<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>CNNVD安全动态</title>
    <link>https://wechat2rss.xlab.app/feed/899e0eaf0e3ea7abac0211b3db9bb39c616e3255.xml</link>
    <description>国家信息安全漏洞库（CNNVD）是中国信息安全测评中心为切实履行漏洞分析和风险评估的职能，负责建设运维的国家信息安全漏洞库，为我国信息安全保障提供基础服务。&#xA;(wechat feed made by @ttttmr https://wechat2rss.xlab.app)</description>
    <managingEditor> (CNNVD安全动态)</managingEditor>
    <image>
      <url>https://wx.qlogo.cn/mmhead/Q3auHgzwzM5Mj4dQX0KRFnoLRKF79Egjv4RWEOFdojEbbdKic76SCMQ/0</url>
      <title>CNNVD安全动态</title>
      <link>https://wechat2rss.xlab.app/feed/899e0eaf0e3ea7abac0211b3db9bb39c616e3255.xml</link>
    </image>
    <item>
      <title>2026年度（第一期）CNNVD漏洞奖励评选结果</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzAxODY1OTM5OQ==&amp;mid=2651464955&amp;idx=1&amp;sn=322a4848f3365d9812f679e144da236b</link>
      <description>近期，国家信息安全漏洞库（CNNVD）开展了2026年度（第一期）漏洞奖励评选工作，其中18个漏洞在我国网络安全漏洞预警及风险消控工作中发挥了积极作用，获奖名单如下。</description>
      <content:encoded><![CDATA[<p>原创 <span>CNNVD</span> <span>2026-05-18 09:18</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=01a87e90&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FuOZw5Efn8etcRry3V9UcbyEeVmCxeGttLVYTonXn52yBTicyrBL82hOh8JZAFggq3Hg0pyX6Opwh0uiaRKIiaBibc98QoKicfFc2iaoXROM1bKgGg%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>近期，国家信息安全漏洞库（CNNVD）开展了2026年度（第一期）漏洞奖励评选工作，其中18个漏洞在我国网络安全漏洞预警及风险消控工作中发挥了积极作用，获奖名单如下。</p>
  <div data-mpa-template="t" mpa-paragraph-type="ignored" data-mp-plugin="96weixin"><div mpa-from-tpl="t"><p data-mpa-powered-by="yiban.io" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: center;visibility: visible;" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img __bg_gif" data-ratio="0.1381345926800472" data-type="gif" data-w="847" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: bottom;font-size: var(--articleFontsize);letter-spacing: 0.034em;height: auto !important;visibility: visible !important;width: 677px !important;" data-imgfileid="503963433" src="https://wechat2rss.xlab.app/img-proxy/?k=22c9ee88&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1JjlMnGl5z2XiaAQGZdFulYs0vsE3icB8RUiawPqDSb5lvm8G0drb7iaw7sQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);letter-spacing: 0.544px;text-align: justify;font-size: 16px;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;text-align: center;justify-content: center;display: flex;flex-flow: row;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;transform: rotateZ(19deg);visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;visibility: visible;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 7px;height: auto;visibility: visible;" mpa-from-tpl="t" nodeleaf=""><img data-aistatus="1" alt="图片" class="__bg_gif" data-ratio="4" data-s="300,640" data-type="gif" data-w="36" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 7px !important;visibility: visible !important;" data-imgfileid="503963431" src="https://wechat2rss.xlab.app/img-proxy/?k=e2d135e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1Js3VkKswpUtkoDWibZ1YQl1lIdcctfqePCcSPEdc38SnhJGdqGJUFx9w%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div><div style="-webkit-tap-highlight-color: transparent;padding-right: 8px;padding-left: 8px;outline: 0px;display: inline-block;vertical-align: middle;width: auto;min-width: 5%;flex: 0 0 auto;height: auto;align-self: center;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: justify;color: rgb(18, 93, 196);" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;text-wrap-style: initial;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;" mpa-from-tpl="t"><span leaf="">点击蓝字 关注我们</span></strong></p></div></div><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;transform: rotateZ(199deg);" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 7px;height: auto;" mpa-from-tpl="t" nodeleaf=""><img data-imgfileid="503963432" alt="图片" class="__bg_gif rich_pages wxw-img" data-ratio="4" data-s="300,640" data-type="gif" data-w="36" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 7px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=e2d135e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1Js3VkKswpUtkoDWibZ1YQl1lIdcctfqePCcSPEdc38SnhJGdqGJUFx9w%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf="">      近期，国家信息安全漏洞库（CNNVD）开展了2026年度（第一期）漏洞奖励评选工作，其中18个漏洞在我国网络安全漏洞预警及风险消控工作中发挥了积极作用，获奖名单如下。</span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.7798466593647316" data-s="300,640" data-type="jpeg" data-w="913" data-imgfileid="503981302" src="https://wechat2rss.xlab.app/img-proxy/?k=fac662a7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FuOZw5Efn8etR3iaHia6ZM2y0XmjLyBVfLhYxPMFMHB060eWTCcpqwPq3CW0vv7np3GIXq1o0a7yialbo4kcuho5ic0etkrRgk5pDWQvgBSvOwt0%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p><p mpa-paragraph-type="body" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;white-space: normal;background-color: rgb(255, 255, 255);text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);outline: 0px;">特此公告</span></p><p mpa-paragraph-type="body" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;white-space: normal;background-color: rgb(255, 255, 255);text-align: right;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);outline: 0px;">国家信息安全漏洞库（CNNVD）</span></p><p mpa-paragraph-type="body" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;white-space: normal;background-color: rgb(255, 255, 255);text-align: right;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);outline: 0px;"> 2026年5月15日</span></p><div mpa-from-tpl="t" data-mp-plugin="96weixin"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;flex: 0 0 auto;height: auto;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: flex;flex-flow: row;text-align: center;justify-content: center;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;width: 45px;vertical-align: top;background-color: rgb(18, 93, 196);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 45px;height: auto;" mpa-from-tpl="t" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img __bg_gif" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 45px !important;visibility: visible !important;" data-imgfileid="503963434" src="https://wechat2rss.xlab.app/img-proxy/?k=68515072&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1JMd8aMOqNkic25xydKvYcCVEsHXvm506icfXiaFep4AfohjraUj3F2jMfg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=6e16cfd2&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzAxODY1OTM5OQ%3D%3D%26mid%3D2651464955%26idx%3D1%26sn%3D322a4848f3365d9812f679e144da236b">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 18 May 2026 09:18:00 +0800</pubDate>
    </item>
    <item>
      <title>2026年国家信息安全漏洞库核心技术支撑单位公告</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzAxODY1OTM5OQ==&amp;mid=2651464955&amp;idx=2&amp;sn=b94c44cb89e1d8e11513d7e89fffb24b</link>
      <description>根据《CNNVD技术支撑单位合作计划指南》，确定华为技术有限公司、奇安信网神信息技术（北京）股份有限公司等11家单位为新一期国家信息安全漏洞库核心技术支撑单位，有效期至2027年5月12日。</description>
      <content:encoded><![CDATA[<p>原创 <span>CNNVD</span> <span>2026-05-18 09:18</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=17c7b97d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FuOZw5Efn8evYJQCfDvBFQTK2hQyon1ibNrZYw1uTFebB7zrzf4qvvCEu45TeicxcbbTtWfWylibXUiaUJC4mDmV9x1HeUQR2yBZ02A4BJmZpFEs%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>根据《CNNVD技术支撑单位合作计划指南》，确定华为技术有限公司、奇安信网神信息技术（北京）股份有限公司等11家单位为新一期国家信息安全漏洞库核心技术支撑单位，有效期至2027年5月12日。</p>
  <div data-mpa-template="t" mpa-paragraph-type="ignored"><div mpa-from-tpl="t"><p data-mpa-powered-by="yiban.io" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: center;visibility: visible;"><img alt="图片" class="rich_pages wxw-img __bg_gif" data-galleryid="" data-imgfileid="503963433" data-ratio="0.1381345926800472" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: bottom;font-size: var(--articleFontsize);letter-spacing: 0.034em;height: auto !important;visibility: visible !important;width: 677px !important;" data-type="gif" data-w="847" src="https://wechat2rss.xlab.app/img-proxy/?k=22c9ee88&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1JjlMnGl5z2XiaAQGZdFulYs0vsE3icB8RUiawPqDSb5lvm8G0drb7iaw7sQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);letter-spacing: 0.544px;text-align: justify;font-size: 16px;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;text-align: center;justify-content: center;display: flex;flex-flow: row;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;transform: rotateZ(19deg);visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;visibility: visible;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 7px;height: auto;visibility: visible;" mpa-from-tpl="t"><img alt="图片" class="__bg_gif rich_pages wxw-img" data-imgfileid="503963431" data-ratio="4" data-s="300,640" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 7px !important;visibility: visible !important;" data-type="gif" data-w="36" src="https://wechat2rss.xlab.app/img-proxy/?k=e2d135e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1Js3VkKswpUtkoDWibZ1YQl1lIdcctfqePCcSPEdc38SnhJGdqGJUFx9w%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div><div style="-webkit-tap-highlight-color: transparent;padding-right: 8px;padding-left: 8px;outline: 0px;display: inline-block;vertical-align: middle;width: auto;min-width: 5%;flex: 0 0 auto;height: auto;align-self: center;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: justify;color: rgb(18, 93, 196);" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;text-wrap-style: initial;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;" mpa-from-tpl="t">点击蓝字 关注我们</strong></p></div></div><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;transform: rotateZ(199deg);" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 7px;height: auto;" mpa-from-tpl="t"><img alt="图片" class="__bg_gif rich_pages wxw-img" data-imgfileid="503963432" data-ratio="4" data-s="300,640" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 7px !important;visibility: visible !important;" data-type="gif" data-w="36" src="https://wechat2rss.xlab.app/img-proxy/?k=e2d135e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1Js3VkKswpUtkoDWibZ1YQl1lIdcctfqePCcSPEdc38SnhJGdqGJUFx9w%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body">      根据《CNNVD技术支撑单位合作计划指南》，确定华为技术有限公司、奇安信网神信息技术（北京）股份有限公司等11家单位为新一期国家信息安全漏洞库核心技术支撑单位，有效期至2027年5月12日。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="503981303" data-ratio="0.724025974025974" data-s="300,640" style="" data-type="jpeg" data-w="616" src="https://wechat2rss.xlab.app/img-proxy/?k=20e96f22&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FuOZw5Efn8es1aiaqMHBWqc63Mb8l0LjKTZZ1wu1pmTl3FmNApuZbybEjFvDuXnAajdy01EtEdpwt1cs9Xs8yfR1u2h6ZTsO1pJgiajVb3C7HE%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p><p mpa-paragraph-type="body" style="margin: 0px;white-space: normal;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);outline: 0px;">特此公告</span></p><p mpa-paragraph-type="body" style="margin: 0px;white-space: normal;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: right;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);outline: 0px;">国家信息安全漏洞库（CNNVD）</span></p><p mpa-paragraph-type="body" style="margin: 0px;white-space: normal;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);outline: 0px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: right;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);outline: 0px;"> 2026年5月15日</span></p><div data-mpa-template="t" mpa-paragraph-type="ignored"><div mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;flex: 0 0 auto;height: auto;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: flex;flex-flow: row;text-align: center;justify-content: center;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;width: 45px;vertical-align: top;background-color: rgb(18, 93, 196);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 45px;height: auto;" mpa-from-tpl="t"><img class="rich_pages wxw-img __bg_gif" data-imgfileid="503963434" data-ratio="0.1503267973856209" data-s="300,640" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 45px !important;visibility: visible !important;" data-type="gif" data-w="306" alt="图片" src="https://wechat2rss.xlab.app/img-proxy/?k=68515072&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1JMd8aMOqNkic25xydKvYcCVEsHXvm506icfXiaFep4AfohjraUj3F2jMfg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=65ad2699&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzAxODY1OTM5OQ%3D%3D%26mid%3D2651464955%26idx%3D2%26sn%3Db94c44cb89e1d8e11513d7e89fffb24b">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 18 May 2026 09:18:00 +0800</pubDate>
    </item>
    <item>
      <title>CNNVD关于微软多个安全漏洞的通报</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzAxODY1OTM5OQ==&amp;mid=2651464941&amp;idx=1&amp;sn=c9c6de536f1f8fd125def1be7458cedd</link>
      <description>近日，微软官方发布了多个安全漏洞的公告，其中微软产品本身漏洞125个，影响到微软产品的其他厂商漏洞17个。</description>
      <content:encoded><![CDATA[<p><span>CNNVD</span> <span>2026-05-14 11:28</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=c93ada58&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FuOZw5Efn8euxPg11GZjPGruWL4avibFE1X9V1jUB6V0uo7JpSPia1q7afssajb3Qknmib4KckjEI55V9zmib0ibxfPAs4KKvkMWyqAFdRErIgBak%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>近日，微软官方发布了多个安全漏洞的公告，其中微软产品本身漏洞125个，影响到微软产品的其他厂商漏洞17个。</p>
  <div data-mpa-template="t" mpa-paragraph-type="ignored"><div mpa-from-tpl="t"><p data-mpa-powered-by="yiban.io" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: center;visibility: visible;" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img __bg_gif" data-ratio="0.1381345926800472" data-type="gif" data-w="847" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: bottom;font-size: var(--articleFontsize);letter-spacing: 0.034em;height: auto !important;visibility: visible !important;width: 677px !important;" data-imgfileid="503963433" src="https://wechat2rss.xlab.app/img-proxy/?k=22c9ee88&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1JjlMnGl5z2XiaAQGZdFulYs0vsE3icB8RUiawPqDSb5lvm8G0drb7iaw7sQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);letter-spacing: 0.544px;text-align: justify;font-size: 16px;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;text-align: center;justify-content: center;display: flex;flex-flow: row;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;transform: rotateZ(19deg);visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;visibility: visible;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 7px;height: auto;visibility: visible;" mpa-from-tpl="t" nodeleaf=""><img data-aistatus="1" alt="图片" class="__bg_gif" data-ratio="4" data-s="300,640" data-type="gif" data-w="36" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 7px !important;visibility: visible !important;" data-imgfileid="503963431" src="https://wechat2rss.xlab.app/img-proxy/?k=e2d135e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1Js3VkKswpUtkoDWibZ1YQl1lIdcctfqePCcSPEdc38SnhJGdqGJUFx9w%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div><div style="-webkit-tap-highlight-color: transparent;padding-right: 8px;padding-left: 8px;outline: 0px;display: inline-block;vertical-align: middle;width: auto;min-width: 5%;flex: 0 0 auto;height: auto;align-self: center;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: justify;color: rgb(18, 93, 196);" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;text-wrap-style: initial;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;" mpa-from-tpl="t"><span leaf="">点击蓝字 关注我们</span></strong></p></div></div><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;transform: rotateZ(199deg);" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 7px;height: auto;" mpa-from-tpl="t" nodeleaf=""><img data-imgfileid="503963432" alt="图片" class="__bg_gif" data-ratio="4" data-s="300,640" data-type="gif" data-w="36" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 7px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=e2d135e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1Js3VkKswpUtkoDWibZ1YQl1lIdcctfqePCcSPEdc38SnhJGdqGJUFx9w%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div><div data-mpa-template="t" mpa-paragraph-type="quote"><div mpa-from-tpl="t" mpa-paragraph-type="quote" data-mp-plugin="96weixin" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;visibility: visible;"><div data-role="outer" mpa-from-tpl="t" data-mp-plugin="96weixin" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;visibility: visible;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 13.5312px;margin-left: 13.5312px;outline: 0px;display: flex;flex-direction: column;border-width: 1px;border-style: solid;border-color: #3f75cf;border-radius: 12px;background-color: #dce8fb;visibility: visible;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;padding: 5px 16px;outline: 0px;align-self: center;background-color: #3f75cf;border-radius: 12px;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;font-size: 15px;letter-spacing: 1.5px;line-height: 15px;color: #ffffff;text-align: center;visibility: visible;"><span style="font-size: 18px;"><strong><span leaf="">漏洞情况</span></strong></span></p></div><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;padding: 10px 20px 15px;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.75em;visibility: visible;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t"><span leaf="">近日，微软官方发布了多个安全漏洞的公告，其中微软产品本身漏洞125个，影响到微软产品的其他厂商漏洞17个。微软Microsoft Windows、Microsoft Windows Ancillary Function Driver for WinSock、Microsoft Azure SDK、Microsoft Azure Monitor Agent等多个产品和系统受漏洞影响。目前，微软官方已经发布了漏洞修复补丁，建议用户及时确认是否受到漏洞影响，尽快采取修补措施。</span></p></div></div></div></div></div></div><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">一</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">漏洞介绍</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf="">2026年5月12日，微软发布了2026年5月份安全更新，共142个漏洞的补丁程序，CNNVD对这些漏洞进行了收录。本次更新主要涵盖了Microsoft Windows、Microsoft Windows Ancillary Function Driver for WinSock、Microsoft Azure SDK、Microsoft Azure Monitor Agent、Microsoft Windows Print Spooler Components、Microsoft Windows SMB Client等。CNNVD对其危害等级进行了评价，其中超危漏洞5个，高危漏洞42个，中危漏洞94个，低危漏洞1个。微软多个产品和系统版本受漏洞影响，具体影响范围可访问微软官方网站查询：</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf=""><a href="https://portal.msrc.microsoft.com/zh-cn/security-guidance" target="_blank">https://portal.msrc.microsoft.com/zh-cn/security-guidance</a></span></p><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">二</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">漏洞详情</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">此次更新共142个漏洞的补丁程序，包括123个新增漏洞的补丁程序、2个更新漏洞的补丁程序和17个影响微软产品的其他厂商漏洞的补丁程序。</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf="">此次更新共包括123个新增漏洞的补丁程序，其中超危漏洞4个，高危漏洞36个，中危漏洞83个。</span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="16.541910331384017" data-s="300,640" data-type="png" data-w="513" data-imgfileid="503981288" src="https://wechat2rss.xlab.app/img-proxy/?k=91fa94a9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuOZw5Efn8eurg9eudfYWoWXTzw5xFmbG1BlN1senTkAaSV9MMCMXJGIkdF7fqowiaqzF1EJR0VBK3tWZ32kpFzeia0Ca1WPAgbp4bxpH7Cjx8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf="">此次更新共包括2个更新漏洞的补丁程序，其中高危漏洞1个，中危漏洞1个。</span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.33723196881091616" data-s="300,640" data-type="png" data-w="513" data-imgfileid="503981289" src="https://wechat2rss.xlab.app/img-proxy/?k=00ab7cb6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuOZw5Efn8etS4jtXwCPV1aNegNOkVhh3lSpyZ2Epx8ia6ZzxQvyxGTNXJXMKlQJHBCugMmQkkFn7OEEDDTkiaHebvqeT9nW44BOAzLC2jLG6Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf="">此次更新共包括17个影响微软产品的其他厂商漏洞的补丁程序，其中超危漏洞1个，高危漏洞5个，中危漏洞10个，低危漏洞1个。</span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.7522935779816513" data-s="300,640" data-type="png" data-w="545" data-imgfileid="503981290" src="https://wechat2rss.xlab.app/img-proxy/?k=0a4d1fbb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuOZw5Efn8etxTOWWBUI2DFVRgdv81pDFTl7HgpxfEhTicpqm6Wu52Ttardic84EibhzqCCzibYTblD1icMr18ectoXDYvzY0rWyJgBZDtOyD5APc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">三</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">修复建议</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf="">目前，微软官方已经发布补丁修复了上述漏洞，建议用户及时确认漏洞影响，尽快采取修补措施。微软官方补丁下载地址：</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf=""><a href="https://msrc.microsoft.com/update-guide/en-us" target="_blank">https://msrc.microsoft.com/update-guide/en-us</a></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">CNNVD将继续跟踪上述漏洞的相关情况，及时发布相关信息。如有需要，可与CNNVD联系。联系方式: cnnvd@itsec.gov.cn</span></p><div data-mpa-template="t" mpa-paragraph-type="ignored"><div mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;flex: 0 0 auto;height: auto;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: flex;flex-flow: row;text-align: center;justify-content: center;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;width: 45px;vertical-align: top;background-color: rgb(18, 93, 196);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 45px;height: auto;" mpa-from-tpl="t" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img __bg_gif" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 45px !important;visibility: visible !important;" data-imgfileid="503963434" src="https://wechat2rss.xlab.app/img-proxy/?k=68515072&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1JMd8aMOqNkic25xydKvYcCVEsHXvm506icfXiaFep4AfohjraUj3F2jMfg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=60295eb6&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzAxODY1OTM5OQ%3D%3D%26mid%3D2651464941%26idx%3D1%26sn%3Dc9c6de536f1f8fd125def1be7458cedd">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 14 May 2026 11:28:00 +0800</pubDate>
