2026年8月12日星期三

思科產品多個漏洞

思科產品多個漏洞

發佈日期: 2026年08月12日

於思科產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況及敏感資料洩露。

 

注意:

CVE-2026-20349 正在被廣泛利用。 如果已啟用 Remote Access SSL VPN 服務,遠端攻擊者可利用此漏洞於目標系統觸發阻斷服務狀況。因此,此漏洞的風險等級被評為高度風險。


影響

  • 阻斷服務
  • 資料洩露

受影響之系統或技術

  • Cisco Secure Endpoint Connector
  • Cisco Secure Firewall ASA Software
  • Cisco Secure FMC Software
  • Cisco Secure FTD Software
  • Cisco Catalyst SD-WAN Manager

請參考供應商發佈的連結以了解受影響的版本:


解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Cisco Products Multiple Vulnerabilities

Cisco Products Multiple Vulnerabilities

Release Date: 12 Aug 2026

Multiple vulnerabilities were identified in Cisco products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition and sensitive information disclosure on the targeted system.

 

Note:

CVE-2026-20349 is being exploited in the wild. A remote attacker could exploit this vulnerability to trigger denial of service on the targeted system if Remote Access SSL VPN service is enabled. Hence, the risk level is rated as High Risk.


Impact

  • Denial of Service
  • Information Disclosure

System / Technologies affected

  • Cisco Secure Endpoint Connector
  • Cisco Secure Firewall ASA Software
  • Cisco Secure FMC Software
  • Cisco Secure FTD Software
  • Cisco Catalyst SD-WAN Manager

For affected versions, please refer to the link issued by the vendor:


Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Docker Desktop 繞過保安限制漏洞

Docker Desktop 繞過保安限制漏洞

發佈日期: 2026年08月12日

於 Docker Desktop 發現一個漏洞。遠端攻擊者可利用此漏洞,於目標系統觸發繞過保安限制。


影響

  • 繞過保安限制

受影響之系統或技術

  • Docker Desktop on Windows 4.86.0 之前的版本
  • Docker Desktop on MacOS 4.86.0 之前的版本
  • Docker Desktop on Linux 4.86.0 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Docker Desktop Security Restriction Bypass Vulnerability

Docker Desktop Security Restriction Bypass Vulnerability

Release Date: 12 Aug 2026

A vulnerability has been identified in Docker Desktop. A remote attacker could exploit this vulnerability to trigger security restriction bypass on the targeted system.


Impact

  • Security Restriction Bypass

System / Technologies affected

  • Docker Desktop on Windows below version 4.86.0
  • Docker Desktop on MacOS below version 4.86.0
  • Docker Desktop on Linux below version 4.86.0

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Google Chrome 多個漏洞

Google Chrome 多個漏洞

發佈日期: 2026年08月12日

於 Google Chrome 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況及遠端執行任意程式碼。


影響

  • 阻斷服務
  • 遠端執行程式碼

受影響之系統或技術

  • Google Chrome 151.0.7922.137 (Linux) 之前的版本
  • Google Chrome 151.0.7922.137/.138 (Mac) 之前的版本
  • Google Chrome 151.0.7922.137/.138 (Windows) 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 151.0.7922.137 (Linux) 或之後版本
  • 更新至 151.0.7922.137/.138 (Mac) 或之後版本
  • 更新至 151.0.7922.137/.138 (Windows) 或之後版本

漏洞識別碼


資料來源


相關連結

Google Chrome Multiple Vulnerabilities

Google Chrome Multiple Vulnerabilities

Release Date: 12 Aug 2026

Multiple vulnerabilities were identified in Google Chrome. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition and remote code execution on the targeted system.


Impact

  • Denial of Service
  • Remote Code Execution

System / Technologies affected

  • Google Chrome prior to 151.0.7922.137 (Linux)
  • Google Chrome prior to 151.0.7922.137/.138 (Mac)
  • Google Chrome prior to 151.0.7922.137/.138 (Windows)

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 151.0.7922.137 (Linux) or later
  • Update to version 151.0.7922.137/.138 (Mac) or later
  • Update to version 151.0.7922.137/.138 (Windows) or later

Vulnerability Identifier


Source


Related Link

微軟每月保安更新 (2026年8月)

微軟每月保安更新 (2026年8月)

發佈日期: 2026年08月12日

微軟已為產品提供本月保安更新:

 

受影響產品風險程度影響備註
視窗高度風險 高度風險權限提升
阻斷服務
遠端執行程式碼
資料洩露
篡改
繞過保安限制
仿冒

CVE-2026-68820 正在被廣泛利用。已在本機通過身分驗證的攻擊者可在受影響的系統上執行特製應用程式,以觸發競爭條件。成功利用此漏洞後,攻擊者可取得 SYSTEM 權限,而攻擊過程無需用戶互動。因此,該漏洞的風險等級被評定為高度風險。

 

CVE-2026-62832 的概念驗證碼已被公開。持有另一個本機帳戶憑證並已通過身分驗證的攻擊者,可執行特製應用程式以載入其他用戶的登錄配置單元。成功利用此漏洞後,攻擊者可存取或修改其他用戶的資料,並取得管理員權限,而攻擊過程無需用戶互動。因此,該漏洞的風險等級被評定為中度風險。

 

CVE-2026-72971 的概念驗證碼已被公開。Windows Container Isolation FS Filter Driver(unionfs.sys)在存取檔案前未有妥善解析連結,可讓已獲授權的攻擊者在本機進行竄改。因此,該漏洞的風險等級被評定為中度風險。

