Výsledky hledání

typ: zranitelnost× v celém archivu zrušit filtry

1784 karet z 1914 položek · strana 1 z 30 CZ · EN/orig

7

Linux Kernel — Four Public Local-Root Vulnerabilities

Classification: Severe, Solution: Official Fix, Exploit Maturity: Functional, CVSSv3.1: 8.8, CVEs: CVE-2026-80844, CVE-2026-81000, CVE-2026-68121, CVE-2026-74469, Summary: A coordinated disclosure has made public four Linux kernel vulnerabilities capable of local privilege escalation to root: DirtyAH6 (CVE-2026-80844), TUNderflow (CVE-2026-81000), PPPoEject (CVE-2026-68121) and DiagSpill (CVE-2026-74469). Public proof-of-concept exploits are available. The first three generally require…

EPSS 0.00 CVSS 8.8 CVE-2026-68121 CVE-2026-74469 CVE-2026-80844 CVE-2026-81000 Linux FI

tg: zranitelnost

· NCSC-FI · Linux Kernel — Four Public Local-Root Vulnerabilities

SPOJENO PŘES CVE Moxa TN-4500B Series — Out-of-Bounds Write Vulnerability

Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv4.0: 8.8, CVEs: CVE-2026-15579, Summary: Moxa has disclosed an out-of-bounds write vulnerability in the Web login functionality of TN-4500B Series Ethernet switches. The vulnerability can be exploited remotely without authentication by supplying an overly long username, potentially causing a buffer overflow and denial of service. Moxa has released firmware 2.1, which addresses the vulnerability. Affected…

EPSS 0.01 CVSS 8.8 CVE-2026-15579 Moxa FI CA FR

tg: zranitelnost tg: novinka v produktu tp: průmyslové systémy

· NCSC-FI · Moxa TN-4500B Series — Out-of-Bounds Write Vulnerability · Cyber Centre Kanada · [Control Systems] Moxa security advisory (AV26-938) · CERT-FR – avis · Vulnérabilité dans les produits Moxa (18 septembre 2026)

Linux Kernel — Multiple Security Vulnerabilities

Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8, CVEs: CVE-2026-93203, CVE-2026-93201, CVE-2026-93196, CVE-2026-93192, CVE-2026-93190, CVE-2026-93189, CVE-2026-93178, CVE-2026-93177, CVE-2026-93176, CVE-2026-93175, CVE-2026-93170, CVE-2026-93165, CVE-2026-93154, CVE-2026-93151, CVE-2026-93148, CVE-2026-93147, CVE-2026-93144, CVE-2026-93138, CVE-2026-93137, CVE-2026-93127 (+146 other associated CVEs), Summary: The Linux kernel project has disclosed a…

CVSS 9.8 Linux FI

tg: zranitelnost

· NCSC-FI · Linux Kernel — Multiple Security Vulnerabilities

IBM MQ September 2026 Security Updates

Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 10.0, CVEs: CVE-2026-5516, CVE-2026-10027, CVE-2026-10575, CVE-2026-10744, CVE-2026-10747, CVE-2026-10751, CVE-2026-10853, CVE-2026-10858, CVE-2026-11381, CVE-2026-11375, CVE-2026-11378, CVE-2026-11716, CVE-2026-11729, CVE-2026-11725, CVE-2026-11726, CVE-2026-11727, CVE-2026-11728, Summary: IBM has issued security updates for IBM MQ addressing multiple vulnerabilities, including CVE-2026-10747, a CVSS 10.0…

EPSS 0.01 CVSS 10.0 CVE-2026-10027 CVE-2026-10575 CVE-2026-10744 CVE-2026-10747 CVE-2026-10751 CVE-2026-10853 CVE-2026-10858 CVE-2026-11375 CVE-2026-11378 CVE-2026-11381 CVE-2026-11716 CVE-2026-11725 CVE-2026-11726 CVE-2026-11727 CVE-2026-11728 CVE-2026-11729 CVE-2026-5516 IBM FI

tg: zranitelnost

· NCSC-FI · IBM MQ September 2026 Security Updates

Microsoft Azure, Cloud and AI Services — Multiple Vulnerabilities

Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 10.0, CVEs: CVE-2026-62874, CVE-2026-68791, CVE-2026-69399, CVE-2026-70009, CVE-2026-69843, CVE-2026-69865, CVE-2026-70200, CVE-2026-83944, CVE-2026-77903, CVE-2026-78501, CVE-2026-83946, CVE-2026-85878, CVE-2026-85885, CVE-2026-85887, CVE-2026-85889, CVE-2026-85917, CVE-2026-87701, CVE-2026-55946, Summary: Microsoft has addressed multiple vulnerabilities affecting Azure, Microsoft Fabric, Azure AI Foundry,…

