno tg: zranitelnost tg: rozbor tp: průmyslové systémy

· CISA Advisories · ABB Ability Edgenius · Fortinet PSIRT · Linux Kernel Vulnerability copy.fail - CVE-2026-31431 · Elastic Security · Copy Fail and DirtyFrag: Linux Page Cache Bugs in the Wild · CERT-EU · 2026-005: High Vulnerability in the Linux Kernel ("Copy Fail") · CERT.at · Copy Fail Update #1: Kritische Linux-Kernel-Schwachstelle ermöglicht lokale Root-Rechte · NKI Maďarsko · Riasztás a Linux rendszereket érintő Copy Fail sérülékenységről

Schneider Electric PowerChute Serial Shutdown

View CSAF Summary Schneider Electric is aware of vulnerabilities in its PowerChute Serial Shutdown product. The PowerChute Serial Shutdown product is a UPS management software enabling graceful system shutdown and energy management capabilities for desktops, servers and workstations. Failure to apply the remediation provided below may risk improper authentication validation which could result in disruption of operations and access to system data. The following versions of Schneider Electric…

EPSS 0.00 CVSS 5.3 CVE-2026-13348 Schneider Electric energetika výroba a průmysl US

tg: zranitelnost tp: identita tp: průmyslové systémy

· CISA Advisories · Schneider Electric PowerChute Serial Shutdown

Schneider Electric Modicon M340 Controller and Communication Modules

View CSAF Summary Schneider Electric is aware of a vulnerability in its Modicon M340 https://www.se.com/ww/en/product-range/1468-modicon-m340-pac/, BMXNOR0200H https://www.se.com/us/en/product/BMXNOR0200H/communication-module-modicon-m340-iec-608705101-104-dnp3-for-severe-environments/: Modicon M340 X80 Ethernet Communication Modules, BMXNGD0100 https://www.se.com/us/en/product/BMXNGD0100/communication-module-modicon-m580-global-data-service/: M580 Global Data module, BMXNOC0401 https://www.se…

EPSS 0.00 CVSS 7.5 CVE-2025-6625 Schneider Electric energetika vodárenství výroba a průmysl US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Schneider Electric Modicon M340 Controller and Communication Modules

Schneider Electric NetBotz 5 750/755

View CSAF Summary Schneider Electric is aware of multiple vulnerabilities in its NetBotz 5 – 750/755 products.The NetBotz 5 – 750/755 products are security and environmental monitors providing temperature, humidity, leak, smoke, vibration, door contact, and video monitoring capabilities. Failure to apply the remediation provided below may risk arbitrary or remote code execution over the local network, which could result in device manipulation and unauthorized data access. The following versions…

EPSS 0.01 CVSS 6.4 CVE-2026-13336 CVE-2026-13337 Schneider Electric výroba a průmysl US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Schneider Electric NetBotz 5 750/755

Bransys ELD

View CSAF Summary Successful exploitation of these vulnerabilities could allow unauthorized access to telemetry data and firmware. The following versions of Bransys ELD are affected: Android <11.00.00 (CVE-2026-86520, CVE-2026-86689, CVE-2026-77960) iOS <1.1.54 (CVE-2026-86520, CVE-2026-86689, CVE-2026-77960) CVSS Vendor Equipment Vulnerabilities v3 7.5 Bransys Bransys ELD Use of Hard-coded Credentials, Cleartext Transmission of Sensitive Information Background Critical Infrastructure Sectors:…

CVSS 7.5 CVE-2026-77960 CVE-2026-86520 CVE-2026-86689 Bransys doprava US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Bransys ELD

Hitachi Energy FACTS Control Platform (FCP)

View CSAF Summary Hitachi Energy is aware of vulnerabilities that affect the FACTS Control systems with GWS component listed in this document. An attacker exploiting these vulnerabilities can cause impact on confidentiality, integrity and availability of the product. Following FACTS Control systems with GWS component deployed from year 2020 onwards are likely affected by the above vulnerabilities. Product deployments without GWS component are not affected. • SVC Light (STATCOM) • Fixed Series…

EPSS 0.01 CVSS 9.9 CVE-2024-3980 CVE-2024-3982 CVE-2024-4872 CVE-2024-7940 CVE-2024-7941 Hitachi Energy energetika US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Hitachi Energy FACTS Control Platform (FCP)

