CISA½«Æß¸öÑϳÁ·ì϶ÄÉÈëÒÑÖª¿ÉÀûÓ÷ì϶Ŀ¼
°ä²¼¹¦·ò 2026-05-221. CISA½«Æß¸öÑϳÁ·ì϶ÄÉÈëÒÑÖª¿ÉÀûÓ÷ì϶Ŀ¼
5ÔÂ21ÈÕ£¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©½üÈÕ½«Æß¸öÑϳÁ·ì϶ÕýʽÁÐÈëÆä¡°ÒÑÖª¿ÉÀûÓ÷ì϶¡±£¨KEV£©Ä¿Â¼£¬ÒѺÅÁîÁª¹ú»ú¹¹ÔÚ2026Äê6ÔÂ3ÈÕǰʵÏÖ½¨¸´¹¤×÷¡£¾ßÌå¶øÑÔ£¬CVE-2008-4250ÊÇMicrosoft Windows Server·þÎñÖеÄÒ»¸öÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVSS 9.8£©£¬Ó°ÏìWindows XP¡¢Server 2003µÈ¾É°æÏµÍ³£¬¹¥»÷Õ߿ɷ¢ËÍÌØÔìRPCÒªÇó´¥·¢»º³åÇøÒç³ö£¬ÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÖ´ÐÐËÁÒâ´úÂë¡£CVE-2009-1537£¨CVSS 9.3£©ÎªMicrosoft DirectXÖеĿÕ×Ö½Ú¸²¸Ç·ì϶£¬Óû§´ò¿ª¶ñÒâQuickTimeÎļþ¼´¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£CVE-2009-3459£¨CVSS 9.3£©ÊÇAdobe AcrobatºÍReaderÖеĶѻº³åÇøÒç¶Âí½Å£¬Í¨¹ý¶ñÒâPDFÎļþ´¥·¢´úÂëÖ´ÐС£CVE-2010-0249ÓëCVE-2010-0806£¨¾ùCVSS 9.3£©¾ùΪInternet ExplorerÖеĿªÊͺóʹÓ÷ì϶£¬¹¥»÷ÕßÀûÓöñÒâÍøÒ³ÄÚÈÝ¿ÉÔ¶³ÌÖ´ÐдúÂ룬ÆäÖкóÕßÒѱ»APT×éÖ¯GREFÓÃÓÚÁãÈÕ¹¥»÷¡£CVE-2026-41091£¨CVSS 7.8£©ÎªMicrosoft DefenderȨÏÞÌáÉý·ì϶£¬±¾µØ¹¥»÷Õ߿ɽè´Ë»ñµÃ¸ü¸ßȨÏÞÒÔʵÏÖºáÏòÒÆ¶¯¡£CVE-2026-45498£¨CVSS 6.5£©ÔòÊÇMicrosoft Defender»Ø¾ø·þÎñ·ì϶£¬¿Éµ¼Ö°²È«·þÎñʧЧ¡£
https://securityaffairs.com/192508/security/u-s-cisa-adds-microsoft-and-adobe-flaws-to-its-known-exploited-vulnerabilities-catalog.html
