News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
46967 risultati
MikroTrick: technical analysis, disclosure process, and the use of LLM agents Introduction On 3 September 2026, MikroTik released patches almost simultaneously for several maintained RouterOS branches: 7.25beta3, 7.24.2, 7.23.4, and 6.49.21, and recommended installing a patched ... Read more Published Date: Sep 22, 2026 (2 days, 2 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-86060 CVE-2026-67279 CVE-2026-67277 CVE-2026-67276
A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the C++ `new` operator. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability.
A vulnerability has been found in dgtlmoon changedetection.io up to 0.60.7. The impacted element is the function check_authentication of the file changedetectionio/flask_app.py of the component Authentication Hook. Such manipulation leads to improper authentication. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22. The flaw, tracked as CVE-2 ... Read more Published Date: Sep 22, 2026 (2 days, 4 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-93952 CVE-2026-16812
CVE ID :CVE-2026-74849 Published : Sept. 22, 2026, 11:55 a.m. | 32 minutes ago Description :Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to a remote code execution vulnerability in the GINA client. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory A new flaw in the Linux kernel's KVM virtualization code for ARM64 processors can leave a freed piece of host memory exposed to a guest virtual machine on hosts with nested virtualization enabled. The ... Read more Published Date: Sep 22, 2026 (2 days, 3 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-89775
SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE A SharePoint Server vulnerability that Microsoft initially classified as a spoofing flaw with a CVSS score of 6.5 actually enables authenticated remote code execution, according to full technical deta ... Read more Published Date: Sep 22, 2026 (1 day, 22 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-65660 CVE-2026-55040
CVE ID :CVE-2026-95623 Published : Sept. 22, 2026, 11:17 a.m. | 1 hour, 10 minutes ago Description :The Tauri HTTP plugin validates requested URLs against the application's configured scope allowlist only once, on the initial request. When the remote server responds with an HTTP 3xx redirect, reqwest follows the redirect internally without re-checking the new target URL against the scope. This allows an attacker who controls an allowed URL (or finds an open redirect on an allowed host) to reach disallowed destinations such as cloud metadata endpoints, localhost services, or internal network hosts. Severity: 5.6 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-92882 Published : Sept. 22, 2026, 11:17 a.m. | 1 hour, 10 minutes ago Description :Insufficiently protected credentials in the host and folder configuration endpoints of the REST API in Checkmk Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-90990 Published : Sept. 22, 2026, 11:17 a.m. | 1 hour, 10 minutes ago Description :Improper neutralization of newlines in filter values in the monitoring host and service list APIs in Checkmk Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-87119 Published : Sept. 22, 2026, 11:16 a.m. | 1 hour, 10 minutes ago Description :Authentication Bypass by Capture-replay in ZenHive mpp allows an attacker holding a captured subscription activation credential to charge the payer repeatedly. The payer signs a Tempo KeyAuthorization over the chain id, key type, key id, expiry, limits and scopes only, with nothing tying it to the challenge that prompted it. MPP.Methods.Tempo.KeyAuthorization.verify/3 in lib/mpp/methods/tempo/key_authorization.ex pins each of those signed fields against the subscription request, and the access key it pins is a static per-endpoint server key, so one signed authorization verifies against every challenge the server issues for the same subscription terms. MPP.Methods.Tempo.Subscription.activate/4 deduplicates activations by challenge id, so presenting the captured credential under a fresh challenge produces a different dedup key, claim_activation succeeds, and the subscription transaction is built and broadcast again. Each replay charges the payer's wallet a new first-period settlement and re-authorizes the server key, bounded only by the subscription expiry and the chain's own semantics for re-installing an existing key. This issue affects mpp: from 0.14.0 before 0.16.2. Severity: 8.2 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-89420 Published : Sept. 22, 2026, 11:16 a.m. | 1 hour, 11 minutes ago Description :Improper Validation of Specified Quantity in Input in ZenHive mpp allows a client holding an open payment channel to obtain paid resources without being charged. MPP.Session.Actions.accept_voucher/3 in lib/mpp/session/actions.ex treats a voucher whose cumulativeAmount equals the channel's already-accepted cumulative amount as an idempotent success, returning the channel unchanged without calling maybe_spend/2. The credential verifies, the protected resource is served, and spent and units stay where they were. Because the server issues a fresh challenge per request and the credential replay store keys on challenge id and payload, the same signed voucher can be re-presented under every new challenge, so one paid voucher yields an unbounded number of paid units. The path is reachable from any method built on MPP.Session.Method through the Plug, MCP, JSON-RPC and WebSocket transports. This issue affects mpp: from 0.14.0 before 0.16.2. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Pagina 368 di 3914