This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-80161.
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-81977.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Pro DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81988.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81981.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81976.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81973.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Photoshop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-75771.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Photoshop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-75863.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Photoshop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-75862.
Le 06 août 2026, Metabase a publié un avis de sécurité concernant une vulnérabilité critique permettant à un attaquant non authentifié de provoquer une injection SQL (SQLi) dans la base de donnée de l'application Metabase. Cette injection SQL permet d’obtenir les droits administrateur de...
Une vulnérabilité a été découverte dans Microsoft Edge. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance. Microsoft indique que la vulnérabilité CVE-2026-85046 est activement exploitée.
De multiples vulnérabilités ont été découvertes dans Google Android. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et une atteinte à la confidentialité des données.
De multiples vulnérabilités ont été découvertes dans MongoDB Server. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.
De multiples vulnérabilités ont été découvertes dans les produits Palo Alto Networks. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une injection de code indirecte à distance (XSS).
De multiples vulnérabilités ont été découvertes dans Moodle. Certaines d'entre elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, une injection de code indirecte à distance (XSS) et une injection de requêtes illégitimes par rebond (CSRF).
De multiples vulnérabilités ont été découvertes dans les produits Veeam. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.
De multiples vulnérabilités ont été découvertes dans HPE Aruba Networking ClearPass Policy Manager. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks. [...]
The Carnegie Mellon University CERT Coordination Center (CERT/CC) is warning that Skullcandy Dime 3 wireless earbuds accept Bluetooth pairing requests from nearby unpaired devices without requiring user interaction. [...]
Serial number: AV26-023Date: January 13, 2026Updated: September 9, 2026 On January 13, 2026, Fortinet published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following: FortiFone 7.0 – versions 7.0.0 to 7.0.1 FortiFone 3.0 – versions 3.0.13 to 3.0.23 FortiOS 7.6 – versions 7.6.0 to 7.6.3 FortiOS 7.4 – versions 7.4.0 to 7.4.8 FortiOS 7.2 – versions 7.2.0 to 7.2.11 FortiOS 7.0 – versions 7.0.0 to 7.0.17 FortiOS 6.4 – versions 6.4.0 to…
On September 16, 2026, the Cisco Product Security Incident Response Team (PSIRT) will publish advisories to disclose security vulnerability information along with fixed software releases for the following Cisco products: BroadWorks CommPilot Application Software Identity Services Engine (ISE) (security hardening release) Nexus Dashboard (security hardening release) Secure Firewall Adaptive Security Appliance (ASA) (security hardening release) Secure Firewall Management Center (FMC) (security…
Serial Number: AV26-901Date: September 9, 2026 As of September 4, 2026, misp is affected by vulnerabilities in the following product: misp Prior to or equal to 2.5.45 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. Authorise the sharing group whenever one is submitted
Serial Number: AV26-900Date: September 9, 2026 As of September 8, 2026, NVIDIA is affected by vulnerabilities in the following product: Triton Inference Server Versions 0.0 to 26.03 Versions 0.0 to 26.06 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Security Bulletin: Triton Inference Server - September 2026 NVIDIA Product Security
Ivanti ha rilasciato aggiornamenti di sicurezza che sanano 10 vulnerabilità, di cui 6 con gravità "critica" e 4 con gravità "alta" in alcuni prodotti. Tali vulnerabilità potrebbero consentire a un attaccante remoto, in alcuni casi non autenticato, di eseguire codice arbitrario sui sistemi interessati, di eludere i meccanismi di autorizzazione o di ottenere privilegi elevati.
