Výsledky hledání

typ: zranitelnost× v celém archivu zrušit filtry

1790 karet z 1920 položek · strana 27 z 30 CZ · EN/orig

42

Jenkins security advisory (AV26-877)

Serial Number: AV26-877Date: September 3, 2026 As of September 2, 2026, Jenkins Project is affected by vulnerabilities in the following products: Jenkins ALL except 2.568.3 ALL except 2.580 Jenkins Allure Plugin Prior to or equal to 2.35.2 Jenkins Customizable Header Plugin Prior to or equal to 295.v2544b_ca_19b_97 Jenkins File Parameter Plugin Prior to or equal to 425.v3fa_801681b_5e Jenkins GitLab Plugin Prior to or equal to 1.9.16 Jenkins LDAP Plugin Prior to or equal to 807.809.vd3a…

Jenkins CA

tg: zranitelnost

· Cyber Centre Kanada · Jenkins security advisory (AV26-877)

NCSC-2026-0339 [1.00] [M/H] Kwetsbaarheden verholpen in HPE Networking Fabric Composer

HPE heeft meerdere kwetsbaarheden verholpen in HPE Networking Fabric Composer. De kwetsbaarheden in HPE Networking Fabric Composer betreffen onder andere authenticatiebypasses, privilege-escalaties, remote code execution, command injection, cross-site scripting (XSS), denial-of-service, arbitrary file write, path traversal, en onbevoegde toegang tot gevoelige informatie. Sommige kwetsbaarheden kunnen door ongeauthenticeerde aanvallers op afstand worden misbruikt, terwijl andere exploitatie…

EPSS 0.00 CVE-2026-76658 HPE NL

tg: zranitelnost

· NCSC-NL · NCSC-2026-0339 [1.00] [M/H] Kwetsbaarheden verholpen in HPE Networking Fabric Composer

Cisco security advisory (AV26-876)

Serial Number: AV26-876Date: September 3, 2026 As of September 2, 2026, Cisco is affected by vulnerabilities in the following products: Cisco IOS XR Software Multiple versions Cisco Nexus 9000 Series Switches Multiple products Cisco Desk Phone 9800 Series and Video Phone 8875 Prior to 5.0(1) IP Phone 7800 and 8800 Prior to 14.4(1)SR3 IP Phone 8845 and 8865 Prior to14.4(1)SR4 Wireless IP Phone 8821 Prior to 11.0(6)SR8 The Cyber Centre encourages users and administrators to review the provided…

Cisco CA

tg: zranitelnost

· Cyber Centre Kanada · Cisco security advisory (AV26-876)

Risolta vulnerabilità in Grafana

Rilasciati aggiornamenti di sicurezza per risolvere una vulnerabilità con gravità “alta” presente in prodotti Grafana, nota applicazione web per la visualizzazione e l’analisi interattiva di dati. Tale vulnerabilità, qualora sfruttata, potrebbe consentire ad un utente malintenzionato, in presenza di specifiche condizioni, di eludere i meccanismi di autenticazione sui sistemi interessati.

EPSS 0.00 CVE-2026-14199 Grafana IT

tg: zranitelnost tp: identita

· CSIRT Itálie (ACN) · Risolta vulnerabilità in Grafana

NCSC-2026-0338 [1.00] [M/H] Kwetsbaarheden verholpen in Cisco Nexus 9000 Series, IOS XR Software en Secure Email

Cisco heeft kwetsbaarheden verholpen in Cisco Nexus 9000 Series Switches met Silicon One technologie, Cisco IOS XR Software en Cisco Secure Email. De ernstigste kwetsbaarheid betreft Nexus 9000-switches: als TCP 43210 of 43211 bereikbaar is, kan een aanvaller zonder authenticatie code met rootrechten uitvoeren en de switch laten herstarten. De IOS XR-kwetsbaarheden kunnen, afhankelijk van platform en configuratie, diverse beveiligingsfuncties ondermijnen. De Secure Email-kwetsbaarheden kunnen…

