Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

45500 risultati

VulnerabilitàAlta
CVE-2026-63104 (CVSS 8.1)

Kaneo versions 2.3.12 before 2.12.2 contain a missing authorization vulnerability that allows authenticated workspace members with viewer or member roles to delete and modify tasks beyond their assigned permissions by exploiting the bulk task endpoint that omits workspace permission checks. Attackers can send requests to the PATCH /api/task/bulk endpoint, which verifies only workspace membership without calling the role-based permission check enforced on all other task endpoints, to permanently delete all tasks or modify task status, priority, assignee, due date, and labels in a workspace.

NVD (NIST)22 set 2026
VulnerabilitàCritica
CVE-2026-47116 (CVSS 9.8)

LTSecurity LTK3500SF contains a hard-coded credentials vulnerability where root and guest account passwords are stored as reversible hashes in /etc/shadow, recoverable using dictionary-based cracking tools. Attackers can use the recovered credentials to authenticate via Telnet or SSH and obtain full root-level access to the operating system.

NVD (NIST)22 set 2026
VulnerabilitàAlta
CVE-2026-28325 (CVSS 8.8)

SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability stemming from deserialization of untrusted data when the application is configured to use a specific communication mode.

NVD (NIST)22 set 2026
VulnerabilitàCritica
CVE-2026-28324 (CVSS 9.8)

SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks. Installations configured in a non-default and non-secure configuration are affected.

NVD (NIST)22 set 2026
VulnerabilitàAlta
CVE-2026-84395 (CVSS 7.1)

Premiere Pro [NEEDS REVIEW: environment mismatch — product 'Premiere Pro' is only known to appear in the 'Bucket A' bucket but environment_type 'Desktop' is in the 'Bucket A' bucket. This changes the exploitation clause and/or ATO eligibility — verify before publishing.] is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed.

NVD (NIST)22 set 2026
VulnerabilitàAlta
CVE-2026-83963 (CVSS 7.8)

Substance3D - Modeler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

NVD (NIST)22 set 2026
VulnerabilitàAlta
CVE-2026-83962 (CVSS 7.8)

Substance3D - Modeler is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

NVD (NIST)22 set 2026
VulnerabilitàCritica
CVE-2026-82000 (CVSS 9.6)

Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction. Scope is changed.

NVD (NIST)22 set 2026
VulnerabilitàAlta
CVE-2026-81999 (CVSS 8.7)

Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. An attacker with high privileges could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction. Scope is changed.

NVD (NIST)22 set 2026
VulnerabilitàAlta
CVE-2026-81998 (CVSS 7.8)

Substance3D - Modeler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

NVD (NIST)22 set 2026
VulnerabilitàCritica
CVE-2026-81995 (CVSS 9.1)

Adobe Experience Manager Forms JEE is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

NVD (NIST)22 set 2026
VulnerabilitàAlta
CVE-2026-79906 (CVSS 7.8)

Substance3D - Modeler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

NVD (NIST)22 set 2026

Pagina 235 di 3792

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.