Agenzia per la cybersicurezza nazionale
Pubblicato: 11/09/26 17:05
Ultimo aggiornamento: 11/09/26 17:05
Impatto: Critico (79.23)
Agenzia per la cybersicurezza nazionale
Pubblicato: 11/09/26 12:39
Ultimo aggiornamento: 11/09/26 12:39
Impatto: Medio (64.61)
Agenzia per la cybersicurezza nazionale
Pubblicato: 11/09/26 12:10
Ultimo aggiornamento: 11/09/26 12:10
Impatto: Medio (62.94)
Agenzia per la cybersicurezza nazionale
Pubblicato: 11/09/26 11:14
Ultimo aggiornamento: 11/09/26 11:14
Impatto: Medio (62.94)
Agenzia per la cybersicurezza nazionale
Pubblicato: 11/09/26 11:09
Ultimo aggiornamento: 11/09/26 11:09
Impatto: Medio (64.87)
Agenzia per la cybersicurezza nazionale
Pubblicato: 10/09/26 14:17
Ultimo aggiornamento: 10/09/26 14:17
Impatto: Medio (63.07)
Agenzia per la cybersicurezza nazionale
Pubblicato: 10/09/26 12:44
Ultimo aggiornamento: 10/09/26 12:44
Impatto: Medio (64.74)
Agenzia per la cybersicurezza nazionale
Pubblicato: 11/09/26 17:05
Ultimo aggiornamento: 11/09/26 17:05
Impatto: Critico (79.23)
Agenzia per la cybersicurezza nazionale
Pubblicato: 11/09/26 12:39
Ultimo aggiornamento: 11/09/26 12:39
Impatto: Medio (64.61)
Agenzia per la cybersicurezza nazionale
Pubblicato: 11/09/26 12:10
Ultimo aggiornamento: 11/09/26 12:10
Impatto: Medio (62.94)
Agenzia per la cybersicurezza nazionale
Pubblicato: 11/09/26 11:14
Ultimo aggiornamento: 11/09/26 11:14
Impatto: Medio (62.94)
Agenzia per la cybersicurezza nazionale
Pubblicato: 11/09/26 11:09
Ultimo aggiornamento: 11/09/26 11:09
Impatto: Medio (64.87)
Agenzia per la cybersicurezza nazionale
Pubblicato: 10/09/26 14:17
Ultimo aggiornamento: 10/09/26 14:17
Impatto: Medio (63.07)
Agenzia per la cybersicurezza nazionale
Pubblicato: 10/09/26 12:44
Ultimo aggiornamento: 10/09/26 12:44
Impatto: Medio (64.74)
CVE: GHSA-h6w4-32pj-q5p4
Vendor: Tonec
CVSS: 9.3
Exploitation: Not available
Changed: 3 hours ago
Description: A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows. The impacted element is an unknown function of the file idmwfp.sys of the component Kernel Driver. The manipulation results in improper access controls. Attacking locally is a requirement. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE: CVE-2026-90647
Vendor: Kalkitech
CVSS: 9.1
Exploitation: Not available
Changed: 8 hours ago
Description: ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation vulnerability in the IEC 60870-5-104 TLS client (Task Mode). This allows a network-positioned attacker to bypass certificate validation via a certificate with multiple simultaneous faults, enabling a Man-in-the-Middle attack on protected communications.
CVE: CVE-2026-90558
Vendor: irontec
CVSS: 9.3
Exploitation: Not available
Changed: 12 hours ago
Description: sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit. Attackers can craft malicious SIP packets with oversized Call-ID, X-Call-ID, or other header fields to overflow stack buffers and cause crashes or execute arbitrary code during packet parsing and rendering.
CVE: GHSA-97p7-8jv8-2rmm
Vendor: Unknown
CVSS: 0.19
Exploitation: 0.19%
Changed: 15 hours ago
Description: The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML authentication responses before establishing a session, allowing unauthenticated attackers to log in as any user, including administrators, as well as to create arbitrary accounts.
CVE: GHSA-f47w-mrg9-g9p2
Vendor: GitLab
CVSS: 10
Exploitation: N/A
Changed: 19 hours ago
Description: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.
CVE: CVE-2026-42018
Vendor: JFrog
CVSS: 7.5
Exploitation: N/A
Changed: 1 day ago
Description: JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
CVE: CVE-2026-42016
Vendor: JFrog
CVSS: 8.1
Exploitation: N/A
Changed: 1 day ago
Description: JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
CVE: GHSA-rc8v-f46m-jcgm
Vendor: ConnectWise
CVSS: 9.9
Exploitation: N/A
Changed: 1 day ago
Description: A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.
CVE: CVE-2026-86060
Vendor: MikroTik
CVSS: 9.2
Exploitation: N/A
Changed: 2 days ago
Description: RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
CVE: CVE-2026-67277
Vendor: MikroTik
CVSS: 8.8
Exploitation: N/A
Changed: 2 days ago
Description: RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel. This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
CVE: CVE-2026-88915
Vendor: MISP
CVSS: 0.26
Exploitation: 0.26%
Changed: 2 days ago
Description: Affected versions of MISP do not consistently enforce the acting user's authorization when instantiating event templates. For templates using distribution = 4, the template can specify a sharing_group_id. The instantiation path passed that value into event creation without verifying that the user instantiating the template was actually permitted to use the selected sharing group. The commit notes that Event::_add() only performed its own sharing-group authorization in another code path, leaving template instantiation able to write the identifier directly. The same instantiation path also attached template-specified tags without checking the user's normal tagging permissions. In addition, it hardcoded local => 0, meaning tags marked local_only could be attached globally and consequently propagate through synchronization or export, contrary to their intended restriction. The fix adds explicit SharingGroup::canUse() authorization for the acting user, applies the same tag-modification checks used by normal event tagging, and ensures local_only tags are attached locally. Version affected: ≤2.5.45
CVE: CVE-2026-88921
Vendor: MISP
CVSS: 0.36
Exploitation: 0.36%
Changed: 2 days ago
Description: MISP contains an HTML injection vulnerability in the MISPElementHTMLFormatterTool component, which is responsible for rendering MISP element references (attributes, objects, and tags) into inline HTML during PDF report export via the convert_markdown_to_pdf module. The attribute(), objectAttribute(), object(), and tag() methods interpolated user-controlled fields (attribute type, attribute value, object name, object relation, tag name, tag colour, and tag text colour) directly into HTML templates without applying HTML entity encoding. An authenticated user with the ability to create or modify MISP attributes, objects, or tags could embed arbitrary HTML markup in these fields. When a report containing such elements was exported to PDF, the unescaped content was rendered as live HTML rather than inert text, potentially injecting script tags, breaking the document structure, or altering the visual content of the exported report. Additionally, the attribute() method contained a template with hardcoded sample values ("domain-ip" and "google.com") instead of format placeholders, meaning every plain attribute reference in a PDF displayed the sample text rather than the actual indicator value, constituting a data-integrity defect in the exported document. The vulnerability requires an authenticated actor with write access to MISP elements and a subsequent PDF export of a report referencing those elements. The security impact is primarily to the integrity of the exported document and, depending on the HTML-to-PDF rendering engine, potential execution of injected markup during the conversion step. Version affected: ≤2.5.45