‧
南臺首頁
‧
English
:::
:::
南臺頭條新聞
南臺影音新聞
所有訊息
重要公告
行政公告
校園活動
專案計劃
研討會資訊
校內徵才
校園職場實習
工作機會
國際證照
南臺新生
招生資訊
南臺RSS新聞
本月公告一覽
停刊公告活動欄
[公告系統登入]
【行政公告】
:::
[ 上一頁 ]
公 告 單位
圖資處數位服務組
訊 息 類 別
行政公告
行政公告
公 告 對 象
全體
公 告 主 題
【資安漏洞預警】CISA新增10個已知遭駭客利用之漏洞至KEV目錄(2026/07/13-2026/07/19)
【Security Vulnerability Alert】CISA added 10 known exploited vulnerabilities to the KEV catalog (2026/07/13-2026/07/19)
公 告 內 容
轉發 台灣電腦網路危機處理暨協調中心 資安訊息警訊 TWCERTCC-200-202607-00000011
[內容說明]
【CVE-2008-4128】Cisco IOS Cross-Site Request Forgery Vulnerability (CVSS v3.1: 4.3)
【是否遭勒索軟體利用:未知】 Cisco 871 Integrated Services Router 所使用的 Cisco IOS 12.4,其 HTTP Administration 元件存在多個跨網站請求偽造漏洞。遠端攻擊者可能誘使使用者發送特製請求,進而在受影響裝置上執行任意指令。
【CVE-2026-56155】Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability (CVSS v3.1: 7.8)
【是否遭勒索軟體利用:未知】 Microsoft Active Directory Federation Services 存在存取控制粒度不足漏洞,允許經授權的攻擊者在本機提升權限。
【CVE-2026-56164】Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability (CVSS v3.1: 5.3)
【是否遭勒索軟體利用:未知】 Microsoft SharePoint Server存在關鍵功能缺乏身分鑑別漏洞,允許未經授權的攻擊者透過網路提升權限。
【CVE-2026-15409】SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability (CVSS v3.1: 10.0)
【是否遭勒索軟體利用:未知】 SonicWall SMA1000 Appliances 存在伺服器端請求偽造漏洞,可能允許未經身分驗證的遠端攻擊者使裝置向非預期位置發送請求。
【CVE-2026-15410】SonicWall SMA1000 Appliances Code Injection Vulnerability (CVSS v3.1: 7.2)
【是否遭勒索軟體利用:未知】 SonicWall SMA1000 Appliances 存在程式碼注入漏洞,在特定條件下,可能允許經身份驗證並具有管理員權限的遠端攻擊者執行任意作業系統指令。
【CVE-2026-46817】Oracle E-Business Suite Improper Privilege Management Vulnerability (CVSS v3.1: 9.8)
【是否遭勒索軟體利用:未知】 Oracle E-Business Suite 存在權限管理不當漏洞,允許可透過 HTTP 存取系統的未經身分驗證攻擊者入侵 Oracle Payments;成功利用此漏洞可能導致 Oracle Payments 遭到接管。
【CVE-2023-4346】KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability (CVSS v3.1: 7.5)
【是否遭勒索軟體利用:未知】 KNX Association KNX Protocol Connection Authorization Option 1 存在帳戶鎖定機制不當漏洞,可能允許攻擊者清除所有未啟用額外安全性選項的裝置,並設定BCU金鑰以鎖定裝置。
【CVE-2026-58644】Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability (CVSS v3.1: 9.8)
【是否遭勒索軟體利用:未知】 Microsoft SharePoint Server 存在不受信任資料反序列化漏洞,可能允許未經授權的攻擊者透過網路執行程式碼。
【CVE-2026-25089】Fortinet FortiSandbox OS Command Injection Vulnerability (CVSS v3.1: 9.8)
【是否遭勒索軟體利用:未知】 Fortinet FortiSandbox、FortiSandbox Cloud 及 FortiSandbox PaaS 的 Web UI 存在作業系統指令注入漏洞,可能允許未經身分驗證的攻擊者透過特製的 HTTP 請求執行未經授權的指令。
【CVE-2026-39808】Fortinet FortiSandbox OS Command Injection Vulnerability (CVSS v3.1: 9.8)
【是否遭勒索軟體利用:未知】 Fortinet FortiSandbox 的 API 端點存在作業系統指令注入漏洞,可能允許未經身分驗證的攻擊者透過特製的 HTTP 請求執行未經授權的程式碼或指令。
[影響平台]
【CVE-2008-4128】Cisco 871 Integrated Services Router 所使用之 Cisco IOS 12.4,涉及 HTTP Administration 元件。