CVSS 10.0 Microsoft FI

tg: zranitelnost tp: AI

· NCSC-FI · Microsoft Azure, Cloud and AI Services — Multiple Vulnerabilities

SPOJENO PŘES CVE Google Chrome 153 — Stable Channel Security Update

Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.6, CVEs: CVE-2026-93374, CVE-2026-93372, CVE-2026-93375, CVE-2026-93382, CVE-2026-93387, CVE-2026-93373, CVE-2026-93381, CVE-2026-93379, CVE-2026-93377, CVE-2026-93380, CVE-2026-93384, CVE-2026-93383, CVE-2026-93376, CVE-2026-93378, CVE-2026-93385, CVE-2026-93386, Summary: Google released Chrome 153.0.8010.52/.53 for Windows/Mac and 153.0.8010.52 for Linux on 17 September. The update contains 16 security…

EPSS 0.00 CVSS 9.6 CVE-2026-93372 CVE-2026-93373 CVE-2026-93374 CVE-2026-93375 CVE-2026-93376 CVE-2026-93377 CVE-2026-93378 CVE-2026-93379 CVE-2026-93380 CVE-2026-93381 CVE-2026-93382 CVE-2026-93383 CVE-2026-93384 CVE-2026-93385 CVE-2026-93386 CVE-2026-93387 Google FI FR

tg: zranitelnost tg: novinka v produktu

· NCSC-FI · Google Chrome 153 — Stable Channel Security Update · CERT-FR – avis · Multiples vulnérabilités dans Google Chrome (18 septembre 2026)

Synology DSM — Multiple Critical Vulnerabilities

Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8, CVEs: CVE-2026-13684, CVE-2026-13639, CVE-2026-13673, CVE-2026-6205, CVE-2026-13635, CVE-2026-13623, CVE-2026-13666, CVE-2026-13683, Summary: Synology released a security update for DSM on 18 September 2026 addressing multiple vulnerabilities, including two CVSS 9.8 flaws that can allow remote attackers to read/write arbitrary files and cause denial of service.

EPSS 0.01 CVSS 9.8 CVE-2026-13623 CVE-2026-13635 CVE-2026-13639 CVE-2026-13666 CVE-2026-13673 CVE-2026-13683 CVE-2026-13684 CVE-2026-6205 Synology FI

tg: zranitelnost tp: DDoS

· NCSC-FI · Synology DSM — Multiple Critical Vulnerabilities

33

[Control systems] ABB security advisory (AV26-942)

Serial number: AV26-942Date: September 18, 2026 As of September 18, 2026, ABB published a security advisory to address vulnerabilities in the following product: Freelance Controller Multiple versions and models The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Freelance SECURITY - Missing Length Check CVE ID: CVE-2023-5778 ABB Cyber security alerts and notifications

CVE-2023-5778 ABB CA

tg: zranitelnost tp: průmyslové systémy

· Cyber Centre Kanada · [Control systems] ABB security advisory (AV26-942)

SPOJENO PŘES CVE SolarWinds security advisory (AV26-941)

Serial number: AV26-941Date: September 18, 2026 As of September 17, 2026, SolarWinds is affected by a vulnerability in the following product: SolarWinds Access Rights Manager Prior to 2026.2 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. SolarWinds Access Rights Manager Unauthenticated Remote Code Execution Vulnerability (CVE-2026-28326)

EPSS 0.01 CVE-2026-28326 SolarWinds CA IT

tg: zranitelnost

· Cyber Centre Kanada · SolarWinds security advisory (AV26-941) · CSIRT Itálie (ACN) · Vulnerabilità in SolarWinds

