2026年9月23日星期三

F5 BIG-IP 遠端執行程式碼漏洞

F5 BIG-IP 遠端執行程式碼漏洞

發佈日期: 20260923

F5 BIG-IP 發現一個漏洞。遠端攻擊者可利用這漏洞,於目標系統觸發遠端執行程式碼狀況。

 

注意:

CVE-2026-94127 正被廣泛利用。此漏洞僅在 BIG-IP APM 配置為 OAuth 授權伺服器時才會出現。因此,風險等級被評為高度風險。

 


影響

  • 遠端執行程式碼

受影響之系統或技術

BIG-IP APM

 

  • 17.1.0 - 17.1.3 版本
  • 17.5.0 - 17.5.1版本
  • 21.1.0 版本

 


解決方案

請瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的臨時處理方法:


漏洞識別碼


資料來源


相關連結

 


F5 BIG-IP Remote Code Execution Vulnerability

F5 BIG-IP Remote Code Execution Vulnerability

Release Date: 23 Sep 2026

A vulnerability was identified in F5 BIG-IP. A remote attacker could exploit this vulnerability to trigger remote code execution on the targeted system.

 

Note:

CVE-2026-94127  is being exploited in the wild. This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Hence, the risk level is rated as High Risk.


Impact

  • Remote Code Execution

System / Technologies affected

BIG-IP APM

 

  • Versions 17.1.0 - 17.1.3
  • Versions 17.5.0 - 17.5.1
  • Versions 21.1.0

 


Solutions

Please visit the vendor web-site for more details.

 

Apply workarounds issued by the vendor:


Vulnerability Identifier


Source


Related Link

 


Google Chrome 多個漏洞

Google Chrome 多個漏洞

發佈日期: 20260923

Google Chrome 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、繞過保安限制、敏感資料洩露、彷冒跨網站指令碼、資料篡改及遠端執行任意程式碼。


影響

  • 遠端執行程式碼
  • 繞過保安限制
  • 阻斷服務
  • 資料洩露
  • 仿冒
  • 跨網站指令碼
  • 篡改

受影響之系統或技術

  • Google Chrome 154.0.8037.57 (Linux) 之前的版本
  • Google Chrome 154.0.8037.57/.58 (Mac) 之前的版本
  • Google Chrome 154.0.8037.57/.58 (Windows) 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • Google Chrome 154.0.8037.57 (Linux) 或之後版本
  • Google Chrome 154.0.8037.57/.58 (Mac) 或之後版本
  • Google Chrome 154.0.8037.57/.58 (Windows) 或之後版本

漏洞識別碼


資料來源


相關連結

 


Google Chrome Multiple Vulnerabilities

Google Chrome Multiple Vulnerabilities

Release Date: 23 Sep 2026

Multiple vulnerabilities were identified in Google Chrome. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, security restriction bypass, sensitive information disclosure, spoofing, cross-site scripting, data manipulation and remote code execution on the targeted system.


Impact

  • Remote Code Execution
  • Security Restriction Bypass
  • Denial of Service
  • Information Disclosure
  • Spoofing
  • Cross-Site Scripting
  • Data Manipulation

System / Technologies affected

  • Google Chrome prior to 154.0.8037.57 (Linux)
  • Google Chrome prior to 154.0.8037.57/.58 (Mac)
  • Google Chrome prior to 154.0.8037.57/.58 (Windows)

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Google Chrome 154.0.8037.57 (Linux) or later
  • Google Chrome 154.0.8037.57/.58 (Mac) or later
  • Google Chrome 154.0.8037.57/.58 (Windows) or later

Vulnerability Identifier


Source


Related Link

 


2026年9月22日星期二

WordPress 多個漏洞

WordPress 多個漏洞

發佈日期: 20260922

WordPress發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發跨網站指令碼、繞過保安限制、敏感資料洩露、遠端執行任意程式碼及資料篡改。

 

注意:

針對 WordPress 新發現的跨網站請求偽造(CSRF)漏洞「Click2Shell」,已有概念驗證程式碼(PoC)被公開。此漏洞可形成一條需預先身份驗證的遠端程式碼執行攻擊鏈,讓攻擊者從 WordPress.org 官方目錄安裝任何佈景主題,並執行任意 PHP 檔案。需要注意雖然攻擊者無需進行身份驗證,但要成功利用 Click2Shell 漏洞,網站管理員必須已登入並瀏覽特製的 URL。因此,風險等級被評為高度風險。


