Sårbarhetsflöden

Uppdateras var 300 sekund(er). Senast uppdaterad: 2026-10-04 23:58:17 CEST. Visar 10 artiklar per källa från: NVD (National Vulnerability Database), SecurityWeek Vulnerabilities, CERT-SE, CISA KEV-katalog, CISA Alerts, Microsoft MSRC, GitHub Security Advisories, Cisco PSIRT, Fortinet PSIRT, Palo Alto Networks Advisories, BleepingComputer, The Hacker News, Threatpost, Dark Reading. Tidszon: Europe/Stockholm.

Källfilter (klicka för att visa/dölja)
Vy: Kompakt visar endast titel/källa/tid.
Rensa filter
Mottaget tidigare
BleepingComputer

Citrix has released emergency updates for a new NetScaler denial-of-service vulnerability tracked as CVE-2026-88779 that has been exploited in zero-day attacks, with researchers investigating whether it can also be exploited for remote code execution. [...]

CVE-2026-88779
Publicerad: 2026-10-04 23:58:01 CEST
CISA Alerts

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-88779 Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer…

CVE-2026-88779
Publicerad: 2026-10-04 14:00:00 CEST
The Hacker News

A new China-nexus cyber espionage group known as TA419 has been attributed to multiple credential phishing campaigns targeting artificial intelligence (AI) experts working for U.S. think tanks, universities, and legal sector organizations.…

Publicerad: 2026-10-04 09:20:32 CEST
CISA KEV-katalog

Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for a denial of service. |…

CVE-2026-88779
Publicerad: 2026-10-04 02:00:00 CEST
BleepingComputer

A suspected ShinyHunters hacking group member known online as "Rey" has reportedly been detained in Jordan and is cooperating with the FBI to help locate other members of the extortion group. [...]

Publicerad: 2026-10-03 21:09:38 CEST
The Hacker News

The U.K.'s domestic intelligence and security agency has warned that more than 100 academics have helped China boost its intelligence gathering efforts on behalf of Beijing's state security service. In a "Security Service Espionage Alert"…

Publicerad: 2026-10-03 16:38:46 CEST
The Hacker News

The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries. The…

Publicerad: 2026-10-03 16:36:33 CEST
BleepingComputer

The Technical University of Denmark (DTU) says information belonging to up to 200,000 users may have been exposed after hackers accessed its identity and access management system and downloaded a large amount of data. [...]

Publicerad: 2026-10-03 16:35:20 CEST
SecurityWeek Vulnerabilities

doxx.net’s new ADN platform prevents agentic misadventure while the agent is operating under the user’s authority. The post doxx.net Raises $38 Million to Prevent AI Agent-on-the-Internet Misadventures appeared first on SecurityWeek.

Publicerad: 2026-10-03 13:45:00 CEST
SecurityWeek Vulnerabilities

The bugs could lead to authentication bypass, shell command execution, and memory corruption. The post Fortra Patches Critical Vulnerabilities in BoKS appeared first on SecurityWeek.

Publicerad: 2026-10-03 13:34:00 CEST
The Hacker News

Featuring: Cybersecurity is being reshaped by the expansion of cloud infrastructure, AI, distributed systems, and increasingly complex digital environments. As organizations manage more identities, devices, data, and internet-facing…

Publicerad: 2026-10-03 13:00:00 CEST
Cisco PSIRT

A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due…

CVE-2026-76504
Publicerad: 2026-10-03 01:18:42 CEST
GitHub Security Advisories

## Overview `probe-image-size` scans the SVG header with a searching regular expression, `/<[-_.:a-zA-Z0-9][^>]*>/`. On input that contains many `<` characters but no `>`, the engine restarts the `[^>]*` scan at every `<` position and runs…

CVE-2026-104861
Publicerad: 2026-10-03 01:18:02 CEST
GitHub Security Advisories

### Summary Multiple denial-of-service vulnerabilities have been discovered in HTTP/2 server implementations. All have been rated with a severity impact of [Important](https://access.redhat.com/security/updates/classification). The…

