Výsledky hledání

typ: zranitelnost× v celém archivu zrušit filtry

1784 karet z 1914 položek · strana 8 z 30 CZ · EN/orig

60

SPOJENO PŘES CVE Microsoft fixes record 964 flaws, including 2 exploited zero-days

Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs, including 104 rated Critical and 860 rated Important, making it the company’s largest Patch Tuesday release on record. Microsoft lists 974 CVEs in its full September security release. However, 10 of those affect cloud services or involve fixes that Microsoft applies itself, leaving 964 vulnerabilities that customers need to patch. The release includes fixes for two actively exploited Windows zero-days. Both are local elevation-of…

KEV ✓ EPSS 0.01 CVSS 7.8 CVE-2026-81963 CVE-2026-85880 Microsoft US CA

tg: zneužíváno tg: zranitelnost tg: propagace

· Malwarebytes Labs · Microsoft fixes record 964 flaws, including 2 exploited zero-days · Cyber Centre Kanada · Microsoft security advisory – September 2026 monthly rollup (AV26-896) – Update 1

SPOJENO PŘES CVE New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access

An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldCrash" right after Microsoft rolled out its September 2026 Patch Tuesday security updates. [...]

EPSS 0.01 CVE-2026-69414 Microsoft US

tg: zranitelnost

· BleepingComputer · New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access · Malwarebytes Labs · ShieldBreak bypasses Microsoft’s patch for earlier Defender flaw · Microsoft Security · CVE-2026-69414 Microsoft Defender Elevation of Privilege Vulnerability

Riasztás Microsoft szoftverek 2026 szeptemberben javított sérülékenységeiről

A Nemzetbiztonsági Szakszolgálat Nemzeti Kiberbiztonsági Intézet riasztást ad ki a Microsoft szoftvereket érintő kritikus kockázati besorolású sérülékenységek kapcsán azok súlyossága, a szoftverek széleskörű elterjedtsége, valamint az egyes biztonsági hibákat érintő aktív kihasználások miatt. A Microsoft tárgyhavi biztonsági csomagjában összesen 974 különböző biztonsági hibát javított, köztük 2 db nulladik napi (zero-day) sebezhetőséget is, amelyet a Microsoft […]

Microsoft HU

tg: zneužíváno tg: zranitelnost

· NKI Maďarsko · Riasztás Microsoft szoftverek 2026 szeptemberben javított sérülékenységeiről

ZDI-26-629: Microsoft Azure Entra ID OAuth Device Code Grant Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Microsoft Azure. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.8.

CVSS 5.8 Microsoft US

tg: zranitelnost tp: identita

· Zero Day Initiative · ZDI-26-629: Microsoft Azure Entra ID OAuth Device Code Grant Information Disclosure Vulnerability

ZDI-26-630: NI LabVIEW VI File Parsing Integer Overflow Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of NI LabVIEW. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-18445.

EPSS 0.00 CVSS 3.3 CVE-2026-18445 NI US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-630: NI LabVIEW VI File Parsing Integer Overflow Information Disclosure Vulnerability

ZDI-26-631: NI LabVIEW VI File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of NI LabVIEW. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-18444.

EPSS 0.00 CVSS 3.3 CVE-2026-18444 NI US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-631: NI LabVIEW VI File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

ZDI-26-632: WatchGuard FireWare OS epm connect Stack-based Buffer Overflow Remote Code Execution Vulnerability

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-13086.

EPSS 0.00 CVSS 8.8 CVE-2026-13086 WatchGuard US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-632: WatchGuard FireWare OS epm connect Stack-based Buffer Overflow Remote Code Execution Vulnerability

ZDI-26-633: GIMP PSP File Parsing Integer Overflow Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-4153.

EPSS 0.01 CVSS 7.8 CVE-2026-4153 GIMP US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-633: GIMP PSP File Parsing Integer Overflow Remote Code Execution Vulnerability

ZDI-26-634: Flowise CSV Agent Prompt Injection Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Flowise. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2026-70477.

