News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
29115 risultati
CVE ID :CVE-2026-29114 Published : June 10, 2026, 7:16 a.m. | 5 hours, 22 minutes ago Description :A vulnerability has been found in some Dahua products. An attacker may obtain the device’s CA root certificate. If that CA is installed and trusted on client systems, the attacker could issue fraudulent certificates trusted by those clients and undermine the certificate trust chain. Severity: 2.3 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Microsoft Patches Record 200 Vulnerabilities in June 2026 Patch Tuesday Microsoft’s June 2026 Patch Tuesday, released on June 10, 2026, addressed 200 security vulnerabilities across Windows, Office, Azure, and related products—the largest single Patch Tuesday release in t ... Read more Published Date: Jun 10, 2026 (1 day, 12 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-50507 CVE-2026-49160 CVE-2026-45657 CVE-2026-45586 CVE-2026-20245 CVE-2024-1086
June 2026 Patch Tuesday: Microsoft Patches 206 Vulnerabilities Including Three Publicly Disclosed Zero-Days Microsoft has addressed 206 vulnerabilities in its June 2026 security update release. This month's patches include fixes for three publicly disclosed zero-day vulnerabilities and 37 Critical vulnerabi ... Read more Published Date: Jun 10, 2026 (1 day, 12 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-50507 CVE-2026-49160 CVE-2026-48574 CVE-2026-48563 CVE-2026-47654 CVE-2026-47652 CVE-2026-47635 CVE-2026-47291 CVE-2026-47289 CVE-2026-47288 CVE-2026-45657 CVE-2026-45648 CVE-2026-45641 CVE-2026-45607 CVE-2026-45586 CVE-2026-45474 CVE-2026-45472 CVE-2026-45463 CVE-2026-45461 CVE-2026-45460 CVE-2026-45458 CVE-2026-45456 CVE-2026-44815 CVE-2026-44812 CVE-2026-44810 CVE-2026-44803 CVE-2026-44801 CVE-2026-44799 CVE-2026-42992 CVE-2026-42987 CVE-2026-42985 CVE-2026-33828 CVE-2026-32193 CVE-2026-26142 CVE-2026-48579 CVE-2026-48567 CVE-2026-47655 CVE-2026-47644 CVE-2026-45497 CVE-2026-42824 CVE-2026-20929
Microsoft Patch Tuesday — June 2026 Microsoft’s June 2026 Patch Tuesday is the largest release since the Patch Tuesday program began, surpassing the previous record of 167 CVEs set in October 2025. This month’s release addresses 206 vul ... Read more Published Date: Jun 10, 2026 (1 day, 11 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-50507 CVE-2026-49160 CVE-2026-48574 CVE-2026-48563 CVE-2026-47652 CVE-2026-47635 CVE-2026-47291 CVE-2026-47289 CVE-2026-45657 CVE-2026-45648 CVE-2026-45641 CVE-2026-45607 CVE-2026-45586 CVE-2026-45476 CVE-2026-45458 CVE-2026-45456 CVE-2026-44815 CVE-2026-44812 CVE-2026-44810 CVE-2026-44803 CVE-2026-44801 CVE-2026-44799 CVE-2026-42987 CVE-2026-42985 CVE-2026-32193 CVE-2026-47655 CVE-2026-47644 CVE-2026-42824 CVE-2026-28318 CVE-2026-45498 CVE-2026-41091 CVE-2026-33825
Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows The anonymous security researcher going by the name Chaotic Eclipse (aka Nightmare-Eclipse) has released a proof-of-concept (PoC) exploit for yet another Microsoft Defender zero-day named RoguePlanet. ... Read more Published Date: Jun 10, 2026 (1 day, 9 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-11645 CVE-2026-20230 CVE-2026-45498 CVE-2026-41091 CVE-2026-23479 CVE-2026-33825
CVE ID :CVE-2026-26241 Published : June 10, 2026, 5:16 a.m. | 7 hours, 22 minutes ago Description :A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5243 and later Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
A local privilege escalation vulnerability was found in the ansible.posix authorized_key module. The module's keyfile() function uses os.chown() instead of os.lchown() and opens files without O_NOFOLLOW when managing SSH authorized keys. An unprivileged local user can pre-stage symbolic links in their ~/.ssh directory to redirect file ownership changes to arbitrary system paths when an operator runs the authorized_key task as root, leading to local privilege escalation.
CVE ID :CVE-2026-11837 Published : June 10, 2026, 5:16 a.m. | 7 hours, 22 minutes ago Description :A local privilege escalation vulnerability was found in the ansible.posix authorized_key module. The module's keyfile() function uses os.chown() instead of os.lchown() and opens files without O_NOFOLLOW when managing SSH authorized keys. An unprivileged local user can pre-stage symbolic links in their ~/.ssh directory to redirect file ownership changes to arbitrary system paths when an operator runs the authorized_key task as root, leading to local privilege escalation. Severity: 7.3 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-26240 Published : June 10, 2026, 5:16 a.m. | 7 hours, 22 minutes ago Description :A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5243 and later Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2025-8444 Published : June 10, 2026, 5:16 a.m. | 7 hours, 22 minutes ago Description :The Animation Addons for Elementor – GSAP Powered Elementor Addons & Website Templates plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the multiple parameters in all versions up to, and including, 2.6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Severity: 6.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS Cybersecurity researchers have flagged half a dozen vulnerabilities in protobuf.js, a JavaScript and TypeScript implementation of Protocol Buffers (Protobuf), that, if successfully exploited, could re ... Read more Published Date: Jun 10, 2026 (1 day, 10 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-11645 CVE-2026-20230 CVE-2026-44295 CVE-2026-44294 CVE-2026-44292 CVE-2026-44291 CVE-2026-44290 CVE-2026-44289 CVE-2026-23479
CVE ID :CVE-2026-26239 Published : June 10, 2026, 4:17 a.m. | 8 hours, 21 minutes ago Description :A buffer overflow vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5208 and later Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Pagina 668 di 2427