Publicerad: 2026-10-03 01:09:37 CEST
GitHub Security Advisories

### Summary The Headroom WebSocket server does not validate the `Origin` header of incoming client WebSocket requests before forwarding the request to the upstream server, allowing malicious WebSocket clients to perform arbitrary LLM…

CVE-2026-71416
Publicerad: 2026-10-03 01:09:15 CEST
GitHub Security Advisories

Same CWE-862 family, found via an automated bulk sweep of every `/api/block/*` handler in `kernel/api/block.go` for the presence of any access-check reference (`IsReadOnlyRoleContext`, `checkBlockPublishAccess`, `GetPublishAccess`)…

CVE-2026-74904 CVSS 3.1
Publicerad: 2026-10-03 01:05:33 CEST
Cisco PSIRT

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that…

CVE-2026-20267 CVE-2026-20268 CVE-2026-20269 CVE-2026-20270 CVE-2026-20271 CVE-2026-20272 CVE-2026-20273
Publicerad: 2026-10-02 21:21:28 CEST
BleepingComputer

Frontline Education is notifying school districts of a data breach after attackers exploited a vulnerability in third-party software to gain unauthorized access to its systems and steal employee information, including Social Security numbers. [...]

Publicerad: 2026-10-02 21:01:40 CEST
The Hacker News

Dell has released security updates to address multiple critical security flaws in Dell Container Storage Modules (CSM) that could be exploited by bad actors to take over susceptible systems. The vulnerabilities are listed below -…

CVE-2026-63688 CVSS 10.0
Publicerad: 2026-10-02 19:02:12 CEST
Dark Reading

Organizations may face an artificial intelligence (AI) reckoning over the next year. Omdia and Gartner weigh in on how to tackle the governance, security, and value challenges ahead.

Publicerad: 2026-10-02 18:01:22 CEST
Dark Reading

"Rogue AI" terminology anthropomorphizes LLMs and shifts risk responsibility from vendors. Defenders should treat agents as untrusted, nondeterministic software systems, not sentient beings with malicious intent.

Publicerad: 2026-10-02 17:51:33 CEST
BleepingComputer

The U.S. Treasury Department has sanctioned eight members of the Venezuelan gang Tren de Aragua (TdA) for their role in the theft of millions of dollars in ATM jackpotting attacks across the United States. [...]

Publicerad: 2026-10-02 17:20:53 CEST
BleepingComputer

Browser-based attacks can steal sessions, abuse extensions, or manipulate users without creating the endpoint artifacts EDR is designed to detect. NordLayer explains three ways attacks can evade endpoint telemetry and why browser-level controls can help close the gap. [...]

Publicerad: 2026-10-02 16:00:10 CEST
Dark Reading

Organizations don't need better vulnerability scanners; they need to know who owns their assets and has the authority and capacity to actually fix them.

Publicerad: 2026-10-02 16:00:00 CEST
SecurityWeek Vulnerabilities

The dropper “carries a complete universal Mach-O inside itself, roughly 756 KB in the development build, and extracts it at runtime. The post macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor appeared first on SecurityWeek.

Publicerad: 2026-10-02 15:15:00 CEST
CISA Alerts

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-102489 Zammad GmbH Zammad Session Fixation Vulnerability CVE-2026-102490 Zammad GmbH Zammad…

CVE-2026-102489 CVE-2026-102490
Publicerad: 2026-10-02 14:00:00 CEST
SecurityWeek Vulnerabilities

Hackers used the account, which has 13 million followers, to amplify a Clippy-themed cryptocurrency account. The post Crypto Scammers Hijack Microsoft’s Official X Account appeared first on SecurityWeek.

Publicerad: 2026-10-02 13:46:10 CEST
CERT-SE

Fortinet har publicerat information om en kritisk sårbarhet i FortiMail. Sårbarheten, CVE-2026-104286, har fått en CVSS-klassning på 9.8 och påverkar FortiMail managements gränssnitt. Ett framgångsrikt utnyttjande kan innebära att en…

CVE-2026-104286 CVSS 9.8
Publicerad: 2026-10-02 13:30:00 CEST
SecurityWeek Vulnerabilities

Amir Barati, an alleged member of the Mabna Institute, was indicted for targeting universities, private organizations, and government entities in the US and abroad. The post In Rare Move, Alleged Iranian State Hacker Extradited to US appeared first on SecurityWeek.

Publicerad: 2026-10-02 13:14:34 CEST
CERT-SE

CERT-SE presenterar vår årliga utmaning (CTF) som sker under cybersäkerhetsmånaden [1, 2]. Utmaningen vänder sig till alla med it-säkerhetsintresse oavsett kunskapsnivå.

Publicerad: 2026-10-02 12:45:00 CEST
SecurityWeek Vulnerabilities

The China-based hacking group has been exploiting SharePoint vulnerabilities since July 2025. The post Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks appeared first on SecurityWeek.

Publicerad: 2026-10-02 11:34:41 CEST
SecurityWeek Vulnerabilities

The attacks targeted the US Department of Education and Library and Archives Canada, and researchers linked some agents to OpenAI. The post AI Agents Aimed SQL Injection at US and Canadian Government Sites appeared first on SecurityWeek.

Publicerad: 2026-10-02 10:38:46 CEST
SecurityWeek Vulnerabilities

CVE-2026-104286 is a critical-severity path traversal vulnerability that could allow attackers to write arbitrary files to the system. The post Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action appeared first on SecurityWeek.

CVE-2026-104286
Publicerad: 2026-10-02 10:07:33 CEST
CERT-SE

Oktober är cybersäkerhetsmånaden och vi vill passa att slå ett slag för de kunskapshöjande aktiviteter som erbjuds genom NCSC:s och polisens cybersäkerhetskampanj “Tänk Säkert”.

Publicerad: 2026-10-02 09:30:00 CEST
CISA KEV-katalog

Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489. | Åtgärd: Apply mitigations in…

CVE-2026-102489 CVE-2026-102490
Publicerad: 2026-10-02 02:00:00 CEST
CISA KEV-katalog

Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490. | Åtgärd: Apply mitigations in accordance with vendor…

CVE-2026-102489 CVE-2026-102490
Publicerad: 2026-10-02 02:00:00 CEST
Dark Reading

Law enforcement from multiple countries collaborated to disrupt a cybercrime operation that has claimed some 500 victims worldwide in the past two years.

Publicerad: 2026-10-01 23:37:50 CEST
CISA Alerts

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker tointercept and read sensitive information, including credentials andsession data. The following versions of Johnson Controls EasyIO Neo Series EC and…

CVE-2026-64893 CVSS 3 CVSS 3.1 CVSS 3.1 CVSS 4.0
Publicerad: 2026-10-01 14:00:00 CEST
CISA Alerts

View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to manipulate device configurations, trigger unauthorized behaviors, and access sensitive information such as device credentials, owner details, and…

CVE-2026-101104 CVE-2026-96613 CVSS 3 CVSS 3.1 CVSS 3.1 CVSS 4.0 CVSS 3.1 CVSS 3.1 CVSS 4.0
Publicerad: 2026-10-01 14:00:00 CEST
CISA Alerts

View CSAF Summary Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks. The…

CVE-2026-93474 CVE-2026-95102 CVE-2026-97212 CVE-2026-97363 CVSS 3 CVSS 3.1 CVSS 3.1 CVSS 4 CVSS 4.0 CVSS 3.1 CVSS 3.1 CVSS 4 CVSS 4.0 CVSS 3.1 CVSS 3.1 CVSS 4 CVSS 4.0 CVSS 3.1 CVSS 3.1 CVSS 4 CVSS 4.0
Publicerad: 2026-10-01 14:00:00 CEST
CISA Alerts

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to the database, execute arbitrary code on the host with the highest level of privilege, or gain control of the physical…

