2026年7月22日星期三

Google Chrome 多個漏洞

Google Chrome 多個漏洞

發佈日期: 2026年07月22日

風險: 中度風險

類型: 用戶端 - 瀏覽器

於 Google Chrome 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、繞過保安限制、遠端執行任意程式碼、資料篡改及權限提升。


影響

  • 阻斷服務
  • 權限提升
  • 遠端執行程式碼
  • 篡改
  • 繞過保安限制

受影響之系統或技術

  • Google Chrome 150.0.7871.181 (Linux) 之前的版本
  • Google Chrome 150.0.7871.181/.182 (Mac) 之前的版本
  • Google Chrome 150.0.7871.181/.182 (Windows) 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 150.0.7871.181 (Linux) 或之後版本
  • 更新至 150.0.7871.181/.182 (Mac) 或之後版本
  • 更新至 150.0.7871.181/.182 (Windows) 或之後版本

漏洞識別碼


資料來源


相關連結

Google Chrome Multiple Vulnerabilities

Google Chrome Multiple Vulnerabilities

Release Date: 22 Jul 2026

RISK: Medium Risk

TYPE: Clients - Browsers

Multiple vulnerabilities were identified in Google Chrome. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, security restriction bypass, remote code execution, data manipulation and elevation of privilege on the targeted system.


Impact

  • Denial of Service
  • Elevation of Privilege
  • Remote Code Execution
  • Data Manipulation
  • Security Restriction Bypass

System / Technologies affected

  • Google Chrome prior to 150.0.7871.181 (Linux)
  • Google Chrome prior to 150.0.7871.181/.182 (Mac)
  • Google Chrome prior to 150.0.7871.181/.182 (Windows)

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 150.0.7871.181 (Linux) or later
  • Update to version 150.0.7871.181/.182 (Mac) or later
  • Update to version 150.0.7871.181/.182 (Windows) or later

Vulnerability Identifier


Source


Related Link

Mozilla 產品多個漏洞

Mozilla 產品多個漏洞

發佈日期: 2026年07月22日

風險: 中度風險

類型: 用戶端 - 瀏覽器

於 Mozilla 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、繞過保安限制、敏感資料洩露、遠端執行任意程式碼及彷冒。

 


影響

  • 遠端執行程式碼
  • 繞過保安限制
  • 資料洩露
  • 阻斷服務
  • 權限提升
  • 仿冒

受影響之系統或技術

以下版本之前的版本﹕

 

  • Firefox 153
  • Firefox ESR 115.38
  • Firefox ESR 140.13

解決方案

在安裝軟體之前,請先瀏覽供應商之官方網站,以獲得更多詳細資料。

更新至版本:

 

  • Firefox 153
  • Firefox ESR 115.38
  • Firefox ESR 140.13

漏洞識別碼


資料來源


相關連結

Mozilla Products Multiple Vulnerabilities

Mozilla Products Multiple Vulnerabilities

Release Date: 22 Jul 2026

RISK: Medium Risk

TYPE: Clients - Browsers

Multiple vulnerabilities were identified in Mozilla Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, security restriction bypass, sensitive information disclosure, remote code execution and spoofing on the targeted system.

 


Impact

  • Remote Code Execution
  • Security Restriction Bypass
  • Information Disclosure
  • Denial of Service
  • Elevation of Privilege
  • Spoofing

System / Technologies affected

Versions prior to:

 

  • Firefox 153
  • Firefox ESR 115.38
  • Firefox ESR 140.13

Solutions

Before installation of the software, please visit the vendor web-site for more details.

Apply fixes issued by the vendor:

 

  • Firefox 153
  • Firefox ESR 115.38
  • Firefox ESR 140.13

Vulnerability Identifier


Source


Related Link

甲骨文產品多個漏洞

甲骨文產品多個漏洞

發佈日期: 2026年07月22日

風險: 中度風險

類型: 伺服器 - 數據庫伺服器

於甲骨文產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發跨網站指令碼、阻斷服務狀況、權限提升、繞過保安限制、敏感資料洩露、遠端執行任意程式碼、資料篡改及彷冒。


影響

  • 仿冒
  • 跨網站指令碼
  • 權限提升
  • 繞過保安限制
  • 資料洩露
  • 篡改
  • 阻斷服務
  • 遠端執行程式碼

受影響之系統或技術

  • Oracle Database
  • Oracle E-Business Suite
  • Oracle Java SE
  • Oracle MySQL
  • Oracle Virtualization
  • Oracle WebLogic Server

 

有關其他 甲骨文 產品,請參閱以下連結:

https://www.oracle.com/security-alerts/cpujul2026.html


解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:

 

https://www.oracle.com/security-alerts/cpujul2026.html


漏洞識別碼


資料來源


相關連結

Oracle Products Multiple Vulnerabilities

Oracle Products Multiple Vulnerabilities

Release Date: 22 Jul 2026

RISK: Medium Risk

TYPE: Servers - Database Servers

Multiple vulnerabilities were identified in Oracle Products. A remote attacker could exploit some of these vulnerabilities to trigger cross-site scripting, denial of service condition, elevation of privilege, security restriction bypass, sensitive information disclosure, remote code execution, data manipulation and spoofing on the targeted system.


