Nyhetsnavet

Samlar nyheter från utvalda källor. Logga in för att spara urval och skapa profiler.

Uppdaterad 2026-10-05 23:12 Nästa om --:-- Försenad
14 av 14 källor 10 per källa

IT-säkerhet och cybersäkerhet i realtid — CVE-varningar, sårbarhetsrapporter, incidenter och hotinformation från NVD, CISA, BleepingComputer och fler SOC-källor.

Snabbfilter
Toppnyheter Säkerhet
Säkerhet 30 artiklar
GitHub Security Advisories ikon
GitHub Security Advisories
CVE-2026-103918: @orpc/zod: Prototype injection in smart coercion

## Summary `ZodSmartCoercionPlugin` and `experimental_ZodSmartCoercionPlugin` mishandle object keys that name `Object.prototype` members. Both coerce request input before validation, so any client that can reach a...

GitHub Security Advisories ikon GitHub Security Advisories
CISA Alerts ikon
CISA Alerts
Johnson Controls EasyIO Neo Series EC and CW Controllers

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker tointercept and read sensitive information, including credentials andsession data. The following versions of Johnson Controls...

CISA Alerts ikon CISA Alerts
1 fler källor
CISA Alerts Johnson Controls EasyIO Neo Series EC and CW Controllers 2026-10-01 14:00
CISA Alerts ikon
CISA Alerts
Monta monta.app

View CSAF Summary Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
Armatura LLC Armatura One

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to the database, execute arbitrary code on the host with the highest level of privilege, or gain...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
ABB Protection and Control IED Manager PCM600

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to escalate privileges or overwrite files. The following versions of ABB Protection and Control IED Manager PCM600 are...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
CISA Malcolm

View CSAF Summary The following versions of CISA Malcolm are affected: Malcolm CVSS Vendor Equipment Vulnerabilities v3 8.8 CISA CISA Malcolm Improper Neutralization of Input During Web Page Generation ('Cross-site...

CISA Alerts ikon CISA Alerts
Fortinet PSIRT ikon
Fortinet PSIRT
Improper limitation of a pathname to a restricted directory

CVSSv3 Score: 9.8 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] and Improper Neutralization of NULL Byte or NULL Character [CWE-158] vulnerability may allow an...

Fortinet PSIRT ikon Fortinet PSIRT
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-104286 – Fortinet FortiMail

Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-76504 – Cisco Catalyst SD-WAN Manager

Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI...

CISA KEV-katalog ikon CISA KEV-katalog
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-101918 — MEDIUM — CVSS 5.3

PyJWT is a Python implementation of JSON Web Token standards. From 2.0.0a1 until 2.15.0, PyJWT PyJWKClient.get_signing_key_from_jwt is affected because payload parser catches ValueError but not RecursionError. This...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
1 fler källor
NVD (National Vulnerability Database) CVE-2026-101917 — MEDIUM — CVSS 5.3 2026-09-28 23:17
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-88771 – Citrix NetScaler

Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands. | Åtgärd: Apply mitigations in accordance with...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-65660 – Microsoft SharePoint

Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network. | Åtgärd: Apply mitigations in accordance with vendor instructions, ensuring...

CISA KEV-katalog ikon CISA KEV-katalog
Cisco PSIRT ikon
Cisco PSIRT
Cisco Identity Services Engine Authentication Bypass Vulnerabilities

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to access or manipulate data, obtain sensitive information, or cause a...

Cisco PSIRT ikon Cisco PSIRT
1 fler källor
Cisco PSIRT Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Logging Denial of Service Vulnerability 2026-09-18 17:50
Cisco PSIRT Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software for Secure Firewall 3100 and 4200 Series DTLS Denial of Service Vulnerability 2026-09-18 17:50
Cisco PSIRT Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IKEv2 Certificate Authentication Denial of Service Vulnerability 2026-09-18 17:50
Ladda fler
Visar 30 av 41 artiklar