    </item>
    <item>
      <title>信息安全漏洞周报（2026年第19期）</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzAxODY1OTM5OQ==&amp;mid=2651464934&amp;idx=1&amp;sn=9a3cd5fb1f1449e4383859d9857ae042</link>
      <description>根据国家信息安全漏洞库（CNNVD）统计，本周（2026年5月4日至2026年5月10日）安全漏洞情况如下</description>
      <content:encoded><![CDATA[<p>原创 <span>CNNVD</span> <span>2026-05-12 18:39</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=400a108c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FuOZw5Efn8etL2GS4H1TlalgIq5qA17wzicJ3yFLMIgtIQRNFPVjicl5nCZMAduLBfaTs7F4kL6Z3GeP8K8UgTUVlSDIqib629D68VNiagKudBJw%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>根据国家信息安全漏洞库（CNNVD）统计，本周（2026年5月4日至2026年5月10日）安全漏洞情况如下</p>
  <div data-mpa-template="t" mpa-paragraph-type="ignored"><div mpa-from-tpl="t"><p data-mpa-powered-by="yiban.io" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: center;visibility: visible;" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img __bg_gif" data-ratio="0.1381345926800472" data-type="gif" data-w="847" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: bottom;font-size: var(--articleFontsize);letter-spacing: 0.034em;height: auto !important;visibility: visible !important;width: 677px !important;" data-imgfileid="503963433" src="https://wechat2rss.xlab.app/img-proxy/?k=22c9ee88&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1JjlMnGl5z2XiaAQGZdFulYs0vsE3icB8RUiawPqDSb5lvm8G0drb7iaw7sQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);letter-spacing: 0.544px;text-align: justify;font-size: 16px;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;text-align: center;justify-content: center;display: flex;flex-flow: row;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;transform: rotateZ(19deg);visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;visibility: visible;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 7px;height: auto;visibility: visible;" mpa-from-tpl="t" nodeleaf=""><img data-aistatus="1" alt="图片" class="__bg_gif" data-ratio="4" data-s="300,640" data-type="gif" data-w="36" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 7px !important;visibility: visible !important;" data-imgfileid="503963431" src="https://wechat2rss.xlab.app/img-proxy/?k=e2d135e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1Js3VkKswpUtkoDWibZ1YQl1lIdcctfqePCcSPEdc38SnhJGdqGJUFx9w%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div><div style="-webkit-tap-highlight-color: transparent;padding-right: 8px;padding-left: 8px;outline: 0px;display: inline-block;vertical-align: middle;width: auto;min-width: 5%;flex: 0 0 auto;height: auto;align-self: center;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: justify;color: rgb(18, 93, 196);" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;text-wrap-style: initial;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;" mpa-from-tpl="t"><span leaf="">点击蓝字 关注我们</span></strong></p></div></div><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;transform: rotateZ(199deg);" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 7px;height: auto;" mpa-from-tpl="t" nodeleaf=""><img data-imgfileid="503963432" alt="图片" class="__bg_gif" data-ratio="4" data-s="300,640" data-type="gif" data-w="36" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 7px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=e2d135e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1Js3VkKswpUtkoDWibZ1YQl1lIdcctfqePCcSPEdc38SnhJGdqGJUFx9w%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div><div data-mpa-template="t" mpa-paragraph-type="quote"><div mpa-from-tpl="t" mpa-paragraph-type="quote" data-mp-plugin="96weixin" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;visibility: visible;"><div data-role="outer" mpa-from-tpl="t" data-mp-plugin="96weixin" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;visibility: visible;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 13.5312px;margin-left: 13.5312px;outline: 0px;display: flex;flex-direction: column;border-width: 1px;border-style: solid;border-color: #3f75cf;border-radius: 12px;background-color: #dce8fb;visibility: visible;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;padding: 5px 16px;outline: 0px;align-self: center;background-color: #3f75cf;border-radius: 12px;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;font-size: 15px;letter-spacing: 1.5px;line-height: 15px;color: #ffffff;text-align: center;visibility: visible;"><strong><span style="font-size: 18px;"><span leaf="">漏洞情况</span></span></strong></p></div><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;padding: 10px 20px 15px;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.75em;visibility: visible;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t"><span leaf="">根据国家信息安全漏洞库（CNNVD）统计，本周（2026年5月4日至2026年5月10日）安全漏洞情况如下：</span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t"><strong><span leaf="">公开漏洞情况</span></strong></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t"><span leaf="">本周CNNVD采集安全漏洞1657个。</span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t"><strong><span leaf="">接报漏洞情况</span></strong></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t"><span leaf="">本周CNNVD接报漏洞4288个，其中信息技术产品漏洞（通用型漏洞）430个，网络信息系统漏洞（事件型漏洞）102个，漏洞平台推送漏洞3756个。</span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t"><strong><span leaf="">重大漏洞通报</span></strong></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t"><span leaf="">Palo Alto Networks PAN-OS安全漏洞（CNNVD-202605-940、CVE-2026-0300）：攻击者可通过向目标防火墙发送特制的数据包，触发缓冲区溢出，从而在目标设备上执行任意代码。PAN-OS多个版本均受此漏洞影响。目前，Palo Alto Networks官方已发布新版本修复了该漏洞，建议用户及时确认产品版本，尽快采取修补措施。</span></p></div></div></div></div></div></div><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">一</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">公开漏洞情况</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf="">根据国家信息安全漏洞库（CNNVD）统计，本周新增安全漏洞1657个，漏洞新增数量有所上升。从厂商分布来看Linux基金会新增漏洞最多，有439个；从漏洞类型来看，跨站脚本类的安全漏洞占比最大，达到7.06%。新增漏洞中，超危漏洞117个，高危漏洞404个，中危漏洞1084个，低危漏洞52个。</span></p><div data-mpa-template="t" mpa-paragraph-type="secondTitle"><div mpa-from-tpl="t" mpa-paragraph-type="secondTitle" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="27325" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div data-align="title" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;padding-right: 10px;padding-left: 10px;outline: 0px;background-color: rgba(0, 72, 191, 0.75);display: inline-block;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;display: flex;justify-content: center;align-items: center;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 10px;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;letter-spacing: 2px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(255, 255, 255);font-size: 16px;" mpa-is-content="t"><span leaf="">（一） 安全漏洞增长数量情况</span></span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">本周CNNVD采集安全漏洞1657个。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="image" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5858585858585859" data-w="495" style="left: 0px;top: 0px;width: 89.3502%;height: 290px;border-width: 1px;border-style: solid;border-color: rgb(229, 228, 228);" src="https://wechat2rss.xlab.app/img-proxy/?k=d1db7e5b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FuOZw5Efn8etyozD5QVZqPXZxKp24wFcBEH7WojmKVPhntumsFoOwukx9FzzRibickZD3WRbIvoH0MsneicAzfJ4ISIiaKpFibT7nebTSbicKsZUtk%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg"/></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">图1 近五周漏洞新增数量统计图</span></span></p><div data-mpa-template="t" mpa-paragraph-type="secondTitle"><div mpa-from-tpl="t" mpa-paragraph-type="secondTitle" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="27325" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div data-align="title" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;padding-right: 10px;padding-left: 10px;outline: 0px;background-color: rgba(0, 72, 191, 0.75);display: inline-block;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;display: flex;justify-content: center;align-items: center;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 10px;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;letter-spacing: 2px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(255, 255, 255);font-size: 16px;" mpa-is-content="t"><span leaf="">（二） 安全漏洞分布情况</span></span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">从厂商分布来看，Linux基金会新增漏洞最多，有439个。各厂商漏洞数量分布如表1所示。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表1 新增安全漏洞排名前五厂商统计表</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6043360433604336" data-s="300,640" data-type="png" data-w="369" data-imgfileid="503981275" src="https://wechat2rss.xlab.app/img-proxy/?k=e8b155cc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuOZw5Efn8euBJ4z0n6q8sVTTichHRLG1wCsvu4SySrBsAxmbJP2pH9qnI0KyL4pT5vibTlFZE0lpPSl0r5yqel30SyU3oyqnnhcqkyxtGgyvk%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">本周国内厂商漏洞81个，友讯公司漏洞数量最多，有11个。国内厂商漏洞整体修复率为53.41%。请受影响用户关注厂商修复情况，及时下载补丁修复漏洞。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">从漏洞类型来看，跨站脚本类的安全漏洞占比最大，达到7.06%。漏洞类型统计如表2所示。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表2 漏洞类型统计表</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="2.81029810298103" data-s="300,640" data-type="png" data-w="369" data-imgfileid="503981276" src="https://wechat2rss.xlab.app/img-proxy/?k=bb6300c2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuOZw5Efn8esJQYayicEqt4c9OEPxqqeKqbs8d8gPkCzwdP1ssktPms4Kbkibah3w2TJjZibTnwkKh7nNsCscG0g1iauWqnspRtUNK1AFOjtJaGo%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-paragraph-type="secondTitle"><div mpa-from-tpl="t" mpa-paragraph-type="secondTitle" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="27325" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div data-align="title" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;padding-right: 10px;padding-left: 10px;outline: 0px;background-color: rgba(0, 72, 191, 0.75);display: inline-block;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;display: flex;justify-content: center;align-items: center;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 10px;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;letter-spacing: 2px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(255, 255, 255);font-size: 16px;" mpa-is-content="t"><span leaf="">（三） 安全漏洞危害等级与修复情况</span></span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">本周共发布超危漏洞117个，高危漏洞404个，中危漏洞1084个，低危漏洞52个。相应修复率分别为75.21%、85.64%、85.98%和67.31%。根据补丁信息统计，合计1401个漏洞已有修复补丁发布，整体修复率为84.55%。详细情况如表3所示。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表3 漏洞危害等级与修复情况</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.56" data-s="300,640" data-type="png" data-w="400" data-imgfileid="503981277" src="https://wechat2rss.xlab.app/img-proxy/?k=ea4fe3a3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuOZw5Efn8et3r8MbEMnib4qbAEiccGzsbj0wmYRSk0cn3Nib197CRgPTFLeOHKjy8YFW9erepOKF5Nm68y2KpIWE8U3H08ic3lrzOcribsVq9dGE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-paragraph-type="secondTitle"><div mpa-from-tpl="t" mpa-paragraph-type="secondTitle" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="27325" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div data-align="title" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;padding-right: 10px;padding-left: 10px;outline: 0px;background-color: rgba(0, 72, 191, 0.75);display: inline-block;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;display: flex;justify-content: center;align-items: center;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 10px;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;letter-spacing: 2px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(255, 255, 255);font-size: 16px;" mpa-is-content="t"><span leaf="">（四） 本周重要漏洞实例</span></span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">本周重要漏洞实例如表4所示。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表4 本期重要漏洞实例</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4869281045751634" data-s="300,640" data-type="png" data-w="306" data-imgfileid="503981278" src="https://wechat2rss.xlab.app/img-proxy/?k=4eed7257&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuOZw5Efn8es8hJ5svu07X99bawDdYcn5VmAU091XW5uKuK1K6BLEpTiaHEzgy7p2dOwRHml3sWYrib8UpXQuP3NPbBmLrNBFfFZ17xnNdKrxw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">1. Apache CloudStack 信息泄露漏洞（CNNVD-202605-1783）</span></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">Apache CloudStack是美国阿帕奇（Apache）基金会的一套基础架构即服务（IaaS）云计算平台，该平台主要用于部署和管理大型虚拟机网络。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">Apache CloudStack 4.21.0.0版本至4.22.0.0版本存在信息泄露漏洞，该漏洞源于没有限制或验证用户身份，攻击者利用该漏洞可以完全控制其他用户的虚拟机，包括启动、停止和销毁虚拟机。</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">目前厂商已发布升级补丁以修复漏洞，参考链接：</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf=""><a href="https://cloudstack.apache.org/downloads/" target="_blank">https://cloudstack.apache.org/downloads/</a></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">2. Google Chrome 资源管理错误漏洞（CNNVD-202605-786）</span></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">Google Chrome是美国谷歌（Google）公司的一款Web浏览器。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">Google Chrome 148.0.7778.96之前版本存在资源管理错误漏洞，该漏洞源于内存释放后重用，攻击者利用该漏洞可以通过特制的HTML页面在沙盒内执行任意代码。</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">目前厂商已发布升级补丁以修复漏洞，参考链接：</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf=""><a href="https://www.google.com/chrome/" target="_blank">https://www.google.com/chrome/</a></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">3. WordPress plugin WP-Optimize 路径遍历漏洞（CNNVD-202605-1406）</span></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">WordPress和WordPress plugin都是WordPress基金会的产品。WordPress是一套使用PHP语言开发的博客平台，该平台具有在基于PHP和MySQL的服务器上架设个人博客网站的功能。WordPress plugin WP-Optimize是一个应用插件。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">WordPress plugin WP-Optimize 4.5.2版本及之前版本存在路径遍历漏洞，该漏洞源于对文件路径验证不足，攻击者利用该漏洞可以删除服务器上的任意文件，进而远程执行代码。</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf="">目前厂商已发布升级补丁以修复漏洞，参考链接：</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf=""><a href="https://wordpress.org/plugins/wp-optimize/" target="_blank">https://wordpress.org/plugins/wp-optimize/</a></span></p><div data-mpa-template="t" mpa-paragraph-type="secondTitle"><div mpa-from-tpl="t" mpa-paragraph-type="secondTitle" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="27325" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div data-align="title" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;padding-right: 10px;padding-left: 10px;outline: 0px;background-color: rgba(0, 72, 191, 0.75);display: inline-block;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;display: flex;justify-content: center;align-items: center;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 10px;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;letter-spacing: 2px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(255, 255, 255);font-size: 16px;" mpa-is-content="t"><span leaf="">（五） 本周重要人工智能漏洞实例</span></span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">本周重要人工智能漏洞实例如表5所示。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表5 本期重要人工智能漏洞实例</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4869281045751634" data-s="300,640" data-type="png" data-w="306" data-imgfileid="503981279" src="https://wechat2rss.xlab.app/img-proxy/?k=23c3c208&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuOZw5Efn8evgbyZtoPq6zBfj1z37jYVQopXdhxC6xJDaM1ykmY1fwGluM7K3YZpTT3HTsGcQh448ibAqBbGf8R0SmNqiaILAODTfdYEekJRM8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">1. OpenClaw 数据伪造问题漏洞（CNNVD-202605-682）</span></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">OpenClaw是一个开源的智能人工助理。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">OpenClaw 2026.4.10之前版本存在数据伪造问题漏洞，该漏洞源于对用户的输入验证不足，攻击者利用该漏洞可以篡改数据。</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">目前厂商已发布升级补丁以修复漏洞，参考链接：</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf=""><a href="https://github.com/openclaw/openclaw/releases" target="_blank">https://github.com/openclaw/openclaw/releases</a></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">2. n8n 安全漏洞（CNNVD-202605-405）</span></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">n8n是一个开源的可扩展的工作流自动化工具。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">n8n存在安全漏洞，该漏洞源于端点允许接受未经身份验证的请求且未对客户端数据进行充分的资源控制，攻击者利用该漏洞可以通过发送大型注册有效载荷耗尽服务器内存资源，导致n8n程序崩溃。1.123.32之前版本、2.17.4之前版本和2.18.1之前版本受漏洞影响。</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">目前厂商已发布升级补丁以修复漏洞，参考链接：</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf=""><a href="https://github.com/n8n-io/n8n/releases" target="_blank">https://github.com/n8n-io/n8n/releases</a></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">3. PraisonAI 输入验证错误漏洞（CNNVD-202605-1688）</span></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">PraisonAI是一个低代码多智能体协作框架。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">PraisonAI 4.6.34之前版本存在输入验证错误漏洞，该漏洞源于MCP服务器中文件处理工具未对路径进行检查，攻击者利用该漏洞可以写入任意文件，并可以执行任意代码。</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf="">目前厂商已发布升级补丁以修复漏洞，参考链接：</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf=""><a href="https://github.com/MervinPraison/PraisonAI/releases" target="_blank">https://github.com/MervinPraison/PraisonAI/releases</a></span></p><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">二</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">漏洞平台推送情况</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">本周CNNVD接收漏洞平台推送漏洞3756个。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表6 本周漏洞平台推送情况</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5683890577507599" data-s="300,640" data-type="png" data-w="329" data-imgfileid="503981280" src="https://wechat2rss.xlab.app/img-proxy/?k=6e739a0f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuOZw5Efn8etFrNK570icgnD3dT2QJtQibx23Hm43PwDBShR4kq8GMkJ2Ny1ic8XVzbnw40w2ON1ZqtmicNx0OASzM4zn7EujF5rZjiamZFZheo38%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">三</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">接报漏洞情况</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">本周CNNVD接报漏洞532个，其中信息技术产品漏洞（通用型漏洞）430个，网络信息系统漏洞（事件型漏洞）102个。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表7 本周漏洞报送情况</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="6.60167714884696" data-s="300,640" data-type="png" data-w="477" data-imgfileid="503981282" src="https://wechat2rss.xlab.app/img-proxy/?k=569e20d5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuOZw5Efn8eu2fS7yn5ItVQtFdoSIhcibc0PKg7pTSkag6sFQCHKgQaFYrGWuBD9Y3XNKnU05t4DoLBKEGNOAoI3M0sk9VhrDaFJeeQYhDJVQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">四</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">收录漏洞通报情况</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">本周CNNVD收录漏洞通报221份。