Adobe heeft meerdere kwetsbaarheden verholpen in Adobe Illustrator. De kwetsbaarheden bevinden zich in de wijze waarop Adobe Illustrator bestanden verwerkt. Eén kwetsbaarheid betreft een onjuiste autorisatie die het mogelijk maakt dat een aanvaller willekeurige code uitvoert wanneer een gebruiker een kwaadaardig bestand opent. Een andere kwetsbaarheid betreft onjuiste inputvalidatie, waardoor eveneens code-uitvoering mogelijk is bij het openen van speciaal vervaardigde bestanden. Daarnaast is…
Adobe heeft meerdere kwetsbaarheden verholpen in Adobe Experience Manager. Adobe Experience Manager bevat meerdere Cross-Site Scripting (XSS) kwetsbaarheden, waaronder DOM-based en stored XSS. Deze kwetsbaarheden stellen een aanvaller in staat om kwaadaardige JavaScript-code te injecteren en uit te voeren binnen de browsers van gebruikers die een speciaal vervaardigde webpagina bezoeken of met deze pagina's interacteren. De stored XSS kwetsbaarheden ontstaan door onvoldoende input sanitatie en…
Serial Number: AV26-899Date: September 9, 2026 Commvault security advisory (AV26-899) As of September 8, 2026, Commvault is affected by vulnerabilities in the following product: Commvault Cloud 36.0 Prior to 11.36.123 40.0 Prior to 11.40.72 44.0 Prior to 11.44.20 46.0 Prior to 11.46.20 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. Commvault Cloud Security Advisories
Adobe heeft meerdere kwetsbaarheden verholpen in Adobe ColdFusion. De kwetsbaarheden in Adobe ColdFusion omvatten onder andere een stored Cross-Site Scripting (XSS) waarbij een aanvaller met lage privileges kwaadaardige scripts kan injecteren in formulier velden die vervolgens uitgevoerd worden in de browser van een gebruiker. Daarnaast is er een kwetsbaarheid in de dynamische code-evaluatie die het mogelijk maakt voor een aanvaller met lage privileges om zonder gebruikersinteractie…
Citrix har publicerat information om en kritisk sårbarhet som påverkar Citrix NetScaler ADC och NetScaler Gateway. Sårbarheten, CVE-2026-19490, har fått CVSS v.4-klassning på 9.3. [1, 2]
Serial Number: AV26-898Date: September 9, 2026 As of September 8, 2026, Fortinet is affected by vulnerabilities in the following products: FortiOS 7.6 Versions 7.6.1 to 7.6.6 FortiProxy 7.6 Versions 7.6.2 to 7.6.6 FortiPAM Chrome Extension 8.0 All versions FortiPAM Chrome Extension 7.4 All versions FortiSandbox 5.0 Versions 5.0.0 to 5.0.5 FortiSandbox 4.4 Versions 4.4.0 to 4.4.8 FortiSandbox Cloud 5.0 Versions 5.0.4 to 5.0.5 FortiSandbox PaaS 5.0 Versions 5.0.4 to 5.0.5 FortiMonitorOnSight 7.2…
Adobe heeft meerdere kwetsbaarheden verholpen in Adobe Commerce. De kwetsbaarheden betreffen onder andere stored Cross-Site Scripting (XSS) waarbij aanvallers kwaadaardige JavaScript-code kunnen injecteren in formulier velden binnen de applicatie. Deze code wordt uitgevoerd in de context van de browser van het slachtoffer en kan ongeautoriseerde acties uitvoeren, zoals het kapen van sessies of het escaleren van privileges. Daarnaast zijn er meerdere incorrecte autorisatieproblemen…
Adobe heeft meerdere kwetsbaarheden verholpen in Adobe Photoshop Desktop. De kwetsbaarheden bevinden zich in de verwerking van speciaal vervaardigde bestanden binnen Adobe Photoshop Desktop. Deze omvatten out-of-bounds write, integer overflow of wraparound, uncontrolled search path element en heap-based buffer overflow. Door het openen van kwaadaardig opgemaakte bestanden kan een aanvaller code uitvoeren met de privileges van de gebruiker die de applicatie draait. De kwetsbaarheden kunnen…
Ivanti heeft een kwetsbaarheid verholpen in Ivanti Endpoint Manager Mobile. De kwetsbaarheid betreft een ontbrekende autorisatiecontrole in Ivanti Endpoint Manager Mobile versies ouder dan 12.10.0.0, 12.9.0.2 en 12.8.0.4. Hierdoor kunnen geauthenticeerde gebruikers hun privileges verhogen tot een administratief niveau.
