Sårbarhetsflöden

Uppdateras var 300 sekund(er). Senast uppdaterad: 2026-02-17 17:14:27 CET. Visar 10 artiklar per källa från: NVD (National Vulnerability Database), SecurityWeek Vulnerabilities, CERT-SE, CISA KEV-katalog, Microsoft MSRC, Cisco PSIRT, Fortinet PSIRT, Palo Alto Networks Advisories, The Hacker News, Threatpost, Dark Reading. Tidszon: Europe/Stockholm.

Källfilter (klicka för att visa/dölja)
Vy: Kompakt visar endast titel/källa/tid.
Rensa filter
Mottaget idag
SecurityWeek Vulnerabilities

Eurail has confirmed that the stolen data is up for sale, but it’s still trying to determine how many individuals are impacted. The post Hackers Offer to Sell Millions of Eurail User Records appeared first on SecurityWeek.

Publicerad: 2026-02-17 16:27:12 CET
SecurityWeek Vulnerabilities

New research shows attackers increasingly abusing APIs at machine speed as AI-driven systems widen exposure and amplify impact. The post API Threats Grow in Scale as AI Expands the Blast Radius appeared first on SecurityWeek.

Publicerad: 2026-02-17 15:00:00 CET
SecurityWeek Vulnerabilities

As nation-state actors, ransomware groups, and aging infrastructure collide, organizations must rethink how they defend critical operations through resilience, visibility, and modern security strategies. The post Cyber Insights 2026: The…

Publicerad: 2026-02-17 15:00:00 CET
SecurityWeek Vulnerabilities

Polish police said they found evidence of cybercrime on the 47-year-old suspect’s devices. The post Man Linked to Phobos Ransomware Arrested in Poland appeared first on SecurityWeek.

Publicerad: 2026-02-17 13:54:34 CET
The Hacker News

Cybersecurity researchers have disclosed details of a new SmartLoader campaign that involves distributing a trojanized version of a Model Context Protocol (MCP) server associated with Oura Health to deliver an information stealer known as…

Publicerad: 2026-02-17 13:42:00 CET
The Hacker News

My objectiveThe role of NDR in SOC workflowsStarting up the NDR systemHow AI complements the human responseWhat else did I try out?What could I see with NDR that I wouldn’t otherwise?Am I ready to be a network security analyst now? My…

Publicerad: 2026-02-17 12:30:00 CET
SecurityWeek Vulnerabilities

Industrial cybersecurity firm Dragos has published its 9th Year in Review OT/ICS Cybersecurity Report. The post 3 Threat Groups Started Targeting ICS/OT in 2025: Dragos appeared first on SecurityWeek.

Publicerad: 2026-02-17 12:05:26 CET
SecurityWeek Vulnerabilities

Researchers at ETH Zurich have tested the security of Bitwarden, LastPass, Dashlane, and 1Password password managers. The post Password Managers Vulnerable to Vault Compromise Under Malicious Server appeared first on SecurityWeek.

Publicerad: 2026-02-17 10:30:46 CET
The Hacker News

Apple on Monday released a new developer beta of iOS and iPadOS with support for end-to-end encryption (E2EE) in Rich Communications Services (RCS) messages. The feature is currently available for testing in iOS and iPadOS 26.4 Beta, and…

Publicerad: 2026-02-17 07:44:00 CET
Mottaget igår
The Hacker News

Cybersecurity researchers disclosed they have detected a case of an information stealer infection successfully exfiltrating a victim's OpenClaw (formerly Clawdbot and Moltbot) configuration environment. "This finding marks a significant…

Publicerad: 2026-02-16 19:43:00 CET
The Hacker News

A new study has found that multiple cloud-based password managers, including Bitwarden, Dashlane, and LastPass, are susceptible to password recovery attacks under certain conditions. "The attacks range in severity from integrity violations…

Publicerad: 2026-02-16 19:06:00 CET
Dark Reading

The GS7 cyberthreat group targets US financial institutions with near-perfect imitations of corporate portals to steal credentials and gain remote access.

Publicerad: 2026-02-16 19:05:55 CET
SecurityWeek Vulnerabilities

Luxury brands were among the dozens of major companies whose Salesforce instances were targeted by Scattered LAPSUS$ Hunters. The post Dior, Louis Vuitton, Tiffany Fined $25 Million in South Korea After Data Breaches appeared first on SecurityWeek.

Publicerad: 2026-02-16 16:09:13 CET
SecurityWeek Vulnerabilities

CISA is currently operating at roughly 38% capacity (888 out of 2,341 staff) due to the DHS shutdown that began February 14, 2026. The post CISA Navigates DHS Shutdown With Reduced Staff appeared first on SecurityWeek.

