Výsledky hledání

typ: zranitelnost× v celém archivu zrušit filtry

1784 karet z 1914 položek · strana 5 z 30 CZ · EN/orig

38

MongoDB security advisory (AV26-918)

Serial number: AV26-918Date: September 14, 2026 As of September 11, 2026, MongoDB is affected by a vulnerability in the following product: MongoDB Server Prior to 7.0.43 Prior to 8.0.32 Prior to 8.3.11 Prior to 9.1.0-rc0 Prior to 9.0.1 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Shred collection validator constants during parsing Alerts | MongoDB

MongoDB CA

tg: zranitelnost

· Cyber Centre Kanada · MongoDB security advisory (AV26-918)

14th September – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 14th Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES IDScan.net, a US identity verification provider, has disclosed a data breach after detecting unauthorized access on September 1. Exposed data included names and government identification numbers, while a criminal marketplace advertised a collection containing millions of identity documents, including driver’s licenses, associated with the…

KEV ✓ EPSS 0.94 CVSS 10.0 CVE-2026-67276 CVE-2026-72898 CVE-2026-81963 CVE-2026-85046 CVE-2026-85706 CVE-2026-85880 CVE-2026-86060 Microsoft GitLab MikroTik Anthropic IL

tg: incident tg: zranitelnost tg: přehled tp: malware tp: únik dat tp: AI

· Check Point Research · 14th September – Threat Intelligence Report

SPOJENO PŘES CVE CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild

OverviewOn September 10, 2026, GitLab published a critical patch release for GitLab Community Edition (CE) and Enterprise Edition (EE). The release addresses CVE-2026-85706, a critical path traversal vulnerability (CWE-22) in the repository commits API with a CVSSv3.1 score of 10.0. According to GitLab, improper path confinement and missing authentication enforcement could allow an unauthenticated user to read arbitrary files from an affected GitLab server under certain conditions.On September…

KEV ✓ EPSS 0.15 CVSS 10.0 CVE-2026-85706 CVE-2026-87719 GitLab US SE

tg: zneužíváno tg: zranitelnost tg: novinka v produktu

· Rapid7 · CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild · CERT-SE · GitLab rättar kritiska sårbarheter

Risolta vulnerabilità in MongoDB Server

Aggiornamenti di sicurezza sanano una vulnerabilità con gravità "alta" che interessa MongoDB Server, sistema di gestione di basi di dati documentali utilizzato per archiviare, gestire ed elaborare grandi quantità di informazioni. Tale vulnerabilità, qualora sfruttata, potrebbe consentire ad un utente malintenzionato autenticato, con privilegi di lettura/scrittura sul database, di compromettere la disponibilità del servizio e manipolare i dati sui sistemi interessati.

EPSS 0.00 CVE-2026-89099 MongoDB IT

tg: zranitelnost

· CSIRT Itálie (ACN) · Risolta vulnerabilità in MongoDB Server

Control de acceso inadecuado en la API REST de Hiperdino

Inadequate access control in the Hiperdino REST API Mon, 09/14/2026 - 13:27 Aviso Affected Resources Hiperdino REST API v1.0. Description INCIBE has coordinated the disclosure of a critical-severity vulnerability affecting the Hiperdino REST API, which acts as a bridge for carrying out actions automatically and in real time. The vulnerability was discovered by Jorge Ramos Santana.This vulnerability has been assigned the following code, CVSS v4.0 base score, CVSS vector and CWE vulnerability…

EPSS 0.00 CVSS 9.2 CVE-2026-12258 Hiperdino obchod ES

tg: zranitelnost tp: soukromí

· INCIBE-CERT · Control de acceso inadecuado en la API REST de Hiperdino

JFrog: rilevato sfruttamento in rete delle vulnerabilità CVE-2026-42016 e CVE-2026-42018 in Artifactory

Rilevato lo sfruttamento attivo in rete di due vulnerabilità con gravità "alta" - già sanate dal vendor - relative al prodotto JFrog Artifactory, piattaforma per la gestione e distribuzione di artefatti software

KEV ✓ EPSS 0.01 CVE-2026-42016 CVE-2026-42018 JFrog IT

tg: zneužíváno tg: zranitelnost

· CSIRT Itálie (ACN) · JFrog: rilevato sfruttamento in rete delle vulnerabilità CVE-2026-42016 e CVE-2026-42018 in Artifactory

