Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2026091411093131 | Publication Time | 2026-09-14 11:36:32 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2026-09-14 11:36:32 |
| Impact Level | Low | ||
| [Subject] 【Vulnerability Alert】CISA Added 11 Known Exploited Vulnerabilities to the KEV Catalog (2026/08/24-2026/08/30) |
|||
| [Content]
Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202609-00000008 【CVE-2026-21962】Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in Improper Access Control Vulnerability (CVSS v3.1: 10.0) 【CVE-2026-60004】Gitea Code Injection Vulnerability (CVSS v3.1: 9.8) 【CVE-2021-23758】Ajax.NET Professional Deserialization of Untrusted Data Vulnerability (CVSS v3.1: 8.1) 【CVE-2015-3246】Red Hat Libuser Race Condition Vulnerability (CVSS v3.1: 5.1) 【CVE-2015-5287】Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability (CVSS v3.1: 7.8) 【CVE-2022-0995】Linux Kernel Out-of-Bounds Write Vulnerability (CVSS v3.1: 7.8) 【CVE-2026-8452】Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVSS v3.1: 9.8) 【CVE-2019-1068】Microsoft SQL Server Remote Code Execution Vulnerability (CVSS v3.1: 8.8) 【CVE-2023-49105】ownCloud Improper Authentication Vulnerability (CVSS v3.1: 9.8) 【CVE-2026-53362】Linux Kernel Unspecified Vulnerability (CVSS v3.1: 7.8) 【CVE-2026-66384】JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability (CVSS v3.1: 5.3) Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed) |
|||
| [Affected Platform]
【CVE-2026-21962】Please refer to the affected versions listed by the official vendor https://www.oracle.com/security-alerts/cpujan2026.html 【CVE-2026-60004】Please refer to the affected versions listed by the official vendor https://github.com/go-gitea/gitea/security/advisories/GHSA-rcr6-4jqh-j84m 【CVE-2021-23758】Please refer to the affected versions listed by the official vendor https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57 【CVE-2015-3246】Please refer to the affected versions listed by the official vendor https://access.redhat.com/articles/1537873 【CVE-2015-5287】Please refer to the affected versions listed by the official vendor https://access.redhat.com/errata/RHSA-2015:2505.html 【CVE-2022-0995】Please refer to the affected versions listed by the official vendor https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=93ce93587d36493f2f86921fa79921b3cba63fbb 【CVE-2026-8452】Please refer to the affected versions listed by the official vendor https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604 【CVE-2019-1068】Please refer to the affected versions listed by the official vendor https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2019-1068 【CVE-2023-49105】Please refer to the affected versions listed by the official vendor https://owncloud.com/security-advisories/webdav-api-authentication-bypass-using-pre-signed-urls/ 【CVE-2026-53362】Please refer to the affected versions listed by the official vendor https://lore.kernel.org/linux-cve-announce/2026070450-CVE-2026-53362-fe9b@gregkh/T/#u 【CVE-2026-66384】Please refer to the affected versions listed by the official vendor https://docs.jfrog.com/releases/docs/jfrog-security-advisories |
|||
|
[Recommended Actions] 【CVE-2026-21962】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://www.oracle.com/security-alerts/cpujan2026.html 【CVE-2026-60004】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://github.com/go-gitea/gitea/security/advisories/GHSA-rcr6-4jqh-j84m 【CVE-2021-23758】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57 【CVE-2015-3246】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://access.redhat.com/articles/1537873 【CVE-2015-5287】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://access.redhat.com/errata/RHSA-2015:2505.html 【CVE-2022-0995】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=93ce93587d36493f2f86921fa79921b3cba63fbb 【CVE-2026-8452】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604 【CVE-2019-1068】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2019-1068 【CVE-2023-49105】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://owncloud.com/security-advisories/webdav-api-authentication-bypass-using-pre-signed-urls/ 【CVE-2026-53362】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://lore.kernel.org/linux-cve-announce/2026070450-CVE-2026-53362-fe9b@gregkh/T/#u 【CVE-2026-66384】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://docs.jfrog.com/releases/docs/jfrog-security-advisories
|
|||
|
[Reference] |
|||