Arista Networks security advisory (AV26-940)

Serial number: AV26-940Date: September 18, 2026 As of September 9, 2026, Arista Networks is affected by vulnerabilities in the following product: EOS Multiple versions and platforms The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Security Advisory 0174 Arista Networks Advisories & Notices

Arista Networks CA

tg: zranitelnost

· Cyber Centre Kanada · Arista Networks security advisory (AV26-940)

Google security advisory (AV26-939)

Serial number: AV26-939Date: September 18, 2026 As of September 17, 2026, Google is affected by vulnerabilities in the following product: Chrome Prior to 153.0.8010.53 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. Stable Channel Update for Desktop

Google CA

tg: zranitelnost

· Cyber Centre Kanada · Google security advisory (AV26-939)

[Control systems] Advantech security advisory (AV26-937)

Serial number: AV26-937Date: September 18, 2026 As of September 4, 2026, Advantech is affected by vulnerabilities in the following products: EKI-1242EIMS Prior to or equal to V2.00.01 EKI-1242IEIMS Prior to or equal to V2.00.01 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Vulnerabilities Identified in EKI-1242EIMS/EKI-1242IEIMS (PDF) Advantech Security Advisories

Advantech CA

tg: zranitelnost tp: průmyslové systémy

· Cyber Centre Kanada · [Control systems] Advantech security advisory (AV26-937)

Grafana security advisory (AV26-936)

Serial number: AV26-936Date: September 18, 2026 As of September 17, 2026, Grafana is affected by vulnerabilities in the following product: Grafana OSS Version 12.3.0 to 12.4.10 Version 13.0.0 to 13.08 Version 13.1.0 to 13.1.5 Version 13.2.0 to 13.2.1 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Geomap MapLibre XSS Grafana Security Advisories

Grafana CA

tg: zranitelnost

· Cyber Centre Kanada · Grafana security advisory (AV26-936)

SPOJENO PŘES CVE CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-39682 Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management…

KEV ✓ EPSS 0.01 CVE-2025-39682 Linux veřejná správa US

tg: zneužíváno tg: zranitelnost tg: regulace

· CISA Advisories · CISA Adds One Known Exploited Vulnerability to Catalog · CISA KEV · Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability (CVE-2025-39682)

Risolte vulnerabilità in Grafana

Risolte molteplici vulnerabilità di cui 3 con gravità ”alta” in Grafana, nota applicazione web per la visualizzazione e l’analisi interattiva di dati. Tali vulnerabilità, qualora sfruttate, potrebbero consentire ad un utente malintenzionato di elevare i propri privilegi e/o di eseguire codice arbitrario remoto sui sistemi interessati

EPSS 0.01 CVE-2026-15815 CVE-2026-76154 CVE-2026-79656 Grafana IT

tg: zranitelnost

· CSIRT Itálie (ACN) · Risolte vulnerabilità in Grafana

NCSC-2026-0384 [1.00] [M/H] Kwetsbaarheid verholpen in Check Point's Security Management and Log Servers

Check Point heeft een kwetsbaarheid verholpen in Check Point's Security Management and Log Servers. De kwetsbaarheid betreft een stack overflow die optreedt tijdens het ongeauthenticeerde inlogproces. Een aanvaller kan deze kwetsbaarheid op afstand misbruiken om willekeurige code uit te voeren met rootrechten. Hierdoor kan de aanvaller authenticatie omzeilen en volledige controle over het systeem verkrijgen. Voor exploitatie is geen voorafgaande authenticatie vereist.

