Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

35239 risultati

News
Attackers Can Exploit BadHost to Access Sensitive AI Agent Server Endpoints

Attackers Can Exploit BadHost to Access Sensitive AI Agent Server Endpoints A newly disclosed critical vulnerability, tracked as CVE-2026-48710 and dubbed “BadHost,” is putting thousands of AI-powered applications at risk by enabling authentication bypass through manipulated ... Read more Published Date: May 27, 2026 (2 days, 2 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-48710

CVEfeed Newsroom27 mag 2026
VulnerabilitàAlta
CVE-2026-44483 - RVF: Prototype pollution in @rvf/set-get reachable via @rvf/core preprocessFormData (HTTP form data)

CVE ID :CVE-2026-44483 Published : May 27, 2026, 3:20 p.m. | 1 hour, 11 minutes ago Description :RVF (formerly Remix Validated Form) provides easy form validation and state management for React. From 6.0.0 to before 6.0.4 and 7.0.2, setPath in @rvf/set-get (used by @rvf/core to flatten incoming form data into a nested object) does not block the keys __proto__, constructor, or prototype when walking a path. Because field names in submitted form data are passed directly to setPath via preprocessFormData (and through parseFormData / validate), an attacker who can submit a form to a Remix / React Router app using the library can set arbitrary properties on Object.prototype of the running server process. This is a default-reachable prototype pollution primitive: no special configuration is required. Any endpoint that accepts a form via parseFormData or runs a validator created with createValidator is affected. This vulnerability is fixed in 6.0.4 and 7.0.2. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 mag 2026
VulnerabilitàAlta
CVE-2026-48544 (CVSS 7.5)

Taipy 4.1.1, fixed in commit 129fd40, contains a path traversal vulnerability in the ElementLibrary.get_resource() method in taipy/gui/extension/library.py that allows unauthenticated attackers to escape the intended module directory by exploiting an incomplete path containment check using str.startswith() without a trailing path separator. Attackers can send crafted GET requests with path traversal segments targeting a prefix-matching sibling directory on disk, bypassing the directory containment check because Flask's path converter and Werkzeug's WSGI layer preserve the traversal segments while the resolved path still satisfies the flawed startswith comparison, enabling unauthorized file access outside the intended library directory.

NVD (NIST)27 mag 2026
News
More CVEs, Same Playbook: 2026 Vulnerability Exploitation in the Wild

More CVEs, Same Playbook: 2026 Vulnerability Exploitation in the Wild Executive Summary The CVE Landscape Has Changed. The Threat Actors Haven't. Proofpoint's dual telemetry streams — targeted attack visibility covering hundreds of millions of messages daily, and a glob ... Read more Published Date: May 27, 2026 (2 days, 1 hour ago) Vulnerabilities has been mentioned in this article. CVE-2026-42897 CVE-2026-20182 CVE-2026-6973 CVE-2026-0300 CVE-2026-41940 CVE-2026-31431 CVE-2026-32202 CVE-2026-39987 CVE-2026-20133 CVE-2026-20128 CVE-2026-20122 CVE-2026-21513 CVE-2026-21510 CVE-2026-1340 CVE-2026-1281 CVE-2026-21509

CVEfeed Newsroom27 mag 2026
News
CISA Warns of LiteSpeed cPanel Plugin Vulnerability Exploited in Attacks

CISA Warns of LiteSpeed cPanel Plugin Vulnerability Exploited in Attacks CISA has issued an urgent warning regarding a critical vulnerability in the LiteSpeed cPanel Plugin, identified as CVE-2026-48172, which is currently being exploited in real-world attacks. The flaw en ... Read more Published Date: May 27, 2026 (2 days, 1 hour ago) Vulnerabilities has been mentioned in this article. CVE-2026-48172 CVE-2026-40369

CVEfeed Newsroom27 mag 2026
News
GitHub Enterprise Server 3.20.3 Released With Fox for Critical Vulnerabilities

GitHub Enterprise Server 3.20.3 Released With Fox for Critical Vulnerabilities GitHub has shipped GitHub Enterprise Server (GHES) 3.20.3 as a security‑driven patch release that fixes multiple critical and high‑severity vulnerabilities and rotates the signing key used to validate ... Read more Published Date: May 27, 2026 (2 days, 1 hour ago) Vulnerabilities has been mentioned in this article. CVE-2026-9312 CVE-2026-40369 CVE-2026-43500 CVE-2026-43284

CVEfeed Newsroom27 mag 2026
News
Windows Kernel Vulnerability Allows Attackers to Modify Kernel Memory Counters

Windows Kernel Vulnerability Allows Attackers to Modify Kernel Memory Counters A critical Windows kernel vulnerability, tracked as CVE-2026-40369, has been disclosed, enabling attackers to achieve full SYSTEM-level privilege escalation even from the most restricted environments, ... Read more Published Date: May 27, 2026 (1 day, 19 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-40369

CVEfeed Newsroom27 mag 2026
VulnerabilitàAlta
CVE-2026-9617 - PostgreSQL Anonymizer: malicious column name allows SQL injection via anon.k_anonymity() function

CVE ID :CVE-2026-9617 Published : May 27, 2026, 2:17 p.m. | 14 minutes ago Description :PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a table and placing malicious code inside a column identifier. If a superuser calls the k-anonymity function, the malicious code is executed with superuser privileges. The risk is higher with PostgreSQL 14 or with instances upgraded from PostgreSQL 14 or a prior version. With PostgreSQL 15 and later, the creation permission on the public schema is revoked by default and this exploit can only be achieved by a user who was explicitly granted the CREATE TABLE privilege. The problem is resolved in PostgreSQL Anonymizer 3.1.0 and further versions Severity: 6.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 mag 2026
VulnerabilitàAlta
CVE-2026-9704 - Keycloak: keycloak: privilege escalation due to oversized subject_token jwt

CVE ID :CVE-2026-9704 Published : May 27, 2026, 2:17 p.m. | 14 minutes ago Description :A flaw was found in Keycloak. An authenticated user with low privileges can exploit this vulnerability by sending an oversized subject_token JSON Web Token (JWT) to the TokenEndpoint. When the token exceeds a 4000-character limit, it is silently dropped, causing the system to fall back to client credentials. This allows the user to gain the permissions of the client's service account, leading to privilege escalation. Severity: 6.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 mag 2026
VulnerabilitàAlta
CVE-2026-8180 (CVSS 7.5)

IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a potential denial of service in the asperahttpd component. An unauthenticated user can cause the asperahttpd service to crash.

NVD (NIST)27 mag 2026
VulnerabilitàAlta
CVE-2026-9035 - Multiple vulnerabilities in Aspera applications.

CVE ID :CVE-2026-9035 Published : May 27, 2026, 2:17 p.m. | 14 minutes ago Description :IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a potential arbitrary file read in the asperahttpd component. An authenticated user may be able to take advantage of this vulnerability to access files in the server’s local storage that they should not have access to. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 mag 2026
VulnerabilitàAlta
CVE-2026-8405 - IBM Guardium Data Protection is affected by Exposure of Sensitive Information vulnerability

CVE ID :CVE-2026-8405 Published : May 27, 2026, 2:17 p.m. | 14 minutes ago Description :IBM Guardium Data Protection 12.2.1, and 12.2.2 's add-on feature of Guardium Data Protection named "Long Term Retention" (LTR) can expose sensitive credentials in debug mode. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE27 mag 2026

Pagina 1386 di 2937

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.