Sårbarhetsflöden

Uppdateras var 300 sekund(er). Senast uppdaterad: 2026-06-07 01:15:19 CEST. Visar 10 artiklar per källa från: NVD (National Vulnerability Database), SecurityWeek Vulnerabilities, CERT-SE, CISA KEV-katalog, Microsoft MSRC, Cisco PSIRT, Fortinet PSIRT, Palo Alto Networks Advisories, The Hacker News, Threatpost, Dark Reading. Tidszon: Europe/Stockholm.

Källfilter (klicka för att visa/dölja)
Vy: Kompakt visar endast titel/källa/tid.
Rensa filter
Mottaget igår
The Hacker News

OpenAI has begun rolling out a new Lockdown Mode to ChatGPT for eligible personal accounts to reduce the risk of data exfiltration arising from prompt injection attacks. The feature is primarily designed for people and organizations that…

Publicerad: 2026-06-06 15:36:57 CEST
SecurityWeek Vulnerabilities

Raising $59 million to date, Opal also announced five senior leadership appointments. The post Opal Security Raises $23 Million for AI-Native Identity Governance appeared first on SecurityWeek.

Publicerad: 2026-06-06 12:15:00 CEST
The Hacker News

A researcher has reverse-engineered the iOS SDK that Bright Data embeds in consumer apps and documented how it turns devices, including always-on smart TVs, into exit nodes that relay web-scraping traffic for a data business Bright Data…

Publicerad: 2026-06-06 10:29:05 CEST
The Hacker News

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity security flaw impacting SolarWinds Serv-U multi-protocol file server software to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence…

CVE-2026-28318 CVSS 7.5
Publicerad: 2026-06-06 10:14:31 CEST
The Hacker News

Two things landed within days of each other this week. A security startup reported 21 previously unknown vulnerabilities in FFmpeg, the media library inside almost everything that touches video, all of them found by an autonomous AI agent.…

Publicerad: 2026-06-06 09:28:30 CEST
The Hacker News

Microsoft's GitHub repositories have become the latest to fall victim to the ongoing Miasma self-replicating supply chain attack campaign. The incident impacted 73 Microsoft repositories across four of its GitHub organizations, including…

Publicerad: 2026-06-06 08:58:04 CEST
Mottaget denna vecka
Cisco PSIRT

A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system. This vulnerability…

CVE-2026-20127 CVE-2026-20182 CVE-2026-20245
Publicerad: 2026-06-05 23:23:51 CEST
Dark Reading

Threat actors are taking advantage of Internet-exposed tank gauges by breaching gas stations, opening the door to disruption.

Publicerad: 2026-06-05 21:04:36 CEST
The Hacker News

Multiple software supply chain attacks have hit the npm ecosystem, with threat actors using both malicious and poisoned versions of over 50 legitimate packages to distribute a Rust-based information stealer and a self-spreading worm,…

Publicerad: 2026-06-05 20:05:30 CEST
The Hacker News

Arabic-speaking users have emerged as the target of a new Android spyware codenamed Asin, according to findings from ESET. The Slovakian cybersecurity company said it first detected the malware spread via multiple campaigns in early 2025,…

Publicerad: 2026-06-05 16:53:40 CEST
Dark Reading

The White House's executive order establishes voluntary framework for early government access to frontier models while investing in federal security.

Publicerad: 2026-06-05 15:00:00 CEST
CERT-SE

I veckans brev hittar du läsning om “HTTP/2 Bomb”, en metod för överbelastningsangrepp som kombinerar flera tekniker för att göra servrar otillgängliga. Du hittar även information om EU-kommissionens nya åtgärdspaket för att minska…

Publicerad: 2026-06-05 14:50:00 CEST
SecurityWeek Vulnerabilities

The ShinyHunters extortion group leaked roughly 234 GB of data allegedly stolen from the dental benefits administrator. The post Hackers Leak DentaQuest Information Impacting 2.6 Million appeared first on SecurityWeek.

Publicerad: 2026-06-05 13:33:27 CEST
SecurityWeek Vulnerabilities

Over 100 bugs are critical or high-severity, mainly use-after-free and insufficient validation of untrusted input flaws. The post Chrome 149 Patches 429 Vulnerabilities appeared first on SecurityWeek.

Publicerad: 2026-06-05 13:13:57 CEST
SecurityWeek Vulnerabilities

Experts commented on the EO’s voluntary nature, the balance between innovation and security, and potential implementation gaps. The post Industry Reactions to New Trump AI Cybersecurity Executive Order: Feedback Friday appeared first on SecurityWeek.

Publicerad: 2026-06-05 12:24:56 CEST
SecurityWeek Vulnerabilities

Posing as recruiters on online platforms, Chinese intelligence officers target personnel with access to classified or privileged information. The post Five Eyes: Chinese Spies Target Government, Military Staff With Fake Job Opportunities appeared first on SecurityWeek.

