Nye sårbarheter

Sikkerhetsoppdateringer (CVE)

Hva er CVE? CVE er en internasjonal liste over kjente sårbarheter i programvare og maskinvare.
Vi velger å liste opp sårbarheter for Microsoft og FortiNet produkter her.

Microsoft og FortiNet sårbarheter siste 30 dager AKTIV OVERVÅKNING
MICROSOFT CVSS: 8.5
EUVD-2026-70796
Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform spoofing over a network.
Publisert: 03.09.2026SE DETALJER →
MICROSOFT CVSS: 9.1
? EUVD-2026-70798
KRITISK: Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
Publisert: 03.09.2026SE DETALJER →
MICROSOFT CVSS: 8.5
EUVD-2026-70797
Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network.
Publisert: 03.09.2026SE DETALJER →
MICROSOFT CVSS: 10.0
? EUVD-2026-70795
KRITISK: Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
Publisert: 03.09.2026SE DETALJER →
MICROSOFT CVSS: 9.3
? EUVD-2026-70794
KRITISK: Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network.
Publisert: 03.09.2026SE DETALJER →
MICROSOFT CVSS: 10.0
? EUVD-2026-70793
KRITISK: Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.
Publisert: 03.09.2026SE DETALJER →
MICROSOFT CVSS: 8.5
EUVD-2026-70792
Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
Publisert: 03.09.2026SE DETALJER →
MICROSOFT CVSS: 7.4
EUVD-2026-70791
Improper neutralization of special elements in data query logic in Microsoft Discovery Studio allows an unauthorized attacker to disclose information over a network.
Publisert: 03.09.2026SE DETALJER →
MICROSOFT CVSS: 7.8
EUVD-2026-58811
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ".
Publisert: 14.08.2026SE DETALJER →
MICROSOFT CVSS: 9.8
? EUVD-2026-56392
KRITISK: Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.
Publisert: 11.08.2026SE DETALJER →
MICROSOFT CVSS: 7.0
EUVD-2026-56730
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
Publisert: 11.08.2026SE DETALJER →
MICROSOFT CVSS: 7.8
EUVD-2026-56729
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
Publisert: 11.08.2026SE DETALJER →
MICROSOFT CVSS: 7.4
EUVD-2026-56303
Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network.
Publisert: 11.08.2026SE DETALJER →
MICROSOFT CVSS: 7.8
EUVD-2026-56681
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.
Publisert: 11.08.2026SE DETALJER →
MICROSOFT CVSS: 7.8
EUVD-2026-56606
Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.
Publisert: 11.08.2026SE DETALJER →
FORTINET CVSS: 4.8
EUVD-2026-57192
A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow attacker to improper access control via
Publisert: 12.08.2026SE DETALJER →
FORTINET CVSS: 3.4
EUVD-2026-57190
A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIEM 7.3.0 through 7.3.5, FortiSIEM 7.2 all versions, FortiSIEM 7.1 all versions, FortiSIEM 7.0 all versions, FortiSIEM 6.7 all versions, FortiSIEM 6.6 all versions, FortiSIEM 6.5 all versions may allow attacker to execute unauthorized code or commands via
Publisert: 12.08.2026SE DETALJER →
FORTINET CVSS: 5.1
EUVD-2026-57191
A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the context of the WAD daemon via crafted sockets, only if the explicit proxy is configured with Kerberos authentication and SOCKS enabled.
Publisert: 12.08.2026SE DETALJER →
FORTINET CVSS: 7.3
EUVD-2026-57194
A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiManager Cloud 7.2.5 through 7.2.9 may allow attacker to improper access control via
Publisert: 12.08.2026SE DETALJER →
FORTINET CVSS: 8.8
EUVD-2026-57193
An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow a remote unauthenticated attacker to login into the Fortiweb GUI/CLI with a random username and password
Publisert: 12.08.2026SE DETALJER →
FORTINET CVSS: 7.3
EUVD-2026-57188
A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.11 may allow an unauthenticated attacker in a position to alter or craft DNS responses to the targeted host to execute arbitrary code via malicious packets.
Publisert: 12.08.2026SE DETALJER →
FORTINET CVSS: 5.0
EUVD-2026-57189
A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions may allow attacker to denial of service via
Publisert: 12.08.2026SE DETALJER →

Trykk send inn, så sender vi deg oversikt over siste sårbarheter.