Вторник обновлений
январь 2026 г.
Во второй вторник месяца Microsoft, Adobe, SAP, Siemens и Schneider Electric публикуют пакетно; Oracle — в третий вторник января, апреля, июля и октября. Здесь записи того дня из нашей базы, по баллу действия: сначала KEV и зрелые эксплойты.
Как считается: метка CNA + дата публикации (окно два дня, UTC). Полного соответствия бюллетеню производителя не утверждается; внеплановые обновления выходят в другие дни.
записей: 206 · KEV: 3
Затрагивают ваш стек
Записи этого месяца, совпадающие с продуктами и версиями вашего стека.
Войдите, чтобы увидеть совпадения со стеком; записи и уведомления бесплатны. →
Microsoft · 13 января
112 · KEV: 2 · критических: 1| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
78На этой неделе | CVE-2026-20963Готовый эксплойт | Microsoft SharePoint Remote Code Execution Vulnerabilitymicrosoft · sharepoint server · CWE-502 | Критическая9,8 | KEV | 29,2 % | 13 янв. 2026 г. |
54В плане | CVE-2026-20805Готовый эксплойт | Desktop Window Manager Information Disclosure Vulnerabilitymicrosoft · windows 10 1607 · CWE-200 | Средняя5,5 | KEV | 7,5 % | 13 янв. 2026 г. |
41В плане | CVE-2026-20947Эксплойта нет | Microsoft SharePoint Server Remote Code Execution Vulnerabilitymicrosoft · sharepoint server · CWE-89 | Высокая8,8 | — | 18,6 % | 13 янв. 2026 г. |
35Наблюдать | CVE-2026-20868Эксплойта нет | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerabilitymicrosoft · windows 10 1607 · CWE-122 | Высокая8,8 | — | 1,4 % | 13 янв. 2026 г. |
33Наблюдать | CVE-2026-20817Proof of concept | Windows Error Reporting Service Elevation of Privilege Vulnerabilitymicrosoft · windows 10 21h2 · CWE-280 | Высокая7,8 | — | 5,4 % | 13 янв. 2026 г. |
33Наблюдать | CVE-2026-20860Эксплойта нет | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1607 · CWE-843 | Высокая7,8 | — | 8,3 % | 13 янв. 2026 г. |
33Наблюдать | CVE-2026-20944Эксплойта нет | Microsoft Word Remote Code Execution Vulnerabilitymicrosoft · 365 apps · CWE-125 | Высокая8,4 | — | 0,5 % | 13 янв. 2026 г. |
33Наблюдать | CVE-2026-20952Эксплойта нет | Microsoft Office Remote Code Execution Vulnerabilitymicrosoft · 365 apps · CWE-416 | Высокая8,4 | — | 0,5 % | 13 янв. 2026 г. |
33Наблюдать | CVE-2026-20953Эксплойта нет | Microsoft Office Remote Code Execution Vulnerabilitymicrosoft · 365 apps · CWE-416 | Высокая8,4 | — | 0,6 % | 13 янв. 2026 г. |
32Наблюдать | CVE-2026-20820Proof of concept | Windows Common Log File System Driver Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1607 · CWE-122 | Высокая7,8 | — | 2,6 % | 13 янв. 2026 г. |
32Наблюдать | CVE-2026-20840Эксплойта нет | Windows NTFS Remote Code Execution Vulnerabilitymicrosoft · windows 10 1607 · CWE-122 | Высокая7,8 | — | 4,6 % | 13 янв. 2026 г. |
32Наблюдать | CVE-2026-20843Эксплойта нет | Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1607 · CWE-284 | Высокая7,8 | — | 3,4 % | 13 янв. 2026 г. |
- CVE-2026-2096378На этой неделе
Microsoft SharePoint Remote Code Execution Vulnerability
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 29 %microsoft · sharepoint server13 янв. 2026 г.
- CVE-2026-2080554В плане
Desktop Window Manager Information Disclosure Vulnerability
СредняяCVSS 5,5KEVГотовый эксплойтEPSS 7 %microsoft · windows 10 160713 янв. 2026 г.
- CVE-2026-2094741В плане
Microsoft SharePoint Server Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 19 %microsoft · sharepoint server13 янв. 2026 г.