Cisco NL

tg: zranitelnost

· NCSC-NL · NCSC-2026-0338 [1.00] [M/H] Kwetsbaarheden verholpen in Cisco Nexus 9000 Series, IOS XR Software en Secure Email

Pyramid Solutions NetStaX EtherNet/IP Stack

View CSAF Summary Successful exploitation of this vulnerability could result in memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed. The following versions of Pyramid Solutions NetStaX EtherNet/IP Stack are affected: EtherNet/IP Adapter DLL Kit (EIPA) EtherNet/IP Adapter DLL Kit with CIP Security (EIPA-SECURE) EtherNet/IP Adapter Development Kit (EADK) EtherNet/IP Adapter…

EPSS 0.00 CVSS 9.8 CVE-2026-78012 Pyramid Solutions výroba a průmysl energetika vodárenství US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Pyramid Solutions NetStaX EtherNet/IP Stack

IXON VPN Client

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to perform remote code execution on the computer running the client with elevated privileges. The following versions of IXON VPN Client are affected: VPN Client <1.4.7 (CVE-2026-75925) CVSS Vendor Equipment Vulnerabilities v3 9.6 IXON IXON VPN Client Improper Neutralization of CRLF Sequences ('CRLF Injection') Background Critical Infrastructure Sectors: Commercial Facilities, Critical Manufacturing, Energy,…

EPSS 0.01 CVSS 9.6 CVE-2026-75925 IXON energetika výroba a průmysl vodárenství US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · IXON VPN Client

Rockwell Automation ArmorStart LT

View CSAF Summary Successful exploitation of these vulnerabilities could result in a loss of webserver availability or allow an attacker to inject malicious scripts that will be executed when other users access the affected page. The following versions of Rockwell Automation ArmorStart LT are affected: ArmorStart LT <=v2.001 (CVE-2026-19471, CVE-2026-19472) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation ArmorStart LT Improper Neutralization of Input During…

EPSS 0.00 CVSS 7.5 CVE-2026-19471 CVE-2026-19472 Rockwell Automation výroba a průmysl US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Rockwell Automation ArmorStart LT

Rockwell Automation ControlFLASH

View CSAF Summary Successful exploitation of this vulnerability could give an attacker the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level. The following versions of Rockwell Automation ControlFLASH are affected: ControlFLASH <=V15.07 (CVE-2026-12663) CVSS Vendor Equipment Vulnerabilities v3 7.3 Rockwell Automation Rockwell Automation ControlFLASH Missing Authentication for Critical Function Background Critical…

EPSS 0.00 CVSS 7.3 CVE-2026-12663 Rockwell Automation výroba a průmysl energetika vodárenství US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Rockwell Automation ControlFLASH

Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products (Update A)

View CSAF Summary Schneider Electric is aware of a vulnerability in the following products: The Easergy C5 is a scalable and interoperable bay controller, protection and merging unit for large and critical infrastructure electrical distribution systems. The Easergy MiCOM P30 is a family of multifunction protection and control relays designed for medium, high and extra high voltage electrical networks. The Easergy MiCOM P40 is a protection relay series for Medium Voltage, High Voltage and Extra…

EPSS 0.00 CVSS 8.3 CVE-2026-4827 Schneider Electric energetika vodárenství výroba a průmysl US

tg: zranitelnost tp: identita tp: průmyslové systémy

· CISA Advisories · Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products (Update A)

Tycon Systems TPDIN-Monitor-WEB3

View CSAF Summary Successful exploitation of these vulnerabilities could allow for an attacker to perform a man-in-the-middle (MitM) attack, cause a factory reset, wipe credentials, or retrieve sensitive information. The following versions of Tycon Systems TPDIN-Monitor-WEB3 are affected: TPDIN-Monitor-WEB3 <=2.2.9 (CVE-2026-77847, CVE-2026-82712, CVE-2026-82684) CVSS Vendor Equipment Vulnerabilities v3 8.8 Tycon Systems Tycon Systems TPDIN-Monitor-WEB3 Use of Hard-coded Credentials, Cross-Site…

