Výsledky hledání

výrobce: Apache× v celém archivu zrušit filtry

36 karet z 37 položek CZ · EN/orig

1

Risolte vulnerabilità in Apache NiFi

Apache Software Foundation ha rilasciato aggiornamenti di sicurezza per Apache NiFi e Apache NiFi Registry, piattaforme open source per la gestione, l'elaborazione e il versionamento dei flussi di dati, che sanano alcune vulnerabilità, di cui 2 con gravità "alta". Tali vulnerabilità potrebbero consentire a un attaccante di effettuare operazioni sui file al di fuori della directory prevista, manipolare dati, eludere misure di sicurezza e, tramite richieste HTTP opportunamente predisposte, comprom

EPSS 0.00 CVE-2026-70469 CVE-2026-87976 Apache IT

tg: zranitelnost

· CSIRT Itálie (ACN) · Risolte vulnerabilità in Apache NiFi

1

Multiples vulnérabilités dans Apache Zookeeper (16 septembre 2026)

De multiples vulnérabilités ont été découvertes dans Apache Zookeeper. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, une atteinte à l'intégrité des données et un contournement de la politique de sécurité.

EPSS 0.00 CVE-2026-59739 CVE-2026-59969 CVE-2026-79993 CVE-2026-84439 CVE-2026-84501 Apache FR

tg: zranitelnost

· CERT-FR – avis · Multiples vulnérabilités dans Apache Zookeeper (16 septembre 2026)

1

Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon

Research by: Amit Yardeni Key Points A Chinese-speaking actor is now targeting Brazil. Check Point Research has uncovered a sustained campaign against Brazilian organizations, primarily government and educational institutions since mid-2025. We dubbed this group Gambling Goblin: a Chinese-speaking cybercrime cluster connected to a previously documented group, Earth Berberoka, that targeted gambling sites across Asia. It marks a shift from Brazil’s usual home-grown banking-trojan threats to a…

Apache veřejná správa školství IL

tg: varování tg: rozbor tp: malware tp: phishing tp: podvod

· Check Point Research · Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon

2

NCSC-2026-0332 [1.00] [M/H] Kwetsbaarheden verholpen in Apache CloudStack

Apache heeft meerdere kwetsbaarheden verholpen in Apache CloudStack, specifiek in versies 4.12.0.0 tot en met 4.22.1.0. De kwetsbaarheden betreffen onder andere OS Command Injection in de NAS backup provider plugin, Server-Side Request Forgery (SSRF) in verschillende modules zoals metalink mirror URL resolutie en webhook, onvoldoende toegangscontrole in userdata-gerelateerde API's, OAuth en LDAP authenticatie plugins, en improper privilege management in de two-factor authentication plugin.…

Apache NL

· NCSC-NL · NCSC-2026-0332 [1.00] [M/H] Kwetsbaarheden verholpen in Apache CloudStack

Apache Tomcat vulnerabilities

Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8, CVEs: CVE-2026-73180, CVE-2026-68763, CVE-2026-68569, CVE-2026-65927, CVE-2026-65905, CVE-2026-65637, CVE-2026-32990, CVE-2026-65183, CVE-2026-65182, CVE-2026-68525, CVE-2026-66422, Summary: CVE-2026-73180 : Apache Tomcat: Authenticated WebSocket session survives end of HTTP session CVE-2026-68763 : Apache Tomcat: DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset CVE-2026-68569 …

EPSS 0.01 CVSS 9.8 CVE-2026-32990 CVE-2026-65182 CVE-2026-65183 CVE-2026-65637 CVE-2026-65905 CVE-2026-65927 CVE-2026-66422 CVE-2026-68525 CVE-2026-68569 CVE-2026-68763 CVE-2026-73180 Apache FI

· NCSC-FI · Apache Tomcat vulnerabilities

3

Risolte vulnerabilità in prodotti Apache

Rilevate 10 vulnerabilità di sicurezza in prodotti Apache, di cui 7 con gravità "critica" e 3 con gravità "alta". Tali vulnerabilità, qualora sfruttate, potrebbero consentire a un utente malintenzionato di eludere i meccanismi di autenticazione e di sicurezza sui sistemi interessati.

