Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38581 risultati

VulnerabilitàAlta
CVE-2026-23657 (CVSS 7.8)

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

NVD (NIST)14 apr 2026
VulnerabilitàAlta
CVE-2026-20930 (CVSS 7.8)

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

NVD (NIST)14 apr 2026
News
Fortinet Patches 11 Vulnerabilities Across FortiSandbox, FortiOS, FortiAnalyzer, and FortiManager

Fortinet Patches 11 Vulnerabilities Across FortiSandbox, FortiOS, FortiAnalyzer, and FortiManager Fortinet released a sweeping batch of security advisories on April 14, 2026, addressing 11 vulnerabilities spanning multiple product lines, including two rated Critical, two rated High, and seven rate ... Read more Published Date: Apr 14, 2026 (20 hours, 46 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-39813 CVE-2026-39812 CVE-2026-39808 CVE-2026-27316 CVE-2026-25691 CVE-2026-22828 CVE-2025-68649 CVE-2025-61886 CVE-2025-61848 CVE-2025-61624 CVE-2025-53847

CVEfeed Newsroom14 apr 2026
News
The April 2026 Security Update Review

The April 2026 Security Update Review CVE-2026-32201 Microsoft SharePoint Server Spoofing Vulnerability Important 6.5 No Yes Spoofing CVE-2026-5281 * Chromium: CVE-2026-5281 Use after free in Dawn High N/A No Yes RCE CVE-2026-33825 Micros ... Read more Published Date: Apr 14, 2026 (20 hours, 56 minutes ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom14 apr 2026
News
Microsoft Patch Tuesday April 2026 – 168 Vulnerabilities Fixed, Including Actively Exploited 0-day

Microsoft Patch Tuesday April 2026 – 168 Vulnerabilities Fixed, Including Actively Exploited 0-day Microsoft has released its April 2026 Patch Tuesday security update, addressing 168 vulnerabilities across its product portfolio, including one actively exploited zero-day and one publicly disclosed f ... Read more Published Date: Apr 14, 2026 (21 hours, 25 minutes ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom14 apr 2026
VulnerabilitàAlta
CVE-2026-34622 (CVSS 8.6)

Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

NVD (NIST)14 apr 2026
VulnerabilitàAlta
CVE-2026-34626 - Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)

CVE ID :CVE-2026-34626 Published : April 14, 2026, 5:16 p.m. | 40 minutes ago Description :Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary file system read in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Severity: 6.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE14 apr 2026
VulnerabilitàAlta
CVE-2026-27291 (CVSS 7.8)

InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

NVD (NIST)14 apr 2026
VulnerabilitàAlta
CVE-2026-27284 (CVSS 7.8)

InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

NVD (NIST)14 apr 2026
VulnerabilitàAlta
CVE-2026-27285 - InDesign Desktop | Heap-based Buffer Overflow (CWE-122)

CVE ID :CVE-2026-27285 Published : April 14, 2026, 5:16 p.m. | 40 minutes ago Description :InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application or disrupt its functionality. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE14 apr 2026
VulnerabilitàAlta
CVE-2026-27286 - InDesign Desktop | Heap-based Buffer Overflow (CWE-122)

CVE ID :CVE-2026-27286 Published : April 14, 2026, 5:16 p.m. | 40 minutes ago Description :InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Severity: 5.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE14 apr 2026
VulnerabilitàAlta
CVE-2026-27283 (CVSS 7.8)

InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

NVD (NIST)14 apr 2026

Pagina 2273 di 3216

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.