EPSS 0.00 CVSS 8.8 CVE-2026-77847 CVE-2026-82684 CVE-2026-82712 Tycon Systems výroba a průmysl energetika US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Tycon Systems TPDIN-Monitor-WEB3

OPCFoundation OPC UA LocalDiscoveryServer (LDS)

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to take control of a high-privilege terminal during installation and run arbitrary commands. The following versions of OPCFoundation OPC UA LocalDiscoveryServer (LDS) are affected: UA-LDS-Installers <1.04.420 (CVE-2026-77477) CVSS Vendor Equipment Vulnerabilities v3 4.6 OPCFoundation OPCFoundation OPC UA LocalDiscoveryServer (LDS) Execution with Unnecessary Privileges Background Critical Infrastructure…

CVSS 4.6 CVE-2026-77477 OPC Foundation energetika vodárenství výroba a průmysl US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · OPCFoundation OPC UA LocalDiscoveryServer (LDS)

Inductive Automation Ignition

View CSAF Summary Successful exploitation of this vulnerability could allow any authenticated user to create projects. The following versions of Inductive Automation Ignition are affected: Ignition <=8.1.53 (CVE-2026-77393) CVSS Vendor Equipment Vulnerabilities v3 8.8 Inductive Automation Inductive Automation Ignition Incorrect Default Permissions Background Critical Infrastructure Sectors: Critical Manufacturing, Energy, Information Technology Countries/Areas Deployed: Worldwide Company…

EPSS 0.01 CVSS 8.8 CVE-2026-77393 Inductive Automation výroba a průmysl energetika US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Inductive Automation Ignition

Tycon Systems TPDIN-Monitor-WEB2 (Update A)

View CSAF Summary Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk. The following versions of Tycon Systems TPDIN-Monitor-WEB2 (Update A) are affected: TPDIN-Monitor-WEB2 <2.4.5 (CVE-2026-61884, CVE-2026-55985) CVSS Vendor Equipment Vulnerabilities v3 9.8 Tycon Systems Tycon Systems TPDIN-Monitor-WEB2 Missing…

EPSS 0.00 CVSS 9.8 CVE-2026-55985 CVE-2026-61884 Tycon Systems výroba a průmysl US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Tycon Systems TPDIN-Monitor-WEB2 (Update A)

Rockwell Automation 1756-ENBT Module

View CSAF Summary Successful exploitation of this vulnerability could crash the module. The device requires a restart to recover. The following versions of Rockwell Automation 1756-ENBT Module are affected: 1756-ENBT module vers:all/* (CVE-2025-10478) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation 1756-ENBT Module Improper Check for Unusual or Exceptional Conditions Background Critical Infrastructure Sectors: Critical Manufacturing, Food and Agriculture,…

CVSS 7.5 CVE-2025-10478 Rockwell Automation výroba a průmysl doprava vodárenství US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Rockwell Automation 1756-ENBT Module

RIASZTÁS Magyarország Ügyészségének nevével visszaélő ransomware támadásokkal kapcsolatban

A Nemzetbiztonsági Szakszolgálat Nemzeti Kiberbiztonsági Intézet (NBSZ NKI) riasztást ad ki Magyarország Ügyészségének nevével és arculati elemeivel visszaélő, zsarolóvírus fertőzéshez vezető adathalász üzenetekről. A bejelentések alapján a támadók hamis, hivatalos megkeresés látszatát keltő leveleket küldenek, amelyekben ügyészségi alkalmazottak nevével élnek vissza. A kampány célja az, hogy a felhasználó a levélben szereplő hivatkozásra kattintson, majd a […]

veřejná správa HU

tg: varování tg: zranitelnost tp: malware tp: phishing tp: ransomware

· NKI Maďarsko · RIASZTÁS Magyarország Ügyészségének nevével visszaélő ransomware támadásokkal kapcsolatban

SPOJENO PŘES CVE Risolte vulnerabilità in prodotti Cisco

Cisco ha rilasciato aggiornamenti di sicurezza che risolvono 9 vulnerabilità, di cui 3 con gravità "critica" e 6 con gravità “alta”, che interessano diversi prodotti.

