CISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 7.5
WIEDZA Z SIECI
Podatności
CISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 10.0
CVE-2026-85706 · GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits API.Czytaj całość ↵Źródło — otwiera w nowej karcieCISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 9.2
CVE-2026-86060 · MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacker to change the trusted RouterOS policy mask, leading to privilege escalation.Czytaj całość ↵Źródło — otwiera w nowej karcieCISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 8.8
CVE-2026-67277 · MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
MikroTik RouterOS contains a missing authentication for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service.Czytaj całość ↵Źródło — otwiera w nowej karcieCISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 9.3
CVE-2026-19490 · Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass authentication.Czytaj całość ↵Źródło — otwiera w nowej karcieCISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 8.1
CVE-2025-25249 · Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets.Czytaj całość ↵Źródło — otwiera w nowej karcieCISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 8.8
CVE-2026-87491 · Google Chromium V8 Out of Bounds Write Vulnerability
Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.Czytaj całość ↵Źródło — otwiera w nowej karcieCISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 10.0
CVE-2026-20079 · Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.Czytaj całość ↵Źródło — otwiera w nowej karcieCISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 10.0
CVE-2026-75650 · Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code.Czytaj całość ↵Źródło — otwiera w nowej karcieCISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 7.8
CVE-2026-81963 · Microsoft Windows Link Following Vulnerability
Microsoft Windows Update Stack contains a link following vulnerability that allows a local attacker to escalate privileges locally up to SYSTEM.Czytaj całość ↵Źródło — otwiera w nowej karcieCISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 10.0
CVE-2026-86218 · N-able N-central Static Code Injection Vulnerability
N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution.Czytaj całość ↵Źródło — otwiera w nowej karcieCISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 7.8
CVE-2026-85880 · Microsoft Windows Heap-Based Buffer Overflow Vulnerability
Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally.Czytaj całość ↵Źródło — otwiera w nowej karcieCISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 8.8
CVE-2026-85046 · Google Chromium V8 Type Confusion Vulnerability
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.Czytaj całość ↵Źródło — otwiera w nowej karcieCISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 8.8
CVE-2026-59822 · BerriAI LiteLLM Improper Authentication Vulnerability
BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.Czytaj całość ↵Źródło — otwiera w nowej karcieCISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 6.5
CVE-2026-48710 · Kludex Starlette HTTP Request/Response Smuggling Vulnerability
Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the reconstructed URL’s path. This vulnerability could be chaned with CVE-2026-42271.Czytaj całość ↵Źródło — otwiera w nowej karcieCISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 10.0
CVE-2026-49869 · Kestra OSS OS Command Injection Vulnerability
Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.Czytaj całość ↵Źródło — otwiera w nowej karcieCISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 9.8
CVE-2026-82329 · JFrog Artifactory Improper Authentication Vulnerability
JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges.Czytaj całość ↵Źródło — otwiera w nowej karcieCISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 9.3
CVE-2026-9586 · Sangoma Switchvox SQL Injection Vulnerability
Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.Czytaj całość ↵Źródło — otwiera w nowej karcieCISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 10.0
CVE-2026-83548 · SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.Czytaj całość ↵Źródło — otwiera w nowej karcieCISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 7.8