Výsledky hledání

typ: zranitelnost× v celém archivu zrušit filtry

1790 karet z 1920 položek · strana 28 z 30 CZ · EN/orig

Hvězdička u CVE znamená, že radar to číslo vytáhl z textu článku, ne ze seznamu chyb, který zpráva uvádí — u té zprávy proto neukazuje KEV, EPSS ani CVSS.

16

NCSC-2026-0336 [1.00] [M/H] Kwetsbaarheid verholpen in JFrog Artifactory

JFrog heeft een kwetsbaarheid verholpen in JFrog Artifactory. De kwetsbaarheid bevindt zich in de standaardconfiguratie van JFrog Artifactory, waarbij onvoldoende authenticatiecontroles aanwezig zijn. Hierdoor kan een niet-geauthenticeerde aanvaller met netwerktoegang de privileges escaleren naar administratief niveau. Dit kan leiden tot volledige administratieve controle over het systeem.

JFrog NL

tg: zranitelnost tp: identita

· NCSC-NL · NCSC-2026-0336 [1.00] [M/H] Kwetsbaarheid verholpen in JFrog Artifactory

Risolte vulnerabilità in Google Chrome

Google ha rilasciato un aggiornamento per il browser Chrome al fine di correggere 26 nuove vulnerabilità di sicurezza, di cui 2 con gravità “critica” e 9 con gravità “alta”.

EPSS 0.00 CVE-2026-84324 CVE-2026-84325 CVE-2026-84326 CVE-2026-84333 CVE-2026-84349 CVE-2026-84351 CVE-2026-84352 CVE-2026-84353 CVE-2026-84354 CVE-2026-84357 CVE-2026-84359 Google IT

tg: zranitelnost tg: novinka v produktu

· CSIRT Itálie (ACN) · Risolte vulnerabilità in Google Chrome

Risolte vulnerabilità in prodotti Mozilla

Aggiornamenti di sicurezza sanano 11 vulnerabilità di sicurezza, di cui 3 con gravità “critica” e 8 con gravità “alta”, nei prodotti Firefox, Firefox ESR, Thunderbird.

EPSS 0.00 CVE-2026-16365 CVE-2026-75874 CVE-2026-84117 CVE-2026-84119 CVE-2026-84121 CVE-2026-84123 CVE-2026-84143 CVE-2026-84144 CVE-2026-84145 CVE-2026-84639 CVE-2026-84640 Mozilla IT

tg: zranitelnost

· CSIRT Itálie (ACN) · Risolte vulnerabilità in prodotti Mozilla

SPOJENO PŘES CVE SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability (CVE-2026-83548)

CISA added CVE-2026-83548 to the Known Exploited Vulnerabilities catalog. Affected product: SonicWall SMA1000 Appliances. Remediation due date: 2026-09-05.

KEV ✓ EPSS 0.05 CVE-2026-83548 SonicWall US FR

tg: zneužíváno tg: zranitelnost

· CISA KEV · SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability (CVE-2026-83548) · CERT-FR – alerty · Multiples vulnérabilités dans SonicWall Secure Mobile Access (02 septembre 2026)

Multiples vulnérabilités dans Curl (02 septembre 2026)

De multiples vulnérabilités ont été découvertes dans Curl. Certaines d'entre elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, une atteinte à l'intégrité des données et un contournement de la politique de sécurité.

EPSS 0.01 CVE-2026-13608 CVE-2026-18924 CVE-2026-19931 CVE-2026-80229 CVE-2026-80230 CVE-2026-80231 CVE-2026-80255 CVE-2026-82208 CVE-2026-82209 Curl FR

tg: zranitelnost

· CERT-FR – avis · Multiples vulnérabilités dans Curl (02 septembre 2026)

Multiples vulnérabilités dans les produits HPE Aruba Networking (02 septembre 2026)

De multiples vulnérabilités ont été découvertes dans les produits HPE Aruba Networking. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