CVE-2023-46604 CVE-2026-94591 CVE-2026-94592 CVE-2026-94593 CVE-2026-94594 CVSS 3 CVSS 3.1 CVSS 3.1 CVSS 4.0 CVSS 3.1 CVSS 3.1 CVSS 4.0 CVSS 3.1 CVSS 3.1 CVSS 4.0 CVSS 3.1 CVSS 3.1 CVSS 4.0 CVSS 3.1 CVSS 3.1 CVSS 4.0
Publicerad: 2026-10-01 14:00:00 CEST
CISA Alerts

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to escalate privileges or overwrite files. The following versions of ABB Protection and Control IED Manager PCM600 are affected: Protection and…

CVE-2026-15952 CVE-2026-15953 CVSS 3 CVSS 3.1 CVSS 3.1 CVSS 4.0 CVSS 3.1 CVSS 3.1 CVSS 4.0
Publicerad: 2026-10-01 14:00:00 CEST
CISA Alerts

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to gain access to sensitive information that could be used to conduct further attacks against the system. The following versions of Johnson Controls…

CVE-2026-64892 CVSS 3 CVSS 3.1 CVSS 3.1 CVSS 4.0
Publicerad: 2026-10-01 14:00:00 CEST
CISA Alerts

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-104286 Fortinet FortiMail Path Traversal Vulnerability This type of vulnerability is a frequent…

CVE-2026-104286
Publicerad: 2026-10-01 14:00:00 CEST
CISA Alerts

View CSAF Summary The following versions of CISA Malcolm are affected: Malcolm CVSS Vendor Equipment Vulnerabilities v3 8.8 CISA CISA Malcolm Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper…

CVE-2026-90443 CVE-2026-90444 CVE-2026-90445 CVE-2026-90446 CVE-2026-90447 CVE-2026-90448 CVE-2026-90449 CVE-2026-90450 CVE-2026-90451 CVE-2026-90452 CVE-2026-90453 CVE-2026-90454 CVE-2026-90455 CVE-2026-90456 CVE-2026-90457 CVSS 3 CVSS 3.1 CVSS 3.1 CVSS 4.0 CVSS 3.1 CVSS 3.1 CVSS 4.0 CVSS 3.1 CVSS 3.1 CVSS 4.0 CVSS 3.1 CVSS 3.1 CVSS 4.0 CVSS 3.1 CVSS 3.1 CVSS 4.0 CVSS 3.1 CVSS 3.1 CVSS 4.0 CVSS 3.1 CVSS 3.1 CVSS 4.0 CVSS 3.1 CVSS 3.1 CVSS 4.0 CVSS 3.1 CVSS 3.1 CVSS 4.0 CVSS 3.1 CVSS 3.1 CVSS 4.0 CVSS 3.1 CVSS 3.1 CVSS 4.0 CVSS 3.1 CVSS 3.1 CVSS 4.0 CVSS 3.1 CVSS 3.1 CVSS 4.0 CVSS 3.1 CVSS 3.1 CVSS 4.0 CVSS 3.1 CVSS 3.1 CVSS 4.0
Publicerad: 2026-10-01 14:00:00 CEST
Fortinet PSIRT

CVSSv3 Score: 9.8 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] and Improper Neutralization of NULL Byte or NULL Character [CWE-158] vulnerability may allow an unauthenticated attacker to write…

CVSS 3
Publicerad: 2026-10-01 09:00:00 CEST
CISA KEV-katalog

Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS…

CVE-2026-104286
Publicerad: 2026-10-01 02:00:00 CEST
CISA KEV-katalog

Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP…

CVE-2026-76504
Publicerad: 2026-09-30 02:00:00 CEST
CISA KEV-katalog

Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution. | Åtgärd: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD…

CVE-2026-86950
Publicerad: 2026-09-29 02:00:00 CEST
NVD (National Vulnerability Database)

A security flaw has been discovered in amirsanni Mini-Inventory-and-Sales-Management-System up to 81bf0b55f5933f3b0dbb1583204a612e06605b95. The impacted element is the function order_by of the file DB_query_builder.php of the component…

CVE-2026-100887 CVSS 6.3
Publicerad: 2026-09-28 02:16:32 CEST
NVD (National Vulnerability Database)

A malicious user can get read-access to files in the flatpak-system-helper context if a system OCI repository is configured, because the OCI code paths in the system helper follow symlinks when importing OCI images that are under the user's control.

CVE-2026-96284 CVSS 2.5
Publicerad: 2026-09-28 01:17:01 CEST
NVD (National Vulnerability Database)

A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4-build202604241011. The affected element is an unknown function of the component Debug Service. Such manipulation leads to improper authentication. The attack…

CVE-2026-100886 CVSS 10.0
Publicerad: 2026-09-28 01:16:59 CEST
NVD (National Vulnerability Database)

A vulnerability was found in Krayin laravel-crm up to 2.2.4. This affects an unknown function of the file packages/Webkul/Installer/src/Http/Middleware/CanInstall.php of the component admin-config-setup API Endpoint. The manipulation…

CVE-2026-100885 CVSS 7.3
Publicerad: 2026-09-28 01:16:58 CEST
NVD (National Vulnerability Database)

A vulnerability has been found in Krayin laravel-crm up to 2.2.5. The impacted element is the function Storage::download of the file packages/Webkul/Admin/src/Config/acl.php of the component attachment-download Endpoint. The manipulation…

CVE-2026-100884 CVSS 4.3
Publicerad: 2026-09-28 01:16:58 CEST
NVD (National Vulnerability Database)

A flaw has been found in Krayin laravel-crm up to 2.2.5. The affected element is an unknown function of the file packages/Webkul/Admin/src/Config/acl.php. Executing a manipulation can lead to improper access controls. The attack can be…

CVE-2026-100883 CVSS 6.3
Publicerad: 2026-09-28 01:16:58 CEST
NVD (National Vulnerability Database)

By calling org.freedesktop.Flatpak.SystemHelper.CancelPull on another user's pull, the pull is not actually cancelled but removed from internal tracking, making it impossible for the owning user to stop it. Ongoing pulls cannot be stopped.

CVE-2026-96283 CVSS 3.3
Publicerad: 2026-09-28 00:17:06 CEST
NVD (National Vulnerability Database)

A malicious Flatpak extension can probe the host filesystem to determine what files and directories exist at arbitrary paths, and host directory listings can be disclosed to sandboxed applications using the extension. Additionally,…

CVE-2026-96282 CVSS 3.1
Publicerad: 2026-09-28 00:17:06 CEST
NVD (National Vulnerability Database)

A vulnerability was detected in Krayin laravel-crm up to 2.2.5. Impacted is an unknown function of the file packages/Webkul/Admin/src/Resources/views/components/layouts/index.blade.php of the component Admin Settings Endpoint. Performing a…

CVE-2026-100882 CVSS 2.4
Publicerad: 2026-09-28 00:17:06 CEST
NVD (National Vulnerability Database)

A security vulnerability has been detected in zhistaredu StarTraining up to 3.8.1. This issue affects some unknown processing of the file application.yml. Such manipulation of the argument xss.enabled leads to cross site scripting. It is…

CVE-2026-100881 CVSS 2.6
Publicerad: 2026-09-28 00:17:05 CEST
CERT-SE

Citrix har publicerat information om allvarliga och kritiska sårbarheter i Citrix NetScaler ADC (tidigare Citrix ADC) and Citrix NetScaler Gateway (tidigare Citrix Gateway). Två av sårbarheterna, CVE-2026-88771 och CVE-2026-88772, har fått…

CVE-2026-88771 CVE-2026-88772 CVSS 9.5
Publicerad: 2026-09-27 18:09:00 CEST
CISA KEV-katalog

Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service | Åtgärd: Apply mitigations in…

CVE-2026-88772
Publicerad: 2026-09-27 02:00:00 CEST
CISA KEV-katalog

Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands. | Åtgärd: Apply mitigations in accordance with vendor instructions,…

CVE-2026-88771
Publicerad: 2026-09-27 02:00:00 CEST
CERT-SE

För tionde året genomförs Beredskapsveckan i Sverige vecka 39. I år är det fokus på Sveriges totalförsvar, där samhällets motståndskraft mot cyberhot är en viktig del. Tänk på att ha en radio inställd på Sveriges Radio P4 och viktiga telefonnummer nedskrivna på papper.

