2026年7月30日星期四

IBM WebSphere 產品多個漏洞

IBM WebSphere 產品多個漏洞

發佈日期: 2026年07月30日

風險: 中度風險

類型: 伺服器 - 互聯網應用伺服器

於 IBM WebSphere 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發跨網站指令碼、阻斷服務狀況、權限提升、繞過保安限制、敏感資料洩露及遠端執行任意程式碼。


IBM WebSphere Products Multiple Vulnerabilities

IBM WebSphere Products Multiple Vulnerabilities

Release Date: 30 Jul 2026

RISK: Medium Risk

TYPE: Servers - Internet App Servers

Multiple vulnerabilities were identified in IBM WebSphere Products. A remote attacker could exploit some of these vulnerabilities to trigger cross-site scripting, denial of service condition, elevation of privilege, security restriction bypass, sensitive information disclosure and remote code execution on the targeted system.


Impact

  • Denial of Service
  • Elevation of Privilege
  • Remote Code Execution
  • Information Disclosure
  • Cross-Site Scripting
  • Security Restriction Bypass

System / Technologies affected

  • IBM WebSphere Application Server version 8.5, 9.0
  • IBM WebSphere Application Server - Liberty version 17.0.0.3 - 26.0.0.8

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Node.js 多個漏洞

Node.js 多個漏洞

發佈日期: 2026年07月30日

風險: 中度風險

類型: 伺服器 - 其他伺服器

於 Node.js 發現一些漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、繞過保安限制、敏感資料洩露、遠端執行任意程式碼、資料篡改及彷冒。


影響

  • 阻斷服務
  • 權限提升
  • 仿冒
  • 遠端執行程式碼
  • 資料洩露
  • 篡改
  • 繞過保安限制

受影響之系統或技術

  • Node.js 22.23.2 (LTS) 以前的版本
  • Node.js 24.18.1 (LTS) 以前的版本
  • Node.js 26.5.1 (Current) 以前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

  • 更新至 Node.js 22.23.2 (LTS) 版本
  • 更新至 Node.js 24.18.1 (LTS) 版本
  • 更新至 Node.js 26.5.1 (Current) 版本

漏洞識別碼


資料來源


相關連結

Node.js Multiple Vulnerabilities

Node.js Multiple Vulnerabilities

Release Date: 30 Jul 2026

RISK: Medium Risk

TYPE: Servers - Other Servers

Multiple vulnerabilities have been identified in Node.js. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, security restriction bypass, sensitive information disclosure, remote code execution, data manipulation and spoofing on the targeted system.


Impact

  • Denial of Service
  • Elevation of Privilege
  • Spoofing
  • Remote Code Execution
  • Information Disclosure
  • Data Manipulation
  • Security Restriction Bypass

System / Technologies affected

  • Node.js versions prior to 22.23.2 (LTS)
  • Node.js versions prior to 24.18.1 (LTS)
  • Node.js versions prior to 26.5.1 (Current)

Solutions

Before installation of the software, please visit the vendor web-site for more details.

  • Update to Node.js version 22.23.2 (LTS)
  • Update to Node.js version 24.18.1 (LTS)
  • Update to Node.js version 26.5.1 (Current)

Vulnerability Identifier


Source


Related Link

Citrix XenServer 多個漏洞

Citrix XenServer 多個漏洞

發佈日期: 2026年07月30日

風險: 中度風險

類型: 伺服器 - 其他伺服器

於 Citrix XenServer 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、繞過保安限制及資料篡改。


影響

  • 阻斷服務
  • 篡改
  • 繞過保安限制

受影響之系統或技術

  • XenServer 8.4
  • XenServer 9

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Citrix XenServer Multiple Vulnerabilities

Citrix XenServer Multiple Vulnerabilities

Release Date: 30 Jul 2026

RISK: Medium Risk

TYPE: Servers - Other Servers

Multiple vulnerabilities have been identified in Citrix XenServer. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, security restriction bypass and data manipulation on the targeted system.


