Nyhetsnavet

Samlar nyheter från utvalda källor. Logga in för att spara urval och skapa profiler.

Uppdaterad 2026-08-02 20:57 Nästa om --:-- Försenad
14 av 14 källor 20 per källa

IT-säkerhet och cybersäkerhet i realtid — CVE-varningar, sårbarhetsrapporter, incidenter och hotinformation från NVD, CISA, BleepingComputer och fler SOC-källor.

Snabbfilter
Toppnyheter Säkerhet
Full coverage Flera perspektiv på samma ämne.
Security-widgeten är dold. Visa widget
Säkerhet 120 artiklar
GitHub Security Advisories ikon
GitHub Security Advisories
CVE-2026-53573: core-geonetwork has an Open Redirect Bypass

### Summary GeoNetwork's post-login redirect handling can be bypassed to redirect users to an attacker-controlled external site, even though the code attempts to restrict redirect targets to relative, in-application...

GitHub Security Advisories ikon GitHub Security Advisories
1 fler källor
Cisco PSIRT Cisco Secure Firewall Management Center Software Static Credential Vulnerability 2026-07-31 21:49
GitHub Security Advisories ikon
GitHub Security Advisories
CVE-2026-53510: Savon::Model evaluates WSDL operation names as Ruby source

### Impact `Savon::Model` generated SOAP operation methods by interpolating operation names into Ruby source passed to `module_eval`. An attacker who can control the operation names of a WSDL, can inject Ruby code...

GitHub Security Advisories ikon GitHub Security Advisories
1 fler källor
Microsoft MSRC CVE-2026-56197 Windows Admin Center (WAC) Remote Code Execution Vulnerability 2026-07-30 16:00
1 fler källor
Microsoft MSRC CVE-2026-66803 Azure Cosmos DB Remote Code Execution Vulnerability 2026-07-30 16:00
Microsoft MSRC CVE-2026-24304 Azure Cosmos DB Remote Code Execution Vulnerability 2026-07-30 16:00
1 fler källor
Microsoft MSRC CVE-2026-47301 Configuration Manager Elevation of Privilege Vulnerability 2026-07-28 16:00
CISA Alerts ikon
CISA Alerts
Schneider Electric IGSS

View CSAF Summary Schneider Electric is aware of a vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical SCADA System) product. The [IGSS](https://igss.schneider-electric.com/) product is a...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
NASA Core Flight System (cFS) Health & Safety (HS) Application

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. The following versions of NASA Core Flight System (cFS) Health & Safety (HS) Application...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
Mitsubishi Electric CC-Link IE TSN Communication Protocol

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker with access to the same network segment to tamper with communication data in the affected product by sending specially crafted...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
MikroTik RouterOS

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to extract the router's WireGuard private key in plaintext using only low‑privilege API access, enabling full VPN impersonation...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
Toptech Systems RCU II+ and Multiload II+

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to gain full system control and misuse it to access or manipulate connected networks and resources. The following versions of...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
Johnson Controls OpenBlue Employee

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to upload malicious files, execute stored cross-site scripting attacks, or inject arbitrary HTML content. The following...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
MZ Automation GmbH libiec61850

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the device. The following versions of MZ Automation GmbH libiec61850 are affected:...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
MZ Automation lib60870

View CSAF Summary Successful exploitation of these vulnerabilities could crash the device being accessed. The following versions of MZ Automation lib60870 are affected: lib60870 2.4.0 (CVE-2026-61893, CVE-2026-63033)...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
o6 Automation open62541

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to disclose sensitive information, cause a denial of service, or potentially execute arbitrary code. The following versions of...

CISA Alerts ikon CISA Alerts
1 fler källor
Cisco PSIRT Cisco Advance Notification for Publication of July 15, 2026, Security Advisories 2026-07-15 18:01
Cisco PSIRT Cisco Advance Notification for Publication of July 1, 2026, Security Advisories 2026-07-01 18:01
CISA Alerts ikon
CISA Alerts
2026 Minimum Elements for a Software Bill of Materials (SBOM)

CISA, the National Security Agency, the Federal Bureau of Investigation, and international partners released joint guidance, 2026 Minimum Elements for a Software Bill of Materials (SBOM), that updates and replaces the...