SPOJENO PŘES CVE Rilevato sfruttamento della CVE-2026-84869 relativa al prodotto ConnectWise ScreenConnect

Rilevato lo sfruttamento attivo in rete della vulnerabilità CVE-2026-84869 con gravità "critica" - già sanata dal vendor - relativa al prodotto ConnectWise ScreenConnect

KEV ✓ EPSS 0.01 CVE-2026-84869 ConnectWise IT US CA

tg: zneužíváno tg: zranitelnost

· CSIRT Itálie (ACN) · Rilevato sfruttamento della CVE-2026-84869 relativa al prodotto ConnectWise ScreenConnect · CISA KEV · ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability (CVE-2026-84869) · Cyber Centre Kanada · ConnectWise security advisory (AV26-903)

ZDI-26-680: Linux Kernel Crypto Subsystem Use-After-Free Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-31719.

EPSS 0.00 CVSS 8.8 CVE-2026-31719 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-680: Linux Kernel Crypto Subsystem Use-After-Free Local Privilege Escalation Vulnerability

ZDI-26-681: Linux Kernel FUSE Subsystem Race Condition Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-64265.

EPSS 0.00 CVSS 7.8 CVE-2026-64265 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-681: Linux Kernel FUSE Subsystem Race Condition Local Privilege Escalation Vulnerability

ZDI-26-682: Linux Kernel IPv6 Neighbour Discovery Uninitialized Memory Information Disclosure Vulnerability

This vulnerability allows local attackers to disclose sensitive information on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.0. The following CVEs are assigned: CVE-2026-43040.

EPSS 0.00 CVSS 6.0 CVE-2026-43040 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-682: Linux Kernel IPv6 Neighbour Discovery Uninitialized Memory Information Disclosure Vulnerability

ZDI-26-683: Linux Kernel IPv6 VTI Subsystem Use-After-Free Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-72463.

EPSS 0.00 CVSS 7.5 CVE-2026-72463 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-683: Linux Kernel IPv6 VTI Subsystem Use-After-Free Local Privilege Escalation Vulnerability

ZDI-26-684: Linux Kernel KSMBD Query Directory Request Race Condition Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Kernel KSMBD. Authentication is not required to exploit this vulnerability. Furthermore, only systems with KSMBD enabled are vulnerable. The ZDI has assigned a CVSS rating of 9.0. The following CVEs are assigned: CVE-2026-64397.

EPSS 0.00 CVSS 9.0 CVE-2026-64397 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-684: Linux Kernel KSMBD Query Directory Request Race Condition Remote Code Execution Vulnerability

ZDI-26-685: Linux Kernel NFC NCI UART Driver Race Condition Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2025-38416.

EPSS 0.00 CVSS 8.8 CVE-2025-38416 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-685: Linux Kernel NFC NCI UART Driver Race Condition Local Privilege Escalation Vulnerability

ZDI-26-686: Linux Kernel nftables Race Condition Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-74565.

EPSS 0.00 CVSS 7.8 CVE-2026-74565 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-686: Linux Kernel nftables Race Condition Local Privilege Escalation Vulnerability

ZDI-26-687: Linux Kernel Open vSwitch Flow Delete Use-After-Free Information Disclosure Vulnerability

This vulnerability allows local attackers to disclose sensitive information on affected installations of the Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.4. The following CVEs are assigned: CVE-2026-80994.

EPSS 0.00 CVSS 6.4 CVE-2026-80994 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-687: Linux Kernel Open vSwitch Flow Delete Use-After-Free Information Disclosure Vulnerability

ZDI-26-688: Linux Kernel OpenvSwitch Race Condition Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-74465.

EPSS 0.00 CVSS 7.8 CVE-2026-74465 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-688: Linux Kernel OpenvSwitch Race Condition Local Privilege Escalation Vulnerability

ZDI-26-689: Linux Kernel SCTP Subsystem Race Condition Information Disclosure Vulnerability

This vulnerability allows local attackers to disclose sensitive information on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.4. The following CVEs are assigned: CVE-2026-46227.

EPSS 0.00 CVSS 6.4 CVE-2026-46227 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-689: Linux Kernel SCTP Subsystem Race Condition Information Disclosure Vulnerability

ZDI-26-690: Linux Kernel MCTP Routing Uninitialized Memory Information Disclosure Vulnerability

This vulnerability allows local attackers to disclose sensitive information on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.0. The following CVEs are assigned: CVE-2026-45930.