Publicerad: 2026-06-05 10:46:44 CEST
SecurityWeek Vulnerabilities

The company detected a network intrusion in March and an investigation showed that some files were stolen during the attack. The post Nightclub Giant RCI Says Data Breach Affects 40,000 Individuals appeared first on SecurityWeek.

Publicerad: 2026-06-05 09:24:08 CEST
SecurityWeek Vulnerabilities

The vulnerability is tracked as CVE-2026-20245 and it can allow arbitrary command execution as root, but no patch yet. The post Cisco Warns of 7th SD-WAN Zero-Day Exploited in 2026 appeared first on SecurityWeek.

CVE-2026-20245
Publicerad: 2026-06-05 07:47:09 CEST
CISA KEV-katalog

SolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-Encoding: deflate header to crash the Serv-U service without authentication. | Åtgärd: Apply…

CVE-2026-28318
Publicerad: 2026-06-05 02:00:00 CEST
Dark Reading

Like Shai-Hulud, the campaign targets developers to steal credentials and reuses them to propagate across the software supply channel.

Publicerad: 2026-06-04 23:47:06 CEST
Dark Reading

Gartner analysts issued a call to action to bolster defenses against several emerging critical threats, such as deepfakes and prompt injections.

Publicerad: 2026-06-04 23:08:16 CEST
SecurityWeek Vulnerabilities

As AI agents, machine identities, and third-party applications multiply across enterprises, Offroad is betting autonomous security agents can restore control over an increasingly unmanageable identity landscape. The post Offroad Emerges…

Publicerad: 2026-06-04 17:05:45 CEST
Dark Reading

Python scripts were used to test malware against endpoint detection and response agents from Sophos, CrowdStrike, and Windows Defender.

Publicerad: 2026-06-03 23:34:07 CEST
Cisco PSIRT

A vulnerability in the web-based user interface of Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. Cisco has addressed this vulnerability in the Webex Meetings…

CVE-2026-20233
Publicerad: 2026-06-03 18:00:00 CEST
Cisco PSIRT

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request…

CVE-2026-20230
Publicerad: 2026-06-03 18:00:00 CEST
Cisco PSIRT

A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to load arbitrary files from remote locations into an active user session on an affected device, possibly leading to browser-based attacks. This vulnerability…

CVE-2026-20175
Publicerad: 2026-06-03 18:00:00 CEST
Fortinet PSIRT

CVSSv3 Score: 7.9 Linux kernel is impacted by CVE-2026-43284 and CVE-2026-43500 which chained together create the Dirty Frag vulnerability.CVE-2026-43284In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid…

CVE-2026-43284 CVE-2026-43500 CVSS 3
Publicerad: 2026-06-03 09:00:00 CEST
CISA KEV-katalog

Mirasvit Full Page Cache Warmer contains a deserialization of untrusted data vulnerability that could allow unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie.…

CVE-2026-45247
Publicerad: 2026-06-03 02:00:00 CEST
CISA KEV-katalog

Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent feature. | Åtgärd: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance…

CVE-2022-0492
Publicerad: 2026-06-02 02:00:00 CEST
CISA KEV-katalog

Android Framework contains an integer overflow vulnerability that allows for code execution that could allow for local privilege escalation. | Åtgärd: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for…

CVE-2025-48595
Publicerad: 2026-06-02 02:00:00 CEST
CISA KEV-katalog

Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized…

CVE-2024-21182
Publicerad: 2026-06-01 02:00:00 CEST
Mottaget tidigare
CERT-SE

I veckans läsning finns ett urval av nyheter, analyser och rapporter inom cybersäkerhetsområdet från veckan som har gått.

Publicerad: 2026-05-29 14:49:00 CEST
CISA KEV-katalog

Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection. | Åtgärd: Apply mitigations per vendor instructions, follow…

CVE-2026-0257
Publicerad: 2026-05-29 02:00:00 CEST
Cisco PSIRT

May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability was disclosed in February 2026. This…

CVE-2026-20182
Publicerad: 2026-05-28 00:13:44 CEST
CISA KEV-katalog

Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on…

CVE-2026-48027
Publicerad: 2026-05-27 02:00:00 CEST
CISA KEV-katalog

TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity. | Åtgärd: Apply mitigations per vendor…

CVE-2026-45321
Publicerad: 2026-05-27 02:00:00 CEST
CISA KEV-katalog

Daemon Tools contains an unspecified vulnerability that has a high impact on confidentiality, integrity, and availability. | Åtgärd: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or…

CVE-2026-8398
Publicerad: 2026-05-27 02:00:00 CEST
CISA KEV-katalog

LiteSpeed cPanel Plugin contains privilege escalation vulnerability that is exposed via the user-end cPanel plugin, which can be abused by any cPanel user account to execute arbitrary scripts with root privileges. | Åtgärd: Apply…

CVE-2026-48172
Publicerad: 2026-05-26 02:00:00 CEST
CERT-SE

I veckans läsning finns ett urval av nyheter, analyser och rapporter inom cybersäkerhetsområdet från veckan som har gått.