EPSS 0.01 CVE-2026-20212 CVE-2026-20274 CVE-2026-20275 CVE-2026-20276 CVE-2026-20277 CVE-2026-20278 CVE-2026-20279 CVE-2026-20280 CVE-2026-20281 Cisco IT FR

tg: zranitelnost

· CSIRT Itálie (ACN) · Risolte vulnerabilità in prodotti Cisco · CERT-FR – avis · Multiples vulnérabilités dans les produits Cisco (03 septembre 2026)

Múltiples vulnerabilidades en Ocsreports de OCS Inventory NG

Multiple vulnerabilities in Ocsreports for OCS Inventory NG Fri, 08/28/2026 - 12:18 Aviso Affected Resources Ocsreports 2.12.4. Description INCIBE has coordinated the publication of 5 vulnerabilities: 1 of critical severity and 4 of high severity, affecting Ocsreports in OCS Inventory NG, an open-source solution for the management and inventory of hardware and software assets within an IT infrastructure. The vulnerabilities were discovered by Marc Monfort Muñoz.These vulnerabilities have been…

EPSS 0.00 CVSS 9.4 CVE-2026-76174 CVE-2026-76175 CVE-2026-76176 CVE-2026-76177 CVE-2026-76178 OCS Inventory NG ES

tg: zranitelnost

· INCIBE-CERT · Múltiples vulnerabilidades en Ocsreports de OCS Inventory NG

SPOJENO PŘES CVE SonicWall SMA1000 Series Appliances Affected By Multiple Vulnerabilities 10

Classification: Critical, Solution: Official Fix, Exploit Maturity: High, CVSSv3.0: 10.0, CVEs: CVE-2026-83548, CVE-2026-83549, Summary: 1) CVE-2026-83548 - Pre-authentication SSRF via unintended forward-proxy A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform…

KEV ✓ EPSS 0.09 CVSS 10.0 CVE-2026-83548 CVE-2026-83549 SonicWall FI US CA IT AT FR

tg: zneužíváno tg: zranitelnost

· NCSC-FI · SonicWall SMA1000 Series Appliances Affected By Multiple Vulnerabilities 10 · Rapid7 · Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild · Cyber Centre Kanada · SonicWall security advisory (AV26-872) · CSIRT Itálie (ACN) · SonicWall: rilevato sfruttamento in rete delle CVE-2026-83548 e CVE-2026-83549 · CERT.at · Kritische Sicherheitslücken in SonicWall SMA1000 Series - aktiv ausgenutzt - Updates verfügbar · CERT-FR – avis · Multiples vulnérabilités dans les produits SonicWall (02 septembre 2026)

Google Chrome Stable Channel Update for Desktop

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: None, CVEs: CVE-2026-84353, CVE-2026-84352, CVE-2026-84354, CVE-2026-84359, CVE-2026-84357, CVE-2026-84324, CVE-2026-84349, CVE-2026-84326, CVE-2026-84333, CVE-2026-84351, CVE-2026-84325, CVE-2026-84328, CVE-2026-84347, CVE-2026-84323, CVE-2026-84355, CVE-2026-84358, CVE-2026-84332, CVE-2026-84330, CVE-2026-84334, CVE-2026-84348 (+6 other associated CVEs), Summary: The Stable channel has been updated to…

