News, Alert e Bollettini di sicurezza Microsoft e Linux
Microsoft (MSRC Security Update Guide)
- CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theftby Microsoft Threat Intelligence on 31 Luglio 2026 at 9:01 pm
Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to travelers and steal credentials in an operation we call CaptiveCrunch. The post CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft appeared first on Microsoft Security Blog.
- What’s new in Microsoft Security: July 2026by Alym Rayani on 30 Luglio 2026 at 4:00 pm
This month’s updates help security and IT teams secure their AI environments, use AI to defend, and strengthen the foundations that AI-powered operations depend on. The post What’s new in Microsoft Security: July 2026 appeared first on Microsoft Security Blog.
- CVE-2026-24304 Azure Resource Manager Elevation of Privilege Vulnerabilityon 30 Luglio 2026 at 2:00 pm
Informational Change. CVE ID stays the same.
- CVE-2026-56197 Windows Admin Center (WAC) Remote Code Execution Vulnerabilityon 30 Luglio 2026 at 2:00 pm
Updated an acknowledgement. This is an informational change only.
- CVE-2026-66803 Azure Cosmos DB Remote Code Execution Vulnerabilityon 30 Luglio 2026 at 2:00 pm
Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
- CVE-2026-55129 Microsoft Office Remote Code Execution Vulnerabilityon 30 Luglio 2026 at 2:00 pm
Acknowledgement Updated
- CVE-2026-54128 Windows DHCP Client Remote Code Execution Vulnerabilityon 30 Luglio 2026 at 2:00 pm
Updated an acknowledgement. This is an informational change only.
- Better security starts with better questionsby Aarti Borkar on 29 Luglio 2026 at 4:00 pm
Learn how better questions, trusted AI, and human judgment help security leaders make confident decisions and build resilient systems. The post Better security starts with better questions appeared first on Microsoft Security Blog.
- Chromium: CVE-2026-13037 Use after free in WebViewon 28 Luglio 2026 at 10:03 pm
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
- Chromium: CVE-2026-13032 Use after free in WebGLon 28 Luglio 2026 at 10:03 pm
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
- Chromium: CVE-2026-13030 Uninitialized Use in GPUon 28 Luglio 2026 at 10:03 pm
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
- Chromium: CVE-2026-13028 Use after free in WebGLon 28 Luglio 2026 at 10:03 pm
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
- CVE-2026-50422 Windows NTFS Elevation of Privilege Vulnerabilityon 28 Luglio 2026 at 2:00 pm
Updated an acknowledgement. This is an informational change only.
- CVE-2026-59117 Windows Terminal Remote Code Execution Vulnerabilityon 28 Luglio 2026 at 2:00 pm
Change the name of the affected software from **Microsoft Power Apps** to **Microsoft Power Apps Desktop Client**. This is an informational change only.
- CVE-2026-47301 Configuration Manager Elevation of Privilege Vulnerabilityon 28 Luglio 2026 at 2:00 pm
Corrected Build Number in the Security Updates table. This is an informational change only.
- Rethinking security for the age of AIby Hayete Gallot on 27 Luglio 2026 at 4:40 pm
The physics of cybersecurity are changing. Introducing security's new cyber stack: Project Perception. The post Rethinking security for the age of AI appeared first on Microsoft Security Blog.
- Enhancing AI security through global AI red teamingby Ram Shankar Siva Kumar on 27 Luglio 2026 at 4:25 pm
Microsoft's External Red Team Alliance (EXTRA) is a global AI security initiative designed to advance AI safety research and red teaming. By partnering with universities, researchers, and regional experts, EXTRA helps identify emerging AI risks, improve security testing, and strengthen the resilience of frontier AI systems. The post Enhancing AI security through global AI red teaming appeared first on Microsoft Security Blog.
- CVE-2026-56159 DHCP Server Service Remote Code Execution Vulnerabilityon 27 Luglio 2026 at 2:00 pm
Updated an acknowledgement. This is an informational change only.
