Výsledky hledání

téma: dodavatelský řetězec× typ: zranitelnost× v celém archivu zrušit filtry

5 karet z 6 položek CZ · EN/orig

1

SPOJENO PŘES CVE TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities

Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 8.6, CVEs: CVE-2026-81573, CVE-2026-81574, CVE-2026-81572, CVE-2026-81576, CVE-2026-81575, Summary: The TRUMPF product versions listed below include a Wibu CodeMeter Runtime version that contains several vulnerabilities, e.g. potentially allowing privilege escalation.

EPSS 0.00 CVSS 8.6 CVE-2026-81572 CVE-2026-81573 CVE-2026-81574 CVE-2026-81575 CVE-2026-81576 TRUMPF WIBU-SYSTEMS Wibu-Systems výroba a průmysl FI DE

tg: zranitelnost tp: dodavatelský řetězec tp: průmyslové systémy

· NCSC-FI · TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities · CERT@VDE · TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities

1

METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4

[VDE-2026-088] The vulnerabilities found in LabX Standard versions 21.3.22 - 21.4.23 are CVE-2025-69419, CVE-2026-0915, CVE-2025-15467, CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671 and are fixed in LabX Standard v21.4.25. The vulnerabilities found in LabX Enterprise versions 21.3.22 - 21.4.23 are CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671 and are fixed in LabX Enterprise v21.4.25 All other vulnerabilities are to be fixed in the upcoming releases.

EPSS 0.48 CVE-2025-15467 CVE-2025-69419 CVE-2026-0915 CVE-2026-33186 CVE-2026-33671 CVE-2026-39821 CVE-2026-4800 METTLER TOLEDO DE

tg: zranitelnost tp: dodavatelský řetězec

· CERT@VDE · METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4

1

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 10.0, CVEs: CVE-2026-76581, CVE-2026-18431, CVE-2026-19632, CVE-2026-19598, CVE-2026-82222, Summary: Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover, and arbitrary code execution. The vulnerabilities, according to Wordfence and Patchstack,…

EPSS 0.03 CVSS 10.0 CVE-2026-18431 CVE-2026-19598 CVE-2026-19632 CVE-2026-76581 CVE-2026-82222 WordPress WPMU DEV Avada TranslatePress FI

tg: zneužíváno tg: zranitelnost tp: dodavatelský řetězec

· NCSC-FI · Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

1

1

Elastic releases detections for the Axios supply chain compromise

Elastic Security Labs is releasing an initial triage and detection rules for the Axios supply-chain compromise. We have released a detailed analysis on the Axios compromise RAT and payloads. Elastic Security Labs filed a GitHub Security Advisory to the axios repository on March 31, 2026 at 01:50 AM UTC to coordinate disclosure and ensure the maintainers and npm registry could act on the compromised versions. Introduction We are currently tracking a supply chain attack involving malicious Axios…

axios US

tg: zranitelnost tg: rozbor tp: malware tp: dodavatelský řetězec

· Elastic Security · Elastic releases detections for the Axios supply chain compromise