Check Point NL

tg: zranitelnost

· NCSC-NL · NCSC-2026-0384 [1.00] [M/H] Kwetsbaarheid verholpen in Check Point's Security Management and Log Servers

Risolte vulnerabilità in pgAdmin

Rilasciato aggiornamento che risolve 2 vulnerabilità di sicurezza, con gravità “critica”, in pgAdmin, nota piattaforma di amministrazione e sviluppo open source per PostgreSQL. Tali vulnerabilità, qualora sfruttate, potrebbero consentire a un utente malintenzionato di eludere i meccanismi di autenticazione e di scrivere file arbitrari sul filesystem dei sistemi interessati

EPSS 0.00 CVE-2026-86863 CVE-2026-86864 pgAdmin IT

tg: zranitelnost tp: identita

· CSIRT Itálie (ACN) · Risolte vulnerabilità in pgAdmin

Cross-Site Scripting (XSS) almacenado en TAO 2.0 de T-Systems

Stored Cross-Site Scripting (XSS) in T-Systems’ TAO 2.0 Fri, 09/18/2026 - 11:30 Aviso Affected Resources TAO 2.0 Description INCIBE has coordinated the publication of a medium-severity vulnerability affecting T-Systems’ TAO 2.0 suite, a management platform for the public sector. The vulnerability was discovered by Cayetano de Juan Úbeda.This vulnerability has been assigned the following code, CVSS v4.0 base score, CVSS vector and CWE vulnerability type:CVE-2026-92976: CVSS v4.0: 5.1 | CVSS:4.0…

EPSS 0.00 CVSS 5.1 CVE-2026-92976 T-Systems veřejná správa ES

tg: zranitelnost

· INCIBE-CERT · Cross-Site Scripting (XSS) almacenado en TAO 2.0 de T-Systems

ZDI-26-715: Linux Mint Xreader PDF File Parsing Type Confusion Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Mint Xreader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-19772.

CVSS 7.8 CVE-2026-19772 Linux Mint US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-715: Linux Mint Xreader PDF File Parsing Type Confusion Remote Code Execution Vulnerability

ZDI-26-716: Cisco Identity Services Engine createDBLink Command Injection Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-20176.

EPSS 0.01 CVSS 7.2 CVE-2026-20176 Cisco US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-716: Cisco Identity Services Engine createDBLink Command Injection Remote Code Execution Vulnerability

ZDI-26-717: Cisco Identity Services Engine AlarmMessageDiskQueue Deserialization of Untrusted Data Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-20211.

EPSS 0.01 CVSS 7.2 CVE-2026-20211 Cisco US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-717: Cisco Identity Services Engine AlarmMessageDiskQueue Deserialization of Untrusted Data Remote Code Execution Vulnerability

SPOJENO PŘES CVE ZDI-26-718: Cisco Identity Services Engine MnTRESTLivelogService XML External Entity Processing Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.9. The following CVEs are assigned: CVE-2026-20235.

EPSS 0.00 CVSS 4.9 CVE-2026-20235 Cisco US

tg: zranitelnost tp: identita

· Zero Day Initiative · ZDI-26-718: Cisco Identity Services Engine MnTRESTLivelogService XML External Entity Processing Information Disclosure Vulnerability · Cisco PSIRT · Cisco Identity Services Engine Information Disclosure Vulnerability

North Korean hackers infect thousands of devices across 100 countries as part of ‘WaterPlum’ campaign

The FBI and Defense Department partnered with Japan’s National Police Agency and law enforcement agencies in Australia and Germany on a new advisory about “WaterPlum” — a group of cyber actors allegedly stealing cryptocurrency from job applicants by posing as AI or blockchain companies.

US

tg: varování tg: zranitelnost tp: phishing tp: podvod tp: špionáž

· The Record · North Korean hackers infect thousands of devices across 100 countries as part of ‘WaterPlum’ campaign

CISA Releases Eight Industrial Control Systems Advisories

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.0: 9.9, CVEs: CVE-2026-13348, CVE-2026-31431, CVE-2026-13336, CVE-2026-13337, CVE-2025-6625, CVE-2024-4872, CVE-2024-3980, CVE-2024-3982, CVE-2024-7940, CVE-2024-7941, CVE-2026-15688, CVE-2026-86520, CVE-2026-86689, CVE-2026-77960, CVE-2026-13584, Summary: CISA released eight Industrial Control Systems (ICS) Advisories. These advisories provide timely information about current security issues,…

KEV ✓ EPSS 1.00 CVSS 9.9 CVE-2024-3980 CVE-2024-3982 CVE-2024-4872 CVE-2024-7940 CVE-2024-7941 CVE-2025-6625 CVE-2026-13336 CVE-2026-13337 CVE-2026-13348 CVE-2026-13584 CVE-2026-15688 CVE-2026-31431 CVE-2026-77960 CVE-2026-86520 CVE-2026-86689 Bransys Mitsubishi Electric Hitachi Energy Schneider Electric FI

tg: zranitelnost tp: průmyslové systémy

· NCSC-FI · CISA Releases Eight Industrial Control Systems Advisories

Unbound 1.26.1 release has a number of security fixes.

Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv4.0: 9.1, CVEs: CVE-2026-81642, CVE-2026-81634, CVE-2026-82717, CVE-2026-77955, CVE-2026-78227, CVE-2026-80225, CVE-2026-82720, CVE-2026-85501, CVE-2026-77860, Summary: Fix CVE-2026-81642, Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY. Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab for the report. Fix CVE-2026-81634, Possible heap buffer overflow during DNSSEC…

EPSS 0.01 CVSS 9.1 CVE-2026-77860 CVE-2026-77955 CVE-2026-78227 CVE-2026-80225 CVE-2026-81634 CVE-2026-81642 CVE-2026-82717 CVE-2026-82720 CVE-2026-85501 FI

tg: zranitelnost tg: novinka v produktu

· NCSC-FI · Unbound 1.26.1 release has a number of security fixes.

ISC has disclosed fourteen vulnerabilities in BIND 9

Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 7.5, CVEs: CVE-2026-19033, CVE-2026-19662, CVE-2026-19666, CVE-2026-19667, CVE-2026-19668, CVE-2026-19941, CVE-2026-75029, CVE-2026-76163, CVE-2026-77119, CVE-2026-77692, CVE-2026-78301, CVE-2026-80274, CVE-2026-81563, CVE-2026-81736, Summary: In 16 September 2026, Internet Systems Consortium disclosed fourteen vulnerabilities affecting our BIND 9 software: - CVE-2026-19033: Unauthenticated IXFR deltas…

EPSS 0.00 CVSS 7.5 CVE-2026-19033 CVE-2026-19662 CVE-2026-19666 CVE-2026-19667 CVE-2026-19668 CVE-2026-19941 CVE-2026-75029 CVE-2026-76163 CVE-2026-77119 CVE-2026-77692 CVE-2026-78301 CVE-2026-80274 CVE-2026-81563 CVE-2026-81736 ISC FI

tg: zranitelnost

· NCSC-FI · ISC has disclosed fourteen vulnerabilities in BIND 9

20

Tanium security advisory (AV26-935)

Serial Number: AV26-935Date: September 17, 2026 As of September 16, 2026, Tanium is affected by a vulnerability in the following product: Threat Response Prior to Update 15 (v4.12.317) Prior to Update 8 (v4.17.289) Prior to Update 25 (v4.9.447) The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. TAN-2026-047 - Tanium Security Advisories All Advisories - Tanium Security Advisories

Tanium CA

tg: zranitelnost

· Cyber Centre Kanada · Tanium security advisory (AV26-935)

Dell security advisory (AV26-934)

Serial number: AV26-934Date: September 17, 2026 As of September 17, 2026, Dell is affected by vulnerabilities in the following products: Dell Networking OS10 Prior to 10.6.1.3 Dell OpenManage Server Administrator (OMSA) Multiple versions and models Elastic Cloud Storage (ECS) Prior to 4.4.0.0 ObjectScale Prior to 4.4.0.0 Dell Update Package (DUP) Framework Prior to 26.07.03 Dell Wyse Management Suite Prior to 2605.0.3.683 Dell Repository Manager (DRM) Prior to 3.5.2 The Cyber Centre encourages…

Dell CA

tg: zranitelnost

· Cyber Centre Kanada · Dell security advisory (AV26-934)

SPOJENO PŘES CVE Check Point security advisory (AV26-933)

Serial number: AV26-933Date: September 17, 2026 As of September 16, 2026, Check Point is affected by a vulnerability in the following products: Security Management Server, Multi-Domain Security Management Server, Log Server and Multi-Domain Log Server R81.20 with Jumbo Hotfix Take 166 and prior R82 with Jumbo Hotfix Take 126 and prior R82.10 with Jumbo Hotfix Take 44 and prior R82.20 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary…

