Posts of last 24 hours
火绒小问答——「企业版」信任文件
https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247536697&idx=2&sn=7a0e1321f9ad3869c9fb310c7fba1fe5
安全预警:360签名漏洞驱动被恶意利用 可致终端安全防护失效
https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247536697&idx=1&sn=3a18cfe3988300974634b7172c086e5f
A vulnerability identified as very critical has been detected in Microsoft Exchange Server. Affected by this vulnerability is an unknown functionality. This manipulation causes improper access controls.
The identification of this vulnerability is CVE-2026-55006. The attack can only be executed locally. There is no exploit available.
You should upgrade the affected component.
https://vuldb.com/vuln/378500
A vulnerability was found in nodejs node up to 22.23.1/24.18.0/26.5.0. It has been classified as problematic. Affected by this issue is some unknown functionality of the component Agent. Performing a manipulation results in certificate with host mismatch.
This vulnerability is reported as CVE-2026-58040. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.
https://vuldb.com/vuln/384628
A vulnerability described as critical has been identified in nodejs Node.js up to 22.23.1/24.18.0/26.5.0. Impacted is an unknown function of the component Permission Model. Such manipulation leads to improper privilege management.
This vulnerability is referenced as CVE-2026-58043. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.
https://vuldb.com/vuln/384621
A vulnerability was found in nodejs Node.js up to 22.23.1/24.18.0/26.5.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Permission Model. The manipulation results in permission issues.
This vulnerability was named CVE-2026-58039. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.
https://vuldb.com/vuln/384979
A vulnerability was found in nodejs Node.js up to 22.23.1/24.18.0. It has been declared as problematic. This affects an unknown function of the component HTTP2. The manipulation results in uncontrolled memory allocation.
This vulnerability is cataloged as CVE-2026-56846. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
https://vuldb.com/vuln/385735
A vulnerability classified as problematic has been found in uvnc UltraVNC up to 1.8.2.2. Affected by this issue is the function vncWc2Mb of the file rfb/dh.cpp. The manipulation leads to out-of-bounds read.
This vulnerability is documented as CVE-2026-44041. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
https://vuldb.com/vuln/375102
A vulnerability was found in uvnc UltraVNC up to 1.8.2.2. It has been classified as problematic. The impacted element is the function rng of the file rfb/dh.cpp. The manipulation leads to inadequate encryption strength.
This vulnerability is uniquely identified as CVE-2026-7830. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.
https://vuldb.com/vuln/375108
A vulnerability classified as problematic was found in uvnc UltraVNC up to 1.8.2.2 on Windows. Impacted is the function vncRandomBytes of the file rfb/vncauth.c. Such manipulation leads to cryptographically weak prng.
This vulnerability is documented as CVE-2026-44040. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.
https://vuldb.com/vuln/375117