Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38596 risultati

VulnerabilitàAlta
CVE-2026-2728 - LibreNMS Authenticated Cross-site Scripting

CVE ID :CVE-2026-2728 Published : April 13, 2026, 11:16 a.m. | 2 hours, 41 minutes ago Description :LibreNMS versions before 26.3.0 are affected by an authenticated Cross-site Scripting vulnerability on the showconfig page. Successful exploitation requires administrative privileges. Exploitation could result in XSS attacks being performed against other users with access to the page. Severity: 4.6 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 apr 2026
VulnerabilitàAlta
CVE-2026-35337 - Apache Storm Client: RCE through Unsafe Deserialization via Kerberos TGT Credential Handling

CVE ID :CVE-2026-35337 Published : April 13, 2026, 10:16 a.m. | 1 hour, 41 minutes ago Description :Deserialization of Untrusted Data vulnerability in Apache Storm. Versions Affected: before 2.8.6. Description: When processing topology credentials submitted via the Nimbus Thrift API, Storm deserializes the base64-encoded TGT blob using ObjectInputStream.readObject() without any class filtering or validation. An authenticated user with topology submission rights could supply a crafted serialized object in the "TGT" credential field, leading to remote code execution in both the Nimbus and Worker JVMs. Mitigation: 2.x users should upgrade to 2.8.6. Users who cannot upgrade immediately should monkey-patch an ObjectInputFilter allow-list to ClientAuthUtils.deserializeKerberosTicket() restricting deserialized classes to javax.security.auth.kerberos.KerberosTicket and its known dependencies. A guide on how to do this is available in the release notes of 2.8.6. Credit: This issue was discovered by K. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 apr 2026
VulnerabilitàAlta
CVE-2026-35565 - Apache Storm UI: Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata in Storm UI

CVE ID :CVE-2026-35565 Published : April 13, 2026, 10:16 a.m. | 1 hour, 41 minutes ago Description :Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata in Apache Storm UI Versions Affected: before 2.8.6 Description: The Storm UI visualization component interpolates topology metadata including component IDs, stream names, and grouping values directly into HTML via innerHTML in parseNode() and parseEdge() without sanitization at any layer. An authenticated user with topology submission rights could craft a topology containing malicious HTML/JavaScript in component identifiers (e.g., a bolt ID containing an onerror event handler). This payload flows through Nimbus → Thrift → the Visualization API → vis.js tooltip rendering, resulting in stored cross-site scripting. In multi-tenant deployments where topology submission is available to less-trusted users but the UI is accessed by operators or administrators, this enables privilege escalation through script execution in an admin's browser session. Mitigation: 2.x users should upgrade to 2.8.6. Users who cannot upgrade immediately should monkey-patch the parseNode() and parseEdge() functions in the visualization JavaScript file to HTML-escape all API-supplied values including nodeId, :capacity, :latency, :component, :stream, and :grouping before interpolation into tooltip HTML strings, and should additionally restrict topology submission to trusted users via Nimbus ACLs as a defense-in-depth measure. A guide on how to do this is available in the release notes of 2.8.6. Credit: This issue was discovered while investigating another report by K. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 apr 2026
VulnerabilitàAlta
CVE-2025-15632 - 1Panel-dev MaxKB MdPreview chat.ts cross site scripting

CVE ID :CVE-2025-15632 Published : April 13, 2026, 10:16 a.m. | 1 hour, 41 minutes ago Description :A vulnerability has been found in 1Panel-dev MaxKB up to 2.4.2. Impacted is an unknown function of the file ui/src/chat.ts of the component MdPreview. Such manipulation leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.5.0 is recommended to address this issue. The name of the patch is 7230daa5ec3e6574b6ede83dd48a4fbc0e70b8d8. It is advisable to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 apr 2026
News
Adobe issues emergency fix for Acrobat Reader flaw exploited in the wild (CVE-2026-34621)

Adobe issues emergency fix for Acrobat Reader flaw exploited in the wild (CVE-2026-34621) Adobe has pushed out an emergency security update for Adobe Acrobat Reader, patching a zero-day vulnerability (CVE-2026-34621) exploited in the wild since November 2025. About CVE-2026-34621 CVE-2026- ... Read more Published Date: Apr 13, 2026 (22 hours, 51 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-34621