Ivanti heeft meerdere kwetsbaarheden verholpen in Ivanti Neurons for ITSM. Een kwaadwillende kan de kwetsbaarheden misbruiken om ongeautoriseerde acties uit te voeren, waaronder het uitvoeren van willekeurige code op de server.
Ivanti heeft een kwetsbaarheid verholpen in Sentry versies voorafgaand aan R10.8.2, R10.7.3 en R10.6.4. De kwetsbaarheid betreft een authenticatie-bypass die het mogelijk maakt voor externe aanvallers zonder authenticatie om administratieve toegang tot het systeem te verkrijgen. Deze kwetsbaarheid treft meerdere releases van het Sentry-platform en kan leiden tot ongeautoriseerde controle over administratieve functies.
On 8 September 2026, as part of its September Security Patch Day, SAP released Security Notes addressing two critical vulnerabilities affecting a broad range of SAP products[3]. The most severe, CVE-2026-44756 (CVSS 10.0), is a memory corruption vulnerability in SAP Extended Passport (EPP) processing, nicknamed "OVERPASS" by the Onapsis Research Labs (ORL), which discovered and responsibly disclosed it[3]. The second, CVE-2026-58240 (CVSS 9.8), nicknamed "S4GET", is a missing authentication…
Aggiornamenti di sicurezza Google sanano 104 vulnerabilità, di cui 31 con gravità “critica” e 73 con gravità “alta”, nei componenti Android. Tali vulnerabilità, qualora sfruttate, potrebbero consentire di eseguire codice arbitrario, elevare i privilegi, accedere a informazioni riservate o compromettere la disponibilità del servizio sui dispositivi interessati.
SAP heeft kwetsbaarheden verholpen in SAP Extended Passport Protocol (EPP) processing library, SAP NetWeaver Message Server, @sap/cds-mtxs NPM library, SAP GUI for Java, SAP ABAP Development Tools voor SAP NetWeaver AS ABAP, SAP Integration Suite, SAP NetWeaver Business Client, SAP Web Dispatcher, Internet Communication Manager, SAP Content Server, SAP S/4HANA Intercompany Matching and Reconciliation module, en SAP Manufacturing Integration and Intelligence. De kwetsbaarheid met kenmerk CVE…
Rilasciati aggiornamenti di sicurezza Fortinet che sanano alcune vulnerabilità, di cui una con gravità “critica” e una con gravità “alta”, in diversi prodotti.
Adobe ha rilasciato aggiornamenti di sicurezza per risolvere molteplici vulnerabilità, di cui 6 con gravità “critica” e 42 con gravità “alta”, in numerosi prodotti.
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-25249 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability CVE-2026-19490 Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability CVE-2026-87491 Google Chromium V8 Out of Bounds Write Vulnerability CVE-2026-20079 Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel…
Gli aggiornamenti di sicurezza rilasciati da N-able sanano tre vulnerabilità, di cui una con gravità "critica" ed una con gravità "alta", in N-central, piattaforma per il monitoraggio e la gestione remota delle infrastrutture IT. Tra queste si segnala la CVE-2026-86218 che risulta essere attivamente sfruttata in rete.
Fortinet heeft kwetsbaarheden verholpen in FortiAnalyzer, FortiOS, FortiPAM, FortiProxy, FortiSandbox, FortiManager, FortiManager Cloud, FortiMonitorOnSight, FortiClient Windows, FortiSIEM en FortiSOAR. De kwetsbaarheden betreffen verschillende typen fouten in meerdere Fortinet-producten. De ernstigste kwetsbaarheid met kenmerk CVE-2026-26084 heeft een CVSS-score van 8,9. Het betreft een autorisatiekwetsbaarheid in Fortinet FortiSandbox waardoor een ongeauthenticeerde kwaadwillende via speciaal…