影響

  • 遠端執行程式碼
  • 資料洩露
  • 跨網站指令碼
  • 篡改
  • 繞過保安限制

受影響之系統或技術

  • WordPress 4.7
  • WordPress 4.8
  • WordPress 4.9
  • WordPress 5.0
  • WordPress 5.1
  • WordPress 5.2
  • WordPress 5.3
  • WordPress 5.4
  • WordPress 5.5
  • WordPress 5.6
  • WordPress 5.7
  • WordPress 5.8
  • WordPress 5.9
  • WordPress 6.0
  • WordPress 6.1
  • WordPress 6.2
  • WordPress 6.3
  • WordPress 6.4
  • WordPress 6.5
  • WordPress 6.6
  • WordPress 6.7
  • WordPress 6.8
  • WordPress 6.9
  • WordPress 7.0

請參閱以下連結:

https://wordpress.org/documentation/wordpress-version/version-7-1-1/


解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:

 

https://wordpress.org/documentation/wordpress-version/version-7-1-1/


漏洞識別碼

Note: No CVE information is available for this vulnerability


資料來源


相關連結

 


WordPress Multiple Vulnerabilities

WordPress Multiple Vulnerabilities

Release Date: 22 Sep 2026

Multiple vulnerabilities were identified in WordPress. A remote attacker could exploit some of these vulnerabilities to trigger cross-site scripting, security restriction bypass, sensitive information disclosure, remote code execution and data manipulation on the targeted system.

 

Note:

A proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed 'Click2Shell'. It is a pre-authenticated remote code execution chain that allows an attacker to install any theme in the official WordPress.org catalog and run an arbitrary PHP file. It should be noted that although the attacker does not need to authenticate, the Click2Shell exploit requires a site administrator who is already logged in to visit a specially crafted URL. Hence, the risk level is rated as High Risk.


Impact

  • Remote Code Execution
  • Information Disclosure
  • Cross-Site Scripting
  • Data Manipulation
  • Security Restriction Bypass

System / Technologies affected

  • WordPress 4.7
  • WordPress 4.8
  • WordPress 4.9
  • WordPress 5.0
  • WordPress 5.1
  • WordPress 5.2
  • WordPress 5.3
  • WordPress 5.4
  • WordPress 5.5
  • WordPress 5.6
  • WordPress 5.7
  • WordPress 5.8
  • WordPress 5.9
  • WordPress 6.0
  • WordPress 6.1
  • WordPress 6.2
  • WordPress 6.3
  • WordPress 6.4
  • WordPress 6.5
  • WordPress 6.6
  • WordPress 6.7
  • WordPress 6.8
  • WordPress 6.9
  • WordPress 7.0

Please refer to the link below:

https://wordpress.org/documentation/wordpress-version/version-7-1-1/


Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:

 

https://wordpress.org/documentation/wordpress-version/version-7-1-1/


Vulnerability Identifier

Note: No CVE information is available for this vulnerability


Source


Related Link

 


2026年9月21日星期一

F5 BIG-IP 阻斷服務漏洞

F5 BIG-IP 阻斷服務漏洞

發佈日期: 20260921

風險: 高度風險

F5 BIG-IP 發現一個漏洞。遠端攻擊者可利用這漏洞,於目標系統觸發阻斷服務狀況。

 

注意:

暫無可修補 CVE-2026-11622 的修補程式。因此,風險等級被評為高度風險。

 


影響

  • 阻斷服務

受影響之系統或技術

BIG-IP (DNS)

 

  • 17.1.0 - 17.1.3 版本
  • 17.5.0 - 17.5.1 版本
  • 21.1.0 版本

 


解決方案

處理方法:

透過以下方法以緩解此漏洞的影響:

 

  • validating resolver DNS cache 中停用 DNSSEC
  • 切換至 Resolver Transparent cache 類型
  • DNS profile 中停用 Use BIND Server on BIG-IP 選項

 

請瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的臨時處理方法:


漏洞識別碼


資料來源


相關連結

 


F5 BIG-IP 遠端執行程式碼漏洞

F5 BIG-IP 遠端執行程式碼漏洞 發佈日期 : 2026 年 09 月 23 日 於 F5 BIG-IP 發現一個漏洞。遠端攻擊者可利用這漏洞,於目標系統觸發遠端執行程式碼狀況。   注意: CVE-2026-94127 正被廣泛利用。此漏洞僅在 B...