2026年8月14日星期五

Palo Alto 產品多個漏洞

Palo Alto 產品多個漏洞

發佈日期: 2026年08月14日

於 Palo Alto 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發權限提升、繞過保安限制、敏感資料洩露、遠端執行任意程式碼及資料篡改。


影響

  • 資料洩露
  • 遠端執行程式碼
  • 篡改
  • 權限提升
  • 繞過保安限制

受影響之系統或技術

  • Cloud NGFW AWS 上的所有版本
  • Cloud NGFW Azure 上的所有版本
  • GlobalProtect App 6.0 中 6.0.15 之前的版本(Android)
  • GlobalProtect App 6.0 中 6.0.15 之前的版本(Chrome OS)
  • GlobalProtect App 6.0 中 6.0.15 之前的版本(iOS)
  • GlobalProtect App 6.0 中 6.0.15 之前的版本(Linux)
  • GlobalProtect App 6.0 中 6.0.15 之前的版本(macOS)
  • GlobalProtect App 6.0 中 6.0.15 之前的版本(Windows)
  • GlobalProtect App 6.2 Linux 上的所有版本
  • GlobalProtect App 6.2 中 6.2.8-h13 (6.2.8-1045) 之前的版本(macOS)
  • GlobalProtect App 6.2 中 6.2.8-h13 (6.2.8-1045) 之前的版本(Windows)
  • GlobalProtect App 6.3 中 6.3.5 之前的版本(Android)
  • GlobalProtect App 6.3 中 6.3.5 之前的版本(Chrome OS)
  • GlobalProtect App 6.3 中 6.3.5 之前的版本(iOS)
  • GlobalProtect App 6.3 中 6.3.3-h15 之前的版本(Linux)
  • GlobalProtect App 6.3 中 6.3.3-h14 (6.3.3-1121) 之前的版本(macOS)
  • GlobalProtect App 6.3 中 6.3.3-h14 (6.3.3-1121) 之前的版本(Windows)
  • PAN-OS 10.2 中 10.2.8 之前的版本
  • PAN-OS 11.1 中 11.1.16-h1 之前的版本
  • Prisma Access 10.2 中 10.2.10 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Palo Alto Products Multiple Vulnerabilities

Palo Alto Products Multiple Vulnerabilities

Release Date: 14 Aug 2026

Multiple vulnerabilities were identified in Palo Alto Products. A remote attacker could exploit some of these vulnerabilities to trigger elevation of privilege, security restriction bypass, sensitive information disclosure, remote code execution and data manipulation on the targeted system.


Impact

  • Information Disclosure
  • Remote Code Execution
  • Data Manipulation
  • Elevation of Privilege
  • Security Restriction Bypass

System / Technologies affected

  • Cloud NGFW All versions on AWS
  • Cloud NGFW All versions on Azure
  • GlobalProtect App 6.0 versions earlier than 6.0.15 on Android
  • GlobalProtect App 6.0 versions earlier than 6.0.15 on Chrome OS
  • GlobalProtect App 6.0 versions earlier than 6.0.15 on iOS
  • GlobalProtect App 6.0 versions earlier than 6.0.15 on Linux
  • GlobalProtect App 6.0 versions earlier than 6.0.15 on macOS
  • GlobalProtect App 6.0 versions earlier than 6.0.15 on Windows
  • GlobalProtect App 6.2 All versions on Linux
  • GlobalProtect App 6.2 versions earlier than 6.2.8-h13 (6.2.8-1045) on macOS
  • GlobalProtect App 6.2 versions earlier than 6.2.8-h13 (6.2.8-1045) on Windows
  • GlobalProtect App 6.3 versions earlier than 6.3.5 on Android
  • GlobalProtect App 6.3 versions earlier than 6.3.5 on Chrome OS
  • GlobalProtect App 6.3 versions earlier than 6.3.5 on iOS
  • GlobalProtect App 6.3 versions earlier than 6.3.3-h15 on Linux
  • GlobalProtect App 6.3 versions earlier than 6.3.3-h14 (6.3.3-1121) on macOS
  • GlobalProtect App 6.3 versions earlier than 6.3.3-h14 (6.3.3-1121) on Windows
  • PAN-OS 10.2 versions earlier than 10.2.8
  • PAN-OS 11.1 versions earlier than 11.1.16-h1
  • Prisma Access 10.2 versions earlier than 10.2.10