【CVE-2026-56155】請參考官方所列的影響版本 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56155
【CVE-2026-56164】請參考官方所列的影響版本 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56164
【CVE-2026-15409】請參考官方所列的影響版本 https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008
【CVE-2026-15410】請參考官方所列的影響版本 https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008
【CVE-2026-46817】請參考官方所列的影響版本 https://www.oracle.com/security-alerts/cspumay2026.html
【CVE-2023-4346】請參考所列影響版本 https://www.cisa.gov/news-events/ics-advisories/icsa-23-236-01
【CVE-2026-58644】請參考官方所列的影響版本 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644
【CVE-2026-25089】請參考官方所列的影響版本 https://fortiguard.fortinet.com/psirt/FG-IR-26-141
【CVE-2026-39808】請參考官方所列的影響版本 https://fortiguard.fortinet.com/psirt/FG-IR-26-100
[建議措施]
【CVE-2008-4128】 受影響產品可能已達生命週期終止(EoL)和/或服務終止(EoS)階段,建議使用者停止使用該產品。 https://www.cisco.com/c/en/us/obsolete/ios-nx-os-software/cisco-ios-software-releases-12-4-mainline.html
【CVE-2026-56155】 官方已針對漏洞釋出修復更新,請更新至相關版本 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56155
【CVE-2026-56164】 官方已針對漏洞釋出修復更新,請更新至相關版本 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56164
【CVE-2026-15409】 官方已針對漏洞釋出修復更新,請更新至相關版本 https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008
【CVE-2026-15410】 官方已針對漏洞釋出修復更新,請更新至相關版本 https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008
【CVE-2026-46817】 官方已針對漏洞釋出修復更新,請更新至相關版本 https://www.oracle.com/security-alerts/cspumay2026.html
【CVE-2023-4346】 官方已針對漏洞釋出緩解措施 https://www.cisa.gov/news-events/ics-advisories/icsa-23-236-01
【CVE-2026-58644】 官方已針對漏洞釋出修復更新,請更新至相關版本 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644
【CVE-2026-25089】 官方已針對漏洞釋出修復更新,請更新至相關版本 https://fortiguard.fortinet.com/psirt/FG-IR-26-141
【CVE-2026-39808】 官方已針對漏洞釋出修復更新,請更新至相關版本 https://fortiguard.fortinet.com/psirt/FG-IR-26-100
Forwarded Taiwan Computer Network Emergency Response Team / Coordination Center Security Advisory TWCERTCC-200-202607-00000011
[Description]
【CVE-2008-4128】Cisco IOS Cross-Site Request Forgery Vulnerability (CVSS v3.1: 4.3)
【Ransomware exploitation: Unknown】 Cisco IOS 12.4 used by Cisco 871 Integrated Services Router contains multiple cross-site request forgery vulnerabilities in the HTTP Administration component. A remote attacker may trick a user into sending crafted requests, thereby executing arbitrary commands on the affected device.
【CVE-2026-56155】Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability (CVSS v3.1: 7.8)
【Ransomware exploitation: Unknown】 Microsoft Active Directory Federation Services has an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.
