2026年8月11日星期二

F5 產品阻斷服務漏洞

F5 產品阻斷服務漏洞

發佈日期: 2026年08月11日

於 F5 產品發現一個漏洞。遠端攻擊者可利用這漏洞,於目標系統觸發阻斷服務狀況。

 

注意:

受影響之系統或技術暫無可修補 CVE-2026-42534 的修補程式。因此,風險等級評為高度風險。

 

影響

  • 阻斷服務

受影響之系統或技術

BIG-IP Next SPK

 

  • 2.0.0 - 2.0.3
  • 1.7.0 - 1.9.2

 

BIG-IP Next CNF

 

  • 2.0.0 - 2.3.2
  • 1.1.0 - 1.4.3

 

BIG-IP Next for Kubernetes

 

  • 2.0.0 - 2.3.2

 

BIG-IP DNS

 

  • 21.1.03
  • 17.5.0 - 17.5.13
  • 17.1.0 - 17.1.33
 
 

解決方案

注意﹕暫無可用的修補程式

 

臨時處理方法:

從以下臨時處理方法以減輕攻擊:

 

  • 限制上游 DNS 伺服器:確保 BIG-IP 系統上的 DNS 快取解析器只向受信任的內部 DNS 伺服器發出查詢。

  • 使用基於傳輸層安全性(TLS)的 DNS:如系統支援,請設定透過 TLS 進行 DNS 解析,以防止 DNS 傳輸路徑遭受中間人(MITM)攻擊,避免攻擊者注入經特製的 DNS 擴充機制(EDNS)回應。

  • 網絡分隔:將 DNS 解析路徑隔離,確保上游 DNS 伺服器位於受信任且受保護的網絡區段內。

  • 限制 DNS 功能:如不需要配置 DNS 或 DNS 快取解析功能,請將其停用,以徹底消除相關攻擊面。

 

請瀏覽供應商之網站,以獲得更多詳細資料。

 

應用供應商提供的臨時處理方法:


漏洞識別碼


資料來源


相關連結

https://my.f5.com/manage/s/article/K000162784

F5 Products Denial of Service Vulnerability

F5 Products Denial of Service Vulnerability

A vulnerability was identified in F5 Products. A remote attacker could exploit this vulnerability to trigger denial of service condition on the targeted system.

 

Note:

No patch is currently available for CVE-2026-42534 of the affected products. Hence, the risk level is rated as High Risk.


Impact

  • Denial of Service

System / Technologies affected

BIG-IP Next SPK

 

  • 2.0.0 - 2.0.3
  • 1.7.0 - 1.9.2

 

BIG-IP Next CNF

 

  • 2.0.0 - 2.3.2
  • 1.1.0 - 1.4.3

 

BIG-IP Next for Kubernetes

 

  • 2.0.0 - 2.3.2

 

BIG-IP DNS

 

  • 21.1.03
  • 17.5.0 - 17.5.13
  • 17.1.0 - 17.1.33
 

Solutions

Notes: No patch is currently available.

 

Workaround:

Mitigate the vulnerability of attacks by following workaround:

 

  • Restrict upstream DNS servers. Ensure that the DNS cache resolvers on your BIG-IP systems are configured to query only trusted, internal DNS servers.
  • Use DNS over Transport Layer Security (TLS). If supported, configure DNS resolution over TLS to prevent man-in-the-middle (MITM) attacks on the DNS path that could inject crafted Extension Mechanisms for DNS (EDNS) responses.
  • Network segmentation: Isolate the DNS resolution path so that upstream DNS servers are on a trusted, protected network segment.
  • Limit DNS features: If provisioning DNS or DNS cache resolution are not required, disable them to eliminate the attack surface entirely.

 

Please visit the vendor web-site for more details.

 

Apply workarounds issued by the vendor:


Vulnerability Identifier


Source


Related Link

https://my.f5.com/manage/s/article/K000162784

2026年8月10日星期一

PostgreSQL 多個漏洞

PostgreSQL 多個漏洞

發佈日期: 2026年08月10日

於 PostgreSQL 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發權限提升、遠端執行任意程式碼、阻斷服務狀況、資料篡改及洩露敏感資料。


影響

  • 遠端執行程式碼
  • 資料洩露
  • 權限提升
  • 阻斷服務
  • 篡改

受影響之系統或技術

  • PostgreSQL 18.4 之前的版本
  • PostgreSQL 17.10 之前的版本
  • PostgreSQL 16.14 之前的版本
  • PostgreSQL 15.18 之前的版本
  • PostgreSQL 14.23 之前的版本

解決方案

在安裝軟體之前,請先瀏覽軟體供應商之網站,以獲得更多詳細資料。

 

  • 軟件供應商已提供修補程式:
  • 升級至PostgreSQL 18.4 版本
  • 升級至PostgreSQL 17.10 版本
  • 升級至PostgreSQL 16.14 版本
  • 升級至PostgreSQL 15.18 版本
  • 升級至PostgreSQL 14.23 版本

漏洞識別碼


資料來源


相關連結

https://www.postgresql.org/about/news/postgresql-184-1710-1614-1518-and-1423-released-3297/

PostgreSQL Multiple Vulnerabilities

PostgreSQL Multiple Vulnerabilities

Release Date: 10 Aug 2026

Multiple vulnerabilities were identified in PostgreSQL. A remote attacker could exploit some of these vulnerabilities to trigger elevation of privilege, remote code execution, denial of service condition, data manipulation and sensitive information disclosure on the targeted system.