EPSS 0.01 CVSS 9.8 CVE-2026-70477 Flowise US

tg: zranitelnost tp: AI

· Zero Day Initiative · ZDI-26-634: Flowise CSV Agent Prompt Injection Remote Code Execution Vulnerability

ZDI-26-635: Oracle Outside In Technology PDF File Parsing Integer Overflow Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle Outside In Technology. User interaction is required to exploit this vulnerability in that the target must open a malicious file or visit a malicious page. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-60392.

EPSS 0.00 CVSS 7.8 CVE-2026-60392 Oracle US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-635: Oracle Outside In Technology PDF File Parsing Integer Overflow Remote Code Execution Vulnerability

ZDI-26-636: Oracle Outside In Technology PostScript File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle Outside In Technology. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-60412.

EPSS 0.00 CVSS 7.8 CVE-2026-60412 Oracle US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-636: Oracle Outside In Technology PostScript File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

ZDI-26-637: Oracle Outside In Technology GEM File Parsing Integer Overflow Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle Outside In Technology. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-60413.

EPSS 0.00 CVSS 7.8 CVE-2026-60413 Oracle US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-637: Oracle Outside In Technology GEM File Parsing Integer Overflow Remote Code Execution Vulnerability

ZDI-26-638: Oracle Outside In Technology WPS File Parsing Memory Corruption Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle Outside In Technology. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-60414.

EPSS 0.00 CVSS 7.8 CVE-2026-60414 Oracle US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-638: Oracle Outside In Technology WPS File Parsing Memory Corruption Remote Code Execution Vulnerability

ZDI-26-639: Oracle VirtualBox VMSVGA Heap-based Buffer Overflow Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-71116.

EPSS 0.00 CVSS 7.5 CVE-2026-71116 Oracle US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-639: Oracle VirtualBox VMSVGA Heap-based Buffer Overflow Local Privilege Escalation Vulnerability

ZDI-26-640: Oracle VirtualBox VirtioSCSI Uninitialized Memory Information Disclosure Vulnerability

This vulnerability allows local attackers to disclose sensitive information on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.3. The following CVEs are assigned: CVE-2026-71132.

EPSS 0.00 CVSS 5.3 CVE-2026-71132 Oracle US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-640: Oracle VirtualBox VirtioSCSI Uninitialized Memory Information Disclosure Vulnerability

ZDI-26-641: Oracle VirtualBox VirtioSCSI Out-Of-Bounds Read Information Disclosure Vulnerability

This vulnerability allows local attackers to disclose sensitive information on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-71114.

EPSS 0.00 CVSS 6.1 CVE-2026-71114 Oracle US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-641: Oracle VirtualBox VirtioSCSI Out-Of-Bounds Read Information Disclosure Vulnerability

ZDI-26-642: Oracle VirtualBox IDisplay Out-Of-Bounds Read Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-60159.

EPSS 0.00 CVSS 7.5 CVE-2026-60159 Oracle US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-642: Oracle VirtualBox IDisplay Out-Of-Bounds Read Local Privilege Escalation Vulnerability

ZDI-26-643: Oracle VirtualBox VMSVGA Out-Of-Bounds Read Information Disclosure Vulnerability

This vulnerability allows local attackers to disclose sensitive information on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-60162.

EPSS 0.00 CVSS 6.1 CVE-2026-60162 Oracle US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-643: Oracle VirtualBox VMSVGA Out-Of-Bounds Read Information Disclosure Vulnerability

ZDI-26-644: Oracle VirtualBox VMSVGA Race Condition Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-60155.

EPSS 0.00 CVSS 7.5 CVE-2026-60155 Oracle US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-644: Oracle VirtualBox VMSVGA Race Condition Local Privilege Escalation Vulnerability

SPOJENO PŘES CVE ZDI-26-645: Fortinet FortiSandbox write_remote_backup_to_crontab cronValue Command Injection Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fortinet FortiSandbox. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-84387.

EPSS 0.01 CVSS 7.2 CVE-2026-84387 Fortinet US FI

tg: zranitelnost

· Zero Day Initiative · ZDI-26-645: Fortinet FortiSandbox write_remote_backup_to_crontab cronValue Command Injection Remote Code Execution Vulnerability · NCSC-FI · FortiSandbox Cron Job Injection in Remote Backup

SPOJENO PŘES CVE ZDI-26-646: Progress Software Kemp LoadMaster escape_quotes Uninitialized Memory Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Progress Software Kemp LoadMaster. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-8037.

