News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
45302 risultati
CVE ID :CVE-2026-4761 Published : March 25, 2026, 1:16 p.m. | 36 minutes ago Description :When a certificate and its private key are installed in the Windows machine certificate store using Network and Security tool, access rights to the private key are unnecessarily granted to the operator group. * Installations based on Panorama Suite 2025 (25.00.004) are vulnerable unless update PS-2500-00-0357 (or higher) is installed * Installations based on Panorama Suite 2025 Updated Dec. 25 (25.10.007) are not vulnerable Please refer to security bulletin BS-036, available on the Panorama CSIRT website: https://my.codra.net/en-gb/csirt . Severity: 3.3 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-4760 Published : March 25, 2026, 1:16 p.m. | 36 minutes ago Description :From Panorama Web HMI, an attacker can gain read access to certain Web HMI server files, if he knows their paths and if these files are accessible to the Servin process execution account. * Installations based on Panorama Suite 2022-SP1 (22.50.005) are vulnerable unless update PS-2210-02-4079 (or higher) is installed * Installations based on Panorama Suite 2023 (23.00.004) are vulnerable unless updates PS-2300-03-3078 (or higher) and PS-2300-04-3078 (or higher) and PS-2300-82-3078 (or higher) are installed * Installations based on Panorama Suite 2025 (25.00.016) are vulnerable unless updates PS-2500-02-1078 (or higher) and PS-2500-04-1078 (or higher) are installed * Installations based on Panorama Suite 2025 Updated Dec. 25 (25.10.007) are vulnerable unless updates PS-2510-02-1077 (or higher) and PS-2510-04-1077 (or higher) are installed Please refer to security bulletin BS-035, available on the Panorama CSIRT website: https://my.codra.net/en-gb/csirt . Severity: 7.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Firefox 149 Released With Patch for 37 Vulnerabilities that Enables Remote Attacks Mozilla released Firefox 149 on March 24, 2026, delivering one of the largest security advisories in the browser’s recent history, addressing 37 vulnerabilities spanning memory corruption, sandbox esc ... Read more Published Date: Mar 25, 2026 (1 day, 3 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-4729 CVE-2026-4728 CVE-2026-4727 CVE-2026-4726 CVE-2026-4725 CVE-2026-4724 CVE-2026-4723 CVE-2026-4722 CVE-2026-4721 CVE-2026-4720 CVE-2026-4719 CVE-2026-4718 CVE-2026-4717 CVE-2026-4716 CVE-2026-4715 CVE-2026-4714 CVE-2026-4713 CVE-2026-4712 CVE-2026-4711 CVE-2026-4710 CVE-2026-4709 CVE-2026-4708 CVE-2026-4707 CVE-2026-4706 CVE-2026-4705 CVE-2026-4704 CVE-2026-4702 CVE-2026-4701 CVE-2026-4700 CVE-2026-4699 CVE-2026-4698 CVE-2026-4697 CVE-2026-4696 CVE-2026-4695 CVE-2026-4694 CVE-2026-4693 CVE-2026-4692 CVE-2026-4691 CVE-2026-4690 CVE-2026-4689 CVE-2026-4688 CVE-2026-4687 CVE-2026-4686 CVE-2026-4685 CVE-2026-4684 CVE-2025-59375
CVE ID :CVE-2025-40842 Published : March 25, 2026, 1:10 p.m. | 42 minutes ago Description :Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains a Cross-Site Scripting (XSS) vulnerability which, if exploited, can lead to unauthorized disclosure and modification of certain information. Severity: 8.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-40841 Published : March 25, 2026, 1:07 p.m. | 45 minutes ago Description :Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains a Cross-Site Request Forgery (CSRF) vulnerability which, if exploited, can lead to unauthorized modification of certain information. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Squid Caching Proxy Alert: Critical ICP Protocol Flaws Threaten Web Infrastructure Squid, the widely deployed open-source caching proxy, has been hit with a trio of significant security vulnerabilities affecting its Internet Cache Protocol (ICP) implementation. These flaws, which in ... Read more Published Date: Mar 25, 2026 (1 day, 3 hours ago) Vulnerabilities has been mentioned in this article.
CVE ID :CVE-2026-28529 Published : March 25, 2026, 1 p.m. | 51 minutes ago Description :cryptodev-linux version 1.14 and prior contain a page reference handling flaw in the get_userbuf function of the /dev/crypto device driver that allows local users to trigger use-after-free conditions. Attackers with access to the /dev/crypto interface can repeatedly decrement reference counts of controlled pages to achieve local privilege escalation. Severity: 8.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-27260 Published : March 25, 2026, 12:54 p.m. | 58 minutes ago Description :Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains an Improper Filtering of Special Elements vulnerability which, if exploited, can lead to unauthorized modification of certain information Severity: 7.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
GitLab Critical Alert: High-Severity Flaws Allow App Impersonation and AI Token Leaks GitLab has released a critical security advisory alongside versions 18.10.1, 18.9.3, and 18.8.7 for its Community (CE) and Enterprise Editions (EE). The release addresses a battery of vulnerabilities, ... Read more Published Date: Mar 25, 2026 (1 day, 4 hours ago) Vulnerabilities has been mentioned in this article.
AI Infrastructure at Risk: NVIDIA Fixes Critical 9.0 RCE Flaw in Apex Library (CVE-2025-33244) NVIDIA has issued an urgent security update for its Apex library to remediate a critical vulnerability that could allow attackers to execute malicious code on Linux-based systems. The flaw, tracked as ... Read more Published Date: Mar 25, 2026 (1 day, 4 hours ago) Vulnerabilities has been mentioned in this article. CVE-2025-33244 CVE-2025-15517 CVE-2025-33179 CVE-2025-33187 CVE-2024-0138
PTC Warns of Critical Windchill, FlexPLM Flaw Enabling Remote Code Execution PTC has issued an urgent advisory regarding a critical Windchill and FlexPLM vulnerability that exposes affected systems to Remote Code Execution (RCE). The flaw, identified as CVE-2026-4681, has been ... Read more Published Date: Mar 25, 2026 (1 day, 3 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-4681 CVE-2026-21992
CVE ID :CVE-2026-31788 Published : March 25, 2026, 11:16 a.m. | 2 hours, 36 minutes ago Description :In the Linux kernel, the following vulnerability has been resolved: xen/privcmd: restrict usage in unprivileged domU The Xen privcmd driver allows to issue arbitrary hypercalls from user space processes. This is normally no problem, as access is usually limited to root and the hypervisor will deny any hypercalls affecting other domains. In case the guest is booted using secure boot, however, the privcmd driver would be enabling a root user process to modify e.g. kernel memory contents, thus breaking the secure boot feature. The only known case where an unprivileged domU is really needing to use the privcmd driver is the case when it is acting as the device model for another guest. In this case all hypercalls issued via the privcmd driver will target that other guest. Fortunately the privcmd driver can already be locked down to allow only hypercalls targeting a specific domain, but this mode can be activated from user land only today. The target domain can be obtained from Xenstore, so when not running in dom0 restrict the privcmd driver to that target domain from the beginning, resolving the potential problem of breaking secure boot. This is XSA-482 --- V2: - defer reading from Xenstore if Xenstore isn't ready yet (Jan Beulich) - wait in open() if target domain isn't known yet - issue message in case no target domain found (Jan Beulich) Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Pagina 3143 di 3776