2026年9月1日星期二

SUSE Linux 內核多個漏洞

SUSE Linux 內核多個漏洞

發佈日期: 2026年09月01日

於 SUSE Linux 內核 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、敏感資料洩露、遠端執行任意程式碼及資料篡改。


影響

  • 阻斷服務
  • 權限提升
  • 遠端執行程式碼
  • 資料洩露
  • 篡改

受影響之系統或技術

  • openSUSE Leap 15.4
  • SUSE Linux Enterprise High Performance Computing 12 SP5
  • SUSE Linux Enterprise High Performance Computing 15 SP4
  • SUSE Linux Enterprise Live Patching 12-SP5
  • SUSE Linux Enterprise Live Patching 15-SP4
  • SUSE Linux Enterprise Micro 5.3
  • SUSE Linux Enterprise Micro 5.4
  • SUSE Linux Enterprise Real Time 15 SP4
  • SUSE Linux Enterprise Server 12 SP5
  • SUSE Linux Enterprise Server 15 SP4
  • SUSE Linux Enterprise Server 16.0
  • SUSE Linux Enterprise Server for SAP Applications 12 SP5
  • SUSE Linux Enterprise Server for SAP Applications 15 SP4
  • SUSE Linux Enterprise Server for SAP applications 16.0
  • SUSE Linux Micro 6.2

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

SUSE Linux Kernel Multiple Vulnerabilities

SUSE Linux Kernel Multiple Vulnerabilities

Release Date: 1 Sep 2026

Multiple vulnerabilities were identified in SUSE Linux Kernel. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, sensitive information disclosure, remote code execution and data manipulation on the targeted system.


Impact

  • Denial of Service
  • Elevation of Privilege
  • Remote Code Execution
  • Information Disclosure
  • Data Manipulation

System / Technologies affected

  • openSUSE Leap 15.4
  • SUSE Linux Enterprise High Performance Computing 12 SP5
  • SUSE Linux Enterprise High Performance Computing 15 SP4
  • SUSE Linux Enterprise Live Patching 12-SP5
  • SUSE Linux Enterprise Live Patching 15-SP4
  • SUSE Linux Enterprise Micro 5.3
  • SUSE Linux Enterprise Micro 5.4
  • SUSE Linux Enterprise Real Time 15 SP4
  • SUSE Linux Enterprise Server 12 SP5
  • SUSE Linux Enterprise Server 15 SP4
  • SUSE Linux Enterprise Server 16.0
  • SUSE Linux Enterprise Server for SAP Applications 12 SP5
  • SUSE Linux Enterprise Server for SAP Applications 15 SP4
  • SUSE Linux Enterprise Server for SAP applications 16.0
  • SUSE Linux Micro 6.2

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

2026年8月31日星期一

PaperCut 多個漏洞

PaperCut 多個漏洞

發佈日期: 2026年08月31日

於PaperCut發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發繞過保安限制及遠端執行程式碼。
 

注意:

CVE-2026-82078 和 CVE-2026-81578 正在被廣泛利用。針對 CVE-2026-82078,在特定條件下,針對管理功能的未經身份驗證的遠端請求,可能在存取驗證檢查完成之前觸發後端操作; 至於 CVE-2026-81578,若攻擊者能操縱系統配置參數,便可在 PaperCut 伺服器進程的保安設定,執行位於應用程式類路徑上的任意 Java 位元組碼。這些漏洞可被串聯利用,以繞過身份驗證並在受影響的伺服器上執行程式碼。


影響

  • 繞過保安限制
  • 遠端執行程式碼

受影響之系統或技術

所有 PaperCut MF 或 NG 版本

 


解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

PaperCut Multiple Vulnerabilities

PaperCut Multiple Vulnerabilities

Release Date: 31 Aug 2026

Multiple vulnerabilities were identified in PaperCut. A remote attacker could exploit these vulnerabilities to trigger security restriction bypass and remote code execution on the targeted system.

 

Note:

CVE-2026-82078 and CVE-2026-81578 are being exploited in the wild. For CVE-2026-82078, under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks; For CVE-2026-81578, if an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process. These vulnerabilities can be chained to bypass authentication and execute code on vulnerable servers.


Impact

  • Security Restriction Bypass
  • Remote Code Execution

System / Technologies affected

All version of PaperCut MF or NG 


Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Microsoft Edge 多個漏洞

Microsoft Edge 多個漏洞

發佈日期: 2026年08月31日

於 Microsoft Edge 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、繞過保安限制、敏感資料洩露、遠端執行任意程式碼、仿冒及資料篡改。


影響

  • 遠端執行程式碼
  • 阻斷服務
  • 繞過保安限制
  • 資料洩露
  • 權限提升
  • 篡改
  • 仿冒

受影響之系統或技術

  • Microsoft Edge 152.0.4191.53 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 152.0.4191.53 或之後版本

漏洞識別碼


資料來源


相關連結

SUSE Linux 內核多個漏洞

SUSE Linux 內核多個漏洞 發佈日期: 2026年09月01日 於 SUSE Linux 內核 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、敏感資料洩露、遠端執行任意程式碼及資料篡改。 影響 阻斷服務 權限提升 遠端執行程式碼 資料洩露 ...