Publicerad: 2026-05-22 14:15:00 CEST
Cisco PSIRT

A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the Site Admin role. This vulnerability is due to…

CVE-2026-20223
Publicerad: 2026-05-20 18:00:00 CEST
Cisco PSIRT

A vulnerability in the BrowserBot component of Cisco ThousandEyes Enterprise Agent could have allowed an authenticated, remote attacker to execute arbitrary commands on Agents on behalf of the BrowserBot synthetics orchestration process.…

CVE-2026-20206
Publicerad: 2026-05-20 18:00:00 CEST
CERT-SE

Denna vecka vill vi tipsa om att vi har publicerat enkla och korta ”Tabletop”-övningar för hantering av utpressningsangrepp, överbelastningsangrepp och nätfiske. Du hittar övningarna här: https://www.cert.se/tema/ovningar/

Publicerad: 2026-05-15 13:15:00 CEST
CERT-SE

Cisco har publicerat information om en kritisk sårbarhet som fått den högsta CVSS-klassningen på 10.0. [1] Sårbarheten, CVE-2026-20182, utnyttjas aktivt och CISA har lagt till den i KEV-katalogen (Known Exploited Vulnerabilities catalog). [2]

CVE-2026-20182 CVSS 10.0
Publicerad: 2026-05-15 10:45:00 CEST
Fortinet PSIRT

CVSSv3 Score: 7.8 CVE-2026-31431In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated…

CVE-2026-31431 CVSS 3
Publicerad: 2026-05-13 09:00:00 CEST
Fortinet PSIRT

CVSSv3 Score: 4.0 An Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability [CWE-88] in FortiDeceptor WEB UI may allow an authenticated attacker with at least read-only admin permission to read log…

CVSS 3
Publicerad: 2026-05-12 09:00:00 CEST
Fortinet PSIRT

CVSSv3 Score: 6.1 An improper neutralization of special elements used in an OS command ("OS Command Injection") vulnerability [CWE-78] in FortiAP, FortiAP-U & FortiAP-W2 CLI may allow an authenticated privileged attacker to execute…

CVSS 3
Publicerad: 2026-05-12 09:00:00 CEST
Fortinet PSIRT

CVSSv3 Score: 5.2 A use of potentially Dangerous Function vulnerability [CWE-676] in FortiAnalyzer and FortiManager API may allow an authenticated attacker to cause a system hang via multiple specially crafted HTTP requests causing…

CVSS 3
Publicerad: 2026-05-12 09:00:00 CEST
Fortinet PSIRT

CVSSv3 Score: 2.1 A Missing Authorization [CWE-862] in FortiClient Windows may allow an authenticated local attacker to decrypt a currently logged in users VPN password via use of an unprotected DLL function. Revised on 2026-05-12 00:00:00

CVSS 3
Publicerad: 2026-05-12 09:00:00 CEST
Fortinet PSIRT

CVSSv3 Score: 9.1 An Improper Access Control vulnerability [CWE-284] in FortiAuthenticator may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. Revised on 2026-05-12 00:00:00

CVSS 3
Publicerad: 2026-05-12 09:00:00 CEST
Fortinet PSIRT

CVSSv3 Score: 9.1 A missing authorization vulnerability [CWE-862] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to execute unauthorized code or commands via HTTP requests. Revised on 2026-05-12 00:00:00

CVSS 3
Publicerad: 2026-05-12 09:00:00 CEST
Fortinet PSIRT

CVSSv3 Score: 6.5 An OS command injection vulnerabtility [CWE-78] in FortiAP and FortiAP-W2 cli may allow an authenticated attacker to execute unauthorized code or commands via a specifically crafted cli command. Revised on 2026-05-12 00:00:00

CVSS 3
Publicerad: 2026-05-12 09:00:00 CEST
Fortinet PSIRT

CVSSv3 Score: 5.0 An improper export of Android application components [CWE-926] in FortiTokenAndroid may allow other applications on the device to read the OTP code via an exported Content Provider URI. Revised on 2026-05-12 00:00:00

CVSS 3
Publicerad: 2026-05-12 09:00:00 CEST
CERT-SE

I veckans brev kan du läsa om angreppet mot utbildningsplattformen Canvas, som tillhandahålls av det amerikanska företaget Instructure. Företaget har bekräftat att en hotaktör har stulit en mängd information, däribland personuppgifter.…