KEV ✓ EPSS 1.00 CVSS 7.2 CVE-2026-8037 Progress Software Progress veřejná správa US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-646: Progress Software Kemp LoadMaster escape_quotes Uninitialized Memory Remote Code Execution Vulnerability · CISA Advisories · CISA Adds One Known Exploited Vulnerability to Catalog · CISA KEV · Progress LoadMaster Command Injection Vulnerability (CVE-2026-8037)

ZDI-26-647: VMware Workstation VMXNET3 TSO Segmentation Integer Overflow Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of VMware Workstation. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-59346.

CVSS 7.5 CVE-2026-59346 VMware US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-647: VMware Workstation VMXNET3 TSO Segmentation Integer Overflow Local Privilege Escalation Vulnerability

SPOJENO PŘES CVE ZDI-26-624: Backblaze Personal Computer Backup bzbackup Link Following Denial-of-Service Vulnerability

This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Backblaze Personal Computer Backup. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-19820.

EPSS 0.00 CVSS 6.1 CVE-2026-19820 Backblaze US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-624: Backblaze Personal Computer Backup bzbackup Link Following Denial-of-Service Vulnerability

ZDI-26-623: Linux Kernel IPv6 Multicast Routing Use-After-Free Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8.

CVSS 8.8 Linux US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-623: Linux Kernel IPv6 Multicast Routing Use-After-Free Local Privilege Escalation Vulnerability

Security Advisory Ivanti Sentry (CVE-2026-83527)

Classification: Severe, Solution: Official Fix, Exploit Maturity: Unproven, CVSSv3.0: 8.1, CVEs: CVE-2026-83527, Summary: Ivanti has released updates for Ivanti Sentry that address one high severity vulnerability. This vulnerability impacts deployments managed by EPMM and Ivanti Neurons for MDM. We are not aware of any customers being exploited by this vulnerability at the time of disclosure. CVE-2026-83527 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS:3.0 8.1 An Authentication Bypass…

EPSS 0.01 CVSS 8.1 CVE-2026-83527 Ivanti FI

tg: zranitelnost tg: novinka v produktu tp: identita

· NCSC-FI · Security Advisory Ivanti Sentry (CVE-2026-83527)

Security Advisory - Ivanti Endpoint Manager Mobile (CVE-2026-18851)

Classification: Severe, Solution: Official Fix, Exploit Maturity: Unproven, CVSSv3.0: 8.8, CVEs: CVE-2026-18851, Summary: Ivanti has released updates for Ivanti Endpoint Manager Mobile (EPMM) which addresses one high severity vulnerability. Successful exploitation could lead to privilege escalation. We are not aware of any customers being exploited by this vulnerability at the time of disclosure. CVE-2026-18851 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS:3.0 8.8 Missing authorization in…

EPSS 0.01 CVSS 8.8 CVE-2026-18851 Ivanti FI

tg: zranitelnost

· NCSC-FI · Security Advisory - Ivanti Endpoint Manager Mobile (CVE-2026-18851)

Security Advisory Ivanti Neurons for ITSM (Multiple CVEs)

Classification: Critical, Solution: Official Fix, Exploit Maturity: Unproven, CVSSv3.1: 9.9, CVEs: CVE-2026-12744, CVE-2026-12745, CVE-2026-12651, CVE-2026-12650, CVE-2026-12648, CVE-2026-12645, CVE-2026-12646, CVE-2026-12647, Summary: Ivanti has released updates for Ivanti Neurons for ITSM (N-ITSM) which addresses High and Critical severity vulnerabilities. We are not aware of any customers being exploited by these vulnerabilities at the time of disclosure. Additionally, it’s important for…

EPSS 0.02 CVSS 9.9 CVE-2026-12645 CVE-2026-12646 CVE-2026-12647 CVE-2026-12648 CVE-2026-12650 CVE-2026-12651 CVE-2026-12744 CVE-2026-12745 Ivanti FI

tg: zranitelnost tg: novinka v produktu tp: AI

· NCSC-FI · Security Advisory Ivanti Neurons for ITSM (Multiple CVEs)

FortiOS & FortiProxy ZTNA Portal Improper Certificate Validation

Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 7.3, CVEs: CVE-2026-84393, Summary: An improper certificate validation vulnerability [CWE-295] in FortiOS and FortiProxy Agentless ZTNA portal may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the ZTNA portal and the backend destination website.