Mitsubishi Electric GX Works3 and Motion Control Settings

View CSAF Summary Successful exploitation of this vulnerability could allow a local attacker to successfully authenticate even with an invalid block password by executing the affected product and modify part of the executable module in memory, and thereby allows the attacker to view, tamper with, destroy, or delete control programs. The following versions of Mitsubishi Electric GX Works3 and Motion Control Settings are affected: Mitsubishi Electric GX Works3 vers:all/* (CVE-2026-15688)…

EPSS 0.00 CVSS 8.8 CVE-2026-15688 Mitsubishi Electric výroba a průmysl US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Mitsubishi Electric GX Works3 and Motion Control Settings

Mitsubishi Electric CC-Link IE TSN Communication Protocol (Update A)

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker with access to the same network segment to tamper with communication data in the affected product by sending specially crafted packets under specific timing conditions. This could allow the attacker to cause a denial-of-service (DoS) condition in the affected product by interfering with its control function or causing it to operate incorrectly. The following versions of Mitsubishi Electric CC-Link IE TSN…

EPSS 0.00 CVE-2026-13584 Mitsubishi Electric výroba a průmysl US

tg: zranitelnost tp: DDoS tp: průmyslové systémy

· CISA Advisories · Mitsubishi Electric CC-Link IE TSN Communication Protocol (Update A)

NCSC-2026-0383 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle VM VirtualBox

Oracle heeft 19 kwetsbaarheden verholpen in Oracle VM VirtualBox. De kwetsbaarheden betreffen verschillende beveiligingsproblemen in Oracle VM VirtualBox, waaronder mogelijkheden voor lokale en geauthenticeerde kwaadwillenden om ongeautoriseerde acties uit te voeren. De kwetsbaarheden hebben CVSS-scores variërend van laag tot hoog. Van de in totaal 19 kwetsbaarheden kan volgens Oracle één kwetsbaarheid zonder authenticatie op afstand worden misbruikt. Succesvol misbruik kan onder meer leiden…

EPSS 0.00 CVE-2026-87273 CVE-2026-87277 Oracle NL

tg: zranitelnost

· NCSC-NL · NCSC-2026-0383 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle VM VirtualBox

Risolte vulnerabilità in Craft CMS

Rilasciati aggiornamenti di sicurezza per Craft CMS, sistema di gestione dei contenuti per la realizzazione e gestione di siti e applicazioni web, che sanano alcune vulnerabilità, di cui 4 con gravità "alta". Tali vulnerabilità potrebbero consentire a un attaccante di accedere a informazioni sensibili, eludere restrizioni di sicurezza, elevare i privilegi utente ed eseguire codice arbitrario sui sistemi interessati.

EPSS 0.01 CVE-2026-92591 CVE-2026-92592 CVE-2026-92593 CVE-2026-92594 Craft CMS IT

tg: zranitelnost

· CSIRT Itálie (ACN) · Risolte vulnerabilità in Craft CMS

NCSC-2026-0382 [1.00] [H/H] Kwetsbaarheden verholpen in Cisco Identity Services Engine (ISE)

Cisco heeft 21 kwetsbaarheden verholpen in Cisco Identity Services Engine (ISE) en Cisco ISE Passive Identity Connector (ISE-PIC). De kwetsbaarheden betreffen verschillende beveiligingsproblemen in Cisco ISE en ISE-PIC, waaronder mogelijkheden voor niet-geauthenticeerde en laaggeprivilegieerde kwaadwillenden om via netwerktoegang ongeautoriseerde acties uit te voeren. De kwetsbaarheden hebben CVSS-scores variërend van middel tot kritiek. Van de in totaal 21 kwetsbaarheden zijn 13 als kritiek…

KEV ✓ EPSS 0.01 CVE-2026-20130 CVE-2026-20192 CVE-2026-76423 CVE-2026-76460 Cisco NL

tg: zneužíváno tg: zranitelnost tp: identita

· NCSC-NL · NCSC-2026-0382 [1.00] [H/H] Kwetsbaarheden verholpen in Cisco Identity Services Engine (ISE)

Risolte vulnerabilità in ISC BIND 9

ISC ha rilasciato aggiornamenti di sicurezza per BIND 9 e BIND Supported Preview Edition, software per la gestione e la risoluzione delle richieste DNS, che sanano alcune vulnerabilità, di cui 7 con gravità "alta". Tali vulnerabilità possono causare la terminazione anomala di alcuni processi o un consumo eccessivo delle risorse, fino a compromettere la disponibilità del servizio sui sistemi interessati.