延伸安全性更新 (ESU)中度風險 中度風險權限提升
阻斷服務
遠端執行程式碼
資料洩露
篡改
繞過保安限制
仿冒
 
開發者工具中度風險 中度風險繞過保安限制
資料洩露
遠端執行程式碼
阻斷服務
權限提升
 
微軟 Office中度風險 中度風險遠端執行程式碼
仿冒
權限提升
資料洩露
篡改
 
Azure中度風險 中度風險權限提升
資料洩露
遠端執行程式碼
仿冒
 
Device中度風險 中度風險權限提升 
微軟 Dynamics中度風險 中度風險資料洩露
遠端執行程式碼
權限提升
 
Server Software中度風險 中度風險權限提升
阻斷服務
遠端執行程式碼
仿冒
繞過保安限制
 
System Center中度風險 中度風險資料洩露 
SQL Server中度風險 中度風險遠端執行程式碼 
Apps中度風險 中度風險權限提升 
開源軟件中度風險 中度風險權限提升 
瀏覽器中度風險 中度風險遠端執行程式碼 

 

「極高度風險」產品數目:0

「高度風險」產品數目:1

「中度風險」產品數目:12

「低度風險」產品數目:0

整體「風險程度」評估:高度風險


影響

  • 權限提升
  • 阻斷服務
  • 遠端執行程式碼
  • 資料洩露
  • 篡改
  • 繞過保安限制
  • 仿冒

受影響之系統或技術

  • 視窗
  • 延伸安全性更新 (ESU)
  • 開發者工具
  • 微軟 Office
  • Azure
  • Device
  • 微軟 Dynamics
  • Server Software
  • System Center
  • SQL Server
  • Apps
  • 開源軟件
  • 瀏覽器

解決方案

在安裝軟體之前,請先瀏覽軟體供應商之網站,以獲得更多詳細資料。

  • 安裝軟件供應商提供的修補程式。

漏洞識別碼


資料來源


相關連結

Microsoft Monthly Security Update (August 2026)

Microsoft Monthly Security Update (August 2026)

Release Date: 12 Aug 2026

Microsoft has released monthly security update for their products:

 

Vulnerable ProductRisk LevelImpactsNotes
WindowsHigh Risk High RiskElevation of Privilege
Denial of Service
Remote Code Execution
Information Disclosure
Data Manipulation
Security Restriction Bypass
Spoofing

CVE-2026-68820 is being exploited in the wild. A locally authenticated attacker could run a specially crafted application on an affected system to trigger a race condition. Successful exploitation could allow the attacker to gain SYSTEM privileges. User interaction is not required. Hence, the risk level of this vulnerability is rated as High Risk.

 

Proof of Concept exploit code is publicly available for CVE-2026-62832. An authenticated attacker who has credentials for another local account could run a specially crafted application to load another user's registry hive. Successful exploitation could allow the attacker to access or modify another user's data and gain administrator privileges. User interaction is not required. Hence, the risk level of this vulnerability is rated as Medium Risk.

 

Proof of Concept exploit code is publicly available for CVE-2026-72971. Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally. Hence, the risk level of this vulnerability is rated as Medium Risk.

Extended Security Updates (ESU)Medium Risk Medium RiskElevation of Privilege
Denial of Service
Remote Code Execution
Information Disclosure
Data Manipulation
Security Restriction Bypass
Spoofing
 
Developer ToolsMedium Risk Medium RiskSecurity Restriction Bypass
Information Disclosure
Remote Code Execution
Denial of Service
Elevation of Privilege
 
Microsoft OfficeMedium Risk Medium RiskRemote Code Execution
Spoofing
Elevation of Privilege
Information Disclosure
Data Manipulation
 
AzureMedium Risk Medium RiskElevation of Privilege
Information Disclosure
Remote Code Execution
Spoofing
 
DeviceMedium Risk Medium RiskElevation of Privilege 
Microsoft DynamicsMedium Risk Medium RiskInformation Disclosure
Remote Code Execution
Elevation of Privilege
 
Server SoftwareMedium Risk Medium RiskElevation of Privilege
Denial of Service
Remote Code Execution
Spoofing
Security Restriction Bypass
 
System CenterMedium Risk Medium RiskInformation Disclosure 
SQL ServerMedium Risk Medium RiskRemote Code Execution 
AppsMedium Risk Medium RiskElevation of Privilege 
Open Source SoftwareMedium Risk Medium RiskElevation of Privilege 
BrowserMedium Risk Medium RiskRemote Code Execution 

 

Number of 'Extremely High Risk' product(s): 0

Number of 'High Risk' product(s): 1

Number of 'Medium Risk' product(s): 12

Number of 'Low Risk' product(s): 0

Evaluation of overall 'Risk Level': High Risk


Impact

  • Elevation of Privilege
  • Denial of Service
  • Remote Code Execution
  • Information Disclosure
  • Data Manipulation
  • Security Restriction Bypass
  • Spoofing

System / Technologies affected

  • Windows
  • Extended Security Updates (ESU)
  • Developer Tools
  • Microsoft Office
  • Azure
  • Device
  • Microsoft Dynamics
  • Server Software
  • System Center
  • SQL Server
  • Apps
  • Open Source Software
  • Browser

Solutions

Before installation of the software, please visit the vendor web-site for more details.

  •  Apply fixes issued by the vendor.

Vulnerability Identifier


Source


Related Link

思科產品多個漏洞

思科產品多個漏洞 發佈日期: 2026年08月12日 於思科產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況及敏感資料洩露。   注意: CVE-2026-20349 正在被廣泛利用。 如果已啟用 Remote Access SSL VPN 服務,遠端攻擊者...