- CVE-2026-2086835Наблюдать
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %microsoft · windows 10 160713 янв. 2026 г.
- CVE-2026-2081733Наблюдать
Windows Error Reporting Service Elevation of Privilege Vulnerability
ВысокаяCVSS 7,8Proof of conceptEPSS 5 %microsoft · windows 10 21h213 янв. 2026 г.
- CVE-2026-2086033Наблюдать
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 8 %microsoft · windows 10 160713 янв. 2026 г.
- CVE-2026-2094433Наблюдать
Microsoft Word Remote Code Execution Vulnerability
ВысокаяCVSS 8,4Эксплойта нетEPSS 1 %microsoft · 365 apps13 янв. 2026 г.
- CVE-2026-2095233Наблюдать
Microsoft Office Remote Code Execution Vulnerability
ВысокаяCVSS 8,4Эксплойта нетEPSS 1 %microsoft · 365 apps13 янв. 2026 г.
- CVE-2026-2095333Наблюдать
Microsoft Office Remote Code Execution Vulnerability
ВысокаяCVSS 8,4Эксплойта нетEPSS 1 %microsoft · 365 apps13 янв. 2026 г.
- CVE-2026-2082032Наблюдать
Windows Common Log File System Driver Elevation of Privilege Vulnerability
ВысокаяCVSS 7,8Proof of conceptEPSS 3 %microsoft · windows 10 160713 янв. 2026 г.
- CVE-2026-2084032Наблюдать
Windows NTFS Remote Code Execution Vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 5 %microsoft · windows 10 160713 янв. 2026 г.
- CVE-2026-2084332Наблюдать
Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 3 %microsoft · windows 10 160713 янв. 2026 г.
+100 ещёВсе записи производителя
Adobe · 13 января
25 · KEV: 0 · критических: 0| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
34Наблюдать | CVE-2026-21267Эксплойта нет | Dreamweaver Desktop | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)adobe · dreamweaver · CWE-78 | Высокая8,6 | — | 0,8 % | 13 янв. 2026 г. |
34Наблюдать | CVE-2026-21268Эксплойта нет | Dreamweaver Desktop | Improper Input Validation (CWE-20)adobe · dreamweaver · CWE-20 | Высокая8,6 | — | 0,3 % | 13 янв. 2026 г. |
34Наблюдать | CVE-2026-21271Эксплойта нет | Dreamweaver Desktop | Improper Input Validation (CWE-20)adobe · dreamweaver · CWE-20 | Высокая8,6 | — | 0,3 % | 13 янв. 2026 г. |
34Наблюдать | CVE-2026-21272Эксплойта нет | Dreamweaver Desktop | Improper Input Validation (CWE-20)adobe · dreamweaver · CWE-20 | Высокая8,6 | — | 0,2 % | 13 янв. 2026 г. |
34Наблюдать | CVE-2026-21280Эксплойта нет | Illustrator | Untrusted Search Path (CWE-426)adobe · illustrator · CWE-426 | Высокая8,6 | — | 0,3 % | 13 янв. 2026 г. |
31Наблюдать | CVE-2026-21274Эксплойта нет | Dreamweaver Desktop | Incorrect Authorization (CWE-863)adobe · dreamweaver · CWE-863 | Высокая7,8 | — | 0,2 % | 13 янв. 2026 г. |
31Наблюдать | CVE-2026-21275Эксплойта нет | InDesign Desktop | Access of Uninitialized Pointer (CWE-824)adobe · indesign · CWE-824 | Высокая7,8 | — | 0,3 % | 13 янв. 2026 г. |
31Наблюдать | CVE-2026-21276Эксплойта нет | InDesign Desktop | Access of Uninitialized Pointer (CWE-824)adobe · indesign · CWE-824 | Высокая7,8 | — | 0,3 % | 13 янв. 2026 г. |
31Наблюдать | CVE-2026-21277Эксплойта нет | InDesign Desktop | Heap-based Buffer Overflow (CWE-122)adobe · indesign · CWE-122 | Высокая7,8 | — | 0,3 % | 13 янв. 2026 г. |
31Наблюдать | CVE-2026-21281Эксплойта нет | InCopy | Heap-based Buffer Overflow (CWE-122)adobe · incopy · CWE-122 | Высокая7,8 | — | 0,2 % | 13 янв. 2026 г. |
31Наблюдать | CVE-2026-21283Эксплойта нет | Bridge | Heap-based Buffer Overflow (CWE-122)adobe · bridge · CWE-122 | Высокая7,8 | — | 0,3 % | 13 янв. 2026 г. |
31Наблюдать | CVE-2026-21287Эксплойта нет | Substance3D - Stager | Use After Free (CWE-416)adobe · substance 3d stager · CWE-416 | Высокая7,8 | — | 0,2 % | 13 янв. 2026 г. |
- CVE-2026-2126734Наблюдать
Dreamweaver Desktop | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %adobe · dreamweaver13 янв. 2026 г.
