‧
南臺首頁
‧
English
:::
:::
南臺頭條新聞
南臺影音新聞
所有訊息
重要公告
行政公告
校園活動
專案計劃
研討會資訊
校內徵才
校園職場實習
工作機會
國際證照
南臺新生
招生資訊
南臺RSS新聞
本月公告一覽
停刊公告活動欄
[公告系統登入]
【行政公告】
:::
[ 上一頁 ]
公 告 單位
圖資處網路系統組
訊 息 類 別
行政公告
行政公告
公 告 對 象
全體
公 告 主 題
【資安漏洞預警】CISA新增6個已知遭駭客利用之漏洞至KEV目錄(2026/08/03-2026/08/09)
【Security Vulnerability Alert】CISA Adds 6 Known Exploited Vulnerabilities to the KEV Catalog (2026/08/03-2026/08/09)
公 告 內 容
轉發 台灣電腦網路危機處理暨協調中心 資安訊息警訊 TWCERTCC-200-202608-00000009
【CVE-2026-18556】N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability (CVSS v4.0: 8.2)
【是否遭勒索軟體利用:未知】 N-able N-central存在身分鑑別繞過漏洞,攻擊者可利用替代路徑或通道來繞過驗證機制。
【CVE-2026-18577】N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability (CVSS v4.0: 8.2)
【是否遭勒索軟體利用:未知】 N-able N-central存在身分鑑別繞過漏洞,攻擊者可透過替代路徑或通道繞過驗證機制,進而接管N-central中的帳戶。此漏洞源自於針對CVE-2026-18556所發布的修補程式不完整。
【CVE-2026-34486】Apache Tomcat Missing Encryption of Sensitive Data Vulnerability (CVSS v3.1: 7.5)
【是否遭勒索軟體利用:未知】 Apache Tomcat存在敏感資料加密缺失漏洞,攻擊者可利用此漏洞繞過EncryptInterceptor。此漏洞可與CVE-2025-24813串聯利用。
【CVE-2026-9198】IBM Langflow Code Injection Vulnerability (CVSS v3.1: 9.8)
【是否遭勒索軟體利用:未知】 Langflow存在程式碼注入漏洞,未經驗證的攻擊者可利用此漏洞,在預設的Langflow部署環境中實現完整的遠端程式碼執行。
【CVE-2026-63077】JetBrains TeamCity Deserialization of Untrusted Data Vulnerability (CVSS v3.1: 9.8)
【是否遭勒索軟體利用:未知】 JetBrains TeamCity存在反序列化不受信任資料漏洞,攻擊者可透過agent polling protocol,在未經驗證的情況下遠端執行程式碼。
【CVE-2026-8037】Progress LoadMaster Command Injection Vulnerability (CVSS v3.1: 9.6)
【是否遭勒索軟體利用:未知】 Progress LoadMaster存在指令注入漏洞,未經驗證的攻擊者可利用多個指令端點中未經清理的輸入,在LoadMaster設備上執行任意指令。
[影響平台]
【CVE-2026-18556】請參考官方所列的影響版本 https://uptime.n-able.com/event/201522/
【CVE-2026-18577】請參考官方所列的影響版本 https://uptime.n-able.com/event/201522/
【CVE-2026-34486】請參考官方所列的影響版本 https://lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly
【CVE-2026-9198】請參考官方所列的影響版本 https://www.ibm.com/support/pages/node/7278927
【CVE-2026-63077】JetBrains TeamCity 2026.1.3, 2025.11.7之前的版本
【CVE-2026-8037】請參考官方所列的影響版本 https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-June-2026-CVE-2026-8037-CVE-2026-33691
[建議措施]
【CVE-2026-18556】官方已針對漏洞釋出修復更新,請更新至相關版本 https://uptime.n-able.com/event/201522/
【CVE-2026-18577】官方已針對漏洞釋出修復更新,請更新至相關版本 https://uptime.n-able.com/event/201522/
【CVE-2026-34486】官方已針對漏洞釋出修復更新,請更新至相關版本 https://lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly
【CVE-2026-9198】官方已針對漏洞釋出修復更新,請更新至相關版本 https://www.ibm.com/support/pages/node/7278927
【CVE-2026-63077】官方已針對漏洞釋出修復更新,請更新至相關版本 https://www.jetbrains.com/privacy-security/issues-fixed/
【CVE-2026-8037】官方已針對漏洞釋出修復更新,請更新至相關版本 https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-June-2026-CVE-2026-8037-CVE-2026-33691
Forwarded Taiwan Computer Emergency Response Team/Coordination Center Security Information Alert TWCERTCC-200-202608-00000009
【CVE-2026-18556】N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability (CVSS v4.0: 8.2)
【Whether Exploited by Ransomware: Unknown】 N-able N-central has an authentication bypass vulnerability, which allows attackers to bypass the verification mechanism by using an alternate path or channel.
【CVE-2026-18577】N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability (CVSS v4.0: 8.2)
【Whether Exploited by Ransomware: Unknown】 N-able N-central has an authentication bypass vulnerability, which allows attackers to bypass the verification mechanism through an alternate path or channel, thereby taking over accounts in N-central. This vulnerability originates from an incomplete patch released for CVE-2026-18556.
【CVE-2026-34486】Apache Tomcat Missing Encryption of Sensitive Data Vulnerability (CVSS v3.1: 7.5)
【Whether Exploited by Ransomware: Unknown】 Apache Tomcat has a missing encryption of sensitive data vulnerability, which allows attackers to bypass EncryptInterceptor. This vulnerability can be chained with CVE-2025-24813.
