გადასვლა შიგთავსზე

მიმდინარე ვერსიები

ვერსიები და უსაფრთხოება

ოპერაციული სისტემებისა და სერვერული პროგრამების მიმდინარე ვერსიები მხარდაჭერის სტატუსით, და CISA-ს სიიდან ის სუსტი წერტილები, რომლებსაც რეალურად იყენებენ შეტევებისთვის.

წყარო: endoflife.date · CISA KEV · განახლდა 10 სექტემბერი 2026

ოპერაციული სისტემები

11
  • Apple macOS

    26.6.2

    17 აგვისტო 2026

  • Microsoft Windows

    10.0.28000

    10 თებერვალი 2026

    ვადა 13 მარტი 2029

  • Microsoft Windows Server

    LTS

    10.0.26100

    1 ნოემბერი 2024

    ვადა 14 ნოემბერი 2034

  • Ubuntu

    LTS

    26.04.1

    31 აგვისტო 2026

    ვადა 29 მაისი 2031

  • Debian

    13.6

    11 ივლისი 2026

    ვადა 30 ივნისი 2030

  • RHEL

    10.2

    20 მაისი 2026

    ვადა 31 მაისი 2035

  • AlmaLinux OS

    10.2

    26 მაისი 2026

    ვადა 31 მაისი 2035

  • Rocky Linux

    10.2

    29 მაისი 2026

    ვადა 31 მაისი 2035

  • Fedora Linux

    44

    28 აპრილი 2026

    ვადა 2 ივნისი 2027

  • FreeBSD

    releng/14.5

    8 სექტემბერი 2026

    ვადა 30 ივნისი 2027

  • Linux kernel

    7.2.3

    2 სექტემბერი 2026

ვებსერვერები

5
  • nginx

    1.31.5

    2 სექტემბერი 2026

  • Apache HTTP Server

    2.4.68

    8 ივნისი 2026

  • Traefik

    3.7.13

    4 სექტემბერი 2026

  • HAProxy

    LTS

    3.4.4

    27 აგვისტო 2026

    ვადა 1 აპრილი 2031

  • Caddy

    2.11.4

    2 ივნისი 2026

კონტეინერები

3
  • Docker Engine

    29.8.0

    3 სექტემბერი 2026

  • containerd

    LTS

    2.3.5

    4 სექტემბერი 2026

    ვადა 30 აპრილი 2028

  • Kubernetes

    1.37.0

    26 აგვისტო 2026

    ვადა 28 ოქტომბერი 2027

მონაცემთა ბაზები

7
  • PostgreSQL

    18.6

    11 აგვისტო 2026

    ვადა 14 ნოემბერი 2030

  • MySQL

    LTS

    9.7.2

    28 ივლისი 2026

    ვადა 21 აპრილი 2034

  • MariaDB

    LTS

    12.3.3

    24 აგვისტო 2026

    ვადა 12 ივნისი 2029

  • Redis

    8.10.1

    17 აგვისტო 2026

  • MongoDB Server

    8.3.9

    8 სექტემბერი 2026

    ვადა 31 ოქტომბერი 2029

  • Elasticsearch

    9.5.3

    3 სექტემბერი 2026

  • OpenSearch

    3.8.0

    5 აგვისტო 2026

გარემო

4
  • Node.js

    26.8.2

    9 სექტემბერი 2026

    ვადა 30 აპრილი 2029

  • PHP

    8.5.10

    27 აგვისტო 2026

    ვადა 31 დეკემბერი 2029

  • Python

    3.14.7

    5 აგვისტო 2026

    ვადა 31 ოქტომბერი 2030

  • Go

    1.27.1

    1 სექტემბერი 2026

ვირტუალიზაცია

2
  • Proxmox VE

    9.2

    21 მაისი 2026

  • VMware ESXi

    9.1.1.0

    3 სექტემბერი 2026

    ვადა 12 აგვისტო 2028

აპლიკაციები

6
  • WordPress

    7.1.0

    19 აგვისტო 2026

  • GitLab

    19.3.1

    25 აგვისტო 2026

    მალე იწურება · 19 ნოემბერი 2026

  • Grafana

    13.2.1

    1 სექტემბერი 2026

    ვადა 18 მაისი 2027

  • Prometheus

    3.14.0

    17 აგვისტო 2026

    მალე იწურება · 30 სექტემბერი 2026

  • Zabbix

    7.4.14

    25 აგვისტო 2026

    ვადა 31 დეკემბერი 2026

  • Nextcloud

    34.0.3

    13 აგვისტო 2026

    ვადა 30 ივნისი 2027

ქსელი

4
  • FortiOS

    8.0

    21 აპრილი 2026

    ვადა 21 ოქტომბერი 2030

  • OPNsense

    26.7.3

    27 აგვისტო 2026

  • OpenWrt

    25.12.5

    30 ივნისი 2026

  • OpenSSL

    4.0.2

    25 აგვისტო 2026

    ვადა 14 მაისი 2027

აქტიურად გამოყენებული სუსტი წერტილები

1703 სულ

CISA-ს კატალოგი მხოლოდ იმ სუსტ წერტილებს შეიცავს, რომლებიც დადასტურებულად გამოიყენება შეტევებში. აღწერები ინგლისურად — უსაფრთხოების ტექსტის თარგმნა რისკია.

