A vulnerability classified as problematic was found in SAP GUI 8.00 on Windows. The affected element is an unknown function of the component GuiXT. Such manipulation leads to uncontrolled search path.
This vulnerability is documented as CVE-2026-24317. The attack needs to be performed locally. There is not any exploit available.
It is advisable to implement a patch to correct this issue.
A vulnerability described as problematic has been identified in kubewarden kubewarden-controller up to 1.32.x. This issue affects some unknown processing of the component API Call Handler. The manipulation results in incorrect authorization.
This vulnerability is cataloged as CVE-2026-29773. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.
A vulnerability marked as very critical has been reported in oneuptime up to 10.0.19. This vulnerability affects the function this.constructor.constructor. The manipulation leads to exposed dangerous routine.
This vulnerability is listed as CVE-2026-30921. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.
A vulnerability labeled as critical has been found in SAP Supply Chain Management up to SCMAPO 713. This affects an unknown part. Executing a manipulation of the argument control can lead to unchecked input for loop condition.
This vulnerability is tracked as CVE-2026-27689. The attack can be launched remotely. No exploit exists.
Applying a patch is advised to resolve this issue.
A vulnerability identified as problematic has been detected in SAP Solution Tools Plug-In 740/758/2008_1_710/ST-PI 2008_1_700. Affected by this issue is some unknown functionality. Performing a manipulation results in missing authorization.
This vulnerability is identified as CVE-2026-24313. The attack can be initiated remotely. There is not any exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability categorized as critical has been discovered in themeum Tutor LMS Pro Plugin up to 3.9.5 on WordPress. Affected by this vulnerability is an unknown functionality. Such manipulation leads to improper authentication.
This vulnerability is referenced as CVE-2026-0953. It is possible to launch the attack remotely. No exploit is available.
A vulnerability was found in arraytics Booktics Plugin up to 1.0.16 on WordPress. It has been rated as critical. Affected is the function Extension_Controller::update_item_permissions_check. This manipulation causes missing authentication.
The identification of this vulnerability is CVE-2026-1920. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability was found in arraytics Booktics Plugin up to 1.0.16 on WordPress. It has been declared as critical. This impacts an unknown function of the component REST API Endpoint. The manipulation results in missing authentication.
This vulnerability was named CVE-2026-1919. The attack may be performed from remote. There is no available exploit.
Currently trending CVE - Hype Score: 8 - A LogoFAIL issue was discovered in BmpDecoderDxe in Insyde InsydeH2O with kernel 5.2 before 05.28.47, 5.3 before 05.37.47, 5.4 before 05.45.47, 5.5 before 05.53.47, and 5.6 before 05.60.47 for certain Lenovo devices. Image parsing of crafted BMP logo files can copy data to a ...
嗯,用户让我总结一下这篇文章的内容,控制在100字以内。首先,我需要仔细阅读文章,理解主要信息。
文章讲的是美国网络安全和基础设施安全局(CISA)新增了三个安全漏洞到他们的已知被利用漏洞目录中。这三个漏洞分别是CVE-2021-22054、CVE-2025-26399和CVE-2026-1603。每个漏洞都有详细的描述和CVSS评分。
接下来,我需要确定每个漏洞的主要信息。比如,CVE-2021-22054是一个服务器端请求伪造漏洞,影响Omnissa Workspace One UEM,评分7.5。CVE-2025-26399是SolarWinds Web Help Desk中的反序列化漏洞,评分9.8,并且已经被用于初始访问攻击,可能由Warlock勒索团伙实施。第三个漏洞CVE-2026-1603是Ivanti Endpoint Manager的认证绕过问题,评分8.6,目前还没有被利用的详细报告。
然后,CISA要求联邦机构在特定日期前修复这些漏洞,并强调这些漏洞是网络攻击的常见目标,对联邦企业构成重大风险。
现在,我需要将这些信息浓缩到100字以内。要抓住关键点:CISA新增三个高危漏洞到目录中,涉及SolarWinds、Omnissa和Ivanti产品;其中两个已被利用;要求联邦机构在指定日期前修复;强调这些漏洞的风险。
可能的结构是:开头提到CISA新增三个高危漏洞;接着分别简要描述每个漏洞及其影响;最后提到修复要求和风险。
确保语言简洁明了,不使用复杂的术语。避免重复信息,比如每个漏洞的CVSS评分可以省略或合并描述。
最后检查字数是否在限制内,并确保所有关键点都被涵盖。
美国网络安全机构CISA新增三个高危安全漏洞至已知被利用列表中。其中两个已被用于实际攻击:SolarWinds Web Help Desk反序列化漏洞(CVSS 9.8)被用于初始访问攻击;Omnissa Workspace One UEM SSRF漏洞(CVSS 7.5)被用于数据泄露。第三个Ivanti Endpoint Manager认证绕过漏洞暂无活跃利用报告。CISA要求联邦机构于指定日期前完成修复以应对威胁风险。
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added three security flaws to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.
The vulnerability list is as follows -
CVE-2021-22054 (CVSS score: 7.5) - A server-side request forgery (SSRF) vulnerability in Omnissa Workspace One UEM (formerly VMware Workspace One UEM) that
A vulnerability was found in stellarwp Events Calendar Plugin up to 6.15.17 on WordPress. It has been classified as critical. This affects the function ajax_create_import. The manipulation leads to path traversal.
This vulnerability is uniquely identified as CVE-2026-3585. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability was found in SAP NetWeaver Application Server for ABAP up to 918 and classified as critical. The impacted element is an unknown function of the component HTTP Request Handler. Executing a manipulation can lead to server-side request forgery.
This vulnerability is handled as CVE-2026-24316. The attack can be executed remotely. There is not any exploit available.
A patch should be applied to remediate this issue.
A vulnerability has been found in SiYuan up to 3.5.9 and classified as critical. The affected element is an unknown function of the file /export of the component Kernel API. Performing a manipulation results in path traversal.
This vulnerability is known as CVE-2026-30869. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.