最新预警列表

CRITICAL Cisco PSIRT 2026-10-01

Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability

A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handl

CRITICAL Cisco PSIRT 2026-10-01

Cisco Identity Services Engine Authentication Bypass Vulnerabilities

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to access or manipulate data, obtain sensitive information, or cause a reload of certificate and key material

CRITICAL Cisco PSIRT 2026-10-01

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software EIGRP Denial of Service Vulnerability

A vulnerability in the EIGRP implementation in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to cause the device to reload unexpec

CRITICAL Cisco PSIRT 2026-10-01

Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software and Cisco Secure Firewall Management Center (FMC) So

CRITICAL Cisco PSIRT 2026-10-01

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software for Secure Firewall 3100 and 4200 Series DTLS Denial of Service Vulnerability

A vulnerability in Datagram TLS (DTLS) message handling of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software for Cisco Secure Firewall 3100 Series and 4200 Series devices could allow a

CRITICAL Cisco PSIRT 2026-10-01

Cisco IOS XR Software Security Hardening Release: September 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple i

CRITICAL openEuler 安全公告 OSV 2026-09-30

CVE-2026-86320:flatpak-builder security update

flatpak-builder security update

CRITICAL openEuler 安全公告 OSV 2026-09-30

CVE-2026-54284:python-sqlparse security update

python-sqlparse security update

CRITICAL openEuler 安全公告 OSV 2026-09-30

CVE-2026-82560:perl-podlators security update

perl-podlators security update

CRITICAL openEuler 安全公告 OSV 2026-09-30

CVE-2026-94184:fetchmail security update

fetchmail security update

CRITICAL openEuler 安全公告 OSV 2026-09-30

CVE-2026-93590:ImageMagick security update

ImageMagick security update

CRITICAL openEuler 安全公告 OSV 2026-09-30

CVE-2026-80225:unbound security update

unbound security update

CRITICAL Cisco PSIRT 2026-09-30

Cisco Secure Email Gateway SQL Injection Vulnerability

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due

CRITICAL Cisco PSIRT 2026-09-30

Cisco Advance Notification for Publication of September 16, 2026, Security Advisories

On September 16, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the advisories that are listed in the following tables.  To remediate these vulnerabilities, Cisco strongly recommends that customers upgrade to the fixed software

CRITICAL CERT/CC VU 2026-09-28

VU#762428: Authlib library contains a signature‑verification bypass vulnerability

Overview Authlib (versions up to and including 1.7.2) contain a signature‑verification bypass in the JSON Web Signature (JWS) general JSON serialization handling. The JsonWebSignature.deserialize_json() function accepts a JWS object with an empty "signatu

站内所有资源、漏洞预警、工具与专题内容仅面向企业授权自测、合规研究与安全运维使用。本站不提供可直接用于非法攻击的程序、载荷或黑产平台入口。