CVEfeed Newsroom13 apr 2026
VulnerabilitàAlta
CVE-2026-4810 - Remote Code Execution in Google Agent Development Kit (ADK)

CVE ID :CVE-2026-4810 Published : April 13, 2026, 9:16 a.m. | 2 hours, 41 minutes ago Description :A Code Injection and Missing Authentication vulnerability in Google Agent Development Kit (ADK) versions 1.7.0 (and 2.0.0a1) through 1.28.1 (and 2.0.0a2) on Python (OSS), Cloud Run, and GKE allows an unauthenticated remote attacker to execute arbitrary code on the server hosting the ADK instance. This vulnerability was patched in versions 1.28.1 and 2.0.0a2. Customers need to redeploy the upgraded ADK to their production environments. In addition, if they are running ADK Web locally, they also need to upgrade their local instance. Severity: 9.3 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 apr 2026
News
The CPUID Watering Hole Attack Turning CPU-Z into a Trojan

The CPUID Watering Hole Attack Turning CPU-Z into a Trojan In the world of system administration, few tools are as ubiquitous as CPU-Z and HWMonitor. These utilities are the “old reliables” for monitoring hardware health. However, on April 9, 2026, that trust ... Read more Published Date: Apr 13, 2026 (23 hours, 41 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-22679 CVE-2026-35616 CVE-2026-5281 CVE-2025-29824 CVE-2023-22952

CVEfeed Newsroom13 apr 2026
News
Laravel Passport Patches Machine-to-Human Authentication Bypass

Laravel Passport Patches Machine-to-Human Authentication Bypass Laravel Passport is widely recognized as an OAuth2 server and API authentication package that is both simple and enjoyable for developers to implement. However, a newly disclosed security flaw has int ... Read more Published Date: Apr 13, 2026 (1 day ago) Vulnerabilities has been mentioned in this article. CVE-2026-39976 CVE-2026-22679 CVE-2026-35616 CVE-2026-20093 CVE-2026-23898 CVE-2026-5281 CVE-2026-4800

CVEfeed Newsroom13 apr 2026
News
Adobe Patches Acrobat Reader 0-Day Vulnerability Exploited in the Wild

Adobe Patches Acrobat Reader 0-Day Vulnerability Exploited in the Wild Adobe has issued an emergency security patch to neutralize a critical zero-day vulnerability in Acrobat Reader that is currently being exploited in the wild. Tracked as CVE-2026-34621, this severe fla ... Read more Published Date: Apr 13, 2026 (22 hours, 33 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-34621

CVEfeed Newsroom13 apr 2026
News
Adobe Patches Actively Exploited Acrobat Reader Flaw CVE-2026-34621

Adobe Patches Actively Exploited Acrobat Reader Flaw CVE-2026-34621 Adobe has issued emergency security updates addressing a severe Acrobat Reader flaw tracked as CVE-2026-34621, a high-impact Adobe vulnerability that has already been observed being exploited in real- ... Read more Published Date: Apr 13, 2026 (22 hours, 39 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-34621 CVE-2026-5173 CVE-2026-4681

CVEfeed Newsroom13 apr 2026
VulnerabilitàAlta
CVE-2026-0232 - Cortex XDR Agent: Local Administrator can disable the agent on Windows

CVE ID :CVE-2026-0232 Published : April 13, 2026, 8:16 a.m. | 3 hours, 41 minutes ago Description :A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows allows a local Windows administrator to disable the agent. This issue may be leveraged by malware to perform malicious activity without detection. Severity: 4.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE13 apr 2026
News
Critical WordPress Plugin Flaw Lets Attackers Bypass Authentication and Gain Admin Access

Critical WordPress Plugin Flaw Lets Attackers Bypass Authentication and Gain Admin Access A critical security flaw found in a widely used WordPress plugin is putting thousands of websites at serious risk worldwide. Tracked as CVE-2026-1492, this vulnerability affects the User Registration ... Read more Published Date: Apr 13, 2026 (23 hours, 38 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-1492

CVEfeed Newsroom13 apr 2026

Pagina 2299 di 3217

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.