Google FI

tg: zranitelnost tg: novinka v produktu

· NCSC-FI · Google Chrome Stable Channel Update for Desktop

Haavoittuvuuksia Rockwell Automation -tuotteissa

Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.0: 8.6, CVEs: CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625, CVE-2026-9633, CVE-2026-9634, CVE-2026-9637, CVE-2026-16675, Summary: Rockwell Automation FactoryTalk Activation Manager Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the affected product. The following versions of Rockwell Automation RSLinx Classic are affected: RSLinx…

EPSS 0.00 CVSS 8.6 CVE-2026-16675 CVE-2026-9621 CVE-2026-9622 CVE-2026-9624 CVE-2026-9625 CVE-2026-9633 CVE-2026-9634 CVE-2026-9637 Rockwell Automation FI

tg: zranitelnost tp: průmyslové systémy

· NCSC-FI · Haavoittuvuuksia Rockwell Automation -tuotteissa

Hugging Face Transformers library writes remote code to disk prior to consent check

Classification: Critical, Solution: Unavailable, Exploit Maturity: Not Defined, CVSSv3.1: None, CVEs: CVE-2026-80047, Summary: A vulnerability in the Hugging Face Transformers library (versions 4.49.0 through 5.8.1) allows remote, attacker‑controlled Python files to be written to the local disk without user authorization. The library performs a remote module fetch and local cache write before evaluating the trust_remote_code consent prompt, violating the security contract enforced across other…

EPSS 0.00 CVE-2026-80047 Hugging Face FI

tg: zranitelnost tp: AI

· NCSC-FI · Hugging Face Transformers library writes remote code to disk prior to consent check

Multiple vulnerabilities in SOY series

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8, CVEs: CVE-2026-73827, CVE-2026-77838, CVE-2026-78238, CVE-2026-78032, Summary: SOY series provided by Tsuyoshi Saito contain multiple vulnerabilities listed below. Cross-site Scripting (CWE-79) - CVE-2026-73827, CVE-2026-77838, CVE-2026-78238 Deserialization of Untrusted Data (CWE-502) - CVE-2026-78032 An arbitrary script may be executed on the web browser of the user who is logging in to the product…

EPSS 0.00 CVSS 9.8 CVE-2026-73827 CVE-2026-77838 CVE-2026-78032 CVE-2026-78238 Tsuyoshi Saito FI

tg: zranitelnost

· NCSC-FI · Multiple vulnerabilities in SOY series

SPOJENO PŘES CVE Cisco Secure Email Secure/Multipurpose Internet Mail Extensions Ciphertext Decryption Vulnerabilities

Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 5.9, CVEs: CVE-2026-20354, CVE-2026-20355, Summary: Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to insufficient validation of message integrity. An attacker could exploit these…

EPSS 0.00 CVSS 5.9 CVE-2026-20354 CVE-2026-20355 Cisco FI US

tg: zranitelnost

· NCSC-FI · Cisco Secure Email Secure/Multipurpose Internet Mail Extensions Ciphertext Decryption Vulnerabilities · Cisco PSIRT · Cisco Secure Email Secure/Multipurpose Internet Mail Extensions Ciphertext Decryption Vulnerabilities

SPOJENO PŘES CVE Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Denial of Service Vulnerability

Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 7.5, CVEs: CVE-2026-20281, Summary: A vulnerability in Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 that are running Cisco Session Initiation Protocol (SIP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper memory management when an affected…

EPSS 0.00 CVSS 7.5 CVE-2026-20281 Cisco FI US

tg: zranitelnost tp: DDoS

· NCSC-FI · Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Denial of Service Vulnerability · Cisco PSIRT · Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Denial of Service Vulnerability

SPOJENO PŘES CVE Cisco IOS XR Software Security Hardening Release: September 2026

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8, CVEs: CVE-2026-20274, CVE-2026-20275, CVE-2026-20276, CVE-2026-20277, CVE-2026-20278, CVE-2026-20279, CVE-2026-20280, Summary: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered…