CISA Alerts ikon CISA Alerts
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-20316 – Cisco Secure Firewall Management Center (FMC)

Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an...

CISA KEV-katalog ikon CISA KEV-katalog
Microsoft MSRC ikon
Microsoft MSRC
Chromium: CVE-2026-13037 Use after free in WebView

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Microsoft MSRC ikon Microsoft MSRC
Microsoft MSRC ikon
Microsoft MSRC
Chromium: CVE-2026-13032 Use after free in WebGL

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Microsoft MSRC ikon Microsoft MSRC
1 fler källor
Microsoft MSRC Chromium: CVE-2026-13028 Use after free in WebGL 2026-07-29 00:03
Microsoft MSRC ikon
Microsoft MSRC
Chromium: CVE-2026-13030 Uninitialized Use in GPU

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Microsoft MSRC ikon Microsoft MSRC
1 fler källor
Microsoft MSRC CVE-2026-50333 Windows Spaceport.sys Elevation of Privilege Vulnerability 2026-07-27 16:00
CISA Alerts ikon
CISA Alerts
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP

View CSAF Summary Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant). Siemens is...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
ABB KNX Update Tool

View CSAF Summary ABB has been contacted by a researcher who identified a vulnerability in one of its products. ABB has been contacted by a researcher who identified a vulnerability in one of its products. The...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
Siemens Desigo CC

View CSAF Summary OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution. Siemens has released...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
igloohome Smart Lock Mobile Application

View CSAF Summary Successful exploitation of this vulnerability could allow an unauthorized actor to access functions or backend services. The following versions of igloohome Smart Lock Mobile Application are...

CISA Alerts ikon CISA Alerts
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-14235 — HIGH — CVSS 7.5

The Download Manager WordPress plugin before 3.3.62 does not bind its temporary download token to the requesting session nor expire it promptly, making the token a long-lived, multi-use, portable bearer token, so that...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
1 fler källor
NVD (National Vulnerability Database) CVE-2026-13726 — HIGH — CVSS 7.1 2026-07-27 09:16
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-14203 — MEDIUM — CVSS 4.8

The Smart Manager WordPress plugin before 8.92.0 does not properly encode a post field before rendering it into an HTML attribute in its management grid, allowing users with the Contributor role or above to inject...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
1 fler källor
NVD (National Vulnerability Database) CVE-2026-14190 — MEDIUM — CVSS 6.1 2026-07-27 09:16
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-14189 — LOW — CVSS 3.8

The WPBot WordPress plugin before 8.5.2 does not validate administrator-configured field identifiers before using them in a SQL query, allowing users with administrator access to perform SQL injection that executes...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-13714 — CRITICAL — CVSS 9.8

The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload functionality is gated only by an API that is enabled by default and...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
1 fler källor
NVD (National Vulnerability Database) CVE-2026-13597 — CRITICAL — CVSS 9.1 2026-07-27 09:16
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-13400 — MEDIUM — CVSS 6.1

Simply Schedule Appointments is vulnerable to unauthenticated Stored Cross-Site Scripting in all versions up to and including 1.6.12.2. The root cause is a sanitization-ordering defect: the rendered notification...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
1 fler källor
NVD (National Vulnerability Database) CVE-2026-13390 — MEDIUM — CVSS 5.3 2026-07-27 09:16
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-13332 — CRITICAL — CVSS 9.1

The Masteriyo LMS WordPress plugin before 2.3.1 does not correctly verify authorization on an unauthenticated AJAX action used to clear user sessions, allowing unauthenticated attackers to terminate the active...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
1 fler källor
NVD (National Vulnerability Database) CVE-2026-12394 — CRITICAL — CVSS 9.8 2026-07-27 09:16
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-13152 — HIGH — CVSS 8.1

The Custom Fields Account Registration For Woocommerce WordPress plugin before 1.4 does not prevent its custom registration fields from writing to the user capabilities meta key on sites that use a non-default...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
1 fler källor
NVD (National Vulnerability Database) CVE-2026-12493 — HIGH — CVSS 7.5 2026-07-27 09:16
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-12982 — MEDIUM — CVSS 6.1

