Nyhetsnavet

Samlar nyheter från utvalda källor. Logga in för att spara urval och skapa profiler.

Uppdaterad 2026-10-05 22:09 Nästa om --:-- Försenad
14 av 14 källor 10 per källa

IT-säkerhet och cybersäkerhet i realtid — CVE-varningar, sårbarhetsrapporter, incidenter och hotinformation från NVD, CISA, BleepingComputer och fler SOC-källor.

Snabbfilter
Toppnyheter Säkerhet
CERT-SE 3 d
CERT-SE

Antar du vår utmaning? / Do you accept our challenge?

CERT-SE presenterar vår årliga utmaning (CTF) som sker under cybersäkerhetsmånaden [1, 2]. Utmaningen vänder sig till alla med it-säkerhetsintresse oavsett kunskapsnivå.

2026-10-02 12:45 3 d
Säkerhet 30 artiklar
CERT-SE ikon
CERT-SE
CERT-SE:s veckobrev v.40

Oktober är cybersäkerhetsmånaden och vi vill passa på att slå ett slag för de kunskapshöjande aktiviteter som erbjuds genom NCSC:s och polisens cybersäkerhetskampanj “Tänk Säkert”.

CERT-SE ikon CERT-SE
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-102490 – Zammad GmbH Zammad

Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489. | Åtgärd: Apply...

CISA KEV-katalog ikon CISA KEV-katalog
1 fler källor
CISA KEV-katalog CVE-2026-102489 – Zammad GmbH Zammad 2026-10-02 02:00
CISA Alerts ikon
CISA Alerts
Johnson Controls EasyIO Neo Series EC and CW Controllers

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker tointercept and read sensitive information, including credentials andsession data. The following versions of Johnson Controls...

CISA Alerts ikon CISA Alerts
1 fler källor
CISA Alerts Johnson Controls EasyIO Neo Series EC and CW Controllers 2026-10-01 14:00
CISA Alerts ikon
CISA Alerts
Meari IoT Cloud Platform OpenAPI Service

View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to manipulate device configurations, trigger unauthorized behaviors, and access sensitive information such as device...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
Monta monta.app

View CSAF Summary Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
Armatura LLC Armatura One

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to the database, execute arbitrary code on the host with the highest level of privilege, or gain...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
ABB Protection and Control IED Manager PCM600

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to escalate privileges or overwrite files. The following versions of ABB Protection and Control IED Manager PCM600 are...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-104286 Fortinet FortiMail Path Traversal Vulnerability This type of...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
CISA Malcolm

View CSAF Summary The following versions of CISA Malcolm are affected: Malcolm CVSS Vendor Equipment Vulnerabilities v3 8.8 CISA CISA Malcolm Improper Neutralization of Input During Web Page Generation ('Cross-site...

CISA Alerts ikon CISA Alerts
Fortinet PSIRT ikon
Fortinet PSIRT
Improper limitation of a pathname to a restricted directory

CVSSv3 Score: 9.8 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] and Improper Neutralization of NULL Byte or NULL Character [CWE-158] vulnerability may allow an...

Fortinet PSIRT ikon Fortinet PSIRT
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-104286 – Fortinet FortiMail

Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via...

CISA KEV-katalog ikon CISA KEV-katalog
1 fler källor
Microsoft MSRC CVE-2026-70562 Windows Audio Service Elevation of Privilege Vulnerability 2026-09-30 16:00
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-76504 – Cisco Catalyst SD-WAN Manager

Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-86950 – Apple Multiple Products

Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution. | Åtgärd: Apply mitigations in accordance with vendor instructions, ensuring...

CISA KEV-katalog ikon CISA KEV-katalog
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-96760 — CRITICAL — CVSS 9.8

Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability. The JsonWebSignature.deserialize_json() method accepts a JSON Serialization JWS object and returns the payload as successfully...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-93355 — HIGH — CVSS 8.1

LiteLLM contains a weak authentication vulnerability that allows an attacker holding a valid JWT from the configured identity provider to authenticate as any existing user by exploiting an email-based fallback lookup...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
1 fler källor
NVD (National Vulnerability Database) CVE-2026-87741 — HIGH — CVSS 8.8 2026-09-28 22:17
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-86950 — HIGH — CVSS 8.8

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
1 fler källor
NVD (National Vulnerability Database) CVE-2026-102004 — HIGH — CVSS 7.8 2026-09-28 22:17
Ladda fler
Visar 90 av 140 artiklar