CVE-2026-59310 — Broadcom VMware vCenter Path Traversal Vulnerability
Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.
Risk, kontrol, araç, politika, evidence, detection, playbook ve diğer yapılandırılmış içerikleri tek katalogda filtreleyin.
Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.
Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.
Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.
Ray-Project Ray contains a code injection vulnerability that could allow remote code execution. Developers using Ray as a development tool may be exposed to…
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote…
Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give…
Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input…
JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.
N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.
Şüpheli veya doğrulanmış phishing olayında hızlı doğrulama, containment ve kullanıcı koruma akışı.
Şüpheli ransomware olayında izolasyon, kapsam, kimlik, yedek ve recovery kararlarını yöneten akış.
Şüpheli kullanıcı veya ayrıcalıklı hesap ele geçirilmesinde containment ve identity investigation akışı.
Hassas veri sızıntısında kapsam, containment, kanıt ve uyum değerlendirmesi.
Kritik üçüncü tarafta ihlal bildirimi geldiğinde erişim, veri, SLA ve sözleşmesel yükümlülükleri yönetme akışı.
Kurumsal cihaz kaybında hesap, veri ve cihaz yönetimi kontrollerini devreye alma akışı.
Windows 4625 başarısız oturum açma olaylarını password spray/brute force sinyali için bağlamsal değerlendirme.
Sysmon Process Creation telemetrisini parent-child süreç, command line ve signer bağlamıyla detection için kullanma.
Kimlik, cihaz posture, policy decision ve least privilege access katmanlarını ayıran referans yaklaşım.
Log source → collector/forwarder → normalization → SIEM → detection → case management veri akışı.
Admin identity → approval/JIT → vault → session proxy/recording → target system güven zinciri.
Data classification → endpoint/email/web/cloud policy enforcement → incident triage → exception workflow.
User, server, management, backup, security, DMZ ve external zone ayrımıyla trust boundary tasarımı.
Production → backup network → immutable repository → isolated management → recovery verification mimarisi.