HPE FR

tg: zranitelnost

· CERT-FR – avis · Multiples vulnérabilités dans les produits HPE Aruba Networking (02 septembre 2026)

26

Rockwell Automation security advisory (AV26-869)

Serial number: AV26-869Date: September 1, 2026 As of September 1, 2026, Rockwell Automation is affected by vulnerabilities in the following products: 1756-ENBT Module All versions ArmorStart LT Prior to or equal to v2.001 CompactLogix 5380 / ControlLogix 5580 Prior to or equal to V33 V34.011 to V34.014 V35.011 to V35.013 V36.011 to V36.012 RSLinx Classic Prior to or equal to V4.50 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary…

Rockwell Automation CA

tg: zranitelnost tp: průmyslové systémy

· Cyber Centre Kanada · Rockwell Automation security advisory (AV26-869)

Mozilla security advisory (AV26-868)

Serial number: AV26-868Date: September 1, 2026 As of September 1, 2026, Mozilla is affected by vulnerabilities in the following products: Firefox ESR Versions prior to 115.40 Versions prior to 140.15 Versions prior to 153.2 Firefox Versions prior to 155 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Security Vulnerabilities fixed in Firefox ESR 115.40 — Mozilla Security Vulnerabilities fixed in…

Mozilla CA

tg: zranitelnost

· Cyber Centre Kanada · Mozilla security advisory (AV26-868)

SPOJENO PŘES CVE WebPros security advisory (AV26-866)

Serial number: AV26-866Date: September 1, 2026 As of September 1, 2026, WebPros is affected by vulnerabilities in the following product: Plesk Prior to 18.0.79.9 Prior to 18.0.80.5 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. CVE-2026-67394: Vulnerability in Plesk allows privilege escalation to root

EPSS 0.01 CVE-2026-67394 WebPros Plesk CA IT

tg: zranitelnost

· Cyber Centre Kanada · WebPros security advisory (AV26-866) · CSIRT Itálie (ACN) · Risolta vulnerabilità in Plesk

NCSC-2026-0335 [1.00] [M/H] Kwetsbaarheden verholpen in WatchGuard Fireware OS

WatchGuard heeft kwetsbaarheden verholpen in WatchGuard Fireware OS, specifiek in het iked-proces en de epm-service van het Mobile Security onderdeel. De kwetsbaarheden bevinden zich in het iked-proces en de epm-service van WatchGuard Fireware OS. Het iked-proces bevat een stack-based buffer overflow, een type confusion kwetsbaarheid en een heap overflow. Deze kwetsbaarheden kunnen worden misbruikt door een ongeauthenticeerde aanvaller door speciaal vervaardigd netwerkverkeer te verzenden. Dit…

WatchGuard NL

tg: zranitelnost

· NCSC-NL · NCSC-2026-0335 [1.00] [M/H] Kwetsbaarheden verholpen in WatchGuard Fireware OS

Rockwell Automation FactoryTalk Activation Manager

View CSAF Summary The following versions of Rockwell Automation FactoryTalk Activation Manager are affected: FactoryTalk Activation Manager V5.02_and_below (CVE-2026-16675) CVSS Vendor Equipment Vulnerabilities v3 7.8 Rockwell Automation Rockwell Automation FactoryTalk Activation Manager Improper Restriction of Excessive Authentication Attempts Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States…

EPSS 0.00 CVSS 7.8 CVE-2026-16675 Rockwell Automation výroba a průmysl US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Rockwell Automation FactoryTalk Activation Manager

Rockwell Automation Redundancy Module Configuration Tool

View CSAF Summary Successful exploitation of these vulnerabilities could allow for an attacker to escalate and execute processes with administrator privileges. The following versions of Rockwell Automation Redundancy Module Configuration Tool are affected: Redundancy Module Configuration Tool 10.00.00 (CVE-2026-9633) Redundancy Module Configuration Tool >=9.00.00|<=10.00.00 (CVE-2026-9634) CVSS Vendor Equipment Vulnerabilities v3 7.3 Rockwell Automation Rockwell Automation Redundancy Module…

