Saltar para o conteúdo
Mapa esquemático do panorama institucional de segurança digitalIlustração simplificada dos continentes, assinalando com um ponto a localização aproximada de catorze organismos de segurança digital em seis continentes. Os mesmos elementos, com a mesma função, estão disponíveis na lista ao lado.

Vulnerabilidades exploradas ativamente

Catálogos CISA KEV e EUVD/ENISA — as dez mais recentes; as que correspondem a um fabricante vigiado aparecem a vermelho.

Última recolha: 13/08/26, 23:01

  • CVE: CVE-2026-20349[fabricante vigiado]EUVD / ENISA

    Fabricante / produto: Cisco

    A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.  This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.

    Ver na fonte ↗

    Gravidade: [Alto · CVSS 8.6]

    Prazo: sem prazo

  • CVE: CVE-2026-68820[fabricante vigiado]EUVD / ENISA

    Fabricante / produto: Microsoft

    Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

    Ver na fonte ↗

    Gravidade: [Alto · CVSS 7.0]

    Prazo: sem prazo

  • CVE: CVE-2026-20349[fabricante vigiado]CISA KEV

    Fabricante / produto: Cisco · Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)

    Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.

    Ver na fonte ↗

    Gravidade: [Exploração ativa confirmada]

    Prazo: 14/08/26

  • CVE: CVE-2026-68820[fabricante vigiado]CISA KEV

    Fabricante / produto: Microsoft · Windows Ancillary Function Driver for WinSock

    Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.

    Ver na fonte ↗

    Gravidade: [Exploração ativa confirmada]

    Prazo: 25/08/26

  • CVE: CVE-2026-72898CISA KEV

    Fabricante / produto: Metabase · Metabase

    Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.

    Ver na fonte ↗

    Gravidade: [Exploração ativa confirmada]

    Prazo: 14/08/26

  • CVE: CVE-2026-72898EUVD / ENISA

    Fabricante / produto: metabase

    Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.

    Ver na fonte ↗

    Gravidade: [Crítico · CVSS 10.0]

    Prazo: sem prazo

  • CVE: CVE-2026-8037CISA KEV

    Fabricante / produto: Progress · LoadMaster

    Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.

    Ver na fonte ↗

    Gravidade: [Exploração ativa confirmada]

    Prazo: 10/08/26

  • CVE: CVE-2026-63077CISA KEV

    Fabricante / produto: JetBrains · TeamCity

    JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.

    Ver na fonte ↗

    Gravidade: [Exploração ativa confirmada]

    Prazo: 08/08/26

  • CVE: CVE-2026-18556CISA KEV

    Fabricante / produto: N-able · N-central

    N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.

    Ver na fonte ↗

    Gravidade: [Exploração ativa confirmada]

    Prazo: 07/08/26

  • CVE: CVE-2026-34486CISA KEV

    Fabricante / produto: Apache · Tomcat

    Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.

    Ver na fonte ↗

    Gravidade: [Exploração ativa confirmada]

    Prazo: 07/08/26

Ver o arquivo completo (1670 vulnerabilidades)

Radar

O que se passa em tecnologia — Angola, Portugal, África e mundo, com destaque para cibersegurança. Selecionado por nós, escrito por quem assina cada artigo.

Filtrar notícias por categoria

Fontes vigiadas
22
Vulnerabilidades acompanhadas
1670
Itens recolhidos
0

Panorama institucional

Catorze organismos, seis continentes. Nem todos têm um catálogo ou feed consultável — em África, não encontrámos nenhum: nem na coordenação regional (AfricaCERT), nem no enquadramento continental (Convenção de Malabo), nem nas instituições angolanas (APD, INACOM). É essa distância que a TAC ajuda a preencher no mercado angolano.

Com fonte de dados — filtra a lista ao clicar

Sem fonte de dados identificada — informativo

Notícias selecionadas

Sem itens nesta categoria por agora.