2026年1月16日星期五

Juniper Junos OS Multiple Vulnerabilities

Juniper Junos OS Multiple Vulnerabilities

Release Date: 16 Jan 2026

RISK: Medium Risk

TYPE: Operating Systems - Networks OS

Multiple vulnerabilities were identified in Juniper Junos OS. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution, denial of service condition, sensitive information disclosure, elevation of privilege and security restriction bypass on the targeted system.


Impact

  • Denial of Service
  • Information Disclosure
  • Security Restriction Bypass
  • Elevation of Privilege
  • Remote Code Execution

System / Technologies affected

  • Junos OS
  • Junos OS Evolved

Please refer to the link below for detail:

https://supportportal.juniper.net/s/global-search/%40uri#sortCriteria=date%20descending&f-sf_articletype=Security%20Advisories&numberOfResults=25


Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Please refer to 2026-01 Security Bulletin.


Vulnerability Identifier


Source


Related Link

2026年1月15日星期四

Aruba 產品多個漏洞

Aruba 產品多個漏洞

發佈日期: 2026年01月15日

風險: 中度風險

類型: 保安軟件及應用設備 - 保安軟件及應用設備

在Aruba產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、繞過保安限制、資料篡改及遠端執行任意程式碼。


影響

  • 遠端執行程式碼
  • 篡改
  • 繞過保安限制
  • 阻斷服務

受影響之系統或技術

  • AOS-10.7.x.x: 10.7.2.1 及以下版本
  • AOS-10.4.x.x: 10.4.1.9 及以下版本
  • AOS-8.13.x.x: 8.13.1.0 及以下版本
  • AOS-8.10.x.x: 8.10.0.20 及以下版本

 

HPE Aruba Networking 終止維護 (EoM) 的版本:

 

  • AOS-10.6.x.x: 所有版本
  • AOS-10.5.x.x: 所有版本
  • AOS-10.3.x.x: 所有版本
  • AOS-8.12.x.x: 所有版本
  • AOS-8.11.x.x: 所有版本
  • AOS-8.9.x.x: 所有版本
  • AOS-8.8.x.x: 所有版本
  • AOS-8.7.x.x: 所有版本
  • AOS-8.6.x.x: 所有版本
  • AOS-6.5.4.x: 所有版本
  • SD-WAN 8.7.0.0-2.3.0.x: 所有版本
  • SD-WAN 8.6.0.4-2.2.x.x: 所有版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:

注意:解決方案不適用於終止維護(EoM)的版本。


漏洞識別碼


資料來源


相關連結

Aruba Products Multiple Vulnerabilities

Aruba Products Multiple Vulnerabilities

Release Date: 15 Jan 2026

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

Multiple vulnerabilities were identified in Aruba Products. A remote attacker could exploit these vulnerabilities to trigger denial of service condition, security restriction bypass, data manipulation and remote code execution on the targeted system.


Impact

  • Remote Code Execution
  • Data Manipulation
  • Security Restriction Bypass
  • Denial of Service

System / Technologies affected

  • AOS-10.7.x.x: 10.7.2.1 and below
  • AOS-10.4.x.x: 10.4.1.9 and below
  • AOS-8.13.x.x: 8.13.1.0 and below
  • AOS-8.10.x.x: 8.10.0.20 and below

 

HPE Aruba Networking End of Maintenance (EoM) Software Version(s):

 

  • AOS-10.6.x.x: all
  • AOS-10.5.x.x: all
  • AOS-10.3.x.x: all
  • AOS-8.12.x.x: all
  • AOS-8.11.x.x: all
  • AOS-8.9.x.x: all
  • AOS-8.8.x.x: all
  • AOS-8.7.x.x: all
  • AOS-8.6.x.x: all
  • AOS-6.5.4.x: all
  • SD-WAN 8.7.0.0-2.3.0.x: all
  • SD-WAN 8.6.0.4-2.2.x.x: all

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:

Note: End of Maintenance (EoM) versions are not addressed by the provided solution.