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

VMWare 產品多個漏洞

VMWare 產品多個漏洞

發佈日期: 2026年08月14日

於 VMware 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、遠端執行任意程式碼、洩露敏感資料及繞過保安限制。

 


影響

  • 遠端執行程式碼
  • 阻斷服務
  • 資料洩露
  • 繞過保安限制

受影響之系統或技術

  • VMware ESX 8.0

  • VMware vCenter 8.0

  • VMware Workstation 25H2

  • VMware Fusion 25H2

  • VMware Cloud Foundation 5.x, 9.x.x.x

  • VMware vSphere Foundation 9.x.x.x

  • VMware Telco Cloud Platform 3.x, 4.x, 5.x

  • VMware Telco Cloud Infrastructure 3.x


解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 


漏洞識別碼


資料來源


相關連結

VMWare Products Multiple Vulnerabilities

VMWare Products Multiple Vulnerabilities

Release Date: 14 Aug 2026

Multiple vulnerabilities were identified in VMware products.  A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, remote code execution, sensitive information disclosure and security restriction bypass on the targeted system.


Impact

  • Remote Code Execution
  • Denial of Service
  • Information Disclosure
  • Security Restriction Bypass

System / Technologies affected

  • VMware ESX 8.0

  • VMware vCenter 8.0

  • VMware Workstation 25H2

  • VMware Fusion 25H2

  • VMware Cloud Foundation 5.x, 9.x.x.x

  • VMware vSphere Foundation 9.x.x.x

  • VMware Telco Cloud Platform 3.x, 4.x, 5.x

  • VMware Telco Cloud Infrastructure 3.x


Solutions

Before installation of the software, please visit the vendor web-site for more details.

 


Vulnerability Identifier


Source


Related Link

2026年8月13日星期四

IBM WebSphere 產品多個漏洞

IBM WebSphere 產品多個漏洞

發佈日期: 2026年08月13日

於 IBM WebSphere 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升及繞過保安限制。


影響

  • 阻斷服務
  • 權限提升
  • 繞過保安限制

受影響之系統或技術

  • IBM WebSphere Application Server - Liberty 17.0.0.3 - 26.0.0.8 版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

IBM WebSphere Products Multiple Vulnerabilities

IBM WebSphere Products Multiple Vulnerabilities

Release Date: 13 Aug 2026

Multiple vulnerabilities were identified in IBM WebSphere Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege and security restriction bypass on the targeted system.


Impact

  • Denial of Service
  • Elevation of Privilege
  • Security Restriction Bypass

System / Technologies affected

  • IBM WebSphere Application Server - Liberty version 17.0.0.3 - 26.0.0.8

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

MongoDB 多個漏洞

MongoDB 多個漏洞

發佈日期: 2026年08月13日

於 MongoDB 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發繞過保安限制、遠端執行任意程式碼、資料篡改、阻斷服務狀況、權限提升及洩露敏感資料。


影響

  • 阻斷服務
  • 資料洩露
  • 遠端執行程式碼
  • 繞過保安限制
  • 權限提升
  • 篡改

受影響之系統或技術

  • MongoDB Driver 4.11.0 至 5.9.2 之前的版本

  • MongoDB Server 7.0.0 至 7.0.40 之前的版本

  • MongoDB Server 8.0.0 至 8.0.29 之前的版本

  • MongoDB Server 8.3.0 至 8.3.8 之前的版本


解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝供應商提供的修補程式:

 


漏洞識別碼


資料來源


相關連結

Palo Alto 產品多個漏洞

Palo Alto 產品多個漏洞 發佈日期: 2026年08月14日 於 Palo Alto 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發權限提升、繞過保安限制、敏感資料洩露、遠端執行任意程式碼及資料篡改。 影響 資料洩露 遠端執行程式碼 篡改 權限提升 繞過保安限...