【CVE-2026-56164】Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability (CVSS v3.1: 5.3)
【Ransomware exploitation: Unknown】 Microsoft SharePoint Server has a missing authentication for critical function vulnerability, allowing an unauthorized attacker to elevate privileges over the network.
【CVE-2026-15409】SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability (CVSS v3.1: 10.0)
【Ransomware exploitation: Unknown】 SonicWall SMA1000 Appliances has a server-side request forgery vulnerability that may allow an unauthenticated remote attacker to make the device send requests to unintended locations.
【CVE-2026-15410】SonicWall SMA1000 Appliances Code Injection Vulnerability (CVSS v3.1: 7.2)
【Ransomware exploitation: Unknown】 SonicWall SMA1000 Appliances has a code injection vulnerability that, under specific conditions, may allow an authenticated remote attacker with administrator privileges to execute arbitrary operating system commands.
【CVE-2026-46817】Oracle E-Business Suite Improper Privilege Management Vulnerability (CVSS v3.1: 9.8)
【Ransomware exploitation: Unknown】 Oracle E-Business Suite has an improper privilege management vulnerability, allowing an unauthenticated attacker with HTTP access to compromise Oracle Payments; successful exploitation may result in takeover of Oracle Payments.
【CVE-2023-4346】KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability (CVSS v3.1: 7.5)
【Ransomware exploitation: Unknown】 KNX Association KNX Protocol Connection Authorization Option 1 has an improper account lockout mechanism vulnerability that may allow an attacker to clear all devices without additional security options enabled and set a BCU key to lock the devices.
【CVE-2026-58644】Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability (CVSS v3.1: 9.8)
【Ransomware exploitation: Unknown】 Microsoft SharePoint Server has a deserialization of untrusted data vulnerability that may allow an unauthorized attacker to execute code over the network.
【CVE-2026-25089】Fortinet FortiSandbox OS Command Injection Vulnerability (CVSS v3.1: 9.8)
【Ransomware exploitation: Unknown】 The Web UI of Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS has an OS command injection vulnerability that may allow an unauthenticated attacker to execute unauthorized commands via crafted HTTP requests.
【CVE-2026-39808】Fortinet FortiSandbox OS Command Injection Vulnerability (CVSS v3.1: 9.8)
【Ransomware exploitation: Unknown】 The API endpoint of Fortinet FortiSandbox has an OS command injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.
[Impacted Platforms]
【CVE-2008-4128】Cisco IOS 12.4 used by Cisco 871 Integrated Services Router, involving the HTTP Administration component.
【CVE-2026-56155】Please refer to the official listed affected versions https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56155
【CVE-2026-56164】Please refer to the official listed affected versions https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56164
【CVE-2026-15409】Please refer to the official listed affected versions https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008
【CVE-2026-15410】Please refer to the official listed affected versions https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008
【CVE-2026-46817】Please refer to the official listed affected versions https://www.oracle.com/security-alerts/cspumay2026.html
【CVE-2023-4346】Please refer to the listed affected versions https://www.cisa.gov/news-events/ics-advisories/icsa-23-236-01
