2026年9月29日星期二

Apache Tomcat 多個漏洞

Apache Tomcat 多個漏洞

發佈日期: 2026年09月29日

於 Apache Tomcat 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、繞過保安限制及資料篡改。


影響

  • 阻斷服務
  • 篡改
  • 繞過保安限制

受影響之系統或技術

  • Apache Tomcat 9.0.0.M1 至 9.0.121 版本
  • Apache Tomcat 10.1.0-M1 至 10.1.59 版本
  • Apache Tomcat 11.0.0-M1 至 11.0.25 版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

 


Apache Tomcat Multiple Vulnerabilities

Apache Tomcat Multiple Vulnerabilities

Release Date: 29 Sep 2026

Multiple vulnerabilities were identified in Apache Tomcat. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, security restriction bypass and data manipulation on the targeted system.


Impact

  • Denial of Service
  • Data Manipulation
  • Security Restriction Bypass

System / Technologies affected

  • Apache Tomcat version 9.0.0.M1 to 9.0.121
  • Apache Tomcat version 10.1.0-M1 to 10.1.59
  • Apache Tomcat version 11.0.0-M1 to 11.0.25

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

 


蘋果產品遠端執行程式碼漏洞

蘋果產品遠端執行程式碼漏洞

發佈日期: 2026年09月29日

於蘋果產品發現一個漏洞,遠端攻擊者可利用這個漏洞,於目標系統觸發遠端執行任意程式碼。

 

注意:

CVE-2026-86950 正被利用針對特定目標使用者的複雜攻擊。處理惡意製作的檔案可能導致任意程式碼執行。因此,該漏洞的風險等級被評為高度風險。


影響

  • 遠端執行程式碼

受影響之系統或技術

  • iOS 26.7.1 及 iPadOS 26.7.1 以前的版本
  • macOS Tahoe 26.7.1 以前的版本
  • macOS Sequoia 15.8.1 以前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝供應商提供的修補程式:

 

  • iOS 26.7.1 及 iPadOS 26.7.1 版本
  • macOS Tahoe 26.7.1 版本
  • macOS Sequoia 15.8.1 版本

漏洞識別碼


資料來源


相關連結

 


Apple Products Remote Code Execution Vulnerability

Apple Products Remote Code Execution Vulnerability

Release Date: 29 Sep 2026

A vulnerability has been identified in Apple Products. A remote attacker could exploit this vulnerability to trigger remote code execution on the targeted system.

 

Note:

CVE-2026-86950 is being exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.  Processing a maliciously crafted file may lead to arbitrary code execution. Hence, the risk level is rated as High Risk.


Impact

  • Remote Code Execution

System / Technologies affected

  • Versions prior to iOS 26.7.1 and iPadOS 26.7.1
  • Versions prior to macOS Tahoe 26.7.1
  • Versions prior to macOS Sequoia 15.8.1

Solutions

Before installation of the software, please visit the vendor web-site for more details.

Apply fixes issued by the vendor:

 

  • iOS 26.7.1 and iPadOS 26.7.1
  • macOS Tahoe 26.7.1
  • macOS Sequoia 15.8.1

Vulnerability Identifier


Source


Related Link

 


2026年9月28日星期一

Citrix 產品多個漏洞

Citrix 產品多個漏洞

發佈日期: 2026年09月28日

於 Citrix 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、繞過保安限制、敏感資料洩露及遠端執行任意程式碼。

 

注意:

CVE-2026-88771 及 CVE-2026-88772 正在被廣泛利用。CVE-2026-88771 是 Citrix NetScaler ADC 及 NetScaler Gateway 中的一個輸入驗證不當漏洞,可讓未經身份驗證的攻擊者執行任意指令。CVE-2026-88772 是一個記憶體溢位漏洞,可導致遠端程式碼執行或阻斷服務。因此,漏洞的風險等級被評為極高度風險。


影響

  • 阻斷服務
  • 遠端執行程式碼
  • 資料洩露
  • 繞過保安限制

受影響之系統或技術

  • NetScaler ADC 及 NetScaler Gateway 14.1 中 14.1-73.37 之前的版本
  • NetScaler ADC 及 NetScaler Gateway 13.1 中 13.1-64.23 之前的版本
  • NetScaler ADC FIPS 14.1-73.37 FIPS 之前的版本
  • NetScaler ADC FIPS 及 NDcPP  13.1-37.279 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結


Citrix Products Multiple Vulnerabilities

Citrix Products Multiple Vulnerabilities

Release Date: 28 Sep 2026

Multiple vulnerabilities were identified in Citrix Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, security restriction bypass, sensitive information disclosure and remote code execution on the targeted system.