EPSS 0.00 CVSS 7.3 CVE-2026-84393 Fortinet FI

tg: zranitelnost

· NCSC-FI · FortiOS & FortiProxy ZTNA Portal Improper Certificate Validation

FortiMonitorOnSight JWT used for authentication in web GUI signed with static key

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.6, CVEs: CVE-2026-84390, Summary: An Inclusion of Sensitive Information in Source Code vulnerability [CWE-540] in FortiMonitorOnSight web portal may allow a remote unauthenticated attacker to bypass authentication via forged or reused JWT

EPSS 0.01 CVSS 9.6 CVE-2026-84390 Fortinet FI

tg: zranitelnost tp: identita

· NCSC-FI · FortiMonitorOnSight JWT used for authentication in web GUI signed with static key

Improper Authentication of FortiPAM Server

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.1, CVEs: CVE-2026-84388, Summary: An improper authentication vulnerability [CWE-287] in the Fortinet Privileged Access Agent Chrome Extension may allow a remote unauthenticated attacker to proxy a user's browser traffic through attacker controlled servers if the user visits a malicious website. Remediation for this issue required coordinated changes in two components: FortiPAM and the Fortinet…

CVSS 9.1 CVE-2026-84388 Fortinet FI

tg: zranitelnost

· NCSC-FI · Improper Authentication of FortiPAM Server

SPOJENO PŘES CVE Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability

Classification: Important, Solution: Official Fix, Exploit Maturity: Proof-of-Concept, CVSSv3.1: 7.1, CVEs: CVE-2026-20293, Summary: A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-based appliances could allow an authenticated attacker with valid credentials for a user account with the role of user or admin or an unauthenticated attacker with physical access to an affected device to bypass UEFI Secure Boot validation checks…

EPSS 0.00 CVSS 7.1 CVE-2026-20293 Cisco FI FR US

tg: zranitelnost

· NCSC-FI · Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability · CERT-FR – avis · Vulnérabilité dans les produits Cisco (09 septembre 2026) · Cisco PSIRT · Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability

SPOJENO PŘES CVE Security update available for Adobe Commerce | APSB26-146

Classification: Critical, Solution: Official Fix, Exploit Maturity: High, CVSSv3.1: 10.0, CVEs: CVE-2026-75650, Summary: Adobe has released a security update for Adobe Commerce and Magento Open Source. This update resolves a critical vulnerability that could result in arbitrary code execution. Adobe is aware of CVE-2026-75650 being exploited in the wild. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CVSS:3.1 10.0

KEV ✓ EPSS 0.02 CVSS 10.0 CVE-2026-75650 Adobe Magento obchod FI US IT FR

tg: zneužíváno tg: zranitelnost tg: rozbor tp: malware

· NCSC-FI · Security update available for Adobe Commerce | APSB26-146 · Tenable Research · StyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-day · BleepingComputer · Adobe fixes critical Magento zero-day exploited to backdoor servers · CSIRT Itálie (ACN) · Adobe: rilevato sfruttamento in rete della CVE-2026-75650 · CISA KEV · Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability (CVE-2026-75650) · CERT-FR – avis · Vulnérabilité dans les produits Adobe (08 septembre 2026)

SAP Security Patch Day - September 2026

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.0: 10.0, CVEs: CVE-2026-44756, CVE-2026-58240, CVE-2026-76969, CVE-2026-66768, CVE-2026-58243, CVE-2026-76958, CVE-2026-76967, CVE-2026-66767, CVE-2026-2332, CVE-2026-76968, CVE-2026-44766, CVE-2026-76971, CVE-2026-34477, CVE-2026-76977, CVE-2026-76960, CVE-2026-76961, CVE-2026-76959, CVE-2026-76962, CVE-2026-76963, CVE-2026-58234, Summary: On 8th of September 2026, SAP security patch day saw the release of…