EPSS 0.00 CVSS 6.0 CVE-2026-45930 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-690: Linux Kernel MCTP Routing Uninitialized Memory Information Disclosure Vulnerability

ZDI-26-691: Linux Kernel Netlink-based Wireless Configuration Integer Overflow Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.2. The following CVEs are assigned: CVE-2026-53182.

EPSS 0.00 CVSS 8.2 CVE-2026-53182 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-691: Linux Kernel Netlink-based Wireless Configuration Integer Overflow Local Privilege Escalation Vulnerability

ZDI-26-692: Linux Kernel eMPIA USB Device Driver Race Condition Code Execution Vulnerability

This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Linux Kernel. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.1. The following CVEs are assigned: CVE-2026-31583.

EPSS 0.00 CVSS 7.1 CVE-2026-31583 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-692: Linux Kernel eMPIA USB Device Driver Race Condition Code Execution Vulnerability

ZDI-26-693: Linux Kernel ksmbd Share Configuration Race Condition Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Kernel. Authentication is required to exploit this vulnerability. Furthermore, only systems with ksmbd enabled are vulnerable. The ZDI has assigned a CVSS rating of 8.5.

CVSS 8.5 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-693: Linux Kernel ksmbd Share Configuration Race Condition Remote Code Execution Vulnerability

ZDI-26-694: Linux Kernel Net Scheduler Clsact Qdisc Use-After-Free Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.2. The following CVEs are assigned: CVE-2026-23413.

EPSS 0.00 CVSS 8.2 CVE-2026-23413 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-694: Linux Kernel Net Scheduler Clsact Qdisc Use-After-Free Local Privilege Escalation Vulnerability

ZDI-26-695: Linux Kernel NFSv4 Server Race Condition Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Kernel. Authentication is required to exploit this vulnerability. Furthermore, only systems with nfsd enabled are vulnerable. The ZDI has assigned a CVSS rating of 8.5. The following CVEs are assigned: CVE-2026-89688.

EPSS 0.01 CVSS 8.5 CVE-2026-89688 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-695: Linux Kernel NFSv4 Server Race Condition Remote Code Execution Vulnerability

ZDI-26-696: Linux Kernel NTFS3 Journal Heap-based Buffer Overflow Code Execution Vulnerability

This vulnerability allows local attackers to execute arbitrary code on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-72196.

EPSS 0.00 CVSS 8.8 CVE-2026-72196 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-696: Linux Kernel NTFS3 Journal Heap-based Buffer Overflow Code Execution Vulnerability

ZDI-26-697: Linux Kernel NTFS3 Out-Of-Bounds Read Information Disclosure Vulnerability

This vulnerability allows local attackers to disclose sensitive information on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.3.

CVSS 7.3 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-697: Linux Kernel NTFS3 Out-Of-Bounds Read Information Disclosure Vulnerability

ZDI-26-698: Linux Kernel NTFS3 Out-Of-Bounds Read Information Disclosure Vulnerability

This vulnerability allows local attackers to disclose sensitive information on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.2.

CVSS 5.2 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-698: Linux Kernel NTFS3 Out-Of-Bounds Read Information Disclosure Vulnerability

ZDI-26-699: Linux Kernel NTFS3 Out-of-Bounds Read Information Disclosure Vulnerability

This vulnerability allows local attackers to disclose sensitive information on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.2.

CVSS 5.2 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-699: Linux Kernel NTFS3 Out-of-Bounds Read Information Disclosure Vulnerability

ZDI-26-700: Linux Kernel QFQ Plus Scheduler Use-After-Free Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-22999.

EPSS 0.00 CVSS 7.8 CVE-2026-22999 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-700: Linux Kernel QFQ Plus Scheduler Use-After-Free Local Privilege Escalation Vulnerability

ZDI-26-701: Linux Kernel TLS Protocol Out-Of-Bounds Read Information Disclosure Vulnerability

This vulnerability allows local attackers to disclose sensitive information on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.7. The following CVEs are assigned: CVE-2026-64046.

EPSS 0.01 CVSS 6.7 CVE-2026-64046 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-701: Linux Kernel TLS Protocol Out-Of-Bounds Read Information Disclosure Vulnerability

ZDI-26-702: Linux Kernel usbnet Driver Race Condition Privilege Escalation Vulnerability

This vulnerability allows physically present attackers to escalate privileges on affected installations of Linux Kernel. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.1. The following CVEs are assigned: CVE-2025-22050.