Impact

  • Denial of Service
  • Data Manipulation
  • Security Restriction Bypass

System / Technologies affected

  • XenServer 8.4
  • XenServer 9

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

GitLab 多個漏洞

GitLab 多個漏洞

發佈日期: 2026年07月30日

風險: 中度風險

類型: 伺服器 - 其他伺服器

於 GitLab 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發洩露敏感資料、資料篡改、跨網站指令碼、阻斷服務狀況、權限提升及繞過保安限制。


影響

  • 資料洩露
  • 繞過保安限制
  • 篡改
  • 跨網站指令碼
  • 阻斷服務
  • 權限提升

受影響之系統或技術

  • GitLab Community Edition (CE) 19.2.1, 19.1.3, 19.0.5 以前的版本
  • GitLab Enterprise Edition (EE) 19.2.1, 19.1.3, 19.0.5 以前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

GitLab Multiple Vulnerabilities

GitLab Multiple Vulnerabilities

Release Date: 30 Jul 2026 5596 Views

RISK: Medium Risk

TYPE: Servers - Other Servers

Multiple vulnerabilities were identified in GitLab. A remote attacker could exploit some of these vulnerabilities to trigger sensitive information disclosure, data manipulation, cross-site scripting, denial of service condition, elevation of privilege and security restriction bypass on the targeted system.


Impact

  • Information Disclosure
  • Security Restriction Bypass
  • Data Manipulation
  • Cross-Site Scripting
  • Denial of Service
  • Elevation of Privilege

System / Technologies affected

  • GitLab Community Edition (CE) versions prior to 19.2.1, 19.1.3, 19.0.5
  • GitLab Enterprise Edition (EE) versions prior to 19.2.1, 19.1.3, 19.0.5

