Sårbarhetsflöden

Uppdateras var 300 sekund(er). Senast uppdaterad: 2026-04-08 03:53:09 CEST. Visar 10 artiklar per källa från: NVD (National Vulnerability Database), SecurityWeek Vulnerabilities, CERT-SE, CISA KEV-katalog, Microsoft MSRC, Cisco PSIRT, Fortinet PSIRT, Palo Alto Networks Advisories, The Hacker News, Threatpost, Dark Reading. Tidszon: Europe/Stockholm.

Källfilter (klicka för att visa/dölja)
Vy: Kompakt visar endast titel/källa/tid.
Rensa filter
Mottaget igår
Dark Reading

By hiding malicious instructions on an attacker-controlled Web page, AI could ingest orders as benign and return sensitive data to the attacker's server.

Publicerad: 2026-04-07 21:52:26 CEST
SecurityWeek Vulnerabilities

The cybersecurity response to AI-enabled nation-state threats cannot be incremental. It must be architectural. The post The New Rules of Engagement: Matching Agentic Attack Speed appeared first on SecurityWeek.

Publicerad: 2026-04-07 18:40:52 CEST
SecurityWeek Vulnerabilities

The startup has created a layered security solution aiming to secure AI agents throughout their entire lifecycle. The post Trent AI Emerges From Stealth With $13 Million in Funding appeared first on SecurityWeek.

Publicerad: 2026-04-07 18:34:26 CEST
The Hacker News

In the rapid evolution of the 2026 threat landscape, a frustrating paradox has emerged for CISOs and security leaders: Identity programs are maturing, yet the risk is actually increasing. According to new research from the Ponemon…

Publicerad: 2026-04-07 18:29:00 CEST
SecurityWeek Vulnerabilities

The improper validation of user-supplied JavaScript code allows attackers to execute arbitrary code and access the file system. The post Critical Flowise Vulnerability in Attacker Crosshairs appeared first on SecurityWeek.

Publicerad: 2026-04-07 17:34:51 CEST
The Hacker News

A high-severity security vulnerability has been disclosed in Docker Engine that could permit an attacker to bypass authorization plugins (AuthZ) under specific circumstances. The vulnerability, tracked as CVE-2026-34040 (CVSS score: 8.8),…

CVE-2024-41110 CVE-2026-34040 CVSS 8.8
Publicerad: 2026-04-07 17:15:00 CEST
Dark Reading
Publicerad: 2026-04-07 16:36:44 CEST
Dark Reading

A panel of five C-suite leaders discuss how cybersecurity success is measured and why it isn't improving results.

Publicerad: 2026-04-07 16:26:02 CEST
SecurityWeek Vulnerabilities

A critical DoS vulnerability in the Framework component of Android has also been fixed with the latest update. The post Severe StrongBox Vulnerability Patched in Android appeared first on SecurityWeek.

Publicerad: 2026-04-07 16:23:51 CEST
SecurityWeek Vulnerabilities

By targeting Grafana’s AI components, attackers can point to external resources and inject indirect prompts to bypass safeguards. The post GrafanaGhost: Attackers Can Abuse Grafana to Leak Enterprise Data appeared first on SecurityWeek.

Publicerad: 2026-04-07 15:58:45 CEST
SecurityWeek Vulnerabilities

Join the live diagnostic session to expose hidden coverage gaps and shift from flawed tool-level evaluations to a comprehensive, program-level validation discipline. The post Webinar Today: Why Automated Pentesting Alone Is Not Enough appeared first on SecurityWeek.

Publicerad: 2026-04-07 15:19:29 CEST
The Hacker News

An active campaign has been observed targeting internet-exposed instances running ComfyUI, a popular stable diffusion platform, to enlist them into a cryptocurrency mining and proxy botnet. "A purpose-built Python scanner continuously…

Publicerad: 2026-04-07 14:46:00 CEST
SecurityWeek Vulnerabilities

Researchers have demonstrated that GPU Rowhammer attacks can be used to escalate privileges. The post GPUBreach: Root Shell Access Achieved via GPU Rowhammer Attack appeared first on SecurityWeek.