 

Note:

CVE-2026-88771 and CVE-2026-88772 are being exploited in the wild. CVE-2026-88771 is an improper input validation vulnerability in Citrix NetScaler ADC and NetScaler Gateway that allows an unauthenticated attacker to execute arbitrary commands. CVE-2026-88772 is a memory overflow vulnerability that can lead to remote code execution or denial of service. Hence, the risk level is rated as Extremely High Risk.


Impact

  • Denial of Service
  • Remote Code Execution
  • Information Disclosure
  • Security Restriction Bypass

System / Technologies affected

  • NetScaler ADC and  NetScaler Gateway 14.1 BEFORE 14.1-73.37
  • NetScaler ADC and  NetScaler Gateway 13.1 BEFORE 13.1-64.23
  • NetScaler ADC FIPS BEFORE 14.1-73.37 FIPS
  • NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.279

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link


2026年9月24日星期四

WordPress 遠端執行程式碼漏洞

WordPress 遠端執行程式碼漏洞

發佈日期: 2026年09月24日

於 WordPress 發現一個漏洞。遠端攻擊者可利用這漏洞,於目標系統觸發遠端執行任意程式碼。

 

注意:

針對 WordPress 新發現的漏洞 CVE-2026-87902,已有概念驗證程式碼(PoC)被公開。 如果目前啟用的子佈景主題或父佈景主題包含一個名稱以「page-」開頭的頂層目錄,而所選的本機 .php 目標檔案存在於伺服器上,且 Web 伺服器帳戶具備讀取權限,遠端攻擊者便可利用此漏洞觸發遠端執行程式碼。因此,風險等級被評為中度風險。

 


影響

  • 遠端執行程式碼

受影響之系統或技術

  • Wordpress 4.7.0 - 4.7.36
  • Wordpress 4.8.0 - 4.8.31
  • Wordpress 4.9.0 - 4.9.32
  • Wordpress 5.0.0 - 5.0.28
  • Wordpress 5.1.0 - 5.1.25
  • Wordpress 5.2.0 - 5.2.27
  • Wordpress 5.3.0 - 5.3.24
  • Wordpress 5.4.0 - 5.4.22
  • Wordpress 5.5.0 - 5.5.21
  • Wordpress 5.6.0 - 5.6.20
  • Wordpress 5.7.0 - 5.7.18
  • Wordpress 5.8.0 - 5.8.16
  • Wordpress 5.9.0 - 5.9.17
  • Wordpress 6.0.0 - 6.0.15
  • Wordpress 6.1.0 - 6.1.13
  • Wordpress 6.2.0 - 6.2.12
  • Wordpress 6.3.0 - 6.3.11
  • Wordpress 6.4.0 - 6.4.11
  • Wordpress 6.5.0 - 6.5.11
  • Wordpress 6.6.0 - 6.6.8
  • Wordpress 6.7.0 - 6.7.8
  • Wordpress 6.8.0 - 6.8.9
  • Wordpress 6.9.0 - 6.9.8
  • Wordpress 7.0.0 - 7.0.5
  • Wordpress 7.1.0 - 7.1.1

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:

 

https://wordpress.org/news/2026/09/wordpress-7-1-2-release/


漏洞識別碼


資料來源


相關連結

 


WordPress Remote Code Execution Vulnerability

WordPress Remote Code Execution Vulnerability

Release Date: 24 Sep 2026

A vulnerability was identified in identified in WordPress. A remote attacker could exploit this vulnerability to trigger remote code execution on the targeted system.

 

Note:

A proof-of-concept exploit have been published for CVE-2026-87902. If the active child or parent theme contains a top-level directory whose name starts with "page-", and a chosen local .php target file exists on the server and is readable by the web server account, then a remote attacker could exploit this vulnerability to trigger remote code execution. Hence, the risk level is rated as Medium Risk.


