Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2026092404091717 | Publication Time | 2026-09-24 16:18:18 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2026-09-24 16:18:18 |
| Impact Level | Low | ||
| [Subject] 【Vulnerability Alert】CISA Added 7 Known Exploited Vulnerabilities to the KEV Catalog (2026/09/14-2026/09/20) |
|||
| [Content]
Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202609-00000022 【CVE-2026-76461】Cisco Secure Email Gateway SQL Injection Vulnerability (CVSS v3.1: 9.8) 【CVE-2026-58704】Google Pixel Improper Authorization Vulnerability (CVSS v3.1: 8.8) 【CVE-2026-76460】Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability (CVSS v3.1: 10.0) 【CVE-2026-87886】Acronis Backup Incorrect Default Permissions Vulnerability (CVSS v3.1: 7.8) 【CVE-2025-39964】Linux Kernel Race Condition Vulnerability (CVSS v3.1: 7.8) 【CVE-2026-53266】Linux Kernel Out-of-Bounds Write Vulnerability (CVSS v3.1: 8.8) 【CVE-2025-39682】Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability (CVSS v3.1: 9.8) Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed) |
|||
| [Affected Platform]
【CVE-2026-76461】Please refer to the affected versions listed by the official vendor: 【CVE-2026-58704】Please refer to the affected versions listed by the official vendor: 【CVE-2026-76460】Please refer to the affected versions listed by the official vendor: 【CVE-2026-87886】Please refer to the affected versions listed by the official vendor: 【CVE-2025-39964】Please refer to the affected versions listed by the official vendor: 【CVE-2026-53266】Please refer to the affected versions listed by the official vendor: 【CVE-2025-39682】Please refer to the affected versions listed by the official vendor: |
|||
|
[Recommended Actions] 【CVE-2026-76461】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version: 【CVE-2026-58704】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version: 【CVE-2026-76460】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version: 【CVE-2026-87886】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version: 【CVE-2025-39964】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version: 【CVE-2026-53266】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version: 【CVE-2025-39682】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version:
|
|||
|
[Reference] |
|||