【CVE-2026-9198】IBM Langflow Code Injection Vulnerability (CVSS v3.1: 9.8)
【Whether Exploited by Ransomware: Unknown】 Langflow has a code injection vulnerability, which allows unauthenticated attackers to achieve full remote code execution in default Langflow deployment environments.
【CVE-2026-63077】JetBrains TeamCity Deserialization of Untrusted Data Vulnerability (CVSS v3.1: 9.8)
【Whether Exploited by Ransomware: Unknown】 JetBrains TeamCity has a deserialization of untrusted data vulnerability, which allows attackers to remotely execute code without authentication through the agent polling protocol.
【CVE-2026-8037】Progress LoadMaster Command Injection Vulnerability (CVSS v3.1: 9.6)
【Whether Exploited by Ransomware: Unknown】 Progress LoadMaster has a command injection vulnerability, which allows unauthenticated attackers to execute arbitrary commands on LoadMaster devices by exploiting unsanitized input in multiple command endpoints.
[Impacted Platforms]
【CVE-2026-18556】Please refer to the versions listed as affected by the official source https://uptime.n-able.com/event/201522/
【CVE-2026-18577】Please refer to the versions listed as affected by the official source https://uptime.n-able.com/event/201522/
【CVE-2026-34486】Please refer to the versions listed as affected by the official source https://lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly
【CVE-2026-9198】Please refer to the versions listed as affected by the official source https://www.ibm.com/support/pages/node/7278927
【CVE-2026-63077】JetBrains TeamCity versions prior to 2026.1.3, 2025.11.7
【CVE-2026-8037】Please refer to the versions listed as affected by the official source https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-June-2026-CVE-2026-8037-CVE-2026-33691
[Recommended Measures]
【CVE-2026-18556】The official source has released a security update for the vulnerability. Please update to the relevant version https://uptime.n-able.com/event/201522/
【CVE-2026-18577】The official source has released a security update for the vulnerability. Please update to the relevant version https://uptime.n-able.com/event/201522/
【CVE-2026-34486】The official source has released a security update for the vulnerability. Please update to the relevant version https://lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly
【CVE-2026-9198】The official source has released a security update for the vulnerability. Please update to the relevant version https://www.ibm.com/support/pages/node/7278927
【CVE-2026-63077】The official source has released a security update for the vulnerability. Please update to the relevant version https://www.jetbrains.com/privacy-security/issues-fixed/
【CVE-2026-8037】The official source has released a security update for the vulnerability. Please update to the relevant version https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-June-2026-CVE-2026-8037-CVE-2026-33691
相 關 訊 息
公 告 時 間
2026/8/17
至
2027/2/17
點 閱 次 數
93
:::
公告搜尋(含過期公告):
公告標題
公告內容
時間範圍:
起:
2006
2007
2008
2009
2010
2011
2012
2013
2014
2015
2016
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026
01
02
03
04
05
06
07
08
09
10
11
12
01
02
03
04
05
06
07
08
09
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
止:
2006
2007
2008
2009
2010
2011
2012
2013
2014
2015
2016
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026
01
02
03
04
05
06
07
08
09
10
11
12
01
02
03
04
05
06
07
08
09
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
搜尋類別:
所有類別
行政公告
校園活動
新生專區
招生資訊
單位公告
推廣教育招生
南臺英文網站
工讀機會
學術活動
徵才訊息
創業創新
防疫專區
公告對象:
所有對象
學生
職員
教師
主管
訪客
校友
全體
發佈單位:
所有單位
董事長室
董事會辦公室
工學院
機電所
電子系
機械系
機械系汽車組
機械系精密製造組
機械系自動控制組
電機系
電機系系統組
資工系
化材系
環安室
化材中心
永續學位學程
半導體系
貴儀中心
機電與資工學程
財法所
國企系
財金系
會資系
藝文中心
EMBA
GMBA
工管系
企管系
資管系
行流系
休閒系
餐旅系
人文學院
應英系
應日系
幼保系
幼兒園
人文藝術組
自然科學組
社會科學組
師培中心
教育經營碩士班
教經碩班
教經所碩士班
數位學院
資傳系
視傳系
多樂系
產設系
流音系
商管學院
國際認證辦
經管博士學程
國際商務學程
國際金融學程
智慧健康中心
運動科技中心
智慧綠能科技中心
智慧製造科技中心
智慧電動載具中心
智慧健康學院
食品系
高服學程
高福系
共同教育中心
通識教育中心
雙語教學推動中心
體育與運動中心
董事會
校長室
行政副校長室
學術副校長室
秘書室
秘書室公關組
校友中心
秘書室法務組
秘書室文書議事組
人事室
人事室人資管理組
會計室
會計室預算組
會計室帳務組
教務處
教務處註冊組
課程與教學組
教務處綜合業務組
學務處
學務處生活輔導組
學務處課外活動組
學務處衛保組
學務處諮商輔導組
總務處
總務處出納組
總務處事務組
總務處營繕組
總務處保管組
育成中心
三創教育與業務組
企業招商與培育組
研產處
研產處學研管理組
研產處產推組
研產處職涯發展組
軍訓室
國際處
國際處國際合作組
國際處境外學生組
華語中心
國際處國際專修部
(X)職涯實輔組
稽核室
附設文創園區
創意生活發展中心
創意生活體驗中心
行政中心
圖資處
圖資處讀者服務組
圖資處採編典藏組
圖資處校務資訊組
圖資處網路系統組
校務永續中心
校務發展組
社會責任組
為避免搜尋過久,請縮短時間範圍
地址:71005 台南市永康區南台街一號 (開車訪客請由中正南路→正南一街→進入南臺科技大學)