Nyhetsnavet

Samlar nyheter från utvalda källor. Logga in för att spara urval och skapa profiler.

Uppdaterad 2026-07-22 19:53 Nästa om --:-- Försenad
14 av 14 källor 10 per källa

IT-säkerhet och cybersäkerhet i realtid — CVE-varningar, sårbarhetsrapporter, incidenter och hotinformation från NVD, CISA, BleepingComputer och fler SOC-källor.

Snabbfilter
Toppnyheter Säkerhet
Security feed-översikt Dolj widget
Poster
255
Källor
14
Senast uppdaterad
2026-07-22 19:53
NVD (National Vulnerability Database)20
CERT-SE20
CISA KEV-katalog20
CISA Alerts20
Microsoft MSRC20
GitHub Security Advisories20
CVE-toppar
CVE-2025-1169820
CVE-2025-1201120
CVE-2025-1201220
CVE-2026-276417
CVE-2026-586447
Senaste CVE
Fel per källa
NVD (National Vulnerability Database)NVD (National Vulnerability Database):
SecurityWeek VulnerabilitiesSecurityWeek Vulnerabilities: Cannot connect to host www.securityweek.com:443 ssl:default [Temporary failure in name resolution]
CERT-SECERT-SE: Cannot connect to host www.cert.se:443 ssl:default [Temporary failure in name resolution]
CISA KEV-katalogCISA KEV-katalog:
CISA AlertsCISA Alerts: Cannot connect to host www.cisa.gov:443 ssl:default [Temporary failure in name resolution]
Microsoft MSRCMicrosoft MSRC: Cannot connect to host api.msrc.microsoft.com:443 ssl:default [Temporary failure in name resolution]
GitHub Security AdvisoriesGitHub Security Advisories:
Cisco PSIRTCisco PSIRT: Cannot connect to host tools.cisco.com:443 ssl:default [Temporary failure in name resolution]
Fortinet PSIRTFortinet PSIRT:
Palo Alto Networks AdvisoriesPalo Alto Networks Advisories:
BleepingComputerBleepingComputer:
The Hacker NewsThe Hacker News:
ThreatpostThreatpost:
Dark ReadingDark Reading:
Säkerhet 120 artiklar
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-46817 – Oracle E-Business Suite

Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this...

CISA KEV-katalog ikon CISA KEV-katalog
Dark Reading ikon
Dark Reading
6 GHz Wi-Fi Flaws Could Disrupt Critical Systems

Automated Frequency Coordination systems by default trust client-side data, which could lead to location spoofing and other attacks that disrupt traffic.

Dark Reading ikon Dark Reading
Dark Reading ikon
Dark Reading
Manage Vendor Risk in a Few Practical Steps

Risk tolerance, exposure visibility, board oversight — handling third-party risk is complicated but achievable with disciplined, precise governance.

Dark Reading ikon Dark Reading
CERT-SE ikon
CERT-SE
Skadliga npm-paket

Ett koordinerat leveranskedjeangrepp har drabbat separata AsyncAPI GitHub-repon. Angripare har utnyttjat en sårbarhet i GitHub Actions. [1]

CERT-SE ikon CERT-SE
CISA Alerts ikon
CISA Alerts
ABB Advant Master Online Builder

View CSAF Summary ABB became aware of vulnerability in the products versions listed as affected in the advisory, where an incorrect version of Online Builder (ONB) was included in the media. An update is available...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
Rockwell Automation 1715-AENTR EtherNet/IP Adapter

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to read or delete files, stop tasks, modify memory, and change I/O states, potentially impacting the confidentiality, integrity,...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
ABB Ability Edgenius

View CSAF Summary ABB is aware of public reports of a vulnerability CVE‑2026‑31431 (Copy Fail) in the product versions listed as affected in the advisory. An update is available that resolves a publicly reported...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
CISA Urges SharePoint Hardening After New Exploitations

Update July 16, 2026: CISA has updated this Alert to reflect the addition of CVE-2026-58644 to its Known Exploited Vulnerabilities (KEV) Catalog on July 16, 2026. CISA is aware of active exploitation of...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
ABB T-MAC Plus

View CSAF Summary ABB became aware of vulnerability in the products versions listed as affected in the advisory. An update is available that resolves the reported vulnerabilities. An attacker who successfully...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-15409 SonicWall SMA1000 Appliances Server-Side Request Forgery...