EPSS 0.01 CVE-2026-65182 CVE-2026-65183 CVE-2026-65637 CVE-2026-65905 CVE-2026-65927 CVE-2026-66422 CVE-2026-68525 CVE-2026-68569 CVE-2026-68763 CVE-2026-73180 Apache IT

· CSIRT Itálie (ACN) · Risolte vulnerabilità in prodotti Apache

Apache CloudStack LTS Security Releases 4.20.3.1 and 4.22.1.1

Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.1, CVEs: CVE-2026-62440, CVE-2026-61398, CVE-2026-61397, CVE-2026-59780, CVE-2026-59657, CVE-2026-59655, CVE-2026-59085, CVE-2026-66721, CVE-2026-65613, CVE-2026-68745, CVE-2026-66722, CVE-2026-61422, CVE-2026-61399, CVE-2026-59799, CVE-2026-66797, CVE-2026-61400, CVE-2026-50112, CVE-2026-59654, Summary: CVE-2026-62440 9.1 Apache CloudStack: Improper access control in Kubernetes Service (CKS) cluster…

CVSS 9.1 Apache FI

· NCSC-FI · Apache CloudStack LTS Security Releases 4.20.3.1 and 4.22.1.1

Multiples vulnérabilités dans Apache Tomcat (26 août 2026)

De multiples vulnérabilités ont été découvertes dans Apache Tomcat. Elles permettent à un attaquant de provoquer un déni de service à distance et un contournement de la politique de sécurité.

EPSS 0.01 CVE-2026-32990 CVE-2026-65182 CVE-2026-65183 CVE-2026-65637 CVE-2026-65905 CVE-2026-65927 CVE-2026-66299 CVE-2026-66422 CVE-2026-68525 CVE-2026-68569 CVE-2026-68763 CVE-2026-73180 Apache FR

· CERT-FR – avis · Multiples vulnérabilités dans Apache Tomcat (26 août 2026)

1

1

NCSC-2026-0312 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle Financial Services

Oracle heeft kwetsbaarheden verholpen in diverse Financial Services Enterprise modules. De kwetsbaarheden bevinden zich in Third Party producten, zoals Apache Kafka, Log4j en het Spring Framework, waarvoor eerder door de ontwikkelaars updates zijn uitgebracht. Deze updates zijn nu verwerkt door Oracle in de Financial Services modules die gebruik maken van deze Third Party producten. Een kwaadwillende kan de kwetsbaarheden misbruiken om toegang te krijgen tot gevoelige gegevens, een Denial-of…

Oracle Apache Log4j Spring finance NL

· NCSC-NL · NCSC-2026-0312 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle Financial Services

1

SPOJENO PŘES CVE HTTP/2 Bomb CVE-2026-49975

CVSSv3 Score: 5.8 CVE-2026-49975Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67. Revised on 2026-08-12 00:00:00

EPSS 0.34 CVSS 5.8 CVE-2026-49975 Apache US

· Fortinet PSIRT · HTTP/2 Bomb CVE-2026-49975 · Microsoft Security · CVE-2026-49975 Apache HTTP Server: mod_http2 denial of service

4

2

2

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-9198 IBM Langflow Code Injection Vulnerability CVE-2026-18556 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability CVE-2026-34486 Apache Tomcat Missing Encryption of Sensitive Data Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the…

KEV ✓ EPSS 0.99 CVE-2026-18556 CVE-2026-34486 CVE-2026-9198 IBM N-able Apache veřejná správa US

· CISA Advisories · CISA Adds Three Known Exploited Vulnerabilities to Catalog

10

1

4

2