The Document Gallery WordPress plugin before 5.1.1 does not properly sanitise and escape user input before reflecting it back in the response of an unauthenticated AJAX action, leading to a Reflected Cross-Site...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
1 fler källor
NVD (National Vulnerability Database) CVE-2026-10082 — MEDIUM — CVSS 6.1 2026-07-27 09:16
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-12255 — HIGH — CVSS 8.1

The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration request handler when password authentication has been disabled for the targeted account, allowing an...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-15928

XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability in the error page component.

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-17501 — MEDIUM — CVSS 5.3

A flaw has been found in ggml-org llama.cpp e15efe0. This vulnerability affects the function transform of the file common/json-schema-to-grammar.cpp of the component JSON-Schema-to-GBNF Conversion. This manipulation...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
1 fler källor
NVD (National Vulnerability Database) CVE-2026-17500 — MEDIUM — CVSS 5.3 2026-07-27 03:16
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-16812 – Arista VeloCloud Orchestrator

Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-16232 – Check Point SmartConsole

Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-50522 – Microsoft SharePoint

Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network. | Åtgärd: Apply mitigations in accordance with vendor...

CISA KEV-katalog ikon CISA KEV-katalog
1 fler källor
CISA KEV-katalog CVE-2026-58644 – Microsoft SharePoint 2026-07-16 02:00
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-60137 – WordPress Core

WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain...

CISA KEV-katalog ikon CISA KEV-katalog
1 fler källor
CISA KEV-katalog CVE-2026-63030 – WordPress Core 2026-07-21 02:00
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-0770 – Langflow Langflow

Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations. | Åtgärd: Apply mitigations in accordance...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-25089 – Fortinet FortiSandbox

Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP...

CISA KEV-katalog ikon CISA KEV-katalog
1 fler källor
CISA KEV-katalog CVE-2026-39808 – Fortinet FortiSandbox 2026-07-16 02:00
Cisco PSIRT ikon
Cisco PSIRT
Cisco RoomOS Security Hardening Release: July 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening...

Cisco PSIRT ikon Cisco PSIRT
1 fler källor
CERT-SE Patchtisdag juni 2026 – samlad information om månadens säkerhetsuppdateringar 2026-06-10 14:00
CERT-SE Patchtisdag maj 2026 – samlad information om månadens säkerhetsuppdateringar 2026-05-12 10:32
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-46817 – Oracle E-Business Suite

Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-56155 – Microsoft Active Directory Federation Services

Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally. | Åtgärd: Apply mitigations in...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-56164 – Microsoft SharePoint Server

Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network. | Åtgärd: Apply mitigations in accordance with...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-15409 – SonicWall SMA1000 Appliances

SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location. | Åtgärd:...

CISA KEV-katalog ikon CISA KEV-katalog
1 fler källor
CISA KEV-katalog CVE-2026-15410 – SonicWall SMA1000 Appliances 2026-07-14 02:00
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-56291 – Balbooa Forms

Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE. |...

CISA KEV-katalog ikon CISA KEV-katalog
1 fler källor
Palo Alto Networks Advisories CVE-2026-0284 PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN) (Severity: MEDIUM) 2026-07-08 18:00
1 fler källor
Palo Alto Networks Advisories CVE-2026-0281 PAN-OS: Information Disclosure Vulnerability in Management Web Interface (Severity: LOW) 2026-07-08 18:00
1 fler källor
Palo Alto Networks Advisories CVE-2026-0273 PAN-OS: Authenticated Admin Command Injection Vulnerability via CLI or Web UI (Severity: MEDIUM) 2026-06-11 03:00
Cisco PSIRT ikon
Cisco PSIRT
ClamAV Vulnerabilities Affecting Cisco Products: July 2026

Multiple vulnerabilities in ClamAV could allow a remote attacker to cause a denial of service (DoS) condition, interrupting scanning operations. For more information about these vulnerabilities, see the Details...

Cisco PSIRT ikon Cisco PSIRT
Ladda fler
Visar 120 av 170 artiklar