2. Chromium·ì϶й¶£º¹Ø¹Øä¯ÀÀÆ÷ÈÔÔâÔ¶³Ì´úÂëÖ´ÐÐ
5ÔÂ21ÈÕ£¬½üÈÕ£¬¹È¸èʧÉ÷й¶ÁËChromiumÖÐÒ»¸öÉÐ佨¸´µÄÑϳÁ·ì϶µÄ¼¼Êõϸ½Ú¡£¸Ã·ì϶ÔÊÐí¹¥»÷ÕßÔÚÓû§¹Ø¹Øä¯ÀÀÆ÷ºó£¬ÈÔʹ¶ñÒâJavaScript´úÂë³ÖÐøÔÚºó¶ÜÔËÐУ¬½ø¶øÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£ÕâÒ»°²È«Òþ»¼×îÔçÓɰ²È«×êÑÐÔ±Lyra RebaneÓÚ2022Äê12Ô·¢ÏÖ²¢Ìá½»£¬ËæºóÔÚChromiumÎÊÌâ¸ú×ÙÆ÷Éϵõ½È·ÈÏ¡£¸Ã·ì϶ӰÏìËùÓлùÓÚChromiumµÄä¯ÀÀÆ÷£¬º¸ÇGoogle Chrome¡¢Microsoft Edge¡¢Brave¡¢Opera¡¢VivaldiºÍArcµÈÖ÷Á÷²úÆ·¡£Ö»¹Ü¸ÃÎÊÌâÔçÔÚ2022Äêµ×Òѱ»È·ÈÏ£¬µ«½¨¸´½øÕ¹¼«Îª»ºÂý¡£2024Äê10Ô£¬Ò»Î»¹È¸è¿ª·¢ÈËÔ±Ö¸³ö¸Ã·ì϶ÒÀÈ»´æÔÚ£¬²¢½«ÆäÃèÊöΪ¡°ÑϳÁÎÊÌ⡱¡£½ñÄê2Ô£¬¸ÃÎÊÌâÒ»¶È±»ÏóÕ÷ΪÒѽâ¾ö£¬µ«Òò¹ÊºÜ¿ì±»³ÁпªÆô¡£Ëæºó£¬·ì϶״̬¸üÐÂΪͨ¹ýChrome·ì϶¼Î½±´òË㣨VRP£©´¦Ö㬲¢ÓÚ2ÔÂ12ÈÕ±»ÏóÕ÷Ϊ¡°Òѽ¨¸´¡±£¬È»¶øÏÖʵ²¹¶¡²¢Î´°ä²¼¡£RebaneÒò¶ø»ñµÃÁË1000ÃÀÔªµÄÉͽð¡£5ÔÂ20ÈÕ£¬ÓÉÓÚ¸ÃÎÊÌâÔÚϵͳÖÐÒѱ»ÏóÕ÷Ϊ¡°Òѽ¨¸´¡±Çҹعس¬¹ý14ÖÜ£¬ChromiumÎÊÌâ¸ú×ÙÆ÷ÉϵÄËùÓнӼûÏ޶ȱ»½â³ý¡£È»¶øÍ³Ò»Ì죬RebaneÔÚ²âÊÔÖз¢ÏÖ£¬Chrome Dev 150ºÍEdge 148Öи÷ì϶ÒÀÈ»´æÔÚ¡£
https://www.bleepingcomputer.com/news/security/google-accidentally-exposed-details-of-unfixed-chromium-flaw/
3. ¹ú¼Ê·¨ÂÉÐж¯µ·»Ù¡°First VPN¡±·þÎñ