Impact

  • Spoofing
  • Cross-Site Scripting
  • Elevation of Privilege
  • Security Restriction Bypass
  • Information Disclosure
  • Data Manipulation
  • Denial of Service
  • Remote Code Execution

System / Technologies affected

  • Oracle Database
  • Oracle E-Business Suite
  • Oracle Java SE
  • Oracle MySQL
  • Oracle Virtualization
  • Oracle WebLogic Server

 

For other Oracle products, please refer to the link below:

https://www.oracle.com/security-alerts/cpujul2026.html


Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:

 

https://www.oracle.com/security-alerts/cpujul2026.html


Vulnerability Identifier


Source


Related Link

2026年7月20日星期一

Microsoft Edge 多個漏洞

Microsoft Edge 多個漏洞

發佈日期: 2026年07月20日

風險: 中度風險

類型: 用戶端 - 瀏覽器

於 Microsoft Edge 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、遠端執行任意程式碼、洩露敏感資料、資料篡改及繞過保安限制。


影響

  • 遠端執行程式碼
  • 阻斷服務
  • 資料洩露
  • 繞過保安限制
  • 篡改

受影響之系統或技術

  • Microsoft Edge 150.0.4078.83 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 150.0.4078.83 或之後版本

漏洞識別碼


資料來源


相關連結

Microsoft Edge Multiple Vulnerabilities

Microsoft Edge Multiple Vulnerabilities

Release Date: 20 Jul 2026

RISK: Medium Risk

TYPE: Clients - Browsers

Multiple vulnerabilities were identified in Microsoft Edge. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, remote code execution, sensitive information disclosure, data manipulation and security restriction bypass on the targeted system.


Impact

  • Remote Code Execution
  • Denial of Service
  • Information Disclosure
  • Security Restriction Bypass
  • Data Manipulation

System / Technologies affected

  • Microsoft Edge version prior to 150.0.4078.83

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 150.0.4078.83 or later

Vulnerability Identifier


Source


Related Link

WordPress 多個漏洞

WordPress 多個漏洞

發佈日期: 2026年07月20日

風險: 高度風險

類型: 伺服器 - 互聯網應用伺服器

於WordPress發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行程式碼、敏感資料洩露及資料篡改。

 

注意:

CVE-2026-63030 和 CVE-2026-60137 的概念驗證碼已被公開。攻擊者可將這些漏洞串聯利用,對運行 6.9.x 及 7.0.x 版本的 WordPress 安裝實例,實現認證前遠端程式碼執行。


影響

  • 遠端執行程式碼
  • 資料洩露
  • 篡改

受影響之系統或技術

  • WordPress 6.8
  • WordPress 6.9
  • WordPress 7.1

請參閱以下連結:

https://wordpress.org/news/2026/07/wordpress-7-0-2-release/


解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:

 

https://wordpress.org/news/2026/07/wordpress-7-0-2-release/


漏洞識別碼


資料來源


相關連結

WordPress Multiple Vulnerabilities

WordPress Multiple Vulnerabilities

Release Date: 20 Jul 2026

RISK: High Risk

TYPE: Servers - Internet App Servers

Multiple vulnerabilities were identified in WordPress. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution,  sensitive information disclosure and data manipulation on the targeted system.

 

Note:

Proof-of-concept code is publicly available for CVE-2026-63030 and CVE-2026-60137. Attacker can be chained together to achieve pre-authentication remote code execution against WordPress installs running versions 6.9.x and 7.0.x.


Impact

  • Remote Code Execution
  • Information Disclosure
  • Data Manipulation

System / Technologies affected

  • WordPress 6.8
  • WordPress 6.9
  • WordPress 7.1

Please refer to the link below:

https://wordpress.org/news/2026/07/wordpress-7-0-2-release/


Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:

 

https://wordpress.org/news/2026/07/wordpress-7-0-2-release/


Vulnerability Identifier


Source


Related Link

2026年7月17日星期五

Google Chrome 多個漏洞

Google Chrome 多個漏洞

發佈日期: 2026年07月17日

風險: 中度風險

類型: 用戶端 - 瀏覽器

於 Google Chrome 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、洩露敏感資料及資料篡改。