Vulnerability Identifier


Source


Related Link

Mozilla 產品多個漏洞

Mozilla 產品多個漏洞

發佈日期: 2026年01月15日

風險: 中度風險

類型: 用戶端 - 瀏覽器

於 Mozilla 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發仿冒、繞過保安限制、遠端執行任意程式碼及敏感資料洩露。


影響

  • 資料洩露
  • 繞過保安限制
  • 遠端執行程式碼
  • 仿冒

受影響之系統或技術

以下版本之前的版本﹕

 

  • Firefox ESR 115.32
  • Firefox ESR 140.7
  • Firefox 147
  • Thunderbird ESR 140.7
  • Thunderbird 147

解決方案

在安裝軟體之前,請先瀏覽供應商之官方網站,以獲得更多詳細資料。

更新至版本:

 

  • Firefox ESR 115.32
  • Firefox ESR 140.7
  • Firefox 147
  • Thunderbird ESR 140.7
  • Thunderbird 147

漏洞識別碼


資料來源


相關連結

Mozilla Products Multiple Vulnerabilities

Mozilla Products Multiple Vulnerabilities

Release Date: 15 Jan 2026

RISK: Medium Risk

TYPE: Clients - Browsers

Multiple vulnerabilities were identified in Mozilla Products. A remote attacker could exploit some of these vulnerabilities to trigger spoofing, security restriction bypass, remote code execution and sensitive information disclosure on the targeted system.


Impact

  • Information Disclosure
  • Security Restriction Bypass
  • Remote Code Execution
  • Spoofing

System / Technologies affected

Versions prior to:

 

  • Firefox ESR 115.32
  • Firefox ESR 140.7
  • Firefox 147
  • Thunderbird ESR 140.7
  • Thunderbird 147

Solutions

Before installation of the software, please visit the vendor web-site for more details.

Apply fixes issued by the vendor:

 

  • Firefox ESR 115.32
  • Firefox ESR 140.7
  • Firefox 147
  • Thunderbird ESR 140.7
  • Thunderbird 147

Vulnerability Identifier


Source


Related Link

Palo Alto PAN-OS 阻斷服務狀況漏洞

Palo Alto PAN-OS 阻斷服務狀況漏洞

發佈日期: 2026年01月15日

風險: 中度風險

類型: 保安軟件及應用設備 - 保安軟件及應用設備

在 Palo Alto PAN-OS 發現一個漏洞。遠端攻擊者可利用此漏洞,於目標系統觸發阻斷服務狀況。


影響

  • 阻斷服務

受影響之系統或技術

  • PAN-OS 10.1.14-h20 之前的 PAN-OS 10.1 版本
  • PAN-OS 10.2.7-h32、10.2.10-h30、10.2.13-h18、10.2.16-h6、10.2.18-h1 之前的 PAN-OS 10.2 版本
  • PAN-OS 11.1.4-h27、11.1.6-h23、11.1.10-h9、11.1.13 之前的 PAN-OS 11.1 版本
  • PAN-OS 11.2.4-h15、11.2.7-h8、11.2.10-h2 之前的 PAN-OS 11.2 版本
  • PAN-OS 12.1.3-h3、12.1.4 之前的 PAN-OS 12.1 版本
  • PAN-OS Prisma Access 10.2.10-h29 之前的 PAN-OS Prisma Access 10.2 版本
  • PAN-OS Prisma Access 11.2.7-h8 之前的 PAN-OS Prisma Access 11.2 版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 


漏洞識別碼


資料來源


相關連結

Palo Alto PAN-OS Denial Of Service Vulnerability

Palo Alto PAN-OS Denial Of Service Vulnerability

Release Date: 15 Jan 2026

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

A vulnerability was identified in Palo Alto PAN-OS. A remote attacker can exploit this vulnerability to trigger denial of service condition on the targeted system.


