2026年9月10日星期四

MongoDB 多個漏洞

MongoDB 多個漏洞

發佈日期: 2026年09月10日

於 MongoDB 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、彷冒、遠端執行任意程式碼、洩露敏感資料、資料篡改及繞過保安限制。


影響

  • 阻斷服務
  • 資料洩露
  • 遠端執行程式碼
  • 繞過保安限制
  • 權限提升
  • 篡改
  • 仿冒

受影響之系統或技術

  • MongoDB Server 7.0.0 至 7.0.41 之前的版本
  • MongoDB Server 8.0.0 至 8.0.30 之前的版本

  • MongoDB Server 8.3.0 至 8.3.9 之前的版本


解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝供應商提供的修補程式:

 


漏洞識別碼


資料來源


相關連結

MongoDB Multiple Vulnerabilities

MongoDB Multiple Vulnerabilities

Release Date: 10 Sep 2026

Multiple vulnerabilities were identified in MongoDB. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, spoofing, remote code execution, sensitive information disclosure, data manipulation and security restriction bypass on the targeted system.


Impact

  • Denial of Service
  • Information Disclosure
  • Remote Code Execution
  • Security Restriction Bypass
  • Elevation of Privilege
  • Data Manipulation
  • Spoofing

System / Technologies affected

  • MongoDB Server 7.0.0 versions prior to 7.0.41
  • MongoDB Server 8.0.0 versions prior to 8.0.30

  • MongoDB Server 8.3.0 versions prior to 8.3.9

 


Solutions

Before installation of the software, please visit the vendor web-site for more details.

Apply fixes issued by the vendor:

 


Vulnerability Identifier


Source


Related Link

Palo Alto 產品多個漏洞

Palo Alto 產品多個漏洞

發佈日期: 2026年09月10日

於 Palo Alto 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發權限提升、阻斷服務狀況、遠端執行任意程式碼及跨網站指令碼。


影響

  • 遠端執行程式碼
  • 阻斷服務
  • 跨網站指令碼
  • 權限提升

受影響之系統或技術

  • Cloud NGFW AWS 及 Azure 所有版本
  • GlobalProtect App 6.0 中 6.0.15 on macOS, Linux and Windows 之前的版本
  • GlobalProtect App 6.2 中 6.2.8-h14 on macOS and Windows 之前的版本
  • GlobalProtect App 6.3 中 6.3.3-h15 on macOS, Linux and Windows 之前的版本
  • GlobalProtect App iOS, Android, ChromeOS 所有版本
  • PAN-OS 10.2 中 10.2.7-h37 之前的版本
  • PAN-OS 10.2 中 10.2.10-h40 之前的版本
  • PAN-OS 10.2 中 10.2.13-h24 之前的版本
  • PAN-OS 10.2 中 10.2.16-h10 之前的版本
  • PAN-OS 10.2 中 10.2.18-h10 之前的版本
  • PAN-OS 11.1 中 11.1.4-h36 之前的版本
  • PAN-OS 11.1 中 11.1.6-h38 之前的版本
  • PAN-OS 11.1 中 11.1.7-h10 之前的版本
  • PAN-OS 11.1 中 11.1.10-h33 之前的版本
  • PAN-OS 11.1 中 11.1.13-h12 之前的版本
  • PAN-OS 11.1 中 11.1.16-h2 之前的版本
  • PAN-OS 11.2 中 11.2.4-h21 之前的版本
  • PAN-OS 11.2 中 11.2.7-h20 之前的版本
  • PAN-OS 11.2 中 11.2.10-h14 之前的版本
  • PAN-OS 11.2 中 11.2.13-h2 之前的版本
  • PAN-OS 12.1 中 12.1.4-h10 之前的版本
  • PAN-OS 12.1 中 12.1.7-h5 之前的版本
  • PAN-OS 12.1 中 12.1.10 之前的版本
  • PAN-OS 12.2 中 12.2.3 之前的版本
  • Prisma Access 10.2 中 10.2.10-h40 之前的版本
  • Prisma Access 11.2 中 11.2.7-h20 之前的版本
  • Prisma Access 12.1 中 12.1.7-h5 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Palo Alto Products Multiple Vulnerabilities

Palo Alto Products Multiple Vulnerabilities

Release Date: 10 Sep 2026

Multiple vulnerabilities were identified in Palo Alto Products. A remote attacker could exploit some of these vulnerabilities to trigger elevation of privilege, denial of service condition, remote code execution and cross-site scripting on the targeted system.


