Forwarded TWCERT/CC (Taiwan Computer Emergency Response Team and Coordination Center) Security Alert TWCERTCC-200-202610-00000002
【CVE-2026-86950】Apple Multiple Products Out-of-Bounds Write Vulnerability (CVSS v3.1: 8.8)
【Exploited by Ransomware:Unknown】 Apple iOS, macOS and iPadOS have an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution.
【CVE-2026-76504】Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability (CVSS v3.1: 9.8)
【Exploited by Ransomware:Unknown】 Cisco Catalyst SD-WAN Manager has a hex encoding vulnerability. Due to improper handling of
URI encoding in HTTP requests, an unauthenticated remote attacker may exploit this vulnerability to access the affected systems with administrator privileges.
【CVE-2026-104286】Fortinet FortiMail Path Traversal Vulnerability (CVSS v3.1: 9.8)
【Exploited by Ransomware:Unknown】 Fortinet FortiMail has a path traversal vulnerability that may allow an unauthenticated attacker to write arbitrary files to the underlying system through specially crafted HTTP or HTTPS requests.
【CVE-2026-102490】Zammad GmbH Zammad Improper Privilege Management Vulnerability (CVSS v3.1: 9.8)
【Exploited by Ransomware:Unknown】 Zammad GmbH Zammad has an improper privilege management vulnerability that may allow a local zammad user to escalate privileges to root.
【CVE-2026-102489】Zammad GmbH Zammad Session Fixation Vulnerability (CVSS v3.1: 9.8)
【Exploited by Ransomware:Unknown】 Zammad GmbH Zammad has a Session Fixation vulnerability that may allow an attacker to remotely execute arbitrary code as the zammad user.
【CVE-2026-88779】Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVSS v4.0: 8.7)
【Exploited by Ransomware:Unknown】 Citrix NetScaler ADC and Citrix NetScaler Gateway have an improper restriction of operations within the bounds of a memory buffer vulnerability that may lead to denial of service.