Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

45446 risultati

VulnerabilitàCritica
CVE-2026-84474 (CVSS 9.9)

A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The provisioning-callback secret (host_config_key) is exposed to users holding only the read-level view_jobtemplate permission -- both in the job template API representation and in the activity stream -- and the provisioning callback endpoint trusts a client-supplied X-Forwarded-For header to determine the calling host when the controller is deployed behind the AAP gateway with an empty proxy allow-list. By reading the secret and spoofing X-Forwarded-For to match any host in the job template's inventory, a minimally privileged or unauthenticated remote attacker can launch the job template against arbitrary managed hosts using the job template's credentials, resulting in privilege escalation and remote code execution on managed hosts.

NVD (NIST)23 set 2026
VulnerabilitàAlta
CVE-2026-76648 (CVSS 8.5)

CopyAPIView (awx/awx/api/generics.py:873) sets permission_classes = (IsAuthenticated,), so DRF's get_object() performs no object-level RBAC. The get() handler (lines 988–991) explicitly guards with request.user.can_access(obj._class_, 'read', obj) — but post() (lines 1001–1010) does not. POST only checks: can_access(model, 'add', create_kwargs_check) can_access(model, 'copy_related', obj) For JobTemplate, can_add (awx/awx/main/access.py:1465–1520) gates on inventory.use_role + project.use_role + execution_environment.read_role — resource-level roles that do not imply read on the source JT — and can_copy_related (1522–1534) checks only credentials.use_role. None of these imply the caller can read the source JT.

NVD (NIST)23 set 2026
VulnerabilitàAlta
CVE-2026-75131 (CVSS 7.8)

NetworkManager-l2tp through 1.52.4, fixed in 1.52.6, contains a privilege escalation vulnerability that allows local users with permission to create VPN connections to execute arbitrary code as root by injecting pppd options through a crafted VPN username. Attackers can embed a double-quote character or whitespace in the username to break out of the pppd options file quoting context and include the pppd plugin directive, causing the privileged pppd process to load an attacker-controlled shared object.

NVD (NIST)23 set 2026
VulnerabilitàAlta
CVE-2026-91775 - LimeSurvey Community Edition 7.0.14 - Reflected XSS through unescaped LSS survey-import warnings

CVE ID :CVE-2026-91775 Published : Sept. 23, 2026, 6:17 p.m. | 27 minutes ago Description :LimeSurvey fails to safely encode attacker-controlled content from a crafted .lss survey file when displaying import warnings, resulting in XSS in the administrative interface. Severity: 7.4 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-88835 - Busybox: busybox: dpkg read_package_field() steps past nul terminator, causing out-of-bounds read on malformed .deb packages

CVE ID :CVE-2026-88835 Published : Sept. 23, 2026, 6:17 p.m. | 27 minutes ago Description :BusyBox dpkg read_package_field() steps past a NUL terminator on malformed .deb packages, causing an out-of-bounds heap read. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-88839 - Busybox: busybox: passwd/group parser writes heap pointers out of bounds due to stale tokenize() endpoint

CVE ID :CVE-2026-88839 Published : Sept. 23, 2026, 6:17 p.m. | 27 minutes ago Description :BusyBox passwd/group tokenize() references a stale endpoint pointer after trimming, causing an out-of-bounds write of heap pointers. Severity: 6.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-88840 - Busybox: busybox: tls ssl_server reads one byte out of bounds when parsing truncated clienthello

CVE ID :CVE-2026-88840 Published : Sept. 23, 2026, 6:17 p.m. | 27 minutes ago Description :BusyBox TLS get_client_hello() reads past the end of the input buffer when parsing a truncated ClientHello message. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-88831 - Busybox: busybox: httpd silently fails open when ip deny rules contain invalid cidr prefix lengths

CVE ID :CVE-2026-88831 Published : Sept. 23, 2026, 6:17 p.m. | 27 minutes ago Description :BusyBox httpd IP deny rules with invalid CIDR prefix lengths fail open, leaving a parsed IP with a zeroed mask so the rule matches no clients. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-88837 - Busybox: busybox: httpd misidentifies yescrypt password hashes as plaintext, inverting authentication

CVE ID :CVE-2026-88837 Published : Sept. 23, 2026, 6:17 p.m. | 27 minutes ago Description :BusyBox httpd treats yescrypt ($y$) password hashes as plaintext during Basic Authentication, inverting the authentication check. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-86930 - FileMaker Server Out-of-Bounds Read Vulnerability

CVE ID :CVE-2026-86930 Published : Sept. 23, 2026, 6:17 p.m. | 27 minutes ago Description :An out-of-bounds read vulnerability in FileMaker Server for Linux allowed an attacker uploading a specially crafted image file to a container field to disclose process memory during thumbnail generation in FileMaker WebDirect. This vulnerability is addressed in FileMaker Server version 26.0.3. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-86938 - FileMaker Pro DLL Hijacking Vulnerability

CVE ID :CVE-2026-86938 Published : Sept. 23, 2026, 6:17 p.m. | 27 minutes ago Description :A DLL hijacking vulnerability in the FileMaker Pro installer for Windows allowed a local user to execute arbitrary code with elevated administrator privileges by placing a malicious DLL file in the installer directory. This vulnerability is addressed in FileMaker Pro version 26.0.3. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-86934 - Claris FileMaker Server Authorization Bypass Vulnerability

CVE ID :CVE-2026-86934 Published : Sept. 23, 2026, 6:17 p.m. | 27 minutes ago Description :An authorization bypass vulnerability in the FileMaker Server Web Publishing Engine allowed requests containing an extended privilege header to bypass the disabled Custom Web Publishing with XML setting and access the XML Web Publishing interface. This vulnerability is addressed in FileMaker Server version 26.0.3. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026

Pagina 205 di 3788

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.