CISA เพิ่มช่องโหว่ที่ถูกใช้โจมตี 8 รายการลงในแคตตาล็อก
-
เมื่อวันที่ 8-9 กันยายน 2569 Cybersecurity and Infrastructure Security Agency (CISA) ได้เพิ่มช่องโหว่ใหม่ 8 รายการลงในแคตตาล็อก Known Exploited Vulnerabilities (KEV) จากหลักฐานที่พบว่ามีการโจมตีใช้งานจริงแล้ว มีรายละเอียดดังนี้
- CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
- CVE-2026-81963 Microsoft Windows Link Following Vulnerability
- CVE-2026-85880 Microsoft Windows Heap-Based Buffer Overflow Vulnerability
- CVE-2026-86218 N-able N-central Static Code Injection Vulnerability
- CVE-2025-25249 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
- CVE-2026-19490 Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
- CVE-2026-87491 Google Chromium V8 Out of Bounds Write Vulnerability
- CVE-2026-20079 Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability
อ้างอิง
https://www.cisa.gov/news-events/alerts/2026/09/08/cisa-adds-four-known-exploited-vulnerabilities-catalog
https://www.cisa.gov/news-events/alerts/2026/09/09/cisa-adds-four-known-exploited-vulnerabilities-catalogสามารถติดตามข่าวสารได้ที่ webboard หรือ Facebook NCSA Thailand