- CVE-2026-2126834Наблюдать
Dreamweaver Desktop | Improper Input Validation (CWE-20)
ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %adobe · dreamweaver13 янв. 2026 г.
- CVE-2026-2127134Наблюдать
Dreamweaver Desktop | Improper Input Validation (CWE-20)
ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %adobe · dreamweaver13 янв. 2026 г.
- CVE-2026-2127234Наблюдать
Dreamweaver Desktop | Improper Input Validation (CWE-20)
ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %adobe · dreamweaver13 янв. 2026 г.
- CVE-2026-2128034Наблюдать
Illustrator | Untrusted Search Path (CWE-426)
ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %adobe · illustrator13 янв. 2026 г.
- CVE-2026-2127431Наблюдать
Dreamweaver Desktop | Incorrect Authorization (CWE-863)
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %adobe · dreamweaver13 янв. 2026 г.
- CVE-2026-2127531Наблюдать
InDesign Desktop | Access of Uninitialized Pointer (CWE-824)
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %adobe · indesign13 янв. 2026 г.
- CVE-2026-2127631Наблюдать
InDesign Desktop | Access of Uninitialized Pointer (CWE-824)
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %adobe · indesign13 янв. 2026 г.
- CVE-2026-2127731Наблюдать
InDesign Desktop | Heap-based Buffer Overflow (CWE-122)
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %adobe · indesign13 янв. 2026 г.
- CVE-2026-2128131Наблюдать
InCopy | Heap-based Buffer Overflow (CWE-122)
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %adobe · incopy13 янв. 2026 г.
- CVE-2026-2128331Наблюдать
Bridge | Heap-based Buffer Overflow (CWE-122)
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %adobe · bridge13 янв. 2026 г.
- CVE-2026-2128731Наблюдать
Substance3D - Stager | Use After Free (CWE-416)
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %adobe · substance 3d stager13 янв. 2026 г.
+13 ещёВсе записи производителя
SAP · 13 января
0 · KEV: 0 · критических: 0В этом окне записей нет.
Siemens · 13 января
3 · KEV: 0 · критических: 1| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2025-40805Эксплойта нет | Affected devices do not properly enforce user authentication on specific API endpoints.siemens · industrial edge cloud device (iecd) · CWE-639 | Критическая10,0 | — | 0,7 % | 13 янв. 2026 г. |
34Наблюдать | CVE-2025-40944Эксплойта нет | A vulnerability has been identified in SIMATIC ET 200AL IM 157-1 PN (6ES7157-1AB00-0AB0) (All versions), SIMATIC ET 200MP IM 155-5 PN HF (6Esiemens · simatic et 200al im 157-1 pn · CWE-400 | Высокая8,7 | — | 0,4 % | 13 янв. 2026 г. |
29Наблюдать | CVE-2025-40942Эксплойта нет | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.4).siemens · telecontrol server basic · CWE-250 | Высокая7,3 | — | 0,2 % | 13 янв. 2026 г. |
- CVE-2025-4080540В плане
Affected devices do not properly enforce user authentication on specific API endpoints.
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %siemens · industrial edge cloud device (iecd)13 янв. 2026 г.
- CVE-2025-4094434Наблюдать
A vulnerability has been identified in SIMATIC ET 200AL IM 157-1 PN (6ES7157-1AB00-0AB0) (All versions), SIMATIC ET 200MP IM 155-5 PN HF (6E
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %siemens · simatic et 200al im 157-1 pn13 янв. 2026 г.