Impact

  • Denial of Service

System / Technologies affected

  • PAN-OS 10.1 versions earlier than PAN-OS 10.1.14-h20
  • PAN-OS 10.2 versions earlier than PAN-OS 10.2.7-h32, 10.2.10-h30, 10.2.13-h18, 10.2.16-h6, 10.2.18-h1
  • PAN-OS 11.1 versions earlier than PAN-OS 11.1.4-h27, 11.1.6-h23, 11.1.10-h9, 11.1.13
  • PAN-OS 11.2 versions earlier than PAN-OS 11.2.4-h15, 11.2.7-h8, 11.2.10-h2
  • PAN-OS 12.1 versions earlier than PAN-OS 12.1.3-h3, 12.1.4
  • PAN-OS Prisma Access 10.2 versions earlier than 10.2.10-h29
  • PAN-OS Prisma Access 11.2 versions earlier than 11.2.7-h8

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 


Vulnerability Identifier


Source


Related Link

2026年1月14日星期三

Adobe 每月保安更新 (2026年1月)

Adobe 每月保安更新 (2026年1月)

發佈日期: 2026年01月14日

風險: 中度風險

類型: 用戶端 - 辦公室應用

Adobe已為產品提供本月保安更新:

 

受影響產品風險程度影響備註詳情(包括 CVE)
Adobe Dreamweaver中度風險 中度風險遠端執行程式碼
篡改
 APSB26-01
Adobe InDesign中度風險 中度風險

遠端執行程式碼

資料洩露

 APSB26-02
Adobe Illustrator中度風險 中度風險遠端執行程式碼
阻斷服務
 APSB26-03
Adobe InCopy中度風險 中度風險遠端執行程式碼 APSB26-04
Adobe Bridge中度風險 中度風險遠端執行程式碼 APSB26-07
Substance 3D Modeler中度風險 中度風險

遠端執行程式碼
阻斷服務

資料洩露

 APSB26-08
Substance 3D Stager中度風險 中度風險遠端執行程式碼 APSB26-09
Substance 3D Painter中度風險 中度風險遠端執行程式碼 APSB26-10
Substance 3D Sampler中度風險 中度風險遠端執行程式碼 APSB26-11
Adobe ColdFusion中度風險 中度風險遠端執行程式碼 APSB26-12
Substance 3D Designer中度風險 中度風險資料洩露 APSB26-13

 

「極高度風險」產品數目:0

「高度風險」產品數目:0

「中度風險」產品數目:11

「低度風險」產品數目:0

整體「風險程度」評估:中度風險


影響

  • 遠端執行程式碼
  • 資料洩露
  • 篡改
  • 阻斷服務

受影響之系統或技術

  • Adobe Dreamweaver  21.6 及以前版本
  • Adobe InDesign ID21.0 及以前版本
  • Adobe InDesign ID19.5.5 及以前版本
  • Illustrator 2025 29.8.3 及以前版本
  • Illustrator 2026 30.0 及以前版本
  • Adobe InCopy  21.0 及以前版本
  • Adobe InCopy  19.5.5 及以前版本
  • Adobe Bridge  15.1.2 (LTS) 及以前版本
  • Adobe Bridge  16.0 及以前版本
  • Adobe Substance 3D Modeler 1.22.4 及以前版本
  • Adobe Substance 3D Stager 3.1.5 及以前版本
  • Adobe Substance 3D Painter 11.0.3 及以前版本
  • Adobe Substance 3D Sampler 5.1.0 及以前版本
  • ColdFusion 2025 Update 5 及以前版本
  • ColdFusion 2023 Update 17 及以前版本
  • Adobe Substance 3D Designer 15.0.3 及以前版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

  • 安裝供應商提供的修補程式。個別產品詳情可參考上表「詳情」一欄或執行軟件更新。

漏洞識別碼


資料來源


相關連結

Adobe Monthly Security Update (January 2026)

Adobe Monthly Security Update (January 2026)

Release Date: 14 Jan 2026

RISK: Medium Risk

TYPE: Clients - Productivity Products

Adobe has released monthly security update for their products:

 

Vulnerable ProductRisk LevelImpactsNotesDetails (including CVE)
Adobe DreamweaverMedium Risk Medium RiskRemote Code Execution
Data Manipulation
 APSB26-01
Adobe InDesignMedium Risk Medium Risk

Remote Code Execution

Information Disclosure

 APSB26-02
Adobe IllustratorMedium Risk Medium RiskRemote Code Execution
Denial of Service
 APSB26-03
Adobe InCopyMedium Risk Medium RiskRemote Code Execution APSB26-04
Adobe BridgeMedium Risk Medium RiskRemote Code Execution APSB26-07
Substance 3D ModelerMedium Risk Medium Risk