EPSS 0.00 CVE-2026-19666 CVE-2026-19667 CVE-2026-76163 CVE-2026-77692 CVE-2026-80274 CVE-2026-81563 CVE-2026-81736 ISC IT

tg: zranitelnost tp: DDoS

· CSIRT Itálie (ACN) · Risolte vulnerabilità in ISC BIND 9

Cisco warns of max severity ISE zero-day exploited in attacks

Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild. [...]

KEV ✓ EPSS 0.68 CVE-2025-20337 CVE-2026-20176 CVE-2026-20211 CVE-2026-20284 CVE-2026-20307 CVE-2026-76423 CVE-2026-76460 Cisco US

tg: zneužíváno tg: zranitelnost tp: identita

· BleepingComputer · Cisco warns of max severity ISE zero-day exploited in attacks

ZDI-26-714: Samsung rlottie Stack-based Buffer Overflow Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Samsung rlottie. Interaction with the rlottie library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91826.

EPSS 0.00 CVSS 7.8 CVE-2026-91826 Samsung US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-714: Samsung rlottie Stack-based Buffer Overflow Remote Code Execution Vulnerability

Mozilla Foundation Security Advisory 2026-96

Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: None, CVEs: CVE-2026-92238, CVE-2026-92239, CVE-2026-92240, CVE-2026-92005, CVE-2026-92006, CVE-2026-92007, CVE-2026-92008, CVE-2026-92009, CVE-2026-92010, CVE-2026-92011, CVE-2026-92012, CVE-2026-92013, CVE-2026-92015, CVE-2026-92035, CVE-2026-92016, CVE-2026-92017, CVE-2026-92018, CVE-2026-92019, CVE-2026-92020, CVE-2026-92022 (+46 other associated CVEs), Summary: Security Vulnerabilities fixed in…

Mozilla FI

tg: zranitelnost tg: novinka v produktu

· NCSC-FI · Mozilla Foundation Security Advisory 2026-96

Jenkins Security Advisory 2026-09-16

Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 8.8, CVEs: CVE-2026-92122, CVE-2026-92123, CVE-2026-92124, CVE-2026-92125, CVE-2026-92126, CVE-2026-92127, CVE-2026-92128, CVE-2026-92129, CVE-2026-92130, CVE-2026-92131, CVE-2026-92132, CVE-2026-92133, CVE-2026-92134, CVE-2026-92135, CVE-2026-92136, CVE-2026-92137, CVE-2026-92138, CVE-2026-92139, CVE-2026-92140, CVE-2026-92141, Summary: This advisory announces vulnerabilities in the following Jenkins…

CVSS 8.8 Jenkins FI

tg: zranitelnost

· NCSC-FI · Jenkins Security Advisory 2026-09-16

HPESBNW05135 rev.1 - Multiple Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways & Orchestrator

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.9, CVEs: CVE-2026-76669, CVE-2026-76670, CVE-2026-76672, CVE-2026-76673, CVE-2026-76674, CVE-2026-76675, CVE-2026-76676, CVE-2026-76677, CVE-2026-76678, CVE-2026-76679, CVE-2026-76680, CVE-2026-76681, CVE-2026-76682, CVE-2026-76683, CVE-2026-76684, CVE-2026-76685, CVE-2026-76686, CVE-2026-76687, CVE-2026-76688, CVE-2026-76689 (+19 other associated CVEs), Summary: HPE Networking has released updates for…

CVSS 9.9 HPE FI

tg: zranitelnost

· NCSC-FI · HPESBNW05135 rev.1 - Multiple Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways & Orchestrator

MLflow dspy and statsmodels flavors bypass pickle deserialization control

Classification: Severe, Solution: Temporary Fix, Exploit Maturity: Not Defined, CVSSv3.1: None, CVEs: , Summary: A vulnerability in MLflow’s dspy and statsmodels model flavors allows unauthorized pickle deserialization executions despite a safety control. Specifically, the dspy flavor conditionally applies the control based on the model path’s file extension, and the statsmodels flavor does not apply the control. Exploitation of this vulnerability allows for arbitrary remote code execution…