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表8 本周漏洞通报情况</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="4.366876310272537" data-s="300,640" data-type="png" data-w="477" data-imgfileid="503981283" src="https://wechat2rss.xlab.app/img-proxy/?k=589d131c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuOZw5Efn8euC8TawoDR8OaPpoF8Gibf7aF4QEMVkXPlQ0M3tibFVKRq4G6xdWs838nBYVamwXIvWr94jwGIlku4iadpUgOMaGfFj3qNVH4WKK4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">五</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">重大漏洞通报</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px 0px 16px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-size: 17px;"><span leaf="">CNNVD关于Palo Alto Networks PAN-OS安全漏洞的通报</span></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">近日，国家信息安全漏洞库（CNNVD）收到关于Palo Alto Networks PAN-OS安全漏洞（CNNVD-202605-940、CVE-2026-0300）情况的报送。攻击者可通过向目标防火墙发送特制的数据包，触发缓冲区溢出，从而在目标设备上执行任意代码。PAN-OS多个版本均受此漏洞影响。目前，Palo Alto Networks官方已发布新版本修复了该漏洞，建议用户及时确认产品版本，尽快采取修补措施。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">1.漏洞介绍</span></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">Palo Alto Networks PAN-OS是美国Palo Alto Networks公司的一套为其防火墙设备开发的操作系统。该漏洞源于 User-ID Authentication Portal 服务在处理特定数据包时的边界检查不足。未经身份认证的攻击者可通过向目标防火墙的User-ID Authentication Portal服务发送特制的数据包，触发缓冲区溢出，从而在目标设备上以 root 权限执行任意代码。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">2.危害影响</span></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">PAN-OS 12.1 &lt; 12.1.4-h5、PAN-OS 12.1 &lt; 12.1.7、PAN-OS 11.2 &lt; 11.2.4-h17、PAN-OS 11.2 &lt; 11.2.7-h13、PAN-OS 11.2 &lt; 11.2.10-h6、PAN-OS 11.2 &lt; 11.2.12、PAN-OS 11.1 &lt; 11.1.4-h33、PAN-OS 11.1 &lt; 11.1.6-h32、PAN-OS 11.1 &lt; 11.1.7-h6、PAN-OS 11.1 &lt; 11.1.10-h25、PAN-OS 11.1 &lt; 11.1.13-h5、PAN-OS 11.1 &lt; 11.1.15、PAN-OS 10.2 &lt; 10.2.7-h34、PAN-OS 10.2 &lt; 10.2.10-h36、PAN-OS 10.2 &lt; 10.2.13-h21、PAN-OS 10.2 &lt; 10.2.16-h7、PAN-OS 10.2 &lt; 10.2.18-h6等版本均受此漏洞影响。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">3.修复建议</span></span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf="">目前，Palo Alto Networks官方已发布新版本修复了该漏洞，建议用户及时确认产品版本，尽快采取修补措施。官方参考链接：</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf=""><a href="https://security.paloaltonetworks.com/CVE-2026-0300" target="_blank">https://security.paloaltonetworks.com/CVE-2026-0300</a></span></p><div data-mpa-template="t" mpa-paragraph-type="ignored"><div mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;flex: 0 0 auto;height: auto;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: flex;flex-flow: row;text-align: center;justify-content: center;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;width: 45px;vertical-align: top;background-color: rgb(18, 93, 196);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 45px;height: auto;" mpa-from-tpl="t" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img __bg_gif" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 45px !important;visibility: visible !important;" data-imgfileid="503963434" src="https://wechat2rss.xlab.app/img-proxy/?k=68515072&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1JMd8aMOqNkic25xydKvYcCVEsHXvm506icfXiaFep4AfohjraUj3F2jMfg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=7736eb8c&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzAxODY1OTM5OQ%3D%3D%26mid%3D2651464934%26idx%3D1%26sn%3D9a3cd5fb1f1449e4383859d9857ae042">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 12 May 2026 18:39:00 +0800</pubDate>
    </item>
    <item>
      <title>信息安全漏洞月报（2026年04月）</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzAxODY1OTM5OQ==&amp;mid=2651464919&amp;idx=1&amp;sn=76c7885181a55e29770ca9c5988ba129</link>
      <description>根据国家信息安全漏洞库（CNNVD）统计，2026年4月采集漏洞5645个。</description>
      <content:encoded><![CDATA[<p>原创 <span>CNNVD</span> <span>2026-05-08 17:13</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=7b3ac78f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FuOZw5Efn8evrGibuRNiaM8jiaggqxWhe81S5B9oAPJzQI1jvEWgLTVIFic6czudkbkZRYPDHW1YdzyWW4gmdGlhy8CFx3XiaJqwpQksjShyn6fL0%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>根据国家信息安全漏洞库（CNNVD）统计，2026年4月采集漏洞5645个。</p>
  <div data-mpa-template="t" mpa-paragraph-type="ignored" data-mp-plugin="96weixin"><div mpa-from-tpl="t"><p data-mpa-powered-by="yiban.io" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: center;visibility: visible;" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img __bg_gif" data-ratio="0.1381345926800472" data-type="gif" data-w="847" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: bottom;font-size: var(--articleFontsize);letter-spacing: 0.034em;height: auto !important;visibility: visible !important;width: 677px !important;" data-imgfileid="503963433" src="https://wechat2rss.xlab.app/img-proxy/?k=22c9ee88&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1JjlMnGl5z2XiaAQGZdFulYs0vsE3icB8RUiawPqDSb5lvm8G0drb7iaw7sQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);letter-spacing: 0.544px;text-align: justify;font-size: 16px;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;text-align: center;justify-content: center;display: flex;flex-flow: row;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;transform: rotateZ(19deg);visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;visibility: visible;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 7px;height: auto;visibility: visible;" mpa-from-tpl="t" nodeleaf=""><img data-aistatus="1" alt="图片" class="__bg_gif" data-ratio="4" data-s="300,640" data-type="gif" data-w="36" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 7px !important;visibility: visible !important;" data-imgfileid="503963431" src="https://wechat2rss.xlab.app/img-proxy/?k=e2d135e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1Js3VkKswpUtkoDWibZ1YQl1lIdcctfqePCcSPEdc38SnhJGdqGJUFx9w%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div><div style="-webkit-tap-highlight-color: transparent;padding-right: 8px;padding-left: 8px;outline: 0px;display: inline-block;vertical-align: middle;width: auto;min-width: 5%;flex: 0 0 auto;height: auto;align-self: center;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: justify;color: rgb(18, 93, 196);" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;text-wrap-style: initial;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;" mpa-from-tpl="t"><span leaf="">点击蓝字 关注我们</span></strong></p></div></div><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;transform: rotateZ(199deg);" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 7px;height: auto;" mpa-from-tpl="t" nodeleaf=""><img data-imgfileid="503963432" alt="图片" class="__bg_gif" data-ratio="4" data-s="300,640" data-type="gif" data-w="36" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 7px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=e2d135e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1Js3VkKswpUtkoDWibZ1YQl1lIdcctfqePCcSPEdc38SnhJGdqGJUFx9w%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div><div data-mpa-template="t" mpa-paragraph-type="quote" data-mp-plugin="96weixin"><div mpa-from-tpl="t" mpa-paragraph-type="quote" data-mp-plugin="96weixin" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;visibility: visible;"><div data-role="outer" mpa-from-tpl="t" data-mp-plugin="96weixin" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;visibility: visible;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 13.5312px;margin-left: 13.5312px;outline: 0px;display: flex;flex-direction: column;border-width: 1px;border-style: solid;border-color: #3f75cf;border-radius: 12px;background-color: #dce8fb;visibility: visible;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;padding: 5px 16px;outline: 0px;align-self: center;background-color: #3f75cf;border-radius: 12px;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;font-size: 15px;letter-spacing: 1.5px;line-height: 15px;color: #ffffff;text-align: center;visibility: visible;"><strong><span style="font-size: 18px;"><span leaf="">漏洞情况</span></span></strong></p></div><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;padding: 10px 20px 15px;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.75em;visibility: visible;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t"><span leaf="">根据国家信息安全漏洞库（CNNVD）统计，2026年4月采集漏洞5645个。</span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t"><span leaf="">本月接报漏洞2974个，其中信息技术产品漏洞（通用型漏洞）2870个，网络信息系统漏洞（事件型漏洞）104个。漏洞平台推送漏洞17974个。</span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t"><strong><span leaf="">重大漏洞通报</span></strong></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t"><span leaf="">Apache ActiveMQ 安全漏洞（CNNVD-202604-1392/CVE-2026-34197）：Apache ActiveMQ 5.19.4之前版本和6.0.0至6.2.3之前版本存在安全漏洞，该漏洞源于Jolokia JMX-HTTP桥的输入验证不当，可能导致远程代码执行。目前厂商已发布升级补丁以修复漏洞，补丁获取链接：<a href="https://activemq.apache.org/" target="_blank">https://activemq.apache.org/</a></span></p></div></div></div></div></div></div><div data-mpa-template="t" mpa-paragraph-type="title" data-mp-plugin="96weixin"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">一</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">公开漏洞情况</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf="">根据国家信息安全漏洞库（CNNVD）统计，2026年4月新增漏洞5645个，受影响厂商方面，WordPress漏洞数量最多，533个；漏洞类型方面，跨站脚本漏洞占比最大，高达6.31%；危害等级方面，超危漏洞401个、高危漏洞1757个、中危漏洞3225个、低危漏洞262个，相应修复率分别为66.09%、71.09%、72.10%以及61.07%。已发布补丁漏洞3999个，本月整体修复率70.85%。</span></p><div data-mpa-template="t" mpa-paragraph-type="secondTitle" data-mp-plugin="96weixin"><div mpa-from-tpl="t" mpa-paragraph-type="secondTitle" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="27325" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div data-align="title" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;padding-right: 10px;padding-left: 10px;outline: 0px;background-color: rgba(0, 72, 191, 0.75);display: inline-block;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;display: flex;justify-content: center;align-items: center;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 10px;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;letter-spacing: 2px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(255, 255, 255);font-size: 16px;" mpa-is-content="t"><span leaf="">1.1 漏洞增长概况</span></span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" data-mp-plugin="96weixin"><span leaf="">2026年4月新增漏洞5645个，环比减少 -9.5%。近6个月新增漏洞数量统计如图1，平均每月漏洞数量4883个。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="image" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4651600753295669" data-w="531" src="https://wechat2rss.xlab.app/img-proxy/?k=2c4d6165&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuOZw5Efn8evYAf8u2O1JCiaMGIianw9NfvYj1yR5pFPpibmDb9upvG45YUlTicZCETTDL3tJ6ibnqvgghiaHy4acmia2JqmO4vdiaArugooHPolV7yY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">图1  2025年11月至2026年4月新增漏洞数量统计图</span></span></p><div data-mpa-template="t" mpa-paragraph-type="secondTitle" data-mp-plugin="96weixin"><div mpa-from-tpl="t" mpa-paragraph-type="secondTitle" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="27325" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div data-align="title" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;padding-right: 10px;padding-left: 10px;outline: 0px;background-color: rgba(0, 72, 191, 0.75);display: inline-block;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;display: flex;justify-content: center;align-items: center;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 10px;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;letter-spacing: 2px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(255, 255, 255);font-size: 16px;" mpa-is-content="t"><span leaf="">1.2 漏洞分布情况</span></span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" data-mp-plugin="96weixin"><span style="color: rgb(18, 93, 196);"><strong><span leaf="">1.2.1 受影响厂商分布</span></strong></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" data-mp-plugin="96weixin"><span leaf="">2026年4月受影响厂商漏洞数量分布情况如表1，WordPress漏洞533个，占本月漏洞总量9.44%。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表1  2026年4月新增漏洞排名前十受影响厂商统计列表</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.2553846153846153" data-s="300,640" data-type="png" data-w="325" data-imgfileid="503981247" src="https://wechat2rss.xlab.app/img-proxy/?k=c78b5e31&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuOZw5Efn8evnH2oZSeYS42Vc88zgwOZ4zo3uHUzscHpsMBXKNe7kP7mY2dVtavqRichCjwHAIZ0ChCGaJVWZ1dlK5re9pjBd4ks9Z7fcpLfA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="color: rgb(18, 93, 196);"><strong><span leaf="">1.2.2 漏洞类型分布</span></strong></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" data-mp-plugin="96weixin"><span leaf="">2026年4月漏洞类型分布情况如表2，其中跨站脚本类漏洞占比最大，为6.31%。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表2  2026年4月漏洞类型统计列表</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="2.5860349127182043" data-s="300,640" data-type="png" data-w="401" data-imgfileid="503981248" src="https://wechat2rss.xlab.app/img-proxy/?k=d1c1b452&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuOZw5Efn8euia4672BAXjMfRMyp2hGozXqsgTpic8icOwqOnjG5YjWytvKtbyI3r8oFhIUZocCB9qaG5NsYiaZdYecibjJDNiajmWVA6XbsaYT8k0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="color: rgb(18, 93, 196);"><strong><span leaf="">1.2.3 漏洞危害等级分布</span></strong></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" data-mp-plugin="96weixin"><span leaf="">根据漏洞影响范围、利用方式、攻击效果等情况，从高到低分为四个等级：超危、高危、中危和低危。2026年4月漏洞危害等级分布情况如图2，其中超危漏洞401个，占本月漏洞总量7.10%。</span></p><p style="text-align: center;margin-bottom: 0px;" data-mp-plugin="96weixin" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4718045112781955" data-s="300,640" data-type="png" data-w="532" data-imgfileid="503981249" src="https://wechat2rss.xlab.app/img-proxy/?k=e49c9c41&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuOZw5Efn8euiaFfwhWHgt39G73bH815Jd6aZEqBW735E8dBTYly9v7EgmAM7iaUiajEv2oLkIzlcWib81gvFMAEjfCsm4xAyHF8bx1abHIuFftI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">图2  2026年4月漏洞危害等级分布图</span></span></p><div data-mpa-template="t" mpa-paragraph-type="secondTitle" data-mp-plugin="96weixin"><div mpa-from-tpl="t" mpa-paragraph-type="secondTitle" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="27325" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div data-align="title" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;padding-right: 10px;padding-left: 10px;outline: 0px;background-color: rgba(0, 72, 191, 0.75);display: inline-block;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;display: flex;justify-content: center;align-items: center;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 10px;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;letter-spacing: 2px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(255, 255, 255);font-size: 16px;" mpa-is-content="t"><span leaf="">1.3漏洞修复情况</span></span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="color: rgb(18, 93, 196);"><strong><span leaf="">1.3.1 整体修复情况</span></strong></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" data-mp-plugin="96weixin"><span leaf="">2026年4月危害等级修复情况如图3，低危漏洞修复率最高，为72.10%，超危漏洞修复率最低，为61.07%。本月整体修复率环比下降，为70.85%。</span></p><p style="text-align: center;margin-bottom: 0px;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4642857142857143" data-s="300,640" data-type="png" data-w="532" data-imgfileid="503981250" src="https://wechat2rss.xlab.app/img-proxy/?k=16fd4541&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuOZw5Efn8etjNjZhhu9HJDR6qd0z4OqY8eHhkCq6AIYRs2ZBDGBjlO6J8eW41fwFhPHBj1WxNiaibibgIoRKIuB0wLgtTUWCqcZXE0oKcv2ibicI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">图3  2026年4月漏洞危害等级修复统计图</span></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="color: rgb(18, 93, 196);"><strong><span leaf="">1.3.2 厂商修复情况</span></strong></span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf="">2026年4月新增漏洞数量排名前十受影响厂商修复情况如表3，合计1887个漏洞，占本月漏洞总量33.43%，平均修复率为67.92%。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表3  2026年4月受影响厂商漏洞修复统计列表</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.9357798165137615" data-s="300,640" data-type="png" data-w="436" data-imgfileid="503981251" src="https://wechat2rss.xlab.app/img-proxy/?k=482df167&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuOZw5Efn8evd3icyORoQF3LWpibNZLMEgCHo0xib2pxtTJ9Uicg3ibibicEPR06WHibBGMPv6PGNCgeeRWEewnYdFalncuwYypVPm2yJG9ux0IwibQyI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-paragraph-type="title" data-mp-plugin="96weixin"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">二</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">接报漏洞情况</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" data-mp-plugin="96weixin"><span leaf="">2026年4月接报漏洞2974个，其中信息技术产品漏洞（通用型漏洞）2870个，网络信息系统漏洞（事件型漏洞）104个，统计详情如表4。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表4  2026年4月接报漏洞统计列表</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="13.797131147540984" data-s="300,640" data-type="png" data-w="488" data-imgfileid="503981252" src="https://wechat2rss.xlab.app/img-proxy/?k=3a5b87dc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuOZw5Efn8esokOjQSyMj9l82Ww0ibKmoHkibUV9NovVmRKHb7HCVO433NibfibHRmUV9TkQttosJe4k4yOJW96Cv9HM4pmhBsMaowJJrWxiaSZ9Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-paragraph-type="title" data-mp-plugin="96weixin"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">三</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">漏洞通报情况</span></strong></span></p></h2></p></div></div></div></div><div data-mpa-template="t" mpa-paragraph-type="secondTitle" data-mp-plugin="96weixin"><div mpa-from-tpl="t" mpa-paragraph-type="secondTitle" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="27325" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div data-align="title" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;padding-right: 10px;padding-left: 10px;outline: 0px;background-color: rgba(0, 72, 191, 0.75);display: inline-block;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;display: flex;justify-content: center;align-items: center;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 10px;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;letter-spacing: 2px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(255, 255, 255);font-size: 16px;" mpa-is-content="t"><span leaf="">3.1 通报情况</span></span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" data-mp-plugin="96weixin"><span leaf="">2026年4月接报通报1251个，统计详情如表5。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表5  2026年4月接报通报统计列表</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="9.824324324324325" data-s="300,640" data-type="png" data-w="444" data-imgfileid="503981259" src="https://wechat2rss.xlab.app/img-proxy/?k=e820b756&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuOZw5Efn8etoy3OXuP6yjZrn5OPIJQUq4aA4UkHvTU4a8sCde4BGImelAyiatqm2hXqBogtH9Uocs7cCh7pkrEVoX6MswnKqw2HxZ854KDjs%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-paragraph-type="secondTitle" data-mp-plugin="96weixin"><div mpa-from-tpl="t" mpa-paragraph-type="secondTitle" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="27325" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div data-align="title" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;padding-right: 10px;padding-left: 10px;outline: 0px;background-color: rgba(0, 72, 191, 0.75);display: inline-block;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;display: flex;justify-content: center;align-items: center;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 10px;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;letter-spacing: 2px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(255, 255, 255);font-size: 16px;" mpa-is-content="t"><span leaf="">3.2 重要漏洞</span></span></p></div></div></div></div></div></div></div><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表6  2026年4月重要漏洞列表</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="2.134228187919463" data-s="300,640" data-type="png" data-w="447" data-imgfileid="503981254" src="https://wechat2rss.xlab.app/img-proxy/?k=2f24b132&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuOZw5Efn8evcCo9fcB7cQu74eLdGYHjIPV1G9R7biaC7PmP1l5ASraVsOpSztKOvxn3lzcfqba03rc1YickLFYpzERVIhAfyiaz3cysjBibAmks%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-paragraph-type="title" data-mp-plugin="96weixin"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">四</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">漏洞平台推送情况</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" data-mp-plugin="96weixin"><span leaf="">2026年4月漏洞平台推送漏洞17974个，平台推送详情如表7。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表7  2026年4月漏洞平台推送情况列表</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5269121813031161" data-s="300,640" data-type="png" data-w="353" data-imgfileid="503981255" src="https://wechat2rss.xlab.app/img-proxy/?k=5ed178c3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuOZw5Efn8evbEviaPvpib4U8T6zo6ZT9A3oubR0LJXJLKl1Z2OItNbr9tzcFoK1yUvpVVQicB3slXlY94TDaDT1KvdRWnB9oNK6O7Dt0ibylYm4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-paragraph-type="ignored" data-mp-plugin="96weixin"><div mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;flex: 0 0 auto;height: auto;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: flex;flex-flow: row;text-align: center;justify-content: center;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;width: 45px;vertical-align: top;background-color: rgb(18, 93, 196);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 45px;height: auto;" mpa-from-tpl="t" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img __bg_gif" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 45px !important;visibility: visible !important;" data-imgfileid="503963434" src="https://wechat2rss.xlab.app/img-proxy/?k=68515072&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1JMd8aMOqNkic25xydKvYcCVEsHXvm506icfXiaFep4AfohjraUj3F2jMfg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=cbd02cae&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzAxODY1OTM5OQ%3D%3D%26mid%3D2651464919%26idx%3D1%26sn%3D76c7885181a55e29770ca9c5988ba129">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 08 May 2026 17:13:00 +0800</pubDate>
    </item>
    <item>
      <title>信息安全漏洞周报（2026年第18期）</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzAxODY1OTM5OQ==&amp;mid=2651464919&amp;idx=2&amp;sn=b1cb47d66a58470a074953abe0f49a4d</link>
      <description>根据国家信息安全漏洞库（CNNVD）统计，本周（2026年4月27日至2026年5月3日）安全漏洞情况如下</description>
      <content:encoded><![CDATA[<p>原创 <span>CNNVD</span> <span>2026-05-08 17:13</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=01e07cee&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FuOZw5Efn8euAiccfKBrmOGIIPeibZPdIsXjIC0V1854iciaH5dDMNx2iciakCgBd78MfN8kI66LP6nlol00vUOVica9IOkibvBzFIyBh9nRxcecRFSA%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>根据国家信息安全漏洞库（CNNVD）统计，本周（2026年4月27日至2026年5月3日）安全漏洞情况如下</p>
  <div data-mpa-template="t" mpa-paragraph-type="ignored"><div mpa-from-tpl="t"><p data-mpa-powered-by="yiban.io" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: center;visibility: visible;"><img alt="图片" class="rich_pages wxw-img __bg_gif" data-galleryid="" data-imgfileid="503963433" data-ratio="0.1381345926800472" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: bottom;font-size: var(--articleFontsize);letter-spacing: 0.034em;height: auto !important;visibility: visible !important;width: 677px !important;" data-type="gif" data-w="847" src="https://wechat2rss.xlab.app/img-proxy/?k=22c9ee88&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1JjlMnGl5z2XiaAQGZdFulYs0vsE3icB8RUiawPqDSb5lvm8G0drb7iaw7sQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);letter-spacing: 0.544px;text-align: justify;font-size: 16px;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;text-align: center;justify-content: center;display: flex;flex-flow: row;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;transform: rotateZ(19deg);visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;visibility: visible;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 7px;height: auto;visibility: visible;" mpa-from-tpl="t"><img data-imgfileid="503963431" data-ratio="4" data-s="300,640" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 7px !important;visibility: visible !important;" data-type="gif" data-w="36" class="__bg_gif" alt="图片" src="https://wechat2rss.xlab.app/img-proxy/?k=e2d135e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1Js3VkKswpUtkoDWibZ1YQl1lIdcctfqePCcSPEdc38SnhJGdqGJUFx9w%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div><div style="-webkit-tap-highlight-color: transparent;padding-right: 8px;padding-left: 8px;outline: 0px;display: inline-block;vertical-align: middle;width: auto;min-width: 5%;flex: 0 0 auto;height: auto;align-self: center;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: justify;color: rgb(18, 93, 196);" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;text-wrap-style: initial;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;" mpa-from-tpl="t">点击蓝字 关注我们</strong></p></div></div><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;transform: rotateZ(199deg);" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 7px;height: auto;" mpa-from-tpl="t"><img data-imgfileid="503963432" data-ratio="4" data-s="300,640" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 7px !important;visibility: visible !important;" data-type="gif" data-w="36" class="__bg_gif" alt="图片" src="https://wechat2rss.xlab.app/img-proxy/?k=e2d135e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1Js3VkKswpUtkoDWibZ1YQl1lIdcctfqePCcSPEdc38SnhJGdqGJUFx9w%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div><div data-mpa-template="t" mpa-paragraph-type="quote"><div mpa-from-tpl="t" mpa-paragraph-type="quote" data-mp-plugin="96weixin" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);letter-spacing: 0.544px;text-align: justify;visibility: visible;"><div data-role="outer" mpa-from-tpl="t" data-mp-plugin="96weixin" style="-webkit-tap-highlight-color: transparent;outline: 0px;visibility: visible;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 13.5312px;margin-left: 13.5312px;outline: 0px;display: flex;flex-direction: column;border-width: 1px;border-style: solid;border-color: #3f75cf;border-radius: 12px;background-color: #dce8fb;visibility: visible;"><div mpa-from-tpl="t" style="font-size: 16px;-webkit-tap-highlight-color: transparent;padding: 5px 16px;outline: 0px;align-self: center;background-color: #3f75cf;border-radius: 12px;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;font-size: 15px;letter-spacing: 1.5px;line-height: 15px;color: #ffffff;text-align: center;visibility: visible;"><strong><span style="font-size: 18px;">漏洞情况</span></strong></p></div><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;padding: 10px 20px 15px;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.75em;visibility: visible;" mpa-from-tpl="t"><p style="font-size: 16px;-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t">根据国家信息安全漏洞库（CNNVD）统计，本周（2026年4月27日至2026年5月3日）安全漏洞情况如下：</p><p style="font-size: 16px;-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t"><strong>公开漏洞情况</strong></p><p style="font-size: 16px;-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t">本周CNNVD采集安全漏洞1096个。</p><p style="font-size: 16px;-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t"><strong>接报漏洞情况</strong></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t"><span style="font-size: 16px;">本周CNNVD接报漏洞2414个，其中信息技术产品漏洞（通用型漏洞）403个，网络信息系统漏洞（事件型漏洞）15个，漏洞平台推送漏洞1996个。</span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t"><strong><span style="font-size: 16px;">重大漏洞通报</span></strong></p><p style="font-size: 16px;-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t">Linux kernel安全漏洞（CNNVD-202604-4496、CVE-2026-31431）：成功利用漏洞的攻击者，可在目标系统获取root权限。Linux kernel多个版本均受此漏洞影响。目前，Linux官方已发布新版本修复了该漏洞，建议用户及时确认产品版本，尽快采取修补措施。</p></div></div></div></div></div></div><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t">一</span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;">公开漏洞情况</strong></span></p></h2></p></div></div></div></div><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body">根据国家信息安全漏洞库（CNNVD）统计，本周新增安全漏洞1096个，漏洞新增数量有所下降。从厂商分布来看Linux基金会新增漏洞最多，有157个；从漏洞类型来看，注入类的安全漏洞占比最大，达到8.49%。新增漏洞中，超危漏洞72个，高危漏洞340个，中危漏洞649个，低危漏洞35个。</p><div data-mpa-template="t" mpa-paragraph-type="secondTitle"><div mpa-from-tpl="t" mpa-paragraph-type="secondTitle" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="27325" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div data-align="title" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;padding-right: 10px;padding-left: 10px;outline: 0px;background-color: rgba(0, 72, 191, 0.75);display: inline-block;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;display: flex;justify-content: center;align-items: center;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 10px;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;letter-spacing: 2px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(255, 255, 255);font-size: 16px;" mpa-is-content="t">（一） 安全漏洞增长数量情况</span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;">本周CNNVD采集安全漏洞1096个。</p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="image"><img class="rich_pages wxw-img" data-ratio="0.5948103792415169" style="left: 0px;top: 0px;width: 90.4332%;height: 298px;border-width: 1px;border-style: solid;border-color: rgb(229, 228, 228);" data-w="501" src="https://wechat2rss.xlab.app/img-proxy/?k=743c5b83&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FuOZw5Efn8es7TnTUO9VE4RPCiaF1lHfNRmibsMB7Mkp3aA863AibE5G2dVJaJyskC75HO67VUHozy8OhdtVia5Mp0x415KRHkvgcsxIw9fdssNA%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg"/></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;">图1 近五周漏洞新增数量统计图</span></p><div data-mpa-template="t" mpa-paragraph-type="secondTitle"><div mpa-from-tpl="t" mpa-paragraph-type="secondTitle" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="27325" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div data-align="title" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;padding-right: 10px;padding-left: 10px;outline: 0px;background-color: rgba(0, 72, 191, 0.75);display: inline-block;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;display: flex;justify-content: center;align-items: center;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 10px;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;letter-spacing: 2px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(255, 255, 255);font-size: 16px;" mpa-is-content="t">（二） 安全漏洞分布情况</span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;">从厂商分布来看，Linux基金会新增漏洞最多，有157个。各厂商漏洞数量分布如表1所示。</p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;">表1 新增安全漏洞排名前五厂商统计表</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="503981261" data-ratio="0.5777202072538861" data-s="300,640" style="" data-type="png" data-w="386" src="https://wechat2rss.xlab.app/img-proxy/?k=2948bbdf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuOZw5Efn8evdZTwdfE1gGIHmXjgDy7L7CyRfib8A9DanY4GWzRBuI2Y0dtuM7ec4IbgrYJYFTDy1VvMBJW4zLxkDCSFBx67Mo53Hia5vRY4ics%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;">本周国内厂商漏洞133个，吉翁电子公司漏洞数量最多，有31个。国内厂商漏洞整体修复率为23.70%。请受影响用户关注厂商修复情况，及时下载补丁修复漏洞。</p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;">从漏洞类型来看，注入类的安全漏洞占比最大，达到8.49%。漏洞类型统计如表2所示。</p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;">表2 漏洞类型统计表</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="503981262" data-ratio="2.494818652849741" data-s="300,640" style="" data-type="png" data-w="386" src="https://wechat2rss.xlab.app/img-proxy/?k=58886693&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuOZw5Efn8euC7UQeZxFxAH4ZdelSSibtZicZQIB7hM0ZcKzfYNs1yFTHR4uwXEpPj5S8D6S6LkcClVZrNatUibHE7wjBpdXAWQafW9dibzCxbW8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-paragraph-type="secondTitle"><div mpa-from-tpl="t" mpa-paragraph-type="secondTitle" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="27325" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div data-align="title" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;padding-right: 10px;padding-left: 10px;outline: 0px;background-color: rgba(0, 72, 191, 0.75);display: inline-block;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;display: flex;justify-content: center;align-items: center;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 10px;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;letter-spacing: 2px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(255, 255, 255);font-size: 16px;" mpa-is-content="t">（三） 安全漏洞危害等级与修复情况</span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;">本周共发布超危漏洞72个，高危漏洞340个，中危漏洞649个，低危漏洞35个。相应修复率分别为38.89%、56.18%、72.27%和42.86%。根据补丁信息统计，合计703个漏洞已有修复补丁发布，整体修复率为64.14%。详细情况如表3所示。</p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;">表3 漏洞危害等级与修复情况</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="503981263" data-ratio="0.5490196078431373" data-s="300,640" style="" data-type="png" data-w="408" src="https://wechat2rss.xlab.app/img-proxy/?k=fe0b3253&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuOZw5Efn8etiawaUeLh0mpHNdwt8bTyIiabsuCpbpibexNwllKFOib1uvSUQfPwKoU1vuEZia6x6raPdKc3A3mBq9BxFlN18M2XUwrAuDhcwBTUI%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-paragraph-type="secondTitle"><div mpa-from-tpl="t" mpa-paragraph-type="secondTitle" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="27325" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div data-align="title" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;padding-right: 10px;padding-left: 10px;outline: 0px;background-color: rgba(0, 72, 191, 0.75);display: inline-block;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;display: flex;justify-content: center;align-items: center;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 10px;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;letter-spacing: 2px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(255, 255, 255);font-size: 16px;" mpa-is-content="t">（四） 本周重要漏洞实例</span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;">本周重要漏洞实例如表4所示。</p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;">表4 本期重要漏洞实例</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="503981264" data-ratio="0.4775641025641026" data-s="300,640" style="" data-type="png" data-w="312" src="https://wechat2rss.xlab.app/img-proxy/?k=88378051&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuOZw5Efn8euicSaAyUhb5GS9SlLiccC53rPjEdibW53723v61icNrmkbZcibymo17iaFWYtlibV6KLrFiaHUvIfPX833C9x648eJwdc6Jl8DibWictUCs%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;">1. Apache Camel 安全漏洞（CNNVD-202604-5254）</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;">Apache Camel是美国阿帕奇（Apache）基金会的一套开源的基于Enterprise Integration Pattern(企业整合模式，简称EIP)的集成框架。</p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;">Apache Camel存在安全漏洞，该漏洞源于对部分属性修改不当，攻击者利用该漏洞可以远程执行任意操作系统命令。以下版本受到影响：4.14.0版本至4.14.5版本、4.18.0版本至4.18.1之前版本和4.19.0版本。</p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;">目前厂商已发布升级补丁以修复漏洞，参考链接：</p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><a href="https://camel.apache.org/download/" target="_blank">https://camel.apache.org/download/</a></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;">2. Google Chrome 资源管理错误漏洞（CNNVD-202604-5327）</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;">Google Chrome是美国谷歌（Google）公司的一款Web浏览器。</p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;">Google Chrome 147.0.7727.138之前版本存在资源管理错误漏洞，该漏洞源于内存释放后重用，攻击者利用该漏洞可以通过特制的HTML页面执行任意代码。</p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;">目前厂商已发布升级补丁以修复漏洞，参考链接：</p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><a href="https://chromereleases.googleblog.com/2026/04/stable-channel-update-for-desktop_28.html" target="_blank">https://chromereleases.googleblog.com/2026/04/stable-channel-update-for-desktop_28.html</a></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;">3. WordPress plugin Gravity Forms 跨站脚本漏洞（CNNVD-202605-320）</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;">WordPress和WordPress plugin都是WordPress基金会的产品。WordPress是一套使用PHP语言开发的博客平台，该平台具有在基于PHP和MySQL的服务器上架设个人博客网站的功能。WordPress plugin Gravity Forms是一个应用插件。</p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;">WordPress plugin Gravity Forms 2.10.0版本及之前版本存在跨站脚本漏洞，该漏洞源于对Calculation Product字段产品名称的输入验证和输出转义不足，攻击者利用该漏洞可以通过表单注入任意Web脚本。</p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body">目前厂商已发布升级补丁以修复漏洞，参考链接：</p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/63973f61-81f0-4fc8-810c-a15734ff824e?source=cve" target="_blank">https://www.wordfence.com/threat-intel/vulnerabilities/id/63973f61-81f0-4fc8-810c-a15734ff824e?source=cve</a></p><div data-mpa-template="t" mpa-paragraph-type="secondTitle"><div mpa-from-tpl="t" mpa-paragraph-type="secondTitle" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="27325" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div data-align="title" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;padding-right: 10px;padding-left: 10px;outline: 0px;background-color: rgba(0, 72, 191, 0.75);display: inline-block;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;display: flex;justify-content: center;align-items: center;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 10px;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;letter-spacing: 2px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(255, 255, 255);font-size: 16px;" mpa-is-content="t">（五） 本周重要人工智能漏洞实例</span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;">本周重要人工智能漏洞实例如表5所示。</p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;">表5 本期重要人工智能漏洞实例</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="503981265" data-ratio="0.4775641025641026" data-s="300,640" style="" data-type="png" data-w="312" src="https://wechat2rss.xlab.app/img-proxy/?k=dbd3a9ba&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuOZw5Efn8ettuC2FJG14uy1AfThlqrIhUrCRfJib9tdHN3D153jJJx3A4zl8OcJH8SP4icPS97ZmYcQLPAbzGCf0FmZvxjuicb8s018rURJzjg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;">1. OpenClaw 安全漏洞（CNNVD-202604-5410）</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;">OpenClaw是一个开源的智能人工助理。</p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;">OpenClaw 2026.3.22之前版本存在安全漏洞，该漏洞源于引导设置代码在配对期间未绑定到预期的设备角色，攻击者利用该漏洞可以提升权限。</p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;">目前厂商已发布升级补丁以修复漏洞，参考链接：</p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><a href="https://github.com/openclaw/openclaw/releases" target="_blank">https://github.com/openclaw/openclaw/releases</a></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;">2. Ollama 路径遍历漏洞（CNNVD-202604-5679）</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;">Ollama是一个开源的可以在本地设备上运行、管理和自定义大语言模型的工具。</p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;">Ollama 0.12.10版本至0.17.5版本存在路径遍历漏洞，该漏洞源于在构造本地文件路径时未验证路径安全性，攻击者利用该漏洞可以将文件写入任意位置。</p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;">目前厂商已发布升级补丁以修复漏洞，参考链接：</p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><a href="https://ollama.com/" target="_blank">https://ollama.com/</a></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;">3. VMware Spring AI 代码注入漏洞（CNNVD-202604-5511）</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;">VMware Spring AI是美国威睿（VMware）公司的一个在Spring生态中集成人工智能与大语言模型能力的开发框架。</p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;">VMware Spring AI 1.0.0版本至1.0.5版本和1.1.0版本至1.1.4版本存在代码注入漏洞，该漏洞源于键和值未正确转义，攻击者利用该漏洞可以篡改查询语句。</p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body">目前厂商已发布升级补丁以修复漏洞，参考链接：</p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><a href="https://spring.io/security/cve-2026-40967" target="_blank">https://spring.io/security/cve-2026-40967</a></p><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t">二</span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;">漏洞平台推送情况</strong></span></p></h2></p></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;">本周CNNVD接收漏洞平台推送漏洞1996个。</p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;">表6 本周漏洞平台推送情况</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="503981266" data-ratio="0.4807692307692308" data-s="300,640" style="" data-type="png" data-w="312" src="https://wechat2rss.xlab.app/img-proxy/?k=6f6ffc03&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuOZw5Efn8etLUoQkRqazDIUicEFBkERghQlDdR5g9Eb7vonGNUQOGxgxicJweicC8rohkC9cy6JzyhEBHkHqTqgThpm7slvEtreicY0evj69OTA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t">三</span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;">接报漏洞情况</strong></span></p></h2></p></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;">本周CNNVD接报漏洞418个，其中信息技术产品漏洞（通用型漏洞）403个，网络信息系统漏洞（事件型漏洞）15个。