Nyhetsnavet

Samlar nyheter från utvalda källor. Logga in för att spara urval och skapa profiler.

Uppdaterad 2026-07-29 02:19 Nästa om --:-- Försenad
14 av 14 källor 20 per källa

IT-säkerhet och cybersäkerhet i realtid — CVE-varningar, sårbarhetsrapporter, incidenter och hotinformation från NVD, CISA, BleepingComputer och fler SOC-källor.

Snabbfilter
Toppnyheter Säkerhet
CISA Alerts 12 h
CISA Alerts

igloohome Smart Lock Mobile Application

View CSAF Summary Successful exploitation of this vulnerability could allow an unauthorized actor to access functions or backend services. The following versions of igloohome Smart Lock Mobile Application are...

2026-07-28 14:00 12 h
Säkerhet 93 artiklar
GitHub Security Advisories ikon
GitHub Security Advisories
CVE-2026-66064: goshs has ACL Bypass & Path Traversal

## Summary `sendFile` derives the served filename from the raw request path while opening the file from the cleaned path, so appending a trailing slash empties the derived name and defeats both the never-serve rule...

GitHub Security Advisories ikon GitHub Security Advisories
1 fler källor
GitHub Security Advisories CVE-2026-66063: goshs has a Path Traversal issue 2026-07-29 00:08
SecurityWeek Vulnerabilities ikon
SecurityWeek Vulnerabilities
Cyera Acquiring Oasis Security in $1 Billion Deal

Oasis Security recently raised $120 million in Series B funding for its agentic access management platform. The post Cyera Acquiring Oasis Security in $1 Billion Deal appeared first on SecurityWeek.

SecurityWeek Vulnerabilities ikon SecurityWeek Vulnerabilities
SecurityWeek Vulnerabilities ikon
SecurityWeek Vulnerabilities
Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe

Apple announced that dozens of vulnerabilities have been patched in each of its operating systems. The post Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe appeared first on SecurityWeek.

SecurityWeek Vulnerabilities ikon SecurityWeek Vulnerabilities
BleepingComputer ikon
BleepingComputer
Is Your SSO Protected Against Modern Credential Attacks?

A compromised SSO login can provide attackers with access to multiple enterprise applications and services. Specops Software explains how stronger passwords, phishing-resistant MFA, and identity hardening help secure...

BleepingComputer ikon BleepingComputer
SecurityWeek Vulnerabilities ikon
SecurityWeek Vulnerabilities
OT Security Startup Frenos Raises $1.52 Million

The company will use the fresh investment to grow its customer success and AI R&D teams. The post OT Security Startup Frenos Raises $1.52 Million appeared first on SecurityWeek.

SecurityWeek Vulnerabilities ikon SecurityWeek Vulnerabilities
CISA Alerts ikon
CISA Alerts
igloohome Smart Lock Mobile Application

View CSAF Summary Successful exploitation of this vulnerability could allow an unauthorized actor to access functions or backend services. The following versions of igloohome Smart Lock Mobile Application are...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP

View CSAF Summary Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant). Siemens is...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
Siemens Mendix Runtime

View CSAF Summary Mendix documentation for access rules does not adequately describe the special behavior of the System.User entity, leaving developers without sufficient guidance to configure access rules securely....

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
ABB KNX Update Tool

View CSAF Summary ABB has been contacted by a researcher who identified a vulnerability in one of its products. ABB has been contacted by a researcher who identified a vulnerability in one of its products. The...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
MikroTik RouterOS and Cloud Hosted Router

View CSAF Summary Successful exploitation of this vulnerability could allow attackers to rapidly guess passwords and gain unauthorized system access. The following versions of MikroTik RouterOS and Cloud Hosted Router...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
CI Fortify – Advice for isolating vital systems

CI Fortify – Advice for isolating vital systems CISA and the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), in collaboration with the Federal Bureau of Investigation and international...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
Siemens SIMATIC S7-PLCSIM Advanced

View CSAF Summary SIMATIC S7-PLCSIM Advanced contains a vulnerability that could allow an attacker to cause a denial of service condition. Siemens is preparing fix versions and recommends specific countermeasures for...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
Siemens Desigo CC

View CSAF Summary OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution. Siemens has released...

CISA Alerts ikon CISA Alerts
SecurityWeek Vulnerabilities ikon
SecurityWeek Vulnerabilities
Microsoft Unveils MAI-Cyber-1-Flash, Its First Cybersecurity AI Model

The company claims MAI-Cyber-1-Flash tops Anthropic’s Mythos and OpenAI’s GPT-5.6 Sol in CyberGym testing. The post Microsoft Unveils MAI-Cyber-1-Flash, Its First Cybersecurity AI Model appeared first on SecurityWeek.