5ÔÂ21ÈÕ£¬Ò»Ïî´úºÅ²»ÏêµÄ³Á´ó¹ú¼Ê·¨ÂÉÐж¯³É¹¦½«¡°First VPN¡±·þÎñÏÂÏß¡£ÕâÏîÒÔ¡°ÒþÖÔÖÁÉÏ¡±ÎªÂôµã¡¢³Ðŵ²»¼Í¼ÈÕÖ¾ÇÒ²»Óë·¨Âɲ¿ÃźÏ×÷µÄVPN·þÎñ£¬½üÄêÀ´ÒѳÉΪÀÕË÷Èí¼þÍŻÊý¾ÝÇÔÔô¼°ÆäËûÍøÂç·¸×ï·Ö×ÓµÄÊ×Ñ¡ÄäÃû¹¤¾ß¡£Å·ÖÞÐ̾¯×éÖ¯ÓÚ5ÔÂ19ÈÕÖÁ20ÈÕе÷¶à¹úÁ¦Á¿·¢Õ¹Ðͬҵ¶¯£¬ÔÚ27¸ö¹ú¶È²é»ñÁËÊýʮ̨·þÎñÆ÷£¬¿ÛÁôÁË·þÎñÖÎÀíÔ±£¬²¢ÔÚÎÚ¿ËÀ¼½øÐÐÁËËѲ飬³¹µ×¶Â½ØÁËÕâÒ»³Ö¾ÃÓÃÓÚÑÚ»¤·¸×ï»î¶¯µÄ»ù´¡ÉèÊ©¡£Õâ´ÎÐж¯µÄÌØÊâ¼ÛÖµÔÚÓÚ£¬µ÷²éÈËÔ±²»½ö¹Ø¹ØÁË·þÎñ£¬»¹ÔÚÆäÒþûǰ³É¹¦ÈëÇÖÁË»ù´¡ÉèÊ©¡£ÕâʹµÃ·¨Âɲ¿ÃŵÃÒÔ»ñÈ¡Óû§¼Í¼¡¢ÏνÓÊý¾ÝµÈ¹Ø¼üÖ¤¾Ý£¬´Ó¶ø½«ÍøÂç·¸×ï»î¶¯×·Òäµ½ÕæÊµµÄÈ˺ÍÉ豸¡£µ±¾Öµ·»ÙÁËÔ̺¬33̨·þÎñÆ÷ÔÚÄÚµÄÍøÂç·¸×ï»ù´¡ÉèÊ©£¬²é·âÁË1vpns.com¡¢1vpns.net¡¢1vpns.org¼°ÓйØÑó´ÐÍøÕ¾ÓòÃû£¬²¢Ö±½Ó֪ͨÁËÓû§¡£Ðж¯³É¾ÍÏÔÖø£ºÅ·ÖÞÐ̾¯×éÖ¯¾Ý´ËÍÆ¶¯ÁË21Ïîµ÷²é£¬·Ö·¢ÁË83·Ýµý±¨°ü£¬²¢Óë¹ú¼ÊºÏ×÷ͬ°é¹²ÏíÁË506λÓû§µÄÐÅÏ¢£¬Ô¤Ê¾ºóÐøµ÷²é½«Ô¶³¬VPN×ÔÉí¡£
https://securityaffairs.com/192491/cyber-crime/global-law-enforcement-operation-takes-first-vpn-offline.html
4. ±±Ô¼Êý¾Ý¿â±»½ÐÂô£º3.5TB¹ú·ÀÈËÔ±ÐÅÏ¢½öÊÛ5000ÃÀÔª
5ÔÂ21ÈÕ£¬Ò»ÃûÍøÂç·¸×ï·Ö×Ó½üÈÕÔÚµØÏÂÍøÂç·¸×ïÂÛ̳Éϰ䲼¸æ°×£¬Ðû³ÆÏúÊÛÈÝÁ¿Ô¼3.5TBµÄ¡°±±Ô¼Êý¾Ý¿â+»úÃÜÎļþ¡±µµ°¸£¬Òý·¢Á˶Զà¸öÃ˹ú»ú¹¹Ãô¸Ð¹ú·ÀÓйØÁªÏµÊý¾Ý¿ÉÄÜÒѾй¶µÄ¿í·ºÓÇÓô¡£Ä¿Ç°ÉÐÎÞ¶ÀÁ¢»ú¹¹ºËʵ¸ÃÊý¾Ý¼¯µÄÕæÊµÐÔ¡¢ÆðÔ´»òÆëÈ«ÁìÓò£¬µ«Ñù±¾Êý¾ÝÒÑÔ̺¬È«Ãû¡¢¹ú¼®¡¢¹¤×÷ÓÊÏä¡¢µç»°ºÅÂë¡¢¹¤×÷µØÖ·¡¢¹ÍÖ÷ÐÅÏ¢¡¢Ö°Î»Ãû³ÆµÈÓ×ÎÒÉí·ÝÐÅÏ¢¡£¾Éó²é£¬ÔÚ¹¥»÷Õß°ä²¼µÄÑù±¾ÖУ¬½ö2±Ê¼Í¼Óë±±Ô¼¹ÙÔ±Ö±½ÓÓйأ¬ÆäÓà¼Í¼¾Ý³ÆÊôÓÚÈðµä»Ê¼ÒÀí¹¤Ñ§Ôº¡¢Å²Íþ¹ú·À×êÑлú¹¹£¨FFI£©¡¢Å²Íþ¶ÀÁ¢×êÑлú¹¹SINTEFÒÔ¼°ÍÁ¶úÆäµ±¾Ö¹ØÁªÊµÌåµÄÈËÔ±¡£×êÑÐÈËÔ±Ö¸³ö£¬Êý¾Ý½á¹¹Åú×¢Êý¾ÝÆðÔ´¿ÉÄܲ¢·Ç±±Ô¼Ö±½ÓÔâÈëÇÖ£¬¶øÊǵÚÈý·½·þÎñ±»¹¥ÆÆËùÖ¡£×êÑÐÈËÔ±ÖÒ¸æ³Æ£¬Ð¹Â¶ÐÅÏ¢½«Ê¹ÓйØÓ×ÎÒ¼°ÆäµØµã»ú¹¹Ãæ¶Ô¼«¸ßµÄÓã²æÊ½ÍøÂç´¹µö¹¥»÷·çÏÕ¡£¹¥»÷Õß½öÒÔÔ¼5000ÃÀÔªÏúÊ۾ݳÆ3.5TBµÄµµ°¸¡£×êÑÐÈËÔ±°µÊ¾£¬Õâ¿ÉÄÜÅú×¢Êý¾Ý²»×ãÕæÊµÐÔ£¬»ò´æÔÚ´óÁ¿³Á¸´Êý¾Ý¡¢Î´¾ºËʵµÄ¼Í¼¡¢µÚÈý·½ÍøÂçµÄÐÅÏ¢ÒÔ¼°ÇÔÈ¡ÕßÈÕÖ¾ÆðÔ´Êý¾Ý£¬Í¬Ê±Ò²·´Ó³³öÂô¼Ò¶Ô¶À¼ÒÏúÊÛȨ²»×ãÐÅÄî¡£
https://cybernews.com/security/nato-defense-data-leak-hacker-forum/
5. CypherLoc¿ÖÏÅÈí¼þ£º¼Ù±¨¾¯ÓÕµ¼Óû§²¦´òڿƵ绰
5ÔÂ20ÈÕ£¬°²È«×êÑÐÈËÔ±·¢ÏÖÁËÒ»ÖÖÃûΪCypherLocµÄÐÂÐÍÉç»á¹¤³ÌڿƼ¿Á©£¬¸Ã¼¿Á©ÀûÓúýŪÐԵĵ¯³ö´°¿ÚºÍÐéαÖҸ棬ÓÕÆÓû§ÏàÐÅ×Ô¼ºµÄÉ豸Òѱ»ÈëÇÖ£¬´Ó¶ø´ÙʹÆäÁªÏµÚ²ÆÐÔµÄIT·þÎñ̨¡£×Ô2026ËêÊ×ÒÔÀ´£¬CypherLocÒѱ»ÓÃÓÚÔ¼280Íò´Î¹¥»÷¡£ÕâÖÖ¹¥»÷ͨ³£Ê¼ÓÚÒ»·â´¹µöÓʼþ£¬Í¨¹ýǶÈëÔÚÓʼþÕýÎÄ»ò¸½¼þÖеÄÁ´½Ó£¬½«Êܺ¦ÕßÊèµ¼ÖÁ¶ñÒâÍøÒ³¡£³õʼ¼ÓÔØµÄÍøÒ³¿´ËÆÎÞº¦£¬Ö»ÓÐÔÚ¼ì²âµ½¶Ìȱ°²È«É¨Ã跨ʽµÈǰÌáÏàÒËʱ£¬²Å»á´¥·¢¿ÖÏÅÈí¼þ¡£¸Ã¿ÖÏÅÈí¼þ»¹Ê¹ÓöàÖÖÉúÀíÕ½Êõ¼ÓǿѹÆÈ¸Ð¡£ËüÀûÓÃÒôƵ²¥·ÅÖÒ¸æÉù£¬Ã¿µ±Óû§ÊÔͼµã»÷»ò½ÚÔìʱ¾Í»á·¢³öÌáÐÑÒô£¬ÕâЩ¶î±íÔëÒô»¹»á½µµÍä¯ÀÀÆ÷ÔËÐÐËÙ¶È£¬Ê¹Æä³öÏÖ¹ÊÕÏÉõÖÁ±ÀÀ££¬´Ó¶øÔö³¤·ÖÎöÄѶȡ£¶ñÒâÈí¼þ»¹»á»ñÈ¡²¢ÏÔʾÓû§µÄIPµØÖ·£¬×÷ΪһÖÖÉúÀíÕ½Êõ£¬Ê¹ÖÒ¸æ¸Ð´¥ÏñÊÇÕë¶ÔÓ×Îҵģ¬ÒÔ¼ÓÇ¿Õ𾪸кͽôÆÈ¸Ð¡£´Ë±í£¬Óû§»¹»á¿´µ½µÇ¼µ¯´°£¬µ±µÇ¼ʧ°Üʱ½øÒ»²½¼Ó¾ç·¢¼±¡£¹¥»÷¹ý³ÌÖУ¬ÆÁÄ»ÉÏ»áÏÔÖøÏÔʾһ¸öÐéαµÄ¿Í·þµç»°ºÅÂ룬²¢Ðû³ÆÕâÊǽâ¾öÎÊÌâµÄΨһõè¾¶¡£Ëæºó£¬¼ÙÒâ΢ÈíÖ§³ÖÈËÔ±µÄÈËΪ²Ù×÷Ô±»áÊÕÊÜ£¬Í¨¹ýʵʱ¶Ô»°³ÖÐø½øÐÐÚ¿Æ¡£