CISA Alerts ikon CISA Alerts
1 fler källor
CISA Alerts CISA Adds One Known Exploited Vulnerability to Catalog 2026-07-13 14:00
Fortinet PSIRT ikon
Fortinet PSIRT
Buffer overread in authd and wad daemon

CVSSv3 Score: 4.1 A buffer over-read vulnerability [CWE-126] in FortiOS, FortiProxy, and FortiSASE may allow an authenticated remote attacker to return a portion of device memory in the redirect response via...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Cross-Site Scripting in Domain parameter

CVSSv3 Score: 5.3 An Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability [CWE-80] in FortiSIEM may allow a privileged administrator to execute unauthorized commands via crafted...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Header injection in Web Filter warning page

CVSSv3 Score: 3.4 An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy may allow an attacker in possession of a valid web filter...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Header injection in captive portal authentication form

CVSSv3 Score: 3.1 An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy captive portal may allow an attacker able to intercept and...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Out of bounds read in GUI

CVSSv3 Score: 7.0 An out of bounds read [CWE-125] vulnerability in FortiAuthenticator may allow a remote unauthenticated attacker to retrieve sensitive information via a specially crafted request. Revised on...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Path traversal in CLI command allows deletion of root file system

CVSSv3 Score: 5.0 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiOS, FortiPAM, FortiProxy and FortiSwitch Manager may allow a privileged authenticated...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
SSL-VPN Reflected XSS

CVSSv3 Score: 6.1 An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiOS, FortiProxy, FortiPAM and FortiSwitch-Manager Agentless SSL-VPN may allow an...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Stack Buffer Overflow in Log Report

CVSSv3 Score: 5.9 A Stack-based Buffer Overflow vulnerability [CWE-121] in FortiOS, FortiProxy and FortiPAM may allow a privileged authenticated attacker who can bypass stack protection and ASLR to execute arbitrary...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Supers override fails to properly override supervisor address

CVSSv3 Score: 6.9 An Improper Restriction of Communication Channel to Intended Endpoints [CWE-923] vulnerability in FortiSIEM Windows Agent may allow an unauthorized attacker on the same local network to execute...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Unauthenticated VNC access exposed on all interfaces

CVSSv3 Score: 7.7 An Exposure of Resource to Wrong Sphere vulnerability [CWE-668] in FortiSandbox may allow an unauthenticated attacker to access the VNC server of VMs performing scanning via network requests. Revised...

Fortinet PSIRT ikon Fortinet PSIRT
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-56155 – Microsoft Active Directory Federation Services

Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally. | Åtgärd: Apply mitigations in...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-56164 – Microsoft SharePoint Server

Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network. | Åtgärd: Apply mitigations in accordance with...

CISA KEV-katalog ikon CISA KEV-katalog
1 fler källor
CISA KEV-katalog CVE-2026-45659 – Microsoft SharePoint Server 2026-07-01 02:00
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-15409 – SonicWall SMA1000 Appliances

SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location. | Åtgärd:...

CISA KEV-katalog ikon CISA KEV-katalog
1 fler källor
CISA KEV-katalog CVE-2026-15410 – SonicWall SMA1000 Appliances 2026-07-14 02:00
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2008-4128 – Cisco IOS

Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain...

CISA KEV-katalog ikon CISA KEV-katalog
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-61465 — LOW — CVSS 3.3

ImageMagick before 7.1.2-26 and 6.9.13-51 is missing a check for the allowed memory allocation limit in matrix-backed operations such as -canny. An attacker can supply a crafted image that causes ImageMagick to...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
1 fler källor
NVD (National Vulnerability Database) CVE-2026-56372 — LOW — CVSS 3.3 2026-07-11 16:16
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-61454 — MEDIUM — CVSS 5.3

The Grav Admin2 plugin (getgrav/grav-plugin-admin2) before 2.0.4 embeds a global JavaScript variable window.__GRAV_CONFIG__ in the Admin2 SPA bootstrap page at /grav/admin (and its subroutes). This object is returned...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
1 fler källor
NVD (National Vulnerability Database) CVE-2026-60088 — MEDIUM — CVSS 5.5 2026-07-11 16:16
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-61448

Parse Server is affected by a stored cross-site scripting (XSS) vulnerability in versions >= 9.0.0, < 9.10.0-alpha.2 and <= 8.6.83. When an uploaded file's extension is not recognized by the mime package, Parse Server...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-61447 — CRITICAL — CVSS 10.0

PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement....