MLflow FI

tg: zranitelnost tp: AI

· NCSC-FI · MLflow dspy and statsmodels flavors bypass pickle deserialization control

Sentry Seer vulnerability allows attacker-controlled input to be executed in a privileged environment

Classification: Severe, Solution: Workaround, Exploit Maturity: Not Defined, CVSSv3.1: None, CVEs: CVE-2026-90999, Summary: A vulnerability exists in Sentry Seer when the system is configured to automatically hand issues to a coding agent for remediation. Successful exploitation results in arbitrary code execution within the coding‑agent environment and access to connected source repositories. This vulnerability is tracked as CVE-2026-90999. Successful exploitation may allow arbitrary code…

EPSS 0.00 CVE-2026-90999 Sentry FI

tg: zranitelnost tp: AI

· NCSC-FI · Sentry Seer vulnerability allows attacker-controlled input to be executed in a privileged environment

Drupal core - Moderately critical - Third-party libraries - SA-CORE-2026-013

Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: None, CVEs: , Summary: The Drupal project uses the CKEditor library for WYSIWYG editing. CKEditor has released a security update that impacts Drupal. Vulnerabilities are possible if Drupal is configured to use CKEditor for WYSIWYG editing. An attacker that can create or edit content (even without access to CKEditor themselves) may be able to exploit this Cross-Site Scripting (XSS) vulnerability to target…

Drupal CKEditor FI

tg: zranitelnost

· NCSC-FI · Drupal core - Moderately critical - Third-party libraries - SA-CORE-2026-013

Issabel Framework Hard-coded JWT Key RCE via pbxapi/manager/originate

Classification: Critical, Solution: Official Fix, Exploit Maturity: High, CVSSv4.0: 9.3, CVEs: CVE-2026-89026, Summary: The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote attackers to forge valid bearer tokens. Attackers can use the forged token to call the manager originate endpoint with the System…

EPSS 0.01 CVSS 9.3 CVE-2026-89026 Issabel FI

tg: zneužíváno tg: zranitelnost tp: identita

· NCSC-FI · Issabel Framework Hard-coded JWT Key RCE via pbxapi/manager/originate

Cisco - Multiple security advisories 2026-09-16

Classification: Critical, Solution: Official Fix, Exploit Maturity: High, CVSSv3.1: 10.0, CVEs: CVE-2026-20350, CVE-2026-20309, CVE-2026-20247, CVE-2026-20300, CVE-2026-20176, CVE-2026-20211, CVE-2026-20307, CVE-2026-76448, CVE-2026-76449, CVE-2026-76450, CVE-2026-76451, CVE-2026-76439, CVE-2026-76444, CVE-2026-76446, CVE-2026-76447, CVE-2026-20071, CVE-2026-20072, CVE-2026-76431, CVE-2026-76432, CVE-2026-76433 (+59 other associated CVEs), Summary: Advisories: Cisco ThousandEyes Virtual…

CVSS 10.0 Cisco FI

tg: zranitelnost

· NCSC-FI · Cisco - Multiple security advisories 2026-09-16

SPOJENO PŘES CVE Acronis - Local privilege escalation due to insecure file permissions

Classification: Severe, Solution: Official Fix, Exploit Maturity: High, CVSSv3.0: 7.8, CVEs: CVE-2026-87886, Summary: Exploitation of this vulnerability has been detected in the wild in limited, targeted attacks against Acronis Backup plugin for cPanel & WHM deployments. Affected products Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021 Acronis Backup extension for Plesk (Linux) before build 1.8.11.638

KEV ✓ EPSS 0.00 CVSS 7.8 CVE-2026-87886 Acronis cPanel Plesk WebHost Manager FI IT US

tg: zneužíváno tg: zranitelnost

· NCSC-FI · Acronis - Local privilege escalation due to insecure file permissions · CSIRT Itálie (ACN) · Acronis: rilevato sfruttamento in rete della CVE-2026-87886 · CISA KEV · Acronis Backup Incorrect Default Permissions Vulnerability (CVE-2026-87886) · BleepingComputer · Acronis warns of actively exploited flaw in its cPanel backup plugin