https://cybernews.com/security/millions-hit-scareware-attack-fake-it-helpdesks/
6. ˼¿ÆSecure Workload¸ßΣ·ì϶¿ÉÖÂÖÎÀíԱȨÏÞ±»ÇÔ
5ÔÂ21ÈÕ£¬Ë¼¿Æ½üÈÕ°ä²¼Á˰²È«¸üУ¬ÒÔ½¨¸´ÆäSecure Workload²úÆ·ÖÐÒ»¸öµÚÒ»Á÷´ËÍⰲȫ·ì϶¡£Secure Workload£¨Ç°ÉíΪCisco Tetration£©ÊÇÒ»¿îͨ¹ýÁãÐÅÀµÎ¢¸ôÀë¼¼ÊõÔ®ÊÖÖÎÀíÔ±Ï÷¼õÍøÂç¹¥»÷Ãæ¡¢×èÖ¹ºáÏòÒÆ¶¯£¬´Ó¶ø±£»¤ÒµÎñÀûÓ÷¨Ê½°²È«µÄ²úÆ·¡£¸Ã·ì϶±»×·×ÙΪCVE-2026-20223£¬ÊÇÓÉÓÚ½Ó¼ûREST API¶ËµãʱÑéÖ¤ºÍÉí·ÝÑéÖ¤²»¼°Ôì³ÉµÄ¡£¹¥»÷ÕßÈôÄÜÏòÊÜÓ°ÏìµÄ¶Ëµã·¢Ë;«ÐÄ»ú¹ØµÄAPIÒªÇ󣬱ã¿É³É¹¦ÀûÓô˷ì϶£¬´Ó¶øÒÔÕ¾µãÖÎÀíÔ±Óû§µÄȨÏÞ¿ç×â»§Ììǵ¶ÁÈ¡Ãô¸ÐÐÅÏ¢²¢½øÐÐÅäÖøü¸Ä¡£Ë¼¿Æ°µÊ¾£¬Ä¿Ç°Ã»ÓÐһʱ½â¾ö¹æ»®»ò±äͨ´ëÊ©Äܹ»¶ã±Ü´Ë·ì϶£¬±¾µØ²¿Êð¿Í»§Ðè×°ÖÃÈí¼þ¸üнøÐн¨²¹£¬¶ø»ùÓÚÔÆµÄSecure Workload SaaS²¿ÊðÖиÃÎÊÌâÒѱ»×Ô¶¯½â¾ö¡£¾ßÌ彨¸´°æ±¾Ô̺¬£º3.10°æ±¾ÐèÉý¼¶ÖÁ3.10.8.3£¬4.0°æ±¾ÐèÉý¼¶ÖÁ4.0.3.17£¬¶ø3.9¼°¸üÔç°æ±¾ÔòÐèǨáãµ½Òѽ¨¸´µÄ°æ±¾¡£Ë¼¿Æ²úÆ·°²È«ÊÂÎñÏìÓ¦ÍŶӣ¨PSIRT£©Ç¿µ÷£¬ÔÚ°ä²¼±¾Öܰ²È«²¼¸æÖ®Ç°£¬ÉÐδ·¢Ïָ÷ì϶Òѱ»ÏÖʵÀûÓõÄÖ¤¾Ý¡£
https://www.bleepingcomputer.com/news/security/cisco-max-severity-secure-workload-flaw-gives-hackers-site-admin-privileges/


¾©¹«Íø°²±¸11010802024551ºÅ