2026年8月24日星期一

Zimbra多個漏洞

Zimbra多個漏洞

發佈日期: 2026年08月24日

於 Zimbra 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發跨網站指令碼、洩露敏感資料、繞過保安限制及遠端執行任意程式碼。 

 

注意:

CVE-2026-73570 正在被廣泛利用。此漏洞可能允許未經身份驗證的攻擊者發送經過特殊設計的 SMTP 請求,當系統安裝了可選的 zimbra-snmp 套件且啟用了 SNMP 通知時,此攻擊可能導致攻擊者以 Zimbra 使用者身分執行任意的作業系統指令。因此,風險等級被評為高度風險。


影響

  • 跨網站指令碼
  • 資料洩露
  • 遠端執行程式碼
  • 繞過保安限制

受影響之系統或技術

  • 10.1.20 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝軟件供應商提供的修補程式:

  • 版本 10.1.20

漏洞識別碼


資料來源


相關連結

Zimbra Multiple Vulnerabilities

Zimbra Multiple Vulnerabilities

Release Date: 24 Aug 2026

Multiple vulnerabilities were identified in Zimbra. A remote attacker could exploit some of these vulnerabilities to trigger cross-site scripting, sensitive information disclosure, security restriction bypass and remote code execution on the targeted system.

 

Note:


Impact

  • Cross-Site Scripting
  • Information Disclosure
  • Remote Code Execution
  • Security Restriction Bypass

System / Technologies affected

  • Prior to Version 10.1.20

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:

  • Version 10.1.20

Vulnerability Identifier


Source


Related Link

Microsoft Edge 多個漏洞

Microsoft Edge 多個漏洞

發佈日期: 2026年08月24日

於 Microsoft Edge 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、繞過保安限制、敏感資料洩露及遠端執行任意程式碼。


Microsoft Edge Multiple Vulnerabilities

Microsoft Edge Multiple Vulnerabilities

Release Date: 24 Aug 2026

Multiple vulnerabilities were identified in Microsoft Edge. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, security restriction bypass, sensitive information disclosure and remote code execution on the targeted system.


2026年8月21日星期五

Google Chrome 多個漏洞

Google Chrome 多個漏洞

發佈日期: 2026年08月21日

於 Google Chrome 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發權限提升、繞過保安限制及遠端執行任意程式碼。


影響

  • 遠端執行程式碼
  • 權限提升
  • 繞過保安限制

受影響之系統或技術

  • Google Chrome 151.0.7922.173 (Android) 之前的版本
  • Google Chrome 151.0.7922.173 (Linux) 之前的版本
  • Google Chrome 151.0.7922.173/.174 (Mac) 之前的版本
  • Google Chrome 151.0.7922.173/.174 (Windows) 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 151.0.7922.173 (Android) 或之後版本
  • 更新至 151.0.7922.173 (Linux) 或之後版本
  • 更新至 151.0.7922.173/.174 (Mac) 或之後版本
  • 更新至 151.0.7922.173/.174 (Windows) 或之後版本

漏洞識別碼


資料來源


相關連結

Google Chrome Multiple Vulnerabilities

Google Chrome Multiple Vulnerabilities

Release Date: 21 Aug 2026

Multiple vulnerabilities were identified in Google Chrome. A remote attacker could exploit some of these vulnerabilities to trigger elevation of privilege, security restriction bypass and remote code execution on the targeted system.


Impact

  • Remote Code Execution
  • Elevation of Privilege
  • Security Restriction Bypass

System / Technologies affected

  • Google Chrome prior to 151.0.7922.173 (Android)
  • Google Chrome prior to 151.0.7922.173 (Linux)
  • Google Chrome prior to 151.0.7922.173/.174 (Mac)
  • Google Chrome prior to 151.0.7922.173/.174 (Windows)

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 151.0.7922.173 (Android) or later
  • Update to version 151.0.7922.173 (Linux) or later
  • Update to version 151.0.7922.173/.174 (Mac) or later
  • Update to version 151.0.7922.173/.174 (Windows) or later

Vulnerability Identifier


Source


Related Link

2026年8月20日星期四

Splunk 產品多個漏洞

Splunk 產品多個漏洞

發佈日期: 2026年08月20日

於 Splunk 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發跨網站指令碼、阻斷服務狀況、權限提升、繞過保安限制、敏感資料洩露及遠端執行任意程式碼。


Zimbra多個漏洞

Zimbra多個漏洞 發佈日期: 2026年08月24日 於 Zimbra 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發跨網站指令碼、洩露敏感資料、繞過保安限制及遠端執行任意程式碼。    注意: CVE-2026-73570 正在被廣泛利用。此漏洞可能允許未經身份驗證...