Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

34825 risultati

News
ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More

ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More Every time you think the industry has finally stopped doing some reckless, low-effort crap, somebody spins up a fresh box full of sketchy loaders, fake installers, recycled social-engineering bait, an ... Read more Published Date: May 28, 2026 (3 days, 22 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-45585 CVE-2026-8398 CVE-2026-42945 CVE-2026-31635

CVEfeed Newsroom28 mag 2026
News
Gehackte FortiClient-servers verspreiden malware vermomd als Fortinet-patch

Gehackte FortiClient-servers verspreiden malware vermomd als Fortinet-patch Criminelen gebruiken gehackte Fortinet FortiClient-servers om binnen organisaties malware te verspreiden die vermomd is als een update van Fortinet. Dat meldt cybersecuritybedrijf Arctic Wolf. FortiCl ... Read more Published Date: May 28, 2026 (3 days, 20 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-35616

CVEfeed Newsroom28 mag 2026
VulnerabilitàAlta
CVE-2026-9658 - Plack::Middleware::Security::Common versions before 0.13.1 for Perl did not block header injections in request paths

CVE ID :CVE-2026-9658 Published : May 28, 2026, 1:16 p.m. | 1 hour, 15 minutes ago Description :Plack::Middleware::Security::Common versions before 0.13.1 for Perl did not block header injections in request paths. The header injection rule was ineffective at blocking header injections in the request paths unless they were double-encoded, for example, GET /path\r\nHTTP/1.1\r\nHost: secret.example.com Note that it is unclear whether request paths with CRLF followed by additional headers would be blocked by reverse proxies, or how they would be processed by Plack-based servers. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 mag 2026
VulnerabilitàAlta
CVE-2026-9818 - Roundcube Local/Private URL Fetch Bypass

CVE ID :CVE-2026-9818 Published : May 28, 2026, 1:16 p.m. | 1 hour, 15 minutes ago Description :Roundcube's HTML sanitization path for message rendering allows loopback, localhost, RFC1918, link-local, and ULA URLs even when remote content loading is disabled. A remote attacker can send an HTML email that causes the victim's browser to issue requests to local or private-network services simply by opening the message preview. Severity: 4.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 mag 2026
VulnerabilitàAlta
CVE-2026-40914 - Apache Artemis Stomp Protocol, Apache ActiveMQ Artemis Stomp Protocol: Address routing-type can be updated by STOMP protocol user without the createAddress permission

CVE ID :CVE-2026-40914 Published : May 28, 2026, 1:16 p.m. | 1 hour, 15 minutes ago Description :A vulnerability exists in Apache Artemis whereby an application using the STOMP protocol with security credentials that grant either the consume or send permission on an address can augment the routing-type supported by that address even if said user doesn't have the createAddress permission for that particular address. A user could successfully send a message to an address or consume a message from a queue with a routing-type not supported by the corresponding address when that operation should actually be rejected on the basis that the user doesn't have permission to change the routing-type of the address. Even though the user was already granted permission to send and/or consume messages, they should not be able to augment the routing-type of the address without the createAddress permission. This issue affects Apache Artemis: from 2.50.0 through 2.53.0; Apache ActiveMQ Artemis: from 2.0.0 through 2.44.0. Users are recommended to upgrade to version 2.54.0, which fixes the issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 mag 2026
News
CISA adds Three Vulnerabilities to KEV Catalog

CISA adds Three Vulnerabilities to KEV Catalog May 28, 2026OverviewCISA has added three new vulnerabilities to its Known Exploited Vulnerabilities catalog:CVE-2026-8398 (Daemon Tools Lite Embedded Malicious Code)CVE-2026-45321 (TanStack Unspecifie ... Read more Published Date: May 28, 2026 (3 days, 20 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-48027 CVE-2026-45659 CVE-2026-48172 CVE-2026-8398 CVE-2026-45321

CVEfeed Newsroom28 mag 2026
News
Vulnerability in bzip2 software

Vulnerability in bzip2 software Vulnerability in bzip2 software CVE ID CVE-2026-42250 Publication date 28 May 2026 Vendor bzip2 Product bzip2 Vulnerable versions All before 1.0.9 Vulnerability type (CWE) Out-of-bounds Write (CWE-787 ... Read more Published Date: May 28, 2026 (3 days, 21 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom28 mag 2026
News
Vulnerability in D-Link DWR-X1820 router

Vulnerability in D-Link DWR-X1820 router Vulnerability in D-Link DWR-X1820 router CVE ID CVE-2026-4377 Publication date 28 May 2026 Vendor D-Link Corporation Product DWR-X1820 Vulnerable versions From 1.00B14CP to 1.00B16CP Vulnerability typ ... Read more Published Date: May 28, 2026 (3 days, 20 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom28 mag 2026
News
Gitea Container Vulnerability Exposes Private Container Images to Attackers

Gitea Container Vulnerability Exposes Private Container Images to Attackers A critical security vulnerability in Gitea’s built-in container registry exposes private container images to unauthenticated attackers, raising significant concerns for organizations that rely on self ... Read more Published Date: May 28, 2026 (3 days, 20 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom28 mag 2026
VulnerabilitàAlta
CVE-2026-9813 - FlowIntel external reference URL probe allows server-side request forgery

CVE ID :CVE-2026-9813 Published : May 28, 2026, 10:16 a.m. | 4 hours, 15 minutes ago Description :FlowIntel up to version 3.3.0 contains a server-side request forgery (SSRF) vulnerability in the external reference URL probe functionality in app/case/task.py. An attacker who can submit an external reference URL can cause the application server to issue an HTTP HEAD request to an attacker-specified destination. Due to insufficient validation of the URL scheme and resolved destination address, affected versions may allow requests to loopback, link-local, private, reserved, or other restricted network resources, potentially enabling interaction with internal services or cloud metadata endpoints from the server's network context. Severity: 6.2 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 mag 2026
VulnerabilitàAlta
CVE-2026-46240 - media: iris: Fix use-after-free in iris_release_internal_buffers()

CVE ID :CVE-2026-46240 Published : May 28, 2026, 10:16 a.m. | 4 hours, 15 minutes ago Description :In the Linux kernel, the following vulnerability has been resolved: media: iris: Fix use-after-free in iris_release_internal_buffers() The recent change in commit 1dabf00ee206 ("media: iris: gen1: Destroy internal buffers after FW releases") introduced a regression where session_release_buf() may free the buffer. The caller, iris_release_internal_buffers(), continued to access `buffer` after the call, leading to a potential use-after-free. Fix this by setting BUF_ATTR_PENDING_RELEASE before calling session_release_buf(), and reverting the flag if the call fails. This ensures no dereference occurs after potential freeing. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 mag 2026
VulnerabilitàAlta
CVE-2026-46236 - media: rc: xbox_remote: heed DMA restrictions

CVE ID :CVE-2026-46236 Published : May 28, 2026, 10:16 a.m. | 4 hours, 15 minutes ago Description :In the Linux kernel, the following vulnerability has been resolved: media: rc: xbox_remote: heed DMA restrictions The buffer for IO must not be part of the device structure because that violates the DMA coherency rules. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 mag 2026

Pagina 1336 di 2903

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.