Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

36763 risultati

VulnerabilitàCritica
CVE-2026-33844 (CVSS 9)

Improper input validation in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.

NVD (NIST)07 mag 2026
VulnerabilitàCritica
CVE-2026-33823 (CVSS 9.6)

Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network.

NVD (NIST)07 mag 2026
VulnerabilitàAlta
CVE-2026-33111 (CVSS 7.5)

Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network.

NVD (NIST)07 mag 2026
VulnerabilitàCritica
CVE-2026-33109 (CVSS 9.9)

Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.

NVD (NIST)07 mag 2026
VulnerabilitàAlta
CVE-2026-33823 - Microsoft Team Events Portal Information Disclosure Vulnerability

CVE ID :CVE-2026-33823 Published : May 7, 2026, 10:16 p.m. | 2 hours, 9 minutes ago Description :Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network. Severity: 9.6 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
VulnerabilitàAlta
CVE-2026-40213 - OpenStack Cyborg Default Policy Authorization Bypass

CVE ID :CVE-2026-40213 Published : May 7, 2026, 10:16 p.m. | 2 hours, 9 minutes ago Description :OpenStack Cyborg before 16.0.1 uses rule:allow (check_str='@') as the default policy for multiple API endpoints. This unconditionally authorizes any request carrying a valid Keystone token regardless of roles, project membership, or scope. An authenticated user with zero role assignments can complete various actions such as reprogramming FPGA bitstreams on arbitrary compute nodes via agent RPC. Severity: 7.4 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
VulnerabilitàAlta
CVE-2026-35428 - Azure Cloud Shell Spoofing Vulnerability

CVE ID :CVE-2026-35428 Published : May 7, 2026, 10:16 p.m. | 2 hours, 9 minutes ago Description :Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unauthorized attacker to perform spoofing over a network. Severity: 9.6 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
VulnerabilitàAlta
CVE-2026-34327 - Microsoft Partner Center Spoofing Vulnerability

CVE ID :CVE-2026-34327 Published : May 7, 2026, 10:16 p.m. | 2 hours, 9 minutes ago Description :Externally controlled reference to a resource in another sphere in Microsoft Partner Center allows an unauthorized attacker to perform spoofing over a network. Severity: 8.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
VulnerabilitàAlta
CVE-2026-33844 - Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability

CVE ID :CVE-2026-33844 Published : May 7, 2026, 10:16 p.m. | 2 hours, 9 minutes ago Description :Improper input validation in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network. Severity: 9.0 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
VulnerabilitàAlta
CVE-2026-35435 - Azure AI Foundry Elevation of Privilege Vulnerability

CVE ID :CVE-2026-35435 Published : May 7, 2026, 10:16 p.m. | 2 hours, 9 minutes ago Description :Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network. Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE07 mag 2026
VulnerabilitàAlta
CVE-2026-32207 (CVSS 8.8)

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network.

NVD (NIST)07 mag 2026
VulnerabilitàAlta
CVE-2026-26164 (CVSS 7.5)

Improper neutralization of special elements in output used by a downstream component ('injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

NVD (NIST)07 mag 2026

Pagina 1791 di 3064

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.