Nyhetsnavet

Samlar nyheter från utvalda källor. Logga in för att spara urval och skapa profiler.

Uppdaterad 2026-03-06 23:37 Nästa om --:--
11 av 11 källor 20 per källa
Snabbfilter
Toppnyheter Säkerhet
Full coverage Flera perspektiv på samma ämne.
2 källor · 2026-02-19 12:35
CERT-SE CISA KEV-katalog
Fler källor:
Säkerhet 92 artiklar
1 fler källor
Microsoft MSRC CVE-2026-23651 Microsoft ACI Confidential Containers Elevation of Privilege Vulnerability 2026-03-06 17:00
Microsoft MSRC CVE-2026-26124 Microsoft ACI Confidential Containers Elevation of Privilege Vulnerability 2026-03-06 17:00
Microsoft MSRC CVE-2026-26122 Microsoft ACI Confidential Containers Information Disclosure Vulnerability 2026-03-06 17:00
Microsoft MSRC CVE-2026-23651 Microsoft ACI Confidential Containers Elevation of Privilege Vulnerability 2026-03-05 17:00
Microsoft MSRC CVE-2026-26124 Microsoft ACI Confidential Containers Elevation of Privilege Vulnerability 2026-03-05 17:00
Microsoft MSRC CVE-2026-26122 Microsoft ACI Confidential Containers Information Disclosure Vulnerability 2026-03-05 17:00
1 fler källor
Microsoft MSRC CVE-2026-3338 PKCS7_verify Signature Validation Bypass in AWS-LC 2026-03-06 10:38
CERT-SE ikon
CERT-SE
Kritiska sårbarheter i Cisco FMC och Cisco SCC

Cisco har publicerat information gällande två kritiska sårbarheter i Cisco Secure Firewall Management Center (FMC) och Cisco Security Cloud Control (SCC) Firewall Management. Båda sårbarheterna (CVE-2026-20079 och...

CERT-SE ikon CERT-SE
Cisco PSIRT ikon
Cisco PSIRT
Cisco Catalyst SD-WAN Vulnerabilities

Multiple vulnerabilities in Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an attacker to access an affected system, elevate privileges to root, gain access to sensitive information, and overwrite...

Cisco PSIRT ikon Cisco PSIRT
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2017-7921 – Hikvision Multiple Products

Multiple Hikvision products contain an improper authentication vulnerability that could allow a malicious user to escalate privileges on the system and gain access to sensitive information. | Åtgärd: Apply mitigations...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2021-22681 – Rockwell Multiple Products

Multiple Rockwell products contain an insufficient protected credentials vulnerability. Studio 5000 Logix Designer software may allow a key to be discovered. This key is used to verify Logix controllers are...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2023-43000 – Apple Multiple Products

Apple macOS, iOS, iPadOS, and Safari 16.6 contain a use-after-free vulnerability due to the processing of maliciously crafted web content that may lead to memory corruption. | Åtgärd: Apply mitigations per vendor...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2021-30952 – Apple Multiple Products

Apple tvOS, macOS, Safari, iPadOS and watchOS contain an integer overflow or wraparound vulnerability due to the processing of maliciously crafted web content that may lead to arbitrary code execution. | Åtgärd: Apply...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2023-41974 – Apple iOS and iPadOS

Apple iOS and iPadOS contain a use-after-free vulnerability. An app may be able to execute arbitrary code with kernel privileges. | Åtgärd: Apply mitigations per vendor instructions, follow applicable BOD 22-01...

CISA KEV-katalog ikon CISA KEV-katalog
1 fler källor
Cisco PSIRT Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software VPN Web Server Denial of Service Vulnerability 2026-03-05 01:00
Cisco PSIRT Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Authenticated Command Injection Vulnerabilities 2026-03-05 01:00
Cisco PSIRT Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IPsec Denial of Service Vulnerability 2026-03-04 17:00
1 fler källor
Cisco PSIRT Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability 2026-03-05 01:00
1 fler källor
Cisco PSIRT Multiple Cisco Products Snort 3 Visual Basic for Applications Denial of Service Vulnerabilities 2026-03-04 17:00
1 fler källor
Cisco PSIRT Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Access Control List Bypass Vulnerability 2026-03-04 17:00
1 fler källor
Cisco PSIRT Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IKEv2 Denial of Service Vulnerabilities 2026-03-04 17:00
Cisco PSIRT Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software SAML Reflected Cross-Site Scripting Vulnerability 2026-03-04 17:00
1 fler källor
Cisco PSIRT Cisco Secure Firewall Threat Defense Software SSL Decryption Policy Denial of Service Vulnerability 2026-03-04 17:00
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-22719 – Broadcom VMware Aria Operations

Broadcom VMware Aria Operations formerly known as vRealize Operations (vROps) contains a command injection vulnerability that allows an unauthenticated attacker to execute arbitrary commands, potentially leading to...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-21385 – Qualcomm Multiple Chipsets

Multiple Qualcomm chipsets contain a memory corruption vulnerability while using alignments for memory allocation. | Åtgärd: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud...

CISA KEV-katalog ikon CISA KEV-katalog
CERT-SE ikon
CERT-SE
Kritisk nolldagssårbarhet i Cisco Catalyst SD-WAN

Cisco har publicerat information om en nolldagssårbarhet (CVE-2026-20127) som påverkar i Cisco Catalyst SD-WAN Controller (tidigare vSmart) och Cisco Catalyst SD-WAN Manager (tidigare vManage). Sårbarheten är kritisk...

CERT-SE ikon CERT-SE
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2022-20775 – Cisco SD-WAN

Cisco SD-WAN CLI contains a path traversal vulnerability that could allow an authenticated local attacker to gain elevated privileges via improper access controls on commands within the application CLI. A successful...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-25108 – Soliton Systems K.K FileZen

Soliton Systems K.K FileZen contains an OS command injection vulnerability when an user logs-in to the affected product and sends a specially crafted HTTP request. | Åtgärd: Apply mitigations per vendor instructions,...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2025-49113 – Roundcube Webmail

RoundCube Webmail contains a deserialization of untrusted data vulnerability that allows remote code execution by authenticated users because the _from parameter in a URL is not validated in...

CISA KEV-katalog ikon CISA KEV-katalog
1 fler källor
CISA KEV-katalog CVE-2025-68461 – Roundcube Webmail 2026-02-20 01:00
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2021-22175 – GitLab GitLab

GitLab contains a server-side request forgery (SSRF) vulnerability when requests to the internal network for webhooks are enabled. | Åtgärd: Apply mitigations per vendor instructions, follow applicable BOD 22-01...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-2441 – Google Chromium

Google Chromium CSS contains a use-after-free vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2020-7796 – Synacor Zimbra Collaboration Suite

Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery vulnerability if WebEx zimlet installed and zimlet JSP is enabled. | Åtgärd: Apply mitigations per vendor instructions, follow applicable...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2024-7694 – TeamT5 ThreatSonar Anti-Ransomware

TeamT5 ThreatSonar Anti-Ransomware contains an unrestricted upload of file with dangerous type vulnerability. ThreatSonar Anti-Ransomware does not properly validate the content of uploaded files. Remote attackers with...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2008-0015 – Microsoft Windows

Microsoft Windows Video ActiveX Control contains a remote code execution vulnerability. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-20700 – Apple Multiple Products

Apple iOS, macOS, tvOS, watchOS, and visionOS contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow an attacker with memory write the capability to execute...

CISA KEV-katalog ikon CISA KEV-katalog
1 fler källor
Palo Alto Networks Advisories PAN-SA-2026-0001 Chromium: Monthly Vulnerability Update (January 2026) (Severity: MEDIUM) 2026-01-14 18:00
1 fler källor
CERT-SE Patchtisdag januari 2026 – samlad information om månadens säkerhetsuppdateringar 2026-01-14 14:45
Fortinet PSIRT ikon
Fortinet PSIRT
Request smuggling attack in FortiOS

CVSSv3 Score: 5.2 An HTTP request smuggling vulnerability [CWE-444] in FortiOS may allow an unauthenticated attacker to smuggle an unlogged http request through the firewall policies via a specially crafted header...