SecurityWeek Vulnerabilities ikon SecurityWeek Vulnerabilities
SecurityWeek Vulnerabilities ikon
SecurityWeek Vulnerabilities
Act Security Emerges from Stealth to Fight the Patch Problem

Act Security tackles the spiraling patch problem caused by AI’s ability to find new vulnerabilities in existing cloud environments. The post Act Security Emerges from Stealth to Fight the Patch Problem appeared first...

SecurityWeek Vulnerabilities ikon SecurityWeek Vulnerabilities
SecurityWeek Vulnerabilities ikon
SecurityWeek Vulnerabilities
Hush Security Raises $30 Million for AI Agent Governance

The startup will invest in expanding engineering and sales teams, accelerating ecosystem support, and expanding corporate partnerships. The post Hush Security Raises $30 Million for AI Agent Governance appeared first...

SecurityWeek Vulnerabilities ikon SecurityWeek Vulnerabilities
SecurityWeek Vulnerabilities ikon
SecurityWeek Vulnerabilities
Google Adopts New Threat Actor Naming System

The new two-word naming convention uses a memorable term utilized in public reporting and a cluster-categorization word. The post Google Adopts New Threat Actor Naming System appeared first on SecurityWeek.

SecurityWeek Vulnerabilities ikon SecurityWeek Vulnerabilities
SecurityWeek Vulnerabilities ikon
SecurityWeek Vulnerabilities
Unpatched Fastjson Vulnerability Exploited in Attacks

The critical remote code execution bug can be exploited without authentication, under the library’s stock default configurations. The post Unpatched Fastjson Vulnerability Exploited in Attacks appeared first on...

SecurityWeek Vulnerabilities ikon SecurityWeek Vulnerabilities
SecurityWeek Vulnerabilities ikon
SecurityWeek Vulnerabilities
Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day

Impacting on-premises deployments, the OS command injection allows attackers to access privileged internal functionality. The post Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day appeared...

SecurityWeek Vulnerabilities ikon SecurityWeek Vulnerabilities
CISA Alerts ikon
CISA Alerts
CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-68686 Fortinet FortiOS Exposure of Sensitive Information to an...

CISA Alerts ikon CISA Alerts
1 fler källor
CISA Alerts CISA Adds Two Known Exploited Vulnerabilities to Catalog 2026-07-22 14:00
CISA Alerts CISA Adds Four Known Exploited Vulnerabilities to Catalog 2026-07-21 14:00
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2025-68686 – Fortinet FortiOS

Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-16812 – Arista VeloCloud Orchestrator

Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may...

CISA KEV-katalog ikon CISA KEV-katalog
CISA Alerts ikon
CISA Alerts
Johnson Controls C-CURE 9000 and Victor application server

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution. The following versions of Johnson Controls C-CURE 9000 and Victor...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
Rockwell Automation ThinManager

View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to restricted system directories outside of the application's intended directory. The...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
MZ Automation libIEC61850

View CSAF Summary Successful exploitation of these vulnerabilities could allow an unauthenticated network-adjacent attacker to crash critical IEC 61850 services or execute arbitrary code, disrupting or compromising...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
Johnson Controls XAAP Android

View CSAF Summary Successful exploitation of this vulnerability could result in an attacker obtaining confidential information from the device. The following versions of Johnson Controls XAAP Android are affected:...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
Weintek cMT3092X

View CSAF Summary Successful exploitation of these vulnerabilities could allow a non-privileged user to escalate privileges or view the credentials of other users. The following versions of Weintek cMT3092X are...

CISA Alerts ikon CISA Alerts
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-16551

Denial-of-Service in Thinkst Applied Research OpenCanary (MongoDB module) allows Excessive Allocation. This issue affects OpenCanary 0.9.8 only.

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-16544 — MEDIUM — CVSS 6.5

A flaw was found in AWX. The websocket event consumer performs RBAC authorization checks only for event groups that are mapped in the consumer_access() function (job_events, workflow_events, ad_hoc_command_events)....

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
1 fler källor
NVD (National Vulnerability Database) CVE-2026-15787 — MEDIUM — CVSS 6.4 2026-07-22 11:16
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-14322 — MEDIUM — CVSS 5.3

The Timetics WordPress plugin before 1.0.57 does not enforce a pending or unpaid status for new bookings created through a payment method other than its recognised gateways, allowing unauthenticated users to create...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-56844

A vulnerability in the Veeam Updater component of the Veeam Software Appliance that could allow a local user to elevate their privileges and gain root-level access to the underlying operating system.

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-16232 – Check Point SmartConsole

Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-50522 – Microsoft SharePoint

Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network. | Åtgärd: Apply mitigations in accordance with vendor...

