Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

45464 risultati

News
Vulnerability in WEBCON BPS software

Vulnerability in WEBCON BPS software Vulnerability in WEBCON BPS software CVE ID CVE-2026-92419 Publication date 23 September 2026 Vendor WEBCON Product WEBCON BPS Vulnerable versions From 2024.1.1.145 before 2025.2.1.177From 2026.1.1.1 ... Read more Published Date: Sep 23, 2026 (4 days, 23 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom23 set 2026
VulnerabilitàAlta
CVE-2026-19599 - Remote Code Execution vulnerability

CVE ID :CVE-2026-19599 Published : Sept. 23, 2026, 12:41 p.m. | 4 minutes ago Description :ZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below were vulnerable to a Remote Code Execution vulnerability in the Notification Profile module. Severity: 9.9 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-75825 - Authentication Bypass vulnerability

CVE ID :CVE-2026-75825 Published : Sept. 23, 2026, 12:35 p.m. | 10 minutes ago Description :ZohoCorp ManageEngine OpManager versions 12.8.710 and below with the Application Manager Plugin enabled were vulnerable to an Authentication Bypass vulnerability. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-86247 - Apache Tomcat Native: Client certificate requirements can be down-graded

CVE ID :CVE-2026-86247 Published : Sept. 23, 2026, 12:31 p.m. | 13 minutes ago Description :Race condition within a thread vulnerability in Apache Tomcat Native allowed client certificate verification requirements to be down-graded for some configurations. This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Unsupported versions may also be affected. Users are recommended to upgrade to version 2.0.16 or 1.3.9, which fixes the issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-76978 - Command Injection vulnerability

CVE ID :CVE-2026-76978 Published : Sept. 23, 2026, 12:28 p.m. | 16 minutes ago Description :ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to a Command Injection vulnerability in the Diagnose Settings feature. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-86246 - Apache Tomcat Native: Insecure OpenSSL options enabled

CVE ID :CVE-2026-86246 Published : Sept. 23, 2026, 12:26 p.m. | 18 minutes ago Description :Initialization of a resource with an insecure default vulnerability in Apache Tomcat Native enabled insecure options by default including ALLOW_CLIENT_RENEGOTIATION, NO_EXTENDED_MASTER_SECRET, IGNORE_UNEXPECTED_EOF and ALLOW_NO_DHE_KEX. This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Earlier unsupported versions may also be affected. Users are recommended to upgrade to version 2.0.16 or 1.3.9, which fix the issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-86243 - Apache Tomcat Native: DoS via TLS handshake

CVE ID :CVE-2026-86243 Published : Sept. 23, 2026, 12:24 p.m. | 20 minutes ago Description :Buffer over-read vulnerability in Apache Tomcat Native during the TLS handshake permits a malicious user to trigger a DoS via a JVM crash. This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Earlier, unsupported versions may also be affected. Users are recommended to upgrade to version 1.3.9 or 2.0.16, which fix the issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-76979 - XML Injection vulnerability

CVE ID :CVE-2026-76979 Published : Sept. 23, 2026, 12:22 p.m. | 22 minutes ago Description :ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to an XML Injection vulnerability in the Rule Tracking Compare Policies feature. Severity: 7.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-96446 - Keycloak-services: keycloak-services: par single-use bypass via prompt=none silent authentication path

CVE ID :CVE-2026-96446 Published : Sept. 23, 2026, 12:17 p.m. | 28 minutes ago Description :A flaw was found in the Pushed Authorization Request PAR implementation of Keycloak. The issue occurs when the silent authentication path prompt=none is used, which allows the authorization process to skip certain steps if a user is already logged in. Due to this bypass, the security rule that ensures a pushed request URI is used only once is not enforced. An attacker could potentially reuse a request URI to obtain multiple authorization codes for a user who is already signed in, violating security standards like FAPI-2. Severity: 4.2 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-96445 - Keycloak-services: keycloak-services: conditional otp skip-header policy evaluated against untrusted proxy headers

CVE ID :CVE-2026-96445 Published : Sept. 23, 2026, 12:17 p.m. | 28 minutes ago Description :A flaw was found in the Conditional OTP authenticator of Keycloak, an identity and access management solution. The issue occurs when the system evaluates specific HTTP headers to determine if a one-time password (OTP) should be skipped, but fails to verify if those headers came from a trusted source. This could allow an attacker who already has a user's password to bypass the second-factor authentication by providing a specially crafted header in their request. Severity: 6.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-84791 - Broken Access Control vulnerability

CVE ID :CVE-2026-84791 Published : Sept. 23, 2026, 12:17 p.m. | 28 minutes ago Description :ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to modify Change Management report schedule configurations for firewalls outside their assigned scope. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026
VulnerabilitàAlta
CVE-2026-86248 - Apache Tomcat: Fix for CVE-2026-34500 was incomplete. OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled

CVE ID :CVE-2026-86248 Published : Sept. 23, 2026, 12:17 p.m. | 28 minutes ago Description :CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.25, from 10.1.22 through 10.1.59, from 9.0.92 through 9.0.121. Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE23 set 2026

Pagina 214 di 3789

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.