CVSS 10.0 SAP FI

tg: zranitelnost

· NCSC-FI · SAP Security Patch Day - September 2026

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Classification: Critical, Solution: Official Fix, Exploit Maturity: High, CVSSv3.1: 10.0, CVEs: CVE-2026-69805, CVE-2026-58649, CVE-2026-69806, CVE-2026-69439, CVE-2026-69821, CVE-2026-69624, CVE-2026-62810, CVE-2026-69395, CVE-2026-62762, CVE-2026-62813, CVE-2026-69809, CVE-2026-69359, CVE-2026-69524, CVE-2026-69546, CVE-2026-72978, CVE-2026-57099, CVE-2026-69304, CVE-2026-69401, CVE-2026-70352, CVE-2026-62895 (+1151 other associated CVEs), Summary: Today is Microsoft's September 2026 Patch…

CVSS 10.0 Microsoft FI

tg: zneužíváno tg: zranitelnost

· NCSC-FI · Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Actively exploited MikroTik RouterOS zero-day vulnerability

Classification: Critical, Solution: Official Fix, Exploit Maturity: High, CVSSv4.0: 9.2, CVEs: CVE-2026-67278, CVE-2026-67279, CVE-2026-67281, CVE-2026-86060, CVE-2026-67277, CVE-2026-67276, Summary: MikroTik has found a security vulnerability in RouterOS and releases containing a fix have been published in all channels. There is evidence that these vulnerabilities are under active exploitation. This is an important security update. Most configurations are not at risk, but upgrading is highly…

KEV ✓ EPSS 0.01 CVSS 9.2 CVE-2026-67276 CVE-2026-67277 CVE-2026-67278 CVE-2026-67279 CVE-2026-67281 CVE-2026-86060 MikroTik FI

tg: zneužíváno tg: zranitelnost

· NCSC-FI · Actively exploited MikroTik RouterOS zero-day vulnerability

September 3, 2026: ScreenConnect® Remote Access: Guest File Transfer Advisory

Classification: Severe, Solution: Workaround, Exploit Maturity: Not Defined, CVSSv3.1: None, CVEs: , Summary: ConnectWise has identified an issue affecting file transfer behavior in ScreenConnect® Remote Access Support and Access sessions. The issue affects both Cloud and On-Premise deployments. A CVE identifier and an official fix will be issued within the week. Until the official fix is available, partners can reduce risk today by disabling the ability for technicians to transfer files. This…

ConnectWise FI

tg: zranitelnost

· NCSC-FI · September 3, 2026: ScreenConnect® Remote Access: Guest File Transfer Advisory

N-central 2026.3 Hotfix 4 – CVE-2026-86218 & Hotfix 3 - CVE-2026-86206 and CVE-2026-86207

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv4.0: 10.0, CVEs: CVE-2026-86206, CVE-2026-86207, CVE-2026-86218, Summary: Hotfix 4 includes security fixes for CVE-2026-86218 which is a critical-CVSS-rated vulnerability that could allow for pre-authenticated remote code execution on the N-central server. Hotfix 3 includes security fixes for CVE-2026-86206 and CVE-2026-86207 which are high-CVSS-rated vulnerabilities that could allow an unauthorized party to…

KEV ✓ EPSS 0.01 CVSS 10.0 CVE-2026-86206 CVE-2026-86207 CVE-2026-86218 N-able FI

tg: zranitelnost tg: novinka v produktu

· NCSC-FI · N-central 2026.3 Hotfix 4 – CVE-2026-86218 & Hotfix 3 - CVE-2026-86206 and CVE-2026-86207

SPOJENO PŘES CVE VMSA-2026-0007: VMware Workstation and Fusion updates address integer-overflow and buffer overflow vulnerabilities (CVE-2026-59346, CVE-2026-59347)