EPSS 0.01 CVSS 9.8 CVE-2026-20274 CVE-2026-20275 CVE-2026-20276 CVE-2026-20277 CVE-2026-20278 CVE-2026-20279 CVE-2026-20280 Cisco FI US

tg: zranitelnost tg: novinka v produktu

· NCSC-FI · Cisco IOS XR Software Security Hardening Release: September 2026 · Cisco PSIRT · Cisco IOS XR Software Security Hardening Release: September 2026

SPOJENO PŘES CVE Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8, CVEs: CVE-2026-20212, Summary: A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privileges. This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF). A successful exploit could allow the attacker to connect to…

EPSS 0.01 CVSS 9.8 CVE-2026-20212 Cisco FI US

tg: zranitelnost

· NCSC-FI · Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability · Cisco PSIRT · Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability

Multiples vulnérabilités dans les produits F5 (03 septembre 2026)

De multiples vulnérabilités ont été découvertes dans les produits F5. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

EPSS 0.01 CVE-2026-18329 CVE-2026-33278 CVE-2026-42959 CVE-2026-63020 CVE-2026-66362 CVE-2026-66842 CVE-2026-77180 CVE-2026-78222 CVE-2026-78689 F5 FR

tg: zranitelnost

· CERT-FR – avis · Multiples vulnérabilités dans les produits F5 (03 septembre 2026)

18

SPOJENO PŘES CVE Hackers exploit Sangoma Switchvox flaw to deploy reverse shells

Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead to remote code execution. [...]

KEV ✓ EPSS 0.12 CVE-2026-9586 Sangoma telekomunikace US

tg: zneužíváno tg: zranitelnost

· BleepingComputer · Hackers exploit Sangoma Switchvox flaw to deploy reverse shells · CISA KEV · Sangoma Switchvox SQL Injection Vulnerability (CVE-2026-9586)

SPOJENO PŘES CVE Hackers exploit critical JFrog Artifactory flaw to forge admin tokens

A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being exploited in attacks to create tokens that provide administrative access. [...]

KEV ✓ EPSS 0.08 CVE-2026-82329 JFrog US CA

tg: zneužíváno tg: zranitelnost tp: identita

· BleepingComputer · Hackers exploit critical JFrog Artifactory flaw to forge admin tokens · CISA KEV · JFrog Artifactory Improper Authentication Vulnerability (CVE-2026-82329) · Cyber Centre Kanada · JFrog security advisory (AV26-867)

Progress Software security advisory (AV26-875)

Serial number: AV26-875Date: September 2, 2026 As of September 2, 2026, Progress Software is affected by vulnerabilities in the following product: Telerik UI for ASP.NET AJAX Prior to 2026.3.812 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Telerik Web Forms RadImageEditor Path Traversal Vulnerability (CVE-2026-18672) Telerik Web Forms DialogHandler UploadPaths Tampering Vulnerability (CVE-2026…

EPSS 0.00 CVE-2026-18672 CVE-2026-19219 Progress Software CA

tg: zranitelnost

· Cyber Centre Kanada · Progress Software security advisory (AV26-875)

Google security advisory (AV26-874)

Serial number: AV26-874Date: September 2, 2026 As of September 2, 2026, Google is affected by vulnerabilities in the following product: Chrome Prior to 152.0.7977.75 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. Stable Channel Update for Desktop

Google CA

tg: zranitelnost

· Cyber Centre Kanada · Google security advisory (AV26-874)

HPE security advisory (AV26-873)

Serial number: AV26-873Date: September 2, 2026 As of September 1, 2026, Hewlett Packard Enterprise (HPE) is affected by vulnerabilities in the following products: HPE Networking AOS-CX Prior to or equal to 10.10.1180 Prior to or equal to 10.13.1180 Prior to or equal to 10.16.1051 Prior to or equal to 10.17.1021 Prior to or equal to 10.18.0001 HPE Networking Fabric Composer Prior to or equal to 7.3.3 The Cyber Centre encourages users and administrators to review the provided web links and apply…

HPE CA

tg: zranitelnost

· Cyber Centre Kanada · HPE security advisory (AV26-873)

Risolte vulnerabilità in prodotti Zohocorp ManageEngine

Aggiornamenti di sicurezza Zohocorp sanano una vulnerabilità con gravità "alta" presente nei prodotti ManageEngine Password Manager Pro, PAM360 e Access Manager Plus. Tale vulnerabilità, qualora sfruttata, potrebbe consentire ad un utente malintenzionato autenticato di eludere i meccanismi di sicurezza sui sistemi interessati.