Remote Code Execution
Denial of Service

Information Disclosure

 APSB26-08
Substance 3D StagerMedium Risk Medium RiskRemote Code Execution APSB26-09
Substance 3D PainterMedium Risk Medium RiskRemote Code Execution APSB26-10
Substance 3D SamplerMedium Risk Medium RiskRemote Code Execution APSB26-11
Adobe ColdFusionMedium Risk Medium RiskRemote Code Execution APSB26-12
Substance 3D DesignerMedium Risk Medium RiskInformation Disclosure APSB26-13

 

Number of 'Extremely High Risk' product(s): 0

Number of 'High Risk' product(s): 0

Number of 'Medium Risk' product(s): 11

Number of 'Low Risk' product(s): 0

Evaluation of overall 'Risk Level': Medium Risk


Impact

  • Remote Code Execution
  • Information Disclosure
  • Data Manipulation
  • Denial of Service

System / Technologies affected

  • Adobe Dreamweaver  21.6 and earlier versions
  • Adobe InDesign ID21.0 and earlier versions
  • Adobe InDesign ID19.5.5 and earlier versions
  • Illustrator 2025 29.8.3 and earlier versions
  • Illustrator 2026 30.0 and earlier versions
  • Adobe InCopy  21.0 and earlier versions
  • Adobe InCopy  19.5.5 and earlier versions
  • Adobe Bridge  15.1.2 (LTS) and earlier versions
  • Adobe Bridge  16.0 and earlier versions
  • Adobe Substance 3D Modeler 1.22.4 and earlier versions
  • Adobe Substance 3D Stager 3.1.5 and earlier versions
  • Adobe Substance 3D Painter 11.0.3 and earlier versions
  • Adobe Substance 3D Sampler 5.1.0 and earlier versions
  • ColdFusion 2025 Update 5 and earlier versions
  • ColdFusion 2023 Update 17 and earlier versions
  • Adobe Substance 3D Designer 15.0.3 and earlier versions

Solutions

Before installation of the software, please visit the vendor web-site for more details.

  • Apply fixes issued by the vendor. Please refer to 'Details' column in the above table for details of individual product update or run software update.

Vulnerability Identifier


Source


Related Link

Fortinet 產品遠端執行程式碼漏洞

Fortinet 產品遠端執行程式碼漏洞

發佈日期: 2026年01月14日

風險: 中度風險

類型: 操作系統 - Network

於 Fortinet 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼。


影響

  • 遠端執行程式碼

受影響之系統或技術

FortiClientEMS

  • FortiClientEMS 7.0 所有版本
  • FortiClientEMS 7.2.0 至 7.2.10
  • FortiClientEMS 7.4.0 至 7.4.1
  • FortiClientEMS 7.4.3 至 7.4.4

FortiOS

  • FortiOS 6.4.0 至 6.4.16
  • FortiOS 7.0.0 至 7.0.17
  • FortiOS 7.2.0 至 7.2.11
  • FortiOS 7.4.0 至 7.4.8
  • FortiOS 7.6.0 至 7.6.3

FortiSwitchManager

  • FortiSwitchManager 7.0.0 至 7.0.5
  • FortiSwitchManager 7.2.0 至 7.2.6

FortiSASE

  • FortiSASE 25.1.a
  • FortiSASE 25.2.b

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Fortinet Products Remote Code Execution Vulnerabilities

Fortinet Products Remote Code Execution Vulnerabilities

Release Date: 14 Jan 2026

RISK: Medium Risk

TYPE: Operating Systems - Networks OS

Multiple vulnerabilities were identified in Fortinet Products. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution on the targeted system.