Publicerad: 2026-09-25 10:45:00 CEST
CISA KEV-katalog

Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve…

CVE-2026-67279 CVE-2026-86060
Publicerad: 2026-09-25 02:00:00 CEST
CISA KEV-katalog

Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network. | Åtgärd: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD…

CVE-2026-65660
Publicerad: 2026-09-25 02:00:00 CEST
Cisco PSIRT

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to access or manipulate data, obtain sensitive information, or cause a reload of certificate…

CVE-2026-76439 CVE-2026-76444 CVE-2026-76446 CVE-2026-76447
Publicerad: 2026-09-24 19:16:37 CEST
CERT-SE

F5 har publicerat information om en kritisk sårbarhet, CVE-2026-94127, i BIG-IP APM. Sårbarheten kan resultera i att en oautentiserad angripare kan fjärrexekvera godtycklig kod.

CVE-2026-94127
Publicerad: 2026-09-23 11:20:00 CEST
Cisco PSIRT

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software and Cisco Secure Firewall Management…

CVE-2026-20329 CVE-2026-20330 CVE-2026-20331 CVE-2026-20332 CVE-2026-20333 CVE-2026-20334 CVE-2026-20335 CVE-2026-20336
Publicerad: 2026-09-18 17:50:33 CEST
Cisco PSIRT

A vulnerability in Datagram TLS (DTLS) message handling of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software for Cisco Secure Firewall 3100 Series and 4200 Series…

CVE-2026-20250
Publicerad: 2026-09-18 17:50:31 CEST
CERT-SE

Den här veckan innehåller CERT-SE:s veckobrev bland annat information om att NCSC och AI Sweden med flera bjuder in till seminarium den 22 oktober på temat “Modern sårbarhetshantering i en AI-driven hotmiljö”. Läs mer om detta nedan.

Publicerad: 2026-09-18 13:15:00 CEST
CERT-SE

Den 16 september publicerade Cisco säkerhetsuppdateringar för flera sårbarheter, där några av dessa utnyttjas aktivt enligt Cisco. [1, 2] Ett exempel är CVE-2026-76460, en sårbarhet i ett API för Cisco Identity Services Engine (ISE).…

CVE-2026-76460 CVSS 10.0
Publicerad: 2026-09-17 15:20:00 CEST
CERT-SE

Cisco har publicerat information om en kritisk SQL injection-sårbarhet i Cisco Secure Email Gateway som utnyttjas aktivt. Sårbarheten (CVE-2026-76461) har fått CVSS-klassificering 9.8 (CVSS v.3.1). [1] CISA har lagt till sårbarheten i KEV-…

CVE-2026-76461 CVSS 9.8 CVSS 3.1
Publicerad: 2026-09-15 15:00:00 CEST
CERT-SE

GitLab har publicerat säkerhetsuppdateringar för flera sårbarheter i GitLab Community Edition (CE) och Enterprise Edition (EE). [1] Två av dessa sårbarheter, CVE-2026-85706 och CVE-2026-87719, klassas som kritiska.

