2026年10月5日星期一

Google Chrome 多個漏洞

Google Chrome 多個漏洞

發佈日期: 2026年10月05日

於 Google Chrome 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、繞過保安限制、敏感資料洩露及遠端執行任意程式碼。


影響

  • 遠端執行程式碼
  • 阻斷服務
  • 繞過保安限制
  • 資料洩露

受影響之系統或技術

  • Google Chrome 154.0.8037.97 (Linux) 之前的版本
  • Google Chrome 154.0.8037.97/.98 (Mac) 之前的版本
  • Google Chrome 154.0.8037.97/.98 (Windows) 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • Google Chrome 154.0.8037.97 (Linux) 或之後版本
  • Google Chrome 154.0.8037.97/.98 (Mac) 或之後版本
  • Google Chrome 154.0.8037.97/.98 (Windows) 或之後版本

漏洞識別碼


資料來源


相關連結

 


Google Chrome Multiple Vulnerabilities

Google Chrome Multiple Vulnerabilities

Release Date: 5 Oct 2026

Multiple vulnerabilities were identified in Google Chrome. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, security restriction bypass, sensitive information disclosure and remote code execution on the targeted system.


Impact

  • Remote Code Execution
  • Denial of Service
  • Security Restriction Bypass
  • Information Disclosure

System / Technologies affected

  • Google Chrome prior to 154.0.8037.97 (Linux)
  • Google Chrome prior to 154.0.8037.97/.98 (Mac)
  • Google Chrome prior to 154.0.8037.97/.98 (Windows)

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Google Chrome 154.0.8037.97 (Linux) or later
  • Google Chrome 154.0.8037.97/.98 (Mac) or later
  • Google Chrome 154.0.8037.97/.98 (Windows) or later

Vulnerability Identifier


Source


Related Link

 


Microsoft Edge 多個漏洞

Microsoft Edge 多個漏洞

發佈日期: 2026年10月05日

於 Microsoft Edge 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、繞過保安限制、敏感資料洩露、彷冒及遠端執行任意程式碼。


影響

  • 遠端執行程式碼
  • 繞過保安限制
  • 阻斷服務
  • 資料洩露
  • 仿冒

受影響之系統或技術

  • Microsoft Edge 153.0.4234.49 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 153.0.4234.49 或之後版本

漏洞識別碼


資料來源


相關連結

 


Microsoft Edge Multiple Vulnerabilities

Microsoft Edge Multiple Vulnerabilities

Release Date: 5 Oct 2026

Multiple vulnerabilities were identified in Microsoft Edge. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, security restriction bypass, sensitive information disclosure, spoofing and remote code execution on the targeted system.


Impact

  • Remote Code Execution
  • Security Restriction Bypass
  • Denial of Service
  • Information Disclosure
  • Spoofing

System / Technologies affected

  • Microsoft Edge version prior to 153.0.4234.49

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 153.0.4234.49 or later

Vulnerability Identifier


Source


Related Link

 


Citrix 產品阻斷服務漏洞

Citrix 產品阻斷服務漏洞

發佈日期: 2026年10月05日

於 Citrix 產品發現一個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況。

 

注意:

CVE-2026-88779 正在被廣泛利用。該漏洞由記憶體溢位引起,可導致觸發阻斷服務狀況。NetScaler ADC 或 NetScaler Gateway 必須配置為 SAML SP 或 SAML IdP 才會受到影響。因此,該漏洞的風險等級被評為高度風險。


影響

  • 阻斷服務

受影響之系統或技術

  • Citrix NetScaler ADC 及 Citrix NetScaler Gateway 14.1 中 14.1-73.41 之前的版本
  • Citrix NetScaler ADC 及 Citrix NetScaler Gateway 13.1 中 13.1-64.28 之前的版本
  • Citrix NetScaler ADC FIPS 14.1-73.41 FIPS 之前的版本
  • Citrix NetScaler ADC FIPS 及 NDcPP  13.1-37.282 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

 


Citrix Products Denial of Service Vulnerability

Citrix Products Denial of Service Vulnerability

Release Date: 5 Oct 2026

A vulnerability was identified in Citrix Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition on the targeted system.

 

Note:

CVE-2026-88779 are being exploited in the wild. This vulnerability is caused by a memory overflow that leads to a Denial of Service. NetScaler ADC or NetScaler Gateway must be configured as a SAML SP or SAML IdP to be vulnerable. Hence, the risk level is rated as High Risk.


Impact

  • Denial of Service

System / Technologies affected

  • Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 BEFORE 14.1-73.41
  • Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 BEFORE 13.1-64.28
  • Citrix NetScaler ADC FIPS BEFORE 14.1-73.41 FIPS
  • Citrix NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.282

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

 


2026年10月2日星期五

Fortinet 產品遠端執行程式碼漏洞

Fortinet 產品遠端執行程式碼漏洞

發佈日期: 2026年10月02日

於 Fortinet 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼及資料篡改。

 

注意:

CVE-2025-25249 正在被廣泛利用。此漏洞涉及未有適當限制受限目錄的路徑名稱(「路徑遍歷」),以及未有妥善處理 NULL 位元組或 NULL 字元。未經身份驗證的攻擊者可透過特製的 HTTP 或 HTTPS 請求,在底層系統上寫入任意檔案。因此,該漏洞的風險等級被評為極高度風險。


影響

  • 遠端執行程式碼
  • 篡改

受影響之系統或技術

FortiMail

  • FortiMail 8.0.0 至 8.0.1
  • FortiMail 7.6.0 至 7.6.6
  • FortiMail 7.4.0 至 7.4.8
  • FortiMail 7.2.0 至 7.2.9

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

 


Fortinet Products Remote Code Execution Vulnerability

Fortinet Products Remote Code Execution Vulnerability

Release Date: 2 Oct 2026

Multiple vulnerabilities were identified in Fortinet Products. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution and data manipulation on the targeted system.

 

Note:

CVE-2025-25249 is being exploited in the wild. An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') and Improper Neutralization of NULL Byte or NULL Character vulnerability may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. Hence, the risk level of this vulnerability is rated as Extremely High Risk.


Impact

  • Remote Code Execution
  • Data Manipulation

System / Technologies affected

FortiMail

  • FortiMail 8.0.0 through 8.0.1
  • FortiMail 7.6.0 through 7.6.6
  • FortiMail 7.4.0 through 7.4.8
  • FortiMail 7.2.0 through 7.2.9

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

 


Mozilla Thunderbird 多個漏洞

Mozilla Thunderbird 多個漏洞

發佈日期: 2026年10月02日

於 Mozilla 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、繞過保安限制、敏感資料洩露、遠端執行任意程式碼、資料篡改及彷冒。


影響

  • 遠端執行程式碼
  • 阻斷服務
  • 權限提升
  • 繞過保安限制
  • 資料洩露
  • 篡改
  • 仿冒

受影響之系統或技術

以下版本之前的版本﹕

 

  • Thunderbird 140.17
  • Thunderbird 153.4
  • Thunderbird 157

解決方案

在安裝軟體之前,請先瀏覽供應商之官方網站,以獲得更多詳細資料。

更新至版本:

 

  • Thunderbird 140.17
  • Thunderbird 153.4
  • Thunderbird 157

漏洞識別碼


資料來源


相關連結

 


Google Chrome 多個漏洞

Google Chrome 多個漏洞 發佈日期 : 2026 年 10 月 05 日 於 Google Chrome 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、繞過保安限制、敏感資料洩露及遠端執行任意程式碼。 影響 遠端...