2026年10月10日星期六

Apache HTTP Server 多個漏洞

Apache HTTP Server 多個漏洞

發佈日期: 2026年10月09日

於 Apache 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行程式碼、資料篡改、阻斷服務狀況、繞過保安限制及敏感資料洩露。


影響

  • 阻斷服務
  • 繞過保安限制
  • 資料洩露
  • 篡改
  • 遠端執行程式碼

受影響之系統或技術

  • Apache HTTP Server 2.4.69 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:

  • Apache HTTP Server 2.4.69 版本

漏洞識別碼


資料來源


相關連結

 


Apache HTTP Server Multiple Vulnerabilities

Apache HTTP Server Multiple Vulnerabilities

Release Date: 9 Oct 2026

Multiple vulnerabilities were identified in Apache HTTP Server. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution, data manipulation, denial of service condition, security restriction bypass and sensitive information disclosure on the targeted system.


Impact

  • Denial of Service
  • Security Restriction Bypass
  • Information Disclosure
  • Data Manipulation
  • Remote Code Execution

System / Technologies affected

  • Apache HTTP Server versions prior to 2.4.69

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:

  • Apache HTTP Server version 2.4.69

Vulnerability Identifier


Source


Related Link

 


ONLYOFFICE Docs 遠端執行程式碼漏洞

ONLYOFFICE Docs 遠端執行程式碼漏洞

發佈日期: 2026年10月09日

於 ONLYOFFICE Docs 發現一個漏洞。遠端攻擊者可利用此漏洞,於目標系統觸發遠端執行程式碼及繞過保安限制。

 

注意:

CVE-2021-3199 正被廣泛利用。ONLYOFFICE Docs 存在路徑遍歷漏洞。當使用 JWT 時,攻擊者可透過圖片上傳參數中的 /.. 序列觸發此漏洞,並可能導致遠端程式碼執行。因此,該漏洞的風險等級被評為高度風險。


影響

  • 繞過保安限制
  • 遠端執行程式碼

受影響之系統或技術

  • ONLYOFFICE Document Server 5.6.3 之前的版本

解決方案

  • ONLYOFFICE Document Server 5.6.3 及之後的版本

漏洞識別碼


資料來源


相關連結

 


ONLYOFFICE Docs Remote Code Execution Vulnerability

ONLYOFFICE Docs Remote Code Execution Vulnerability

Release Date: 9 Oct 2026

A vulnerability was identified in ONLYOFFICE Docs. A remote attacker could exploit this vulnerability to trigger remote code execution and security restriction bypass on the targeted system.

 

Note:

CVE-2021-3199 is being exploited in the wild. ONLYOFFICE Docs contains a path traversal vulnerability that can occur when JWT is used, via a /.. sequence in an image upload parameter and could allow for remote code execution. Hence, the risk level is rated as High Risk.


Impact

  • Security Restriction Bypass
  • Remote Code Execution

System / Technologies affected

  • ONLYOFFICE Document Server versions earlier than 5.6.3

Solutions

  • ONLYOFFICE Document Server to version 5.6.3 or later

Vulnerability Identifier


Source


Related Link

 


Splunk 產品多個漏洞

Splunk 產品多個漏洞

發佈日期: 2026年10月09日

於 Splunk 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發資料篡改、阻斷服務狀況、權限提升、繞過保安限制、敏感資料洩露及遠端執行任意程式碼。


影響

  • 遠端執行程式碼
  • 阻斷服務
  • 資料洩露
  • 權限提升
  • 繞過保安限制
  • 篡改

受影響之系統或技術

  • Splunk Enterprise 9.4 版本 9.4.0 至 9.4.14
  • Splunk Enterprise 10.0 版本 10.0.0 至 10.0.9
  • Splunk Enterprise 10.2 版本 10.2.0 至 10.2.6
  • Splunk Enterprise 10.4 版本 10.4.0 至 10.4.2

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

 


Splunk Products Multiple Vulnerabilities

Splunk Products Multiple Vulnerabilities

Release Date: 9 Oct 2026

Multiple vulnerabilities were identified in Splunk products. A remote attacker could exploit some of these vulnerabilities to trigger data manipulation, denial of service condition, elevation of privilege, security restriction bypass, sensitive information disclosure and remote code execution on the targeted system.


Impact

  • Remote Code Execution
  • Denial of Service
  • Information Disclosure
  • Elevation of Privilege
  • Security Restriction Bypass
  • Data Manipulation

System / Technologies affected

  • Splunk Enterprise 9.4 versions 9.4.0 to 9.4.14
  • Splunk Enterprise 10.0 versions 10.0.0 to 10.0.9
  • Splunk Enterprise 10.2 versions 10.2.0 to 10.2.6
  • Splunk Enterprise 10.4 versions 10.4.0 to 10.4.2

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

 


2026年10月8日星期四

思科產品多個漏洞

思科產品多個漏洞

發佈日期: 2026年10月08日

於思科產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、繞過保安限制、敏感資料洩露及遠端執行任意程式碼。


影響

  • 阻斷服務
  • 遠端執行程式碼
  • 繞過保安限制
  • 資料洩露

受影響之系統或技術

  • 思科 NX-OS Software

請參考供應商發佈的連結以了解受影響的版本:


解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

 


Cisco Products Multiple Vulnerabilities

Cisco Products Multiple Vulnerabilities

Release Date: 8 Oct 2026

Multiple vulnerabilities were identified in Cisco Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, security restriction bypass, sensitive information disclosure and remote code execution on the targeted system.


Impact

  • Denial of Service
  • Remote Code Execution
  • Security Restriction Bypass
  • Information Disclosure

System / Technologies affected

  • Cisco NX-OS Software

For affected versions, please refer to the link issued by the vendor:


Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

 


GitHub Enterprise Server 多個漏洞

GitHub Enterprise Server 多個漏洞

發佈日期: 2026年10月08日

於 GitHub Enterprise Server 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼及資料篡改。


影響

  • 遠端執行程式碼
  • 篡改

受影響之系統或技術

  • GitHub Enterprise Server 3.18.16, 3.19.13, 3.20.9, 3.21.7, 3.22.2 以前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:

  • 更新至 GitHub Enterprise Server 3.18.16, 3.19.13, 3.20.9, 3.21.7, 3.22.2 版本

漏洞識別碼


資料來源


相關連結

 


GitHub Enterprise Server Multiple Vulnerabilities

GitHub Enterprise Server Multiple Vulnerabilities

Release Date: 8 Oct 2026

Multiple vulnerabilities were identified in GitHub Enterprise Server. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution and data manipulation on the targeted system.


Impact

  • Remote Code Execution
  • Data Manipulation

System / Technologies affected

  • GitHub Enterprise Server versions prior to 3.18.16, 3.19.13, 3.20.9, 3.21.7, 3.22.2

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:

  • Update to GitHub Enterprise Server versions 3.18.16, 3.19.13, 3.20.9, 3.21.7, 3.22.2

Vulnerability Identifier


Source


Related Link

 


IBM WebSphere 產品多個漏洞

IBM WebSphere 產品多個漏洞

發佈日期: 2026年10月08日

於 IBM WebSphere 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、敏感資料洩露及資料篡改。


影響

  • 阻斷服務
  • 權限提升
  • 篡改
  • 資料洩露

受影響之系統或技術

  • IBM WebSphere Application Server - Liberty 26.0.0.10 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

 


Apache HTTP Server 多個漏洞

Apache HTTP Server 多個漏洞 發佈日期 : 2026 年 10 月 09 日 於 Apache 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行程式碼、資料篡改、阻斷服務狀況、繞過保安限制及敏感資料洩露。 影響 ...