Impact

  • Remote Code Execution

System / Technologies affected

FortiClientEMS

  • FortiClientEMS 7.0 all versions
  • FortiClientEMS 7.2.0 through 7.2.10
  • FortiClientEMS 7.4.0 through 7.4.1
  • FortiClientEMS 7.4.3 through 7.4.4

FortiOS

  • FortiOS 6.4.0 through 6.4.16
  • FortiOS 7.0.0 through 7.0.17
  • FortiOS 7.2.0 through 7.2.11
  • FortiOS 7.4.0 through 7.4.8
  • FortiOS 7.6.0 through 7.6.3

FortiSwitchManager

  • FortiSwitchManager 7.0.0 through 7.0.5
  • FortiSwitchManager 7.2.0 through 7.2.6

FortiSASE

  • FortiSASE 25.1.a
  • FortiSASE 25.2.b

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

Google Chrome 多個漏洞

Google Chrome 多個漏洞

發佈日期: 2026年01月14日

風險: 中度風險

類型: 用戶端 - 瀏覽器

於 Google Chrome 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、遠端執行任意程式碼及繞過保安限制。


影響

  • 遠端執行程式碼
  • 阻斷服務
  • 繞過保安限制

受影響之系統或技術

  • Google Chrome 144.0.7559.59 (Linux) 之前的版本
  • Google Chrome 144.0.7559.59/60 (Mac) 之前的版本
  • Google Chrome 144.0.7559.59/60 (Windows) 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 144.0.7559.59 (Linux) 或之後版本
  • 更新至 144.0.7559.59/60 (Mac) 或之後版本
  • 更新至 144.0.7559.59/60 (Windows) 或之後版本

漏洞識別碼


資料來源


相關連結

Google Chrome Multiple Vulnerabilities

Google Chrome Multiple Vulnerabilities

Release Date: 14 Jan 2026

RISK: Medium Risk

TYPE: Clients - Browsers

Multiple vulnerabilities were identified in Google Chrome. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, remote code execution and security restriction bypass on the targeted system.


Impact

  • Remote Code Execution
  • Denial of Service
  • Security Restriction Bypass

System / Technologies affected

  • Google Chrome prior to 144.0.7559.59 (Linux)
  • Google Chrome prior to 144.0.7559.59/60 (Mac)
  • Google Chrome prior to 144.0.7559.59/60 (Windows)

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 144.0.7559.59 (Linux) or later
  • Update to version 144.0.7559.59/60 (Mac) or later
  • Update to version 144.0.7559.59/60 (Windows) or later

Vulnerability Identifier


Source


Related Link

微軟每月保安更新 (2026年1月)

微軟每月保安更新 (2026年1月)

發佈日期: 2026年01月14日

風險: 中度風險

類型: 操作系統 - 視窗操作系統

微軟已為產品提供本月保安更新:

 

受影響產品風險程度影響備註
視窗中度風險 中度風險資料洩露
繞過保安限制
遠端執行程式碼
篡改
權限提升
仿冒
阻斷服務

CVE-2026-20805 正被廣泛利用。此漏洞存在於 Desktop Window Manager。成功利用此漏洞的已授權攻擊者可以在本地洩露資訊。因此,該漏洞的風險等級被評為中度風險。

 

CVE-2026-21265 被視為公開披露。此漏洞存在於 Windows Secure Boot。 Microsoft憑證儲存於Unified Extensible Firmware Interface Key Enrollment Key 以及DB. 為確保Secure Boot功能持續運作並預防未來問題發生,必須更新這些憑證。

延伸安全性更新 (ESU)中度風險 中度風險繞過保安限制
遠端執行程式碼
資料洩露
權限提升
仿冒
阻斷服務
CVE-2026-20805 正被廣泛利用。此漏洞存在於 Desktop Window Manager。成功利用此漏洞的已授權攻擊者可以在本地洩露資訊。因此,該漏洞的風險等級被評為中度風險。
SQL Server中度風險 中度風險權限提升 
Azure中度風險 中度風險權限提升
遠端執行程式碼
 
微軟 Office中度風險 中度風險遠端執行程式碼
仿冒
繞過保安限制
資料洩露
 
開發者工具中度風險 中度風險遠端執行程式碼 
瀏覽器低度風險 低度風險  
開源軟件低度風險 低度風險  
Mariner低度風險 低度風險  

 