影響

  • 阻斷服務
  • 資料洩露
  • 篡改

受影響之系統或技術

  • Google Chrome 150.0.7871.128 (Linux) 之前的版本
  • Google Chrome 150.0.7871.128/.129 (Mac) 之前的版本
  • Google Chrome 150.0.7871.128/.129 (Windows) 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 150.0.7871.128 (Linux) 或之後版本
  • 更新至 150.0.7871.128/.129 (Mac) 或之後版本
  • 更新至 150.0.7871.128/.129 (Windows) 或之後版本

漏洞識別碼


資料來源


相關連結

Google Chrome Multiple Vulnerabilities

Google Chrome Multiple Vulnerabilities

Release Date: 17 Jul 2026

RISK: Medium Risk

TYPE: Clients - Browsers

Multiple vulnerabilities were identified in Google Chrome. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, sensitive information disclosure and data manipulation on the targeted system.


Impact

  • Denial of Service
  • Information Disclosure
  • Data Manipulation

System / Technologies affected

  • Google Chrome prior to 150.0.7871.128 (Linux)
  • Google Chrome prior to 150.0.7871.128/.129 (Mac)
  • Google Chrome prior to 150.0.7871.128/.129 (Windows)

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 150.0.7871.128 (Linux) or later
  • Update to version 150.0.7871.128/.129 (Mac) or later
  • Update to version 150.0.7871.128/.129 (Windows) or later

Vulnerability Identifier


Source


Related Link

IBM WebSphere 產品繞過保安限制漏洞

IBM WebSphere 產品繞過保安限制漏洞

發佈日期: 2026年07月17日

風險: 中度風險

類型: 伺服器 - 互聯網應用伺服器

於 IBM WebSphere 產品發現一個漏洞。遠端攻擊者可利用這個漏洞,於目標系統觸發繞過保安限制。


影響

  • 繞過保安限制

受影響之系統或技術

  • IBM WebSphere Application Server - 8.5
  • IBM WebSphere Application Server - 9.0
  • IBM WebSphere Application Server - Liberty - 17.0.0.3 - 26.0.0.7

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

IBM WebSphere Products Security Restriction Bypass Vulnerability

IBM WebSphere Products Security Restriction Bypass Vulnerability

Release Date: 17 Jul 2026

RISK: Medium Risk

TYPE: Servers - Internet App Servers

A vulnerability was identified in IBM WebSphere Products. A remote attacker could exploit this vulnerability to trigger security restriction bypass on the targeted system.


Impact

  • Security Restriction Bypass

System / Technologies affected

  • IBM WebSphere Application Server - 8.5
  • IBM WebSphere Application Server - 9.0
  • IBM WebSphere Application Server - Liberty - 17.0.0.3 - 26.0.0.7

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

2026年7月16日星期四

Google Chrome 多個漏洞

Google Chrome 多個漏洞

發佈日期: 2026年07月16日

風險: 中度風險

類型: 用戶端 - 瀏覽器

於 Google Chrome 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、遠端執行任意程式碼及繞過保安限制。


影響

  • 阻斷服務
  • 遠端執行程式碼
  • 繞過保安限制

受影響之系統或技術

  • Google Chrome 150.0.7871.124 (Linux) 之前的版本
  • Google Chrome 150.0.7871.124/.125 (Mac) 之前的版本
  • Google Chrome 150.0.7871.124/.125 (Windows) 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 150.0.7871.124 (Linux) 或之後版本
  • 更新至 150.0.7871.124/.125 (Mac) 或之後版本
  • 更新至 150.0.7871.124/.125 (Windows) 或之後版本

漏洞識別碼


資料來源


相關連結

Google Chrome Multiple Vulnerabilities

Google Chrome Multiple Vulnerabilities

Release Date: 16 Jul 2026

RISK: Medium Risk

TYPE: Clients - Browsers

Multiple vulnerabilities were identified in Google Chrome. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, remote code execution and security restriction bypass on the targeted system.


Impact

  • Denial of Service
  • Remote Code Execution
  • Security Restriction Bypass

System / Technologies affected

  • Google Chrome prior to 150.0.7871.124 (Linux)
  • Google Chrome prior to 150.0.7871.124/.125 (Mac)
  • Google Chrome prior to 150.0.7871.124/.125 (Windows)

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 150.0.7871.124 (Linux) or later
  • Update to version 150.0.7871.124/.125 (Mac) or later
  • Update to version 150.0.7871.124/.125 (Windows) or later

Vulnerability Identifier


Source


Related Link

三星產品多個漏洞

三星產品多個漏洞

發佈日期: 2026年07月16日

風險: 中度風險

類型: 操作系統 - 流動裝置及操作系統

於三星產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發繞過保安限制、敏感資料洩露、遠端執行任意程式碼及資料篡改。


Samsung Products Multiple Vulnerabilities

Samsung Products Multiple Vulnerabilities

Release Date: 16 Jul 2026

RISK: Medium Risk

TYPE: Operating Systems - Mobile & Apps

Multiple vulnerabilities were identified in Samsung Products. A remote attacker could exploit some of these vulnerabilities to trigger security restriction bypass, sensitive information disclosure, remote code execution and data manipulation on the targeted system.