</p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;">表7 本周漏洞报送情况</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="503981267" data-ratio="7.128968253968254" data-s="300,640" style="" data-type="png" data-w="504" src="https://wechat2rss.xlab.app/img-proxy/?k=c8749eda&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuOZw5Efn8et4jJfbsjzficdRx4GgIh5BsCdlsaqKrH2vveVdPSpIKsAzm0pqm1zPGkrPkaFtf88NE9qKtpf2jhMF0qnQnrQc3RTH6UdhicZew%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t">四</span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;">收录漏洞通报情况</strong></span></p></h2></p></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;">本周CNNVD收录漏洞通报186份。</p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;">表8 本周漏洞通报情况</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="503981268" data-ratio="4.044444444444444" data-s="300,640" style="" data-type="png" data-w="495" src="https://wechat2rss.xlab.app/img-proxy/?k=59cfe2ee&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuOZw5Efn8es06DJOgHXwPNegjcPrxM4ISV8dgUIxgwgXU5RqUBPznRlopswyRU0SXuHYC9NwodgibvVQJn7raNHruiaNB8IHjDO7AFib1ECtY0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t">五</span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;">重大漏洞通报</strong></span></p></h2></p></div></div></div></div><p style="margin: 0px 0px 16px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-size: 17px;">CNNVD关于Linux kernel安全漏洞的通报</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;">近日，国家信息安全漏洞库（CNNVD）收到关于Linux kernel安全漏洞（CNNVD-202604-4496、CVE-2026-31431）情况的报送。成功利用漏洞的攻击者，可在目标系统获取root权限。Linux kernel多个版本均受此漏洞影响。目前，Linux官方已发布新版本修复了该漏洞，建议用户及时确认产品版本，尽快采取修补措施。</p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="color: rgb(18, 93, 196);"><strong>1.漏洞介绍</strong></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;">Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。该漏洞源于内核加密子系统中的一处逻辑缺陷，攻击者可以利用AF_ALG加密接口与splice()系统调用的组合，向任意可读文件的页缓存写入受控的4字节数据，从而篡改setuid程序，获取系统root权限。目前该漏洞利用代码和技术细节已公开。</p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;">该漏洞于4月22日被国家信息安全漏洞库采集并收录。近期，该漏洞利用代码和技术细节被公开，影响范围迅速扩大，建议用户尽快采取修补措施。</p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="color: rgb(18, 93, 196);"><strong>2.危害影响</strong></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;">Ubuntu 24.04 LTS及以下版本、Amazon Linux 2023及以下版本、Red Hat Enterprise Linux 10及以下版本、Red Hat Enterprise Linux 9及以下版本、Red Hat Enterprise Linux 8及以下版本、SUSE 16及以下版本、Debian/Arch/Fedora/Rocky/Alma/Oracle等同期内核版本均受此漏洞影响。</p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="color: rgb(18, 93, 196);"><strong>3.修复建议</strong></span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;">目前，Linux官方已发布新版本修复了该漏洞，建议用户及时确认产品版本，尽快采取修补措施。参考链接：</p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><a href="https://www.kernel.org/" target="_blank">https://www.kernel.org/</a></p><div data-mpa-template="t" mpa-paragraph-type="ignored"><div mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;flex: 0 0 auto;height: auto;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: flex;flex-flow: row;text-align: center;justify-content: center;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;width: 45px;vertical-align: top;background-color: rgb(18, 93, 196);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 45px;height: auto;" mpa-from-tpl="t"><img class="rich_pages wxw-img __bg_gif" data-imgfileid="503963434" data-ratio="0.1503267973856209" data-s="300,640" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 45px !important;visibility: visible !important;" data-type="gif" data-w="306" alt="图片" src="https://wechat2rss.xlab.app/img-proxy/?k=68515072&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1JMd8aMOqNkic25xydKvYcCVEsHXvm506icfXiaFep4AfohjraUj3F2jMfg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=0a589863&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzAxODY1OTM5OQ%3D%3D%26mid%3D2651464919%26idx%3D2%26sn%3Db1cb47d66a58470a074953abe0f49a4d">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 08 May 2026 17:13:00 +0800</pubDate>
    </item>
    <item>
      <title>CNNVD关于Palo Alto Networks PAN-OS 安全漏洞的通报</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzAxODY1OTM5OQ==&amp;mid=2651464891&amp;idx=1&amp;sn=9ecaa66ca0874d315e99a0b85ad4bd02</link>
      <description>近日，国家信息安全漏洞库（CNNVD）收到关于Palo Alto Networks PAN-OS安全漏洞（CNNVD-202605-766、CVE-2026-0300）情况的报送。</description>
      <content:encoded><![CDATA[<p><span>CNNVD</span> <span>2026-05-07 18:33</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=4252e089&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FuOZw5Efn8evDxtD25l6xV9EnNw1y3tdsAeh7wxicRngL3AMaYn8Qwsxen0pH4jJYOHRBlFwUIFd09Oyo3icaSzUXplz6GYl7d5ezdoWLE55vc%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>近日，国家信息安全漏洞库（CNNVD）收到关于Palo Alto Networks PAN-OS安全漏洞（CNNVD-202605-766、CVE-2026-0300）情况的报送。</p>
  <div data-mpa-template="t" mpa-paragraph-type="ignored"><div mpa-from-tpl="t"><p data-mpa-powered-by="yiban.io" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: center;visibility: visible;" nodeleaf=""><img alt="图片" class="rich_pages wxw-img __bg_gif" data-aistatus="1" data-imgfileid="503963433" data-ratio="0.1381345926800472" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: bottom;font-size: var(--articleFontsize);letter-spacing: 0.034em;height: auto !important;visibility: visible !important;width: 677px !important;" data-type="gif" data-w="847" src="https://wechat2rss.xlab.app/img-proxy/?k=22c9ee88&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1JjlMnGl5z2XiaAQGZdFulYs0vsE3icB8RUiawPqDSb5lvm8G0drb7iaw7sQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);letter-spacing: 0.544px;text-align: justify;font-size: 16px;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;text-align: center;justify-content: center;display: flex;flex-flow: row;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;transform: rotateZ(19deg);visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;visibility: visible;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 7px;height: auto;visibility: visible;" mpa-from-tpl="t" nodeleaf=""><img data-aistatus="1" alt="图片" class="__bg_gif" data-ratio="4" data-s="300,640" data-type="gif" data-w="36" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 7px !important;visibility: visible !important;" data-imgfileid="503963431" src="https://wechat2rss.xlab.app/img-proxy/?k=e2d135e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1Js3VkKswpUtkoDWibZ1YQl1lIdcctfqePCcSPEdc38SnhJGdqGJUFx9w%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div><div style="-webkit-tap-highlight-color: transparent;padding-right: 8px;padding-left: 8px;outline: 0px;display: inline-block;vertical-align: middle;width: auto;min-width: 5%;flex: 0 0 auto;height: auto;align-self: center;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: justify;color: rgb(18, 93, 196);" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;text-wrap-style: initial;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;" mpa-from-tpl="t"><span leaf="">点击蓝字 关注我们</span></strong></p></div></div><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;transform: rotateZ(199deg);" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 7px;height: auto;" mpa-from-tpl="t" nodeleaf=""><img data-imgfileid="503963432" alt="图片" class="__bg_gif" data-ratio="4" data-s="300,640" data-type="gif" data-w="36" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 7px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=e2d135e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1Js3VkKswpUtkoDWibZ1YQl1lIdcctfqePCcSPEdc38SnhJGdqGJUFx9w%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div><div data-mpa-template="t" mpa-paragraph-type="quote"><div mpa-from-tpl="t" mpa-paragraph-type="quote" data-mp-plugin="96weixin" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;visibility: visible;"><div data-role="outer" mpa-from-tpl="t" data-mp-plugin="96weixin" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;visibility: visible;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 13.5312px;margin-left: 13.5312px;outline: 0px;display: flex;flex-direction: column;border-width: 1px;border-style: solid;border-color: #3f75cf;border-radius: 12px;background-color: #dce8fb;visibility: visible;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;padding: 5px 16px;outline: 0px;align-self: center;background-color: #3f75cf;border-radius: 12px;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;font-size: 15px;letter-spacing: 1.5px;line-height: 15px;color: #ffffff;text-align: center;visibility: visible;"><span style="font-size: 18px;"><strong><span leaf="">漏洞情况</span></strong></span></p></div><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;padding: 10px 20px 15px;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.75em;visibility: visible;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t"><span leaf="">近日，国家信息安全漏洞库（CNNVD）收到关于Palo Alto Networks PAN-OS安全漏洞（CNNVD-202605-766、CVE-2026-0300）情况的报送。攻击者可通过向目标防火墙发送特制的数据包，触发缓冲区溢出，从而在目标设备上执行任意代码。PAN-OS多个版本均受此漏洞影响。目前，Palo Alto Networks官方已发布新版本修复了该漏洞，建议用户及时确认产品版本，尽快采取修补措施。</span></p></div></div></div></div></div></div><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">一</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">漏洞介绍</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf="">Palo Alto Networks PAN-OS是美国Palo Alto Networks公司的一套为其防火墙设备开发的操作系统。该漏洞源于 User-ID Authentication Portal 服务在处理特定数据包时的边界检查不足。未经身份认证的攻击者可通过向目标防火墙的User-ID Authentication Portal服务发送特制的数据包，触发缓冲区溢出，从而在目标设备上以 root 权限执行任意代码。</span></p><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">二</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">危害影响</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf="">PAN-OS 12.1 &lt; 12.1.4-h5、PAN-OS 12.1 &lt; 12.1.7、PAN-OS 11.2 &lt; 11.2.4-h17、PAN-OS 11.2 &lt; 11.2.7-h13、PAN-OS 11.2 &lt; 11.2.10-h6、PAN-OS 11.2 &lt; 11.2.12、PAN-OS 11.1 &lt; 11.1.4-h33、PAN-OS 11.1 &lt; 11.1.6-h32、PAN-OS 11.1 &lt; 11.1.7-h6、PAN-OS 11.1 &lt; 11.1.10-h25、PAN-OS 11.1 &lt; 11.1.13-h5、PAN-OS 11.1 &lt; 11.1.15、PAN-OS 10.2 &lt; 10.2.7-h34、PAN-OS 10.2 &lt; 10.2.10-h36、PAN-OS 10.2 &lt; 10.2.13-h21、PAN-OS 10.2 &lt; 10.2.16-h7、PAN-OS 10.2 &lt; 10.2.18-h6等版本均受此漏洞影响。</span></p><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">三</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">修复建议</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf="">目前，Palo Alto Networks官方已发布新版本修复了该漏洞，建议用户及时确认产品版本，尽快采取修补措施。官方参考链接：</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf=""><a href="https://security.paloaltonetworks.com/CVE-2026-0300" target="_blank">https://security.paloaltonetworks.com/CVE-2026-0300</a></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">本通报由CNNVD技术支撑单位——奇安信网神信息技术（北京）股份有限公司、上海戎磐网络科技有限公司、广东南方信息安全研究院、贵州粟字科技有限公司、北方实验室（沈阳）股份有限公司、深圳市魔方安全科技有限公司等技术支撑单位提供支持。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">CNNVD将继续跟踪上述漏洞的相关情况，及时发布相关信息。如有需要，可与CNNVD联系。联系方式: cnnvd@itsec.gov.cn</span></p><div data-mpa-template="t" mpa-paragraph-type="ignored"><div mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;flex: 0 0 auto;height: auto;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: flex;flex-flow: row;text-align: center;justify-content: center;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;width: 45px;vertical-align: top;background-color: rgb(18, 93, 196);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 45px;height: auto;" mpa-from-tpl="t" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img __bg_gif" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 45px !important;visibility: visible !important;" data-imgfileid="503963434" src="https://wechat2rss.xlab.app/img-proxy/?k=68515072&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1JMd8aMOqNkic25xydKvYcCVEsHXvm506icfXiaFep4AfohjraUj3F2jMfg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=67d97f4c&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzAxODY1OTM5OQ%3D%3D%26mid%3D2651464891%26idx%3D1%26sn%3D9ecaa66ca0874d315e99a0b85ad4bd02">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 07 May 2026 18:33:00 +0800</pubDate>
    </item>
    <item>
      <title>人工智能重要安全漏洞通报Ollama安全漏洞</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzAxODY1OTM5OQ==&amp;mid=2651464882&amp;idx=1&amp;sn=0568478d25e0afe6316278ebfeb80c0a</link>
      <description>近日，国家信息安全漏洞库（CNNVD）收到关于Ollama安全漏洞（CNNVD-202605-502、CVE-2026-7482）情况的报送。攻击者通过漏洞可获取环境变量、API密钥、系统提示和并发用户的对话数据。Ollama 0.17.1之前版本均受此漏洞影响。</description>
      <content:encoded><![CDATA[<p>原创 <span>CNNVD</span> <span>2026-05-06 18:25</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=f78a28fd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FuOZw5Efn8evLOmQ52iaCpAFQ8yvR2G4CJ6Dg4LlAWmEXOqSH0Ryw9DxIQ9HRicmvGuLWHRDWS8Ewy3AQTI6bp8hVpZbstVdCx3icAMMicNWavXg%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>近日，国家信息安全漏洞库（CNNVD）收到关于Ollama安全漏洞（CNNVD-202605-502、CVE-2026-7482）情况的报送。攻击者通过漏洞可获取环境变量、API密钥、系统提示和并发用户的对话数据。Ollama 0.17.1之前版本均受此漏洞影响。</p>
  <div data-mpa-template="t" mpa-paragraph-type="ignored"><div mpa-from-tpl="t"><p data-mpa-powered-by="yiban.io" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: center;visibility: visible;" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img __bg_gif" data-ratio="0.1381345926800472" data-type="gif" data-w="847" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: bottom;font-size: var(--articleFontsize);letter-spacing: 0.034em;height: auto !important;visibility: visible !important;width: 677px !important;" data-imgfileid="503963433" src="https://wechat2rss.xlab.app/img-proxy/?k=22c9ee88&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1JjlMnGl5z2XiaAQGZdFulYs0vsE3icB8RUiawPqDSb5lvm8G0drb7iaw7sQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);letter-spacing: 0.544px;text-align: justify;font-size: 16px;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;text-align: center;justify-content: center;display: flex;flex-flow: row;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;transform: rotateZ(19deg);visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;visibility: visible;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 7px;height: auto;visibility: visible;" mpa-from-tpl="t" nodeleaf=""><img data-aistatus="1" alt="图片" class="__bg_gif" data-ratio="4" data-s="300,640" data-type="gif" data-w="36" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 7px !important;visibility: visible !important;" data-imgfileid="503963431" src="https://wechat2rss.xlab.app/img-proxy/?k=e2d135e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1Js3VkKswpUtkoDWibZ1YQl1lIdcctfqePCcSPEdc38SnhJGdqGJUFx9w%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div><div style="-webkit-tap-highlight-color: transparent;padding-right: 8px;padding-left: 8px;outline: 0px;display: inline-block;vertical-align: middle;width: auto;min-width: 5%;flex: 0 0 auto;height: auto;align-self: center;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: justify;color: rgb(18, 93, 196);" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;text-wrap-style: initial;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;" mpa-from-tpl="t"><span leaf="">点击蓝字 关注我们</span></strong></p></div></div><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;transform: rotateZ(199deg);" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 7px;height: auto;" mpa-from-tpl="t" nodeleaf=""><img data-aistatus="1" alt="图片" class="__bg_gif rich_pages wxw-img" data-ratio="4" data-s="300,640" data-type="gif" data-w="36" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 7px !important;visibility: visible !important;" data-imgfileid="503963432" src="https://wechat2rss.xlab.app/img-proxy/?k=e2d135e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1Js3VkKswpUtkoDWibZ1YQl1lIdcctfqePCcSPEdc38SnhJGdqGJUFx9w%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div><div data-mpa-template="t" mpa-paragraph-type="quote"><div mpa-from-tpl="t" mpa-paragraph-type="quote" data-mp-plugin="96weixin" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;visibility: visible;"><div data-role="outer" mpa-from-tpl="t" data-mp-plugin="96weixin" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;visibility: visible;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 13.5312px;margin-left: 13.5312px;outline: 0px;display: flex;flex-direction: column;border-width: 1px;border-style: solid;border-color: #3f75cf;border-radius: 12px;background-color: #dce8fb;visibility: visible;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;padding: 5px 16px;outline: 0px;align-self: center;background-color: #3f75cf;border-radius: 12px;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;font-size: 15px;letter-spacing: 1.5px;line-height: 15px;color: #ffffff;text-align: center;visibility: visible;"><span style="font-size: 18px;"><strong><span leaf="">漏洞情况</span></strong></span></p></div><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;padding: 10px 20px 15px;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.75em;visibility: visible;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t"><span leaf="">近日，国家信息安全漏洞库（CNNVD）收到关于Ollama安全漏洞（CNNVD-202605-502、CVE-2026-7482）情况的报送。攻击者通过漏洞可获取环境变量、API密钥、系统提示和并发用户的对话数据。Ollama 0.17.1之前版本均受此漏洞影响。目前，Ollama官方已发布新版本修复了该漏洞，建议用户及时确认产品版本，尽快采取修补措施。</span></p></div></div></div></div></div></div><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">一</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(71, 122, 200);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);outline: 0px;visibility: visible;">漏洞介绍</span></strong></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf="">Ollama是一个开源的跨</span><span leaf="" style="text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;">平台大模型工具。该漏洞源于GGUF模型加载器中堆越界读取，可能导致服务器读取超出分配的堆缓冲区内存，攻击者通过漏洞可获取环境变量、API密钥、系统提示和并发用户的对话数据。</span></p><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">二</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(71, 122, 200);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);visibility: visible;"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);outline: 0px;visibility: visible;">危害影响</span></strong></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf="">Ollama 0.17.1之前版本均受此漏洞影响。</span></p><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">三</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(71, 122, 200);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 18px;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);"><span leaf="" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);outline: 0px;">修复建议</span></strong></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="" style="text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;">目前，Ollama官方已发布新版本修复了该漏洞，建议用户及时确认产品版本，尽快采取修补措施。官方补丁链接：</span></p><p><span leaf=""><span textstyle="" style="font-size: 16px;"><a href="https://github.com/ollama/ollama/releases/tag/v0.17.1" target="_blank">https://github.com/ollama/ollama/releases/tag/v0.17.1</a></span></span></p><p><span leaf=""><span textstyle="" style="font-size: 16px;">本通报由CNNVD技术支撑单位——奇安信网神信息技术（北京）股份有限公司、北方实验室（沈阳）股份有限公司、中国银联股份有限公司、内蒙古万德系统集成有限责任公司、内蒙古网安信息安全技术有限公司等技术支撑单位提供支持。</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 16px;">CNNVD将继续跟踪上述漏洞的相关情况，及时发布相关信息。如有需要，可与CNNVD联系。联系方式: cnnvd@itsec.gov.cn</span></span></p><div data-mpa-template="t" mpa-paragraph-type="ignored"><div mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;flex: 0 0 auto;height: auto;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: flex;flex-flow: row;text-align: center;justify-content: center;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;width: 45px;vertical-align: top;background-color: rgb(18, 93, 196);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 45px;height: auto;" mpa-from-tpl="t" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img __bg_gif" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 45px !important;visibility: visible !important;" data-imgfileid="503963434" src="https://wechat2rss.xlab.app/img-proxy/?k=68515072&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1JMd8aMOqNkic25xydKvYcCVEsHXvm506icfXiaFep4AfohjraUj3F2jMfg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=208eacf5&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzAxODY1OTM5OQ%3D%3D%26mid%3D2651464882%26idx%3D1%26sn%3D0568478d25e0afe6316278ebfeb80c0a">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 06 May 2026 18:25:00 +0800</pubDate>