EPSS 0.01 CVE-2026-91843 Check Point CA IT FR

tg: zranitelnost

· Cyber Centre Kanada · Check Point security advisory (AV26-933) · CSIRT Itálie (ACN) · Risolta vulnerabilità in prodotti Check Point · CERT-FR – avis · Vulnérabilité dans les produits Check Point (17 septembre 2026)

AL26-021 - Vulnerabilities Impacting Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) - CVE-2026-20192, CVE-2026-76423 and CVE-2026-76460

Number: AL26-021Date: September 17, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested. Details The Canadian…

KEV ✓ EPSS 0.01 CVE-2026-20192 CVE-2026-76423 CVE-2026-76460 Cisco CA

tg: zneužíváno tg: zranitelnost tp: identita

· Cyber Centre Kanada · AL26-021 - Vulnerabilities Impacting Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) - CVE-2026-20192, CVE-2026-76423 and CVE-2026-76460

SPOJENO PŘES CVE Cisco security advisory (AV26-932)

Serial number: AV26-932Date: September 17, 2026 As of September 16, 2026, Cisco is affected by vulnerabilities in the following products: Cisco Secure Firewall Threat Defense (FTD) Software Prior to 7.0.10, 7.2.12, 7.4.8, 7.6.6, 7.7.13, 10.0.2 and 10.1.0 Cisco Secure Firewall Management Center (FMC) Software Prior to 7.0.10, 7.2.12, 7.4.8, 7.6.6, 7.7.13, 10.0.2 and 10.1.0 Cisco Identity Services Engine (ISE) Software Prior to 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4…

KEV ✓ EPSS 0.01 CVE-2026-76460 Cisco CA SE HU IT FR US

tg: zneužíváno tg: zranitelnost tp: identita

· Cyber Centre Kanada · Cisco security advisory (AV26-932) · CERT-SE · Cisco publicerar säkerhetsuppdateringar för flera sårbarheter · NKI Maďarsko · Riasztás Cisco szoftvereket érintő sérülékenységekről · CSIRT Itálie (ACN) · Risolte vulnerabilità in prodotti Cisco · CERT-FR – avis · Multiples vulnérabilités dans les produits Cisco (17 septembre 2026) · Cisco PSIRT · Cisco Identity Services Engine Authentication Bypass Vulnerability · CISA KEV · Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability (CVE-2026-76460)

Joomla JCE: rilevato sfruttamento CVE-2026-48907 al fine di distribuire webshell utilizzate per defacement

Questo CSIRT ha recentemente registrato, nel contesto nazionale, un aumento significativo di sfruttamenti attivi della CVE-2026-48907 – già sanata dal vendor e trattata nell’ambito dell’AL02/260615/CSIRT-ITA – ai danni di server web esposti. Tale vulnerabilità interessa il plugin Joomla Content Editor (JCE), estensione per il noto Content Management System (CMS) Joomla!.

KEV ✓ EPSS 0.78 CVE-2026-48907 Joomla JCE IT

tg: zneužíváno tg: zranitelnost tp: malware

· CSIRT Itálie (ACN) · Joomla JCE: rilevato sfruttamento CVE-2026-48907 al fine di distribuire webshell utilizzate per defacement

SPOJENO PŘES CVE LiteLLM: rilevato sfruttamento in rete della CVE-2026-59822

Rilevato lo sfruttamento in rete di una vulnerabilità, identificata tramite la CVE-2026-59822, in LiteLLM di BerriAI, server proxy impiegato come gateway per l'accesso a modelli linguistici di grandi dimensioni (LLM). La vulnerabilità consente a un attaccante remoto non autenticato di eludere i meccanismi di autenticazione e accedere agli strumenti MCP senza disporre di credenziali valide.

KEV ✓ EPSS 0.01 CVE-2026-59822 BerriAI IT US

tg: zneužíváno tg: zranitelnost tp: AI tp: identita

· CSIRT Itálie (ACN) · LiteLLM: rilevato sfruttamento in rete della CVE-2026-59822 · CISA KEV · BerriAI LiteLLM Improper Authentication Vulnerability (CVE-2026-59822)