EPSS 0.00 CVSS 7.1 CVE-2025-22050 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-702: Linux Kernel usbnet Driver Race Condition Privilege Escalation Vulnerability

SPOJENO PŘES CVE Multiples vulnérabilités dans Microsoft Edge (14 septembre 2026)

De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Elles permettent à un attaquant de provoquer un contournement de la politique de sécurité et un problème de sécurité non spécifié par l'éditeur. Microsoft indique que la vulnérabilité CVE-2026-87491 est activement exploitée.

KEV ✓ EPSS 0.01 CVE-2026-87491 Microsoft Google Chrome FR HR US CA NL

tg: zneužíváno tg: zranitelnost tg: novinka v produktu

· CERT-FR – avis · Multiples vulnérabilités dans Microsoft Edge (14 septembre 2026) · CERT.hr · Google je izdao zakrpe za 230 ranjivosti. Ažurirajte Chrome preglednik. · Malwarebytes Labs · Update Chrome now to protect against an actively exploited vulnerability · Cyber Centre Kanada · Google security advisory (AV26-904) · NCSC-NL · NCSC-2026-0354 [1.00] [M/H] Kwetsbaarheid verholpen in Google Chrome · CISA KEV · Google Chromium V8 Out of Bounds Write Vulnerability (CVE-2026-87491)

Multiples vulnérabilités dans MongoDB (14 septembre 2026)

De multiples vulnérabilités ont été découvertes dans MongoDB. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.

EPSS 0.00 CVE-2026-88022 CVE-2026-88023 CVE-2026-88024 CVE-2026-88025 CVE-2026-88026 CVE-2026-88027 CVE-2026-88028 CVE-2026-88029 CVE-2026-88030 CVE-2026-88031 CVE-2026-88032 CVE-2026-88033 CVE-2026-88034 CVE-2026-88035 CVE-2026-88036 CVE-2026-89099 MongoDB FR

tg: zranitelnost

· CERT-FR – avis · Multiples vulnérabilités dans MongoDB (14 septembre 2026)

3

SPOJENO PŘES CVE Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103. [...]

EPSS 0.00 CVE-2026-85102 CVE-2026-85103 Check Point US NL IT FR CA

tg: varování tg: zranitelnost

· BleepingComputer · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent · NCSC-NL · NCSC-2026-0365 [1.00] [H/H] Kwetsbaarheden verholpen in Check Point VPN producten · CSIRT Itálie (ACN) · Risolte vulnerabilità in prodotti Check Point · CERT-FR – avis · Multiples vulnérabilités dans les produits Check Point (10 septembre 2026) · Cyber Centre Kanada · Check Point security advisory (AV26-902)

GitLab Critical Patch Release: 19.3.2, 19.2.6, 19.1.8

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 10.0, CVEs: CVE-2026-85706, CVE-2026-87719, CVE-2026-88765, CVE-2026-79708, CVE-2026-78252, CVE-2026-13210, CVE-2025-14871, CVE-2026-1168, CVE-2024-11222, CVE-2026-12910, CVE-2026-82837, CVE-2026-19619, CVE-2026-86341, CVE-2026-86340, CVE-2026-7514, CVE-2026-8030, CVE-2026-16794, CVE-2026-3855, Summary: On September 10, 2026, we released versions 19.3.2, 19.2.6, 19.1.8 for GitLab Community Edition (CE)…

CVSS 10.0 GitLab FI

tg: zranitelnost tg: novinka v produktu

· NCSC-FI · GitLab Critical Patch Release: 19.3.2, 19.2.6, 19.1.8

19

VAROVANIE: Kritické zraniteľnosti GITLAB CE a EE

Národné centrum kybernetickej bezpečnosti (NCKB) NBÚ varuje pred kritickými zraniteľnosťami v produktoch GitLab Community Edition (CE) a GitLab Enterprise Edition (EE). Uvedené zraniteľnosti možno zneužiť na získanie neoprávneného prístupu k citlivým údajom a úplné narušenie dôvernosti, integrity a dostupnosti systémov. Vývojári GitLab 10. septembra 2026 vydali bezpečnostné aktualizácie, ktoré opravujú až 18 zraniteľností, z ktorých 2 sú... The post VAROVANIE: Kritické zraniteľnosti GITLAB CE a…