Publicerad: 2026-02-16 14:49:03 CET
The Hacker News

Cybersecurity researchers have disclosed details of a new mobile spyware platform dubbed ZeroDayRAT that's being advertised on Telegram as a way to grab sensitive data and facilitate real-time surveillance on Android and iOS devices. "The…

Publicerad: 2026-02-16 11:24:00 CET
Mottaget tidigare
Dark Reading

As AI deployments scale and start to include packs of agents autonomously working in concert, organizations face a naturally amplified attack surface.

Publicerad: 2026-02-13 17:49:39 CET
Cisco PSIRT

A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco…

CVE-2026-20045
Publicerad: 2026-02-13 16:21:01 CET
CERT-SE

Idag kom nyheten om ett nytt samarbete gällande cybersäkerhet mellan Sverige och Ukraina, något som går att ta del av i veckobrevet. Utöver det kan du läsa om andra nyheter, rapporter och analyser inom cybersäkerhetsområdet.

Publicerad: 2026-02-13 13:37:00 CET
CISA KEV-katalog

BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command injection vulnerability. Successful exploitation could allow an unauthenticated remote attacker to execute operating system commands in the context of…

CVE-2026-1731
Publicerad: 2026-02-13 01:00:00 CET
Cisco PSIRT

Multiple Cisco products are affected by vulnerabilities in the HTTP Multipurpose Internet Mail Extensions (MIME) Decoder that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to leak possible sensitive…

CVE-2025-20359 CVE-2025-20360
Publicerad: 2026-02-12 19:38:13 CET
CISA KEV-katalog

Apple iOS, macOS, tvOS, watchOS, and visionOS contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow an attacker with memory write the capability to execute arbitrary code. |…

CVE-2026-20700
Publicerad: 2026-02-12 01:00:00 CET
CISA KEV-katalog

Microsoft Configuration Manager contains an SQL injection vulnerability. An unauthenticated attacker could exploit this vulnerability by sending specially crafted requests to the target environment which are processed in an unsafe manner…

CVE-2024-43468
Publicerad: 2026-02-12 01:00:00 CET
CISA KEV-katalog

Notepad++ when using the WinGUp updater, contains a download of code without integrity check vulnerability that could allow an attacker to intercept or redirect update traffic to download and execute an attacker-controlled installer. This…

CVE-2025-15556
Publicerad: 2026-02-12 01:00:00 CET
CISA KEV-katalog

SolarWinds Web Help Desk contains a security control bypass vulnerability that could allow an unauthenticated attacker to gain access to certain restricted functionality. | Åtgärd: Apply mitigations per vendor instructions, follow…

CVE-2025-40536
Publicerad: 2026-02-12 01:00:00 CET
Fortinet PSIRT

CVSSv3 Score: 6.4 An Improper Link Resolution Before File Access vulnerability [CWE-59] in FortiClient Windows may allow a local low-privilege attacker to perform an arbitrary file write with elevated permissions via crafted named pipe messages. Revised on 2026-02-10 00:00:00

CVSS 3
Publicerad: 2026-02-10 09:00:00 CET
Fortinet PSIRT

CVSSv3 Score: 3.8 An Improper Verification of Source of a Communication Channel vulnerability [CWE-940] in FortiOS FSSO Terminal Services Agent may allow an authenticated user with knowledge of FSSO policy configurations to gain…

CVSS 3
Publicerad: 2026-02-10 09:00:00 CET
Fortinet PSIRT

CVSSv3 Score: 6.7 A Use of Externally-Controlled Format String vulnerability [CWE-134] in FortiGate may allow an authenticated admin to execute unauthorized code or commands via specifically crafted configuration. Revised on 2026-02-10 00:00:00

CVSS 3
Publicerad: 2026-02-10 09:00:00 CET
Fortinet PSIRT

CVSSv3 Score: 7.5 An Authentication Bypass by Primary Weakness vulnerability [CWE-305] in FortiOS fnbamd may allow an unauthenticated attacker to bypass LDAP authentication of Agentless VPN or FSSO policy, under specific LDAP server configuration. Revised on 2026-02-10 00:00:00

CVSS 3
Publicerad: 2026-02-10 09:00:00 CET
Fortinet PSIRT

CVSSv3 Score: 6.8 A missing authorization vulnerability [CWE-862] in FortiAuthenticator may allow a read-only admin to make modification to local users via a file upload to an unprotected endpoint. Revised on 2026-02-10 00:00:00

CVSS 3
Publicerad: 2026-02-10 09:00:00 CET
Fortinet PSIRT

CVSSv3 Score: 5.2 An HTTP request smuggling vulnerability [CWE-444] in FortiOS may allow an unauthenticated attacker to smuggle an unlogged http request through the firewall policies via a specially crafted header Revised on 2026-02-10 00:00:00