- CVE-2026-50697 Windows Common Log File System Driver Elevation of Privilege Vulnerabilityon 27 Luglio 2026 at 2:00 pm
Updated an acknowledgement. This is an informational change only.
- CVE-2026-50343 Microsoft Install Service Elevation of Privilege Vulnerabilityon 27 Luglio 2026 at 2:00 pm
Updated an acknowledgement. This is an informational change only.
- CVE-2026-50333 Windows Spaceport.sys Elevation of Privilege Vulnerabilityon 27 Luglio 2026 at 2:00 pm
Updated an acknowledgement. This is an informational change only.
- CVE-2026-16461 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbdump() short-mode version-list formattingon 27 Luglio 2026 at 8:44 am
Information published.
- CVE-2026-8450 HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file()on 27 Luglio 2026 at 8:44 am
Information published.
- CVE-2026-16277 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbaddrlist()on 27 Luglio 2026 at 8:43 am
Information published.
- CVE-2026-64530 net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handleon 27 Luglio 2026 at 8:04 am
Information published.
- CVE-2024-14040 net: nexthop: Increase weight to u16on 27 Luglio 2026 at 8:04 am
Information published.
- Chromium: CVE-2026-16807 Out of bounds write in Codecson 25 Luglio 2026 at 7:29 am
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
- Chromium: CVE-2026-16806 Use after free in WebMCPon 25 Luglio 2026 at 7:29 am
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
- Chromium: CVE-2026-16805 Use after free in Blinkon 25 Luglio 2026 at 7:29 am
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
- Chromium: CVE-2026-16804 Use after free in Inputon 25 Luglio 2026 at 7:29 am
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Linux (Community’s Center for Security)
- Oracle Linux 10 openssh Important Remote Access Issues ELSA-2026-47757by LinuxSecurity Advisories on 31 Luglio 2026 at 10:44 pm
Oracle Linux has released updated OpenSSH packages for version 10, addressing multiple CVEs related to security vulnerabilities, including remote-to-remote copying issues and memory management flaws.
- Oracle Linux 10 gstreamer1-plugins-bad-free Important Fix CVE-2026-59691by LinuxSecurity Advisories on 31 Luglio 2026 at 10:44 pm
Oracle Linux has released updated RPM packages for version 10 addressing security vulnerabilities CVE-2026-59691 and CVE-2026-59692 in the gstreamer1-plugins-bad-free software.
- Oracle Linux 10 ELSA-2026-47085 Rest Important Weak Random Generationby LinuxSecurity Advisories on 31 Luglio 2026 at 10:44 pm
Oracle released updated RPMs for Oracle Linux 10 addressing CVE-2026-16615, which concerns weak random number generation in PKCE implementation. Available for x86_64 and aarch64 architectures.
- Oracle Linux 10 Pipewire Important Patch CVE-2026-5674 ELSA-2026-47083by LinuxSecurity Advisories on 31 Luglio 2026 at 10:44 pm
Oracle Linux 10 released updated Pipewire RPMs addressing CVE-2026-5674, featuring version 1.4.11 for x86_64 and aarch64 architectures, improving audio functionalities and security.
- Oracle Linux 10 libXfont2 Important CVE Fixes ELSA-2026-47079by LinuxSecurity Advisories on 31 Luglio 2026 at 10:44 pm
Oracle Linux has released security updates for libXfont2, addressing CVEs 2026-56001 and 2026-56002, available for x86_64 and aarch64 architectures on the Unbreakable Linux Network.
- Oracle Linux 9 Node.js Key Security Updates ELSA-2026-47058 CVE-2026-13149by LinuxSecurity Advisories on 31 Luglio 2026 at 10:41 pm
Oracle Linux 9 has received updates for Node.js addressing multiple CVEs, including fixes for vulnerabilities in npm's bundled packages, along with new versions of related nodejs components.
- Oracle Linux 9 Nodejs Important Security Advisory ELSA-2026-47057by LinuxSecurity Advisories on 31 Luglio 2026 at 10:41 pm
Oracle Linux 9 has new RPM packages addressing security vulnerabilities in Node.js, including updates to version 24.18.0 and fixes for CVEs related to npm's bundled packages.