Classification: Critical, Solution: Official Fix, Exploit Maturity: High, CVSSv3.1: 9.3, CVEs: CVE-2026-59346, CVE-2026-59347, Summary: An integer-overflow and a buffer-overflow vulnerabilities in VMware Workstation and Fusion were privately reported to Broadcom. Updates are available to remediate these vulnerabilities in affected Broadcom products. VMXNET3 integer-overflow vulnerability (CVE-2026-59346) CVSSv3.1: 9.3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H A malicious actor with local…

CVSS 9.3 CVE-2026-59346 CVE-2026-59347 Broadcom VMware FI FR IT

tg: zranitelnost

· NCSC-FI · VMSA-2026-0007: VMware Workstation and Fusion updates address integer-overflow and buffer overflow vulnerabilities (CVE-2026-59346, CVE-2026-59347) · CERT-FR – avis · Multiples vulnérabilités dans les produits VMware (04 septembre 2026) · CSIRT Itálie (ACN) · Risolte vulnerabilità in VMware Workstation e Fusion

Multiples vulnérabilités dans Microsoft Azure (09 septembre 2026)

De multiples vulnérabilités ont été découvertes dans Microsoft Azure. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et une atteinte à la confidentialité des données.

EPSS 0.01 CVE-2026-62895 CVE-2026-69854 CVE-2026-77909 CVE-2026-81349 CVE-2026-83948 Microsoft FR

tg: zranitelnost

· CERT-FR – avis · Multiples vulnérabilités dans Microsoft Azure (09 septembre 2026)

SPOJENO PŘES CVE Multiples vulnérabilités dans Microsoft Windows (09 septembre 2026)

De multiples vulnérabilités ont été découvertes dans Microsoft Windows. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance. Microsoft indique que les vulnérabilités CVE-2026-81963...

KEV ✓ EPSS 0.01 CVE-2026-81963 Microsoft FR US

tg: zneužíváno tg: zranitelnost

· CERT-FR – avis · Multiples vulnérabilités dans Microsoft Windows (09 septembre 2026) · Microsoft Security · CVE-2026-81963 Windows Update Stack Elevation of Privilege Vulnerability · CISA KEV · Microsoft Windows Link Following Vulnerability (CVE-2026-81963)

Multiples vulnérabilités dans Microsoft .Net (09 septembre 2026)

De multiples vulnérabilités ont été découvertes dans Microsoft .Net. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

EPSS 0.02 CVE-2026-58649 CVE-2026-69304 CVE-2026-69439 CVE-2026-69522 CVE-2026-69806 CVE-2026-71328 Microsoft FR

tg: zranitelnost

· CERT-FR – avis · Multiples vulnérabilités dans Microsoft .Net (09 septembre 2026)

Multiples vulnérabilités dans Xen (09 septembre 2026)

De multiples vulnérabilités ont été découvertes dans Xen. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, un déni de service à distance et un contournement de la politique de sécurité.

EPSS 0.00 CVE-2026-62437 CVE-2026-79602 CVE-2026-79603 CVE-2026-79604 CVE-2026-79605 CVE-2026-79606 Xen FR

tg: zranitelnost

· CERT-FR – avis · Multiples vulnérabilités dans Xen (09 septembre 2026)

SPOJENO PŘES CVE Multiples vulnérabilités dans les produits Ivanti (09 septembre 2026)

De multiples vulnérabilités ont été découvertes dans les produits Ivanti. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un contournement de la politique de sécurité.

EPSS 0.01 CVE-2026-18851 CVE-2026-83527 Ivanti FR CA

tg: zranitelnost

· CERT-FR – avis · Multiples vulnérabilités dans les produits Ivanti (09 septembre 2026) · Cyber Centre Kanada · Ivanti security advisory (AV26-897)

Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities

Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."Microsoft notes that 2 of the vulnerabilities disclosed this month have been exploited in the wild:CVE-2026-81963 affects Windows Update Stack. CVE-2026-81963 is a elevation of privilege vulnerability associated with Improper Link Resolution Before File Access ('Link Following') and Improper Access Control and…

Microsoft US

tg: zneužíváno tg: zranitelnost

· Cisco Talos · Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities