Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

33517 risultati

VulnerabilitàAlta
CVE-2026-15560 (CVSS 8.1)

when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmarshalling on :3528, allowing an unauthenticated attacker to load and instantiate arbitrary classes from a remote URL in the server JVM before EJB security interceptors run.

NVD (NIST)4g fa
VulnerabilitàAlta
CVE-2026-15556 (CVSS 8.1)

A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the signature check can allow an attacker to forge a SAML response and auth as any principal with any roles on the protected application.

NVD (NIST)4g fa
VulnerabilitàAlta
CVE-2026-15555 (CVSS 8.8)

A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicated session data via the JBoss Marshalling River unmarshaller with no class filtering — enabling RCE via deserialization gadget chains on every cluster node.

NVD (NIST)4g fa
VulnerabilitàAlta
CVE-2026-15554 (CVSS 7.4)

the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authentication. This enables an unauthenticated attacker with direct TCP access to port 8009 to bypass CLIENT-CERT authentication by injecting a forged X.509 certificate via the AJP protocol.

NVD (NIST)4g fa
VulnerabilitàCritica
CVE-2026-10579 (CVSS 9.8)

A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in any role. This could lead to information disclosure, access to restricted operations, or other flaws.

NVD (NIST)4g fa
VulnerabilitàAlta
CVE-2026-10579 - Picketlink-federation: auth bypass in picketlink saml unsolicited-response

CVE ID :CVE-2026-10579 Published : 11. August 2026 09:17 | 1 Stunde, 14 Minuten ago Description :A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in any role. This could lead to information disclosure, access to restricted operations, or other flaws. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE4g fa
VulnerabilitàAlta
CVE-2026-15554 - Undertow-core: undertow: authentication bypass via ajp ssl_cert/is_ssl forgery

CVE ID :CVE-2026-15554 Published : 11. August 2026 09:17 | 1 Stunde, 14 Minuten ago Description :the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authentication. This enables an unauthenticated attacker with direct TCP access to port 8009 to bypass CLIENT-CERT authentication by injecting a forged X.509 certificate via the AJP protocol. Severity: 7.4 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE4g fa
VulnerabilitàAlta
CVE-2026-15560 - Openjdk-orb: unauthed class loading via iiop in eap

CVE ID :CVE-2026-15560 Published : 11. August 2026 09:17 | 1 Stunde, 14 Minuten ago Description :when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmarshalling on :3528, allowing an unauthenticated attacker to load and instantiate arbitrary classes from a remote URL in the server JVM before EJB security interceptors run. Severity: 8.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE4g fa
VulnerabilitàAlta
CVE-2026-15556 - Picketlink-federation: picketlink saml 2.0 auth bypass via missing assertions

CVE ID :CVE-2026-15556 Published : 11. August 2026 09:17 | 1 Stunde, 14 Minuten ago Description :A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the signature check can allow an attacker to forge a SAML response and auth as any principal with any roles on the protected application. Severity: 8.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE4g fa
VulnerabilitàAlta
CVE-2026-15555 - Jboss-marshalling-river: wildfly-clustering-infinispan-marshalling: jboss deserialization rce via unfiltered river unmarshaller

CVE ID :CVE-2026-15555 Published : 11. August 2026 09:17 | 1 Stunde, 14 Minuten ago Description :A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicated session data via the JBoss Marshalling River unmarshaller with no class filtering — enabling RCE via deserialization gadget chains on every cluster node. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE4g fa
VulnerabilitàAlta
CVE-2026-15561 - Undertow-core: oom via missing limits in chunked trailer in eap's undertow

CVE ID :CVE-2026-15561 Published : 11. August 2026 09:17 | 1 Stunde, 14 Minuten ago Description :A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the JVM to an OutOfMemory error, stopping all deployments on the listener, and achieving Denial of Service. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE4g fa
News
Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks

Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world. Targets of these ... Read more Published Date: Aug 11, 2026 (1 day, 10 hours ago) Vulnerabilities has been mentioned in this article. CVE-2025-24472 CVE-2024-5559

CVEfeed Newsroom4g fa

Pagina 98 di 2794

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.