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Xen 多個漏洞

Xen 多個漏洞

發佈日期: 2026年07月30日

風險: 中度風險

類型: 操作系統 - LINUX

於 Xen 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、繞過保安限制及敏感資料洩露。


影響

  • 阻斷服務
  • 資料洩露
  • 繞過保安限制
  • 權限提升

受影響之系統或技術

  • CVE-2026-42492:Xen 4.21 及其後版本均受影響。Xen 4.20 及其之前版本不受影響。
  • CVE-2026-42493:所有使用啟用了 SHADOW_PAGING=y 的 Xen 組建版本之 x86 系統均受影響。在 Xen 4.7 之前,此控制選項並不存在,因此所有組建版本均受影響。Xen 4.6 提供了另一種停用影子分頁的機制,方法是在 make 命令列中傳入 shadow-paging=n。
  • CVE-2026-42494:至少從 Xen 3.2 起的所有版本均受影響。更舊的版本尚未經過檢查。
  • CVE-2026-42495:至少從 Xen 3.2 起的所有版本均受影響。更舊的版本尚未經過檢查。
  • CVE-2026-62423:至少從 Xen 3.2 起的所有版本均受影響。更舊的版本尚未經過檢查。
  • CVE-2026-62424:至少從 Xen 3.2 起的所有版本均受影響。更舊的版本尚未經過檢查。
  • CVE-2026-62425:至少從 Xen 3.2 起的所有版本均受影響。更舊的版本尚未經過檢查。
  • CVE-2026-62426:Xen 4.0 及其後的所有版本均受影響。較舊版本使用不同的鎖定操作,但亦可能受影響。
  • CVE-2026-62427:Xen 4.0 及其後的所有版本均受影響。較舊版本使用不同的鎖定操作,但亦可能受影響。
  • CVE-2026-62428:Xen 4.2 及其後的所有版本均受影響。Xen 4.1 及其之前版本不受影響。Xen 4.13 及其後版本如在組建時停用授權表支援(關閉 CONFIG_GRANT_TABLE),則不受影響。
  • CVE-2026-62429:Xen 4.5 及其後的所有版本均受影響。Xen 4.4 及其之前版本不受影響。只有控制客體(在 x86 上為 HVM 客體)的實體才能利用此漏洞,包括在 stub domain 中執行或在 Dom0 中以低權限執行的裝置模型。只有已啟用 vNUMA 的客體,才會讓控制該客體的實體能夠利用此漏洞。
  • CVE-2026-62430:Xen 3.2 及其後的所有版本均受影響。Xen 3.1 及其之前版本不受影響。
  • CVE-2026-62431:Xen 4.13 及其後的所有版本均受影響。Xen 4.12 及其之前版本不受影響。只有已啟用 Viridian STIMER 的 HVM 客體才能觸發此漏洞。
  • CVE-2026-62432:Xen 4.5 及其後的所有版本均受影響。Xen 4.4 及其之前版本不受影響。
  • CVE-2026-62433:Xen 4.10 及其後的所有版本均受影響。Xen 4.9 及其之前版本不受影響。只有控制 HVM 客體的實體才能利用此漏洞,包括在 stub domain 中執行或在 Dom0 中以低權限執行的裝置模型。
  • CVE-2026-62434:Xen 3.4 及其後的所有版本均受影響。Xen 3.3 及其之前版本不受影響。只有 x86 系統受影響。據信,只有以按需填充(populate-on-demand)模式啟動的 x86 HVM 及 PVH 客體才能利用此漏洞。當客體的 xl 配置中指定的 maxmem 值大於 memory 值時,便會啟用此模式。
  • CVE-2026-62435:Xen 4.0 及其後的所有版本均受影響。Xen 3.4 及其之前版本不受影響。只有獲准使用授權表第 2 版介面的多 vCPU x86 客體才能利用此漏洞。Arm 明確不支援授權表第 2 版。Xen 4.13 及其後版本如在組建時停用授權表支援(關閉 CONFIG_GRANT_TABLE),則不受影響。
  • CVE-2026-62436:Xen 4.0 及其後的所有版本均受影響。Xen 3.4 及其之前版本不受影響。只有獲准使用授權表第 2 版介面的多 vCPU x86 客體才能利用此漏洞。Arm 明確不支援授權表第 2 版。Xen 4.13 及其後版本如在組建時停用授權表支援(關閉 CONFIG_GRANT_TABLE),則不受影響。

解決方案

在安裝軟體之前,請先瀏覽軟體供應商之網站,以獲得更多詳細資料。

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Xen Multiple Vulnerabilities

Xen Multiple Vulnerabilities

Release Date: 30 Jul 2026

RISK: Medium Risk

TYPE: Operating Systems - Linux

Multiple vulnerabilities have been identified in Xen. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, security restriction bypass and sensitive information disclosure on the targeted system.


Impact

  • Denial of Service
  • Information Disclosure
  • Security Restriction Bypass
  • Elevation of Privilege

