2026年8月5日星期三

Apache Tomcat 多個漏洞

Apache Tomcat 多個漏洞

發佈日期: 2026年08月05日

風險: 中度風險

類型: 伺服器 - 網站伺服器

於 Apache Tomcat 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發繞過保安限制、敏感資料洩露和資料篡改。

 

注意:

CVE-2026-34486 正在被廣泛利用。假如啟用了 EncryptInterceptor(非默認配置),該漏洞可能會導致敏感資料洩露。因此,風險等級被評為中度風險。


Apache Tomcat Multiple Vulnerabilities

Apache Tomcat Multiple Vulnerabilities

Release Date: 5 Aug 2026

RISK: Medium Risk

TYPE: Servers - Web Servers

Multiple vulnerabilities were identified in Apache Tomcat. A remote attacker could exploit some of these vulnerabilities to trigger security restriction bypass, sensitive information disclosure and data manipulation on the targeted system.

 

Note:


Mozilla Firefox 資料洩露漏洞

Mozilla Firefox 資料洩露漏洞

發佈日期: 2026年08月05日

風險: 中度風險

類型: 用戶端 - 瀏覽器

於 Mozilla Firefox 發現一個漏洞。遠端攻擊者可利用此漏洞,於目標系統觸發洩露敏感資料。


影響

  • 資料洩露

受影響之系統或技術

以下版本之前的版本﹕

 

  • Firefox for Android 153.0.3

解決方案

在安裝軟體之前,請先瀏覽供應商之官方網站,以獲得更多詳細資料。

更新至版本:

 

  • Firefox for Android 153.0.3

漏洞識別碼


資料來源


相關連結

Mozilla Firefox Information Disclosure Vulnerability

Mozilla Firefox Information Disclosure Vulnerability

Release Date: 5 Aug 2026

RISK: Medium Risk

TYPE: Clients - Browsers

A vulnerability was identified in Mozilla Firefox . A remote attacker could exploit this vulnerability to trigger sensitive information disclosure on the targeted system.


Impact

  • Information Disclosure

System / Technologies affected

Versions prior to:

 

  • Firefox for Android 153.0.3

Solutions

Before installation of the software, please visit the vendor web-site for more details.

Apply fixes issued by the vendor:

 

  • Firefox for Android 153.0.3

Vulnerability Identifier


Source


Related Link

TP-Link Omada 產品多個漏洞

TP-Link Omada 產品多個漏洞

發佈日期: 2026年08月05日

風險: 中度風險

類型: 操作系統 - Network

於 TP-Link Omada 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發繞過保安限制、敏感資料洩露及彷冒。

 

影響

  • 資料洩露
  • 繞過保安限制
  • 仿冒

受影響之系統或技術

  • Omada Access Points
  • Omada App
  • Omada Controllers
  • Omada Gateways
  • Omada OLTs
  • Omada Switches

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

TP-Link Omada Products Multiple Vulnerabilities

TP-Link Omada Products Multiple Vulnerabilities

Release Date: 5 Aug 2026

RISK: Medium Risk

TYPE: Operating Systems - Networks OS

Multiple vulnerabilities were identified in TP-Link Omada Products. A remote attacker could exploit some of these vulnerabilities to trigger security restriction bypass, sensitive information disclosure and spoofing on the targeted system.


Impact

  • Information Disclosure
  • Security Restriction Bypass
  • Spoofing

System / Technologies affected

  • Omada Access Points
  • Omada App
  • Omada Controllers
  • Omada Gateways
  • Omada OLTs
  • Omada Switches

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

SUSE Linux 內核多個漏洞

SUSE Linux 內核多個漏洞

發佈日期: 2026年08月04日

風險: 中度風險

類型: 操作系統 - LINUX

於 SUSE Linux 內核 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升及遠端執行任意程式碼。


影響

  • 阻斷服務
  • 遠端執行程式碼
  • 權限提升

受影響之系統或技術

  • SUSE Linux Micro 6.2

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

SUSE Linux Kernel Multiple Vulnerabilities

SUSE Linux Kernel Multiple Vulnerabilities

Release Date: 4 Aug 2026

RISK: Medium Risk

TYPE: Operating Systems - Linux

Multiple vulnerabilities were identified in SUSE Linux Kernel. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege and remote code execution on the targeted system.

 


Impact

  • Denial of Service
  • Remote Code Execution
  • Elevation of Privilege

System / Technologies affected

  • SUSE Linux Micro 6.2

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

2026年8月3日星期一

Microsoft Edge 多個漏洞

Microsoft Edge 多個漏洞

發佈日期: 2026年08月03日

風險: 中度風險

類型: 用戶端 - 瀏覽器

於 Microsoft Edge 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、繞過保安限制、敏感資料洩露、遠端執行任意程式碼及資料篡改及彷冒。


影響

  • 遠端執行程式碼
  • 阻斷服務
  • 資料洩露
  • 繞過保安限制
  • 篡改
  • 仿冒

受影響之系統或技術

  • Microsoft Edge 151.0.4129.59 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 151.0.4129.59 或之後版本

漏洞識別碼


資料來源


相關連結

Apache Tomcat 多個漏洞

Apache Tomcat 多個漏洞 發佈日期: 2026年08月05日 風險: 中度風險 類型: 伺服器 - 網站伺服器 於 Apache T...