GitLab SK

tg: zranitelnost

· SK-CERT (NBÚ SR) · VAROVANIE: Kritické zraniteľnosti GITLAB CE a EE

n8n security advisory (AV26-916)

Serial Number: AV26-916Date: September 11, 2026 As of September 8, 2026, n8n is affected by a vulnerability in the following product: n8n Prior to 2.37.7 Prior to 2.38.2 Prior to 1.123.76 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Release n8n@1.123.76 Release n8n@2.37.7 Release n8n@2.38.2 Overview - n8n-io/n8n - GitHub

n8n CA

tg: zranitelnost

· Cyber Centre Kanada · n8n security advisory (AV26-916)

Progress security advisory (AV26-915)

Serial Number: AV26-915Date: September 11, 2026 As of September 11, 2026, Progress Software is affected by a vulnerability in the following product: Chef Automate Prior to 4.13.520 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Critical Security Bulletin - August 2026 - Chef Automate Security Vulnerability Progress Trust Center

Progress CA

tg: zranitelnost

· Cyber Centre Kanada · Progress security advisory (AV26-915)

[Control Systems] National Instruments security advisory (AV26-914)

Serial number: AV26-914Date: September 11, 2026 As of September 10, 2026, National Instruments is affected by vulnerabilities in the following products: SystemLink Prior to or equal to 2026 Q3 Patch 1 SystemLink Server Prior to or equal to 2026 Q3 Patch 1 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available./p> Improper Access Controls in NI SystemLink Storage of Sensitive Information in Cleartext in NI…

National Instruments CA

tg: zranitelnost tp: průmyslové systémy

· Cyber Centre Kanada · [Control Systems] National Instruments security advisory (AV26-914)

[Control systems] GeoVision security advisory (AV26-913)

Serial number: AV26-913Date: Septembre 11, 2026 As of September 10, 2026, GeoVision is affected by vulnerabilities in the following product:: GV-LPC2011/LPC2211 Firmware version 1.13 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. GeoVision Security Advisory - GV-LPC-2026-09-01 Cyber Security - GeoVision

GeoVision CA

tg: zranitelnost tp: průmyslové systémy

· Cyber Centre Kanada · [Control systems] GeoVision security advisory (AV26-913)

SPOJENO PŘES CVE Risolte vulnerabilità in GitLab CE/EE

Aggiornamenti di sicurezza rilasciati per GitLab, nota piattaforma per la gestione del ciclo di sviluppo software e della collaborazione sui progetti, sanano alcune vulnerabilità, di cui 2 con gravità "critica" e 6 con gravità "alta"

KEV ✓ EPSS 0.15 CVSS 10.0 CVE-2025-14871 CVE-2026-1168 CVE-2026-13210 CVE-2026-78252 CVE-2026-79708 CVE-2026-85706 CVE-2026-87719 CVE-2026-88765 GitLab IT US

tg: zranitelnost tg: novinka v produktu

· CSIRT Itálie (ACN) · Risolte vulnerabilità in GitLab CE/EE · GitLab Security · GitLab Critical Patch Release: 19.3.2, 19.2.6, 19.1.8

[Control systems] Schneider Electric security advisory (AV26-912)

Serial number: AV26-912Date: September 11, 2026 As of September 9, 2026, Schneider Electric is affected by vulnerabilities in the following products: EcoStruxure™ IT Data Center Expert (Formerly known as StruxureWare Data Center Expert) Versions 9.1.2 and prior PowerLogic T300 Versions 2.9.8-5620 and prior The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates. Multiple Vulnerabilities on…

Schneider Electric CA

tg: zranitelnost tp: průmyslové systémy

· Cyber Centre Kanada · [Control systems] Schneider Electric security advisory (AV26-912)

SPOJENO PŘES CVE NCSC-2026-0271 [1.01] [M/H] Kwetsbaarheid verholpen in Cisco Secure Firewall Management Center

Cisco heeft een kwetsbaarheid verholpen in Cisco Secure Firewall Management Center. De kwetsbaarheid bevindt zich in de webinterface van Cisco Secure Firewall Management Center en betreft een hard-coded, statisch wachtwoord voor een laaggeprivilegieerd account. Hierdoor kunnen niet-geauthenticeerde externe aanvallers toegang verkrijgen zonder inloggegevens. Deze toegang kan leiden tot het blootstellen van gevoelige data die door het systeem wordt opgeslagen of beheerd. In combinatie met andere…