System / Technologies affected

  • CVE-2026-42492: Xen 4.21 and later are vulnerable. Xen 4.20 and earlier are not vulnerable.
  • CVE-2026-42493: All x86 systems running Xen builds with SHADOW_PAGING=y are affected. Before Xen 4.7, this control did not exist and all builds are affected. Xen 4.6 provided a separate mechanism to disable shadow paging by passing shadow-paging=n on the make command line.
  • CVE-2026-42494: All Xen versions from at least 3.2 onwards are affected. Older versions have not been inspected.
  • CVE-2026-42495: All Xen versions from at least 3.2 onwards are affected. Older versions have not been inspected.
  • CVE-2026-62423: All Xen versions from at least 3.2 onwards are affected. Older versions have not been inspected.
  • CVE-2026-62424: All Xen versions from at least 3.2 onwards are affected. Older versions have not been inspected.
  • CVE-2026-62425: All Xen versions from at least 3.2 onwards are affected. Older versions have not been inspected.
  • CVE-2026-62426: All Xen versions from 4.0 onwards are vulnerable. Earlier versions use a different locking operation but may also be vulnerable.
  • CVE-2026-62427: All Xen versions from 4.0 onwards are vulnerable. Earlier versions use a different locking operation but may also be vulnerable.
  • CVE-2026-62428: All Xen versions from 4.2 onwards are vulnerable. Xen 4.1 and earlier are not vulnerable. Xen 4.13 and later built without grant table support (CONFIG_GRANT_TABLE turned off) are not vulnerable.
  • CVE-2026-62429: All Xen versions from 4.5 onwards are vulnerable. Xen 4.4 and earlier are not vulnerable. Only entities controlling guests—on x86, HVM guests—can leverage the vulnerability. These are device models running in either a stub domain or de-privileged in Dom0. Only guests with vNUMA enabled allow their controlling entities to leverage the vulnerability.
  • CVE-2026-62430: All Xen versions from 3.2 onwards are vulnerable. Xen 3.1 and earlier are not vulnerable.
  • CVE-2026-62431: All Xen versions from 4.13 onwards are vulnerable. Xen 4.12 and earlier are not vulnerable. Only HVM guests with Viridian STIMERs enabled can trigger the vulnerability.
  • CVE-2026-62432: All Xen versions from 4.5 onwards are vulnerable. Xen 4.4 and earlier are not vulnerable.
  • CVE-2026-62433: All Xen versions from 4.10 onwards are vulnerable. Xen 4.9 and earlier are not vulnerable. Only entities controlling HVM guests can leverage the vulnerability. These are device models running in either a stub domain or de-privileged in Dom0.
  • CVE-2026-62434: All Xen versions from 3.4 onwards are vulnerable. Xen 3.3 and earlier are not vulnerable. Only x86 systems are vulnerable. Only x86 HVM and PVH guests started in populate-on-demand mode are believed to be able to leverage the vulnerability. This mode is activated when the guest's xl configuration specifies a maxmem value larger than its memory value.
  • CVE-2026-62435: All Xen versions from 4.0 onwards are vulnerable. Xen 3.4 and earlier are not vulnerable. Only multi-vCPU x86 guests permitted to use grant table version 2 interfaces can leverage the vulnerability. Grant table version 2 is explicitly unsupported on Arm. Xen 4.13 and later built without grant table support (CONFIG_GRANT_TABLE turned off) are not vulnerable.
  • CVE-2026-62436: All Xen versions from 4.0 onwards are vulnerable. Xen 3.4 and earlier are not vulnerable. Only multi-vCPU x86 guests permitted to use grant table version 2 interfaces can leverage the vulnerability. Grant table version 2 is explicitly unsupported on Arm. Xen 4.13 and later built without grant table support (CONFIG_GRANT_TABLE turned off) are not vulnerable.

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

2026年7月29日星期三

F5 產品多個漏洞

F5 產品多個漏洞

發佈日期: 2026年07月29日

風險: 高度風險

類型: 操作系統 - Network

於 F5 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、敏感資料洩露及遠端執行任意程式碼。

 

注意:

對於 BIG-IP Next SPK 版本 2.0.0 - 2.2.1,暫無可修補 CVE-2025-48976 的修補程式。因此,風險等級被評為高度風險。


影響

  • 阻斷服務
  • 遠端執行程式碼
  • 資料洩露

受影響之系統或技術

BIG-IP Next for Kubernetes

  • 版本 2.0.0 - 2.2.1
  • 版本 2.3.0

BIG-IP Next SPK

  • 版本 1.7.0 - 1.7.16
  • 版本 1.8.0 - 1.9.2
  • 版本 2.0.0 - 2.0.3

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:

 


漏洞識別碼


資料來源


相關連結

Mozilla Firefox 多個漏洞

Mozilla Firefox 多個漏洞 發佈日期 : 2026 年 09 月 30 日 於 Mozilla Firefox 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、繞過保安限制、敏感資料洩露、遠端執行任意程式碼及彷冒。 ...