Publicerad: 2026-04-07 13:31:38 CEST
The Hacker News

When talking about credential security, the focus usually lands on breach prevention. This makes sense when IBM’s 2025 Cost of a Data Breach Report puts the average cost of a breach at $4.4 million. Avoiding even one major incident is…

Publicerad: 2026-04-07 13:30:00 CEST
SecurityWeek Vulnerabilities

The group is using zero-days, quickly weaponizes fresh bugs, and exfiltrates and encrypts data within days of initial access. The post Medusa Ransomware Fast to Exploit Vulnerabilities, Breached Systems appeared first on SecurityWeek.

Publicerad: 2026-04-07 12:52:33 CEST
CERT-SE

Fortinet har publicerat information om en kritisk sårbarhet i Fortinet FortiClient EMS. [1] Det finns observationer som tyder på att sårbarheten utnyttjas aktivt. Fortinet har publicerat en säkerhetsuppdatering och uppmanar användare att installera den.

Publicerad: 2026-04-07 12:45:00 CEST
SecurityWeek Vulnerabilities

Shchukin is accused of extorting more than $2 million as the head of the GandCrab and REvil ransomware operations. The post German Police Unmask REvil Ransomware Leader appeared first on SecurityWeek.

Publicerad: 2026-04-07 11:24:40 CEST
Microsoft MSRC

Information published.

CVE-2026-35414
Publicerad: 2026-04-07 10:41:35 CEST
The Hacker News

New academic research has identified multiple RowHammer attacks against high-performance graphics processing units (GPUs) that could be exploited to escalate privileges and, in some cases, even take full control of a host. The efforts have…

Publicerad: 2026-04-07 10:38:00 CEST
Microsoft MSRC

Information published.

CVE-2026-35386
Publicerad: 2026-04-07 10:02:11 CEST
The Hacker News

A China-based threat actor known for deploying Medusa ransomware has been linked to the weaponization of a combination of zero-day and N-day vulnerabilities to orchestrate "high-velocity" attacks and break into susceptible internet-facing…

Publicerad: 2026-04-07 08:35:00 CEST
Mottaget denna vecka
Dark Reading

PRT-scan is the second campaign in recent months where a threat actor appears to have leveraged AI for automated targeting of a widespread GitHub misconfiguration.

Publicerad: 2026-04-06 23:38:53 CEST
Dark Reading

The attack on the popular NPM package Axios is just one of many targeting maintainers and has shone a light on how threat actors can scale sophisticated social engineering campaigns.

Publicerad: 2026-04-06 22:55:44 CEST
Dark Reading

The authentication bypass flaw, tracked as CVE-2026-35616, is the latest in a series of Fortinet vulnerabilities that have been exploited in the wild.

CVE-2026-35616
Publicerad: 2026-04-06 22:24:19 CEST
CISA KEV-katalog

Fortinet FortiClient EMS contains an improper access control vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. | Åtgärd: Apply mitigations per vendor instructions,…

CVE-2026-35616
Publicerad: 2026-04-06 02:00:00 CEST
Mottaget tidigare
Fortinet PSIRT

CVSSv3 Score: 9.1 An Improper Access Control vulnerability [CWE-284] in FortiClient EMS may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.Fortinet has observed this to be exploited in the…

CVSS 3
Publicerad: 2026-04-04 09:00:00 CEST
Cisco PSIRT

A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability exists because incorrect privileges are associated with…

CVE-2026-20110
Publicerad: 2026-04-03 04:43:54 CEST
CERT-SE

Den senaste tiden har det noterats flera leveranskedjeangrepp, senast genom Axios JavaScript-bibliotek. Australiens cybersäkerhetscenter har tagit fram en bra sammanfattning om den senaste tidens händelser, som finns att läsa nedan.

