SysAdmin 24x7
Kanalga Telegram’da o‘tish
Noticias y alertas de seguridad informática. Chat y contacto: t.me/sysadmin24x7chat
Ko'proq ko'rsatish4 429
Obunachilar
-124 soatlar
-27 kun
+730 kun
Ma'lumot yuklanmoqda...
O'xshash kanallar
Taglar buluti
Kirish va chiqish esdaliklari
---
---
---
---
---
---
Obunachilarni jalb qilish
Oktabr '26Okt '26
Oktabr '26
+4
0 kanalda
Sentabr '26
+63
0 kanalda
Get PRO
Avgust '26
+62
1 kanalda
Get PRO
Iyul '26
+52
1 kanalda
Get PRO
Iyun '26
+58
0 kanalda
Get PRO
May '26
+54
0 kanalda
Get PRO
Aprel '26
+61
0 kanalda
Get PRO
Mart '26
+50
0 kanalda
Get PRO
Fevral '26
+35
0 kanalda
Get PRO
Yanvar '26
+43
0 kanalda
Get PRO
Dekabr '25
+41
0 kanalda
Get PRO
Noyabr '25
+67
0 kanalda
Get PRO
Oktabr '25
+45
0 kanalda
Get PRO
Sentabr '25
+25
0 kanalda
Get PRO
Avgust '25
+34
0 kanalda
Get PRO
Iyul '25
+65
0 kanalda
Get PRO
Iyun '25
+34
0 kanalda
Get PRO
May '25
+36
0 kanalda
Get PRO
Aprel '25
+59
0 kanalda
Get PRO
Mart '25
+63
0 kanalda
Get PRO
Fevral '25
+62
0 kanalda
Get PRO
Yanvar '25
+98
0 kanalda
Get PRO
Dekabr '24
+89
0 kanalda
Get PRO
Noyabr '24
+109
0 kanalda
Get PRO
Oktabr '24
+114
0 kanalda
Get PRO
Sentabr '24
+122
0 kanalda
Get PRO
Avgust '24
+132
0 kanalda
Get PRO
Iyul '24
+114
0 kanalda
Get PRO
Iyun '24
+117
0 kanalda
Get PRO
May '24
+86
0 kanalda
Get PRO
Aprel '24
+145
0 kanalda
Get PRO
Mart '24
+116
0 kanalda
Get PRO
Fevral '24
+122
0 kanalda
Get PRO
Yanvar '24
+157
0 kanalda
Get PRO
Dekabr '23
+94
0 kanalda
Get PRO
Noyabr '23
+40
0 kanalda
Get PRO
Oktabr '23
+99
0 kanalda
Get PRO
Sentabr '23
+41
0 kanalda
Get PRO
Avgust '23
+31
0 kanalda
Get PRO
Iyul '23
+33
0 kanalda
Get PRO
Iyun '23
+26
0 kanalda
Get PRO
May '23
+36
0 kanalda
Get PRO
Aprel '23
+31
0 kanalda
Get PRO
Mart '23
+39
0 kanalda
Get PRO
Fevral '23
+41
0 kanalda
Get PRO
Yanvar '23
+48
0 kanalda
Get PRO
Dekabr '22
+33
0 kanalda
Get PRO
Noyabr '22
+41
0 kanalda
Get PRO
Oktabr '22
+84
0 kanalda
Get PRO
Sentabr '22
+31
0 kanalda
Get PRO
Avgust '22
+53
0 kanalda
Get PRO
Iyul '22
+43
0 kanalda
Get PRO
Iyun '22
+44
0 kanalda
Get PRO
May '22
+57
0 kanalda
Get PRO
Aprel '22
+44
0 kanalda
Get PRO
Mart '22
+36
0 kanalda
Get PRO
Fevral '22
+27
0 kanalda
Get PRO
Yanvar '22
+37
0 kanalda
Get PRO
Dekabr '21
+28
0 kanalda
Get PRO
Noyabr '21
+45
0 kanalda
Get PRO
Oktabr '21
+40
0 kanalda
Get PRO
Sentabr '21
+38
0 kanalda
Get PRO
Avgust '21
+42
0 kanalda
Get PRO
Iyul '21
+57
0 kanalda
Get PRO
Iyun '21
+49
0 kanalda
Get PRO
May '21
+44
0 kanalda
Get PRO
Aprel '21
+63
0 kanalda
Get PRO
Mart '21
+86
0 kanalda
Get PRO
Fevral '21
+68
0 kanalda
Get PRO
Yanvar '21
+84
0 kanalda
Get PRO
Dekabr '20
+2 225
0 kanalda
| Sana | Obunachilarni jalb qilish | Esdaliklar | Kanallar | |
| 06 Oktabr | 0 | |||
| 05 Oktabr | +1 | |||
| 04 Oktabr | +1 | |||
| 03 Oktabr | +1 | |||
| 02 Oktabr | 0 | |||
| 01 Oktabr | +1 |
Kanal postlari
Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2026-96940
Security Vulnerability
Released: Oct 2, 2026
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-96940
| 2 | Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778
Description of Problem