    </item>
    <item>
      <title>人工智能重要漏洞通报（2026年第六期）</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzAxODY1OTM5OQ==&amp;mid=2651464856&amp;idx=1&amp;sn=4bcad41d0cb6306a6323b194131f638c</link>
      <description>根据国家信息安全漏洞库（CNNVD）统计，近期（2026年4月16日至2026年4月28日）共采集重要人工智能漏洞213个</description>
      <content:encoded><![CDATA[<p>原创 <span>CNNVD</span> <span>2026-04-30 13:54</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=32195d0e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FuOZw5Efn8esYqLx8vyW1EfeMv7cmTP75libjUcAE6HVicPwxMm7KIAqstdASOfgCmV7ic0elG7jehKfhRjjoOm3rGUFgMicWxUTLIQ3libwxLoicQ%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>根据国家信息安全漏洞库（CNNVD）统计，近期（2026年4月16日至2026年4月28日）共采集重要人工智能漏洞213个</p>
  <div data-mpa-template="t" mpa-paragraph-type="ignored"><div mpa-from-tpl="t"><p data-mpa-powered-by="yiban.io" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: center;visibility: visible;" nodeleaf=""><img alt="图片" class="rich_pages wxw-img __bg_gif" data-aistatus="1" data-imgfileid="503963433" data-ratio="0.1381345926800472" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: bottom;font-size: var(--articleFontsize);letter-spacing: 0.034em;height: auto !important;visibility: visible !important;width: 677px !important;" data-type="gif" data-w="847" src="https://wechat2rss.xlab.app/img-proxy/?k=22c9ee88&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1JjlMnGl5z2XiaAQGZdFulYs0vsE3icB8RUiawPqDSb5lvm8G0drb7iaw7sQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);letter-spacing: 0.544px;text-align: justify;font-size: 16px;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;text-align: center;justify-content: center;display: flex;flex-flow: row;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;transform: rotateZ(19deg);visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;visibility: visible;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 7px;height: auto;visibility: visible;" mpa-from-tpl="t" nodeleaf=""><img data-aistatus="1" alt="图片" class="__bg_gif" data-ratio="4" data-s="300,640" data-type="gif" data-w="36" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 7px !important;visibility: visible !important;" data-imgfileid="503963431" src="https://wechat2rss.xlab.app/img-proxy/?k=e2d135e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1Js3VkKswpUtkoDWibZ1YQl1lIdcctfqePCcSPEdc38SnhJGdqGJUFx9w%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div><div style="-webkit-tap-highlight-color: transparent;padding-right: 8px;padding-left: 8px;outline: 0px;display: inline-block;vertical-align: middle;width: auto;min-width: 5%;flex: 0 0 auto;height: auto;align-self: center;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: justify;color: rgb(18, 93, 196);" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;text-wrap-style: initial;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;" mpa-from-tpl="t"><span leaf="">点击蓝字 关注我们</span></strong></p></div></div><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;transform: rotateZ(199deg);" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 7px;height: auto;" mpa-from-tpl="t" nodeleaf=""><img data-imgfileid="503963432" alt="图片" class="__bg_gif" data-ratio="4" data-s="300,640" data-type="gif" data-w="36" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 7px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=e2d135e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1Js3VkKswpUtkoDWibZ1YQl1lIdcctfqePCcSPEdc38SnhJGdqGJUFx9w%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div><div data-mpa-template="t" mpa-paragraph-type="quote"><div mpa-from-tpl="t" mpa-paragraph-type="quote" data-mp-plugin="96weixin" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;visibility: visible;"><div data-role="outer" mpa-from-tpl="t" data-mp-plugin="96weixin" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;visibility: visible;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 13.5312px;margin-left: 13.5312px;outline: 0px;display: flex;flex-direction: column;border-width: 1px;border-style: solid;border-color: #3f75cf;border-radius: 12px;background-color: #dce8fb;visibility: visible;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;padding: 5px 16px;outline: 0px;align-self: center;background-color: #3f75cf;border-radius: 12px;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;font-size: 15px;letter-spacing: 1.5px;line-height: 15px;color: #ffffff;text-align: center;visibility: visible;"><span style="font-size: 18px;"><strong><span leaf="">漏洞情况</span></strong></span></p></div><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;padding: 10px 20px 15px;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.75em;visibility: visible;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t"><span leaf="">根据国家信息安全漏洞库（CNNVD）统计，近期（2026年4月16日至2026年4月28日）共采集重要人工智能漏洞213个，CNNVD对这些漏洞进行了收录。本周人工智能类漏洞主要涵盖了NVIDIA、OpenClaw、Samsung（ONE）、Ollama等多个厂商（项目）。CNNVD对其危害等级进行了评价，其中超危漏洞8个，高危漏洞89个，中危漏洞116个。</span></p></div></div></div></div></div></div><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">一</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">人工智能漏洞增长数量情况</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">近期CNNVD采集人工智能漏洞213个。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="image" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-ratio="0.6028225806451613" style="left: 0px;top: 0px;width: 86.1111%;height: 299px;border-width: 1px;border-style: solid;border-color: rgb(229, 228, 228);" data-w="496" src="https://wechat2rss.xlab.app/img-proxy/?k=fb716470&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FuOZw5Efn8etVcw0a2RXyOvEIyDD3Zzo8lH8YQb7eib6r8tM8cxeY3zMmdchqhyE6LiaK57OH7UcCD7KdIic3UqFT0hfMN6IpTztPhaooJXsuZg%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg"/></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-size: 14px;"><span leaf="">图1 近五周漏洞新增数量统计图</span></span></p><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">二</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">人工智能漏洞具体情况</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">近期共采集人工智能漏洞213个，包括NVIDIA、OpenClaw、Samsung（ONE）、Ollama等多个厂商（项目）的漏洞。其中超危漏洞8个，高危漏洞89个，中危漏洞116个。具体如表1所示：</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表1 人工智能漏洞列表</span></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="503981201" data-ratio="21.599624060150376" data-s="300,640" data-w="532" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=a9384fbd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuOZw5Efn8euWVib8Wh9gQeOPEwft2LHHvr1fia1M2l3PoLF92z8weDzdLqdh0pfB8XzT3eyxUeOicGsULAjAz2wIdtA1Cpj9Gw6ccNA15MLgUA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">三</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">重要人工智能漏洞实例</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">近期重要漏洞实例如表2所示。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表2 本期重要漏洞实例</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4983277591973244" data-s="300,640" data-type="png" data-w="299" data-imgfileid="503981202" src="https://wechat2rss.xlab.app/img-proxy/?k=883c8b94&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuOZw5Efn8ev5YpryYY4KNPWiaiadlFojzldicmdsObHmZ4Jl1sibKmPkibjpJV1hSrSANgiaYpOiaxLo55BSrQ4ic97lTqFS8M8ESw3cSibU43Jx4Zzc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">1. OpenClaw 安全漏洞（CNNVD-202604-4179）</span></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">OpenClaw是一个开源的智能人工助理。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">OpenClaw 2026.3.31之前版本存在安全漏洞，该漏洞源于对权限验证不正确，攻击者利用该漏洞可以提升权限。</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">目前厂商已发布升级补丁以修复漏洞，参考链接：</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf=""><a href="https://github.com/openclaw/openclaw/releases" target="_blank">https://github.com/openclaw/openclaw/releases</a></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">2. Hermes Web UI 路径遍历漏洞（CNNVD-202604-3859）</span></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">Hermes Web UI是一个轻量级、暗色主题的自主智能体Web界面。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">Hermes Web UI存在路径遍历漏洞，该漏洞源于对路径名限制不当，攻击者利用该漏洞可以删除会话目录之外的文件。</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">目前厂商已发布升级补丁以修复漏洞，参考链接：</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf=""><a href="https://github.com/nesquena/hermes-webui/releases" target="_blank">https://github.com/nesquena/hermes-webui/releases</a></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">3. OpenHarness 安全漏洞（CNNVD-202604-3877）</span></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">OpenHarness是一个开源的轻量级智能体开发与运行框架。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">OpenHarness PR #147之前版本存在安全漏洞，该漏洞源于默认配置不安全，攻击者利用该漏洞可以绕过访问控制，从而访问未授权的文件。</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf="">目前厂商已发布升级补丁以修复漏洞，参考链接：</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf=""><a href="https://github.com/ryaneggz/open-harness/releases" target="_blank">https://github.com/ryaneggz/open-harness/releases</a></span></p><div data-mpa-template="t" mpa-paragraph-type="ignored"><div mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;flex: 0 0 auto;height: auto;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: flex;flex-flow: row;text-align: center;justify-content: center;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;width: 45px;vertical-align: top;background-color: rgb(18, 93, 196);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 45px;height: auto;" mpa-from-tpl="t" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img __bg_gif" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 45px !important;visibility: visible !important;" data-imgfileid="503963434" src="https://wechat2rss.xlab.app/img-proxy/?k=68515072&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1JMd8aMOqNkic25xydKvYcCVEsHXvm506icfXiaFep4AfohjraUj3F2jMfg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=02ef136b&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzAxODY1OTM5OQ%3D%3D%26mid%3D2651464856%26idx%3D1%26sn%3D4bcad41d0cb6306a6323b194131f638c">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 30 Apr 2026 13:54:00 +0800</pubDate>
    </item>
    <item>
      <title>人工智能重要安全漏洞的通报-openclaw多个安全漏洞</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzAxODY1OTM5OQ==&amp;mid=2651464856&amp;idx=2&amp;sn=3165c570d0dc6e70839794ceba5b7d48</link>
      <description>根据国家信息安全漏洞库（CNNVD）统计，自2026年4月14日-2026年4月28日，共采集OpenClaw漏洞111个。</description>
      <content:encoded><![CDATA[<p>原创 <span>CNNVD</span> <span>2026-04-30 13:54</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=0fb20866&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FuOZw5Efn8eua0prVXdFHInKWntjC2ExA6qY3U2icN7eYOoKU9jswZqR6wKJfE7xHE4xOhmIqT1TPpQbvHKNuDia9y7K9s51SqvuRibsY9TPTuU%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>根据国家信息安全漏洞库（CNNVD）统计，自2026年4月14日-2026年4月28日，共采集OpenClaw漏洞111个。</p>
  <div data-mpa-template="t" mpa-paragraph-type="ignored"><div mpa-from-tpl="t"><p data-mpa-powered-by="yiban.io" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: center;visibility: visible;" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img __bg_gif" data-ratio="0.1381345926800472" data-type="gif" data-w="847" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: bottom;font-size: var(--articleFontsize);letter-spacing: 0.034em;height: auto !important;visibility: visible !important;width: 677px !important;" data-imgfileid="503963433" src="https://wechat2rss.xlab.app/img-proxy/?k=22c9ee88&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1JjlMnGl5z2XiaAQGZdFulYs0vsE3icB8RUiawPqDSb5lvm8G0drb7iaw7sQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);letter-spacing: 0.544px;text-align: justify;font-size: 16px;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;text-align: center;justify-content: center;display: flex;flex-flow: row;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;transform: rotateZ(19deg);visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;visibility: visible;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 7px;height: auto;visibility: visible;" mpa-from-tpl="t" nodeleaf=""><img data-aistatus="1" alt="图片" class="__bg_gif" data-ratio="4" data-s="300,640" data-type="gif" data-w="36" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 7px !important;visibility: visible !important;" data-imgfileid="503963431" src="https://wechat2rss.xlab.app/img-proxy/?k=e2d135e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1Js3VkKswpUtkoDWibZ1YQl1lIdcctfqePCcSPEdc38SnhJGdqGJUFx9w%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div><div style="-webkit-tap-highlight-color: transparent;padding-right: 8px;padding-left: 8px;outline: 0px;display: inline-block;vertical-align: middle;width: auto;min-width: 5%;flex: 0 0 auto;height: auto;align-self: center;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: justify;color: rgb(18, 93, 196);" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;text-wrap-style: initial;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;" mpa-from-tpl="t"><span leaf="">点击蓝字 关注我们</span></strong></p></div></div><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;transform: rotateZ(199deg);" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 7px;height: auto;" mpa-from-tpl="t" nodeleaf=""><img data-imgfileid="503963432" alt="图片" class="__bg_gif" data-ratio="4" data-s="300,640" data-type="gif" data-w="36" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 7px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=e2d135e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1Js3VkKswpUtkoDWibZ1YQl1lIdcctfqePCcSPEdc38SnhJGdqGJUFx9w%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div><div data-mpa-template="t" mpa-paragraph-type="quote"><div mpa-from-tpl="t" mpa-paragraph-type="quote" data-mp-plugin="96weixin" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;visibility: visible;"><div data-role="outer" mpa-from-tpl="t" data-mp-plugin="96weixin" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;visibility: visible;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 13.5312px;margin-left: 13.5312px;outline: 0px;display: flex;flex-direction: column;border-width: 1px;border-style: solid;border-color: #3f75cf;border-radius: 12px;background-color: #dce8fb;visibility: visible;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;padding: 5px 16px;outline: 0px;align-self: center;background-color: #3f75cf;border-radius: 12px;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;font-size: 15px;letter-spacing: 1.5px;line-height: 15px;color: #ffffff;text-align: center;visibility: visible;"><strong><span style="font-size: 18px;"><span leaf="">漏洞情况</span></span></strong></p></div><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;padding: 10px 20px 15px;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.75em;visibility: visible;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t"><span leaf="">根据国家信息安全漏洞库（CNNVD）统计，自2026年4月14日-2026年4月28日，共采集OpenClaw漏洞111个，其中超危漏洞2个、高危漏洞38个，中危漏洞65个、低危漏洞6个，包含了访问控制错误、代码问题、路径遍历等多个漏洞类型。OpenClaw多个版本受到漏洞影响。目前，OpenClaw官方已经发布了更新修复漏洞，建议用户及时确认是否受到漏洞影响，尽快采取修补措施。</span></p></div></div></div></div></div></div><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">一</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">漏洞介绍</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf="">OpenClaw是一个开源的智能人工助理，可运行在PC或服务器等多种终端设备上，能够直接通过微信、Telegram、Discord、Slack、iMessage等聊天平台接收指令并执行操作。OpenClaw拥有大量用户群体，影响范围涉及多个行业和领域，攻击者利用漏洞可在未授权状态下获取目标敏感数据，提升权限、或远程执行代码。OpenClaw 2026.4.27及之前多个版本均受到漏洞影响。</span></p><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">二</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">漏洞详情</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">自2026年4月14日-2026年4月28日，国家信息安全漏洞库（CNNVD）共采集OpenClaw漏洞111个，其中超危漏洞2个、高危漏洞38个、中危漏洞65个、低危漏洞6个。参考链接：<a href="https://github.com/openclaw/openclaw/releases" target="_blank">https://github.com/openclaw/openclaw/releases</a></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="503981205" data-ratio="12.080610021786493" data-s="300,640" data-w="459" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=08100c2a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuOZw5Efn8esIfOiaGiapsdruAQegt8wnpd6CVG9bZWJsoZx0VG4TAPa0qrK917mOOhBpUI1N4rJ69BoqGLAjdscDSsicljKiaG2AuibxPHdN76RM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">三</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">修复建议</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf="">目前，OpenClaw官方已经发布了更新修复漏洞，建议用户及时确认是否受到漏洞影响，尽快采取修补措施。OpenClaw官方公告地址：</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf=""><a href="https://openclaw.ai/" target="_blank">https://openclaw.ai/</a></span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf="">CNNVD将继续跟踪上述漏洞的相关情况，及时发布相关信息。如有需要，可与CNNVD联系。联系方式: cnnvd@itsec.gov.cn</span></p><div data-mpa-template="t" mpa-paragraph-type="ignored"><div mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;flex: 0 0 auto;height: auto;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: flex;flex-flow: row;text-align: center;justify-content: center;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;width: 45px;vertical-align: top;background-color: rgb(18, 93, 196);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 45px;height: auto;" mpa-from-tpl="t" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img __bg_gif" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 45px !important;visibility: visible !important;" data-imgfileid="503963434" src="https://wechat2rss.xlab.app/img-proxy/?k=68515072&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1JMd8aMOqNkic25xydKvYcCVEsHXvm506icfXiaFep4AfohjraUj3F2jMfg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=c459a2fb&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzAxODY1OTM5OQ%3D%3D%26mid%3D2651464856%26idx%3D2%26sn%3D3165c570d0dc6e70839794ceba5b7d48">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 30 Apr 2026 13:54:00 +0800</pubDate>
    </item>
    <item>
      <title>信息安全漏洞周报（2026年第17期）</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzAxODY1OTM5OQ==&amp;mid=2651464843&amp;idx=1&amp;sn=512286b3a469205e2b09c833ed7f208e</link>
      <description>根据国家信息安全漏洞库（CNNVD）统计，本周（2026年4月20日至2026年4月26日）安全漏洞情况如下</description>
      <content:encoded><![CDATA[<p>原创 <span>CNNVD</span> <span>2026-04-29 13:59</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=fbfb56b1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FuOZw5Efn8esMZY7M1N2cyvLHURhOweU0ia4XvgmQAzKGI7gd5F60yG5jeX26PZ3l3PDITJM5BtiaJib6jzfGNic8RyC9ZjDnibxHZ8vulKnhXGpI%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>根据国家信息安全漏洞库（CNNVD）统计，本周（2026年4月20日至2026年4月26日）安全漏洞情况如下</p>