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
1 fler källor
NVD (National Vulnerability Database) CVE-2026-61445 — CRITICAL — CVSS 9.9 2026-07-11 16:16
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-61442 — HIGH — CVSS 7.1

PraisonAI Platform (praisonai-platform) before 0.1.9 fails to enforce owner/admin authorization on the PATCH routes for projects, issues, and agents, which only require workspace-member role. A workspace member can...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
1 fler källor
NVD (National Vulnerability Database) CVE-2026-61439 — HIGH — CVSS 7.5 2026-07-11 16:16
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-61429 — HIGH — CVSS 8.5

PraisonAI versions before 1.6.78 contain a server-side request forgery vulnerability in the Crawl4AI/Chromium backend that allows attackers to bypass SSRF validation by exploiting DNS rebinding and HTTP redirects....

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
1 fler källor
NVD (National Vulnerability Database) CVE-2026-61428 — HIGH — CVSS 7.3 2026-07-11 16:16
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-61426 — HIGH — CVSS 8.6

PraisonAI before 1.7.3 contains an insecure default configuration that binds to all interfaces with no API key requirement and wildcard CORS. Unauthenticated attackers can call GET /api/agents to read agent...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
1 fler källor
NVD (National Vulnerability Database) CVE-2026-56303 — HIGH — CVSS 7.5 2026-07-11 16:16
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-60090 — CRITICAL — CVSS 9.8

PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and Cassandra knowledge-store create_collection() backends. Although schema, keyspace, and collection-name identifiers...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
1 fler källor
NVD (National Vulnerability Database) CVE-2026-57827 — CRITICAL — CVSS 9.8 2026-07-11 12:16
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-56763 — MEDIUM — CVSS 4.8

Hono before 4.12.7 allows __proto__ key in parseBody with dot option enabled, permitting specially crafted form field names to create objects with __proto__ properties. When parsed results are merged into regular...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
1 fler källor
NVD (National Vulnerability Database) CVE-2026-56296 — MEDIUM — CVSS 5.3 2026-07-11 16:16
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-56240 — MEDIUM — CVSS 4.3

Capgo before 12.128.12 contains a billing authorization bypass vulnerability in the plan_valid calculation that allows organizations with exhausted or expired usage credit grants to bypass billing gates. Attackers can...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-57828 — HIGH — CVSS 8.8

The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE.

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
1 fler källor
NVD (National Vulnerability Database) CVE-2026-1359 — HIGH — CVSS 8.8 2026-07-11 11:16
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-56291 – Balbooa Forms

Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE. |...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-48939 – iCagenda iCagenda

iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution. |...

CISA KEV-katalog ikon CISA KEV-katalog
1 fler källor
Palo Alto Networks Advisories CVE-2026-0281 PAN-OS: Information Disclosure Vulnerability in Management Web Interface (Severity: LOW) 2026-07-08 18:00
1 fler källor
Palo Alto Networks Advisories CVE-2026-0283 PAN-OS: Authentication Bypass Vulnerability in Large Scale VPN (LSVPN) (Severity: MEDIUM) 2026-07-08 18:00
1 fler källor
Palo Alto Networks Advisories CVE-2026-0269 PAN-OS: Denial of Service (DoS) in Tunnel Traffic Processing (Severity: MEDIUM) 2026-06-10 18:00
1 fler källor
Palo Alto Networks Advisories CVE-2026-0273 PAN-OS: Authenticated Admin Command Injection Vulnerability via CLI or Web UI (Severity: MEDIUM) 2026-06-11 03:00
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-48908 – JoomShaper SP Page Builder

JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-55255 – Langflow Langflow

Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-56290 – Joomlack Page Builder

Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload. | Åtgärd: Apply mitigations in accordance with vendor...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-48282 – Adobe ColdFusion

Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user. | Åtgärd: Apply mitigations in accordance with vendor instructions, ensuring...

CISA KEV-katalog ikon CISA KEV-katalog
Cisco PSIRT ikon
Cisco PSIRT
Cisco Catalyst Center Arbitrary File Read Vulnerability

A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted container. This vulnerability is due to insufficient validation of user-supplied...

Cisco PSIRT ikon Cisco PSIRT
1 fler källor
Cisco PSIRT Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability 2026-06-16 00:00
Cisco PSIRT ikon
Cisco PSIRT
ClamAV Vulnerabilities Affecting Cisco Products: July 2026

Multiple vulnerabilities in ClamAV could allow a remote attacker to cause a denial of service (DoS) condition, interrupting scanning operations. For more information about these vulnerabilities, see the Details...

Cisco PSIRT ikon Cisco PSIRT
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-48558 – SimpleHelp SimpleHelp

SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their...