- CVE-2025-4094229Наблюдать
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.4).
ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %siemens · telecontrol server basic13 янв. 2026 г.
Schneider Electric · 13 января
0 · KEV: 0 · критических: 0В этом окне записей нет.
Oracle (Critical Patch Update) · 20 января
66 · KEV: 1 · критических: 2| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
92Срочно | CVE-2026-21962Готовый эксплойт | Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Serveoracle · http server · CWE-284 | Критическая10,0 | KEV | 73,2 % | 20 янв. 2026 г. |
39Наблюдать | CVE-2026-21969Эксплойта нет | Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Supplier Portal).oracle · agile product lifecycle management for process | Критическая9,8 | — | 0,5 % | 20 янв. 2026 г. |
34Наблюдать | CVE-2026-21967Эксплойта нет | Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Opera Servlet).oracle · hospitality opera 5 | Высокая8,6 | — | 0,3 % | 20 янв. 2026 г. |
32Наблюдать | CVE-2026-21955Proof of concept | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).oracle · vm virtualbox · CWE-400 | Высокая8,2 | — | 0,3 % | 20 янв. 2026 г. |
32Наблюдать | CVE-2026-21956Эксплойта нет | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).oracle · vm virtualbox · CWE-400 | Высокая8,2 | — | 0,3 % | 20 янв. 2026 г. |
32Наблюдать | CVE-2026-21973Эксплойта нет | Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applications (component: Security Management Syoracle · flexcube investor servicing | Высокая8,1 | — | 0,3 % | 20 янв. 2026 г. |
32Наблюдать | CVE-2026-21987Эксплойта нет | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).oracle · vm virtualbox | Высокая8,2 | — | 0,2 % | 20 янв. 2026 г. |
32Наблюдать | CVE-2026-21988Эксплойта нет | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).oracle · vm virtualbox | Высокая8,2 | — | 0,2 % | 20 янв. 2026 г. |
32Наблюдать | CVE-2026-21989Эксплойта нет | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).oracle · vm virtualbox | Высокая8,1 | — | 0,2 % | 20 янв. 2026 г. |
32Наблюдать | CVE-2026-21990Эксплойта нет | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).oracle · vm virtualbox | Высокая8,2 | — | 0,2 % | 20 янв. 2026 г. |
30Наблюдать | CVE-2026-21926Эксплойта нет | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure).oracle · siebel customer relationship management deployment | Высокая7,5 | — | 0,4 % | 20 янв. 2026 г. |
30Наблюдать | CVE-2026-21940Эксплойта нет | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: User and User Group).oracle · supply chain products suite · CWE-200 | Высокая7,5 | — | 0,4 % | 20 янв. 2026 г. |
- CVE-2026-2196292Срочно
Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Serve
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 73 %oracle · http server20 янв. 2026 г.
- CVE-2026-2196939Наблюдать
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Supplier Portal).
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %oracle · agile product lifecycle management for process20 янв. 2026 г.
- CVE-2026-2196734Наблюдать
Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Opera Servlet).
ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %oracle · hospitality opera 520 янв. 2026 г.
- CVE-2026-2195532Наблюдать
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).
ВысокаяCVSS 8,2Proof of conceptEPSS 0 %oracle · vm virtualbox20 янв. 2026 г.
- CVE-2026-2195632Наблюдать
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %oracle · vm virtualbox20 янв. 2026 г.
- CVE-2026-2197332Наблюдать
Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applications (component: Security Management Sy
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %oracle · flexcube investor servicing20 янв. 2026 г.
- CVE-2026-2198732Наблюдать
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %oracle · vm virtualbox20 янв. 2026 г.
- CVE-2026-2198832Наблюдать
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %oracle · vm virtualbox20 янв. 2026 г.
- CVE-2026-2198932Наблюдать
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %oracle · vm virtualbox20 янв. 2026 г.
- CVE-2026-2199032Наблюдать
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %oracle · vm virtualbox20 янв. 2026 г.
- CVE-2026-2192630Наблюдать
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure).
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %oracle · siebel customer relationship management deployment20 янв. 2026 г.
- CVE-2026-2194030Наблюдать
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: User and User Group).
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %oracle · supply chain products suite20 янв. 2026 г.
+54 ещёВсе записи производителя