Pixel Update Bulletin—September 2026

Classification: Critical, Solution: Official Fix, Exploit Maturity: High, CVSSv3.1: None, CVEs: CVE-2026-56914, CVE-2026-58773, CVE-2026-55318, CVE-2026-55343, CVE-2026-56920, CVE-2026-56967, CVE-2026-58683, CVE-2026-58710, CVE-2026-0179, CVE-2026-0187, CVE-2026-0192, CVE-2026-0194, CVE-2026-0199, CVE-2026-0200, CVE-2026-55302, CVE-2026-55317, CVE-2026-55323, CVE-2026-55329, CVE-2026-55337, CVE-2026-55357 (+90 other associated CVEs), Summary: The Pixel Update Bulletin contains details of…

Google FI

tg: zranitelnost tg: novinka v produktu

· NCSC-FI · Pixel Update Bulletin—September 2026

Oracle Critical Security Patch Update Advisory - September 2026

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 10.0, CVEs: CVE-2026-87273, CVE-2026-87268, CVE-2026-87269, CVE-2026-87270, CVE-2026-87271, CVE-2026-87272, CVE-2026-87275, CVE-2026-87279, CVE-2026-87267, CVE-2026-87274, CVE-2026-87280, CVE-2026-87281, CVE-2026-87282, CVE-2026-87283, CVE-2026-87284, CVE-2026-87285, CVE-2026-87289, CVE-2026-70755, CVE-2026-83354, CVE-2026-87276 (+785 other associated CVEs), Summary: This Critical Security Patch Update…

CVSS 10.0 Oracle FI

tg: zranitelnost

· NCSC-FI · Oracle Critical Security Patch Update Advisory - September 2026

Chrome - Stable Channel Update for Desktop

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: None, CVEs: CVE-2026-91726, CVE-2026-91721, CVE-2026-91749, CVE-2026-91724, CVE-2026-91728, CVE-2026-91734, CVE-2026-91727, CVE-2026-91743, CVE-2026-91744, CVE-2026-91712, CVE-2026-91748, CVE-2026-91720, CVE-2026-91731, CVE-2026-91747, CVE-2026-91733, CVE-2026-91741, CVE-2026-91709, CVE-2026-91717, CVE-2026-91735, CVE-2026-91708 (+22 other associated CVEs), Summary: The Stable channel has been updated to…

FI

tg: zranitelnost tg: novinka v produktu

· NCSC-FI · Chrome - Stable Channel Update for Desktop

Multiples vulnérabilités dans ISC BIND (17 septembre 2026)

De multiples vulnérabilités ont été découvertes dans ISC BIND. Elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à l'intégrité des données et un contournement de la politique de sécurité.

EPSS 0.00 CVE-2026-75029 CVE-2026-76163 CVE-2026-77119 CVE-2026-77692 CVE-2026-78301 CVE-2026-80274 CVE-2026-81563 CVE-2026-81736 ISC FR

tg: zranitelnost tp: DDoS

· CERT-FR – avis · Multiples vulnérabilités dans ISC BIND (17 septembre 2026)

18

The Apple Security Update Review for September 2026

Welcome back to our monthly look at Apple security patches. This release shows Apple is not immune to the new normal of AI-assisted vulnerability discovery as they release patches for 273 total CVEs.For the September 2026 release, Apple released 273 unique CVEs across macOS 27 (Golden Gate), macOS Sequoia 15.8, macOS Tahoe 26.7, iOS / iPadOS 27, visionOS 27, watchOS 27, tvOS 27, iOS / iPadOS 26.7, Safari 27, and Xcode 27. This patch release actually happened a couple of days ago, but since…

Apple US

tg: zneužíváno tg: zranitelnost tg: rozbor

· ZDI Blog · The Apple Security Update Review for September 2026

ISC BIND security advisory (AV26-931)

Serial Number: AV26-931Date: September 16, 2026 As of September 16, 2026, ISC is affected by vulnerabilities in the following product: ISC BIND 9 Prior to or equal to 9.18.50 Prior to or equal to 9.18.50-S1 Prior to or equal to 9.20.27 Prior to or equal to 9.20.27-S1 Prior to or equal to 9.21.25 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. BIND 9 Software Vulnerability Matrix

