轉發 國家資安資訊分享與分析中心 資安訊息警訊 NISAC-200-202609-00000001
[內容說明]
研究人員發現綠色運算NUMail存在作業系統指令注入(OS Command Injection)漏洞(CVE-2026-82082),未經身分鑑別之遠端攻擊者可注入任意作業系統指令並於伺服器上執行,請儘速確認並進行修補。
[建議措施]
廠商已完成漏洞修補並派發更新,請確認是否已更新Patch至202602162(含)以後版本
[參考資料]
1. https://nvd.nist.gov/vuln/detail/CVE-2026-82082
2. https://www.twcert.org.tw/tw/cp-132-11144-45c6a-1.html
Forwarded from National Information Sharing and Analysis Center Cybersecurity Information Alert NISAC-200-202609-00000001
[Content Description]
Researchers discovered that Green-Computing NUMail has an OS Command Injection vulnerability(CVE-2026-82082). Unauthenticated remote attackers can inject arbitrary OS commands and execute them on the server. Please confirm and patch as soon as possible.
[Recommended Measures]
The service provider has resolved the vulnerability and deployed the patch. Please confirm whether the patch has been updated to version 202602162 or later.
[References]
1. https://nvd.nist.gov/vuln/detail/CVE-2026-82082
2. https://www.twcert.org.tw/tw/cp-132-11144-45c6a-1.html