Multiple vulnerabilities have been discovered in Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway). Refer below for further details.
Affected Versions:
The following supported versions of Citrix NetScaler ADC and Citrix NetScaler Gateway are affected by the vulnerabilities:
Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 BEFORE 14.1-73.37
Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 BEFORE 13.1-64.23
Citrix NetScaler ADC FIPS BEFORE 14.1-73.37 FIPS
Citrix NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.279
Additional Note: Secure Private Access Hybrid deployments using NetScaler instances are also affected by the vulnerabilities. Customers need to upgrade these NetScaler instances to the recommended NetScaler builds to address the vulnerabilities.
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096 | 805 |
| 3 | Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771 through CVE-2026-88778
Guidance for customers on newly addressed vulnerabilities and recommended updates
As the cybersecurity landscape continues to evolve, organizations across the industry are seeing changes in the pace, scale, and complexity of vulnerability research, discovery, and analysis. AI-assisted research and automation may contribute to this shift by enabling faster identification and validation of certain classes of security issues. Citrix continues to invest in secure development, security testing, coordinated disclosure, and vulnerability response processes.
Citrix has released updates for NetScaler ADC and NetScaler Gateway to address multiple security vulnerabilities. These vulnerabilities vary by deployment configuration and enabled features, and include issues that could allow remote code execution, denial of service, HTTP request smuggling, policy bypass, and TCP initial sequence number prediction under specific conditions.
Exploitation of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments has been observed. Citrix strongly urges affected customers to install the relevant updated versions as soon as possible.
https://community.citrix.com/techzone-blogs/110_security-updates/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve-2026-88771-through-cve-2026-88778/ | 619 |
| 4 | Microsoft - Sep 2026 Security Updates
https://msrc.microsoft.com/update-guide/releaseNote/2026-Sep | 984 |
| 5 | VMSA-2026-0007: VMware Workstation and Fusion updates address integer-overflow and buffer overflow vulnerabilities (CVE-2026-59346, CVE-2026-59347)
Advisory ID: VMSA-2026-0007
Advisory Severity:
Critical
CVSSv3 Range:
8.1-9.3
Synopsis:
VMware Workstation and Fusion updates address integer-overflow and buffer overflow vulnerabilities (CVE-2026-59346, CVE-2026-59347)
Issue date:
2026-09-03
Updated on:
2026-09-03 (Initial Advisory)
CVE(s)
CVE-2026-59346, CVE-2026-59347
1. Impacted Products
VMware Workstation
VMware Fusion
2. Introduction
An integer-overflow and a buffer-overflow vulnerabilities in VMware Workstation and Fusion were privately reported to Broadcom. Updates are available to remediate these vulnerabilities in affected Broadcom products.
