News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
40178 risultati
CVE ID :CVE-2026-4761 Published : March 25, 2026, 1:16 p.m. | 36 minutes ago Description :When a certificate and its private key are installed in the Windows machine certificate store using Network and Security tool, access rights to the private key are unnecessarily granted to the operator group. * Installations based on Panorama Suite 2025 (25.00.004) are vulnerable unless update PS-2500-00-0357 (or higher) is installed * Installations based on Panorama Suite 2025 Updated Dec. 25 (25.10.007) are not vulnerable Please refer to security bulletin BS-036, available on the Panorama CSIRT website: https://my.codra.net/en-gb/csirt . Severity: 3.3 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-4760 Published : March 25, 2026, 1:16 p.m. | 36 minutes ago Description :From Panorama Web HMI, an attacker can gain read access to certain Web HMI server files, if he knows their paths and if these files are accessible to the Servin process execution account. * Installations based on Panorama Suite 2022-SP1 (22.50.005) are vulnerable unless update PS-2210-02-4079 (or higher) is installed * Installations based on Panorama Suite 2023 (23.00.004) are vulnerable unless updates PS-2300-03-3078 (or higher) and PS-2300-04-3078 (or higher) and PS-2300-82-3078 (or higher) are installed * Installations based on Panorama Suite 2025 (25.00.016) are vulnerable unless updates PS-2500-02-1078 (or higher) and PS-2500-04-1078 (or higher) are installed * Installations based on Panorama Suite 2025 Updated Dec. 25 (25.10.007) are vulnerable unless updates PS-2510-02-1077 (or higher) and PS-2510-04-1077 (or higher) are installed Please refer to security bulletin BS-035, available on the Panorama CSIRT website: https://my.codra.net/en-gb/csirt . Severity: 7.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Firefox 149 Released With Patch for 37 Vulnerabilities that Enables Remote Attacks Mozilla released Firefox 149 on March 24, 2026, delivering one of the largest security advisories in the browser’s recent history, addressing 37 vulnerabilities spanning memory corruption, sandbox esc ... Read more Published Date: Mar 25, 2026 (1 day, 3 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-4729 CVE-2026-4728 CVE-2026-4727 CVE-2026-4726 CVE-2026-4725 CVE-2026-4724 CVE-2026-4723 CVE-2026-4722 CVE-2026-4721 CVE-2026-4720 CVE-2026-4719 CVE-2026-4718 CVE-2026-4717 CVE-2026-4716 CVE-2026-4715 CVE-2026-4714 CVE-2026-4713 CVE-2026-4712 CVE-2026-4711 CVE-2026-4710 CVE-2026-4709 CVE-2026-4708 CVE-2026-4707 CVE-2026-4706 CVE-2026-4705 CVE-2026-4704 CVE-2026-4702 CVE-2026-4701 CVE-2026-4700 CVE-2026-4699 CVE-2026-4698 CVE-2026-4697 CVE-2026-4696 CVE-2026-4695 CVE-2026-4694 CVE-2026-4693 CVE-2026-4692 CVE-2026-4691 CVE-2026-4690 CVE-2026-4689 CVE-2026-4688 CVE-2026-4687 CVE-2026-4686 CVE-2026-4685 CVE-2026-4684 CVE-2025-59375
CVE ID :CVE-2025-40842 Published : March 25, 2026, 1:10 p.m. | 42 minutes ago Description :Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains a Cross-Site Scripting (XSS) vulnerability which, if exploited, can lead to unauthorized disclosure and modification of certain information. Severity: 8.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-40841 Published : March 25, 2026, 1:07 p.m. | 45 minutes ago Description :Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains a Cross-Site Request Forgery (CSRF) vulnerability which, if exploited, can lead to unauthorized modification of certain information. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Squid Caching Proxy Alert: Critical ICP Protocol Flaws Threaten Web Infrastructure Squid, the widely deployed open-source caching proxy, has been hit with a trio of significant security vulnerabilities affecting its Internet Cache Protocol (ICP) implementation. These flaws, which in ... Read more Published Date: Mar 25, 2026 (1 day, 3 hours ago) Vulnerabilities has been mentioned in this article.
CVE ID :CVE-2026-28529 Published : March 25, 2026, 1 p.m. | 51 minutes ago Description :cryptodev-linux version 1.14 and prior contain a page reference handling flaw in the get_userbuf function of the /dev/crypto device driver that allows local users to trigger use-after-free conditions. Attackers with access to the /dev/crypto interface can repeatedly decrement reference counts of controlled pages to achieve local privilege escalation. Severity: 8.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-27260 Published : March 25, 2026, 12:54 p.m. | 58 minutes ago Description :Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains an Improper Filtering of Special Elements vulnerability which, if exploited, can lead to unauthorized modification of certain information Severity: 7.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
GitLab Critical Alert: High-Severity Flaws Allow App Impersonation and AI Token Leaks GitLab has released a critical security advisory alongside versions 18.10.1, 18.9.3, and 18.8.7 for its Community (CE) and Enterprise Editions (EE). The release addresses a battery of vulnerabilities, ... Read more Published Date: Mar 25, 2026 (1 day, 4 hours ago) Vulnerabilities has been mentioned in this article.
AI Infrastructure at Risk: NVIDIA Fixes Critical 9.0 RCE Flaw in Apex Library (CVE-2025-33244) NVIDIA has issued an urgent security update for its Apex library to remediate a critical vulnerability that could allow attackers to execute malicious code on Linux-based systems. The flaw, tracked as ... Read more Published Date: Mar 25, 2026 (1 day, 4 hours ago) Vulnerabilities has been mentioned in this article. CVE-2025-33244 CVE-2025-15517 CVE-2025-33179 CVE-2025-33187 CVE-2024-0138
PTC Warns of Critical Windchill, FlexPLM Flaw Enabling Remote Code Execution PTC has issued an urgent advisory regarding a critical Windchill and FlexPLM vulnerability that exposes affected systems to Remote Code Execution (RCE). The flaw, identified as CVE-2026-4681, has been ... Read more Published Date: Mar 25, 2026 (1 day, 3 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-4681 CVE-2026-21992
CVE ID :CVE-2026-23393 Published : March 25, 2026, 11:16 a.m. | 2 hours, 36 minutes ago Description :In the Linux kernel, the following vulnerability has been resolved: bridge: cfm: Fix race condition in peer_mep deletion When a peer MEP is being deleted, cancel_delayed_work_sync() is called on ccm_rx_dwork before freeing. However, br_cfm_frame_rx() runs in softirq context under rcu_read_lock (without RTNL) and can re-schedule ccm_rx_dwork via ccm_rx_timer_start() between cancel_delayed_work_sync() returning and kfree_rcu() being called. The following is a simple race scenario: cpu0 cpu1 mep_delete_implementation() cancel_delayed_work_sync(ccm_rx_dwork); br_cfm_frame_rx() // peer_mep still in hlist if (peer_mep->ccm_defect) ccm_rx_timer_start() queue_delayed_work(ccm_rx_dwork) hlist_del_rcu(&peer_mep->head); kfree_rcu(peer_mep, rcu); ccm_rx_work_expired() // on freed peer_mep To prevent this, cancel_delayed_work_sync() is replaced with disable_delayed_work_sync() in both peer MEP deletion paths, so that subsequent queue_delayed_work() calls from br_cfm_frame_rx() are silently rejected. The cc_peer_disable() helper retains cancel_delayed_work_sync() because it is also used for the CC enable/disable toggle path where the work must remain re-schedulable. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Pagina 2716 di 3349