ISC CA

tg: zranitelnost

· Cyber Centre Kanada · ISC BIND security advisory (AV26-931)

Apple security advisory (AV26-930)

Serial Number: AV26-930Date: September 16, 2026 As of September 14, 2026, Apple is affected by vulnerabilities in the following products: iOS and iPadOS Prior to 27 Prior to 26.7 macOS Golden Gate Prior to 27 macOS Tahoe Prior to 26.7 macOS Sequoia Prior to 15.8 tvOS Prior to 27 watchOS Prior to 27 visionOS 27 Prior to 27 Safari Prior to 27 Xcode Prior to 27 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become…

Apple CA

tg: zranitelnost

· Cyber Centre Kanada · Apple security advisory (AV26-930)

Oracle Corporation security advisory (AV26-929)

Serial number: AV26-929Date: September 16, 2026 As of September 15, 2026, Oracle Corporation is affected by vulnerabilities in the following products: Helidon Oracle Access Manager Oracle Agile Engineering Data Management Oracle Agile PLM Oracle Agile PLM MCAD Connector Oracle Application Testing Suite Oracle Autonomous Health Framework Oracle Banking Branch Oracle Banking Corporate Lending Oracle Banking Corporate Lending Process Management Oracle Banking Origination Oracle Banking Treasury…

Oracle CA

tg: zranitelnost

· Cyber Centre Kanada · Oracle Corporation security advisory (AV26-929)

HPE security advisory (AV26-928)

Serial number: AV26-928Date: September 16, 2026 As of September 15, 2026, Hewlett Packard Enterprise (HPE) is affected by vulnerabilities in the following products: HPE Networking EdgeConnect SD-WAN Gateways Multiple versions HPE Networking EdgeConnect SD-WAN Orchestrator Multiple versions The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. HPESBNW05135 rev.1 - Multiple Vulnerabilities in HPE Networking…

HPE CA

tg: zranitelnost

· Cyber Centre Kanada · HPE security advisory (AV26-928)

[Control Systems] Phoenix Contact security advisory (AV26-927)

Serial number: AV26-927Date: September 16, 2026 As of September 16, 2026, Phoenix Contact is affected by vulnerabilities in the following products: ICE2-8IOL-G65L-V1D Prior to 1.7.4 ICE2-8IOL-K45P-RJ45 Prior to 1.7.4 ICE2-8IOL-K45S-RJ45 Prior to 1.7.4 ICE2-8IOL1-G65L-V1D Prior to 1.7.4 ICE3-8IOL-G65L-V1D Prior to 1.7.4 ICE3-8IOL-G65L-V1D-Y Prior to 1.7.4 ICE3-8IOL-K45P-RJ45 Prior to 1.7.4 ICE3-8IOL-K45S-RJ45 Prior to 1.7.4 ICE3-8IOL1-G65L-V1D Prior to 1.7.4 IOL MA8 EIP DI8 Prior to 1.7.4 IOL…

Phoenix Contact Pepperl+Fuchs Carlo Gavazzi Automation CA

tg: zranitelnost tp: průmyslové systémy

· Cyber Centre Kanada · [Control Systems] Phoenix Contact security advisory (AV26-927)

Google security advisory (AV26-926)

Serial number: AV26-926 Date: September 16, 2026 As of September 15, 2026, Google is affected by vulnerabilities in the following product: Chrome Prior to 153.0.8010.48 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. Stable Channel Update for Desktop

Google CA

tg: zranitelnost

· Cyber Centre Kanada · Google security advisory (AV26-926)

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software SSL VPN Denial of Service Vulnerability

Update for September 16, 2026: The original 1.0 version of this advisory was specific to the Cisco Adaptive Security Virtual Appliance (ASAv) and Cisco Secure Firewall Threat Defense Virtual (FTDv) models. However, it was later found that this vulnerability affects all Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software platforms. A vulnerability in the VPN and management web servers of the Cisco Secure Firewall ASA Software…

EPSS 0.01 CVE-2024-20260 Cisco US

tg: zranitelnost tp: DDoS

· Cisco PSIRT · Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software SSL VPN Denial of Service Vulnerability