CISA KEV-katalog ikon CISA KEV-katalog
1 fler källor
CISA KEV-katalog CVE-2026-58644 – Microsoft SharePoint 2026-07-16 02:00
CISA Alerts ikon
CISA Alerts
Siemens SIDIS Secured SmartPlug

View CSAF Summary SIDIS Secured SmartPlug before V7.26.0310 is affected by multiple vulnerabilities in the components OpenSSL, OpenSSH, and several other packages as described below. Siemens has released a new version...

CISA Alerts ikon CISA Alerts
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-60137 – WordPress Core

WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain...

CISA KEV-katalog ikon CISA KEV-katalog
1 fler källor
CISA KEV-katalog CVE-2026-63030 – WordPress Core 2026-07-21 02:00
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-0770 – Langflow Langflow

Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations. | Åtgärd: Apply mitigations in accordance...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2021-27137 – DD-WRT DD-WRT

DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability. | Åtgärd: Apply...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-25089 – Fortinet FortiSandbox

Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP...

CISA KEV-katalog ikon CISA KEV-katalog
1 fler källor
CISA KEV-katalog CVE-2026-39808 – Fortinet FortiSandbox 2026-07-16 02:00
Cisco PSIRT ikon
Cisco PSIRT
Cisco RoomOS Security Hardening Release: July 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening...

Cisco PSIRT ikon Cisco PSIRT
Cisco PSIRT ikon
Cisco PSIRT
Cisco Identity Services Engine Path Traversal Vulnerability

A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating...

Cisco PSIRT ikon Cisco PSIRT
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-46817 – Oracle E-Business Suite

Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-15409 – SonicWall SMA1000 Appliances

SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location. | Åtgärd:...

CISA KEV-katalog ikon CISA KEV-katalog
1 fler källor
CISA KEV-katalog CVE-2026-15410 – SonicWall SMA1000 Appliances 2026-07-14 02:00
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-56155 – Microsoft Active Directory Federation Services

Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally. | Åtgärd: Apply mitigations in...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-56164 – Microsoft SharePoint Server

Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network. | Åtgärd: Apply mitigations in accordance with...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2008-4128 – Cisco IOS

Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-56291 – Balbooa Forms

Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE. |...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-48939 – iCagenda iCagenda

iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution. |...

CISA KEV-katalog ikon CISA KEV-katalog
Cisco PSIRT ikon
Cisco PSIRT
Cisco Catalyst Center Arbitrary File Read Vulnerability

A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted container. This vulnerability is due to insufficient validation of user-supplied...

Cisco PSIRT ikon Cisco PSIRT
1 fler källor
Cisco PSIRT Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability 2026-06-16 00:00
Cisco PSIRT ikon
Cisco PSIRT
ClamAV Vulnerabilities Affecting Cisco Products: July 2026

Multiple vulnerabilities in ClamAV could allow a remote attacker to cause a denial of service (DoS) condition, interrupting scanning operations. For more information about these vulnerabilities, see the Details...

Cisco PSIRT ikon Cisco PSIRT
Cisco PSIRT ikon
Cisco PSIRT
Cisco Finesse Remote File Inclusion Vulnerability

A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to load arbitrary files from remote locations into an active user session on an affected device, possibly leading to browser-based...

Cisco PSIRT ikon Cisco PSIRT
Cisco PSIRT ikon
Cisco PSIRT
Cisco Webex App Open Redirect Vulnerability

A vulnerability in the browser-based version of Cisco Webex App could have allowed an unauthenticated, remote attacker to redirect users to a malicious webpage. Cisco has addressed this vulnerability in the Cisco...

Cisco PSIRT ikon Cisco PSIRT
Cisco PSIRT ikon
Cisco PSIRT
Cisco Umbrella Virtual Appliance Privilege Escalation Vulnerability

A vulnerability in the vmadmin CLI of Cisco Umbrella Virtual Appliance could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient validation of...

Cisco PSIRT ikon Cisco PSIRT
1 fler källor
Cisco PSIRT Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability 2026-06-16 19:39
Cisco PSIRT ikon
Cisco PSIRT
Cisco Webex Meetings Cross-Site Scripting Vulnerability

A vulnerability in the web-based user interface of Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. Cisco has addressed this vulnerability in...

Cisco PSIRT ikon Cisco PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Linux Kernel vulnerability Dirty Frag

CVSSv3 Score: 7.9 Linux kernel is impacted by CVE-2026-43284 and CVE-2026-43500 which chained together create the Dirty Frag vulnerability.CVE-2026-43284In the Linux kernel, the following vulnerability has been...

Fortinet PSIRT ikon Fortinet PSIRT
CERT-SE ikon
CERT-SE
CERT-SE:s veckobrev v.22

I veckans läsning finns ett urval av nyheter, analyser och rapporter inom cybersäkerhetsområdet från veckan som har gått.

CERT-SE ikon CERT-SE
1 fler källor
CERT-SE CERT-SE:s veckobrev v.21 2026-05-22 14:15