EPSS 0.00 CVSS 7.3 CVE-2026-9633 CVE-2026-9634 Rockwell Automation výroba a průmysl US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Rockwell Automation Redundancy Module Configuration Tool

Rockwell Automation Logix Platform

View CSAF Summary The following versions of Rockwell Automation Logix Platform are affected: ControlLogix 5580 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637) CompactLogix 5380 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637) GuardLogix 5580 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637)…

EPSS 0.00 CVSS 7.5 CVE-2026-9637 Rockwell Automation výroba a průmysl US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Rockwell Automation Logix Platform

Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix

View CSAF Summary The following versions of Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix are affected: ControlLogix 5580 <34.015, <35.014, <36.013, <37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260) GuardLogix 5580 <34.015, <35.014, <36.013, <37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260) CompactLogix 5380 <34.015, <35.014, <36.013, <37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE…

EPSS 0.03 CVSS 7.5 CVE-2021-42260 Rockwell Automation výroba a průmysl US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix

Rockwell Automation Historian ME

View CSAF Summary Successful exploitation of these vulnerabilities could crash the device being accessed; an out-of-bounds write condition may allow remote code execution. The following versions of Rockwell Automation Historian ME are affected: Series B 5.202 (CVE-2025-12768, CVE-2026-12661) Series C 7.101 (CVE-2025-12768, CVE-2026-12661) CVSS Vendor Equipment Vulnerabilities v3 8 Rockwell Automation Rockwell Automation Historian ME Out-of-bounds Write, Stack-based Buffer Overflow Background…

EPSS 0.00 CVSS 8.0 CVE-2025-12768 CVE-2026-12661 Rockwell Automation výroba a průmysl zdravotnictví vodárenství US

tg: zranitelnost tp: průmyslové systémy

· CISA Advisories · Rockwell Automation Historian ME

Rockwell Automation RSLinx Classic

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the affected product. The following versions of Rockwell Automation RSLinx Classic are affected: RSLinx Classic <=4.50 (CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625) CVSS Vendor Equipment Vulnerabilities v3 8.6 Rockwell Automation Rockwell Automation RSLinx Classic Integer Overflow or Wraparound, Integer Underflow (Wrap or Wraparound), Buffer Copy…

EPSS 0.00 CVSS 8.6 CVE-2026-9621 CVE-2026-9622 CVE-2026-9624 CVE-2026-9625 Rockwell Automation výroba a průmysl US

tg: zranitelnost tp: DDoS tp: průmyslové systémy

· CISA Advisories · Rockwell Automation RSLinx Classic

Infostealers are hijacking Claude accounts at users’ expense

Anthropic has warned some Claude users that criminals are using information stealers to take over their accounts. Rather than guessing passwords or intercepting two-factor authentication (2FA) codes, the attackers steal the browser sessions that prove a user is already logged in. According to a warning email shared publicly by an affected user, the attackers used common infostealer malware to copy Claude login sessions from victims’ computers. They then used those sessions to access the…

Anthropic US

tg: incident tg: varování tg: zranitelnost tp: malware tp: podvod tp: AI tp: identita

· Malwarebytes Labs · Infostealers are hijacking Claude accounts at users’ expense

SAUTER: modulo 6 and EY-modulo 5 Vulnerability in Firmware update mechanism allowing remote code execution

[VDE-2026-093] A vulnerability has been found in the firmware update process of SAUTER Building Controllers. The identified vulnerability could allow unauthorized code execution on affected controllers.

EPSS 0.00 CVE-2026-78319 SAUTER DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · SAUTER: modulo 6 and EY-modulo 5 Vulnerability in Firmware update mechanism allowing remote code execution

Sanata vulnerabilità in libexpat

Aggiornamenti di sicurezza sanano una vulnerabilità in libexpat, nota libreria scritta in C per l'analisi di documenti XML. Tale vulnerabilità, qualora sfruttata, consentirebbe ad utente malintenzionato di innescare la corruzione della memoria o il crash dell'applicazione, portando alla compromissione della disponibilità del servizio sulle istanze interessate.