Publicerad: 2026-04-02 11:30:00 CEST
CISA KEV-katalog

TrueConf Client contains a download of code without integrity check vulnerability. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the…

CVE-2026-3502
Publicerad: 2026-04-02 02:00:00 CEST
Cisco PSIRT

A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected SSM On-Prem host. This vulnerability is…

CVE-2026-20160
Publicerad: 2026-04-02 01:00:00 CEST
Cisco PSIRT

Multiple vulnerabilities in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow a remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. For more…

CVE-2026-20085 CVE-2026-20087 CVE-2026-20088 CVE-2026-20089 CVE-2026-20090
Publicerad: 2026-04-02 01:00:00 CEST
Cisco PSIRT

A vulnerability in the web interface of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to elevate privileges on an affected system. This vulnerability is due to the improper transmission of…

CVE-2026-20151
Publicerad: 2026-04-02 01:00:00 CEST
Cisco PSIRT

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker with low privileges to access sensitive information that they are not authorized to…

CVE-2026-20155
Publicerad: 2026-04-02 01:00:00 CEST
Cisco PSIRT

A vulnerability in the change password functionality of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to bypass authentication and gain access to the system as Admin. This vulnerability is due…

CVE-2026-20093
Publicerad: 2026-04-02 01:00:00 CEST
Cisco PSIRT

A vulnerability in the Metadata update feature of Cisco Nexus Dashboard Insights could allow an authenticated, remote attacker to write arbitrary files to an affected system. This vulnerability is due to insufficient validation of the…

CVE-2026-20174
Publicerad: 2026-04-01 18:00:00 CEST
CISA KEV-katalog

Google Dawn contains an use-after-free vulnerability that could allow a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. This vulnerability could affect multiple Chromium-based…

CVE-2026-5281
Publicerad: 2026-04-01 02:00:00 CEST
CERT-SE

StepSecurity informerar om ett skadligt Axios JavaScript-bibliotek som funnits tillgängligt för nedladdning via NPM. [1] Enligt Socradar rör det sig om uppskattningsvis knappt tre timmar innan det togs bort. Vid installation laddas en…

Publicerad: 2026-03-31 15:22:00 CEST
CERT-SE

Vid uppsättning av en klientorganisation (engelska: tenant) i Microsofts molnmiljö är flexibiliteten hög och nya funktioner läggs till kontinuerligt. CERT-SE uppmanar organisationer att regelbundet se över aktiverade, eller inaktiverade,…

Publicerad: 2026-03-30 11:10:00 CEST
CISA KEV-katalog

Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (formerly Citrix Gateway) and NetScaler ADC FIPS and NDcPP contain an out-of-bounds reads vulnerability when configured as a SAML IDP leading to memory overread. | Åtgärd: Apply…

CVE-2026-3055
Publicerad: 2026-03-30 02:00:00 CEST
CERT-SE

I veckans brev från CERT-SE finner du en inbjudan till CERT-SE:s introduktionsutbildning i MISP. Utbildningen fokuserar på den praktiska användningen av MISP samt hur du kan använda verktyget i din vardag. Du kan även läsa om ett angrepp…

Publicerad: 2026-03-27 15:50:00 CET
CISA KEV-katalog

F5 BIG-IP APM contains a stack-based buffer overflow vulnerability that could allow a threat actor to achieve remote code execution. | Åtgärd: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud…

CVE-2025-53521
Publicerad: 2026-03-27 01:00:00 CET
CISA KEV-katalog

Aquasecurity Trivy contains an embedded malicious code vulnerability that could allow an attacker to gain access to everything in the CI/CD environment, including all tokens, SSH keys, cloud credentials, database passwords, and any…

CVE-2026-33634
Publicerad: 2026-03-26 01:00:00 CET
CISA KEV-katalog

Langflow contains a code injection vulnerability that could allow building public flows without requiring authentication. | Åtgärd: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or…

CVE-2026-33017
Publicerad: 2026-03-25 01:00:00 CET
CERT-SE

Citrix har publicerat information om sårbarheten CVE-2026-3055 som påverkar NetScaler Gateway och NetScaler ADC. Sårbarheten beskrivs som kritisk och har fått en CVSS v4.0-klassning på 9.3. [1]

CVE-2026-3055 CVSS 4.0
Publicerad: 2026-03-24 16:00:00 CET
CERT-SE

I veckobrevet hittar du information om ett flertal sårbarheter, bland annat gällande Microsoft SharePoint och hur en sårbarhet i Cisco FMC nu exploateras. Du finner även nyheter, rapporter och analyser inom cybersäkerhetsområdet från veckan som har gått.

Publicerad: 2026-03-20 14:18:00 CET
CERT-SE

Roundcube informerar om en säkerhetsuppdatering som åtgärdar flera sårbarheter i Roundcube Webmail. Ingen av sårbarheterna har i nuläget tilldelats CVE eller CVSS-klassificering. Den som framstår som mest allvarlig har enligt CERT-SE:s…

CVSS 9.0
Publicerad: 2026-03-20 13:16:00 CET
CISA KEV-katalog

Craft CMS contains a code injection vulnerability that allows a remote attacker to execute arbitrary code. | Åtgärd: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of…

CVE-2025-32432
Publicerad: 2026-03-20 01:00:00 CET
CISA KEV-katalog

Laravel Livewire contain a code injection vulnerability that could allow unauthenticated attackers to achieve remote command execution in specific scenarios. | Åtgärd: Apply mitigations per vendor instructions, follow applicable BOD 22-01…

CVE-2025-54068
Publicerad: 2026-03-20 01:00:00 CET
CISA KEV-katalog

Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain an improper locking vulnerability that could allow a malicious application to cause unexpected changes in memory shared between processes. | Åtgärd: Apply mitigations per vendor…

CVE-2025-43510
Publicerad: 2026-03-20 01:00:00 CET
Fortinet PSIRT

CVSSv3 Score: 6.7 An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow a privileged attacker with super-admin…

CVSS 3
Publicerad: 2026-03-10 08:00:00 CET
Fortinet PSIRT

CVSSv3 Score: 6.0 An Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability [CWE-88] in FortiDeceptor WEBUI may allow a privileged attacker with super-admin profile and CLI access to delete…

CVSS 3
Publicerad: 2026-03-10 08:00:00 CET
Fortinet PSIRT

CVSSv3 Score: 3.4 An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiManager and FortiAnalyzer may allow an attacker to bypass bruteforce protections via exploitation of race conditions. Revised on 2026-03-10 00:00:00

CVSS 3
Publicerad: 2026-03-10 08:00:00 CET
Fortinet PSIRT

CVSSv3 Score: 7.3 An Improper Control of Interaction Frequency vulnerability [CWE-799] in FortiWeb may allow a remote unauthenticated attacker to bypass the authentication rate-limit via crafted requests. The success of the attack depends…

CVSS 3
Publicerad: 2026-03-10 08:00:00 CET
Fortinet PSIRT

CVSSv3 Score: 7.7 A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability [CWE-120] in FortiSwitchAXFixed may allow an unauthenticated attacker within the same adjacent network to execute unauthorized code or…

CVSS 3
Publicerad: 2026-03-10 08:00:00 CET
Fortinet PSIRT

CVSSv3 Score: 7.0 A Stack-based Buffer Overflow vulnerability [CWE-121] in FortiManager fgtupdates service may allow a remote unauthenticated attacker to execute unauthorized commands via crafted requests, if the service is enabled. The…

CVSS 3
Publicerad: 2026-03-10 08:00:00 CET
Fortinet PSIRT

CVSSv3 Score: 6.5 A use of externally-controlled format string vulnerability [CWE-134] in FortiAnalyzer, FortiAnalyzer Cloud, FortiManager and FortiManager Cloud fazsvcd daemon may allow a remote privileged attacker with admin profile to…

CVSS 3
Publicerad: 2026-03-10 08:00:00 CET
Fortinet PSIRT

CVSSv3 Score: 5.3 An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] in FortiOS SSL-VPN may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency…

CVSS 3
Publicerad: 2026-02-10 09:00:00 CET
Fortinet PSIRT

CVSSv3 Score: 9.8 CVE-2025-15467Parsing CMS AuthEnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially…

CVE-2025-15467 CVSS 3
Publicerad: 2026-01-30 09:00:00 CET
CERT-SE

F5 Networks har publicerat en större mängd sårbarhetsuppdateringar gällande produkterna BIG-IP, F5OS, BIG-IP Next for Kubernetes, BIG-IQ, och APM Clients [1]. Uppdateringarna är en åtgärd som svar på ett tidigare cyberangrepp mot F5…