  <div data-mpa-template="t" mpa-paragraph-type="ignored"><div mpa-from-tpl="t"><p data-mpa-powered-by="yiban.io" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: center;visibility: visible;" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img __bg_gif" data-ratio="0.1381345926800472" data-type="gif" data-w="847" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: bottom;font-size: var(--articleFontsize);letter-spacing: 0.034em;height: auto !important;visibility: visible !important;width: 677px !important;" data-imgfileid="503963433" src="https://wechat2rss.xlab.app/img-proxy/?k=22c9ee88&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1JjlMnGl5z2XiaAQGZdFulYs0vsE3icB8RUiawPqDSb5lvm8G0drb7iaw7sQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);letter-spacing: 0.544px;text-align: justify;font-size: 16px;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;text-align: center;justify-content: center;display: flex;flex-flow: row;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;transform: rotateZ(19deg);visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;visibility: visible;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 7px;height: auto;visibility: visible;" mpa-from-tpl="t" nodeleaf=""><img data-aistatus="1" alt="图片" class="__bg_gif" data-ratio="4" data-s="300,640" data-type="gif" data-w="36" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 7px !important;visibility: visible !important;" data-imgfileid="503963431" src="https://wechat2rss.xlab.app/img-proxy/?k=e2d135e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1Js3VkKswpUtkoDWibZ1YQl1lIdcctfqePCcSPEdc38SnhJGdqGJUFx9w%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div><div style="-webkit-tap-highlight-color: transparent;padding-right: 8px;padding-left: 8px;outline: 0px;display: inline-block;vertical-align: middle;width: auto;min-width: 5%;flex: 0 0 auto;height: auto;align-self: center;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: justify;color: rgb(18, 93, 196);" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;text-wrap-style: initial;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;" mpa-from-tpl="t"><span leaf="">点击蓝字 关注我们</span></strong></p></div></div><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;transform: rotateZ(199deg);" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 7px;height: auto;" mpa-from-tpl="t" nodeleaf=""><img data-imgfileid="503963432" alt="图片" class="__bg_gif" data-ratio="4" data-s="300,640" data-type="gif" data-w="36" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 7px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=e2d135e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1Js3VkKswpUtkoDWibZ1YQl1lIdcctfqePCcSPEdc38SnhJGdqGJUFx9w%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div><div data-mpa-template="t" mpa-paragraph-type="quote"><div mpa-from-tpl="t" mpa-paragraph-type="quote" data-mp-plugin="96weixin" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;visibility: visible;"><div data-role="outer" mpa-from-tpl="t" data-mp-plugin="96weixin" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;visibility: visible;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 13.5312px;margin-left: 13.5312px;outline: 0px;display: flex;flex-direction: column;border-width: 1px;border-style: solid;border-color: #3f75cf;border-radius: 12px;background-color: #dce8fb;visibility: visible;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;padding: 5px 16px;outline: 0px;align-self: center;background-color: #3f75cf;border-radius: 12px;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;font-size: 15px;letter-spacing: 1.5px;line-height: 15px;color: #ffffff;text-align: center;visibility: visible;"><strong><span style="font-size: 18px;"><span leaf="">漏洞情况</span></span></strong></p></div><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;padding: 10px 20px 15px;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.75em;visibility: visible;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t"><span leaf="">根据国家信息安全漏洞库（CNNVD）统计，本周（2026年4月20日至2026年4月26日）安全漏洞情况如下：</span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t"><strong><span leaf="">公开漏洞情况</span></strong></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t"><span leaf="">本周CNNVD采集安全漏洞1447个。</span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t"><strong><span leaf="">接报漏洞情况</span></strong></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t"><span leaf="">本周CNNVD接报漏洞5252个，其中信息技术产品漏洞（通用型漏洞）683个，网络信息系统漏洞（事件型漏洞）46个，漏洞平台推送漏洞4523个。</span></p></div></div></div></div></div></div><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">一</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">公开漏洞情况</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf="">根据国家信息安全漏洞库（CNNVD）统计，本周新增安全漏洞1447个，漏洞新增数量有所上升。从厂商分布来看Linux基金会新增漏洞最多，有255个；从漏洞类型来看，跨站脚本类的安全漏洞占比最大，达到6.15%。新增漏洞中，超危漏洞96个，高危漏洞369个，中危漏洞896个，低危漏洞86个。</span></p><div data-mpa-template="t" mpa-paragraph-type="secondTitle"><div mpa-from-tpl="t" mpa-paragraph-type="secondTitle" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="27325" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div data-align="title" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;padding-right: 10px;padding-left: 10px;outline: 0px;background-color: rgba(0, 72, 191, 0.75);display: inline-block;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;display: flex;justify-content: center;align-items: center;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 10px;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;letter-spacing: 2px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(255, 255, 255);font-size: 16px;" mpa-is-content="t"><span leaf="">（一） 安全漏洞增长数量情况</span></span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">本周CNNVD采集安全漏洞1447个。</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="image" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-ratio="0.584493041749503" data-w="503" style="left: 0px; top: 0px; width: 88.9892%; border-width: 1px; border-style: solid; border-color: rgb(229, 228, 228); pointer-events: initial;" src="https://wechat2rss.xlab.app/img-proxy/?k=a3b46a0b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuOZw5Efn8es53V4bI9t7bz66KWftMSicKLcZW4mwl2N4Hx2Oe4uR8Lv3CNlo37eibfEArHRQWBiaZBWotnHRRSy2sRSQxEV5wvzaGIId23ibo6M%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">图1 近五周漏洞新增数量统计图</span></span></p><div data-mpa-template="t" mpa-paragraph-type="secondTitle"><div mpa-from-tpl="t" mpa-paragraph-type="secondTitle" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="27325" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div data-align="title" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;padding-right: 10px;padding-left: 10px;outline: 0px;background-color: rgba(0, 72, 191, 0.75);display: inline-block;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;display: flex;justify-content: center;align-items: center;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 10px;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;letter-spacing: 2px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(255, 255, 255);font-size: 16px;" mpa-is-content="t"><span leaf="">（二） 安全漏洞分布情况</span></span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">从厂商分布来看，Linux基金会新增漏洞最多，有255个。各厂商漏洞数量分布如表1所示。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表1 新增安全漏洞排名前五厂商统计表</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5822454308093995" data-s="300,640" data-type="png" data-w="383" data-imgfileid="503981185" src="https://wechat2rss.xlab.app/img-proxy/?k=c0e66fef&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuOZw5Efn8evpPJIzx6iaovVN0CT5YH7MiapFpAk3KXVN30v38HZDswtngAfgSCLfhwibwttXdSrEbibXe8EaHo4nUcTaiby5HHnmHN7grLNWTk5A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">本周国内厂商漏洞85个，腾达公司漏洞数量最多，有21个。国内厂商漏洞整体修复率为51.16%。请受影响用户关注厂商修复情况，及时下载补丁修复漏洞。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">从漏洞类型来看，跨站脚本类的安全漏洞占比最大，达到6.15%。漏洞类型统计如表2所示。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表2 漏洞类型统计表</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="2.5755395683453237" data-s="300,640" data-type="png" data-w="417" data-imgfileid="503981186" src="https://wechat2rss.xlab.app/img-proxy/?k=880f2fee&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuOZw5Efn8ethOE6pCzrWtyoXFrcOFSqncNpE9n482M4wwwQYAzCHvlzYyklxpK3sk7T6aPSiaPushZQia2jHql8W9LWgGs0eF1zzUJjicWQicAk%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-paragraph-type="secondTitle"><div mpa-from-tpl="t" mpa-paragraph-type="secondTitle" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="27325" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div data-align="title" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;padding-right: 10px;padding-left: 10px;outline: 0px;background-color: rgba(0, 72, 191, 0.75);display: inline-block;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;display: flex;justify-content: center;align-items: center;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 10px;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;letter-spacing: 2px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(255, 255, 255);font-size: 16px;" mpa-is-content="t"><span leaf="">（三） 安全漏洞危害等级与修复情况</span></span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">本周共发布超危漏洞96个，高危漏洞369个，中危漏洞896个，低危漏洞86个。相应修复率分别为75.00%、75.07%、80.13%和47.67%。根据补丁信息统计，合计1108个漏洞已有修复补丁发布，整体修复率为76.57%。详细情况如表3所示。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表3 漏洞危害等级与修复情况</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5503685503685504" data-s="300,640" data-type="png" data-w="407" data-imgfileid="503981187" src="https://wechat2rss.xlab.app/img-proxy/?k=7b34f3de&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuOZw5Efn8etMFibzRKtE6bWakYwgaiaVPv9LQlia17Kic5h3TUDCgCX4Jib4feMqwepG7iba7ZbEDHfEz4eFEaIIWyY1L4SWVuKYbwskCM67zLt8M%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-paragraph-type="secondTitle"><div mpa-from-tpl="t" mpa-paragraph-type="secondTitle" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="27325" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div data-align="title" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;padding-right: 10px;padding-left: 10px;outline: 0px;background-color: rgba(0, 72, 191, 0.75);display: inline-block;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;display: flex;justify-content: center;align-items: center;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 10px;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;letter-spacing: 2px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(255, 255, 255);font-size: 16px;" mpa-is-content="t"><span leaf="">（四） 本周重要漏洞实例</span></span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">本周重要漏洞实例如表4所示。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表4 本期重要漏洞实例</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.47151898734177217" data-s="300,640" data-type="png" data-w="316" data-imgfileid="503981188" src="https://wechat2rss.xlab.app/img-proxy/?k=d148f4bb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuOZw5Efn8etIzHVX7yVAnsbOmRmLZlzIRp9naJqIy6PSvRnx2jvq0uCibTsjibEp8zY9Lc6ZHc3iagOYg0rQCI8SYoV3LGIb33xzZjXwp6AamE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">1. Microsoft ASP.NET Core 数据伪造问题漏洞（CNNVD-202604-4193）</span></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">Microsoft ASP.NET Core是美国微软（Microsoft）公司的一框跨平台开源框架。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">Microsoft ASP.NET Core存在数据伪造问题漏洞，该漏洞源于对加密签名验证不当，攻击者利用该漏洞可以提升权限。</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">目前厂商已发布升级补丁以修复漏洞，参考链接：</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf=""><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40372" target="_blank">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40372</a></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">2. IBM Total Storage Service Console / TS4500 IMC 操作系统命令注入漏洞（CNNVD-202604-4722）</span></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">IBM Total Storage Service Console / TS4500 IMC是美国国际商业机器（IBM）公司的一个用于存储系统监控、配置与维护管理的服务控制台软件。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">IBM Total Storage Service Console / TS4500 IMC 9.2版本、9.3版本、9.4版本、9.5版本和9.6版本存在操作系统命令注入漏洞，该漏洞源于对用户输入验证不当，攻击者利用该漏洞可以以普通用户权限执行任意命令。</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">目前厂商已发布升级补丁以修复漏洞，参考链接：</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf=""><a href="https://www.ibm.com/support/pages/node/7270127" target="_blank">https://www.ibm.com/support/pages/node/7270127</a></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">3. WordPress plugin wpForo Forum 安全漏洞（CNNVD-202604-3710）</span></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">WordPress和WordPress plugin都是WordPress基金会的产品。WordPress是一套使用PHP语言开发的博客平台，该平台具有在基于PHP和MySQL的服务器上架设个人博客网站的功能。WordPress plugin wpForo Forum是一个应用插件。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">WordPress plugin wpForo Forum 3.0.5版本及之前版本存在安全漏洞，该漏洞源于对文件类型自定义字段的值验证和限制不足，攻击者利用该漏洞可以删除任意文件。</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf="">目前厂商已发布升级补丁以修复漏洞，参考链接：</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf=""><a href="https://wordpress.org/plugins/wpforo" target="_blank">https://wordpress.org/plugins/wpforo</a></span></p><div data-mpa-template="t" mpa-paragraph-type="secondTitle"><div mpa-from-tpl="t" mpa-paragraph-type="secondTitle" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="27325" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div data-align="title" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;padding-right: 10px;padding-left: 10px;outline: 0px;background-color: rgba(0, 72, 191, 0.75);display: inline-block;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;display: flex;justify-content: center;align-items: center;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 10px;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;letter-spacing: 2px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(255, 255, 255);font-size: 16px;" mpa-is-content="t"><span leaf="">（五） 本周重要人工智能漏洞实例</span></span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">本周重要人工智能漏洞实例如表5所示。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表5 本期重要人工智能漏洞实例</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.47151898734177217" data-s="300,640" data-type="png" data-w="316" data-imgfileid="503981189" src="https://wechat2rss.xlab.app/img-proxy/?k=054efdbe&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuOZw5Efn8eucgQolmLOtn83VIAicpGX0ukmKKFdnHaiab9UaIg5fRC30lpy5OJx8b0kticMdYgrh0dfE53Ajycab0X2FXUZ12jSXJ4AoiaZ7lc0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">1. OpenClaw 安全漏洞（CNNVD-202604-4179）</span></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">OpenClaw是一个开源的智能人工助理。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">OpenClaw 2026.3.31之前版本存在安全漏洞，该漏洞源于对权限验证不正确，攻击者利用该漏洞可以提升权限。</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">目前厂商已发布升级补丁以修复漏洞，参考链接：</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf=""><a href="https://github.com/openclaw/openclaw/releases" target="_blank">https://github.com/openclaw/openclaw/releases</a></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">2. Hermes Web UI 路径遍历漏洞（CNNVD-202604-3859）</span></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">Hermes Web UI是一个轻量级、暗色主题的自主智能体Web界面。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">Hermes Web UI存在路径遍历漏洞，该漏洞源于对路径名限制不当，攻击者利用该漏洞可以删除会话目录之外的文件。</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">目前厂商已发布升级补丁以修复漏洞，参考链接：</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf=""><a href="https://github.com/nesquena/hermes-webui/releases" target="_blank">https://github.com/nesquena/hermes-webui/releases</a></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">3. OpenHarness 安全漏洞（CNNVD-202604-3877）</span></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">OpenHarness是一个开源的轻量级智能体开发与运行框架。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">OpenHarness PR #147之前版本存在安全漏洞，该漏洞源于默认配置不安全，攻击者利用该漏洞可以绕过访问控制，从而访问未授权的文件。</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf="">目前厂商已发布升级补丁以修复漏洞，参考链接：</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf=""><a href="https://github.com/ryaneggz/open-harness/releases" target="_blank">https://github.com/ryaneggz/open-harness/releases</a></span></p><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">二</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">漏洞平台推送情况</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">本周CNNVD接收漏洞平台推送漏洞4523个。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表6 本周漏洞平台推送情况</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5917721518987342" data-s="300,640" data-type="png" data-w="316" data-imgfileid="503981190" src="https://wechat2rss.xlab.app/img-proxy/?k=4c0eb8c0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuOZw5Efn8euWmBOfoTibp6tpOSXqPF5cVRdR9xPdHLJ3EJvdVubY2hqZWicb4UhruNbCgUVKm6IbdLPraTRHNd1sKUMTRcqkleqibShaYQE8eE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">三</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">接报漏洞情况</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">本周CNNVD接报漏洞729个，其中信息技术产品漏洞（通用型漏洞）683个，网络信息系统漏洞（事件型漏洞）46个。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表7 本周漏洞报送情况</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="7.344226579520697" data-s="300,640" data-type="png" data-w="459" data-imgfileid="503981191" src="https://wechat2rss.xlab.app/img-proxy/?k=4e64c27c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuOZw5Efn8euwARezUlLNsibIOd9ticjQ6eZxTibLXOXROtkfElKFzwEq2sDARKrNQMuNiaVcZibzFfvQTiaJGjDrNBtlzh6h94s7pqcMEhJueZsK0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">四</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">收录漏洞通报情况</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">本周CNNVD收录漏洞通报200份。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表8 本周漏洞通报情况</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="2.2778675282714054" data-s="300,640" data-type="png" data-w="619" data-imgfileid="503981192" src="https://wechat2rss.xlab.app/img-proxy/?k=6d75ddd8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuOZw5Efn8esBhZhohDOTenR8JtogzNPKoJBvVQg3Ztd4L6upQLxm4pKZJGnJqLFsgam5vNiagshQk4lN9JMgaLlV4fKL1d615PP4t9UJib4J8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-paragraph-type="ignored"><div mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;flex: 0 0 auto;height: auto;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: flex;flex-flow: row;text-align: center;justify-content: center;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;width: 45px;vertical-align: top;background-color: rgb(18, 93, 196);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 45px;height: auto;" mpa-from-tpl="t" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img __bg_gif" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 45px !important;visibility: visible !important;" data-imgfileid="503963434" src="https://wechat2rss.xlab.app/img-proxy/?k=68515072&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1JMd8aMOqNkic25xydKvYcCVEsHXvm506icfXiaFep4AfohjraUj3F2jMfg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=902ad395&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzAxODY1OTM5OQ%3D%3D%26mid%3D2651464843%26idx%3D1%26sn%3D512286b3a469205e2b09c833ed7f208e">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 29 Apr 2026 13:59:00 +0800</pubDate>
    </item>
    <item>
      <title>国家人工智能安全漏洞库启动运行</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzAxODY1OTM5OQ==&amp;mid=2651464829&amp;idx=1&amp;sn=93c1699b772c050d17bde58adb2f965c</link>
      <description>2026年4月23日，国家信息安全漏洞库（CNNVD）在北京举办“国家人工智能安全漏洞库正启动运行”发布会。</description>
      <content:encoded><![CDATA[<p>原创 <span>CNNVD</span> <span>2026-04-24 10:08</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=9f2f6943&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FuOZw5Efn8evRgmiaWHjjYiaPJTwqjuXDwlHlzKueotWeaicNeqDoSYcMIXp0xFtFQQPz2sPjDMLLxlla5xeF3lxGtmOZs1w2FgdGXM1dTY9SVY%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>2026年4月23日，国家信息安全漏洞库（CNNVD）在北京举办“国家人工智能安全漏洞库正启动运行”发布会。</p>