  • CVE-2026-20079

    Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementCisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability

    Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.

  • CVE-2026-87491

    Google Chromium V8Google Chromium V8 Out of Bounds Write Vulnerability

    Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

  • CVE-2025-25249

    Fortinet Multiple ProductsFortinet Multiple Products Heap-based Buffer Overflow Vulnerability

    Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets.

  • CVE-2026-19490

    Citrix NetScalerCitrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability

    Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass authentication.

  • CVE-2026-85880windows

    Microsoft WindowsMicrosoft Windows Heap-Based Buffer Overflow Vulnerability

    Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally.

  • CVE-2026-86218

    N-able N-centralN-able N-central Static Code Injection Vulnerability

    N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution.

  • CVE-2026-81963windows

    Microsoft WindowsMicrosoft Windows Link Following Vulnerability

    Microsoft Windows Update Stack contains a link following vulnerability that allows a local attacker to escalate privileges locally up to SYSTEM.

  • CVE-2026-75650

    Adobe Commerce and MagentoAdobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability

    Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code.

  • CVE-2026-85046

    Google Chromium V8Google Chromium V8 Type Confusion Vulnerability

    Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

  • CVE-2026-83549

    SonicWall SMA1000 AppliancesSonicWall SMA1000 Appliances OS Command Injection Vulnerability

    SonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.

  • CVE-2026-83548

    SonicWall SMA1000 AppliancesSonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

    SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.

  • CVE-2026-9586

    Sangoma SwitchvoxSangoma Switchvox SQL Injection Vulnerability

    Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.

  • CVE-2026-82329

    JFrog ArtifactoryJFrog Artifactory Improper Authentication Vulnerability

    JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges.

  • CVE-2026-49869

    Kestra Kestra OSSKestra OSS OS Command Injection Vulnerability

    Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.

  • CVE-2026-48710

    Kludex StarletteKludex Starlette HTTP Request/Response Smuggling Vulnerability

    Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the reconstructed URL’s path. This vulnerability could be chaned with CVE-2026-42271.

  • CVE-2026-59822

    BerriAI LiteLLMBerriAI LiteLLM Improper Authentication Vulnerability

    BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.

  • CVE-2026-81578

    PaperCut NG/MFPaperCut NG/MF Missing Authentication for Critical Function Vulnerability

    PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations. This vulnerability can be chained with CVE-2026-82078.

  • CVE-2026-82078

    PaperCut NG/MFPaperCut NG/MF Unsafe Reflection Vulnerability

    PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process. This vulnerability can be chained with CVE-2026-81578.

  • CVE-2026-66384

    JFrog ArtifactoryJFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability

    JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions.

  • CVE-2026-53362Linux kernel

    Linux KernelLinux Kernel Unspecified Vulnerability

    Linux Kernel contains an unspecified vulnerability that can allow for privilege escalation via IPv6 networking subsystem. This vulnerability can impact multiple products, including but not limited to Suse, Red Hat, and other products using Linux.

  • CVE-2023-49105

    ownCloud ownCloudownCloud Improper Authentication Vulnerability

    ownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured.

  • CVE-2019-1068

    Microsoft SQL ServerMicrosoft SQL Server Remote Code Execution Vulnerability

    Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.

  • CVE-2026-8452

    Citrix NetScaler ADC and NetScaler GatewayCitrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

    Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to denial of service.

  • CVE-2022-0995Linux kernel

    Linux KernelLinux Kernel Out-of-Bounds Write Vulnerability

    Linux Kernel contains an out-of-bounds memory write vulnerability which could allow a local user to gain privileged access or cause a denial of service on the system.

  • CVE-2015-5287

    Red Hat Automatic Bug Reporting ToolRed Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability

    Red Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.

  • CVE-2015-3246

    Red Hat LibuserRed Hat Libuser Race Condition Vulnerability

    Red Hat libuser contains a race condition vulnerability that allows authenticated local users to corrupt the /etc/passwd file to cause a denial of service or privilege escalation.

  • CVE-2021-23758

    Ajax.NET Professional Ajax.NET ProfessionalAjax.NET Professional Deserialization of Untrusted Data Vulnerability

    Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.

  • CVE-2026-60004

    Gitea GiteaGitea Code Injection Vulnerability

    Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account.

  • CVE-2026-21962

    Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-inOracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability

    Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in accessible data.

  • CVE-2026-73570

    Synacor Zimbra Collaboration Suite (ZCS)Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability

    Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.