KEV ✓ · ransomware EPSS 0.11 CVSS 9.8 CVE-2026-20316 Cisco NL US

tg: zneužíváno tg: zranitelnost

· NCSC-NL · NCSC-2026-0271 [1.01] [M/H] Kwetsbaarheid verholpen in Cisco Secure Firewall Management Center · Cisco PSIRT · Cisco Secure Firewall Management Center Software Static Credential Vulnerability · Zero Day Initiative · ZDI-26-533: Cisco Secure Firewall Management Center login.cgi Authentication Bypass Vulnerability · CISA KEV · Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability (CVE-2026-20316)

SPOJENO PŘES CVE NCSC-2026-0076 [1.02] [H/H] Kwetsbaarheden verholpen in Cisco Secure Firewall Management Center

Cisco heeft kwetsbaarheden verholpen in Cisco Secure Firewall Management Center. De kwetsbaarheid met kenmerk CVE-2026-20079 bevindt zich in de webinterface van Cisco Secure Firewall Management Center. Een ongeauthenticeerde externe kwaadwillende kan de authenticatiecontroles omzeilen door een onjuist systeemproces dat bij het opstarten is aangemaakt te misbruiken. De kwaadwillende kan deze kwetsbaarheid misbruiken door speciaal geprepareerde HTTP-verzoeken naar een getroffen apparaat te sturen…

KEV ✓ · ransomware EPSS 0.76 CVE-2026-20079 CVE-2026-20131 Cisco NL CA

tg: zneužíváno tg: zranitelnost tp: ransomware

· NCSC-NL · NCSC-2026-0076 [1.02] [H/H] Kwetsbaarheden verholpen in Cisco Secure Firewall Management Center · Cyber Centre Kanada · Cisco security advisory (AV26-197) – Update 3

Rclone: PoC pubblici per lo sfruttamento delle CVE-2026-88018, CVE-2026-88044, CVE-2026-88045, CVE-2026-88016 e CVE-2026-88017

Disponibili Proof of Concept (PoC) per le CVE-2026-88018, CVE-2026-88044, CVE-2026-88045, CVE-2026-88016 e CVE-2026-88017 - già sanate dal vendor - presenti in Rclone.

EPSS 0.01 CVE-2026-88016 CVE-2026-88017 CVE-2026-88018 CVE-2026-88044 CVE-2026-88045 Rclone IT

tg: zranitelnost

· CSIRT Itálie (ACN) · Rclone: PoC pubblici per lo sfruttamento delle CVE-2026-88018, CVE-2026-88044, CVE-2026-88045, CVE-2026-88016 e CVE-2026-88017

MongoDB security advisory (AV26-911)

Serial Number: AV26-911Date: September 11, 2026 As of September 10, 2026, MongoDB is affected by vulnerabilities in the following products: Java Driver Prior to 5.11.1 Laravel MongoDB (PHP) Prior to 5.11.0 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. [PHPLARA-260] Query builder: force literal equality when 3-arg where uses '=' with an array value [JAVA-6276] Native heap use-after-free via…

MongoDB CA

tg: zranitelnost

· Cyber Centre Kanada · MongoDB security advisory (AV26-911)

HashiCorp security advisory (AV26-910)

Serial Number: AV26-910Date: September 11, 2026 As of September 10, 2026, HashiCorp is affected by vulnerabilities in the following products: Consul Prior to 2.0.4 Consul Enterprise 1.0 Prior to 1.21.18 21.0 Prior to 1.21.18 9.0 Prior to 1.21.18 consul-template Prior to 0.43.0 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. HCSEC-2026-34 - Consul vulnerable to an authorization bypass in the catalog…

HashiCorp CA

tg: zranitelnost

· Cyber Centre Kanada · HashiCorp security advisory (AV26-910)

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-42016 JFrog Artifactory Incorrect Authorization Vulnerability CVE-2026-42018 JFrog Artifactory Improper Authentication Vulnerability CVE-2026-84869 ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant…

KEV ✓ EPSS 0.01 CVE-2026-42016 CVE-2026-42018 CVE-2026-84869 JFrog ConnectWise veřejná správa US

tg: zneužíváno tg: zranitelnost tg: regulace

· CISA Advisories · CISA Adds Three Known Exploited Vulnerabilities to Catalog