Risolte vulnerabilità su GitHub Enterprise Server
Rilasciati aggiornamenti di sicurezza che risolvono 4 nuove vulnerabilità, di cui 3 con gravità “alta”, in GitHub Enterprise Server.
EPSS 0.01 CVE-2026-18730 CVE-2026-19118 CVE-2026-76851 GitHub IT
Hvězdička u CVE znamená, že radar to číslo vytáhl z textu článku, ne ze seznamu chyb, který zpráva uvádí — u té zprávy proto neukazuje KEV, EPSS ani CVSS.
Rilasciati aggiornamenti di sicurezza che risolvono 4 nuove vulnerabilità, di cui 3 con gravità “alta”, in GitHub Enterprise Server.
EPSS 0.01 CVE-2026-18730 CVE-2026-19118 CVE-2026-76851 GitHub IT
JFrog heeft een kwetsbaarheid verholpen in JFrog Artifactory. De kwetsbaarheid bevindt zich in de standaardconfiguratie van JFrog Artifactory, waarbij onvoldoende authenticatiecontroles aanwezig zijn. Hierdoor kan een niet-geauthenticeerde aanvaller met netwerktoegang de privileges escaleren naar administratief niveau. Dit kan leiden tot volledige administratieve controle over het systeem.
JFrog NL
Google ha rilasciato un aggiornamento per il browser Chrome al fine di correggere 26 nuove vulnerabilità di sicurezza, di cui 2 con gravità “critica” e 9 con gravità “alta”.
EPSS 0.00 CVE-2026-84324 CVE-2026-84325 CVE-2026-84326 CVE-2026-84333 CVE-2026-84349 CVE-2026-84351 CVE-2026-84352 CVE-2026-84353 CVE-2026-84354 CVE-2026-84357 CVE-2026-84359 Google IT
Rilevate nuove vulnerabilità di cui cinque con gravità “alta” in vari prodotti Rockwell Automation.
EPSS 0.00 CVE-2025-12768 CVE-2026-12661 CVE-2026-16675 CVE-2026-9633 CVE-2026-9634 CVE-2026-9637 Rockwell Automation IT
Aggiornamenti di sicurezza sanano 11 vulnerabilità di sicurezza, di cui 3 con gravità “critica” e 8 con gravità “alta”, nei prodotti Firefox, Firefox ESR, Thunderbird.
EPSS 0.00 CVE-2026-16365 CVE-2026-75874 CVE-2026-84117 CVE-2026-84119 CVE-2026-84121 CVE-2026-84123 CVE-2026-84143 CVE-2026-84144 CVE-2026-84145 CVE-2026-84639 CVE-2026-84640 Mozilla IT
SonicWall warned customers that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks. [...]
CVE-2025-40602 * CVE-2026-15409 * CVE-2026-15410 * CVE-2026-83548 * CVE-2026-83549 * SonicWall US
CISA added CVE-2026-83549 to the Known Exploited Vulnerabilities catalog. Affected product: SonicWall SMA1000 Appliances. Remediation due date: 2026-09-05.
KEV ✓ EPSS 0.09 CVE-2026-83549 SonicWall US
CISA added CVE-2026-83548 to the Known Exploited Vulnerabilities catalog. Affected product: SonicWall SMA1000 Appliances. Remediation due date: 2026-09-05.
KEV ✓ EPSS 0.05 CVE-2026-83548 SonicWall US FR
CISA added CVE-2026-49869 to the Known Exploited Vulnerabilities catalog. Affected product: Kestra Kestra OSS. Remediation due date: 2026-09-05.
KEV ✓ EPSS 0.02 CVE-2026-49869 Kestra US
CISA added CVE-2026-48710 to the Known Exploited Vulnerabilities catalog. Affected product: Kludex Starlette. Remediation due date: 2026-09-16.
KEV ✓ EPSS 0.36 CVE-2026-48710 Kludex US
Categories: Threat ResearchTags: advisory, vulnerability, SonicWall
SonicWall GB
De multiples vulnérabilités ont été découvertes dans Curl. Certaines d'entre elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, une atteinte à l'intégrité des données et un contournement de la politique de sécurité.
EPSS 0.01 CVE-2026-13608 CVE-2026-18924 CVE-2026-19931 CVE-2026-80229 CVE-2026-80230 CVE-2026-80231 CVE-2026-80255 CVE-2026-82208 CVE-2026-82209 Curl FR
De multiples vulnérabilités ont été découvertes dans les produits Elastic. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et une atteinte à la confidentialité des données.
Elastic FR
De multiples vulnérabilités ont été découvertes dans les produits Mozilla. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité des données et un contournement de la politique de sécurité.
Mozilla FR
De multiples vulnérabilités ont été découvertes dans Google Chrome. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.
Google FR
De multiples vulnérabilités ont été découvertes dans les produits HPE Aruba Networking. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
HPE FR
Serial number: AV26-870Date: September 1, 2026 As of September 1, 2026, Erlang is affected by vulnerabilities in the following product: OTP - Multiple versions The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates. Erlang Security Advisories
Erlang CA
Serial number: AV26-869Date: September 1, 2026 As of September 1, 2026, Rockwell Automation is affected by vulnerabilities in the following products: 1756-ENBT Module All versions ArmorStart LT Prior to or equal to v2.001 CompactLogix 5380 / ControlLogix 5580 Prior to or equal to V33 V34.011 to V34.014 V35.011 to V35.013 V36.011 to V36.012 RSLinx Classic Prior to or equal to V4.50 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary…
Serial number: AV26-868Date: September 1, 2026 As of September 1, 2026, Mozilla is affected by vulnerabilities in the following products: Firefox ESR Versions prior to 115.40 Versions prior to 140.15 Versions prior to 153.2 Firefox Versions prior to 155 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Security Vulnerabilities fixed in Firefox ESR 115.40 — Mozilla Security Vulnerabilities fixed in…
Mozilla CA
Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for building AI applications, to steal credentials, tokens, and keys. [...]
EPSS 0.08 CVE-2026-0768 Langflow US
Serial number: AV26-866Date: September 1, 2026 As of September 1, 2026, WebPros is affected by vulnerabilities in the following product: Plesk Prior to 18.0.79.9 Prior to 18.0.80.5 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. CVE-2026-67394: Vulnerability in Plesk allows privilege escalation to root
EPSS 0.01 CVE-2026-67394 WebPros Plesk CA IT
WatchGuard heeft kwetsbaarheden verholpen in WatchGuard Fireware OS, specifiek in het iked-proces en de epm-service van het Mobile Security onderdeel. De kwetsbaarheden bevinden zich in het iked-proces en de epm-service van WatchGuard Fireware OS. Het iked-proces bevat een stack-based buffer overflow, een type confusion kwetsbaarheid en een heap overflow. Deze kwetsbaarheden kunnen worden misbruikt door een ongeauthenticeerde aanvaller door speciaal vervaardigd netwerkverkeer te verzenden. Dit…
WatchGuard NL
Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes. [...]
Disponibili Proof of Concept (PoC) per lo sfruttamento di 3 nuove vulnerabilità con gravità "critica", che interessano i router Tenda AC1206 e AC18.
EPSS 0.01 CVE-2026-82693 CVE-2026-82694 CVE-2026-82695 Tenda IT
View CSAF Summary The following versions of Rockwell Automation FactoryTalk Activation Manager are affected: FactoryTalk Activation Manager V5.02_and_below (CVE-2026-16675) CVSS Vendor Equipment Vulnerabilities v3 7.8 Rockwell Automation Rockwell Automation FactoryTalk Activation Manager Improper Restriction of Excessive Authentication Attempts Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States…
EPSS 0.00 CVSS 7.8 CVE-2026-16675 Rockwell Automation výroba a průmysl US
View CSAF Summary Successful exploitation of these vulnerabilities could allow for an attacker to escalate and execute processes with administrator privileges. The following versions of Rockwell Automation Redundancy Module Configuration Tool are affected: Redundancy Module Configuration Tool 10.00.00 (CVE-2026-9633) Redundancy Module Configuration Tool >=9.00.00|<=10.00.00 (CVE-2026-9634) CVSS Vendor Equipment Vulnerabilities v3 7.3 Rockwell Automation Rockwell Automation Redundancy Module…
EPSS 0.00 CVSS 7.3 CVE-2026-9633 CVE-2026-9634 Rockwell Automation výroba a průmysl US
View CSAF Summary The following versions of Rockwell Automation Logix Platform are affected: ControlLogix 5580 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637) CompactLogix 5380 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637) GuardLogix 5580 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637)…
EPSS 0.00 CVSS 7.5 CVE-2026-9637 Rockwell Automation výroba a průmysl US
View CSAF Summary The following versions of Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix are affected: ControlLogix 5580 <34.015, <35.014, <36.013, <37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260) GuardLogix 5580 <34.015, <35.014, <36.013, <37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260) CompactLogix 5380 <34.015, <35.014, <36.013, <37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE…
EPSS 0.03 CVSS 7.5 CVE-2021-42260 Rockwell Automation výroba a průmysl US
View CSAF Summary Successful exploitation of these vulnerabilities could crash the device being accessed; an out-of-bounds write condition may allow remote code execution. The following versions of Rockwell Automation Historian ME are affected: Series B 5.202 (CVE-2025-12768, CVE-2026-12661) Series C 7.101 (CVE-2025-12768, CVE-2026-12661) CVSS Vendor Equipment Vulnerabilities v3 8 Rockwell Automation Rockwell Automation Historian ME Out-of-bounds Write, Stack-based Buffer Overflow Background…
EPSS 0.00 CVSS 8.0 CVE-2025-12768 CVE-2026-12661 Rockwell Automation výroba a průmysl zdravotnictví vodárenství US
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the affected product. The following versions of Rockwell Automation RSLinx Classic are affected: RSLinx Classic <=4.50 (CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625) CVSS Vendor Equipment Vulnerabilities v3 8.6 Rockwell Automation Rockwell Automation RSLinx Classic Integer Overflow or Wraparound, Integer Underflow (Wrap or Wraparound), Buffer Copy…
EPSS 0.00 CVSS 8.6 CVE-2026-9621 CVE-2026-9622 CVE-2026-9624 CVE-2026-9625 Rockwell Automation výroba a průmysl US
Anthropic has warned some Claude users that criminals are using information stealers to take over their accounts. Rather than guessing passwords or intercepting two-factor authentication (2FA) codes, the attackers steal the browser sessions that prove a user is already logged in. According to a warning email shared publicly by an affected user, the attackers used common infostealer malware to copy Claude login sessions from victims’ computers. They then used those sessions to access the…
Anthropic US
[VDE-2026-093] A vulnerability has been found in the firmware update process of SAUTER Building Controllers. The identified vulnerability could allow unauthorized code execution on affected controllers.
EPSS 0.00 CVE-2026-78319 SAUTER DE
Aggiornamenti di sicurezza sanano una vulnerabilità in libexpat, nota libreria scritta in C per l'analisi di documenti XML. Tale vulnerabilità, qualora sfruttata, consentirebbe ad utente malintenzionato di innescare la corruzione della memoria o il crash dell'applicazione, portando alla compromissione della disponibilità del servizio sulle istanze interessate.
EPSS 0.00 CVE-2026-76641 libexpat IT
Lack of authorisation in OpenNebula by OpenNebula Systems Tue, 09/01/2026 - 12:12 Aviso Affected Resources OpenNebula 7.4. Description INCIBE has coordinated the publication of a high-severity vulnerability affecting OpenNebula by OpenNebula Systems, a platform for managing virtualised data. The vulnerability was discovered by Yonghwa Lee, Xint from Theori.This vulnerability has been assigned the following code, CVSS v4.0 base score, CVSS vector and CWE vulnerability type:CVE-2026-84165: CVSS…
EPSS 0.00 CVSS 8.7 CVE-2026-84165 OpenNebula Systems ES
Two security vulnerabilities in the PaperCut NG and MF print management software, patched last week after being exploited as zero-days, are now being abused in data theft attacks. [...]
CVE-2023-2533 * CVE-2026-81578 * CVE-2026-82078 * PaperCut US
Code injection in the Lutece Core Tue, 09/01/2026 - 11:44 Aviso Affected Resources Lutece Core: versión 7.1.7 y anteriores. Description INCIBE has coordinated the disclosure of a critical-severity vulnerability in Lutece Core, an open platform that enables local authorities to share, reuse and adapt digital services. The vulnerability was discovered by I Dorian Piette (Trachinus).This vulnerability has been assigned the following code, CVSS v4.0 base score, CVSS vector and CWE vulnerability…
EPSS 0.00 CVSS 9.4 CVE-2026-4813 Lutece veřejná správa ES
Cadence uses JetBrains TeamCity to orchestrate cloud workloads, and the affected server, api.cadence.jetbrains.com, remained vulnerable to CVE-2026-63077 despite having been intended for patching. Threat actors exploited the vulnerability beginning on August 8 to gain unauthor...
KEV ✓ EPSS 0.87 CVSS 9.8 CVE-2026-63077 JetBrains veřejná správa US
De multiples vulnérabilités ont été découvertes dans SPIP. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance et un problème de sécurité non spécifié par l'éditeur.
SPIP FR
Une vulnérabilité a été découverte dans Kaspersky Endpoint Security Windows. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité.
Kaspersky FR
De multiples vulnérabilités ont été découvertes dans JFrog Artifactory. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, une falsification de requêtes côté serveur (SSRF) et un contournement de la politique de sécurité.
KEV ✓ EPSS 0.08 CVE-2026-69104 CVE-2026-70548 CVE-2026-70550 CVE-2026-70551 CVE-2026-82329 JFrog FR
Une vulnérabilité a été découverte dans Mozilla Firefox pour iOS. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité.
EPSS 0.00 CVE-2026-81267 Mozilla FR
De multiples vulnérabilités ont été découvertes dans Mattermost Server. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.
Mattermost FR
Serial Number: AV26-865Date: August 31, 2026 As of August 27, 2026, WatchGuard is affected by vulnerabilities in the following products: Dimension Prior to 2.3.1 Fireware OS Prior to 12.12.2 Prior to 12.5.20 Prior to 2026.2.2 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. WatchGuard Security Advisories
WatchGuard CA
Serial Number: AV26-864Date: August 31, 2026 As of August 27, 2026, Siemens is affected by a vulnerability in the following products: Element maps-ng V47 Prior to V47.12.3 Element maps-ng V48 Prior to V48.11.3 Element maps-ng V49 Prior to V49.16.1 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. SSA-682041 CERT Services | Siemens
Siemens CA
Serial Number: AV26-863Date: August 31, 2026 As of August 28, 2026, Dell is affected by vulnerabilities in the following products: Dell PowerEdge Server for Intel Processor Firmware Multiple versions and models Dell AppSync Prior to or equal to 4.6.0.4 and 4.6.1.0 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. DSA-2026-356: Security Update for Dell PowerEdge Server for Intel® Processor Firmware…
Dell CA
Serial Number: AV26-862Date: August 31, 2026 As of August 28, 2026, IBM is affected by vulnerabilities in the following products: SPSS Collaboration and Deployment Services Multiple versions IBM SPSS Analytic Server Multiple version IBM MQ Agent Multiple versions IBM Maximo Application Suite - Monitor Component Prior to or equal to 9.2, 9.1 and 9.0 IBM Observability with Instana (Agent) Prior to or equal to 1.0.323 IBM Financial Transaction Manager (FTM) for RedHat OpenShift Multiple versions…
IBM CA
For the latest discoveries in cyber research for the week of 31st August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Manchester Airports Group, the UK operator of Manchester, London Stansted, and East Midlands airports, has disclosed a cyberattack that exposed data belonging to about 8.7 million customers. The compromised information includes contact details, vehicle registration numbers, and information collected through car park, lounge, fast-track, and Wi-Fi…
KEV ✓ EPSS 0.04 CVSS 10.0 CVE-2026-18885 CVE-2026-18886 CVE-2026-74820 CVE-2026-75604 CVE-2026-81578 CVE-2026-82078 PaperCut Ubiquiti Vercel ServiceNow IL
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-81578 PaperCut NG/MF Missing Authentication for Critical Function Vulnerability CVE-2026-82078 PaperCut NG/MF Unsafe Reflection Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates…
KEV ✓ EPSS 0.04 CVSS 9.4 CVE-2026-81578 CVE-2026-82078 PaperCut veřejná správa US IT FI FR
A Nemzetbiztonsági Szakszolgálat Nemzeti Kiberbiztonsági Intézet riasztást ad ki a Zimbra Collaboration Suite (ZCS) szoftvert érintő, CVE-2026-73570 azonosítón nyomon követett kritikus sérülékenység kapcsán. Intézetünkhöz megnövekedett számú bejelentés érkezett a CVE-2026-73570 sérülékenység aktív kihasználásáról. A sebezhetőség kihasználása hitelesítés nélküli támadók számára távoli kódfuttatást tehet lehetővé. A sérülékenység a Zimbra SNMP-monitorozási komponensét érinti, és akkor használható…
KEV ✓ EPSS 0.32 CVE-2026-73570 Zimbra Synacor veřejná správa HU US IT
Rilevate 8 nuove vulnerabilità di sicurezza, di cui 2 con gravità “critica” e 4 con gravità “alta”, che interessano il software Langflow, nota piattaforma open-source che permette di costruire, testare e distribuire applicazioni e agenti basati su intelligenza artificiale.
EPSS 0.02 CVE-2026-18729 CVE-2026-18891 CVE-2026-18899 CVE-2026-18904 CVE-2026-19286 CVE-2026-19295 LangFlow IT
Rilevata una vulnerabilità di sicurezza con gravità "alta" in Sudo, nota utility per sistemi operativi Unix-like che permette di delegare i privilegi utente. Tale vulnerabilità, qualora sfruttata, potrebbe consentire ad un utente locale autenticato di eludere i meccanismi di sicurezza e di eseguire programmi non autorizzati sul sistema interessato, ottenendo privilegi superiori rispetto a quelli previsti dalle policy configurate.
EPSS 0.00 CVE-2026-82474 Sudo IT
Aggiornamenti di sicurezza sanano sanano una vulnerabilità con gravità “alta” nel linguaggio di programmazione Go. Tale vulnerabilità, qualora sfruttata, potrebbe consentire a utenti malintenzionati di aggirare i meccanismi di autenticazione sui sistemi interessati.
EPSS 0.00 CVE-2026-56854 Go IT
This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.
CVSS 7.8 pdfforge US
This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.
CVSS 7.8 pdfforge US
This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.
CVSS 7.8 pdfforge US
This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.
CVSS 7.8 pdfforge US
This vulnerability allows local attackers to escalate privileges on affected installations of pdfforge PDF Architect. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8.
CVSS 7.8 pdfforge US
De multiples vulnérabilités ont été découvertes dans les produits Tenable. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance et une élévation de privilèges.
EPSS 0.03 CVE-2026-19626 CVE-2026-19628 CVE-2026-19629 CVE-2026-19635 Tenable FR
De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.
Microsoft FR
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 10.0, CVEs: CVE-2026-76581, CVE-2026-18431, CVE-2026-19632, CVE-2026-19598, CVE-2026-82222, Summary: Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover, and arbitrary code execution. The vulnerabilities, according to Wordfence and Patchstack,…
EPSS 0.03 CVSS 10.0 CVE-2026-18431 CVE-2026-19598 CVE-2026-19632 CVE-2026-76581 CVE-2026-82222 WordPress WPMU DEV Avada TranslatePress FI