EPSS 0.00 CVE-2026-76641 libexpat IT

tg: zranitelnost

· CSIRT Itálie (ACN) · Sanata vulnerabilità in libexpat

Falta de autorización en OpenNebula de OpenNebula Systems

Lack of authorisation in OpenNebula by OpenNebula Systems Tue, 09/01/2026 - 12:12 Aviso Affected Resources OpenNebula 7.4. Description INCIBE has coordinated the publication of a high-severity vulnerability affecting OpenNebula by OpenNebula Systems, a platform for managing virtualised data. The vulnerability was discovered by Yonghwa Lee, Xint from Theori.This vulnerability has been assigned the following code, CVSS v4.0 base score, CVSS vector and CWE vulnerability type:CVE-2026-84165: CVSS…

EPSS 0.00 CVSS 8.7 CVE-2026-84165 OpenNebula Systems ES

tg: zranitelnost

· INCIBE-CERT · Falta de autorización en OpenNebula de OpenNebula Systems

Inyección de código en el Core de Lutece

Code injection in the Lutece Core Tue, 09/01/2026 - 11:44 Aviso Affected Resources Lutece Core: versión 7.1.7 y anteriores. Description INCIBE has coordinated the disclosure of a critical-severity vulnerability in Lutece Core, an open platform that enables local authorities to share, reuse and adapt digital services. The vulnerability was discovered by I Dorian Piette (Trachinus).This vulnerability has been assigned the following code, CVSS v4.0 base score, CVSS vector and CWE vulnerability…

EPSS 0.00 CVSS 9.4 CVE-2026-4813 Lutece veřejná správa ES

tg: zranitelnost

· INCIBE-CERT · Inyección de código en el Core de Lutece

SPOJENO PŘES CVE JetBrains Cadence Compromised via Exploitation of TeamCity Vulnerability (Incident)

Cadence uses JetBrains TeamCity to orchestrate cloud workloads, and the affected server, api.cadence.jetbrains.com, remained vulnerable to CVE-2026-63077 despite having been intended for patching. Threat actors exploited the vulnerability beginning on August 8 to gain unauthor...

KEV ✓ EPSS 0.87 CVSS 9.8 CVE-2026-63077 JetBrains veřejná správa US

tg: incident tg: zneužíváno tg: zranitelnost tg: rozbor

· Wiz Research · JetBrains Cadence Compromised via Exploitation of TeamCity Vulnerability (Incident) · Rapid7 · Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077) · CISA Advisories · CISA Adds One Known Exploited Vulnerability to Catalog · CISA KEV · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability (CVE-2026-63077)

Multiples vulnérabilités dans JFrog Artifactory (01 septembre 2026)

De multiples vulnérabilités ont été découvertes dans JFrog Artifactory. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, une falsification de requêtes côté serveur (SSRF) et un contournement de la politique de sécurité.

KEV ✓ EPSS 0.08 CVE-2026-69104 CVE-2026-70548 CVE-2026-70550 CVE-2026-70551 CVE-2026-82329 JFrog FR

tg: zranitelnost

· CERT-FR – avis · Multiples vulnérabilités dans JFrog Artifactory (01 septembre 2026)

17

WatchGuard security advisory (AV26-865)

Serial Number: AV26-865Date: August 31, 2026 As of August 27, 2026, WatchGuard is affected by vulnerabilities in the following products: Dimension Prior to 2.3.1 Fireware OS Prior to 12.12.2 Prior to 12.5.20 Prior to 2026.2.2 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. WatchGuard Security Advisories

WatchGuard CA

tg: zranitelnost

· Cyber Centre Kanada · WatchGuard security advisory (AV26-865)

[Control Systems] Siemens security advisory (AV26-864)

