最新预警列表

CRITICAL NVD Recent 2026-09-22

CVE-2026-90647:ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation

ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation vulnerability in the IEC 60870-5-104 TLS client (Task Mode). This allows a network-positioned attacker to bypass certificate validatio

CRITICAL CERT-EU 2026-09-22

2026-013: Critical Vulnerability in F5 BIG-IP APM

On 22 September 2026, F5 published an advisory addressing a critical vulnerability affecting its BIG-IP APM product. The vendor confirmed active exploitation in the wild. CERT-EU recommends taking appropriate actions as soon as possible.

CRITICAL CERT/CC VU 2026-09-22

VU#738147: Vendor-signed UEFI Shell applications allow Secure Boot bypass

Overview Vendor-signed UEFI Shell applications may allow an attacker to bypass Secure Boot protections by abusing commands such as mm (Memory Modify). On systems that trust the affected vendor’s certificate or include the application’s Authenticode hash i

CRITICAL openEuler 安全公告 OSV 2026-09-20

CVE-2026-53612:util-linux security update

util-linux security update

CRITICAL openEuler 安全公告 OSV 2026-09-20

CVE-2026-82397:python-tornado security update

python-tornado security update

CRITICAL openEuler 安全公告 OSV 2026-09-20

CVE-2026-77358:cpp-httplib security update

cpp-httplib security update

CRITICAL openEuler 安全公告 OSV 2026-09-20

CVE-2026-13346:python-pip security update

python-pip security update

CRITICAL openEuler 安全公告 OSV 2026-09-20

CVE-2025-28162:openjdk-21 security update

openjdk-21 security update

CRITICAL NVD Recent 2026-09-18

CVE-2026-20331:As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appl

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has

CRITICAL NVD Recent 2026-09-18

CVE-2026-75156:Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s

Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s during OAuth login. Deployments are affected only when the FAB auth manager is configured with Azure AD as an OAuth provider. Because t

CRITICAL Cisco PSIRT 2026-09-18

Cisco Identity Services Engine Vulnerabilities

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to bypass authentication to the REST API, achieve remote code execution, perform SQL injection, and conduct X

CRITICAL Cisco PSIRT 2026-09-18

Cisco Identity Services Engine Authenticated Remote Code Execution and API Vulnerabilities

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct SQL injections, modify data, or execute arbitrary commands on the underlying operating system on an affected device. For more informa

CRITICAL Cisco PSIRT 2026-09-18

Cisco Identity Services Engine Remote Code Execution Vulnerabilities

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit these vulnerabilities, the attacker must have

CRITICAL Cisco PSIRT 2026-09-18

Cisco Secure Firewall Management Center Software Java Deserialization Remote Code Execution Vulnerability

A vulnerability in the External Database Access feature of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary commands as root on an affected device. This vulnerability is due to ins

CRITICAL Cisco PSIRT 2026-09-18

Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。