「極高度風險」產品數目:0

「高度風險」產品數目:0

「中度風險」產品數目:6

「低度風險」產品數目:3

整體「風險程度」評估:中度風險


影響

  • 遠端執行程式碼
  • 阻斷服務
  • 資料洩露
  • 權限提升
  • 仿冒
  • 繞過保安限制
  • 篡改

受影響之系統或技術

  • 視窗
  • 延伸安全性更新 (ESU)
  • SQL Server
  • Azure
  • 微軟 Office
  • 開發者工具
  • 瀏覽器
  • 開源軟件
  • Mariner

解決方案

在安裝軟體之前,請先瀏覽軟體供應商之網站,以獲得更多詳細資料。

  • 安裝軟件供應商提供的修補程式。

漏洞識別碼


資料來源


相關連結

Microsoft Monthly Security Update (January 2026)

Microsoft Monthly Security Update (January 2026)

Release Date: 14 Jan 2026

RISK: Medium Risk

TYPE: Operating Systems - Windows OS

Microsoft has released monthly security update for their products:

 

Vulnerable ProductRisk LevelImpactsNotes
WindowsMedium Risk Medium RiskInformation Disclosure
Security Restriction Bypass
Remote Code Execution
Data Manipulation
Elevation of Privilege
Spoofing
Denial of Service

CVE-2026-20805 is being exploited in the wild. This vulnerability exist in Desktop Window Manager. Successful exploitation of this vulnerability could allow an authorized attacker to disclose information locally.  Hence, the risk level of this vulnerability is rated as Medium Risk.

 

CVE-2026-21265 is considered publicly disclosed. This vulnerability exist in the Windows Secure Boot. Microsoft certificates are stored in the Unified Extensible Firmware Interface Key Enrollment Key and DB. These certificates need to be updated to ensure Secure Boot functionality remains and to prevent future issues from arising. 

Extended Security Updates (ESU)Medium Risk Medium RiskSecurity Restriction Bypass
Remote Code Execution
Information Disclosure
Elevation of Privilege
Spoofing
Denial of Service

CVE-2026-20805 is being exploited in the wild. This vulnerability exist in Desktop Window Manager. Successful exploitation of this vulnerability could allow an authorized attacker to disclose information locally.  Hence, the risk level of this vulnerability is rated as Medium Risk.

SQL ServerMedium Risk Medium RiskElevation of Privilege 
AzureMedium Risk Medium RiskElevation of Privilege
Remote Code Execution
 
Microsoft OfficeMedium Risk Medium RiskRemote Code Execution
Spoofing
Security Restriction Bypass
Information Disclosure
 
Developer ToolsMedium Risk Medium RiskRemote Code Execution 
BrowserLow Risk Low Risk  
Open Source SoftwareLow Risk Low Risk  
MarinerLow Risk Low Risk  

 

Number of 'Extremely High Risk' product(s): 0

Number of 'High Risk' product(s): 0

Number of 'Medium Risk' product(s): 6

Number of 'Low Risk' product(s): 3

Evaluation of overall 'Risk Level': Medium Risk


Impact

  • Remote Code Execution
  • Denial of Service
  • Information Disclosure
  • Elevation of Privilege
  • Spoofing
  • Security Restriction Bypass
  • Data Manipulation

System / Technologies affected

  • Windows
  • Extended Security Updates (ESU)
  • SQL Server
  • Azure
  • Microsoft Office
  • Developer Tools
  • Browser
  • Open Source Software
  • Mariner

Solutions

Before installation of the software, please visit the vendor web-site for more details.

  •  Apply fixes issued by the vendor.

Vulnerability Identifier


Source


Related Link

2026年1月13日星期二

Apache Struts 阻斷服務漏洞

Apache Struts 阻斷服務漏洞

發佈日期: 2026年01月13日

風險: 中度風險

類型: 伺服器 - 網站伺服器

於Apache Struts發現一個漏洞。遠端使用者可利用此漏洞,於目標系統觸發阻斷服務狀況、洩露敏感資料及繞過保安限制。


影響

  • 阻斷服務
  • 繞過保安限制
  • 資料洩露

受影響之系統或技術

  • Struts 2.0.0 至 Struts 2.3.37 (EOL)
  • Struts 2.5.0 至 Struts 2.5.33 (EOL)
  • Struts 6.0.0 至 Struts 6.1.0

解決方案

在安裝軟體之前,請先瀏覽軟體供應商之網站,以獲得更多詳細資料。

  • 至少更新至 Struts 6.1.1 版本

 


漏洞識別碼


資料來源


相關連結

Apache Struts Denial of Service Vulnerability

Apache Struts Denial of Service Vulnerability

Release Date: 13 Jan 2026

RISK: Medium Risk

TYPE: Servers - Web Servers

A vulnerability was identified in Apache Struts. A remote user can exploit this vulnerability to trigger denial of service condition, sensitive information disclosure and security restriction bypass on the targeted system.

