Apache Kafka 權限提升漏洞
風險: 中度風險
類型: 伺服器 - 網站伺服器
於 Apache Kafka發現一個漏洞。遠端攻擊者可利用這個漏洞,於目標系統觸發權限提升及敏感資料洩露。
影響
- 權限提升
- 資料洩露
受影響之系統或技術
- Apache Kafka Client 3.1.0 至 3.9.0
解決方案
在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。
安裝供應商提供的修補程式:
- Apache Kafka Client 4.0.0 版本
風險: 中度風險
類型: 伺服器 - 網站伺服器
於 Apache Kafka發現一個漏洞。遠端攻擊者可利用這個漏洞,於目標系統觸發權限提升及敏感資料洩露。
在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。
安裝供應商提供的修補程式:
RISK: Medium Risk
TYPE: Servers - Web Servers
A vulnerability was identified in Apache Kafka. A remote attacker could exploit this vulnerability to trigger elevation of privilege and sensitive information disclosure on the targeted system.
Before installation of the software, please visit the vendor web-site for more details.
Apply fixes issued by the vendor:
風險: 中度風險
類型: 操作系統 - Network
於 Fortinet 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發權限提升、遠端執行任意程式碼、洩露敏感資料、繞過保安限制、篡改及仿冒。
FortiOS
FortiProxy
FortiClientWindows
FortiClientEMS
FortiWeb
FortiSASE
在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。
安裝供應商提供的修補程式:
RISK: Medium Risk
TYPE: Operating Systems - Networks OS
Multiple vulnerabilities were identified in Fortinet Products. A remote attacker could exploit some of these vulnerabilities to trigger elevation of privilege, remote code execution, sensitive information disclosure, security restriction bypass, data manipulation and spoofing on the targeted system.
FortiOS
FortiProxy
FortiClientWindows
FortiClientEMS
FortiWeb
FortiSASE
Before installation of the software, please visit the vendor web-site for more details.
Apply fixes issued by the vendor:
風險: 中度風險
類型: 用戶端 - 瀏覽器
於 Google Chrome 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況及遠端執行任意程式碼。
在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。
安裝軟件供應商提供的修補程式:
RISK: Medium Risk
TYPE: Clients - Browsers
Multiple vulnerabilities were identified in Google Chrome. A remote attacker could exploit some of these vulnerabilities to trigger denial of service and remote code execution on the targeted system.
Before installation of the software, please visit the software vendor web-site for more details.
Apply fixes issued by the vendor:
風險: 中度風險
類型: 用戶端 - 瀏覽器
於 Mozilla 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務、繞過保安限制及敏感資料洩露。
以下版本之前的版本﹕
在安裝軟體之前,請先瀏覽供應商之官方網站,以獲得更多詳細資料。
更新至版本:
RISK: Medium Risk
TYPE: Clients - Browsers
Multiple vulnerabilities were identified in Mozilla Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, security restriction bypass and sensitive information disclosure on the targeted system.
Versions prior to:
Before installation of the software, please visit the vendor web-site for more details.