CVSS 3
Publicerad: 2026-02-10 09:00:00 CET
Fortinet PSIRT

CVSSv3 Score: 5.3 An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] in FortiOS SSL-VPN may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency…

CVSS 3
Publicerad: 2026-02-10 09:00:00 CET
Fortinet PSIRT

CVSSv3 Score: 7.9 An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiSandbox may allow an unauthenticated attacker to execute commands via crafted requests.FortiSandbox…

CVSS 3
Publicerad: 2026-02-10 09:00:00 CET
CISA KEV-katalog

Microsoft MSHTML Framework contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network. | Åtgärd: Apply mitigations per vendor instructions, follow applicable…

CVE-2026-21513
Publicerad: 2026-02-10 01:00:00 CET
CISA KEV-katalog

Microsoft Windows Remote Access Connection Manager contains a NULL pointer dereference that could allow an unauthorized attacker to deny service locally. | Åtgärd: Apply mitigations per vendor instructions, follow applicable BOD 22-01…

CVE-2026-21525
Publicerad: 2026-02-10 01:00:00 CET
CISA KEV-katalog

Microsoft Windows Shell contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network. | Åtgärd: Apply mitigations per vendor instructions, follow applicable BOD…

CVE-2026-21510
Publicerad: 2026-02-10 01:00:00 CET
CISA KEV-katalog

Microsoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to elevate privileges locally. | Åtgärd: Apply mitigations per vendor instructions, follow applicable…

CVE-2026-21533
Publicerad: 2026-02-10 01:00:00 CET
CISA KEV-katalog

Microsoft Desktop Windows Manager contains a type confusion vulnerability that could allow an authorized attacker to elevate privileges locally. | Åtgärd: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for…

CVE-2026-21519
Publicerad: 2026-02-10 01:00:00 CET
CERT-SE

Behöver din organisation stärka sin förmåga att hantera cyberhot och arbeta effektivt med informationsdelning?

Publicerad: 2026-02-09 10:30:00 CET
CERT-SE

Måndagen 9 februari lanseras MISP-SE, något som du kan läsa mer om nedan tillsammans med andra nyheter, rapporter och analyser inom cybersäkerhetsområdet.

Publicerad: 2026-02-06 15:15:00 CET
Fortinet PSIRT

CVSSv3 Score: 9.1 An improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiClientEMS may allow an unauthenticated attacker to execute unauthorized code or commands via…

CVSS 3
Publicerad: 2026-02-06 09:00:00 CET
Cisco PSIRT

A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system.…

CVE-2026-20111
Publicerad: 2026-02-05 01:00:00 CET
Cisco PSIRT

A vulnerability in the Dynamic Vectoring and Streaming (DVS) Engine implementation of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to bypass the anti-malware scanner, allowing…

CVE-2026-20056
Publicerad: 2026-02-05 01:00:00 CET
Cisco PSIRT

A vulnerability in the Certificate Management feature of Cisco Meeting Management could allow an authenticated, remote attacker to upload arbitrary files, execute arbitrary commands, and elevate privileges to root on an affected system.…

CVE-2026-20098
Publicerad: 2026-02-05 01:00:00 CET
CERT-SE

Denna vecka har det rapporterats om ett flertal sårbarheter, bland annat gällande nolldagssårbarheter i Microsoft Office och Fortinet FortiOS. Utöver detta går det även att läsa CERT-PL:s rapport om angreppet mot polska energianläggningar som skedde i december.

Publicerad: 2026-01-30 14:50:00 CET
CERT-SE

Ivanti har publicerat säkerhetsuppdateringar för två kritiska sårbarheter i Ivanti Endpoint Manager Mobile (EPMM). [1]

Publicerad: 2026-01-30 10:05:00 CET
Fortinet PSIRT

CVSSv3 Score: 9.8 CVE-2025-15467Parsing CMS AuthEnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially…

CVE-2025-15467 CVSS 3
Publicerad: 2026-01-30 09:00:00 CET
CERT-SE

SolarWinds har publicerat uppdateringar som åtgärdar följande fyra kritiska sårbarheter i SolarWinds Web Help Desk: CVE-2025-40551 CVE-2025-40552 CVE-2025-40553 CVE-2025-40554

CVE-2025-40551 CVE-2025-40552 CVE-2025-40553 CVE-2025-40554
Publicerad: 2026-01-29 15:15:00 CET
CERT-SE

Microsoft har publicerat information om en nolldagssårbarhet i Microsoft Office som exploateras av hotaktörer [1]. Sårbarheten (CVE-2026-21509) har fått CVSS-klassificering 7.8 (CVSS v.3.1) av Microsoft [2] och kan ge en oautentiserad…

CVE-2026-21509 CVSS 7.8 CVSS 3.1
Publicerad: 2026-01-27 12:30:00 CET
CERT-SE

EU-kommissionen har under veckan presenterat ett nytt cybersäkerhetspaket, där cybersäkerhetsmyndigheten ENISA får en tydlig förstärkning. Detta går att läsa om i veckobrevet tillsammans med flera nyheter, rapporter och analyser inom cybersäkerhetsområdet.

