Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38738 risultati

News
ThreatsDay Bulletin: Hybrid P2P Botnet, 13-Year-Old Apache RCE and 18 More Stories

ThreatsDay Bulletin: Hybrid P2P Botnet, 13-Year-Old Apache RCE and 18 More Stories Thursday. Another week, another batch of things that probably should've been caught sooner but weren't.This one's got some range — old vulnerabilities getting new life, a few "why was that even possib ... Read more Published Date: Apr 09, 2026 (3 days, 3 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-34197 CVE-2026-35616 CVE-2026-5281 CVE-2026-34040 CVE-2026-23226 CVE-2025-55182 CVE-2025-40039 CVE-2024-32114 CVE-2022-41678

CVEfeed Newsroom09 apr 2026
News
Frontend Secrets Exposed: Vite Patches Critical Security Bypass in Dev Server

Frontend Secrets Exposed: Vite Patches Critical Security Bypass in Dev Server Vite has become the “speed demon” of modern frontend development, prized for its lightning-fast Hot Module Replacement (HMR) and native ES module serving. However, two recently disclosed vulnerabiliti ... Read more Published Date: Apr 09, 2026 (2 days, 18 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom09 apr 2026
VulnerabilitàAlta
CVE-2026-24661 - Unbounded Request Body Read in MS Teams Plugin {{/changes}} Webhook Endpoint

CVE ID :CVE-2026-24661 Published : April 9, 2026, 11:16 a.m. | 2 hours, 40 minutes ago Description :Mattermost Plugins versions Severity: 3.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 apr 2026
VulnerabilitàAlta
CVE-2025-57735 - Apache Airflow: Airflow Logout Not Invalidating JWT

CVE ID :CVE-2025-57735 Published : April 9, 2026, 11:16 a.m. | 2 hours, 40 minutes ago Description :When user logged out, the JWT token the user had authtenticated with was not invalidated, which could lead to reuse of that token in case it was intercepted. In Airflow 3.2 we implemented the mechanism that implements token invalidation at logout. Users who are concerned about the logout scenario and possibility of intercepting the tokens, should upgrade to Airflow 3.2+ Users are recommended to upgrade to version 3.2.0, which fixes this issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 apr 2026
VulnerabilitàAlta
CVE-2026-21388 - Unbounded Request Body Read in MS Teams Plugin {{/lifecycle}} Webhook Endpoint

CVE ID :CVE-2026-21388 Published : April 9, 2026, 11:16 a.m. | 2 hours, 40 minutes ago Description :Mattermost Plugins versions Severity: 3.7 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 apr 2026
VulnerabilitàAlta
CVE-2024-1490 (CVSS 7.2)

An authenticated remote attacker with high privileges can exploit the OpenVPN configuration via the web-based management interface of a WAGO PLC. If user-defined scripts are permitted, OpenVPN may allow the execution of arbitrary shell commands enabling the attacker to run arbitrary commands on the device.

NVD (NIST)09 apr 2026
VulnerabilitàAlta
CVE-2024-1490 - Wago: Vulnerability in WBM through Open VPN

CVE ID :CVE-2024-1490 Published : April 9, 2026, 11:16 a.m. | 2 hours, 40 minutes ago Description :An authenticated remote attacker with high privileges can exploit the OpenVPN configuration via the web-based management interface of a WAGO PLC. If user-defined scripts are permitted, OpenVPN may allow the execution of arbitrary shell commands enabling the attacker to run arbitrary commands on the device. Severity: 7.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE09 apr 2026
News
Vulnerabilities in Hydrosystem Control System software

Vulnerabilities in Hydrosystem Control System software Vulnerabilities in Hydrosystem Control System software CVE ID CVE-2026-4901 Publication date 09 April 2026 Vendor Hydrosystem Product Control System Vulnerable versions All before 9.8.5 Vulnerability ... Read more Published Date: Apr 09, 2026 (2 days, 20 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-4901 CVE-2026-34185 CVE-2026-34184

CVEfeed Newsroom09 apr 2026
News
CISA Warns of Critical Ivanti EPMM Code Injection Vulnerability Exploited in Attacks

CISA Warns of Critical Ivanti EPMM Code Injection Vulnerability Exploited in Attacks The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning regarding a critical security flaw in Ivanti Endpoint Manager Mobile (EPMM). The agency recently added this fla ... Read more Published Date: Apr 09, 2026 (2 days, 20 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-1340

CVEfeed Newsroom09 apr 2026
News
GitLab Patches Multiple Vulnerabilities That Enables DoS and Code Injection Attacks

GitLab Patches Multiple Vulnerabilities That Enables DoS and Code Injection Attacks GitLab has released urgent security updates (versions 18.10.3, 18.9.5, and 18.8.9) for its Community Edition (CE) and Enterprise Edition (EE) to address high-severity flaws that enable Denial-of-Servi ... Read more Published Date: Apr 09, 2026 (1 day, 8 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom09 apr 2026
News
Multiple SonicWall Vulnerabilities Enable SQL Injection and Privilege Escalation Attacks

Multiple SonicWall Vulnerabilities Enable SQL Injection and Privilege Escalation Attacks SonicWall has released a critical security advisory addressing four vulnerabilities affecting its Secure Mobile Access (SMA) 1000 series appliances. These security flaws could allow remote attackers t ... Read more Published Date: Apr 09, 2026 (1 day, 8 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom09 apr 2026
News
Palo Alto Cortex Microsoft Teams Integration Vulnerability Enables Data Access for Attackers

Palo Alto Cortex Microsoft Teams Integration Vulnerability Enables Data Access for Attackers Palo Alto Networks released an urgent update to patch a high-severity flaw (CVE-2026-0234) affecting the Microsoft Teams integration in Cortex XSOAR and Cortex XSIAM. This flaw could allow unauthorize ... Read more Published Date: Apr 09, 2026 (1 day, 8 hours ago) Vulnerabilities has been mentioned in this article.

CVEfeed Newsroom09 apr 2026

Pagina 2361 di 3229

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.