- Oracle Linux 8 Fence Agents Important CVE Fix Advisory ELSA-2026-47736by LinuxSecurity Advisories on 31 Luglio 2026 at 10:40 pm
Oracle Linux released security updates for multiple fence agent packages to address CVE-2026-59939, enhancing system security on Oracle Linux 8 for both x86_64 and aarch64 architectures.
- Oracle Linux 8 ELSA-2026-47731 GStreamer1 Plugins Bad Free Important Fixby LinuxSecurity Advisories on 31 Luglio 2026 at 10:39 pm
Oracle Linux 8 has new RPM updates for gstreamer1-plugins-bad-free addressing CVEs 2026-59691 and 2026-59692, fixing vulnerabilities and improving security.
- Oracle Linux 8 ELSA-2026-47184 libtiff Important Heap Overflowby LinuxSecurity Advisories on 31 Luglio 2026 at 10:39 pm
Oracle Linux has released updates for libtiff addressing CVE-2026-12912, which fixes a heap-buffer-overflow issue in the PixarLog processing. Various RPMs are available for multiple architectures.
- Oracle Linux compat-libtiff3 Important Buffer Overflow Fix ELSA-2026-47183by LinuxSecurity Advisories on 31 Luglio 2026 at 10:39 pm
Oracle Linux has released an update for version 8, addressing CVE-2026-12912, a heap-buffer-overflow issue in PixarLog ABGR decoding, with new RPMs available for multiple architectures.
- Oracle ELSA-2026-47177 yelp Important Fix for CVE-2026-13601by LinuxSecurity Advisories on 31 Luglio 2026 at 10:39 pm
Oracle Linux 8 has received security updates for the Yelp package to address CVE-2026-13601, with new RPMs available for various architectures on the Unbreakable Linux Network.
- Oracle Linux 8 libgcrypt Moderate Denial of Service Fix ELSA-2026-47117by LinuxSecurity Advisories on 31 Luglio 2026 at 10:36 pm
Oracle Linux 8 has released updates for libgcrypt to address CVE-2026-41989, which fixes a denial of service and buffer overflow vulnerability in specific rpms for various architectures.
- Oracle Linux Firefox Important Security Fix ELSA-2026-47105by LinuxSecurity Advisories on 31 Luglio 2026 at 10:36 pm
Oracle Linux has released security updates for Firefox version 140.13.0 to address various CVEs and include fixes and debranding patches for enhanced system security.
- Oracle Linux 8 libXfont2 Major CVE Resolution Notice ELSA-2026-47103by LinuxSecurity Advisories on 31 Luglio 2026 at 10:36 pm
Oracle Linux has released updated RPMs for version 8, fixing vulnerabilities linked to CVE-2026-56001, CVE-2026-56002, and CVE-2026-56003, available through the Unbreakable Linux Network.
- Oracle Linux 8 Vim Important Arbitrary Execution ELSA-2026-48703by LinuxSecurity Advisories on 31 Luglio 2026 at 10:30 pm
Oracle Linux has released security updates for Vim on version 8 with several related CVEs addressed, improving system security and stability for both x86_64 and aarch64 architectures.
- Oracle python-pillow Important Buffer Overflow Fix ELSA-2026-48021by LinuxSecurity Advisories on 31 Luglio 2026 at 10:30 pm
Oracle Linux released security updates for python3-pillow addressing CVE-2026-54058 and CVE-2026-59197. Updated rpms are available for x86_64 and aarch64 architectures.
- Oracle Linux 8 SSSD Important Bug Fix Advisory ELSA-2026-46990by LinuxSecurity Advisories on 31 Luglio 2026 at 10:30 pm
Oracle has released updates for various Oracle Linux 8 packages, addressing security vulnerabilities and improving functionality, specifically related to the System Security Services Daemon (SSSD).
