RCE

UniFi OSの重大な脆弱性により、ハッカーが認証なしでroot権限を取得可能に News

UniFi OSの重大な脆弱性により、ハッカーが認証なしでroot権限を取得可能に

攻撃者は、Ubiquiti UniFi OSサーバーの3つの既に対処済みの脆弱性を組み合わせて利用することで、認証なしでroot権限を持つリモートコードを実行することが可能です。 これらのセキュリティ問題は、CVE-2026-34908、C...
Gogsのパッチ:リモートコード実行を可能にする重大なゼロデイ脆弱性 News

Gogsのパッチ:リモートコード実行を可能にする重大なゼロデイ脆弱性

Gogsは、攻撃者がインターネットに公開されているインスタンスを乗っ取り、あらゆるリポジトリ(非公開のリポジトリを含む)にアクセスできる可能性のある、重大なセキュリティ上のゼロデイ脆弱性に対する修正パッチを適用しました。 この引数注入の脆弱...
Critical Windows Netlogon RCE flaw now exploited in attacks News

Critical Windows Netlogon RCE flaw now exploited in attacks

The Centre for Cybersecurity Belgium (CCB), the country's national authority for cybersecurity, warned on Friday that th...
New Gogs zero-day flaw lets hackers get remote code execution News

New Gogs zero-day flaw lets hackers get remote code execution

An unpatched zero-day vulnerability in the Gogs self-hosted Git service can allow attackers to gain remote code executio...
KnowledgeDeliver flaw exploited as a zero-day to install web shells News

KnowledgeDeliver flaw exploited as a zero-day to install web shells

Hackers exploited a critical zero-day vulnerability in a server running the KnowledgeDeliver learning management system ...
Max-severity flaw in ChromaDB for AI apps allows server hijacking News

Max-severity flaw in ChromaDB for AI apps allows server hijacking

A max-severity vulnerability in the latest Python FastAPI version of the ChromaDB project allows unauthenticated attacke...
18-year-old NGINX vulnerability allows DoS, potential RCE News

18-year-old NGINX vulnerability allows DoS, potential RCE

An 18-year-old flaw in the NGINX open-source web server, discovered using an autonomous scanning system, can be exploite...
New critical Exim mailer flaw allows remote code execution News

New critical Exim mailer flaw allows remote code execution

A critical vulnerability affecting certain configurations of the Exim open-source mail transfer agent could be exploited...
フォーティネット、FortiSandboxとFortiAuthenticatorにRCEの重大な欠陥があると警告 News

フォーティネット、FortiSandboxとFortiAuthenticatorにRCEの重大な欠陥があると警告

フォーティネットは、FortiSandboxおよびFortiAuthenticatorにおける2つの重大な脆弱性に対処するためのセキュリティアップデートをリリースしました。 最初の脆弱性は、CVE-2026-44277として追跡されており、...
CISA、ゼロデイとして悪用されたIvantiの欠陥にパッチを当てるようFBIに4日間の猶予を与える News

CISA、ゼロデイとして悪用されたIvantiの欠陥にパッチを当てるようFBIに4日間の猶予を与える

米国サイバーセキュリティ・インフラストラクチャ・セキュリティ局(CISA)は、ゼロデイ攻撃で悪用されているIvanti Endpoint Manager Mobile(EPMM)の深刻度の高い脆弱性に対し、ネットワークを保護するよう米国連邦...