Publicerad: 2025-10-16 10:15:00 CEST
NVD (National Vulnerability Database)

A vulnerability classified as problematic has been found in Ortus Solutions ColdBox Elixir 3.1.6. This affects an unknown part of the file src/defaultConfig.js of the component ENV Variable Handler. The manipulation leads to information…

CVE-2021-4430
Publicerad: 2023-11-06 09:15:21 CET
NVD (National Vulnerability Database)

A vulnerability was found in Vaerys-Dawn DiscordSailv2 up to 2.10.2. It has been rated as critical. Affected by this issue is some unknown functionality of the component Tag Handler. The manipulation leads to improper access controls.…

CVE-2018-25093
Publicerad: 2023-11-06 02:15:08 CET
NVD (National Vulnerability Database)

** UNSUPPPORTED WHEN ASSIGNED ** ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Magnesium-PHP up to 0.3.0. It has been classified as problematic. Affected is the function formatEmailString of the file…

CVE-2017-20187
Publicerad: 2023-11-05 22:15:09 CET
NVD (National Vulnerability Database)

A vulnerability was found in Vaerys-Dawn DiscordSailv2 up to 2.10.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Command Mention Handler. The manipulation leads to improper…

CVE-2018-25092
Publicerad: 2023-11-05 22:15:09 CET
NVD (National Vulnerability Database)

A security issue was discovered in kube-apiserver that allows an aggregated API server to redirect client traffic to any URL. This could lead to the client performing unexpected actions as well as forwarding the client's API server credentials to third parties.

CVE-2022-3172
Publicerad: 2023-11-03 21:15:08 CET
NVD (National Vulnerability Database)

Ivanti Avalanche Smart Device Service Missing Authentication Local Privilege Escalation Vulnerability

CVE-2022-43554
Publicerad: 2023-11-03 21:15:08 CET
NVD (National Vulnerability Database)

Ivanti Avalanche Printer Device Service Missing Authentication Local Privilege Escalation Vulnerability

CVE-2022-43555
Publicerad: 2023-11-03 21:15:08 CET
NVD (National Vulnerability Database)

A locally authenticated attacker with low privileges can bypass authentication due to insecure inter-process communication.

CVE-2022-44569
Publicerad: 2023-11-03 21:15:08 CET
NVD (National Vulnerability Database)

In swtpm before 0.4.2 and 0.5.x before 0.5.1, a local attacker may be able to overwrite arbitrary files via a symlink attack against a temporary file such as TMP2-00.permall.

CVE-2020-28407
Publicerad: 2023-11-03 05:15:15 CET
NVD (National Vulnerability Database)

bcrypt password hashing in Botan before 2.1.0 does not correctly handle passwords with a length between 57 and 72 characters, which makes it easier for attackers to determine the cleartext password.

CVE-2017-7252
Publicerad: 2023-11-03 02:15:07 CET
Threatpost

Researchers uncover a watering hole attack likely carried out by APT TA423, which attempts to plant the ScanBox JavaScript-based reconnaissance tool.

Publicerad: 2022-08-30 18:00:43 CEST
Threatpost

Lockbit is by far this summer’s most prolific ransomware group, trailed by two offshoots of the Conti group.

Publicerad: 2022-08-26 18:44:27 CEST
Threatpost

Twitter is blasted for security and privacy lapses by the company’s former head of security who alleges the social media giant’s actions amount to a national security risk.

Publicerad: 2022-08-24 16:17:04 CEST
Threatpost
Publicerad: 2022-08-22 15:59:06 CEST
Threatpost

Separate fixes to macOS and iOS patch respective flaws in the kernel and WebKit that can allow threat actors to take over devices and are under attack.

Publicerad: 2022-08-19 17:25:56 CEST
Threatpost

An insufficient validation input flaw, one of 11 patched in an update this week, could allow for arbitrary code execution and is under active attack.

Publicerad: 2022-08-18 16:31:38 CEST