Nyhetsbild
Fortinet PSIRT ikon
Fortinet PSIRT
Arbitrary XML file write in FCConfig

CVSSv3 Score: 6.4 An Improper Link Resolution Before File Access vulnerability [CWE-59] in FortiClient Windows may allow a local low-privilege attacker to perform an arbitrary file write with elevated permissions via...

Nyhetsbild
Fortinet PSIRT ikon
Fortinet PSIRT
Missing authorization on CSV user import

CVSSv3 Score: 6.8 A missing authorization vulnerability [CWE-862] in FortiAuthenticator may allow a read-only admin to make modification to local users via a file upload to an unprotected endpoint. Revised on...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
SSL-VPN Symlink Persistence Patch Bypass

CVSSv3 Score: 5.3 An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] in FortiOS SSL-VPN may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic...

Nyhetsbild
Fortinet PSIRT ikon
Fortinet PSIRT
XSS via back button

CVSSv3 Score: 7.9 An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiSandbox may allow an unauthenticated attacker to execute commands via crafted...

Nyhetsbild
Fortinet PSIRT ikon
Fortinet PSIRT
SQLi in administrative interface

CVSSv3 Score: 9.1 An improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiClientEMS may allow an unauthenticated attacker to execute unauthorized code or...

Nyhetsbild
Fortinet PSIRT ikon
Fortinet PSIRT
OpenSSL CVE-2025-15467

CVSSv3 Score: 9.8 CVE-2025-15467Parsing CMS AuthEnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. A stack buffer overflow may lead to a crash, causing Denial of...

Nyhetsbild
CERT-SE ikon
CERT-SE
Allvarlig nolldagssårbarhet i Microsoft Office

Microsoft har publicerat information om en nolldagssårbarhet i Microsoft Office som exploateras av hotaktörer [1]. Sårbarheten (CVE-2026-21509) har fått CVSS-klassificering 7.8 (CVSS v.3.1) av Microsoft [2] och kan ge...

CERT-SE ikon CERT-SE
Fortinet PSIRT ikon
Fortinet PSIRT
Heap-based buffer overflow in cw_acd daemon

CVSSv3 Score: 7.4 A heap-based buffer overflow vulnerability [CWE-122] in FortiOS and FortiSwitchManager cw_acd daemon may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically...

Nyhetsbild
Fortinet PSIRT ikon
Fortinet PSIRT
Authenticated SQL injection in API endpoint

CVSSv3 Score: 6.8 An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] in FortiClientEMS may allow an authenticated attacker with at least read-only admin...

Nyhetsbild
Fortinet PSIRT ikon
Fortinet PSIRT
SSRF in GUI console

CVSSv3 Score: 3.4 A Server-Side Request Forgery (SSRF) vulnerability [CWE-918] in FortiSandbox may allow an authenticated attacker to proxy internal requests limited to plaintext endpoints only via crafted HTTP...

Nyhetsbild
Fortinet PSIRT ikon
Fortinet PSIRT
Unauthenticated access to local configuration

CVSSv3 Score: 9.3 An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in FortiFone Web Portal page may allow an unauthenticated attacker to obtain the device configuration via crafted...

Nyhetsbild
Fortinet PSIRT ikon
Fortinet PSIRT
Unauthenticated remote command injection

CVSSv3 Score: 9.4 An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiSIEM may allow an unauthenticated attacker to execute unauthorized code or...

Nyhetsbild
Fortinet PSIRT ikon
Fortinet PSIRT
Authenticated Heap Overflow in SSL-VPN bookmarks

CVSSv3 Score: 6.7 An Heap-based Buffer Overflow vulnerability [CWE-122] in FortiOS, FortiPAM and FortiProxy RDP bookmark connection may allow an authenticated user to execute unauthorized code via crafted requests....

Nyhetsbild
Fortinet PSIRT ikon
Fortinet PSIRT
`Host` header injection

CVSSv3 Score: 4.1 An externally controlled reference to a resource in another sphere vulnerability [CWE-610] in multiple products may allow an unauthenticated attacker to poison web caches between the device and the...

Nyhetsbild