- Oracle 8 dovecot Important IMAP Parser Fix ELSA-2026-46532by LinuxSecurity Advisories on 31 Luglio 2026 at 10:30 pm
Oracle Linux 8 has released updated Dovecot packages to address CVE-2026-42006, which fixes an IMAP parser issue, with RPMs available for x86_64 and aarch64 architectures.
- Oracle Linux 8 Grafana Important Bug Fix CVE-2026-44740 ELSA-2026-46391by LinuxSecurity Advisories on 31 Luglio 2026 at 10:30 pm
Oracle Linux has released security updates for Grafana addressing CVE-2026-44740 and enhancing user email verification in version 9.2.10-32.0.1 across x86_64 and aarch64 architectures.
- Oracle Linux 8 Kernel Significant Security Patch ELSA-2026-45115by LinuxSecurity Advisories on 31 Luglio 2026 at 10:30 pm
Oracle Linux 8 has received an update with several kernel-related RPMs, addressing various security vulnerabilities and enhancing system security through updated certificates and kernel features.
- Oracle glibc Medium Out-of-Bounds Write Vulnerabilities ELSA-2026-42733by LinuxSecurity Advisories on 31 Luglio 2026 at 10:30 pm
Oracle has released a security advisory for updated glibc packages in Oracle Linux 8, addressing multiple CVEs and enhancing stability across x86_64 and aarch64 architectures.
- Oracle Linux 10 Vim Important Command Issues ELSA-2026-48650by LinuxSecurity Advisories on 31 Luglio 2026 at 10:25 pm
Oracle Linux released security updates for Vim in version 10 to address multiple vulnerabilities, including potential command execution and buffer overflow issues, along with related CVEs.
- Oracle Linux 10 Fence Agents Important Fix ELSA-2026-48585 CVE-2026-59939by LinuxSecurity Advisories on 31 Luglio 2026 at 10:25 pm
Oracle Linux 10 has updated RPMs addressing CVE-2026-59939, including a bundled httplib2 upgrade to version 0.32.0, available through the Unbreakable Linux Network.
- Oracle Linux 10 Kernel Important Security Update ELSA-2026-45114by LinuxSecurity Advisories on 31 Luglio 2026 at 10:25 pm
Oracle Linux has released kernel updates for version 10 addressing several CVEs, introducing new certificates, disabling signing for aarch64, and implementing various bug fixes and performance improvements.
- Oracle Linux 10 buildah Important Buffer Overflow Vuln ELSA-2026-36199by LinuxSecurity Advisories on 31 Luglio 2026 at 10:25 pm
Oracle Linux 10 has updated packages for Buildah addressing multiple CVEs, including fixes for vulnerabilities and requirement changes, as documented in the security advisory ELSA-2026-36199.
- Oracle Linux 10 OpenSSL Critical Security Notice ELSA-2026-25237by LinuxSecurity Advisories on 31 Luglio 2026 at 10:25 pm
Oracle Linux 10 has released updated OpenSSL packages to address multiple vulnerabilities, including several CVEs, and includes changes like improved header reading and provider name updates.
- Oracle 10 Kernel Important Security Update ELSA-2026-21557by LinuxSecurity Advisories on 31 Luglio 2026 at 10:25 pm
Oracle Linux updated numerous RPM packages for version 10, addressing various security vulnerabilities detailed in related CVEs and including changes to kernel signing and module management.
- Oracle Linux 7 gimp Important Multiple Security Issues ELSA-2026-26168by LinuxSecurity Advisories on 31 Luglio 2026 at 10:20 pm
Oracle Linux 7 has released GIMP updates to fix multiple CVEs, including vulnerabilities in image parsing, by updating relevant RPM packages on the Unbreakable Linux Network.
- Oracle PackageKit Important CVE-2026-41651 Update ELSA-2026-22146by LinuxSecurity Advisories on 31 Luglio 2026 at 10:20 pm
Oracle Linux 7 has updated PackageKit RPMs to address CVE-2026-41651, with various components available for x86_64 and i686 architectures uploaded to the Unbreakable Linux Network.