CISA KEV-katalog ikon CISA KEV-katalog
CERT-SE ikon
CERT-SE
CERT-SE:s veckobrev v.26

Fortsätt att få våra utskick - För att ytterligare stärka Sveriges motståndskraft inom cybersäkerhet blir CERT-SE en del av Nationellt cybersäkerhetscenter den 1 juli 2026. Det innebär att vi måste inhämta nytt...

CERT-SE ikon CERT-SE
1 fler källor
CERT-SE CERT-SE:s veckobrev v.25 2026-06-18 15:00
CERT-SE CERT-SE:s veckobrev v.24 2026-06-12 13:15
CERT-SE CERT-SE:s veckobrev v.23 2026-06-05 14:50
CERT-SE CERT-SE:s veckobrev v.22 2026-05-29 14:49
CERT-SE CERT-SE:s veckobrev v.21 2026-05-22 14:15
CERT-SE CERT-SE:s veckobrev v.20 2026-05-15 13:15
Cisco PSIRT ikon
Cisco PSIRT
Cisco Finesse Remote File Inclusion Vulnerability

A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to load arbitrary files from remote locations into an active user session on an affected device, possibly leading to browser-based...

Cisco PSIRT ikon Cisco PSIRT
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-12569 – PTC Windchill and FlexPLM

PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network. | Åtgärd: Apply...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-20230 – Cisco Unified Communications Manager

Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an...

CISA KEV-katalog ikon CISA KEV-katalog
Cisco PSIRT ikon
Cisco PSIRT
Cisco Umbrella Virtual Appliance Privilege Escalation Vulnerability

A vulnerability in the vmadmin CLI of Cisco Umbrella Virtual Appliance could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient validation of...

Cisco PSIRT ikon Cisco PSIRT
Cisco PSIRT ikon
Cisco PSIRT
Cisco Webex App Open Redirect Vulnerability

A vulnerability in the browser-based version of Cisco Webex App could have allowed an unauthenticated, remote attacker to redirect users to a malicious webpage. Cisco has addressed this vulnerability in the Cisco...

Cisco PSIRT ikon Cisco PSIRT
1 fler källor
Cisco PSIRT Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability 2026-06-16 19:39
CERT-SE ikon
CERT-SE
Fortsätt att få våra utskick

CERT-SE blir den 1 juli 2026 en del av Nationellt cybersäkerhetscenter som en del i arbetet med att ytterligare stärka Sveriges motståndskraft inom cybersäkerhet. Du kan läsa mer om detta här:...

CERT-SE ikon CERT-SE
1 fler källor
CERT-SE Patchtisdag maj 2026 – samlad information om månadens säkerhetsuppdateringar 2026-05-12 10:32
Fortinet PSIRT ikon
Fortinet PSIRT
Improper access control in API endpoints

CVSSv3 Score: 6.2 An improper access control vulnerability [CWE-284] in FortiPortal API endpoints may allow a remote privileged attacker with organization user role to obtain sensitive network configuration data via...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Restricted CLI escape using Lua

CVSSv3 Score: 6.0 An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] in FortiOS and FortiProxy may allow an authenticated admin to execute lua scripts via crafted CLI commands....

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Second-Order OS Command Injection via JSON Input on start vnc feature

CVSSv3 Score: 9.1 An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to...

Fortinet PSIRT ikon Fortinet PSIRT
Cisco PSIRT ikon
Cisco PSIRT
Cisco Webex Meetings Cross-Site Scripting Vulnerability

A vulnerability in the web-based user interface of Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. Cisco has addressed this vulnerability in...

Cisco PSIRT ikon Cisco PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Linux Kernel vulnerability Dirty Frag

CVSSv3 Score: 7.9 Linux kernel is impacted by CVE-2026-43284 and CVE-2026-43500 which chained together create the Dirty Frag vulnerability.CVE-2026-43284In the Linux kernel, the following vulnerability has been...

Fortinet PSIRT ikon Fortinet PSIRT
CERT-SE ikon
CERT-SE
Kritisk sårbarhet i PAN-OS

Palo Alto Networks har publicerat information om en kritisk sårbarhet i PAN-OS. Sårbarheten, CVE-2026-0300, har fått en CVSS-klassning på 9.3 och påverkar USER-ID Autentication Portal. [1]

CERT-SE ikon CERT-SE
CERT-SE ikon
CERT-SE
Åtgärder för att säkra upp Microsoft 365-miljöer

Vid uppsättning av en klientorganisation (engelska: tenant) i Microsofts molnmiljö är flexibiliteten hög och nya funktioner läggs till kontinuerligt. CERT-SE uppmanar organisationer att regelbundet se över aktiverade,...

CERT-SE ikon CERT-SE
Ladda fler
Visar 120 av 255 artiklar