Nyhetsnavet

Samlar nyheter från utvalda källor. Logga in för att spara urval och skapa profiler.

Uppdaterad 2026-06-18 06:41 Nästa om --:-- Försenad
11 av 11 källor 10 per källa

IT-säkerhet och cybersäkerhet i realtid — CVE-varningar, sårbarhetsrapporter, incidenter och hotinformation från NVD, CISA, BleepingComputer och fler SOC-källor.

Snabbfilter
Toppnyheter Säkerhet
Linux Kernel Vulnerability copy.fail - CVE-2026-31431
Fortinet PSIRT

Linux Kernel Vulnerability copy.fail - CVE-2026-31431

CVSSv3 Score: 7.8 CVE-2026-31431In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying...

2026-05-13 09:00 35 d
Security-widgeten är dold. Visa widget
Säkerhet 70 artiklar
Cisco PSIRT ikon
Cisco PSIRT
Cisco Webex App Open Redirect Vulnerability

A vulnerability in the browser-based version of Cisco Webex App could have allowed an unauthenticated, remote attacker to redirect users to a malicious webpage. Cisco has addressed this vulnerability in the Cisco...

Cisco PSIRT ikon Cisco PSIRT
Cisco PSIRT ikon
Cisco PSIRT
Cisco Umbrella Virtual Appliance Privilege Escalation Vulnerability

A vulnerability in the vmadmin CLI of Cisco Umbrella Virtual Appliance could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient validation of...

Cisco PSIRT ikon Cisco PSIRT
The Hacker News ikon
The Hacker News
The Top 10 Attack Surface Exposures in 2026

Breaches don't always start with a zero-day. An exposed admin panel can get brute-forced, or credentials reused from a previous attack. But when a vulnerability does drop — like MongoBleed earlier this year, which let...

The Hacker News ikon The Hacker News
SecurityWeek Vulnerabilities ikon
SecurityWeek Vulnerabilities
Oracle’s Second Monthly Security Updates Deliver 245 Patches

Oracle has released its June 2026 Critical Security Patch Update to fix vulnerabilities in Communications, EBS, Enterprise Manager and other products. The post Oracle’s Second Monthly Security Updates Deliver 245...

Oracle’s Second Monthly Security Updates Deliver 245 Patches
1 fler källor
Cisco PSIRT Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability 2026-06-16 19:39
1 fler källor
Microsoft MSRC CVE-2026-50656 Microsoft Defender Elevation of Privilege Vulnerability 2026-06-16 16:00
Microsoft MSRC ikon
Microsoft MSRC
CVE-2026-54411 Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences. The comparison uses strncmp() (or strncasecmp() when PAM_ICASE_ARG is set) preceded by a length-equality check, so the time to reject a candidate depends on the index of the first differing byte and on whether the candidate's length matches the stored password, leaking the password length and individual prefix bytes. The vulnerable path is reached when the administrator configures pam_userdb with crypt=none, with an unrecognized crypt method, or without a crypt= argument, causing the module to store and compare credentials in plaintext.

Information published.

Microsoft MSRC ikon Microsoft MSRC
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-48907 – Widget Factory Joomla Content Editor

Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users. |...

CISA KEV-katalog ikon CISA KEV-katalog
Cisco PSIRT ikon
Cisco PSIRT
Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system....

Cisco PSIRT ikon Cisco PSIRT
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-54420 – LiteSpeed cPanel Plugin

LiteSpeed cPanel plugin contains a UNIX symbolic link (Symlink) following vulnerability that could allow a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS. | Åtgärd: Apply...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-20262 – Cisco Catalyst SD-WAN Manager

Cisco Catalyst SD-WAN Manager contains a directory or path traversal vulnerability that could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. |...

CISA KEV-katalog ikon CISA KEV-katalog
1 fler källor
CISA KEV-katalog CVE-2026-20245 – Cisco Catalyst SD-WAN Manager 2026-06-09 02:00
CERT-SE ikon
CERT-SE
CERT-SE:s veckobrev v.24

Fortsätt att få våra utskick - För att ytterligare stärka Sveriges motståndskraft inom cybersäkerhet blir CERT-SE en del av Nationellt cybersäkerhetscenter den 1 juli 2026. Det innebär att vi måste inhämta nytt...

CERT-SE ikon CERT-SE
CERT-SE ikon
CERT-SE
Fortsätt att få våra utskick

CERT-SE blir den 1 juli 2026 en del av Nationellt cybersäkerhetscenter som en del i arbetet med att ytterligare stärka Sveriges motståndskraft inom cybersäkerhet. Du kan läsa mer om detta här:...

CERT-SE ikon CERT-SE
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-35273 – Oracle PeopleSoft Enterprise PeopleTools

Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools. |...