【CVE-2026-58644】Please refer to the official listed affected versions https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644
【CVE-2026-25089】Please refer to the official listed affected versions https://fortiguard.fortinet.com/psirt/FG-IR-26-141
【CVE-2026-39808】Please refer to the official listed affected versions https://fortiguard.fortinet.com/psirt/FG-IR-26-100
[Recommended Actions]
【CVE-2008-4128】 The affected product may have reached End of Life (EoL) and/or End of Service (EoS); users are advised to discontinue use of the product. https://www.cisco.com/c/en/us/obsolete/ios-nx-os-software/cisco-ios-software-releases-12-4-mainline.html
【CVE-2026-56155】 The vendor has released a patch; please update to the relevant version https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56155
【CVE-2026-56164】 The vendor has released a patch; please update to the relevant version https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56164
【CVE-2026-15409】 The vendor has released a patch; please update to the relevant version https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008
【CVE-2026-15410】 The vendor has released a patch; please update to the relevant version https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008
【CVE-2026-46817】 The vendor has released a patch; please update to the relevant version https://www.oracle.com/security-alerts/cspumay2026.html
【CVE-2023-4346】 The vendor has released mitigation measures https://www.cisa.gov/news-events/ics-advisories/icsa-23-236-01
【CVE-2026-58644】 The vendor has released a patch; please update to the relevant version https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644
【CVE-2026-25089】 The vendor has released a patch; please update to the relevant version https://fortiguard.fortinet.com/psirt/FG-IR-26-141
【CVE-2026-39808】 The vendor has released a patch; please update to the relevant version https://fortiguard.fortinet.com/psirt/FG-IR-26-100
相 關 訊 息
公 告 時 間
2026/7/29
至
2027/1/29
點 閱 次 數
244
:::
公告搜尋(含過期公告):
公告標題
公告內容
時間範圍:
起:
2006
2007
2008
2009
2010
2011
2012
2013
2014
2015
2016
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026
01
02
03
04
05
06
07
08
09
10
11
12
01
02
03
04
05
06
07
08
09
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
止:
2006
2007
2008
2009
2010
2011
2012
2013
2014
2015
2016
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026
01
02
03
04
05
06
07
08
09
10
11
12
01
02
03
04
05
06
07
08
09
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
搜尋類別:
所有類別
行政公告
校園活動
新生專區
招生資訊
單位公告
推廣教育招生
南臺英文網站
工讀機會
學術活動
徵才訊息
創業創新
防疫專區
公告對象:
所有對象
學生
職員
教師
主管
訪客
校友
全體
發佈單位:
所有單位
董事長室
董事會辦公室
工學院
機電所
電子系
機械系
機械系汽車組
機械系精密製造組
機械系自動控制組
電機系
電機系系統組
資工系
化材系
環安室
化材中心
永續學位學程
半導體系
貴儀中心
機電與資工學程
財法所
國企系
財金系
會資系
藝文中心
EMBA
GMBA
工管系
企管系
資管系
行流系
休閒系
餐旅系
人文學院
應英系
應日系
幼保系
幼兒園
人文藝術組
自然科學組
社會科學組
師培中心
教育經營碩士班
教經碩班
教經所碩士班
數位學院
資傳系
視傳系
多樂系
產設系
流音系
商管學院
國際認證辦
經管博士學程
國際商務學程
國際金融學程
智慧健康中心
運動科技中心
智慧綠能科技中心
智慧製造科技中心
智慧電動載具中心
智慧健康學院
食品系
高服學程
高福系
共同教育中心
通識教育中心
雙語教學推動中心
體育與運動中心
董事會
校長室
行政副校長室
學術副校長室
秘書室
秘書室公關組
校友中心
秘書室法務組
秘書室文書議事組
人事室
人事室人資管理組
會計室
會計室預算組
會計室帳務組
教務處
教務處註冊組
課程與教學組
教務處綜合業務組
學務處
學務處生活輔導組
學務處課外活動組
學務處衛保組
學務處諮商輔導組
總務處
總務處出納組
總務處事務組
總務處營繕組
總務處保管組
育成中心
三創教育與業務組
企業招商與培育組
研產處
研產處學研管理組
研產處產推組
研產處職涯發展組
軍訓室
國際處
國際處國際合作組
國際處境外學生組
華語中心
國際處國際專修部
(X)職涯實輔組
稽核室
附設文創園區
創意生活發展中心
創意生活體驗中心
行政中心
圖資處
圖資處讀者服務組
圖資處採編典藏組
圖資處校務資訊組
圖資處網路系統組
校務永續中心
校務發展組
社會責任組
為避免搜尋過久,請縮短時間範圍
地址:71005 台南市永康區南台街一號 (開車訪客請由中正南路→正南一街→進入南臺科技大學)