Doorzoek en filter alle geregistreerde cyberdreigingen voor gemeenten.
371 dreigingen gevonden · pagina 16 van 31
Apple heeft meerdere kwetsbaarheden verholpen in macOS (Specifiek voor Golden Gate 27, Sequoia 15.8, Tahoe 26.7). De kwetsbaarheden in macOS betreffen onder andere heap-based buffer overflows, use-after-free fouten, integer overflows, null pointer dereferences, onjuiste toegangscontrole, privilege escalatie, race conditions, out-of-bounds reads en writes, loggingsproblemen, en problemen met state management. Deze kunnen leiden tot onverwachte systeem- of applicatie-terminaties, kernel geheugen corruptie, ongeautoriseerde toegang tot gevoelige gebruikersdata, omzeilen van sandbox- en Gatekeeper
Overview On September 14, 2026, Cisco published a security advisory for CVE-2026-76461 , a critical SQL injection vulnerability affecting Cisco AsyncOS Software for Cisco Secure Email Gateway. The vulnerability has a reported CVSS v3.1 base score of 9.8 and could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on an affected appliance. Cisco Secure Email Gateway, formerly known as IronPort Email Security Appliance, is an enterprise email security product that inspects inbound and outbound email for threats including phishing, malware, spam, and busi
CVE-2026-76461
UK and allies provide advice to help organisations and individuals at risk detect and counter the threat from CHOSEN BRICK malware.
Advisory on CHOSEN BRICK malware, including technical analysis and advice to help individuals and organisations protect themselves.
Overview On September 10, 2026, GitLab published a critical patch release for GitLab Community Edition (CE) and Enterprise Edition (EE). The release addresses CVE-2026-85706 , a critical path traversal vulnerability ( CWE-22 ) in the repository commits API with a CVSSv3.1 score of 10.0 . According to GitLab, improper path confinement and missing authentication enforcement could allow an unauthenticated user to read arbitrary files from an affected GitLab server under certain conditions. On September 11, 2026, CVE-2026-85706 was added to the U.S. Cybersecurity and Infrastructure Security Agency
CVE-2024-11222
Er is een kritieke kwetsbaarheid in GitLab Community Edition en Enterprise Edition gevonden met het kenmerk CVE-2026-85706. De kwetsbaarheid heeft een CVSS-score van 10.0 en wordt actief misbruikt. Het NCSC beoordeelt de kans op misbruik en de mogelijke schade als hoog en adviseert om zo snel mogelijk beveiligingsupdates te installeren.
CVE-2026-85706
CVE-2026-0297
CVE-2026-0295
This One Goes to Sixteen! Another banger from Metasploit with sixteen new modules, including ten exploit modules, with five on the CISA KEV list. Cisco, Papercut, Sonicwall, Jetbrains, and Langflow all have exploit modules, and not to be outdone, we even have a Metasploit scanner to watch the watchers! New module content (16) Elasticsearch ingest-attachment Apache Tika XFA XXE Local File Read Authors: Bourbon Offensive Security Services and Jean-Marie Bourbon Type: Auxiliary Pull request: #21739 contributed by kmkz Path: scanner/http/elasticsearch_tika_xfa_xxe CVE reference: CVE-2025-66516 Des
CVE-2025-54988
Introduction The surge in emerging threat actors directly correlates with the rapid escalation of victim counts and stolen financial resources. Simultaneously, this growth has spurred the proliferation of specialized supply storefronts across social media platforms, dark web channels, and various smaller niche marketplaces. Security teams today face evolving challenges, requiring them to continuously refine monitoring channels, adjust operational strategies, and foster cross-functional internal collaboration to capture actionable intelligence. With fraud damages anticipated to approach hundred
JFrog Artifactory contains an incorrect authorization vulnerability that leads to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
CVE-2026-42016
ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to transfer and execute files through an active remote session without authorization or host confirmation.
CVE-2026-84869