Cisco Secure Firewall Management Center Software sftunnel Root Arbitrary Code Execution Vulnerability

A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands as root. This vulnerability exists because a registered sftunnel peer has incorrect permissions to write an arbitrary file to any location on the device. An attacker could exploit this vulnerability by hijacking the sftunnel communication connection or being a valid registered sftunnel peer and…

EPSS 0.00 CVE-2026-20324 Cisco US

tg: zranitelnost

· Cisco PSIRT · Cisco Secure Firewall Management Center Software sftunnel Root Arbitrary Code Execution Vulnerability

Cisco Identity Services Engine SQL Injection Vulnerabilities

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow a remote attacker to conduct SQL injection attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content…

EPSS 0.00 CVE-2026-20247 CVE-2026-20300 Cisco US

tg: zranitelnost

· Cisco PSIRT · Cisco Identity Services Engine SQL Injection Vulnerabilities

Cisco Identity Services Engine SQL and HQL Injection Vulnerabilities

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct SQL or HQL injection attacks on an affected device. These vulnerabilities are due to insufficient validation of user-supplied input to the affected APIs before it is used to build database queries. An attacker could exploit these vulnerabilities by sending a crafted request to an affected device. A successful exploit could…

EPSS 0.00 CVE-2026-76448 CVE-2026-76449 CVE-2026-76450 CVE-2026-76451 Cisco US

tg: zranitelnost

· Cisco PSIRT · Cisco Identity Services Engine SQL and HQL Injection Vulnerabilities

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IKEv2 Certificate Authentication Denial of Service Vulnerability

A vulnerability in the certification authentication feature of Internet Key Exchange version 2 (IKEv2) for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly. This vulnerability is due to a logic error during the certificate authentication phase of the IKEv2 connection setup. An attacker could exploit this vulnerability by…

EPSS 0.00 CVE-2026-20249 Cisco US

tg: zranitelnost

· Cisco PSIRT · Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IKEv2 Certificate Authentication Denial of Service Vulnerability

Cisco Identity Services Engine Authentication Bypass Vulnerabilities

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to access or manipulate data, obtain sensitive information, or cause a reload of certificate and key material on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these…

EPSS 0.00 CVE-2026-76439 CVE-2026-76444 CVE-2026-76446 CVE-2026-76447 Cisco US

tg: zranitelnost tp: identita

· Cisco PSIRT · Cisco Identity Services Engine Authentication Bypass Vulnerabilities

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Logging Denial of Service Vulnerability

A vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause high CPU utilization on an affected device, resulting in a denial of service (DoS) condition. This vulnerability is due to improper rate limiting for syslog message 419002. An attacker could exploit this vulnerability by sending a flood of…

EPSS 0.00 CVE-2026-20154 Cisco US

tg: zranitelnost tp: DDoS

· Cisco PSIRT · Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Logging Denial of Service Vulnerability

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software EIGRP Denial of Service Vulnerability

A vulnerability in the EIGRP implementation in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper resource management when handling EIGRP update messages. An attacker could exploit this vulnerability by sending crafted EIGRP updates at a high rate…

EPSS 0.00 CVE-2026-20222 Cisco US

tg: zranitelnost tp: DDoS

· Cisco PSIRT · Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software EIGRP Denial of Service Vulnerability

Cisco BroadWorks CommPilot Application Software Authorization Bypass Vulnerability

A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker with low privileges to alter configurations on an affected device. This vulnerability is due to missing authorization checks. An attacker could exploit this vulnerability by sending a crafted HTTP request. A successful exploit could allow the attacker to alter configurations on select pages. Cisco has released software updates that address this…

EPSS 0.00 CVE-2026-76438 Cisco US

tg: zranitelnost

· Cisco PSIRT · Cisco BroadWorks CommPilot Application Software Authorization Bypass Vulnerability

Cisco Nexus Dashboard Software Security Hardening Release: September 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by…

EPSS 0.00 CVE-2026-20322 CVE-2026-20325 CVE-2026-20326 CVE-2026-20360 CVE-2026-20361 CVE-2026-76409 Cisco US

tg: zranitelnost tg: novinka v produktu

· Cisco PSIRT · Cisco Nexus Dashboard Software Security Hardening Release: September 2026