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38288 | 1 433 |
| 6 | Microsoft - Aug 2026 Security Updates
https://msrc.microsoft.com/update-guide/releaseNote/2026-Aug | 1 254 |
| 7 | SAP Security Patch Day - August 2026
https://support.sap.com/en/my-support/knowledge-base/security-notes-news/august-2026.html | 1 201 |
| 8 | VMSA-2026-0005.1: VMware Avi Load Balancer addresses multiple vulnerabilities (CVE-2026-47865, CVE-2026-47866, CVE-2026-47867, CVE-2026-47868, CVE-2026-47869, CVE-2026-47870, CVE-2026-47871)
Advisory ID: VMSA-2026-0005.1
Advisory Severity: Critical
CVSSv3 Range: 7.1 - 9.8
Synopsis:
VMware Avi Load Balancer addresses multiple vulnerabilities (CVE-2026-47865, CVE-2026-47866, CVE-2026-47867, CVE-2026-47868, CVE-2026-47869, CVE-2026-47870, CVE-2026-47871)
Issue date: 2026-07-14
Updated on: 2026-08-07
1. Impacted Products
VMware Avi Load Balancer
2. Introduction
Multiple vulnerabilities in Avi Load Balancer were privately reported to Broadcom. Patches are available to remediate these vulnerabilities in the affected Broadcom product.
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37926 | 1 257 |
| 9 | Keyv and friends compromised in active Shai-Hulud supply chain attack
On August 4, 2026, attackers compromised the GitHub account of the maintainer behind keyv, a key-value storage library with roughly 127 million weekly npm downloads, and used that access to inject a credential-stealing worm across the entire package family. The same maintainer owns cacheable (29M downloads/month), flat-cache (565M downloads/month), file-entry-cache (557M downloads/month), and several other widely-used caching utilities, all of which were swept up in the same attack.
https://www.aikido.dev/blog/keyv-and-friends-compromised-in-npm-supply-chain-attack | 796 |
| 10 | Feliz SysAdminDay a tod@s
Día del Administrador de Sistemas Informáticos
Viernes 31 de julio de 2026 | 1 035 |
| 11 | VMSA-2026-0006: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709)
Advisory ID: VMSA-2026-0006
Advisory Severity: Critical
CVSSv3 Range: 2.7-9.8
Synopsis:
VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709)
Issue date: 2026-07-29
CVE(s) CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709
Impacted Products
VMware ESX
VMware vCenter
VMware Workstation
VMware Fusion
VMware Cloud Foundation
VMware vSphere Foundation
VMware Telco Cloud Platform
VMware Telco Cloud Infrastructure
Introduction
Multiple vulnerabilities in VMware ESX, vCenter, Workstation, and Fusion were privately reported to Broadcom. Updates are available to remediate these vulnerabilities in affected Broadcom products.
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017 | 1 068 |
| 12 | Oracle Critical Patch Update Advisory - July 2026
https://www.oracle.com/security-alerts/cpujul2026.html | 1 091 |
| 13 | SonicWall SMA1000 Series Appliances Affected By Multiple Vulnerabilities
Advisory ID SNWLID-2026-0008
First Published 2026-07-14
Workaround false
Status Applicable
CVE CVE-2026-15409, CVE-2026-15410
CWE CWE-918, CWE-94
CVSS v3 10.0
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008 | 1 394 |
| 14 | CISA Urges SharePoint Hardening After New Exploitations
Release DateJuly 14, 2026
CISA is aware of active exploitation of vulnerabilities CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164, enabling cyber threat actors to gain unauthorized access to on-premises SharePoint Server instances.
https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-urges-sharepoint-hardening-after-new-exploitations | 1 358 |
| 15 | Microsoft - July 2026 Security Updates
https://msrc.microsoft.com/update-guide/releaseNote/2026-Jul | 1 078 |
| 16 | Neutralización incorrecta de elementos especiales en FortiSandbox de Fortinet
Fecha 09/07/2026
Importancia 5 - Crítica
Recursos Afectados
FortiSandbox 5.0: versiones desde 5.0.0 a 5.0.5;
FortiSandbox 4.4: versiones desde 4.4.0 a 4.4.8;
FortiSandbox Cloud 5.0: versiones desde 5.0.4 a 5.0.5;
FortiSandbox PaaS 5.0: versiones desde 5.0.4 a 5.0.5.
