Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38326 risultati

News
MOVEit WAF Critical Alert: Multi-Level RCE and WAF Bypass Vulnerabilities Disclosed

MOVEit WAF Critical Alert: Multi-Level RCE and WAF Bypass Vulnerabilities Disclosed Progress Software has released a critical security bulletin for April 2026, revealing five high-impact vulnerabilities affecting MOVEit WAF and related Application Delivery Controller (ADC) products. ... Read more Published Date: Apr 21, 2026 (1 day, 15 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-4048 CVE-2026-3519 CVE-2026-3518 CVE-2026-3517 CVE-2026-39813 CVE-2026-39808 CVE-2026-35337 CVE-2026-22679 CVE-2026-20133 CVE-2026-20128 CVE-2026-20122 CVE-2026-21962 CVE-2026-21876 CVE-2025-32975 CVE-2025-48700 CVE-2025-2749 CVE-2024-4358 CVE-2024-27199 CVE-2023-27351

CVEfeed Newsroom21 apr 2026
News
6000+ Apache ActiveMQ Instances Vulnerable to CVE-2026-34197 Exposed Online

6000+ Apache ActiveMQ Instances Vulnerable to CVE-2026-34197 Exposed Online More than 6,000 internet-exposed Apache ActiveMQ instances are still vulnerable to CVE-2026-34197. This newly tracked security flaw has now been added to the U.S. Cybersecurity and Infrastructure Secu ... Read more Published Date: Apr 21, 2026 (1 day, 15 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-34197

CVEfeed Newsroom21 apr 2026
News
Hackers Use Nightmare-Eclipse Tools After Compromising FortiGate SSL VPN Access

Hackers Use Nightmare-Eclipse Tools After Compromising FortiGate SSL VPN Access A real-world intrusion campaign leveraging publicly available Nightmare-Eclipse privilege escalation tooling, BlueHammer, RedSun, and UnDefend, following what appears to be unauthorized access through ... Read more Published Date: Apr 21, 2026 (1 day, 8 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-33825 CVE-2026-34197

CVEfeed Newsroom21 apr 2026
News
OVN Security Alert: Critical Heap Over-Read Flaws Risk Sensitive Data Leaks

OVN Security Alert: Critical Heap Over-Read Flaws Risk Sensitive Data Leaks The Open Virtual Network (OVN) team has issued a dual-threat security advisory concerning two critical heap over-read vulnerabilities. These flaws, identified as CVE-2026-5265 and CVE-2026-5367, could ... Read more Published Date: Apr 21, 2026 (1 day, 6 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom21 apr 2026
News
CISA flags another Cisco Catalyst SD-WAN Manager bug as exploited (CVE-2026-20133)

CISA flags another Cisco Catalyst SD-WAN Manager bug as exploited (CVE-2026-20133) CISA added eight new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including a Cisco Catalyst SD-WAN Manager vulnerability (CVE-2026-20133) that Cisco has yet to flag as exploi ... Read more Published Date: Apr 21, 2026 (1 day, 6 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-20133 CVE-2026-20128 CVE-2026-20122 CVE-2025-32975 CVE-2025-48700 CVE-2025-2749 CVE-2024-27199 CVE-2024-27198 CVE-2023-27351

CVEfeed Newsroom21 apr 2026
VulnerabilitàAlta
CVE-2026-41039 - Information Disclosure Vulnerability in Quantum Networks Router QN-I-470

CVE ID :CVE-2026-41039 Published : April 21, 2026, 11:16 a.m. | 49 minutes ago Description :This vulnerability exists in Quantum Networks router due to improper access control and insecure default configuration in the web-based management interface. An unauthenticated attacker could exploit this vulnerability by accessing exposed API endpoints on the targeted device. Successful exploitation of this vulnerability could allow the attacker to access sensitive information, including internal endpoints, scripts and directories on the targeted device. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 apr 2026
VulnerabilitàAlta
CVE-2026-41038 - Weak Password Policy Vulnerability in Quantum Networks Router QN-I-470

CVE ID :CVE-2026-41038 Published : April 21, 2026, 11:16 a.m. | 49 minutes ago Description :This vulnerability exists in Quantum Networks router due to lack of enforcement of strong password policies in the web-based management interface. An attacker on the same network could exploit this vulnerability by performing password guessing or brute-force attacks against user accounts, leading to unauthorized access to the targeted device. Severity: 7.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 apr 2026
News
Google Patches Antigravity IDE Flaw Enabling Prompt Injection Code Execution

Google Patches Antigravity IDE Flaw Enabling Prompt Injection Code Execution Cybersecurity researchers have discovered a vulnerability in Google's agentic integrated development environment (IDE), Antigravity, that could be exploited to achieve code execution. The flaw, since ... Read more Published Date: Apr 21, 2026 (1 day, 1 hour ago) Vulnerabilities has been mentioned in this article. CVE-2026-34197 CVE-2026-33032 CVE-2026-21520

CVEfeed Newsroom21 apr 2026
News
Hackers Could Weaponize GGUF Models to Achieve RCE on SGLang Inference Servers

Hackers Could Weaponize GGUF Models to Achieve RCE on SGLang Inference Servers A critical vulnerability in the SGLang inference server that allows threat actors to execute arbitrary code. Tracked as CVE-2026-5760, this flaw allows hackers to weaponize standard GGUF machine learn ... Read more Published Date: Apr 21, 2026 (1 day, 1 hour ago) Vulnerabilities has been mentioned in this article. CVE-2026-5760

CVEfeed Newsroom21 apr 2026
VulnerabilitàAlta
CVE-2026-6553 - TYPO3 CMS Stores Cleartext Password in User Settings Module

CVE ID :CVE-2026-6553 Published : April 21, 2026, 10:16 a.m. | 1 hour, 49 minutes ago Description :Changing backend users' passwords via the user settings module results in storing the cleartext password in the uc and user_settings fields of the be_users database table. This issue affects TYPO3 CMS version 14.2.0. Severity: 7.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 apr 2026
VulnerabilitàAlta
CVE-2026-41036 - Command Injection Vulnerability in Quantum Networks Router QN-I-470

CVE ID :CVE-2026-41036 Published : April 21, 2026, 10:16 a.m. | 1 hour, 49 minutes ago Description :This vulnerability exists in Quantum Networks router due to inadequate sanitization of user-supplied input in the management CLI interface. An authenticated remote attacker could exploit this vulnerability by injecting arbitrary OS commands on the targeted device. Successful exploitation of this vulnerability could allow the attacker to perform remote code execution with root privileges on the targeted device. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 apr 2026
VulnerabilitàAlta
CVE-2026-41037 - Missing Rate Limiting Vulnerability in Quantum Networks Router QN-I-470

CVE ID :CVE-2026-41037 Published : April 21, 2026, 10:16 a.m. | 1 hour, 49 minutes ago Description :This vulnerability exists in Quantum Networks router due to missing rate limiting and CAPTCHA protection for failed login attempts in the web-based management interface. An attacker on the same network could exploit this vulnerability by performing brute force attacks against administrative credentials, leading to unauthorized access with root privileges on the targeted device. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 apr 2026

Pagina 2165 di 3194

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.