Publicerad: 2026-05-08 15:10:00 CEST
CERT-SE

Palo Alto Networks har publicerat information om en kritisk sårbarhet i PAN-OS. Sårbarheten, CVE-2026-0300, har fått en CVSS-klassning på 9.3 och påverkar USER-ID Autentication Portal. [1]

CVE-2026-0300 CVSS 9.3
Publicerad: 2026-05-06 15:20:00 CEST
CERT-SE

Vid uppsättning av en klientorganisation (engelska: tenant) i Microsofts molnmiljö är flexibiliteten hög och nya funktioner läggs till kontinuerligt. CERT-SE uppmanar organisationer att regelbundet se över aktiverade, eller inaktiverade,…

Publicerad: 2026-03-30 11:10:00 CEST
NVD (National Vulnerability Database) Stale

A vulnerability classified as problematic has been found in Ortus Solutions ColdBox Elixir 3.1.6. This affects an unknown part of the file src/defaultConfig.js of the component ENV Variable Handler. The manipulation leads to information…

CVE-2021-4430
Publicerad: 2023-11-06 09:15:21 CET
NVD (National Vulnerability Database) Stale

A vulnerability was found in Vaerys-Dawn DiscordSailv2 up to 2.10.2. It has been rated as critical. Affected by this issue is some unknown functionality of the component Tag Handler. The manipulation leads to improper access controls.…

CVE-2018-25093
Publicerad: 2023-11-06 02:15:08 CET
NVD (National Vulnerability Database) Stale

** UNSUPPPORTED WHEN ASSIGNED ** ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Magnesium-PHP up to 0.3.0. It has been classified as problematic. Affected is the function formatEmailString of the file…

CVE-2017-20187
Publicerad: 2023-11-05 22:15:09 CET
NVD (National Vulnerability Database) Stale

A vulnerability was found in Vaerys-Dawn DiscordSailv2 up to 2.10.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Command Mention Handler. The manipulation leads to improper…

CVE-2018-25092
Publicerad: 2023-11-05 22:15:09 CET
NVD (National Vulnerability Database) Stale

A security issue was discovered in kube-apiserver that allows an aggregated API server to redirect client traffic to any URL. This could lead to the client performing unexpected actions as well as forwarding the client's API server credentials to third parties.

CVE-2022-3172
Publicerad: 2023-11-03 21:15:08 CET
NVD (National Vulnerability Database) Stale

Ivanti Avalanche Smart Device Service Missing Authentication Local Privilege Escalation Vulnerability

CVE-2022-43554
Publicerad: 2023-11-03 21:15:08 CET
NVD (National Vulnerability Database) Stale

Ivanti Avalanche Printer Device Service Missing Authentication Local Privilege Escalation Vulnerability

CVE-2022-43555
Publicerad: 2023-11-03 21:15:08 CET
NVD (National Vulnerability Database) Stale

A locally authenticated attacker with low privileges can bypass authentication due to insecure inter-process communication.

CVE-2022-44569
Publicerad: 2023-11-03 21:15:08 CET
NVD (National Vulnerability Database) Stale

In swtpm before 0.4.2 and 0.5.x before 0.5.1, a local attacker may be able to overwrite arbitrary files via a symlink attack against a temporary file such as TMP2-00.permall.

CVE-2020-28407
Publicerad: 2023-11-03 05:15:15 CET
NVD (National Vulnerability Database) Stale

bcrypt password hashing in Botan before 2.1.0 does not correctly handle passwords with a length between 57 and 72 characters, which makes it easier for attackers to determine the cleartext password.

CVE-2017-7252
Publicerad: 2023-11-03 02:15:07 CET
Threatpost

Researchers uncover a watering hole attack likely carried out by APT TA423, which attempts to plant the ScanBox JavaScript-based reconnaissance tool.

Publicerad: 2022-08-30 18:00:43 CEST
Threatpost

Lockbit is by far this summer’s most prolific ransomware group, trailed by two offshoots of the Conti group.

Publicerad: 2022-08-26 18:44:27 CEST
Threatpost

Twitter is blasted for security and privacy lapses by the company’s former head of security who alleges the social media giant’s actions amount to a national security risk.

Publicerad: 2022-08-24 16:17:04 CEST
Threatpost
Publicerad: 2022-08-22 15:59:06 CEST
Threatpost

Separate fixes to macOS and iOS patch respective flaws in the kernel and WebKit that can allow threat actors to take over devices and are under attack.

Publicerad: 2022-08-19 17:25:56 CEST
Threatpost

An insufficient validation input flaw, one of 11 patched in an update this week, could allow for arbitrary code execution and is under active attack.

Publicerad: 2022-08-18 16:31:38 CEST