Výsledky hledání

typ: zranitelnost× v celém archivu zrušit filtry

1790 karet z 1920 položek · strana 26 z 30 CZ · EN/orig

10

SPOJENO PŘES CVE ZDI-26-617: Microsoft Windows MIDI Service Incorrect Permission Assignment Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-66804.

EPSS 0.05 CVSS 7.8 CVE-2026-66804 Microsoft US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-617: Microsoft Windows MIDI Service Incorrect Permission Assignment Local Privilege Escalation Vulnerability · Microsoft Security · CVE-2026-66804 Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability

SPOJENO PŘES CVE ZDI-26-618: Microsoft Windows UMPDDrvStretchBlt Improper Object Management Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-62712.

EPSS 0.00 CVSS 7.8 CVE-2026-62712 Microsoft US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-618: Microsoft Windows UMPDDrvStretchBlt Improper Object Management Local Privilege Escalation Vulnerability · Microsoft Security · CVE-2026-62712 Windows Win32k Elevation of Privilege Vulnerability

SPOJENO PŘES CVE ZDI-26-622: Microsoft Windows IKEv2 AES-GCM Decryption Integer Underflow Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows. Authentication is not required to exploit this vulnerability, but only systems with specific IPsec configurations are vulnerable. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2026-50696.

EPSS 0.01 CVSS 8.1 CVE-2026-50696 Microsoft US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-622: Microsoft Windows IKEv2 AES-GCM Decryption Integer Underflow Remote Code Execution Vulnerability · Microsoft Security · CVE-2026-50696 Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability

Multiples vulnérabilités dans Schneider Electric EcoStruxure (08 septembre 2026)

De multiples vulnérabilités ont été découvertes dans Schneider Electric EcoStruxure. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance et une falsification de requêtes côté serveur (SSRF).

EPSS 0.01 CVE-2026-19233 CVE-2026-8044 Schneider Electric FR

tg: zranitelnost tp: průmyslové systémy

· CERT-FR – avis · Multiples vulnérabilités dans Schneider Electric EcoStruxure (08 septembre 2026)

Multiples vulnérabilités dans strongSwan (08 septembre 2026)

De multiples vulnérabilités ont été découvertes dans strongSwan. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et un contournement de la politique de sécurité.

EPSS 0.02 CVE-2014-2338 CVE-2017-9023 CVE-2026-78127 CVE-2026-78129 CVE-2026-78130 CVE-2026-78131 CVE-2026-78132 CVE-2026-78133 CVE-2026-78134 CVE-2026-78135 strongSwan FR

tg: zranitelnost

· CERT-FR – avis · Multiples vulnérabilités dans strongSwan (08 septembre 2026)

17

NCSC-2026-0343 [1.00] [M/H] Kwetsbaarheden verholpen in GeoNetwork door OpenGeo

OpenGeo heeft meerdere kwetsbaarheden verholpen in GeoNetwork, een open-source catalogusapplicatie, specifiek in versies 4.4.5 tot en met 4.4.11 en versies voorafgaand aan 4.4.12 en 4.2.17. De eerste kwetsbaarheid betreft een reflected cross-site scripting (XSS) in de publieke, niet-geauthenticeerde cataloguszoekfunctie. Dit wordt veroorzaakt door onvoldoende sanering van de uiconfig queryparameter, waardoor een aanvaller JavaScript kan injecteren en uitvoeren in de browsercontext van…

OpenGeo GeoNetwork NL

tg: zranitelnost

· NCSC-NL · NCSC-2026-0343 [1.00] [M/H] Kwetsbaarheden verholpen in GeoNetwork door OpenGeo

NCSC-2026-0342 [1.00] [H/H] Kwetsbaarheid verholpen in N-central van N-able

N-able heeft een kwetsbaarheid verholpen in N-central versies eerder dan 2026.3.1.14. De kwetsbaarheid betreft een pre-authenticatie remote code execution flaw. Een aanvaller kan hierdoor op afstand willekeurige code uitvoeren op het getroffen systeem zonder enige vorm van authenticatie. Alle installaties die draaien op de kwetsbare versies van N-central zijn getroffen. Klanten met een on-premises N-central-omgeving wordt geadviseerd zo snel mogelijk te upgraden naar N-central 2026.3 HF4. Voor…

N-able NL

tg: zneužíváno tg: zranitelnost

· NCSC-NL · NCSC-2026-0342 [1.00] [H/H] Kwetsbaarheid verholpen in N-central van N-able

VAROVANIE: Útočníci aktívne zneužívajú zraniteľnosti MIKROTIK smerovačov

Národné centrum kybernetickej bezpečnosti (NCKB) NBÚ varuje pred útokmi na smerovače značky MikroTik. Útočníci zreťazením bezpečnostných zraniteľností operačného systému MikroTik RouterOS dokážu získať úplnú kontrolu nad zariadením bez potreby autentifikácie. MikroTik routre sú sieťové zariadenia vyrábané spoločnosťou MikroTik a využívajú vlastný operačný systém RouterOS. Využívané sú poskytovateľmi internetových služieb, v komerčnej sfére a rovnako aj v domácnostiach.... The post VAROVANIE:…

MikroTik SK

tg: zneužíváno tg: zranitelnost

· SK-CERT (NBÚ SR) · VAROVANIE: Útočníci aktívne zneužívajú zraniteľnosti MIKROTIK smerovačov

Risolte vulnerabilità nei chipset MediaTek

Aggiornamenti di sicurezza MediaTek sanano alcune vulnerabilità, di cui 5 con gravità “alta”, nei chipset MediaTek, componenti hardware impiegati in numerosi dispositivi mobili e sistemi embedded. Tali vulnerabilità, qualora sfruttate, potrebbero consentire a un utente malintenzionato di eseguire codice arbitrario o compromettere la disponibilità del servizio sui sistemi interessati.

EPSS 0.00 CVE-2026-20500 CVE-2026-20501 CVE-2026-20502 CVE-2026-20503 CVE-2026-20504 MediaTek IT

tg: zranitelnost

· CSIRT Itálie (ACN) · Risolte vulnerabilità nei chipset MediaTek

Control de acceso incorrecto en PrestaShop

Incorrect access control in PrestaShop Mon, 09/07/2026 - 13:19 Aviso Affected Resources PrestaShop, versions prior to 9.1.5 and 8.2.8, depending on the branch. Description INCIBE has coordinated the publication of a medium-severity vulnerability affecting PrestaShop, a free and open-source content management system designed to build e-commerce online shops from scratch. The vulnerability was discovered by Pedro Gabaldón Juliá.This vulnerability has been assigned the following code, CVSS v4.0…

EPSS 0.00 CVSS 6.9 CVE-2026-84186 PrestaShop ES

tg: zranitelnost

· INCIBE-CERT · Control de acceso incorrecto en PrestaShop

Upozornění na zranitelnost ve firmware RouterOS v zařízeních MikroTik

Upozorňujeme na zranitelnost ve firmware RouterOS v zařízeních MikroTik, kterou lze před autentizací zneužít k vzdálenému spuštění kódu s administrátorskými oprávněními. Aktuálně dochází k masovému zneužití této zranitelnosti. Dne 4. září 2026 byla vydána aktualizace RouterOS, v současnosti jsou však na internetu v ČR stále vystaveny tisíce zranitelných zařízení. Útočníci navíc u napadených zařízení upravují konfiguraci, aby si zajistili trvalý přístup k zařízení, který přežije jakoukoli…

MikroTik CZ

tg: zneužíváno tg: zranitelnost tg: návod

· NÚKIB · Upozornění na zranitelnost ve firmware RouterOS v zařízeních MikroTik

Multiples vulnérabilités dans les produits Juniper Networks (07 septembre 2026)

De multiples vulnérabilités ont été découvertes dans les produits Juniper Networks. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, une élévation de privilèges et un déni de service à distance.

EPSS 0.98 CVE-2013-5211 CVE-2016-9042 CVE-2016-9310 CVE-2017-6451 CVE-2017-6452 CVE-2017-6455 CVE-2017-6458 CVE-2017-6459 CVE-2017-6460 CVE-2017-6462 CVE-2017-6463 CVE-2017-6464 Juniper Networks FR

tg: zranitelnost tp: DDoS

· CERT-FR – avis · Multiples vulnérabilités dans les produits Juniper Networks (07 septembre 2026)

Multiples vulnérabilités dans MongoDB (07 septembre 2026)

De multiples vulnérabilités ont été découvertes dans MongoDB. Certaines d'entre elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, une atteinte à l'intégrité des données et une injection de requêtes illégitimes par rebond (CSRF).

EPSS 0.00 CVE-2026-84962 CVE-2026-84963 CVE-2026-84964 CVE-2026-84965 CVE-2026-84966 CVE-2026-84967 CVE-2026-84968 CVE-2026-84969 CVE-2026-84970 CVE-2026-84971 MongoDB FR

tg: zranitelnost

· CERT-FR – avis · Multiples vulnérabilités dans MongoDB (07 septembre 2026)

Multiples vulnérabilités dans Roundcube Webmail (07 septembre 2026)

De multiples vulnérabilités ont été découvertes dans Roundcube Webmail. Certaines d'entre elles permettent à un attaquant de provoquer une falsification de requêtes côté serveur (SSRF), une injection de code indirecte à distance (XSS) et un contournement de la politique de sécurité.

Roundcube FR

tg: zranitelnost

· CERT-FR – avis · Multiples vulnérabilités dans Roundcube Webmail (07 septembre 2026)

1

Critical MikroTik Vulnerability - Patch Now, (Sun, Sep 6th)

Mikrotik released a patch late last week for an already-exploited vulnerability. The vulnerability allows an SSH authentication bypass and is already being exploited. At this point, assume compromise. Attackers have been adding new accounts to affected devices to maintain access after a patch is installed. The patch will attempt to detect compromise and set the "Flagged" status. Details: https://mikrotik.com/supportsec/september-2026-vulnerability -- Johannes B. Ullrich, Ph.D. , Dean of…

MikroTik US

tg: zneužíváno tg: zranitelnost tp: identita

· SANS Internet Storm Ctr. · Critical MikroTik Vulnerability - Patch Now, (Sun, Sep 6th)

3

Critical vulnerabilities in MikroTik RouterOS are being actively exploited. Immediate update recommended

The CERT Polska team has identified and coordinated the disclosure of six vulnerabilities in MikroTik RouterOS, including two critical ones. The vulnerabilities are already being actively exploited to take over devices whose SSH service is accessible from the internet. We recommend immediately updating devices to the patched versions and verifying the configuration for signs of compromise.

MikroTik PL

tg: zneužíváno tg: zranitelnost

· CERT Polska · Critical vulnerabilities in MikroTik RouterOS are being actively exploited. Immediate update recommended

Google Chrome Stable Channel Update

Classification: Severe, Solution: Official Fix, Exploit Maturity: High, CVSSv3.1: None, CVEs: CVE-2026-85046, CVE-2026-85052, CVE-2026-85043, CVE-2026-85048, CVE-2026-85045, CVE-2026-85050, CVE-2026-85053, CVE-2026-85042, CVE-2026-85049, CVE-2026-85051, CVE-2026-85047, CVE-2026-85044, Summary: The Stable channel has been updated to 152.0.7977.82/.83 for Windows and Mac and 152.0.7977.82 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available…

KEV ✓ EPSS 0.01 CVE-2026-85042 CVE-2026-85043 CVE-2026-85044 CVE-2026-85045 CVE-2026-85046 CVE-2026-85047 CVE-2026-85048 CVE-2026-85049 CVE-2026-85050 CVE-2026-85051 CVE-2026-85052 CVE-2026-85053 Google FI

tg: zneužíváno tg: zranitelnost tg: novinka v produktu

· NCSC-FI · Google Chrome Stable Channel Update

21

SPOJENO PŘES CVE AL26-019 - Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway - CVE-2026-19490 and CVE-2026-19489

Number: AL26-019Date: September 4, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested. Details The Cyber Centre…

KEV ✓ EPSS 0.06 CVSS 9.3 CVE-2026-19489 CVE-2026-19490 Citrix CA IT NL FI FR

tg: zranitelnost tp: identita

· Cyber Centre Kanada · AL26-019 - Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway - CVE-2026-19490 and CVE-2026-19489 · CSIRT Itálie (ACN) · Vulnerabilità in prodotti Citrix · NCSC-NL · NCSC-2026-0318 [1.00] [M/M] Kwetsbaarheden verholpen in Citrix NetScaler ADC en NetScaler Gateway · NCSC-FI · Citrix Netscaler ADC ja Gateway -tuotteissa kriittisiä haavoittuvuuksia · CERT-FR – avis · Multiples vulnérabilités dans les produits Citrix (20 août 2026)

SPOJENO PŘES CVE Dirty Frag (CVE-2026-43284): the Linux kernel bug that turns read access into root

Dirty Frag turns low-privileged Linux access into root, and can escape containers. The affected CVEs, how to check if you're exposed, and how to fix it. Category: Vulnerabilities & Threats

