Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36462 risultati

News
9.8 Severity Alert: Malicious Git Branches Can Hijack Your WebdriverIO Build Servers

9.8 Severity Alert: Malicious Git Branches Can Hijack Your WebdriverIO Build Servers A critical security vulnerability has been found in WebdriverIO, a popular open-source test automation framework used for end-to-end and component testing. The flaw, tracked as CVE-2026-25244, carries ... Read more Published Date: May 13, 2026 (1 day, 5 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom13 mag 2026
News
Microsoft Patch Tuesday May 2026 Fixes 137 Flaws, Including Netlogon RCE and Critical SSO Bypass

Microsoft Patch Tuesday May 2026 Fixes 137 Flaws, Including Netlogon RCE and Critical SSO Bypass Microsoft has dropped a heavy-hitting security update for May 2026, addressing a total of 137 vulnerabilities. This month’s release is particularly dense, featuring 30 Critical and 103 Important-sever ... Read more Published Date: May 13, 2026 (1 day, 5 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom13 mag 2026
News
CVSS 10 Alert: SandboxJS Critical Escape Vulnerability Enables Host Takeover

CVSS 10 Alert: SandboxJS Critical Escape Vulnerability Enables Host Takeover The fundamental promise of any digital sandbox is strict isolation: providing a secure container where untrusted code can run without threatening the underlying host system. However, a critical new vu ... Read more Published Date: May 13, 2026 (1 day, 5 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom13 mag 2026
News
PraisonAI CVE-2026-44338 Exploited in the Wild Hours After Patch Disclosure

PraisonAI CVE-2026-44338 Exploited in the Wild Hours After Patch Disclosure A new report from the Sysdig Threat Research Team (TRT) reveals that on May 11, 2026, a critical vulnerability in PraisonAI, an open-source multi-agent orchestration framework, was exploited in the wi ... Read more Published Date: May 13, 2026 (1 day, 3 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom13 mag 2026
News
9.8 Critical Alert: One-Byte Heap Corruption in Exim Exposes Global Mail Servers to Takeover

9.8 Critical Alert: One-Byte Heap Corruption in Exim Exposes Global Mail Servers to Takeover A “highest-caliber” vulnerability was found in Exim, one of the internet’s most widely used Mail Transfer Agents (MTAs). Tracked as CVE-2026-45185 with a CVSS score of 9.8, this flaw exposes thousands ... Read more Published Date: May 13, 2026 (1 day, 4 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom13 mag 2026
News
Fortinet Critical Alert: 9.1 Severity Flaws in FortiSandbox and FortiAuthenticator Risk Remote Takeover

Fortinet Critical Alert: 9.1 Severity Flaws in FortiSandbox and FortiAuthenticator Risk Remote Takeover Fortinet has issued a high-priority warning regarding two separate critical vulnerabilities affecting core security components: FortiSandbox and FortiAuthenticator. Both flaws carry a CVSS score of 9. ... Read more Published Date: May 13, 2026 (1 day, 4 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom13 mag 2026
News
Multiple Memory Flaws in Dnsmasq Threaten Millions of Connected Devices

Multiple Memory Flaws in Dnsmasq Threaten Millions of Connected Devices In the foundational architecture of small-to-medium networks and home routing devices, dnsmasq is the open-source networking tool that quietly handles DNS forwarding, DHCP, and network boot services f ... Read more Published Date: May 13, 2026 (1 day ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom13 mag 2026
News
Microsoft Patch Tuesday — May 2026

Microsoft Patch Tuesday — May 2026 By the Numbers137 vulnerabilities patched. 17 rated Critical — 14 RCE, 2 EoP, 1 information disclosure. No zero-days exploited in the wild, no public disclosures ahead of release. Notably, EoP vulnera ... Read more Published Date: May 13, 2026 (1 day ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom13 mag 2026
News
Critical Casdoor Vulnerability CVE-2026-44213 Allows Arbitrary File Overwrites

Critical Casdoor Vulnerability CVE-2026-44213 Allows Arbitrary File Overwrites In the complex world of Identity and Access Management (IAM), the security of the gateway is paramount. Security researcher disclosures a critical arbitrary file write vulnerability in Casdoor, a popu ... Read more Published Date: May 13, 2026 (1 day ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom13 mag 2026
VulnerabilitàAlta
CVE-2026-8202 - Post-authentication CPU utilization DoS via $trim/$ltrim/$rtrim operators

CVE ID :CVE-2026-8202 Published : May 13, 2026, 12:19 a.m. | 4 hours, 11 minutes ago Description :Using a densely populated chars mask and a large input string in the MongoDB aggregation operators $trim, $ltrim, and $rtrim, an authenticated user with aggregation permissions can pin CPU utilization at 100% for an extended period of time. This issue impacts MongoDB Server v7.0 versions prior to 7.0.34, v8.0 versions prior to 8.0.23, v8.2 versions prior to 8.2.9 and v8.3 versions prior to 8.3.2. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 mag 2026
VulnerabilitàAlta
CVE-2026-8336 - Post-authentication use-after-free error in $_internalJsEmit and mapreduce commands

CVE ID :CVE-2026-8336 Published : May 13, 2026, 12:16 a.m. | 4 hours, 14 minutes ago Description :After invoking $_internalJsEmit, which is not intended to be directly accessible, or mapreduce command’s map function in a certain way, an authenticated user can subsequently crash mongod when the server-side JavaScript engine (through $where, $function, mapreduce reduce stage, etc.) is used also in a specific way, resulting in a post-authentication denial-of-service. This issue impacts MongoDB Server v7.0 versions prior to 7.0.34, v8.0 versions prior to 8.0.23, v8.2 versions prior to 8.2.9 and v8.3 versions prior to 8.3.2. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 mag 2026
VulnerabilitàAlta
CVE-2026-8201 - Use-After-Free in MongoDB FLE Query Analysis When Processing Positional Projections on Encrypted Fields

CVE ID :CVE-2026-8201 Published : May 13, 2026, 12:12 a.m. | 4 hours, 18 minutes ago Description :A use-after-free vulnerability exists in MongoDB's Field-Level Encryption (FLE) query analysis component, affecting client-side uses of mongocryptd and crypt_shared. Triggering this vulnerability requires control over the structure of a client's FLE-related query. This issue impacts MongoDB Server’s mongocryptd component v7.0 versions prior to 7.0.34, v8.0 versions prior to 8.0.23, v8.2 versions prior to 8.2.9 and v8.3 versions prior to 8.3.2. Severity: 6.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 mag 2026

Pagina 1686 di 3039

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.