Quantcast
Channel: Threat Bulletin Archive - TechCERT
Browsing all 12 articles
Browse latest View live

Image may be NSFW.
Clik here to view.

A Serious Remote Code Execution Flaw Found in Apache Log4j 2 Library

A remote code execution vulnerability was found in multiple versions of the Apache Log4j 2 library. The vulnerability was assigned with CVE-2021-44228. Log4j 2 is an open-source Java logging library...

View Article


Spring4Shell – A Critical Remote Execution Found Spring Framework

Security researchers have found a critical security flaw that can lead to remote code execution in the popular Java Spring Framework. The vulnerability was assigned with CVE-2022-22965 with CVSSv3 base...

View Article


Image may be NSFW.
Clik here to view.

Possible Increase of Intrusion Attempts on Sri Lankan Websites

TechCERT observed that hacktivists are staging intrusions on some Sri Lankan websites, in parallel to the ongoing protests. As a result, an increased number of website intrusions may be reported in...

View Article

Image may be NSFW.
Clik here to view.

A Critical Unauthenticated Remote Code Execution (RCE) Flaw Found in WSO2 API...

A Critical Unauthenticated Remote Code Execution (RCE) through an arbitrary file upload was found in the management console of WSO2 API Manager, Identity Server, Enterprise Integrator. The...

View Article

Image may be NSFW.
Clik here to view.

Cacti Crisis: Severe Vulnerability Exploited in the Wild

A severe vulnerability in the Cacti open-source web-based monitoring solution, identified as CVE-2022-46169 with a CVSS score of 9.8, is being actively exploited in the wild. The vulnerability, which...

View Article


Fortinet fixes critical RCE flaws in FortiNAC and FortiWeb

Fortinet has released security updates for its FortiNAC and FortiWeb products, addressing two critical-severity vulnerabilities that may allow unauthenticated attackers to perform arbitrary code or...

View Article

A Critical Code Execution Flaw Found in FortiOS and FortiProxy Administrative...

A critical vulnerability with CVSSv3 score of 9.3 (critical) has been discovered in FortiOS and FortiProxy administrative interfaces that could allow an attacker to execute arbitrary code or cause a...

View Article

Fortinet Releases Urgent Patches for Critical Pre-Authentication RCE...

Fortinet, a leading provider of network security appliances, recently issued firmware updates for its FortiGate devices to address a critical pre-authentication remote code execution (RCE)...

View Article


WSO2 Releases Patches for Vulnerabilities in API Manager, Identity Server,...

WSO2, a leading provider of open-source API management and identity and access management (IAM) solutions, has issued four security advisories, WSO2-2022-2177, WSO2-2022-2182, WSO2-2022-2023, and...

View Article


Fortinet Patches Critical Remote Code Execution Vulnerability in...

A critical severity flaw has been identified in Fortinet’s FortiOS and FortiProxy devices, designated as CVE-2023-33308. This vulnerability allows a remote attacker to execute arbitrary code on...

View Article

Critical Remote Code Execution Vulnerability Found in FortiOS SSL VPN

A critical vulnerability, identified as CVE-2024-21762, has been discovered in FortiOS SSL VPN. This out-of-bounds write flaw, with a severity score of 9.6, allows unauthenticated attackers to execute...

View Article

Critical Command Injection Vulnerability Found in Palo Alto Networks...

A critical vulnerability has been identified in Palo Alto Networks PAN-OS, specifically affecting the GlobalProtect gateways and portals. Designated as CVE-2024-3400, this command injection flaw...

View Article
Browsing all 12 articles
Browse latest View live


Latest Images