2026年9月21日星期一

F5 BIG-IP 阻斷服務漏洞

F5 BIG-IP 阻斷服務漏洞

發佈日期: 20260921

風險: 高度風險

F5 BIG-IP 發現一個漏洞。遠端攻擊者可利用這漏洞,於目標系統觸發阻斷服務狀況。

 

注意:

暫無可修補 CVE-2026-11622 的修補程式。因此,風險等級被評為高度風險。

 


影響

  • 阻斷服務

受影響之系統或技術

BIG-IP (DNS)

 

  • 17.1.0 - 17.1.3 版本
  • 17.5.0 - 17.5.1 版本
  • 21.1.0 版本

 


解決方案

處理方法:

透過以下方法以緩解此漏洞的影響:

 

  • validating resolver DNS cache 中停用 DNSSEC
  • 切換至 Resolver Transparent cache 類型
  • DNS profile 中停用 Use BIND Server on BIG-IP 選項

 

請瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的臨時處理方法:


漏洞識別碼


資料來源


相關連結

 


F5 BIG-IP Denial of Service Vulnerability

F5 BIG-IP Denial of Service Vulnerability

Release Date: 21 Sep 2026

RISK: High Risk

A vulnerability was identified in F5 BIG-IP. A remote attacker could exploit this vulnerability to trigger denial of service condition on the targeted system.

 

Note:

No patch is currently available for CVE-2026-11622 of the affected products. Hence, the risk level is rated as High Risk.


Impact

  • Denial of Service

System / Technologies affected

BIG-IP (DNS)

 

  • Versions 17.1.0 - 17.1.3
  • Versions 17.5.0 - 17.5.1
  • Versions 21.1.0

 


Solutions

Workaround:

Mitigate the vulnerability by the following workaround:

 

  • Disable DNSSEC in a validating resolver DNS cache
  • Switch to a Resolver or Transparent cache type
  • Disable the Use BIND Server on BIG-IP option on the DNS profile

 

Please visit the vendor web-site for more details.

 

Apply workarounds issued by the vendor:


Vulnerability Identifier


Source


Related Link

 


2026年9月19日星期六

ISC BIND 多個漏洞

ISC BIND 多個漏洞

發佈日期: 20260918 273 觀看次數

風險: 中度風險

Medium Risk

類型: 伺服器 - 網絡管理

類型: 網絡管理

ISC BIND 發現多個漏洞,遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、資料篡改及繞過保安限制。


影響

  • 阻斷服務
  • 篡改
  • 繞過保安限制

受影響之系統或技術

  • BIND 9.11.0 9.18.50 版本
  • BIND 9.18.0 9.18.50 版本
  • BIND 9.20.0 9.20.27 版本
  • BIND 9.21.0 9.21.25 版本
  • BIND Supported Preview Edition 9.11.3-S1 9.18.50-S1 版本
  • BIND Supported Preview Edition 9.20.9-S1 9.20.27-S1 版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:

  • BIND 9.20.29 版本
  • BIND 9.21.26 版本
  • BIND Supported Preview Edition 9.20.29-S1 版本

漏洞識別碼


資料來源


相關連結

 


ISC BIND Multiple Vulnerabilities

ISC BIND Multiple Vulnerabilities

Release Date: 18 Sep 2026

Multiple vulnerabilities were identified in ISC BIND. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, data manipulation and security restriction bypass on the targeted system.


Impact

  • Denial of Service
  • Data Manipulation
  • Security Restriction Bypass

System / Technologies affected

  • BIND version 9.11.0 to 9.18.50
  • BIND version 9.18.0 to 9.18.50
  • BIND version 9.20.0 to 9.20.27
  • BIND version 9.21.0 to 9.21.25
  • BIND Supported Preview Edition version 9.11.3-S1 to 9.18.50-S1
  • BIND Supported Preview Edition version 9.20.9-S1 to 9.20.27-S1

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:

  • BIND version 9.20.29
  • BIND version 9.21.26
  • BIND Supported Preview Edition version 9.20.29-S1

Vulnerability Identifier


Source


Related Link

Google Chrome 多個漏洞

Google Chrome 多個漏洞

發佈日期: 2026年09月18日

於 Google Chrome 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、繞過保安限制、敏感資料洩露、彷冒及遠端執行任意程式碼。


影響

  • 遠端執行程式碼
  • 繞過保安限制
  • 阻斷服務
  • 資料洩露
  • 仿冒

受影響之系統或技術

  • Google Chrome 153.0.8010.52 (Linux) 之前的版本
  • Google Chrome 153.0.8010.52/.53 (Mac) 之前的版本
  • Google Chrome 153.0.8010.52/.53 (Windows) 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • Google Chrome 153.0.8010.52 (Linux) 或之後版本
  • Google Chrome 153.0.8010.52/.53 (Mac) 或之後版本
  • Google Chrome 153.0.8010.52/.53 (Windows) 或之後版本

漏洞識別碼


資料來源


相關連結

Google Chrome Multiple Vulnerabilities

Google Chrome Multiple Vulnerabilities

Release Date: 18 Sep 2026 

Multiple vulnerabilities were identified in Google Chrome. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, security restriction bypass, sensitive information disclosure, spoofing and remote code execution on the targeted system.


Impact

  • Remote Code Execution
  • Security Restriction Bypass
  • Denial of Service
  • Information Disclosure
  • Spoofing

System / Technologies affected

  • Google Chrome prior to 153.0.8010.52 (Linux)
  • Google Chrome prior to 153.0.8010.52/.53 (Mac)
  • Google Chrome prior to 153.0.8010.52/.53 (Windows)

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Google Chrome 153.0.8010.52 (Linux) or later
  • Google Chrome 153.0.8010.52/.53 (Mac) or later
  • Google Chrome 153.0.8010.52/.53 (Windows) or later

Vulnerability Identifier


Source


Related Link

2026年9月17日星期四

思科產品多個漏洞

思科產品多個漏洞

發佈日期: 2026年09月17日

於思科產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況及繞過保安限制。


影響

  • 阻斷服務
  • 繞過保安限制

受影響之系統或技術

  • 思科 IOS XR Software
  • 思科 Secure Firewall ASA Software

請參考供應商發佈的連結以了解受影響的版本:


解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

F5 BIG-IP 阻斷服務漏洞

F5 BIG-IP 阻斷服務漏洞 發佈日期 : 2026 年 09 月 21 日 風險 : 高度風險 於 F5 BIG-IP 發現一個漏洞。遠端攻擊者可利用這漏洞,於目標系統觸發阻斷服務狀況。   注意: 暫無可修補  CVE-2026-11622  的...