Serial Number: AV26-864Date: August 31, 2026 As of August 27, 2026, Siemens is affected by a vulnerability in the following products: Element maps-ng V47 Prior to V47.12.3 Element maps-ng V48 Prior to V48.11.3 Element maps-ng V49 Prior to V49.16.1 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. SSA-682041 CERT Services | Siemens

Siemens CA

tg: zranitelnost tp: průmyslové systémy

· Cyber Centre Kanada · [Control Systems] Siemens security advisory (AV26-864)

Dell security advisory (AV26-863)

Serial Number: AV26-863Date: August 31, 2026 As of August 28, 2026, Dell is affected by vulnerabilities in the following products: Dell PowerEdge Server for Intel Processor Firmware Multiple versions and models Dell AppSync Prior to or equal to 4.6.0.4 and 4.6.1.0 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. DSA-2026-356: Security Update for Dell PowerEdge Server for Intel® Processor Firmware…

Dell CA

tg: zranitelnost

· Cyber Centre Kanada · Dell security advisory (AV26-863)

IBM security advisory (AV26-862)

Serial Number: AV26-862Date: August 31, 2026 As of August 28, 2026, IBM is affected by vulnerabilities in the following products: SPSS Collaboration and Deployment Services Multiple versions IBM SPSS Analytic Server Multiple version IBM MQ Agent Multiple versions IBM Maximo Application Suite - Monitor Component Prior to or equal to 9.2, 9.1 and 9.0 IBM Observability with Instana (Agent) Prior to or equal to 1.0.323 IBM Financial Transaction Manager (FTM) for RedHat OpenShift Multiple versions…

IBM CA

tg: zranitelnost

· Cyber Centre Kanada · IBM security advisory (AV26-862)

31th August – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 31st August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Manchester Airports Group, the UK operator of Manchester, London Stansted, and East Midlands airports, has disclosed a cyberattack that exposed data belonging to about 8.7 million customers. The compromised information includes contact details, vehicle registration numbers, and information collected through car park, lounge, fast-track, and Wi-Fi…

KEV ✓ EPSS 0.04 CVSS 10.0 CVE-2026-18885 CVE-2026-18886 CVE-2026-74820 CVE-2026-75604 CVE-2026-81578 CVE-2026-82078 PaperCut Ubiquiti Vercel ServiceNow IL

tg: incident tg: zneužíváno tg: zranitelnost tg: přehled tp: phishing tp: únik dat tp: AI

· Check Point Research · 31th August – Threat Intelligence Report

SPOJENO PŘES CVE CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-81578 PaperCut NG/MF Missing Authentication for Critical Function Vulnerability CVE-2026-82078 PaperCut NG/MF Unsafe Reflection Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates…

KEV ✓ EPSS 0.04 CVSS 9.4 CVE-2026-81578 CVE-2026-82078 PaperCut veřejná správa US IT FI FR

tg: zneužíváno tg: zranitelnost tg: regulace

· CISA Advisories · CISA Adds Two Known Exploited Vulnerabilities to Catalog · CSIRT Itálie (ACN) · PaperCut: rilevato sfruttamento in rete delle CVE-2026-82078 e CVE-2026-81578 · NCSC-FI · URGENT Security Advisory: PaperCut NG/MF Security Bulletin (27 Aug 2026) · CERT-FR – avis · Multiples vulnérabilités dans Papercut (28 août 2026)

SPOJENO PŘES CVE Riasztás a CVE-2026-73570 Zimbra Collaboration Suite szoftvert érintő sérülékenységről

A Nemzetbiztonsági Szakszolgálat Nemzeti Kiberbiztonsági Intézet riasztást ad ki a Zimbra Collaboration Suite (ZCS) szoftvert érintő, CVE-2026-73570 azonosítón nyomon követett kritikus sérülékenység kapcsán. Intézetünkhöz megnövekedett számú bejelentés érkezett a CVE-2026-73570 sérülékenység aktív kihasználásáról. A sebezhetőség kihasználása hitelesítés nélküli támadók számára távoli kódfuttatást tehet lehetővé. A sérülékenység a Zimbra SNMP-monitorozási komponensét érinti, és akkor használható…

