選單換圖效果,請啟用Active Scripting功能
南臺首頁 English
:::
訪客 未來學生 本校學生 教職同仁 畢業校友
:::
  南臺頭條新聞
  南臺影音新聞
  所有訊息
  重要公告
  行政公告
  校園活動
  專案計劃
  研討會資訊
  校內徵才
  校園職場實習
  工作機會
  國際證照
  南臺新生
  招生資訊
  南臺RSS新聞
  本月公告一覽
  停刊公告活動欄
  [公告系統登入]


【行政公告】 ::: [ 上一頁 ]
 
公 告 單位
圖資處網路系統組
訊 息 類 別 行政公告 行政公告 公 告 對 象 全體
公 告 主 題
【資安漏洞預警】VMware多項產品存在3項高風險安全漏洞(CVE-2026-47876、CVE-2026-59309及CVE-2026-59310),請儘速確認並進行修補
【Security Vulnerability Alert】Multiple VMware products contain three high-risk security vulnerabilities (CVE-2026-47876, CVE-2026-59309, and CVE-2026-59310), please promptly verify and perform patching
公 告 內 容
轉發 國家資安資訊分享與分析中心 資安訊息警訊 NISAC-200-202608-00000001

[內容說明]
研究人員發現VMware多項產品存在3項高風險安全漏洞(CVE-2026-47876、CVE-2026-59309及CVE-2026-59310),類型分別為越界寫入(Out-of-Bounds Write)、身分鑑別繞過(Authentication Bypass)及路徑遍歷(Path Traversal),請儘速確認並進行修補。
CVE-2026-47876:已取得虛擬機器VMXNET3介面卡本機管理員權限之攻擊者,可於ESXi主機上執行任意程式碼。 CVE-2026-59309:已取得VMware vCenter網路存取權限之遠端攻擊者,可利用此漏洞於未經授權之情況下繞過身分鑑別並存取系統。
CVE-2026-59310:已取得VMware vCenter網路存取權限之遠端攻擊者,可利用此漏洞執行任意程式碼。

[影響平台]
VMware Cloud Foundation 5.x版本至8.0 U3k(不含)版本
VMware Cloud Foundation與VMware vSphere Foundation 9.0.x.x版本
VMware Cloud Foundation與VMware vSphere Foundation 9.1.x.x版本
VMware vCenter 8.0
VMware Telco Cloud Platform 3.0版本
VMware Telco Cloud Platform 4.x版本
VMware Telco Cloud Platform 5.0.x版本
VMware Telco Cloud Platform 5.1.x版本
VMware Telco Cloud Infrastructure 3.0版本
VMware ESX 8.0版本

[建議措施]
官方已針對漏洞釋出修復更新,請參考官方說明進行更新,網址如下: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017

[參考資料]
1. https://nvd.nist.gov/vuln/detail/CVE-2026-47876
2. https://nvd.nist.gov/vuln/detail/CVE-2026-59309
3. https://nvd.nist.gov/vuln/detail/CVE-2026-59310
4. https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017

Forwarded National Information Sharing and Analysis Center for Cybersecurity Information Security Alert NISAC-200-202608-00000001

[Content Description]
Researchers have discovered that multiple VMware products contain three high-risk security vulnerabilities (CVE-2026-47876, CVE-2026-59309, and CVE-2026-59310), with types being Out-of-Bounds Write, Authentication Bypass, and Path Traversal respectively. Please promptly verify and perform patching.
CVE-2026-47876: An attacker who has obtained local administrator privileges on a virtual machine VMXNET3 network adapter can execute arbitrary code on the ESXi host. CVE-2026-59309: A remote attacker who has obtained network access to VMware vCenter can exploit this vulnerability to bypass authentication and access the system without authorization.
CVE-2026-59310: A remote attacker who has obtained network access to VMware vCenter can exploit this vulnerability to execute arbitrary code.

[Impacted Platforms]
VMware Cloud Foundation versions 5.x to 8.0 U3k (excluding)
VMware Cloud Foundation and VMware vSphere Foundation 9.0.x.x versions
VMware Cloud Foundation and VMware vSphere Foundation 9.1.x.x versions
VMware vCenter 8.0
VMware Telco Cloud Platform version 3.0
VMware Telco Cloud Platform versions 4.x
VMware Telco Cloud Platform versions 5.0.x
VMware Telco Cloud Platform versions 5.1.x
VMware Telco Cloud Infrastructure version 3.0
VMware ESX version 8.0

[Recommended Actions]
The official has released patches for the vulnerabilities. Please refer to the official instructions for updates. The URL is as follows: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017

[Reference]
1. https://nvd.nist.gov/vuln/detail/CVE-2026-47876
2. https://nvd.nist.gov/vuln/detail/CVE-2026-59309
3. https://nvd.nist.gov/vuln/detail/CVE-2026-59310
4. https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017
相 關 訊 息


公 告 時 間
 2026/8/5   至 2027/2/5   
點 閱 次 數
222

:::
 
地址:71005 台南市永康區南台街一號 (開車訪客請由中正南路→正南一街→進入南臺科技大學) HyperLink