 


Impact

  • Denial of Service
  • Security Restriction Bypass
  • Information Disclosure

System / Technologies affected

  • Struts 2.0.0 through Struts 2.3.37 (EOL)
  • Struts 2.5.0 through Struts 2.5.33 (EOL)
  • Struts 6.0.0 through Struts 6.1.0

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Upgrade to Struts 6.1.1 at least

Vulnerability Identifier


Source


Related Link

TP-Link 路由器多個漏洞

TP-Link 路由器多個漏洞

發佈日期: 2026年01月13日

風險: 中度風險

類型: 操作系統 - Network

於 TP-Link 路由器 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況及資料篡改。

 

影響

  • 阻斷服務
  • 篡改

受影響之系統或技術

  • Archer BE400 從 0 至 1.1.0 Build 20250710 rel.14914
  • Archer AXE75 從 0 至 build 20250107

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

TP-Link Router Multiple Vulnerabilities

TP-Link Router Multiple Vulnerabilities

Release Date: 13 Jan 2026

RISK: Medium Risk

TYPE: Operating Systems - Networks OS

Multiple vulnerabilities were identified in TP-Link Router. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition and data manipulation on the targeted system.


Impact

  • Denial of Service
  • Data Manipulation

System / Technologies affected

  • Archer BE400 from 0 through 1.1.0 Build 20250710 rel.14914
  • Archer AXE75 from 0 through build 20250107
 

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

2026年1月12日星期一

Microsoft Edge 繞過保安限制漏洞

Microsoft Edge 繞過保安限制漏洞

發佈日期: 2026年01月12日

風險: 中度風險

類型: 用戶端 - 瀏覽器

於微軟 Edge 發現一個漏洞。遠端攻擊者可利用此漏洞,於目標系統觸發繞過保安限制。


影響

  • 繞過保安限制

受影響之系統或技術

  • Microsoft Edge 143.0.3650.139 之前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

安裝軟件供應商提供的修補程式:

  • 更新至 143.0.3650.139 或之後版本

漏洞識別碼


資料來源


相關連結

Microsoft Edge Security Restriction Bypass Vulnerability

Microsoft Edge Security Restriction Bypass Vulnerability

Release Date: 12 Jan 2026

RISK: Medium Risk

TYPE: Clients - Browsers

A vulnerability was identified in Microsoft Edge. A remote attacker could exploit this vulnerability to trigger security restriction bypass on the targeted system.


Impact

  • Security Restriction Bypass

System / Technologies affected

  • Microsoft Edge version prior to 143.0.3650.139

Solutions

Before installation of the software, please visit the software vendor web-site for more details.

Apply fixes issued by the vendor:

  • Update to version 143.0.3650.139 or later

Vulnerability Identifier


Source


Related Link

Ubuntu Linux 核心多個漏洞

Ubuntu Linux 核心多個漏洞

發佈日期: 2026年01月12日

風險: 中度風險

類型: 操作系統 - LINUX

於 Ubuntu Linux 核心發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況及洩露敏感資料。


影響

  • 阻斷服務
  • 資料洩露

受影響之系統或技術

  • Ubuntu 18.04 LTS
  • Ubuntu 20.04 LTS
  • Ubuntu 22.04 LTS
  • Ubuntu 24.04 LTS

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

思科產品多個漏洞

思科產品多個漏洞 於思科產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況,資料篡改及繞過保安限制。 影響 阻斷服務 繞過保安限制 篡改 受影響之系統或技術 Cisco IOS Cisco IOS XE 請參考供應商發佈的連結以了解受影響的版本: https:...