EPSS 0.01 CVE-2026-14828 Zoho IT

tg: zranitelnost

· CSIRT Itálie (ACN) · Risolte vulnerabilità in prodotti Zohocorp ManageEngine

[Control systems] Schneider Electric security advisory (AV26-871)

Serial Number: AV26-871Date: September 2, 2026 As of September 1, 2026, Schneider Electric is affected by vulnerabilities in the following products: NetBotz 5 - 750/755 Versions prior to or equal to 5.5.2 PowerChute Serial Shutdown Versions prior to or equal to 1.5 The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates. Multiple Vulnerabilities on NetBotz 5 - 750/755 Products Improper Restriction…

Schneider Electric CA

tg: zranitelnost tp: identita tp: průmyslové systémy

· Cyber Centre Kanada · [Control systems] Schneider Electric security advisory (AV26-871)

iba: Deserialization vulnerability in ibaPDA and ibaDatCoordinator

[VDE-2026-051] A vulnerability has been identified in ibaPDA, ibaDatCoordinator and ibaLogic. The affected applications do not properly restrict the .NET BinaryFormatter when deserializing client-server input. This could allow an attacker to cause a type confusion and execute arbitrary code within the affected applications. This is the same issue that exists for the .NET BinaryFormatter: https://docs.microsoft.com/en-us/visualstudio/code-quality/ca2300.

EPSS 0.01 CVE-2026-8024 iba DE

tg: zranitelnost

· CERT@VDE · iba: Deserialization vulnerability in ibaPDA and ibaDatCoordinator

CISA Adds Seven Known Exploited Vulnerabilities to Catalog

CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-9586 Sangoma Switchvox SQL Injection Vulnerability CVE-2026-48710 Kludex Starlette HTTP Request/Response Smuggling Vulnerability CVE-2026-49869 Kestra OSS OS Command Injection Vulnerability CVE-2026-59822 BerriAI LiteLLM Improper Authentication Vulnerability CVE-2026-82329 JFrog Artifactory Improper Authentication Vulnerability CVE-2026-83548…

KEV ✓ EPSS 0.36 CVE-2026-48710 CVE-2026-49869 CVE-2026-59822 CVE-2026-82329 CVE-2026-83548 CVE-2026-83549 CVE-2026-9586 Sangoma JFrog SonicWall BerriAI veřejná správa US

tg: zneužíváno tg: zranitelnost

· CISA Advisories · CISA Adds Seven Known Exploited Vulnerabilities to Catalog

SPOJENO PŘES CVE Závažná zranitelnost ohrožuje téměř 22 000 Microsoft Exchange serverů

Microsoft 11. srpna 2026 vydal opravu zranitelnosti CVE-2026-62911 (CVSS 8,0), přesto téměř 22 000 veřejně dostupných Exchange serverů zůstává zranitelných. V Česku Shadowserver eviduje přibližně 300 unikátních IP adres Exchange serverů, které vyhodnocuje jako zranitelné (na jednu či více zranitelností). Zranitelnost postihuje Exchange Server 2016, 2019 a Subscription Edition a může vést až k převzetí uživatelských e-mailových schránek. Exploit je již veřejně dostupný. Verze 2016 a 2019 jsou…