Publicerad: 2026-01-23 15:25:00 CET
Cisco PSIRT

A vulnerability in the read-only maintenance shell of Cisco Intersight Virtual Appliance could allow an authenticated, local attacker with administrative privileges to elevate privileges to root on the virtual appliance. This vulnerability…

CVE-2026-20092
Publicerad: 2026-01-21 17:00:00 CET
CERT-SE

Oracle har publicerat information om en sårbarhet i Oracle HTTP Server och WebLogic Server Proxy Plug-in. Sårbarheten, CVE-2026-21962, är kritisk och har fått en CVSS-klassning på 10. [1]

CVE-2026-21962 CVSS 10
Publicerad: 2026-01-21 13:00:00 CET
NVD (National Vulnerability Database)

A vulnerability classified as problematic has been found in Ortus Solutions ColdBox Elixir 3.1.6. This affects an unknown part of the file src/defaultConfig.js of the component ENV Variable Handler. The manipulation leads to information…

CVE-2021-4430
Publicerad: 2023-11-06 09:15:21 CET
NVD (National Vulnerability Database)

A vulnerability was found in Vaerys-Dawn DiscordSailv2 up to 2.10.2. It has been rated as critical. Affected by this issue is some unknown functionality of the component Tag Handler. The manipulation leads to improper access controls.…

CVE-2018-25093
Publicerad: 2023-11-06 02:15:08 CET
NVD (National Vulnerability Database)

** UNSUPPPORTED WHEN ASSIGNED ** ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Magnesium-PHP up to 0.3.0. It has been classified as problematic. Affected is the function formatEmailString of the file…

CVE-2017-20187
Publicerad: 2023-11-05 22:15:09 CET
NVD (National Vulnerability Database)

A vulnerability was found in Vaerys-Dawn DiscordSailv2 up to 2.10.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Command Mention Handler. The manipulation leads to improper…

CVE-2018-25092
Publicerad: 2023-11-05 22:15:09 CET
NVD (National Vulnerability Database)

A security issue was discovered in kube-apiserver that allows an aggregated API server to redirect client traffic to any URL. This could lead to the client performing unexpected actions as well as forwarding the client's API server credentials to third parties.

CVE-2022-3172
Publicerad: 2023-11-03 21:15:08 CET
NVD (National Vulnerability Database)

Ivanti Avalanche Smart Device Service Missing Authentication Local Privilege Escalation Vulnerability

CVE-2022-43554
Publicerad: 2023-11-03 21:15:08 CET
NVD (National Vulnerability Database)

Ivanti Avalanche Printer Device Service Missing Authentication Local Privilege Escalation Vulnerability

CVE-2022-43555
Publicerad: 2023-11-03 21:15:08 CET
NVD (National Vulnerability Database)

A locally authenticated attacker with low privileges can bypass authentication due to insecure inter-process communication.

CVE-2022-44569
Publicerad: 2023-11-03 21:15:08 CET
NVD (National Vulnerability Database)

In swtpm before 0.4.2 and 0.5.x before 0.5.1, a local attacker may be able to overwrite arbitrary files via a symlink attack against a temporary file such as TMP2-00.permall.

CVE-2020-28407
Publicerad: 2023-11-03 05:15:15 CET
NVD (National Vulnerability Database)

bcrypt password hashing in Botan before 2.1.0 does not correctly handle passwords with a length between 57 and 72 characters, which makes it easier for attackers to determine the cleartext password.

CVE-2017-7252
Publicerad: 2023-11-03 02:15:07 CET
Threatpost

Researchers uncover a watering hole attack likely carried out by APT TA423, which attempts to plant the ScanBox JavaScript-based reconnaissance tool.

Publicerad: 2022-08-30 18:00:43 CEST
Threatpost

Lockbit is by far this summer’s most prolific ransomware group, trailed by two offshoots of the Conti group.

Publicerad: 2022-08-26 18:44:27 CEST
Threatpost

Twitter is blasted for security and privacy lapses by the company’s former head of security who alleges the social media giant’s actions amount to a national security risk.

Publicerad: 2022-08-24 16:17:04 CEST
Threatpost
Publicerad: 2022-08-22 15:59:06 CEST
Threatpost

Separate fixes to macOS and iOS patch respective flaws in the kernel and WebKit that can allow threat actors to take over devices and are under attack.

Publicerad: 2022-08-19 17:25:56 CEST
Threatpost

An insufficient validation input flaw, one of 11 patched in an update this week, could allow for arbitrary code execution and is under active attack.

Publicerad: 2022-08-18 16:31:38 CEST