Impact

  • Remote Code Execution

System / Technologies affected

  • Wordpress 4.7.0 - 4.7.36
  • Wordpress 4.8.0 - 4.8.31
  • Wordpress 4.9.0 - 4.9.32
  • Wordpress 5.0.0 - 5.0.28
  • Wordpress 5.1.0 - 5.1.25
  • Wordpress 5.2.0 - 5.2.27
  • Wordpress 5.3.0 - 5.3.24
  • Wordpress 5.4.0 - 5.4.22
  • Wordpress 5.5.0 - 5.5.21
  • Wordpress 5.6.0 - 5.6.20
  • Wordpress 5.7.0 - 5.7.18
  • Wordpress 5.8.0 - 5.8.16
  • Wordpress 5.9.0 - 5.9.17
  • Wordpress 6.0.0 - 6.0.15
  • Wordpress 6.1.0 - 6.1.13
  • Wordpress 6.2.0 - 6.2.12
  • Wordpress 6.3.0 - 6.3.11
  • Wordpress 6.4.0 - 6.4.11
  • Wordpress 6.5.0 - 6.5.11
  • Wordpress 6.6.0 - 6.6.8
  • Wordpress 6.7.0 - 6.7.8
  • Wordpress 6.8.0 - 6.8.9
  • Wordpress 6.9.0 - 6.9.8
  • Wordpress 7.0.0 - 7.0.5
  • Wordpress 7.1.0 - 7.1.1

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:

 

https://wordpress.org/news/2026/09/wordpress-7-1-2-release/


Vulnerability Identifier


Source


Related Link

 


2026年9月23日星期三

F5 BIG-IP 遠端執行程式碼漏洞

F5 BIG-IP 遠端執行程式碼漏洞

發佈日期: 2026年09月23日

於 F5 BIG-IP 發現一個漏洞。遠端攻擊者可利用這漏洞,於目標系統觸發遠端執行程式碼狀況。

 

注意:

CVE-2026-94127 正被廣泛利用。此漏洞僅在 BIG-IP APM 配置為 OAuth 授權伺服器時才會出現。因此,風險等級被評為高度風險。

 


影響

  • 遠端執行程式碼

受影響之系統或技術

BIG-IP APM

 

  • 17.1.0 - 17.1.3 版本
  • 17.5.0 - 17.5.1版本
  • 21.1.0 版本

 


解決方案

請瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的臨時處理方法:


漏洞識別碼


資料來源


相關連結

 


F5 BIG-IP Remote Code Execution Vulnerability

F5 BIG-IP Remote Code Execution Vulnerability

Release Date: 23 Sep 2026

A vulnerability was identified in F5 BIG-IP. A remote attacker could exploit this vulnerability to trigger remote code execution on the targeted system.

 

Note:

CVE-2026-94127  is being exploited in the wild. This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Hence, the risk level is rated as High Risk.


Impact

  • Remote Code Execution

System / Technologies affected

BIG-IP APM

 

  • Versions 17.1.0 - 17.1.3
  • Versions 17.5.0 - 17.5.1
  • Versions 21.1.0

 


Solutions

Please visit the vendor web-site for more details.

 

Apply workarounds issued by the vendor:


Vulnerability Identifier


Source


Related Link

 


Google Chrome 多個漏洞

Google Chrome 多個漏洞

發佈日期: 2026年09月23日

於 Google Chrome 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、繞過保安限制、敏感資料洩露、彷冒跨網站指令碼、資料篡改及遠端執行任意程式碼。


影響

  • 遠端執行程式碼
  • 繞過保安限制
  • 阻斷服務
  • 資料洩露
  • 仿冒
  • 跨網站指令碼
  • 篡改

受影響之系統或技術

  • Google Chrome 154.0.8037.57 (Linux) 之前的版本
  • Google Chrome 154.0.8037.57/.58 (Mac) 之前的版本
  • Google Chrome 154.0.8037.57/.58 (Windows) 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • Google Chrome 154.0.8037.57 (Linux) 或之後版本
  • Google Chrome 154.0.8037.57/.58 (Mac) 或之後版本
  • Google Chrome 154.0.8037.57/.58 (Windows) 或之後版本

漏洞識別碼


資料來源


相關連結

 


Apache Tomcat 多個漏洞

Apache Tomcat 多個漏洞 發佈日期 : 2026 年 09 月 29 日 於 Apache Tomcat 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、繞過保安限制及資料篡改。 影響 阻斷服務 篡改 繞過...