EPSS 0.01 CVSS 8.8 CVE-2026-62911 Microsoft finance veřejná správa CZ NL US

tg: zneužíváno tg: zranitelnost tp: identita

· CSIRT.CZ (CZ.NIC) · Závažná zranitelnost ohrožuje téměř 22 000 Microsoft Exchange serverů · NCSC-NL · NCSC-2026-0289 [1.01] [H/H] Kwetsbaarheden verholpen in Microsoft Exchange server · Microsoft Security · CVE-2026-62911 Microsoft Exchange Server Elevation of Privilege Vulnerability · Zero Day Initiative · ZDI-26-534: (Pwn2Own) Microsoft Exchange Capture-Replay Authentication Bypass Vulnerability

Two critical Chrome flaws put users at risk on malicious websites

Chrome is rolling out an update for its desktop browser. The update includes 26 security fixes, two of which Google rates as critical use-after-free vulnerabilities. The Stable channel has been updated to 152.0.7977.75/.76 for Windows and Mac, and 152.0.7977.75 for Linux. How to update Chrome If you don’t want to wait for the rollout to reach you, manually updating is easy. The easiest option is to allow Chrome to update automatically. But you can end up lagging behind if you never close your…

EPSS 0.00 CVE-2026-84352 CVE-2026-84353 Google US

tg: zranitelnost tg: propagace

· Malwarebytes Labs · Two critical Chrome flaws put users at risk on malicious websites

Rilevate vulnerabilità in Erlang/OTP

Rilevate molteplici vulnerabilità di sicurezza, di cui 11 con gravità "alta", in diversi componenti di Erlang/OTP, piattaforma open source basata sul linguaggio Erlang e sul relativo set di librerie OTP, utilizzata per lo sviluppo di sistemi distribuiti ad alta disponibilità.

EPSS 0.01 CVE-2026-55951 CVE-2026-66357 CVE-2026-66835 CVE-2026-69664 CVE-2026-70399 CVE-2026-71380 CVE-2026-73270 CVE-2026-73276 CVE-2026-73812 CVE-2026-74835 CVE-2026-75538 Erlang IT

tg: zranitelnost

· CSIRT Itálie (ACN) · Rilevate vulnerabilità in Erlang/OTP

NCSC-2026-0337 [1.00] [H/H] Zero-Day kwetsbaarheden verholpen in SMA1000 Appliance van SonicWall

SonicWall heeft kwetsbaarheden verholpen in de SMA1000 Appliance. De SMA1000 Appliance bevat twee kwetsbaarheden. De eerste is een pre-authenticatie Server-Side Request Forgery (SSRF) in de Work Place interface, waarmee een externe, niet-geauthenticeerde aanvaller ongeautoriseerde acties kan uitvoeren. De tweede kwetsbaarheid betreft post-authenticatie remote code execution, waarbij een aanvaller met geldige inloggegevens willekeurige code op afstand kan uitvoeren. Beide kwetsbaarheden zijn als…

SonicWall NL

tg: zneužíváno tg: zranitelnost

· NCSC-NL · NCSC-2026-0337 [1.00] [H/H] Zero-Day kwetsbaarheden verholpen in SMA1000 Appliance van SonicWall

Aggiornamenti di sicurezza Dell Technologies

Dell Technologies ha rilasciato aggiornamenti di sicurezza per risolvere 17 vulnerabilità, di cui 3 con gravità "critica" e 13 con gravità "alta", presenti in Dell PowerStore.

EPSS 0.01 CVE-2026-58566 CVE-2026-58567 CVE-2026-58569 CVE-2026-58571 CVE-2026-58572 CVE-2026-58574 CVE-2026-58575 CVE-2026-67262 CVE-2026-67271 CVE-2026-70415 CVE-2026-76111 CVE-2026-79682 CVE-2026-79683 CVE-2026-79684 CVE-2026-79686 CVE-2026-79687 Dell Technologies IT

tg: zranitelnost

· CSIRT Itálie (ACN) · Aggiornamenti di sicurezza Dell Technologies