Apply fixes issued by the vendor:
風險: 中度風險
類型: 用戶端 - 辦公室應用
Adobe已為產品提供本月保安更新:
| 受影響產品 | 風險程度 | 影響 | 備註 | 詳情(包括 CVE) |
| Adobe InCopy | 中度風險 | 遠端執行程式碼 | APSB25-41 | |
| Adobe Experience Manager | 中度風險 | 權限提升 遠端執行程式碼 跨網站指令碼 繞過保安限制 | APSB25-48 | |
| Adobe Commerce | 中度風險 | 跨網站指令碼 遠端執行程式碼 繞過保安限制 權限提升 | APSB25-50 | |
| Adobe InDesign | 中度風險 | 遠端執行程式碼 資料洩露 阻斷服務 | APSB25-53 | |
| Substance 3D Sampler | 中度風險 | 遠端執行程式碼 | APSB25-55 | |
| Adobe Acrobat and Reader | 中度風險 | 遠端執行程式碼 資料洩露 阻斷服務 繞過保安限制 | APSB25-57 | |
| Substance 3D Painter | 中度風險 | 遠端執行程式碼 | APSB25-58 |
「極高度風險」產品數目:0
「高度風險」產品數目:0
「中度風險」產品數目:7
「低度風險」產品數目:0
整體「風險程度」評估:中度風險
在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。
RISK: Medium Risk
TYPE: Clients - Productivity Products
Adobe has released monthly security update for their products:
| Vulnerable Product | Risk Level | Impacts | Notes | Details (including CVE) |
| Adobe InCopy | Medium Risk | Remote Code Execution | APSB25-41 | |
| Adobe Experience Manager | Medium Risk | Elevation of Privilege Remote Code Execution Cross-site Scripting Security Restriction Bypass | APSB25-48 | |
| Adobe Commerce | Medium Risk | Cross-site Scripting Remote Code Execution Security Restriction Bypass Elevation of Privilege | APSB25-50 | |
| Adobe InDesign | Medium Risk | Remote Code Execution Information Disclosure Denial of Service | APSB25-53 | |
| Substance 3D Sampler | Medium Risk | Remote Code Execution | APSB25-55 | |
| Adobe Acrobat and Reader | Medium Risk | Remote Code Execution Information Disclosure Denial of Service Security Restriction Bypass | APSB25-57 | |
| Substance 3D Painter | Medium Risk | Remote Code Execution | APSB25-58 |
Number of 'Extremely High Risk' product(s): 0
Number of 'High Risk' product(s): 0
Number of 'Medium Risk' product(s): 7
Number of 'Low Risk' product(s): 0
Evaluation of overall 'Risk Level': Medium Risk
Before installation of the software, please visit the vendor web-site for more details.
風險: 極高度風險
類型: 操作系統 - 視窗操作系統
微軟已為產品提供本月保安更新:
| 受影響產品 | 風險程度 | 影響 | 備註 |
| 微軟 Office | 中度風險 | 遠端執行程式碼 權限提升 | |
| 視窗 | 極高度風險 | 遠端執行程式碼 權限提升 資料洩露 阻斷服務 繞過保安限制 仿冒 | CVE-2025-33053 正被廣泛利用。此漏洞存在於 Microsoft Windows Web Distributed Authoring and Versioning。成功利用此漏洞的攻擊者可以觸發遠端執行程式碼。因此,該漏洞的風險等級被評為極高度風險。
CVE-2025-33073 的概念驗證碼已被公開,該漏洞影響 Windows Server Message Block(SMB)用戶端。成功利用此漏洞的授權攻擊者,可以在受影響的系統上提升權限。因此,該漏洞的風險等級被評為中度風險。 |
| 開發者工具 | 中度風險 | 遠端執行程式碼 權限提升 | |
| 延伸安全性更新 (ESU) | 極高度風險 | 遠端執行程式碼 權限提升 資料洩露 阻斷服務 繞過保安限制 | CVE-2025-33053 正被廣泛利用。此漏洞存在於 Microsoft Windows Web Distributed Authoring and Versioning。成功利用此漏洞的攻擊者可以觸發遠端執行程式碼。因此,該漏洞的風險等級被評為極高度風險。
CVE-2025-33073 的概念驗證碼已被公開,該漏洞影響 Windows Server Message Block(SMB)用戶端。成功利用此漏洞的授權攻擊者,可以在受影響的系統上提升權限。因此,該漏洞的風險等級被評為中度風險。 |
| 微軟 Dynamics | 中度風險 | 權限提升 | |
| Azure | 低度風險 | 仿冒 |
「極高度風險」產品數目:2
「高度風險」產品數目:0
「中度風險」產品數目:3
「低度風險」產品數目:1
整體「風險程度」評估:極高度風險
在安裝軟體之前,請先瀏覽軟體供應商之網站,以獲得更多詳細資料。
F5 BIG-IP 阻斷服務漏洞 發佈日期 : 2026 年 09 月 21 日 風險 : 高度風險 於 F5 BIG-IP 發現一個漏洞。遠端攻擊者可利用這漏洞,於目標系統觸發阻斷服務狀況。 注意: 暫無可修補 CVE-2026-11622 的...