Výsledky hledání

typ: zranitelnost× v celém archivu zrušit filtry

1790 karet z 1920 položek · strana 25 z 30 CZ · EN/orig

60

NCSC-2026-0346 [1.01] [M/H] Kwetsbaarheden verholpen in Siemens producten

Siemens heeft kwetsbaarheden verholpen in diverse producten als Desigo, Reyrolle, SIMATIC, SCALANCE, SINAMICS en Siveillance. De kwetsbaarheden stellen een kwaadwillende in staat aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade: * Denial-of-Service (DoS) * Manipulatie van gegevens * Omzeilen van een beveiligingsmaatregel * (Remote) code execution (root/admin rechten) * (Remote) code execution (gebruikersrechten) * Toegang tot gevoelige gegevens * Verhogen van rechten…

Siemens NL

tg: zranitelnost tp: průmyslové systémy

· NCSC-NL · NCSC-2026-0346 [1.01] [M/H] Kwetsbaarheden verholpen in Siemens producten

SPOJENO PŘES CVE Sanate vulnerabilità in TYPO3 CMS

Aggiornamenti di sicurezza TYPO3 sanano 2 vulnerabilità con gravità “alta” in TYPO3 CMS, sistema open source per la gestione di contenuti web. Tali vulnerabilità, qualora sfruttate, potrebbero consentire a un utente malevolo autenticato di accedere a informazioni sensibili ed elevare i propri privilegi sui sistemi interessati.

EPSS 0.00 CVE-2026-77132 CVE-2026-85400 TYPO3 Typo3 IT FR

tg: zranitelnost

· CSIRT Itálie (ACN) · Sanate vulnerabilità in TYPO3 CMS · CERT-FR – avis · Multiples vulnérabilités dans Typo3 (08 septembre 2026)

Risolte vulnerabilità in prodotti Qualcomm Technologies Inc.

Aggiornamenti di sicurezza Qualcomm Technologies Inc. sanano 14 vulnerabilità con gravità “alta” che interessano componenti software impiegati nelle piattaforme e nei chipset del produttore, utilizzati in dispositivi mobili, sistemi di connettività wireless, piattaforme automotive e soluzioni di calcolo. Tali vulnerabilità, qualora sfruttate, potrebbero consentire di accedere a informazioni riservate, compromettere la disponibilità del servizio sui sistemi interessati.

EPSS 0.00 CVE-2025-59607 CVE-2026-24073 CVE-2026-24074 CVE-2026-24075 CVE-2026-24081 CVE-2026-25275 CVE-2026-25278 CVE-2026-25280 CVE-2026-25281 CVE-2026-25282 CVE-2026-25283 CVE-2026-25284 CVE-2026-25290 CVE-2026-25294 Qualcomm IT

tg: zranitelnost

· CSIRT Itálie (ACN) · Risolte vulnerabilità in prodotti Qualcomm Technologies Inc.

CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability CVE-2026-81963 Microsoft Windows Link Following Vulnerability CVE-2026-85880 Microsoft Windows Heap-Based Buffer Overflow Vulnerability CVE-2026-86218 N-able N-central Static Code Injection Vulnerability These types of vulnerabilities…

KEV ✓ EPSS 0.07 CVE-2026-75650 CVE-2026-81963 CVE-2026-85880 CVE-2026-86218 Adobe Magento Microsoft N-able veřejná správa US

tg: zneužíváno tg: zranitelnost tg: regulace

· CISA Advisories · CISA Adds Four Known Exploited Vulnerabilities to Catalog

China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies

Executive summary China-based artificial intelligence (AI) companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns that form the core—not merely a supplement—of their AI development strategy. While “distillation” is recognized as a legitimate and useful technique in AI research, China-based AI companies are engaging in aggressive, malicious, and targeted distillation…

US

tg: varování tg: zranitelnost tp: AI tp: špionáž

· CISA Advisories · China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies

CareCam Pro IP Cameras

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to take full control of the device. The following versions of CareCam Pro IP Cameras are affected: ANJIA AJL33PC0801 Firmware linux_linux_202008261138_svn13796_/_Bootloader_U-Boot_2010.06_compiled_2020-08-26 (CVE-2026-85083) CVSS Vendor Equipment Vulnerabilities v3 6.8 CareCam CareCam Pro IP Cameras Use of Hard-coded Credentials Background Critical Infrastructure Sectors: Commercial Facilities Countries…