KEV ✓ EPSS 0.32 CVE-2026-73570 Zimbra Synacor veřejná správa HU US IT

tg: zneužíváno tg: zranitelnost

· NKI Maďarsko · Riasztás a CVE-2026-73570 Zimbra Collaboration Suite szoftvert érintő sérülékenységről · BleepingComputer · Hackers breached over 270 Zimbra servers in ongoing attacks · CISA Advisories · CISA Adds One Known Exploited Vulnerability to Catalog · CISA KEV · Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability (CVE-2026-73570) · CSIRT Itálie (ACN) · Risolta vulnerabilità su Zimbra Collaboration

Rilevate nuove vulnerabilità in LangFlow

Rilevate 8 nuove vulnerabilità di sicurezza, di cui 2 con gravità “critica” e 4 con gravità “alta”, che interessano il software Langflow, nota piattaforma open-source che permette di costruire, testare e distribuire applicazioni e agenti basati su intelligenza artificiale.

EPSS 0.02 CVE-2026-18729 CVE-2026-18891 CVE-2026-18899 CVE-2026-18904 CVE-2026-19286 CVE-2026-19295 LangFlow IT

tg: zranitelnost tp: AI

· CSIRT Itálie (ACN) · Rilevate nuove vulnerabilità in LangFlow

Rilevata una nuova vulnerabilità in Sudo

Rilevata una vulnerabilità di sicurezza con gravità "alta" in Sudo, nota utility per sistemi operativi Unix-like che permette di delegare i privilegi utente. Tale vulnerabilità, qualora sfruttata, potrebbe consentire ad un utente locale autenticato di eludere i meccanismi di sicurezza e di eseguire programmi non autorizzati sul sistema interessato, ottenendo privilegi superiori rispetto a quelli previsti dalle policy configurate.

EPSS 0.00 CVE-2026-82474 Sudo IT

tg: zranitelnost

· CSIRT Itálie (ACN) · Rilevata una nuova vulnerabilità in Sudo

Aggiornamenti di sicurezza per il linguaggio di programmazione Go

Aggiornamenti di sicurezza sanano sanano una vulnerabilità con gravità “alta” nel linguaggio di programmazione Go. Tale vulnerabilità, qualora sfruttata, potrebbe consentire a utenti malintenzionati di aggirare i meccanismi di autenticazione sui sistemi interessati.

EPSS 0.00 CVE-2026-56854 Go IT

tg: zranitelnost tp: identita

· CSIRT Itálie (ACN) · Aggiornamenti di sicurezza per il linguaggio di programmazione Go

ZDI-26-611: (0Day) pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.

CVSS 7.8 pdfforge US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-611: (0Day) pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vulnerability

ZDI-26-612: (0Day) pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.

CVSS 7.8 pdfforge US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-612: (0Day) pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

ZDI-26-613: (0Day) pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.

CVSS 7.8 pdfforge US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-613: (0Day) pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability

ZDI-26-614: (0Day) pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.

CVSS 7.8 pdfforge US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-614: (0Day) pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

ZDI-26-615: (0Day) pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of pdfforge PDF Architect. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8.

CVSS 7.8 pdfforge US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-615: (0Day) pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

1

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 10.0, CVEs: CVE-2026-76581, CVE-2026-18431, CVE-2026-19632, CVE-2026-19598, CVE-2026-82222, Summary: Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover, and arbitrary code execution. The vulnerabilities, according to Wordfence and Patchstack,…

EPSS 0.03 CVSS 10.0 CVE-2026-18431 CVE-2026-19598 CVE-2026-19632 CVE-2026-76581 CVE-2026-82222 WordPress WPMU DEV Avada TranslatePress FI

tg: zneužíváno tg: zranitelnost tp: dodavatelský řetězec

· NCSC-FI · Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE