VIRY.CZ RADAR je monitor bezpečnostních hrozeb: advisories, zranitelnosti a threat intel z veřejných zdrojů, česky a na jednom místě.

65 zdrojů
25 zemí
6 561 položek
5 319 CVE s hodnocením
Více informací

Jsem „protkán“ AI. Snažím se pochopit zdrojové texty a bez vymýšlení je zestručnit a převést do českého jazyka, případně s využitím AI seskupit. Patřičně jsem pak hrdý na týdenní reporty, kde s pomocí AI zpracovávám stovky článků a hledám v nich souvislosti. Používám ale i čistou matematiku, takže pokud například více zdrojů mluví o shodné CVE chybě, seskupím to do jednoho příspěvku. Doporučuji se přihlásit k jejich odběru e-mailem nebo jinou cestou. Pokud se Vám líbím, nebráním se finanční podpoře :-)

Původní „Igiho stránka o virech“ se odstěhovala sem.

Všechny zprávy za posledních 7 dní

K seskupování zpráv do jedné události používám AI 2x denně nebo logiku kolem shodného výčtu CVE (okamžitě).

361 záznamů z 429 položek · strana 4 z 7 CZ · EN/orig

60

Cisco Identity Services Engine Authenticated Remote Code Execution and API Vulnerabilities

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct SQL injections, modify data, or execute arbitrary commands on the underlying operating system on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. Note: For CVE-2026-20282 and CVE-2026-20283, Cisco has assigned a Security Impact Rating (SIR) of High rather than Medium as the scores indicate. The reason is that it…

EPSS 0.01 CVE-2026-20282 CVE-2026-20283 CVE-2026-20284 Cisco US

tg: zranitelnost

· Cisco PSIRT · Cisco Identity Services Engine Authenticated Remote Code Execution and API Vulnerabilities

Cisco Identity Services Engine Remote Code Execution Vulnerabilities

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit these vulnerabilities, the attacker must have valid administrative credentials. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these…

EPSS 0.01 CVE-2026-20176 CVE-2026-20211 CVE-2026-20307 Cisco US

tg: zranitelnost

· Cisco PSIRT · Cisco Identity Services Engine Remote Code Execution Vulnerabilities

SPOJENO PŘES CVE Cisco Secure Firewall Management Center Software Java Deserialization Remote Code Execution Vulnerability

A vulnerability in the External Database Access feature of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary commands as root on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream from a host that is configured in the external database access list. An attacker could exploit this vulnerability by sending a crafted, serialized Java byte stream to a specific TCP port…

EPSS 0.01 CVSS 8.1 CVE-2026-20242 Cisco US

tg: zranitelnost

· Cisco PSIRT · Cisco Secure Firewall Management Center Software Java Deserialization Remote Code Execution Vulnerability · Zero Day Initiative · ZDI-26-709: Cisco Secure Firewall Management Center CommandSinkRmi Deserialization of Untrusted Data Remote Code Execution Vulnerability

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software for Secure Firewall 3100 and 4200 Series DTLS Denial of Service Vulnerability

A vulnerability in Datagram TLS (DTLS) message handling of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software for Cisco Secure Firewall 3100 Series and 4200 Series devices could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper resource management when processing certain DTLS messages. An attacker could exploit this vulnerability…

EPSS 0.01 CVE-2026-20250 Cisco US

tg: zranitelnost

· Cisco PSIRT · Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software for Secure Firewall 3100 and 4200 Series DTLS Denial of Service Vulnerability

NCSC-2026-0381 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle PeopleSoft Enterprise

Oracle heeft 16 kwetsbaarheden verholpen in diverse Oracle PeopleSoft-producten, waaronder PeopleSoft Enterprise PeopleTools, PeopleSoft Enterprise PRTL Interaction Hub en PeopleSoft Enterprise CC Common Application Objects. De kwetsbaarheden betreffen verschillende beveiligingsproblemen in Oracle PeopleSoft-producten, waaronder mogelijkheden voor niet-geauthenticeerde en laaggeprivilegieerde kwaadwillenden om via netwerktoegang ongeautoriseerde acties uit te voeren. De kwetsbaarheden hebben…

EPSS 0.00 CVE-2026-73954 CVE-2026-83017 Oracle NL

tg: zranitelnost

· NCSC-NL · NCSC-2026-0381 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle PeopleSoft Enterprise

NCSC-2026-0380 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle Java SE

Oracle heeft 3 kwetsbaarheden verholpen in Oracle Java SE, waaronder Oracle GraalVM for JDK en Oracle GraalVM Enterprise Edition. De kwetsbaarheden betreffen verschillende beveiligingsproblemen in Oracle Java SE-producten, waarbij niet-geauthenticeerde kwaadwillenden via netwerktoegang kwetsbaarheden in de Compiler-component kunnen misbruiken. De kwetsbaarheden hebben CVSS-scores in de categorie hoog. Alle drie de kwetsbaarheden kunnen volgens Oracle zonder authenticatie op afstand worden…

EPSS 0.00 CVE-2026-83357 CVE-2026-83408 Oracle NL

tg: zranitelnost

· NCSC-NL · NCSC-2026-0380 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle Java SE

NCSC-2026-0379 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle Analytics

Oracle heeft 50 kwetsbaarheden verholpen in diverse Oracle Analytics-producten, waaronder Oracle Business Intelligence Enterprise Edition en Oracle BI Publisher. De kwetsbaarheden betreffen verschillende beveiligingsproblemen in Oracle Analytics-producten, waaronder mogelijkheden voor niet-geauthenticeerde en laaggeprivilegieerde kwaadwillenden om via netwerktoegang ongeautoriseerde acties uit te voeren. De kwetsbaarheden hebben CVSS-scores variërend van hoog tot kritiek. Van de in totaal 50…

EPSS 0.00 CVE-2026-83268 CVE-2026-83269 CVE-2026-83282 CVE-2026-83283 Oracle NL

tg: zranitelnost

· NCSC-NL · NCSC-2026-0379 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle Analytics

NCSC-2026-0378 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle Financial Services

Oracle heeft 6 kwetsbaarheden verholpen in diverse Oracle Financial Services Applications-producten, waaronder Oracle Banking Branch, Oracle Banking Corporate Lending, Oracle Banking Origination, Oracle Banking Treasury Management en Oracle Banking Corporate Lending Process Management. De kwetsbaarheden betreffen verschillende beveiligingsproblemen in Oracle Financial Services Applications-producten, waaronder mogelijkheden voor niet-geauthenticeerde en laaggeprivilegieerde kwaadwillenden om…

Oracle finance NL

tg: zranitelnost

· NCSC-NL · NCSC-2026-0378 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle Financial Services

NCSC-2026-0377 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle Enterprise Manager

Oracle heeft 7 kwetsbaarheden verholpen in diverse Oracle Enterprise Manager-producten, waaronder Oracle Enterprise Manager Base Platform, Oracle Enterprise Manager for Fusion Middleware en Oracle Enterprise Manager for Oracle Database. De beveiligingsupdates zijn niet van toepassing op client-only installaties waarop Oracle Enterprise Manager niet is geïnstalleerd. De kwetsbaarheden betreffen verschillende beveiligingsproblemen in Oracle Enterprise Manager-producten, waaronder mogelijkheden…

EPSS 0.01 CVE-2026-2332 CVE-2026-41635 CVE-2026-83355 Oracle NL

tg: zranitelnost

· NCSC-NL · NCSC-2026-0377 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle Enterprise Manager

NCSC-2026-0376 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle E-Business Suite

Oracle heeft 159 kwetsbaarheden verholpen in diverse Oracle E-Business Suite-producten, waaronder Oracle Applications Framework, Oracle Document Management and Collaboration, Oracle Mobile Application Server, Oracle Alert, Oracle Application Object Library, Oracle Applications Manager, Oracle Bills of Material, Oracle Complex Maintenance, Repair and Overhaul, Oracle Contract Lifecycle Management for Public Sector, Oracle Contracts, Oracle Customer Interaction History, Oracle Demand Signal…

EPSS 0.00 CVE-2026-83327 CVE-2026-83452 CVE-2026-83462 Oracle NL

tg: zranitelnost

· NCSC-NL · NCSC-2026-0376 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle E-Business Suite

NCSC-2026-0375 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle Communications

Oracle heeft 31 kwetsbaarheden verholpen in diverse Oracle Communications-producten, waaronder Oracle Communications Unified Assurance, Oracle Communications Cloud Native Core Security Edge Protection Proxy, Oracle Communications MetaSolv Solution Module - ASR, Oracle Communications Service Catalog and Design en Oracle Communications Operations Monitor. De kwetsbaarheden betreffen verschillende beveiligingsproblemen in Oracle Communications-producten, waaronder mogelijkheden voor niet…

EPSS 0.01 CVE-2026-17544 CVE-2026-44024 CVE-2026-71290 CVE-2026-73194 Oracle telekomunikace NL

tg: zranitelnost

· NCSC-NL · NCSC-2026-0375 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle Communications

NCSC-2026-0374 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle Commerce Platform

Oracle heeft 27 kwetsbaarheden verholpen in Commerce Platform, waaronder Oracle Commerce Guided Search en Oracle Commerce Experience Manager, waaronder de componenten Experience Manager, Forge en Endeca Application Controller. De kwetsbaarheden betreffen verschillende beveiligingsproblemen in Oracle Commerce-producten, waaronder mogelijkheden voor niet-geauthenticeerde en laaggeprivilegieerde kwaadwillenden om via netwerktoegang ongeautoriseerde acties uit te voeren. De kwetsbaarheden hebben…

Oracle NL

tg: zranitelnost

· NCSC-NL · NCSC-2026-0374 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle Commerce Platform

NCSC-2026-0373 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle Database Producten

Oracle heeft 16 kwetsbaarheden verholpen in diverse Database producten, waaronder Database Server, Autonomous Health Framework en Application Testing Suite. De kwetsbaarheden betreffen verschillende beveiligingsproblemen in Oracle-producten, waaronder mogelijkheden voor niet-geauthenticeerde en laaggeprivilegieerde kwaadwillenden om via netwerktoegang ongeautoriseerde acties uit te voeren. De kwetsbaarheden hebben CVSS-scores variërend van middel tot kritiek. Van de in totaal 16 kwetsbaarheden…

EPSS 0.00 CVE-2026-83149 Oracle NL

tg: zranitelnost

· NCSC-NL · NCSC-2026-0373 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle Database Producten

NCSC-2026-0372 [1.00] [H/H] Kwetsbaarheden verholpen in Oracle Fusion Middleware

Oracle heeft 153 kwetsbaarheden verholpen in diverse Oracle Fusion Middleware-producten, waaronder Helidon, Oracle Access Manager, Oracle Coherence, Oracle Data Integrator, Oracle Forms, Oracle Fusion Middleware Control, Oracle Identity Manager, Oracle Identity Manager Connector, Oracle Internet Directory, Oracle JDeveloper, Oracle Managed File Transfer, Oracle Middleware Common Libraries and Tools, Oracle Platform Security for Java, Oracle Web Services Manager, Oracle WebCenter Content, Oracle…

EPSS 0.00 CVE-2026-71133 CVE-2026-83020 CVE-2026-83021 CVE-2026-83059 CVE-2026-83099 Oracle NL

tg: zranitelnost

· NCSC-NL · NCSC-2026-0372 [1.00] [H/H] Kwetsbaarheden verholpen in Oracle Fusion Middleware

SPOJENO AI HPE patches critical ArubaOS-CX remote code execution flaw

Hewlett Packard Enterprise (HPE) has patched a critical vulnerability in the ArubaOS-CX network operating system that could lead to remote code execution. [...]

CVSS 9.8 HPE Networking HPE Aruba Networks IT RO FI US NL FR

tg: zranitelnost tp: DDoS

Portál NÚKIB rozšiřuje informace k povinným i dobrovolným hlášením

Dne 11. září 2026 začaly platit ohlašovací povinnosti podle článku 14 aktu o kybernetické odolnosti CRA, které se týkají hlášení aktivně zneužívaných zranitelností a závažných incidentů. Povinnost se vztahuje na výrobce produktů s digitálními prvky uváděných na trh Evropské unie. V souvislosti s tím byly na Portálu NÚKIB v sekci Chci vyřídit zveřejněny nové rozcestníky určené pro hlášení aktivně zneužívaných zranitelností a závažných incidentů podle CRA. Uživatelé zde naleznou také související…

CZ

tg: regulace tg: návod

· NÚKIB · Portál NÚKIB rozšiřuje informace k povinným i dobrovolným hlášením

Ukraine moves to crack down on scam call centers after corruption scandal

Ukraine’s parliament has approved tougher criminal penalties for involvement in fraudulent call centers and the theft of personal data, following a corruption scandal in which prosecutors were accused of taking bribes to protect scam operations.

veřejná správa US

tg: vymáhání práva tg: regulace tp: podvod tp: soukromí

· The Record · Ukraine moves to crack down on scam call centers after corruption scandal

Using Cyber Decoys to Strengthen Detection and Response

CISA developed this guidance to help defensive teams at varying levels of cybersecurity maturity plan and implement cyber decoy strategies that strengthen their detection and response capabilities. Many organizations struggle to detect adversaries who use legitimate credentials, native tools, and living off the land (LOTL) techniques to conduct discovery, move laterally, and access data. Cyber decoys are assets that appear to be legitimate systems, accounts, or data, but are designed to…

US

tg: návod tp: identita

· CISA Advisories · Using Cyber Decoys to Strengthen Detection and Response

SPOJENO AI Critical ScreenConnect flaw now actively exploited in attacks

Attackers now exploit a critical-severity ConnectWise ScreenConnect vulnerability in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). [...]

KEV ✓ EPSS 0.01 CVE-2026-84869 ConnectWise US IT CA FI

tg: zneužíváno tg: zranitelnost

Risolte vulnerabilità nei prodotti Atlassian

Aggiornamenti di sicurezza Atlassian sanano alcune vulnerabilità, di cui una con gravità "alta", che interessano il prodotto Crowd Data Center. Tale vulnerabilità, qualora sfruttata, potrebbe consentire, a un utente malintenzionato non autenticato, di eludere i meccanismi di autenticazione e ottenere accesso a funzionalità o risorse riservate sui sistemi interessati.

EPSS 0.00 CVE-2026-21582 Atlassian IT

tg: zranitelnost tp: identita

· CSIRT Itálie (ACN) · Risolte vulnerabilità nei prodotti Atlassian

Risolte vulnerabilità in MISP

Aggiornamenti di sicurezza MISP risolvono molteplici vulnerabilità, tra cui una con gravità "critica" e due con gravità "alta", in MISP, nota piattaforma collaborativa open source per la condivisione e l'analisi di informazioni sulle minacce informatiche. Tali vulnerabilità, qualora sfruttate, potrebbero consentire a un utente malintenzionato di eludere i meccanismi di autenticazione e sicurezza ed accedere a informazioni sensibili sui sistemi target.

EPSS 0.00 CVE-2026-90961 CVE-2026-91825 CVE-2026-91846 MISP IT

tg: zranitelnost

· CSIRT Itálie (ACN) · Risolte vulnerabilità in MISP

Securing the unpatchable in an age of AI-driven vulnerabilities

AI is accelerating vulnerability discovery, leaving unpatchable operational technology (OT) systems at risk. Hoping for the best is not a viable anti-exploitation strategy. Deploying next-generation firewalls directly upstream allows for virtual patching through deep packet inspection. These systems scan incoming traffic to detect and block exploit attempts before they can impact the vulnerable device.The predictability of legitimate network connections to OT systems can be used to protect…

US

tg: rozbor tg: návod tp: AI tp: průmyslové systémy

· Cisco Talos · Securing the unpatchable in an age of AI-driven vulnerabilities

Agents at Large | Tracing Illicit OpenAI Agent Activity on Hugging Face

Executive Summary OpenAI disclosed that agents used exposed Hugging Face credentials to write a file and deploy proxy Spaces during an unrelated May 2026 research workload, but it did not identify the accounts. SentinelLABS identified two accounts likely used in associated activity, 0Time and Nyx9. Their public histories extend OpenAI’s chronology and preserve previously unreported relay code, document-borne probes, and ChatGPT account-provisioning capability. The public records provide precise…

OpenAI Hugging Face US

tg: incident tg: rozbor tp: AI tp: identita

· SentinelLabs · Agents at Large | Tracing Illicit OpenAI Agent Activity on Hugging Face

AI helps scammers build convincing antivirus renewal pages

Antivirus renewal scams often begin with a message claiming that your subscription has automatically renewed. When you follow the instructions to cancel it, you are taken to a fake page designed to collect your contact details. The renewal charge never existed. Receiving a message that names the antivirus software you use does not necessarily mean the sender has access to your device or account. Scammers impersonate popular brands and send the same message to large numbers of people, knowing…

Avast US

tg: rozbor tg: propagace tp: phishing tp: podvod tp: AI

· Malwarebytes Labs · AI helps scammers build convincing antivirus renewal pages

SPOJENO PŘES CVE Risolte vulnerabilità in Squid

Aggiornamenti di sicurezza Squid risolvono tre vulnerabilità, di cui una con gravità “alta”, in Squid, software open source utilizzato come caching proxy. Tale vulnerabilità potrebbe consentire ad un utente malintenzionato di eludere le funzionalità di sicurezza e di alterare il contenuto memorizzato nella cache mediante richieste HTTP opportunamente predisposte.

CVE-2026-61642 Squid IT FR

tg: zranitelnost tp: DDoS

· CSIRT Itálie (ACN) · Risolte vulnerabilità in Squid · CERT-FR – avis · Multiples vulnérabilités dans Squid (14 septembre 2026)

Carlo Gavazzi Automation: YL212* and YN115* are affected by multiple security vulnerabilities

[VDE-2026-028] The affected devices have security vulnerabilities that can be used to bypass authentication. Code can be executed on the devices through command injection and local file inclusion. Path traversal and modified schemata can be used to read sensitive information such as password hashes or private keys from the devices.

Carlo Gavazzi DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · Carlo Gavazzi Automation: YL212* and YN115* are affected by multiple security vulnerabilities

Pepperl+Fuchs: ICE2-* and ICE3-* are affected by multiple security vulnerabilities

[VDE-2026-014] The affected devices have security vulnerabilities that can be used to bypass authentication. Code can be executed on the devices through command injection and local file inclusion. Path traversal and modified schemata can be used to read sensitive information such as password hashes or private keys from the devices.

Pepperl+Fuchs DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · Pepperl+Fuchs: ICE2-* and ICE3-* are affected by multiple security vulnerabilities

Phoenix Contact: Multiple vulnerabilities in the firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices

[VDE-2026-027] The firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices is affected by security vulnerabilities that can be used to bypass authentication. Code can be executed on the devices through command injection and local file inclusion. Path traversal and modified schemata can be used to read sensitive information such as password hashes or private keys from the devices.

Phoenix Contact DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · Phoenix Contact: Multiple vulnerabilities in the firmware of IOL MA8 EIP DI8 and IOL MA8 PN DI8 devices

ZDI-26-710: NoMachine mDNS Heap-based Buffer Overflow Remote Code Execution Vulnerability

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NoMachine. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-92208.

CVSS 8.8 CVE-2026-92208 NoMachine US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-710: NoMachine mDNS Heap-based Buffer Overflow Remote Code Execution Vulnerability

ZDI-26-711: NoMachine Redis Improper Authentication Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of NoMachine. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-92209.

CVSS 7.8 CVE-2026-92209 NoMachine US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-711: NoMachine Redis Improper Authentication Local Privilege Escalation Vulnerability

ZDI-26-712: NoMachine nxhtd Server-Side Request Forgery Information Disclosure Vulnerability

This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of NoMachine. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-92210.

CVSS 7.2 CVE-2026-92210 NoMachine US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-712: NoMachine nxhtd Server-Side Request Forgery Information Disclosure Vulnerability

ZDI-26-713: GIMP APNG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-92183.

CVSS 7.8 CVE-2026-92183 GIMP US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-713: GIMP APNG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability

ZDI-26-703: (0Day) Airbyte SharePoint Connector _get_shared_drive_object Server-Side Request Forgery Information Disclosure Vulnerability

This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of Airbyte. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.7. The following CVEs are assigned: CVE-2026-92203.

CVSS 7.7 CVE-2026-92203 Airbyte US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-703: (0Day) Airbyte SharePoint Connector _get_shared_drive_object Server-Side Request Forgery Information Disclosure Vulnerability

ZDI-26-704: (0Day) Airbyte OneDrive Connector _get_shared_drive_object Server-Side Request Forgery Information Disclosure Vulnerability

This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of Airbyte. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.7. The following CVEs are assigned: CVE-2026-92204.

CVSS 7.7 CVE-2026-92204 Airbyte US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-704: (0Day) Airbyte OneDrive Connector _get_shared_drive_object Server-Side Request Forgery Information Disclosure Vulnerability

ZDI-26-705: (0Day) BusyBox libarchive Symlink Directory Traversal Arbitrary File Creation Vulnerability

This vulnerability allows remote attackers to create arbitrary files on affected installations of BusyBox. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-92205.

CVSS 6.1 CVE-2026-92205 BusyBox US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-705: (0Day) BusyBox libarchive Symlink Directory Traversal Arbitrary File Creation Vulnerability

ZDI-26-706: (0Day) CrewAI crewAI Framework Agent Loading Unsafe Reflection Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of CrewAI crewAI. User interaction is required to exploit this vulnerability in that the target must load a malicious agent configuration from the repository. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-92206.

CVSS 8.8 CVE-2026-92206 CrewAI US

tg: zranitelnost tp: AI

· Zero Day Initiative · ZDI-26-706: (0Day) CrewAI crewAI Framework Agent Loading Unsafe Reflection Remote Code Execution Vulnerability

ZDI-26-707: (0Day) MindsDB OpenBBtable Code Injection Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of MindsDB. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-92207.

CVSS 8.8 CVE-2026-92207 MindsDB US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-707: (0Day) MindsDB OpenBBtable Code Injection Remote Code Execution Vulnerability

ZDI-26-708: (0Day) Microsoft Windows HTTP Proxy Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.3.

CVSS 5.3 Microsoft US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-708: (0Day) Microsoft Windows HTTP Proxy Privilege Escalation Vulnerability

SPOJENO PŘES CVE K000162604: NGINX ngx_http_v3_module vulnerability CVE-2026-90439

Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 6.5, CVEs: CVE-2026-90439, Summary: NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module module. When using HTTP/3 with OpenSSL versions 3.5.0 and earlier under certain configurations, a limited heap buffer overflow could happen while processing a Transport Layer Security (TLS) handshake. This can happen in a non-deterministic manner that is beyond the attacker's control. This…

EPSS 0.00 CVSS 6.5 CVE-2026-90439 NGINX OpenSSL F5 FI FR

tg: zranitelnost

· NCSC-FI · K000162604: NGINX ngx_http_v3_module vulnerability CVE-2026-90439 · CERT-FR – avis · Vulnérabilité dans F5 NGINX (16 septembre 2026)

Mozilla Foundation Security Advisory 2026-90 - Security Vulnerabilities fixed in Firefox 156

Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: None, CVEs: CVE-2026-92033, CVE-2026-92005, CVE-2026-92006, CVE-2026-92007, CVE-2026-92008, CVE-2026-92009, CVE-2026-92010, CVE-2026-92011, CVE-2026-92012, CVE-2026-92013, CVE-2026-92015, CVE-2026-92034, CVE-2026-92035, CVE-2026-92016, CVE-2026-92017, CVE-2026-92018, CVE-2026-92019, CVE-2026-92020, CVE-2026-92022, CVE-2026-92023 (+55 other associated CVEs), Summary: Security Vulnerabilities fixed in Firefox…

Mozilla FI

tg: zranitelnost tg: novinka v produktu

· NCSC-FI · Mozilla Foundation Security Advisory 2026-90 - Security Vulnerabilities fixed in Firefox 156

Atlassian - Security Bulletin - September 15 2026

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 10.0, CVEs: CVE-2026-75595, CVE-2026-54512, CVE-2026-54513, CVE-2026-45623, CVE-2026-73507, CVE-2026-68763, CVE-2026-73646, CVE-2026-53404, CVE-2026-55153, CVE-2026-21582, CVE-2026-4800, CVE-2026-44249, CVE-2026-76172, CVE-2026-75975, CVE-2026-75899, CVE-2026-50010, CVE-2026-45416, CVE-2026-42583, CVE-2026-73086, CVE-2026-45674 (+44 other associated CVEs), Summary: September 2026 Security Bulletin The…

CVSS 10.0 Atlassian FI

tg: zranitelnost

· NCSC-FI · Atlassian - Security Bulletin - September 15 2026

SPOJENO PŘES CVE TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities

Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 8.6, CVEs: CVE-2026-81573, CVE-2026-81574, CVE-2026-81572, CVE-2026-81576, CVE-2026-81575, Summary: The TRUMPF product versions listed below include a Wibu CodeMeter Runtime version that contains several vulnerabilities, e.g. potentially allowing privilege escalation.

EPSS 0.00 CVSS 8.6 CVE-2026-81572 CVE-2026-81573 CVE-2026-81574 CVE-2026-81575 CVE-2026-81576 TRUMPF WIBU-SYSTEMS Wibu-Systems výroba a průmysl FI DE

tg: zranitelnost tp: dodavatelský řetězec tp: průmyslové systémy

· NCSC-FI · TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities · CERT@VDE · TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities

CISA Releases Eight Industrial Control Systems Advisories

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.0: 9.8, CVEs: CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372, CVE-2026-88259, CVE-2026-84398, CVE-2026-84400, CVE-2026-81305, CVE-2026-85478, CVE-2026-85497, CVE-2026-81321, CVE-2026-58113, CVE-2026-80465, CVE-2024-42384, CVE-2024-42385, CVE-2024-42386, CVE-2024-42391, CVE-2024-42392 (+14 other associated CVEs), Summary: CISA released eight Industrial Control…

CVSS 9.8 Digital Watchdog Wärtsilä mySCADA Schneider Electric FI

tg: zranitelnost tp: průmyslové systémy

· NCSC-FI · CISA Releases Eight Industrial Control Systems Advisories

LiteSpeed Enterprise security advisory - September 14, 2026

Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: None, CVEs: , Summary: We have received notice that a critical privilege-escalation vulnerability has been identified in LiteSpeed Web Server Enterprise. On shared-hosting servers, a malicious low-privilege website user could potentially gain root-level access to the server. This could allow an attacker to access or alter other hosted websites and the server itself. This issue can bypass expected account…

LiteSpeed FI

tg: zranitelnost

· NCSC-FI · LiteSpeed Enterprise security advisory - September 14, 2026