 


Zoom 產品多個漏洞

Zoom 產品多個漏洞

發佈日期: 2026年07月16日

風險: 中度風險

類型: 用戶端 - 辦公室應用

於 Zoom 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發權限提升及繞過保安限制。


影響

  • 權限提升
  • 繞過保安限制

受影響之系統或技術

  • Zoom Rooms for Windows 7.1.0 之前的版本
  • Zoom Workplace for Windows 7.0.5 之前的版本
  • Zoom Workplace VDI Client for Windows 在各自分支中低於 6.5.18, 6.6.15 和 7.0.10 的版本
  • Zoom Workplace VDI plugin for Windows 在各自分支中低於 6.5.17 和 6.6.14 的版本
  • Zoom Remote Control for Zoom Contact Center for Windows 7.0.0 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之官方網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

 


漏洞識別碼


資料來源


相關連結

Zoom Products Multiple Vulnerabilities

Zoom Products Multiple Vulnerabilities

Release Date: 16 Jul 2026

RISK: Medium Risk

TYPE: Clients - Productivity Products

Multiple vulnerabilities were identified in Zoom Products. A remote attacker could exploit some of these vulnerabilities to trigger elevation of privilege and security restriction bypass on the targeted system.


Impact

  • Elevation of Privilege
  • Security Restriction Bypass

System / Technologies affected

  • Zoom Rooms for Windows before version 7.1.0
  • Zoom Workplace for Windows before version 7.0.5
  • Zoom Workplace VDI Client for Windows before versions 6.5.18, 6.6.15 and 7.0.10 in their respective branch
  • Zoom Workplace VDI plugin for Windows before 6.5.17 and 6.6.14 in their respective branch
  • Zoom Remote Control for Zoom Contact Center for Windows before version 7.0.0

Solutions

Before installation of the software, please visit the vendor web-site for more details.

Apply fixes issued by the vendor:

 


Vulnerability Identifier


Source


Related Link

2026年7月15日星期三

Mozilla 產品多個漏洞

Mozilla 產品多個漏洞

發佈日期: 2026年07月15日

風險: 高度風險

類型: 用戶端 - 瀏覽器

於 Mozilla 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、遠端執行任意程式碼、繞過保安限制及資料篡改。

 

注意:

CVE-2026-15718 及 CVE-2026-15719 的漏洞利用程式碼已公開。CVE-2026-15718 是 Firefox JavaScript WebAssembly 元件中的無效記憶體指標漏洞。CVE-2026-15719 則影響 Firefox DOM 導覽元件的網站隔離功能。因此,此漏洞的風險等級被評為高度風險。


影響

  • 阻斷服務
  • 遠端執行程式碼
  • 繞過保安限制
  • 篡改

受影響之系統或技術

以下版本之前的版本﹕

 

  • Firefox 152.0.6
  • Firefox for iOS 152.4

解決方案

在安裝軟體之前,請先瀏覽供應商之官方網站,以獲得更多詳細資料。

更新至版本:

 

  • Firefox 152.0.6
  • Firefox for iOS 152.4

漏洞識別碼


資料來源


相關連結

Mozilla Products Multiple Vulnerabilities

Mozilla Products Multiple Vulnerabilities

Release Date: 15 Jul 2026

RISK: High Risk

TYPE: Clients - Browsers

Multiple vulnerabilities were identified in Mozilla Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, remote code execution, security restriction bypass and data manipulation on the targeted system.

 

Note:

Exploit code for CVE-2026-15718 and CVE-2026-15719 is public. For CVE-2026-15718, it is an invalid memory pointer in WebAssembly flaw in Firefox’s JavaScript WebAssembly component. For CVE-2026-15719, it affects site isolation in Firefox’s DOM navigation component. Hence, the risk level is rated as High Risk.

 

 


Impact

  • Denial of Service
  • Remote Code Execution
  • Security Restriction Bypass
  • Data Manipulation

System / Technologies affected

Versions prior to:

 

  • Firefox 152.0.6
  • Firefox for iOS 152.4

Solutions

Before installation of the software, please visit the vendor web-site for more details.

Apply fixes issued by the vendor:

 

  • Firefox 152.0.6
  • Firefox for iOS 152.4

Vulnerability Identifier


Source


Related Link

Google Chrome 多個漏洞

Google Chrome 多個漏洞 發佈日期: 2026年07月22日 風險: 中度風險 類型: 用戶端 - 瀏覽器 於 Google Chr...