EPSS 0.93 CVE-2026-43284 Linux BE HU

tg: zranitelnost tg: návod

· Aikido Security · Dirty Frag (CVE-2026-43284): the Linux kernel bug that turns read access into root · NKI Maďarsko · Riasztás a Linux rendszereket érintő Dirty Frag sérülékenységről

Aggiornamenti disponibili per TP-Link Archer AX55 v4

Aggiornamenti di sicurezza TP-Link sanano due vulnerabilità, di cui una con gravità "alta", presente in TP-Link Archer AX55 v4. Tale vulnerabilità, qualora sfruttata, potrebbe consentire ad un utente malintenzionato, con accesso alla rete locale e in presenza di specifiche configurazioni, di eseguire codice arbitrario e di compromettere la disponibilità del servizio sui sistemi interessati.

EPSS 0.00 CVE-2026-18167 TP-Link IT

tg: zranitelnost

· CSIRT Itálie (ACN) · Aggiornamenti disponibili per TP-Link Archer AX55 v4

Casdoor authentication server is vulnerable to authorization bypass

Classification: Critical, Solution: Temporary Fix, Exploit Maturity: Not Defined, CVSSv3.1: None, CVEs: CVE-2026-15630, Summary: Casdoor is an open-source Access Management (IAM) platform used to manage web applications. An authorization bypass vulnerability affects Casdoor versions 3.115.0 and earlier. The vulnerability allows a non-global organization administrator to perform unauthorized administrative actions against arbitrary organizations by exploiting inconsistent object resolution…

EPSS 0.00 CVE-2026-15630 Casdoor FI

tg: zranitelnost tp: identita

· NCSC-FI · Casdoor authentication server is vulnerable to authorization bypass

Multiple Vulnerabilities in HPE Aruba Networking ArubaOS-CX (AOS-CX)

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8, CVEs: CVE-2026-73749, CVE-2026-73750, CVE-2026-73751, CVE-2026-73752, CVE-2026-73753, CVE-2026-73782, CVE-2026-73781, CVE-2026-73780, CVE-2026-73779, CVE-2026-73778, CVE-2026-73777, CVE-2026-73776, CVE-2026-73775, CVE-2026-73774, CVE-2026-73773, CVE-2026-73771, CVE-2026-73770, CVE-2026-73768, CVE-2026-73767, CVE-2026-73766 (+14 other associated CVEs), Summary: Potential Security Impact: Local: Access…

CVSS 9.8 HPE FI

tg: zranitelnost

· NCSC-FI · Multiple Vulnerabilities in HPE Aruba Networking ArubaOS-CX (AOS-CX)

Multiples vulnérabilités dans le noyau Linux de Debian (04 septembre 2026)

De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité des données et un déni de service.

EPSS 0.01 CVE-2025-40074 CVE-2026-64216 CVE-2026-64581 CVE-2026-74626 CVE-2026-74653 CVE-2026-74662 CVE-2026-80536 CVE-2026-80557 CVE-2026-80562 CVE-2026-80572 CVE-2026-80583 CVE-2026-80590 CVE-2026-80725 Debian Linux FR

tg: zranitelnost

· CERT-FR – avis · Multiples vulnérabilités dans le noyau Linux de Debian (04 septembre 2026)

Multiples vulnérabilités dans Sonicwall Network Security Manager (04 septembre 2026)

De multiples vulnérabilités ont été découvertes dans Sonicwall Network Security Manager. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un contournement de la politique de sécurité.

EPSS 0.02 CVE-2026-78327 CVE-2026-78328 CVE-2026-81939 SonicWall FR

tg: zranitelnost

· CERT-FR – avis · Multiples vulnérabilités dans Sonicwall Network Security Manager (04 septembre 2026)

Multiples vulnérabilités dans Elastic Kibana (04 septembre 2026)

De multiples vulnérabilités ont été découvertes dans Elastic Kibana. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, un déni de service à distance et une atteinte à la confidentialité des données.