Impact

  • Remote Code Execution
  • Information Disclosure
  • Elevation of Privilege
  • Denial of Service
  • Data Manipulation

System / Technologies affected

  • PostgreSQL versions prior to 18.4
  • PostgreSQL versions prior to 17.10
  • PostgreSQL versions prior to 16.14
  • PostgreSQL versions prior to 15.18
  • PostgreSQL versions prior to 14.23

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

 

  • The vendor has issued fixes:
  • Update to PostgreSQL version 18.4
  • Update to PostgreSQL version 17.10
  • Update to PostgreSQL version 16.14
  • Update to PostgreSQL version 15.18
  • Update to PostgreSQL version 14.23

Vulnerability Identifier


Source


Related Link

https://www.postgresql.org/about/news/postgresql-184-1710-1614-1518-and-1423-released-3297/

2026年8月8日星期六

蘋果 macOS 繞過保安限制漏洞

蘋果 macOS 繞過保安限制漏洞

發佈日期: 2026年08月07日

於蘋果 macOS 發現一個漏洞。遠端攻擊者可利用此漏洞,於目標系統觸發繞過保安限制。


影響

  • 繞過保安限制

受影響之系統或技術

  • macOS Sequoia 15.7.9 以前的版本
  • macOS Sonoma 14.8.9 以前的版本
  • macOS Tahoe 26.6.1 以前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝供應商提供的修補程式:

 

  • macOS Sequoia 15.7.9
  • macOS Sonoma 14.8.9
  • macOS Tahoe 26.6.1

漏洞識別碼


資料來源


相關連結

Apple macOS Security Restriction Bypass Vulnerability

Apple macOS Security Restriction Bypass Vulnerability

Release Date: 7 Aug 2026

A vulnerability has been identified in Apple macOS. A remote attacker could exploit this vulnerability to trigger security restriction bypass on the targeted system.


Impact

  • Security Restriction Bypass

System / Technologies affected

  • Versions prior to macOS Sequoia 15.7.9
  • Versions prior to macOS Sonoma 14.8.9
  • Versions prior to macOS Tahoe 26.6.1

Solutions

Before installation of the software, please visit the vendor web-site for more details.

Apply fixes issued by the vendor:

 

  • macOS Sequoia 15.7.9
  • macOS Sonoma 14.8.9
  • macOS Tahoe 26.6.1

Vulnerability Identifier


Source


Related Link

Google Chrome 多個漏洞

Google Chrome 多個漏洞

發佈日期: 2026年08月07日

於 Google Chrome 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發洩露敏感資料、阻斷服務狀況、遠端執行任意程式碼、繞過保安限制及資料篡改。


影響

  • 阻斷服務
  • 篡改
  • 繞過保安限制
  • 遠端執行程式碼
  • 資料洩露

受影響之系統或技術

  • Google Chrome 151.0.7922.108 (Linux) 之前的版本
  • Google Chrome 151.0.7922.108/.109 (Mac) 之前的版本
  • Google Chrome 151.0.7922.108/.109 (Windows) 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 151.0.7922.108 (Linux) 或之後版本
  • 更新至 151.0.7922.108/.109 (Mac) 或之後版本
  • 更新至 151.0.7922.108/.109 (Windows) 或之後版本

漏洞識別碼


資料來源


相關連結

Google Chrome Multiple Vulnerabilities

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities were identified in Google Chrome. A remote attacker could exploit some of these vulnerabilities to trigger sensitive information disclosure, denial of service condition, remote code execution, security restriction bypass and data manipulation on the targeted system.


Impact

  • Denial of Service
  • Data Manipulation
  • Security Restriction Bypass
  • Remote Code Execution
  • Information Disclosure

System / Technologies affected

  • Google Chrome prior to 151.0.7922.108 (Linux)
  • Google Chrome prior to 151.0.7922.108/.109 (Mac)
  • Google Chrome prior to 151.0.7922.108/.109 (Windows)

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 151.0.7922.108 (Linux) or later
  • Update to version 151.0.7922.108/.109 (Mac) or later
  • Update to version 151.0.7922.108/.109 (Windows) or later

Vulnerability Identifier

Source

Related Link

F5 產品阻斷服務漏洞

F5 產品阻斷服務漏洞 發佈日期: 2026年08月11日 於 F5 產品發現一個漏洞。遠端攻擊者可利用這漏洞,於目標系統觸發阻斷服務狀況。   注意: 受影響之系統或技術暫無可修補 CVE-2026-42534 的修補程式。因此,風險等級評為高度風險。   影響 阻斷服務 受影...