EPSS 0.00 CVSS 6.8 CVE-2026-85083 CareCam US

tg: zranitelnost tp: identita

· CISA Advisories · CareCam Pro IP Cameras

CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED)

OverviewWhile conducting research into a recent N-able N-central authentication bypass vulnerability (CVE-2026-18577), Rapid7 Labs discovered two new vulnerabilities affecting the latest version of N-central. When chained together, these two vulnerabilities allow a remote unauthenticated attacker to bypass authentication and create a new attacker-controlled System administrator account on an affected server.CVE IDDescriptionCWECVSSv4CVE-2026-86206Semicolon/Forwarded access-control bypassCWE…

KEV ✓ EPSS 0.54 CVE-2026-18577 CVE-2026-86206 CVE-2026-86207 N-able US

tg: zranitelnost tg: rozbor tp: identita

· Rapid7 · CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED)

Risolte vulnerabilità in prodotti JetBrains

Aggiornamenti di sicurezza JetBrains sanano alcune vulnerabilità, di cui 2 con gravità “critica” e 7 con gravità “alta”, che interessano vari prodotti. Tali vulnerabilità potrebbero consentire a un utente malintenzionato di accedere a informazioni riservate, alterare dati, eludere i meccanismi di sicurezza ed eseguire codice arbitrario sui sistemi interessati.

EPSS 0.01 CVE-2026-86478 CVE-2026-86479 CVE-2026-86480 CVE-2026-86482 CVE-2026-86492 CVE-2026-86494 CVE-2026-86498 CVE-2026-86502 CVE-2026-86504 JetBrains IT

tg: zranitelnost

· CSIRT Itálie (ACN) · Risolte vulnerabilità in prodotti JetBrains

SPOJENO PŘES CVE MikroTik router flaws allow takeover without a password

CERT Polska warns that attackers are actively exploiting a chain of critical MikroTik RouterOS flaws to seize control of routers exposed to the internet. Although the warning comes from Poland’s national cybersecurity response team, MikroTik routers are sold worldwide, including in the US. The vulnerabilities can affect users anywhere if their router is running a vulnerable version of RouterOS and its SSH remote-management service is accessible from the internet. Attackers are exploiting two…

KEV ✓ EPSS 0.01 CVSS 9.2 CVE-2026-67276 CVE-2026-86060 MikroTik US HR IT

tg: zneužíváno tg: zranitelnost tg: návod tp: identita

· Malwarebytes Labs · MikroTik router flaws allow takeover without a password · CERT.hr · Upozorenj: kritična ranjivosti u MikroTik RouterOS-u. Preporučuje se hitna nadogradnja. · CSIRT Itálie (ACN) · MikroTik: rilevato sfruttamento in rete di nuove vulnerabilità

NCSC-2026-0345 [1.00] [M/H] Kwetsbaarheden verholpen in MikroTik RouterOS

MikroTik heeft meerdere kwetsbaarheden verholpen in RouterOS. De eerste kwetsbaarheid betreft een fout in de SSH-authenticatiemechanisme waarbij de exponent van RSA-sleutels niet werd geverifieerd. Hierdoor kunnen aanvallers RSA-handtekeningen vervalsen en ongeautoriseerde SSH-toegang verkrijgen. De tweede kwetsbaarheid betreft een probleem met gebruikersnamen die beginnen met een verboden teken, waardoor de trusted policy mask kan worden gemanipuleerd en privilege escalation mogelijk is binnen…

MikroTik NL

tg: zneužíváno tg: zranitelnost tp: identita

· NCSC-NL · NCSC-2026-0345 [1.00] [M/H] Kwetsbaarheden verholpen in MikroTik RouterOS

NCSC-2026-0344 [1.00] [H/H] Kwetsbaarheid verholpen in Adobe Commerce en Magento

Adobe heeft een kwetsbaarheid verholpen in Adobe Commerce en Magento. De kwetsbaarheid bevindt zich in de template engine van Adobe Commerce, waarbij speciale elementen niet correct worden geneutraliseerd. Een aanvaller kan hierdoor op afstand willekeurige code uitvoeren zonder dat er gebruikersinteractie nodig is. Dit gebeurt door misbruik te maken van een gewijzigde scope om privileges te escaleren of de uitvoeringcontext aan te passen. Adobe geeft aan dat deze kwetsbaarheid reeds actief…

Adobe NL

tg: zneužíváno tg: zranitelnost

· NCSC-NL · NCSC-2026-0344 [1.00] [H/H] Kwetsbaarheid verholpen in Adobe Commerce en Magento