按 Enter 到中央內容區塊
:::

TWCERT/CC台灣電腦網路危機處理暨協調中心|企業資安通報協處|資安情資分享|漏洞通報|資安聯盟|資安電子報

:::

8/17至8/23 Known Exploited Vulnerabilities Catalog(KEV)週報

發布日期:
字型大小:
  • 發布單位:TWCERT/CC
  • 更新日期:2026-09-02
  • 點閱次數:124
  • 內容說明

CISA於8/17至8/23在Known Exploited Vulnerabilities Catalog(KEV)中發布9個已遭駭客利用之漏洞。

  • 影響平台

Apple|macOS

Broadcom|VMware vCenter

Microsoft|IKE Service Extensions

Microsoft|SharePoint

MLflow|MLflow

Ray Project|Ray

Synacor|Zimbra Collaboration Suite

TrueConf|Server

  • 處置建議

修補說明請參考以下官方連結:

Apple|macOS

https://support.apple.com/en-us/148170

https://support.apple.com/en-us/148171

https://support.apple.com/en-us/148172

Broadcom|VMware vCenter

https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017

Microsoft|IKE Service Extensions

https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-33824

Microsoft|SharePoint

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55040

MLflow|MLflow

https://github.com/mlflow/mlflow/pull/24258

https://github.com/mlflow/mlflow/issues/24179

Ray Project|Ray

https://github.com/ray-project/ray/security/advisories/GHSA-q279-jhrf-cc6v

https://github.com/ray-project/ray/commit/70e7c72780bdec075dba6cad1afe0832772bfe09

Synacor|Zimbra Collaboration Suite

https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories

https://blog.zimbra.com/2026/07/patch-release-update-zimbra-10-1-20/

TrueConf|Server

https://trueconf.com/blog/news/security-fixes-updates-and-advisories

https://ics-cert.kaspersky.com/advisories/2026/08/11/trueconf-server-missing-authentication-for-critical-function/

  • CVE編號

CVE-2026-33824

CVE-2026-55040

CVE-2026-59310

CVE-2025-62593

CVE-2026-64849

CVE-2026-65400

CVE-2026-72529

CVE-2026-72530

CVE-2026-73570

回頁首