Nyhetsnavet

Samlar nyheter från utvalda källor. Logga in för att spara urval och skapa profiler.

Uppdaterad 2026-10-06 10:28 Nästa om --:-- Försenad
14 av 14 källor 10 per källa

IT-säkerhet och cybersäkerhet i realtid — CVE-varningar, sårbarhetsrapporter, incidenter och hotinformation från NVD, CISA, BleepingComputer och fler SOC-källor.

Snabbfilter
Toppnyheter Säkerhet
CERT-SE 3 d
CERT-SE

Antar du vår utmaning? / Do you accept our challenge?

CERT-SE presenterar vår årliga utmaning (CTF) som sker under cybersäkerhetsmånaden [1, 2]. Utmaningen vänder sig till alla med it-säkerhetsintresse oavsett kunskapsnivå.

2026-10-02 12:45 3 d
Säkerhet 27 artiklar
CERT-SE ikon
CERT-SE
Kritisk sårbarhet i FortiMail

Fortinet har publicerat information om en kritisk sårbarhet i FortiMail. Sårbarheten, CVE-2026-104286, har fått en CVSS-klassning på 9.8 och påverkar FortiMail managements gränssnitt. Ett framgångsrikt utnyttjande kan...

CERT-SE ikon CERT-SE
CISA Alerts ikon
CISA Alerts
Johnson Controls EasyIO Neo Series EC and CW Controllers

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker tointercept and read sensitive information, including credentials andsession data. The following versions of Johnson Controls...

CISA Alerts ikon CISA Alerts
1 fler källor
CISA Alerts Johnson Controls EasyIO Neo Series EC and CW Controllers 2026-10-01 14:00
CISA Alerts ikon
CISA Alerts
Meari IoT Cloud Platform OpenAPI Service

View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to manipulate device configurations, trigger unauthorized behaviors, and access sensitive information such as device...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
Monta monta.app

View CSAF Summary Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
Armatura LLC Armatura One

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to the database, execute arbitrary code on the host with the highest level of privilege, or gain...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
ABB Protection and Control IED Manager PCM600

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to escalate privileges or overwrite files. The following versions of ABB Protection and Control IED Manager PCM600 are...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
CISA Malcolm

View CSAF Summary The following versions of CISA Malcolm are affected: Malcolm CVSS Vendor Equipment Vulnerabilities v3 8.8 CISA CISA Malcolm Improper Neutralization of Input During Web Page Generation ('Cross-site...

CISA Alerts ikon CISA Alerts
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-102473 — MEDIUM — CVSS 5.5

A flaw was found in dash. When built without libc fnmatch, the internal pmatch() matcher implements * by unbounded recursion over candidate positions. A local user who can plant filenames, or otherwise feed that...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
1 fler källor
NVD (National Vulnerability Database) CVE-2026-91085 — MEDIUM — CVSS 6.3 2026-09-29 11:17
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-92142 — HIGH — CVSS 8.8

Apache Karaf exposes a JMX MBeanServer guarded by KarafMBeanServerGuard, which enforces role-based access control (RBAC) on MBean operations invoked over the remote JMX connector (RMI registry/server, enabled by...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-91012 — CRITICAL — CVSS 9.8

org.apache.karaf.config.core.impl.ConfigRepositoryImpl#update(pid, properties), which backs the "config" MBean and the config:* shell commands, derives the file it writes a configuration to from caller-supplied input...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
CERT-SE ikon
CERT-SE
CERT-SE:s veckobrev v.38

Den här veckan innehåller CERT-SE:s veckobrev bland annat information om att NCSC och AI Sweden med flera bjuder in till seminarium den 22 oktober på temat “Modern sårbarhetshantering i en AI-driven hotmiljö”. Läs mer...

CERT-SE ikon CERT-SE
CERT-SE ikon
CERT-SE
Kritisk sårbarhet i Cisco Secure Email Gateway utnyttjas aktivt

Cisco har publicerat information om en kritisk SQL injection-sårbarhet i Cisco Secure Email Gateway som utnyttjas aktivt. Sårbarheten (CVE-2026-76461) har fått CVSS-klassificering 9.8 (CVSS v.3.1). [1] CISA har lagt...

CERT-SE ikon CERT-SE
CERT-SE ikon
CERT-SE
GitLab rättar kritiska sårbarheter

GitLab har publicerat säkerhetsuppdateringar för flera sårbarheter i GitLab Community Edition (CE) och Enterprise Edition (EE). [1] Två av dessa sårbarheter, CVE-2026-85706 och CVE-2026-87719, klassas som kritiska.

CERT-SE ikon CERT-SE