Descripción
Adham El Karn, del equipo de seguridad de productos de Fortinet, ha reportado una vulnerabilidad de severidad critica que, en caso de ser explotada, podría permitir a un atacante ejecutar código o comandos no autorizados.
https://www.incibe.es/incibe-cert/alerta-temprana/avisos/neutralizacion-incorrecta-de-elementos-especiales-en-fortisandbox-de-fortinet | 1 230 |
| 17 | Bad Epoll: The bug missed by Mythos
https://github.com/J-jaeyoung/bad-epoll | 1 052 |
| 18 | [Actualización 02/07/2026] Falsificación de solicitudes del lado del servidor en productos de Cisco
Fecha 04/06/2026
Importancia 4 - Alta
Recursos Afectados
Cisco Unified CM, versión 14, y Unified CM SME, versión 15, si tienen habilitado el servicio WebDialer.
Descripción
Cisco ha publicado una vulnerabilidad de severidad alta que podría permitir a un atacante remoto, no autenticado, realizar ataques de falsificación de solicitudes del lado del servidor (SSRF) a través de un dispositivo afectado.
[Actualización 02/07/2026] El equipo PSIRT de Cisco tiene conocimiento de que existe código de prueba de concepto para explotar la vulnerabilidad descrita en este aviso.
Solución
Actualizar a las versiones 14SU6 y 15SU5 (septiembre de 2026) o COP 1, respectivamente.
https://www.incibe.es/incibe-cert/alerta-temprana/avisos/falsificacion-de-solicitudes-del-lado-del-servidor-en-productos-de-cisco | 1 003 |
| 19 | Múltiples vulnerabilidades en NetScaler de Citrix
Fecha 03/07/2026
Importancia 4 - Alta
Recursos Afectados
NetScaler ADC y NetScaler Gateway 14.1 anteriores a 14.1-72.61;
NetScaler ADC y NetScaler Gateway 13.1 anteriores a 13.1-63.18;
FIPS de NetScaler ADC anteriores a 14.1-72.61 FIPS;
Compatibilidad con FIPS y NDcPP de NetScaler ADC anteriores a la versión 13.1-37.272.
Descripción
Citrix ha publicado 6 vulnerabilidades: 5 de severidad alta y 1 de severidad media que, en caso de ser explotadas, podrían permitir a un atacante leer la memoria, provocar un comportamiento impredecible o una denegación de servicio.
Solución
Cloud Software Group insta a los clientes afectados a que instalen las versiones actualizadas correspondientes.
NetScaler ADC y NetScaler Gateway versiones 14.1-72.61 y posteriores.
NetScaler ADC y NetScaler Gateway 13.1-63.18 y versiones posteriores de 13.1.
NetScaler ADC 14.1-FIPS 14.1-72.61 FIPS y versiones posteriores de 14.1-FIPS.
NetScaler ADC 13.1-FIPS y 13.1-NDcPP 13.1.37.272 y versiones posteriores de 13.1-FIPS y 13.1-NDcPP.
https://www.incibe.es/incibe-cert/alerta-temprana/avisos/multiples-vulnerabilidades-en-netscaler-de-citrix | 794 |
| 20 | SolarWinds Serv-U Unauthenticated Denial of Service Vulnerability (CVE-2026-28318)
Summary
SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate.
Affected Products
SolarWinds Serv-U 15.5.4 and below
Fixed Software Release
SolarWinds Serv-U 15.5.4 HF1
https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28318 | 994 |
