News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
38140 risultati
CVE ID :CVE-2026-31650 Published : April 24, 2026, 3:16 p.m. | 55 minutes ago Description :In the Linux kernel, the following vulnerability has been resolved: mmc: vub300: fix use-after-free on disconnect The vub300 driver maintains an explicit reference count for the controller and its driver data and the last reference can in theory be dropped after the driver has been unbound. This specifically means that the controller allocation must not be device managed as that can lead to use-after-free. Note that the lifetime is currently also incorrectly tied the parent USB device rather than interface, which can lead to memory leaks if the driver is unbound without its device being physically disconnected (e.g. on probe deferral). Fix both issues by reverting to non-managed allocation of the controller. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Governments on high alert after CISA snuffs out Firestarter backdoor on fed network A US federal agency was successfully targeted by a previously unknown backdoor malware called Firestarter, according to CISA cybersnoops and their UK counterparts – neither of which disclosed the agen ... Read more Published Date: Apr 24, 2026 (3 days, 21 hours ago) Vulnerabilities has been mentioned in this article. CVE-2025-20362 CVE-2025-20333
VS en VK waarschuwen voor "FIRESTARTER" backdoor in Cisco ASA-firewalls vrijdag 24 april 2026, 16:15 door Redactie, 0 reactiesLaatst bijgewerkt: Vandaag, 16:58 De Amerikaanse en Britse overheid waarschuwen voor een backdoor genaamd FIRESTARTER die aanvallers in Cisco ASA- ... Read more Published Date: Apr 24, 2026 (3 days, 22 hours ago) Vulnerabilities has been mentioned in this article. CVE-2025-20362 CVE-2025-20333
Academic Exposure: The Unpatched Flaw Siphoning Student Data from DRC INSIGHT A security vulnerability has been unearthed in the DRC INSIGHT software—a platform widely used for proctoring academic exams. The flaw, tracked as CVE-2026-5756, resides in the Central Office Services ... Read more Published Date: Apr 24, 2026 (3 days, 20 hours ago) Vulnerabilities has been mentioned in this article.
A flaw was found in OVN (Open Virtual Network). A remote attacker, by sending crafted DHCPv6 (Dynamic Host Configuration Protocol for IPv6) SOLICIT packets with an inflated Client ID length, could cause the ovn-controller to read beyond the bounds of a packet. This out-of-bounds read can lead to the disclosure of sensitive information stored in heap memory, which is then returned to the attacker's virtual machine port.
CVE ID :CVE-2026-5367 Published : April 24, 2026, 1:16 p.m. | 55 minutes ago Description :A flaw was found in OVN (Open Virtual Network). A remote attacker, by sending crafted DHCPv6 (Dynamic Host Configuration Protocol for IPv6) SOLICIT packets with an inflated Client ID length, could cause the ovn-controller to read beyond the bounds of a packet. This out-of-bounds read can lead to the disclosure of sensitive information stored in heap memory, which is then returned to the attacker's virtual machine port. Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-5265 Published : April 24, 2026, 1:16 p.m. | 55 minutes ago Description :When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original packet into the ICMP error body using the IP header's self-declared total length (ip_tot_len for IPv4, ip6_plen for IPv6) without validating it against the actual packet buffer size. A VM can send a short packet with an inflated IP length field that triggers an ICMP error (e.g., by hitting a reject ACL), causing ovn-controller to read heap memory beyond the valid packet data and include it in the ICMP response sent back to the VM. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-38743 Published : April 24, 2026, 1:16 p.m. | 55 minutes ago Description :The authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and TaskInstance records: a logged-in Airflow user with read access to at least one DAG could retrieve HITL prompts (including their request parameters) and full TaskInstance details for DAGs outside their authorized scope. Because HITL prompts and TaskInstance fields routinely carry operator parameters and free-form context attached to a task, the leak widens visibility of DAG-run data beyond the intended per-DAG RBAC boundary for every authenticated user. Users are recommended to upgrade to version 3.2.1 , which fixes this issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-40690 Published : April 24, 2026, 1:16 p.m. | 55 minutes ago Description :The asset dependency graph did not restrict nodes by the viewer's DAG read permissions: a user with read access to at least one DAG could browse the asset graph for any other asset in the deployment and learn the existence and names of DAGs and assets outside their authorized scope. Users are recommended to upgrade to version 3.2.1, which fixes this issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate privileges over a network.
CVE ID :CVE-2026-21515 Published : April 24, 2026, 1:16 p.m. | 55 minutes ago Description :Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate privileges over a network. Severity: 9.9 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
The 9.1 CVSS Flaw: Why Millions of Spring Boot Apps May Be Exposed In a major update for the Java ecosystem, several critical vulnerabilities have been disclosed in Spring Boot, the framework that powers millions of modern enterprise applications. These flaws—CVE-202 ... Read more Published Date: Apr 24, 2026 (3 days, 21 hours ago) Vulnerabilities has been mentioned in this article.
Pagina 2094 di 3179