Impact

  • Remote Code Execution
  • Denial of Service
  • Cross-Site Scripting
  • Elevation of Privilege

System / Technologies affected

  • Cloud NGFW all versions on AWS and Azure
  • GlobalProtect App 6.0 versions earlier than 6.0.15 on macOS, Linux and Windows
  • GlobalProtect App 6.2 versions earlier than 6.2.8-h14 on macOS and Windows
  • GlobalProtect App 6.3 versions earlier than 6.3.3-h15 on macOS, Linux and Windows
  • GlobalProtect App all versions on iOS, Android, ChromeOS
  • PAN-OS 10.2 versions earlier than 10.2.7-h37
  • PAN-OS 10.2 versions earlier than 10.2.10-h40
  • PAN-OS 10.2 versions earlier than 10.2.13-h24
  • PAN-OS 10.2 versions earlier than 10.2.16-h10
  • PAN-OS 10.2 versions earlier than 10.2.18-h10
  • PAN-OS 11.1 versions earlier than 11.1.4-h36
  • PAN-OS 11.1 versions earlier than 11.1.6-h38
  • PAN-OS 11.1 versions earlier than 11.1.7-h10
  • PAN-OS 11.1 versions earlier than 11.1.10-h33
  • PAN-OS 11.1 versions earlier than 11.1.13-h12
  • PAN-OS 11.1 versions earlier than 11.1.16-h2
  • PAN-OS 11.2 versions earlier than 11.2.4-h21
  • PAN-OS 11.2 versions earlier than 11.2.7-h20
  • PAN-OS 11.2 versions earlier than 11.2.10-h14
  • PAN-OS 11.2 versions earlier than 11.2.13-h2
  • PAN-OS 12.1 versions earlier than 12.1.4-h10
  • PAN-OS 12.1 versions earlier than 12.1.7-h5
  • PAN-OS 12.1 versions earlier than 12.1.10
  • PAN-OS 12.2 versions earlier than 12.2.3
  • Prisma Access 10.2 versions earlier than 10.2.10-h40
  • Prisma Access 11.2 versions earlier than 11.2.7-h20
  • Prisma Access 12.1 versions earlier than 12.1.7-h5

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Google Chrome 多個漏洞

Google Chrome 多個漏洞

發佈日期: 2026年09月10日

於 Google Chrome 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、繞過保安限制、彷冒、敏感資料洩露及遠端執行任意程式碼。

 

注意:

CVE-2026-87491 正在被廣泛利用。遠端攻擊者可以利用此漏洞,透過特製的 HTML 頁面在沙箱環境中執行任意程式碼。因此,此漏洞的風險等級被評為極高度風險。


影響

  • 遠端執行程式碼
  • 阻斷服務
  • 資料洩露
  • 繞過保安限制
  • 權限提升
  • 仿冒

受影響之系統或技術

  • Google Chrome 153.0.8010.36 (Linux) 之前的版本
  • Google Chrome 153.0.8010.36/.37 (Mac) 之前的版本
  • Google Chrome 153.0.8010.36/.37 (Windows) 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • Google Chrome 153.0.8010.36 (Linux) 或之後版本
  • Google Chrome 153.0.8010.36/.37 (Mac) 或之後版本
  • Google Chrome 153.0.8010.36/.37 (Windows) 或之後版本

漏洞識別碼


資料來源


相關連結

MongoDB 多個漏洞

MongoDB 多個漏洞 發佈日期: 2026年09月10日 於 MongoDB 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、彷冒、遠端執行任意程式碼、洩露敏感資料、資料篡改及繞過保安限制。 影響 阻斷服務 資料洩露 遠端執行程式碼 繞過保安限制...