Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

34464 risultati

VulnerabilitàAlta
CVE-2026-9828 - Logback deserialization whitelist bypass for java.lang and java.util

CVE ID :CVE-2026-9828 Published : May 28, 2026, 2:16 p.m. | 2 hours, 15 minutes ago Description :Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection albeit heavily restricted. More precisely, an attacker able to influence serialized data sent to SimpleSocketServer or SimpleSSLSocketServer can instantiate objects from classes in the java.lang and java.util packages that are not explicitly blocked. Although deserialization is heavily restricted by HardenedObjectInputStream and no practical way to achieve remote code execution or significant privilege escalation has been identified, this issue constitutes a bypass of the intended security restrictions. This issue affects logback: through 1.5.32 inclusive. Severity: 1.2 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 mag 2026
VulnerabilitàAlta
CVE-2026-8990 - Authentication Bypass in Kidsview

CVE ID :CVE-2026-8990 Published : May 28, 2026, 2:16 p.m. | 2 hours, 15 minutes ago Description :A user with physical access to a smartphone can bypass authentication mechanism of Kidsview mobile application and grant himself full access to the device owner's account by interacting with application's push notification. This issue was fixed in version 4.4.3 Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 mag 2026
VulnerabilitàAlta
CVE-2026-8980 - Privilege Escalation

CVE ID :CVE-2026-8980 Published : May 28, 2026, 2:16 p.m. | 2 hours, 15 minutes ago Description :The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to privilege escalation. An authenticated low-privileged user can change the passwords of the admin (operator) and manufacturer accounts via crafted POST requests. Severity: 9.3 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 mag 2026
VulnerabilitàAlta
CVE-2026-8979 - Authentication Bypass

CVE ID :CVE-2026-8979 Published : May 28, 2026, 2:16 p.m. | 15 minutes ago Description :The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to an authentication bypass. An unauthenticated remote attacker can change the password of the user account via a crafted POST request to the /operator/operator endpoint. Severity: 9.3 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 mag 2026
VulnerabilitàAlta
CVE-2026-49237 - Local Privilege Escalation in Canonical Multipass

CVE ID :CVE-2026-49237 Published : May 28, 2026, 2:16 p.m. | 15 minutes ago Description :An issue was discovered in Canonical Multipass for macOS before version 1.16.3 due to an incomplete fix for CVE-2025-5199. While the patch in version 1.16.0 updated the ownership of the multipassd daemon binary to root:wheel, five co-located binaries (multipass, qemu-img, qemu-system-aarch64, qemu-system-x86_64, and sshfs_server) in /Library/Application Support/com.canonical.multipass/bin/ retain ownership by the installing user and remain writable. Because the root LaunchDaemon (com.canonical.multipassd.plist) configures a PATH environment variable that prioritizes this user-writable directory and invokes these auxiliary binaries by their bare names, a local attacker can replace an auxiliary binary (such as qemu-img) with a malicious wrapper. When the root daemon subsequently triggers the binary during routine execution (e.g., via multipass launch), the malicious code executes with root privileges, leading to local privilege escalation. Severity: 7.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 mag 2026
VulnerabilitàAlta
CVE-2026-49238 - SFTP Server VM Escape in Canonical Multipass

CVE ID :CVE-2026-49238 Published : May 28, 2026, 2:16 p.m. | 15 minutes ago Description :An issue was discovered in Canonical Multipass before version 1.16.3. The host-side SFTP server component (sshfs_server), which executes with root privileges on the host, contains a path containment bypass vulnerability within its validate_path function in src/sshfs_mount/sftp_server.cpp. The function performs a plain string prefix comparison on requested paths without path separator validation or dot-dot (..) normalization. A local attacker with root privileges inside a guest virtual machine can bypass the FUSE layer by injecting raw SFTP frames (such as an SSH_FXP_OPEN request) directly into the sshfs_server process stdin/stdout pipes via procfs. By supplying a path containing directory traversal sequences that match the allowed mount prefix, the attacker can force the host-side root process to resolve the traversal and open files outside the designated mount boundary. This allows a guest-side user to read arbitrary files on the host filesystem, resulting in a virtual machine escape. Severity: 8.4 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 mag 2026
VulnerabilitàAlta
CVE-2026-37266 - Apache Struts Remote Code Execution

CVE ID :CVE-2026-37266 Published : May 28, 2026, 2:16 p.m. | 16 minutes ago Description :An issue in Responsive File Manager Responsive FileManager Version 9.14.0 allows a remote attacker to execute arbitrary code via the force_download.php component Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 mag 2026
VulnerabilitàAlta
CVE-2026-42250 - Off-by-One Leading to Out-of-Bounds Write in bzip2

CVE ID :CVE-2026-42250 Published : May 28, 2026, 2:16 p.m. | 15 minutes ago Description :bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service). This issue was fixed in bzip2 version 1.0.9 Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 mag 2026
VulnerabilitàAlta
CVE-2026-37579 - SMSGate sms-core Remote Code Execution

CVE ID :CVE-2026-37579 Published : May 28, 2026, 2:16 p.m. | 16 minutes ago Description :An issue in SMSGate sms-core Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 mag 2026
News
Vulnerability in Kidsview application

Vulnerability in Kidsview application Vulnerability in Kidsview application CVE ID CVE-2026-8990 Publication date 28 May 2026 Vendor View Concept Product Kidsview Vulnerable versions From 4.0.1 to 4.4.3 Vulnerability type (CWE) Authentica ... Read more Published Date: May 28, 2026 (4 days ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom28 mag 2026
News
Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal

Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal Microsoft has come out strongly in favor of Coordinated Vulnerability Disclosure (CVD), urging the research community to share their findings and give affected vendors an opportunity to better underst ... Read more Published Date: May 28, 2026 (3 days, 22 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-45498 CVE-2026-41091 CVE-2026-45585 CVE-2026-42945 CVE-2026-31635 CVE-2026-33825

CVEfeed Newsroom28 mag 2026
News
ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More

ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More Every time you think the industry has finally stopped doing some reckless, low-effort crap, somebody spins up a fresh box full of sketchy loaders, fake installers, recycled social-engineering bait, an ... Read more Published Date: May 28, 2026 (3 days, 22 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-45585 CVE-2026-8398 CVE-2026-42945 CVE-2026-31635

CVEfeed Newsroom28 mag 2026

Pagina 1305 di 2872

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.