CVE-2026-85706 CVE-2026-87719
Publicerad: 2026-09-11 23:30:00 CEST
Fortinet PSIRT

CVSSv3 Score: 4.7 An Unverified Ownership Vulnerability [CWE-283] in FortiClient Windows fortimon3 driver may allow an authenticated attacker to terminate arbitrary processes via an exposed minifilter communication port. Revised on 2026-09-08 00:00:00

CVSS 3
Publicerad: 2026-09-08 09:00:00 CEST
Fortinet PSIRT

CVSSv3 Score: 4.9 An Improper Access control vulnerability [CWE-284] in FortiSOAR may allow an authenticated attacker with zero permissions to subscribe to websocket streams and topics and to inject broadcast messages to the stream via…

CVSS 3
Publicerad: 2026-09-08 09:00:00 CEST
Fortinet PSIRT

CVSSv3 Score: 6.7 An Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability [CWE-77] in FortiSandbox may allow a privileged attacker to execute unauthorized code or commands via crafted HTTP requests. Revised on 2026-09-08 00:00:00

CVSS 3
Publicerad: 2026-09-08 09:00:00 CEST
Fortinet PSIRT

CVSSv3 Score: 9.1 An improper authentication vulnerability [CWE-287] in the Fortinet Privileged Access Agent Chrome Extension may allow a remote unauthenticated attacker to proxy a user's browser traffic through attacker controlled servers…

CVSS 3
Publicerad: 2026-09-08 09:00:00 CEST
Fortinet PSIRT

CVSSv3 Score: 9.6 An Inclusion of Sensitive Information in Source Code vulnerability [CWE-540] in FortiMonitorOnSight web portal may allow a remote unauthenticated attacker to bypass authentication via forged or reused JWT Revised on 2026-09-08 00:00:00

CVSS 3
Publicerad: 2026-09-08 09:00:00 CEST
Fortinet PSIRT

CVSSv3 Score: 2.5 A NULL Pointer Dereference vulnerability [CWE-476] in FortiOS, FortiProxy and FortiPAM may allow an authenticated attacker to crash the httpsd daemon via crafted HTTP requests. Revised on 2026-09-08 00:00:00

CVSS 3
Publicerad: 2026-09-08 09:00:00 CEST
Fortinet PSIRT

CVSSv3 Score: 2.8 An URL redirection to untrusted site ('open redirect') [CWE-601] vulnerability in FortiSIEM may allow an authenticated attacker to cause a redirection to any website via specially crafted HTTP requests Revised on 2026-09-08 00:00:00

CVSS 3
Publicerad: 2026-09-08 09:00:00 CEST
Fortinet PSIRT

CVSSv3 Score: 8.9 An improper access control vulnerability [CWE-284] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to access sensitive information via crafted HTTP requests. Revised on 2026-09-08 00:00:00

CVSS 3
Publicerad: 2026-09-08 09:00:00 CEST
Fortinet PSIRT

CVSSv3 Score: 5.9 A Use of Uninitialized Variable [CWE-457] vulnerability in Fortinet FortiAnalyzer SNMP daemon may allow a remote authenticated attacker with user permission to cause a denial of service via SNMP GETBULK requests. Revised on 2026-09-08 00:00:00

CVSS 3
Publicerad: 2026-09-08 09:00:00 CEST
Threatpost

Researchers uncover a watering hole attack likely carried out by APT TA423, which attempts to plant the ScanBox JavaScript-based reconnaissance tool.

Publicerad: 2022-08-30 18:00:43 CEST
Threatpost

Lockbit is by far this summer’s most prolific ransomware group, trailed by two offshoots of the Conti group.

Publicerad: 2022-08-26 18:44:27 CEST
Threatpost

Twitter is blasted for security and privacy lapses by the company’s former head of security who alleges the social media giant’s actions amount to a national security risk.

Publicerad: 2022-08-24 16:17:04 CEST
Threatpost
Publicerad: 2022-08-22 15:59:06 CEST
Threatpost

Separate fixes to macOS and iOS patch respective flaws in the kernel and WebKit that can allow threat actors to take over devices and are under attack.

Publicerad: 2022-08-19 17:25:56 CEST
Threatpost

An insufficient validation input flaw, one of 11 patched in an update this week, could allow for arbitrary code execution and is under active attack.

Publicerad: 2022-08-18 16:31:38 CEST