보안 경보
이 목록은 순위가 아니다. 점수를 매기지 않고, 보도가 몇 건이든 상관없이 모은다. 최근 30일치다.
147건 · 최근 10월 6일 08:48
Top 5는 여러 매체가 함께 다룬 것을 고른다. 그런데 치명적 취약점은 기사가 한 줄도 없는 채로 권고문으로만 나오는 일이 흔하다. 그래서 순위 규칙을 건드리지 않고 이 면을 따로 두었다.
실제 악용 확인
12 / 39건CISA가 실제 공격에 쓰이고 있다고 확인한 것. 미국 연방기관에 기한 내 조치 의무가 붙는다.
Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
CVE-2026-88779Citrix · NetScaler10월 4일 09:00Zammad GmbH Zammad Session Fixation Vulnerability
CVE-2026-102489Zammad GmbH · Zammad10월 2일 09:00권한 상승 · Zammad GmbH · Zammad
Zammad GmbH Zammad Improper Privilege Management Vulnerability
CVE-2026-10249010월 2일 09:00경로 조작 · Fortinet · FortiMail
Fortinet FortiMail Path Traversal Vulnerability
CVE-2026-10428610월 1일 09:00Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability
CVE-2026-76504Cisco · Catalyst SD-WAN Manager9월 30일 09:00메모리 범위 초과 · Apple · Multiple Products
Apple Multiple Products Out-of-Bounds Write Vulnerability
CVE-2026-869509월 29일 09:00입력 검증 결함 · Citrix · NetScaler
Citrix NetScaler Improper Input Validation Vulnerability
CVE-2026-887719월 27일 09:00Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
CVE-2026-88772Citrix · NetScaler9월 27일 09:00Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
CVE-2026-67279MikroTik · RouterOS9월 25일 09:00WordPress Core Remote File Inclusion Vulnerability
CVE-2026-87902WordPress · Core9월 25일 09:00코드 주입 · Microsoft · SharePoint
Microsoft SharePoint Code Injection Vulnerability
CVE-2026-656609월 25일 09:00접근 통제 결함 · Adobe · Commerce and Magento
Adobe Commerce and Magento Incorrect Authorization Vulnerability
CVE-2026-713629월 24일 09:00
생태계 치명적 취약점
12 / 104건GitHub 권고 중 critical 등급. npm·pip·go·maven 생태계만 본다.
simple-git: `VISUAL` editor environment variable is omitted from unsafe editor detection
CVE-2026-102829npm · @simple-git/argv-parser10월 6일 08:48simple-git unsafe-operation guard does not block trailer command configuration
CVE-2026-102828npm · simple-git10월 6일 08:48Seroval: `fromJSON()` Promise thenable assimilation invokes plugin-produced callables (bypass of GHSA-mv8w-475r-vwqw)
CVE-2026-104846CVSS 9.8npm · seroval10월 6일 08:40proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet
CVE-2026-90711CVSS 9.1npm · proxy-addr10월 6일 08:30vm2: NodeVM custom resolution bypasses external path boundaries
CVE-2026-100721CVSS 10.0npm · vm210월 6일 08:24Capacitor Android and iOS: remote content can be loaded at the app origin via the internal HTTP proxy path
CVE-2026-103922CVSS 9.3npm · @capacitor/android10월 6일 07:53Tinypool: Prototype Pollution gadget in worker options leads to Remote Code Execution
CVE-2026-104848npm · tinypool10월 6일 07:50Tinypool: Prototype Pollution Gadget to RCE in run() options
CVE-2026-104849npm · tinypool10월 6일 07:49vm2: Sandbox Escape (NodeVM)
CVE-2026-92955CVSS 10.0npm · vm210월 6일 07:47vm2: Host-returned Promise rejection can bypass vm2's unhandled-rejection hardening and terminate the host process
CVE-2026-92954CVSS 8.6npm · vm210월 6일 07:45vm2: Default VM can mutate host TypedArray and ArrayBuffer intrinsics after the host-prototype pollution fix
CVE-2026-92953CVSS 10.0npm · vm210월 6일 07:45vm2 sandbox escape to host RCE via revisited host-wrapped AggregateError bypassing Error sanitization cycle short-circuit
CVE-2026-92934CVSS 9.0npm · vm210월 6일 07:38
벤더 보안 공지
4건우리가 돌리는 소프트웨어의 공식 공지. CVE 번호가 나오기 전에 먼저 올라오는 일이 잦다.