EPSS 0.00 CVE-2026-78583 CVE-2026-78593 CVE-2026-78595 CVE-2026-78596 CVE-2026-82298 CVE-2026-82299 CVE-2026-82302 Elastic FR

tg: zranitelnost tp: DDoS

· CERT-FR – avis · Multiples vulnérabilités dans Elastic Kibana (04 septembre 2026)

8

SUSE Linux security advisory (AV26-882)

Serial Number: AV26-882Date: September 3, 2026 As of September 3, 2026, SUSE is affected by vulnerabilities in the following product: Rancher Prior to 2.15.1 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Release v2.15.1 · rancher/rancher · GitHub SUSE Update Advisories

SUSE CA

tg: zranitelnost

· Cyber Centre Kanada · SUSE Linux security advisory (AV26-882)

[Control Systems] Siemens security advisory (AV26-881)

Serial Number: AV26-881Date: September 3, 2026 As of September 3, 2026, Siemens is affected by a vulnerability in the following products: Mendix SAML (Mendix 10 compatible) Prior to V4.2.3 Mendix SAML (Mendix 11 compatible) Prior to V4.2.3 Mendix SAML (Mendix 9.24 compatible) Prior to V3.6.27 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. SSA-887643: Account Hijacking Vulnerability in Mendix SAML…

Siemens CA

tg: zranitelnost tp: identita

· Cyber Centre Kanada · [Control Systems] Siemens security advisory (AV26-881)

n8n security advisory (AV26-880)

Serial Number: AV26-880Date: September 3, 2026 As of September 3, 2026, n8n is affected by vulnerabilities in the following product: n8n Prior to 1.123.76 Prior to 2.35.4 Prior to 2.36.2 Prior to 2.37.7 Prior to 2.38.2 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. Overview · n8n-io/n8n · GitHub

n8n CA

tg: zranitelnost

· Cyber Centre Kanada · n8n security advisory (AV26-880)

HPE patches critical ArubaOS-CX remote code execution flaw

Hewlett Packard Enterprise (HPE) has patched a critical vulnerability in the ArubaOS-CX network operating system that could lead to remote code execution. [...]

CVE-2026-73749 CVE-2026-73750 CVE-2026-73751 CVE-2026-73752 CVE-2026-73753 CVE-2026-73777 CVE-2026-73778 CVE-2026-73779 CVE-2026-73780 CVE-2026-73781 CVE-2026-73782 zmíněno v článku HPE US

tg: zranitelnost

· BleepingComputer · HPE patches critical ArubaOS-CX remote code execution flaw

AMD security advisory (AV26-879)

Serial Number: AV26-879Date: September 3, 2026 As of September 2, 2026, AMD is affected by vulnerabilities in the following products: 2nd Gen AMD EPYC™ Processors all except RomePI 1.0.0.H 3rd Gen AMD EPYC™ Processors all except MilanPI 1.0.0.C 4th Gen AMD EPYC™ Processors all except GenoaPI 1.0.0.8 AMD Athlon™ 3000 Series Desktop Processors with Radeon™ Graphics all except ComboAM4 1.0.0.B all except ComboAM4v2 1.2.0.B AMD Athlon™ 3000 Series Mobile Processors with Radeon™ Graphics all except…

AMD CA

tg: zranitelnost

· Cyber Centre Kanada · AMD security advisory (AV26-879)

NCSC-2026-0340 [1.00] [M/H] Kwetsbaarheden verholpen in Aruba Networks ArubaOS-CX

Aruba Networks heeft meerdere kwetsbaarheden verholpen in het AOS-CX netwerk besturingssysteem en de bijbehorende componenten, waaronder de command line interface, API endpoints en web-based management interface. De kwetsbaarheden in AOS-CX betreffen onder andere onbevoegde toegang via bypass van authenticatie, remote code execution door onjuiste verwerking van input zoals format strings en command injection, privilege escalatie door onjuiste toegang tot systeemfuncties, en denial-of-service…

Aruba Networks NL

tg: zranitelnost tp: DDoS

· NCSC-NL · NCSC-2026-0340 [1.00] [M/H] Kwetsbaarheden verholpen in Aruba Networks ArubaOS-CX

F5 security advisory (AV26-878)

Serial Number: AV26-878Date: September 3, 2026 As of September 2, 2026, F5 is affected by vulnerabilities in the following products: BIG-IP (all modules) Prior to 17.1.3.4 Prior to 17.5.1.8 Prior to 21.0.0.3 Prior to 21.1.0.1 BIG-IQ Prior to 8.4.2.1 NGINX Gateway Fabric Prior to 2.6.8 NGINX Ingress Controller Prior to 2026-lts-r5 Prior to 5.6.0 NGINX JavaScript 9.9 Prior to 1.0.1 APM Clients Prior to 7.2.6 BIG-IP APM Multiple versions The Cyber Centre encourages users and administrators to…

F5 CA

tg: zranitelnost

· Cyber Centre Kanada · F5 security advisory (AV26-878)