CISA KEV-katalog ikon CISA KEV-katalog
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-40998 — HIGH — CVSS 8.2

Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed attacker-controlled XML with the JDK's default DocumentBuilderFactory behavior instead of Spring's...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
1 fler källor
NVD (National Vulnerability Database) CVE-2026-40994 — HIGH — CVSS 8.2 2026-06-11 09:16
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-40997 — MEDIUM — CVSS 5.3

Several Spring WS integration paths with Spring Security could surface detailed account state (for example locked or disabled user semantics) to remote SOAP clients through exception messages or callback outcomes,...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
1 fler källor
NVD (National Vulnerability Database) CVE-2026-40996 — MEDIUM — CVSS 4.8 2026-06-11 09:16
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-40995 — MEDIUM — CVSS 5.4

X509AuthenticationProvider could issue a fully authenticated X509AuthenticationToken when a presented certificate mapped to UserDetails, without applying Spring Security's standard account lifecycle checks (disabled,...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
1 fler källor
NVD (National Vulnerability Database) CVE-2026-40992 — MEDIUM — CVSS 5.0 2026-06-11 09:16
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-40987 — HIGH — CVSS 7.1

A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (outside the configured local-directory) with attacker-controlled content. Affected versions: Spring...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
1 fler källor
NVD (National Vulnerability Database) CVE-2026-10795 — HIGH — CVSS 8.1 2026-06-11 09:16
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-40986 — MEDIUM — CVSS 4.8

Spring Web Flow's JavaScript RemotingHandler renders the body of an error response as HTML even when the response is not "text/html", which can result in a scripting attack in the user's browser if the error response...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
1 fler källor
NVD (National Vulnerability Database) CVE-2026-40985 — MEDIUM — CVSS 6.4 2026-06-11 07:16
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-10520 – Ivanti Sentry

Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be...

CISA KEV-katalog ikon CISA KEV-katalog
1 fler källor
CERT-SE Patchtisdag maj 2026 – samlad information om månadens säkerhetsuppdateringar 2026-05-12 10:32
Fortinet PSIRT ikon
Fortinet PSIRT
Improper access control in API endpoints

CVSSv3 Score: 6.2 An improper access control vulnerability [CWE-284] in FortiPortal API endpoints may allow a remote privileged attacker with organization user role to obtain sensitive network configuration data via...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Restricted CLI escape using Lua

CVSSv3 Score: 6.0 An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] in FortiOS and FortiProxy may allow an authenticated admin to execute lua scripts via crafted CLI commands....

Restricted CLI escape using Lua
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-11645 – Google Chromium V8

Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-7473 – Arista Extensible Operating System

Arista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when the switch incorrectly decapsulate and forwards other unexpected tunneled packet with a destination IP...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-42271 – BerriAI LiteLLM

BerriAI LiteLLM contains a command injection vulnerability that could allow any authenticated user, including holders of low-privilege internal-user keys, to run arbitrary commands on the host. | Åtgärd: Apply...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-50751 – Check Point Security Gateway

Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN...

CISA KEV-katalog ikon CISA KEV-katalog
Cisco PSIRT ikon
Cisco PSIRT
Cisco Webex Meetings Cross-Site Scripting Vulnerability

A vulnerability in the web-based user interface of Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. Cisco has addressed this vulnerability in...

Cisco PSIRT ikon Cisco PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Linux Kernel vulnerability Dirty Frag

CVSSv3 Score: 7.9 Linux kernel is impacted by CVE-2026-43284 and CVE-2026-43500 which chained together create the Dirty Frag vulnerability.CVE-2026-43284In the Linux kernel, the following vulnerability has been...

Linux Kernel vulnerability Dirty Frag
Fortinet PSIRT ikon
Fortinet PSIRT
Linux Kernel Vulnerability copy.fail - CVE-2026-31431

CVSSv3 Score: 7.8 CVE-2026-31431In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying...

Linux Kernel Vulnerability copy.fail - CVE-2026-31431
Fortinet PSIRT ikon
Fortinet PSIRT
Arbitrary log file read in administrative interface

CVSSv3 Score: 4.0 An Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability [CWE-88] in FortiDeceptor WEB UI may allow an authenticated attacker with at least read-only admin...

Arbitrary log file read in administrative interface
Fortinet PSIRT ikon
Fortinet PSIRT
Trusted hosts bypass via SSH

CVSSv3 Score: 1.8 An Improper Privilege Management vulnerability [CWE-269] in FortiOS, FortiProxy and FortiPAM may allow an authenticated administrator to bypass the trusted host policy via crafted CLI command....

Trusted hosts bypass via SSH
Fortinet PSIRT ikon
Fortinet PSIRT
Insertion of Sensitive 2FA Information in logs and debug command

CVSSv3 Score: 2.6 An Insertion of Sensitive Information into Log File vulnerability [CWE-532] in FortiOS may allow an attacker with at least read-only privileges to retrieve sensitive 2FA-related information via...

Insertion of Sensitive 2FA Information in logs and debug command
Fortinet PSIRT ikon
Fortinet PSIRT
Information Disclosure on SSLVPN endpoint

CVSSv3 Score: 3.9 An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] in FortiOS SSL-VPN web-mode may allow an authenticated user to access full SSL-VPN settings via crafted URL....

Information Disclosure on SSLVPN endpoint