  <div data-mpa-template="t" mpa-paragraph-type="ignored" data-mp-plugin="96weixin"><div mpa-from-tpl="t"><p data-mpa-powered-by="yiban.io" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: center;visibility: visible;" nodeleaf=""><img alt="图片" class="rich_pages wxw-img __bg_gif" data-aistatus="1" data-imgfileid="503963433" data-ratio="0.1381345926800472" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: bottom;font-size: var(--articleFontsize);letter-spacing: 0.034em;height: auto !important;visibility: visible !important;width: 677px !important;" data-type="gif" data-w="847" src="https://wechat2rss.xlab.app/img-proxy/?k=22c9ee88&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1JjlMnGl5z2XiaAQGZdFulYs0vsE3icB8RUiawPqDSb5lvm8G0drb7iaw7sQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);letter-spacing: 0.544px;text-align: justify;font-size: 16px;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;text-align: center;justify-content: center;display: flex;flex-flow: row;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;transform: rotateZ(19deg);visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;visibility: visible;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 7px;height: auto;visibility: visible;" mpa-from-tpl="t" nodeleaf=""><img data-aistatus="1" alt="图片" class="__bg_gif" data-ratio="4" data-s="300,640" data-type="gif" data-w="36" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 7px !important;visibility: visible !important;" data-imgfileid="503963431" src="https://wechat2rss.xlab.app/img-proxy/?k=e2d135e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1Js3VkKswpUtkoDWibZ1YQl1lIdcctfqePCcSPEdc38SnhJGdqGJUFx9w%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div><div style="-webkit-tap-highlight-color: transparent;padding-right: 8px;padding-left: 8px;outline: 0px;display: inline-block;vertical-align: middle;width: auto;min-width: 5%;flex: 0 0 auto;height: auto;align-self: center;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: justify;color: rgb(18, 93, 196);" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;text-wrap-style: initial;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;" mpa-from-tpl="t"><span leaf="">点击蓝字 关注我们</span></strong></p></div></div><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;transform: rotateZ(199deg);" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 7px;height: auto;" mpa-from-tpl="t" nodeleaf=""><img data-aistatus="1" alt="图片" class="__bg_gif" data-ratio="4" data-s="300,640" data-type="gif" data-w="36" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 7px !important;visibility: visible !important;" data-imgfileid="503963432" src="https://wechat2rss.xlab.app/img-proxy/?k=e2d135e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1Js3VkKswpUtkoDWibZ1YQl1lIdcctfqePCcSPEdc38SnhJGdqGJUFx9w%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div><div style="font-size: 16px;color: rgb(62, 62, 62);margin-bottom: 8px;"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 3px 0px;width: 100%;align-self: flex-start;padding: 21px;background-color: #f0f6ff;height: auto;"><div style="text-align: justify;width: 100%;"><p style="white-space: normal;"><span style="color: rgb(18, 93, 196);"><span leaf="">2026年4月23日，国家信息安全漏洞库（CNNVD）在北京举办“国家人工智能安全漏洞库启动运行”发布会。中国工程院吴世忠院士出席并致辞，来自关键基础设施单位、科研院校、人工智能企业、网络安全企业、知名白帽子等200余名嘉宾参加会议，共同见证“国家人工智能安全漏洞库”的启动运行。国家管网集团、北京航空航天大学、华为技术有限公司、北京百度网讯科技有限公司、北京智谱华章科技股份有限公司、北京启明星辰信息安全技术有限公司、知名白帽子代表发表主题演讲，国家信息安全漏洞库负责人任望，对国家人工智能安全漏洞库运行机制与流程进行了介绍，并宣布将筹建人工智能漏洞联盟。</span></span></p><p style="text-align: center;margin-top: 8px;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="503981102" data-ratio="0.6666666666666666" data-s="300,640" data-w="531" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=69a7482c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuOZw5Efn8evEoQa5rXgHKnykicZia35wCnVxz1FplnNCxLIz5KIt71Mbly0f2rgG76iaOkyYMTaU9o8fnWO6vHxKdROe5ia5p6eMrZjkuxaMx0A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="white-space: normal;text-align: center;"><span style="font-size: 14px;"><span leaf="">国家人工智能安全漏洞库启动仪式</span></span></p></div></div></div><div style="font-size: 16px;color: rgb(62, 62, 62);" data-mp-plugin="96weixin"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 10px 0px;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;height: auto;"><div style="justify-content: center;display: flex;flex-flow: row;margin: 0px 0px 5px;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;flex: 0 0 auto;min-width: 5%;height: auto;"><div style="justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 0 0 auto;background-color: #021559;overflow: hidden;padding: 6px 14px;min-width: 5%;height: auto;border-top-right-radius: 21px;border-bottom-left-radius: 21px;"><div style="text-align: justify;color: #ffffff;font-size: 19px;"><p style="white-space: normal;"><strong><span leaf="">01</span></strong></p></div></div></div></div><div style="display: inline-block;vertical-align: bottom;width: auto;background-color: #e8f0f6;align-self: flex-end;border-top-left-radius: 21px;border-bottom-right-radius: 21px;overflow: hidden;padding: 9px 19px;min-width: 5%;flex: 0 0 auto;height: auto;"><div style="text-align: justify;color: #021559;"><p style="white-space: normal;"><strong><span leaf="">院士致辞</span></strong></p></div></div></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 0px 0px 10px;width: 100%;align-self: flex-start;border-style: solid;border-width: 1px;border-color: #3894bc;padding: 3px;"><div style="justify-content: flex-start;display: flex;flex-flow: row;width: 100%;align-self: flex-start;border-style: solid;border-width: 1px;border-color: #3894bc;padding: 20px;"><div style="transform: translate3d(-10px, 0px, 0px);width: 100%;"><div style="text-align: justify;padding-top: 0px;padding-bottom: 0px;width: 100%;padding-left: 20px;"><p><span leaf="">吴世忠院士首先对“国家人工智能安全漏洞库”成立表示祝贺，并结合长期研究与观察分享了三点体会，一是人工智能的健康发展必须始终坚持统筹发展与安全，以高水平安全保障高质量创新发展；二是人工智能安全漏洞管理必须始终坚持与时俱进，主动应对人工智能带来的全新挑战；三是人工智能安全漏洞治理必须始终坚持开拓创新，不断探索适应新形势的治理路径。</span></p><p style="margin-bottom: 8px;"><span leaf="">吴世忠院士充分肯定了国家信息安全漏洞库近二十年来的建设成效，并指出新建国家人工智能安全漏洞库是回应智能化时代安全命题的重大战略举措。面对AI技术带来的漏洞治理新挑战，吴世忠院士提出了四点建议：一是优化组织机制，构建跨域协同的治理合力；二是创新技术体系，发展以模治模的管理手段；三是制定标准规范，引领科学严谨的评估实践；四是推动国际合作，探索开放包容的治理模式。</span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6765217391304348" data-s="300,640" data-type="png" data-w="575" data-imgfileid="503981103" src="https://wechat2rss.xlab.app/img-proxy/?k=9db264f0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuOZw5Efn8etr8ZPUfEUjBfhUAyNY1Tv0BpJ1JenGYAIa1PFISowLcydNtT7CJuObRibV34FM9CgTiaoEjbjBbzPqZSSm49691xaA2nOW90VSA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="white-space: normal;text-align: center;"><span style="font-size: 14px;"><span leaf="">中国工程院院士 吴世忠</span></span></p></div></div></div></div></div><div style="font-size: 16px;color: rgb(62, 62, 62);" data-mp-plugin="96weixin"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 10px 0px;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;height: auto;"><div style="justify-content: center;display: flex;flex-flow: row;margin: 0px 0px 5px;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;flex: 0 0 auto;min-width: 5%;height: auto;"><div style="justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 0 0 auto;background-color: rgb(2, 21, 89);overflow: hidden;padding: 6px 14px;min-width: 5%;height: auto;border-top-right-radius: 21px;border-bottom-left-radius: 21px;"><div style="text-align: justify;color: rgb(255, 255, 255);font-size: 19px;"><p style="white-space: normal;"><strong><span leaf="">02</span></strong></p></div></div></div></div><div style="display: inline-block;vertical-align: bottom;width: auto;background-color: rgb(232, 240, 246);align-self: flex-end;border-top-left-radius: 21px;border-bottom-right-radius: 21px;overflow: hidden;padding: 9px 19px;min-width: 5%;flex: 0 0 auto;height: auto;"><div style="text-align: justify;color: rgb(2, 21, 89);"><p style="white-space: normal;"><strong><span leaf="">专家发言</span></strong></p></div></div></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 0px 0px 10px;width: 100%;align-self: flex-start;border-style: solid;border-width: 1px;border-color: rgb(56, 148, 188);padding: 3px;"><div style="justify-content: flex-start;display: flex;flex-flow: row;width: 100%;align-self: flex-start;border-style: solid;border-width: 1px;border-color: rgb(56, 148, 188);padding: 20px;"><div style="transform: translate3d(-10px, 0px, 0px);width: 100%;"><div style="text-align: justify;padding-top: 0px;padding-bottom: 0px;padding-left: 20px;width: 100%;"><p style="white-space: normal;"><span leaf="">国家管网集团网络安全总监王学力，发表 “锚定AI安全底线，践行央企使命，护航国家管网数字化转型高质量发展” 的演讲。</span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6666666666666666" data-s="300,640" data-type="png" data-w="558" data-imgfileid="503981104" src="https://wechat2rss.xlab.app/img-proxy/?k=2722a4db&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuOZw5Efn8esWHpK8SlibxqkVVMGo4ZgtKtuia5CgYcTouIOtJCLNCVW7R8JTTmAN3tWpzfZ6prlricVnP8cyaowkhTczvV8hPgI7uNrJ5n2rrQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="white-space: normal;text-align: center;"><span style="font-size: 14px;"><span leaf="">国家管网集团网络安全总监 王学力</span></span></p><p><span style=""><span leaf="">北京航空航天大学网络空间安全学院副院长彭浩，发表 “北航网安学院人工智能漏洞挖掘经验分享”的演讲。 </span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6678700361010831" data-s="300,640" data-type="png" data-w="554" data-imgfileid="503981105" src="https://wechat2rss.xlab.app/img-proxy/?k=739ecc1f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuOZw5Efn8evZ9kJ7vjZXMfjVaajvGesSsVNvV4UibbbaKXoQDrCA4KD663FXzpXnzVftfPyR8Ee1t8HYJiaLxaFZCCOT3CEOkicib0YgvZSOriao%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;"><span style="font-size: 14px;"><span leaf="">北京航空航天大学网络空间安全学院副院长 彭浩</span></span></p><p><span style=""><span leaf="">华为技术有限公司中国区首席网络安全与隐私保护官李加赞，发表 “筑牢AI安全底座，共建国家AI漏洞库”的演讲。</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6678700361010831" data-s="300,640" data-type="png" data-w="554" data-imgfileid="503981106" src="https://wechat2rss.xlab.app/img-proxy/?k=2a5dcb8e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuOZw5Efn8euF0uaNesa1C5JjWCVYVtu4goW6qP2ZzDxHNh2PpUicibAISFmiasX1lHAVvyFicl9OtU2xnkfKypC6mg4d2KBm8BmXze7IYw0ibr1E%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;"><span style="font-size: 14px;"><span leaf="">华为技术有限公司中国区首席网络安全与隐私保护官 李加赞</span></span></p><p><span style=""><span leaf="">北京百度网讯科技有限公司百度安全副总裁顾孔希，发表 “范式重构：AI时代漏洞治理的变与不变”的演讲。</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6660649819494585" data-s="300,640" data-type="png" data-w="554" data-imgfileid="503981107" src="https://wechat2rss.xlab.app/img-proxy/?k=27505368&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuOZw5Efn8euD6jhuA2UB985otpppP9JjotTXbwen6WHe6icicuNayic4opbFJDZ4ZcHR4WTWStwfjDSVSrSpgoTXzl1uBqJib1o8l7GNkYFHIGU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;"><span style="font-size: 14px;"><span leaf="">北京百度网讯科技有限公司百度安全副总裁 顾孔希</span></span></p><p><span style=""><span leaf="">北京智谱华章科技股份有限公司副总裁冯小平，发表 “在Z-Day到来之前”的演讲。</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6660649819494585" data-s="300,640" data-type="png" data-w="554" data-imgfileid="503981108" src="https://wechat2rss.xlab.app/img-proxy/?k=2795e1aa&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuOZw5Efn8evNhkiaGPknoMwZS5gPQM65US0PTkQmGzhL6CcKHicGalHN4OqYiaU1iaSdyEwsAoVIUUibZnwx7lBPO0Yb17qEAgtPXDn7V2U65iccU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;"><span style="font-size: 14px;"><span leaf="">北京智谱华章科技股份有限公司副总裁 冯小平</span></span></p><p><span style=""><span leaf="">北京启明星辰信息安全技术有限公司董事长袁捷，发表 “共筑AI安全基座，护航智能时代发展”的演讲。</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6660649819494585" data-s="300,640" data-type="png" data-w="554" data-imgfileid="503981109" src="https://wechat2rss.xlab.app/img-proxy/?k=8b075af5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuOZw5Efn8esuJfreQ7BGyqMJMfJoZp1gSruhaZOSCz4C4CFtejB3ibnVosEwUEvBhatOMGeyE0CsI3YQwns5k3V1C0pdaujH54Ew0Bx04osA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;"><span style="font-size: 14px;"><span leaf="">北京启明星辰信息安全技术有限公司董事长 袁捷</span></span></p><p><span style=""><span leaf="">国家信息安全漏洞库特约专家、漏洞技术研究联盟理事长、深圳安络科技公司董事长谢朝霞，发表 “人工智能的漏洞密码”的演讲。</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6660649819494585" data-s="300,640" data-type="png" data-w="554" data-imgfileid="503981110" src="https://wechat2rss.xlab.app/img-proxy/?k=506686e7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuOZw5Efn8esELayzRUxMAsWMpcg3TWyw6A26kdSbORI4bR2R6jBQBMzR0pta7ydjU94gZ4ZEGhtrJNAocta4etQicbFtyiaaMAibWJQwwv8LCE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;"><span style="font-size: 14px;"><span leaf="">国家信息安全漏洞库特约专家 谢朝霞</span></span></p><p><span style=""><span leaf="">国家信息安全漏洞库负责人任望，对国家人工智能安全漏洞库机制与流程进行介绍，并宣布将筹建AI漏洞联盟。</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6660649819494585" data-s="300,640" data-type="png" data-w="554" data-imgfileid="503981111" src="https://wechat2rss.xlab.app/img-proxy/?k=3a3b88c2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuOZw5Efn8etMz8iaujIhzbrHLVajFQQ2lLITPBI434a49PPHHvUW7jlPMqHTK6kGzPBaxIOnibg0GibuzwQTOhKVPiatX406ohTVYnOMhWpNRkE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;"><span style="font-size: 14px;"><span leaf="">国家信息安全漏洞库负责人 任望</span></span></p></div></div></div></div></div><div style="font-size: 16px;color: rgb(62, 62, 62);" data-mp-plugin="96weixin"><div style="text-align: center;justify-content: center;display: flex;flex-flow: row;margin: 10px 0px;"><div style="display: inline-block;width: auto;vertical-align: top;align-self: flex-start;flex: 0 0 auto;min-width: 5%;height: auto;"><div style="justify-content: center;display: flex;flex-flow: row;margin: 0px 0px 5px;"><div style="display: inline-block;vertical-align: bottom;width: auto;align-self: flex-end;flex: 0 0 auto;min-width: 5%;height: auto;"><div style="justify-content: center;display: flex;flex-flow: row;"><div style="display: inline-block;vertical-align: top;width: auto;align-self: flex-start;flex: 0 0 auto;background-color: rgb(2, 21, 89);overflow: hidden;padding: 6px 14px;min-width: 5%;height: auto;border-top-right-radius: 21px;border-bottom-left-radius: 21px;"><div style="text-align: justify;color: rgb(255, 255, 255);font-size: 19px;"><p style="white-space: normal;"><strong><span leaf="">03</span></strong></p></div></div></div></div><div style="display: inline-block;vertical-align: bottom;width: auto;background-color: rgb(232, 240, 246);align-self: flex-end;border-top-left-radius: 21px;border-bottom-right-radius: 21px;overflow: hidden;padding: 9px 19px;min-width: 5%;flex: 0 0 auto;height: auto;"><div style="text-align: justify;color: rgb(2, 21, 89);"><p style="white-space: normal;"><strong><span leaf="">结语</span></strong></p></div></div></div></div></div><div style="text-align: left;justify-content: flex-start;display: flex;flex-flow: row;margin: 0px 0px 10px;width: 100%;align-self: flex-start;border-style: solid;border-width: 1px;border-color: rgb(56, 148, 188);padding: 3px;"><div style="justify-content: flex-start;display: flex;flex-flow: row;width: 100%;align-self: flex-start;border-style: solid;border-width: 1px;border-color: rgb(56, 148, 188);padding: 20px;"><div style="transform: translate3d(-10px, 0px, 0px);width: 100%;"><div style="text-align: justify;padding-top: 0px;padding-bottom: 0px;padding-left: 20px;width: 100%;"><p style="white-space: normal;"><span leaf="">国家人工智能安全漏洞库启动运行，是贯彻落实《全球人工智能治理倡议》中提出的“坚持以人为本、智能向善”的务实有力行动。未来国家人工智能安全漏洞库将发挥资源汇聚优势，与社会各界紧密协作、携手共进，合力推动人工智能产业健康有序发展，护航数字中国和网络强国建设，共同构建网络空间命运共同体。</span></p></div></div></div></div></div><div data-mpa-template="t" mpa-paragraph-type="ignored" data-mp-plugin="96weixin"><div mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;flex: 0 0 auto;height: auto;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: flex;flex-flow: row;text-align: center;justify-content: center;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;width: 45px;vertical-align: top;background-color: rgb(18, 93, 196);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 45px;height: auto;" mpa-from-tpl="t" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img __bg_gif" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 45px !important;visibility: visible !important;" data-imgfileid="503963434" src="https://wechat2rss.xlab.app/img-proxy/?k=68515072&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1JMd8aMOqNkic25xydKvYcCVEsHXvm506icfXiaFep4AfohjraUj3F2jMfg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=cc89a11a&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzAxODY1OTM5OQ%3D%3D%26mid%3D2651464829%26idx%3D1%26sn%3D93c1699b772c050d17bde58adb2f965c">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 24 Apr 2026 10:08:00 +0800</pubDate>
    </item>
    <item>
      <title>CNNVD关于Oracle多个安全漏洞的通报</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzAxODY1OTM5OQ==&amp;mid=2651464829&amp;idx=2&amp;sn=e8cee73690e2d610c0fa3cb08b4a33e9</link>
      <description>近日，Oracle官方发布了多个安全漏洞的公告，其中Oracle产品本身漏洞110个，影响到Oracle产品的其他厂商漏洞345个。</description>
      <content:encoded><![CDATA[<p>原创 <span>CNNVD</span> <span>2026-04-24 10:08</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=ec851285&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FuOZw5Efn8etnwvFPDyWQI3qsMRSicicPefBAlTp0biayuFib8jKJyWynamB6XicUyHyegOvktDRSQLa1hHouicXWK9Pf6c6ERg4r0KhNo9WvYpDyk%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>近日，Oracle官方发布了多个安全漏洞的公告，其中Oracle产品本身漏洞110个，影响到Oracle产品的其他厂商漏洞345个。</p>
  <div data-mpa-template="t" mpa-paragraph-type="ignored" data-mp-plugin="96weixin" data-pm-slice="0 0 []"><div mpa-from-tpl="t"><p data-mpa-powered-by="yiban.io" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: center;visibility: visible;" nodeleaf=""><img data-imgfileid="503963433" alt="图片" class="rich_pages wxw-img __bg_gif" data-ratio="0.1381345926800472" data-type="gif" data-w="847" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: bottom;font-size: 17px;letter-spacing: 0.034em;height: auto !important;visibility: visible !important;width: 677px !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=22c9ee88&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1JjlMnGl5z2XiaAQGZdFulYs0vsE3icB8RUiawPqDSb5lvm8G0drb7iaw7sQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);letter-spacing: 0.544px;text-align: justify;font-size: 16px;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;text-align: center;justify-content: center;display: flex;flex-flow: row;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;transform: rotateZ(19deg);visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;visibility: visible;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 7px;height: auto;visibility: visible;" mpa-from-tpl="t" nodeleaf=""><img data-imgfileid="503963431" alt="图片" class="__bg_gif" data-ratio="4" data-s="300,640" data-type="gif" data-w="36" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 7px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=e2d135e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1Js3VkKswpUtkoDWibZ1YQl1lIdcctfqePCcSPEdc38SnhJGdqGJUFx9w%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div><div style="-webkit-tap-highlight-color: transparent;padding-right: 8px;padding-left: 8px;outline: 0px;display: inline-block;vertical-align: middle;width: auto;min-width: 5%;flex: 0 0 auto;height: auto;align-self: center;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: justify;color: rgb(18, 93, 196);" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;text-wrap-style: initial;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;" mpa-from-tpl="t"><span leaf="">点击蓝字 关注我们</span></strong></p></div></div><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;transform: rotateZ(199deg);" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 7px;height: auto;" mpa-from-tpl="t" nodeleaf=""><img data-imgfileid="503963432" alt="图片" class="__bg_gif" data-ratio="4" data-s="300,640" data-type="gif" data-w="36" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 7px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=e2d135e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1Js3VkKswpUtkoDWibZ1YQl1lIdcctfqePCcSPEdc38SnhJGdqGJUFx9w%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div><div data-mpa-template="t" mpa-paragraph-type="quote" data-mp-plugin="96weixin"><div mpa-from-tpl="t" mpa-paragraph-type="quote" data-mp-plugin="96weixin" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;visibility: visible;"><div data-role="outer" mpa-from-tpl="t" data-mp-plugin="96weixin" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;visibility: visible;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 13.5312px;margin-left: 13.5312px;outline: 0px;display: flex;flex-direction: column;border-width: 1px;border-style: solid;border-color: #3f75cf;border-radius: 12px;background-color: #dce8fb;visibility: visible;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;padding: 5px 16px;outline: 0px;align-self: center;background-color: #3f75cf;border-radius: 12px;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;font-size: 15px;letter-spacing: 1.5px;line-height: 15px;color: #ffffff;text-align: center;visibility: visible;"><span style="font-size: 18px;"><strong><span leaf="">漏洞情况</span></strong></span></p></div><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;padding: 10px 20px 15px;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.75em;visibility: visible;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t"><span leaf="">近日，Oracle官方发布了多个安全漏洞的公告，其中Oracle产品本身漏洞110个，影响到Oracle产品的其他厂商漏洞345个。Oracle Mysql、Oracle Identity Manager Connector、Oracle PeopleSoft Enterprise HCM Shared Components、Oracle PeopleSoft Enterprise FIN Maintenance等多个产品和系统受漏洞影响。目前，Oracle官方已经发布了漏洞修复补丁，建议用户及时确认是否受到漏洞影响，尽快采取修补措施。</span></p></div></div></div></div></div></div><div data-mpa-template="t" mpa-paragraph-type="title" data-mp-plugin="96weixin"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">一</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">漏洞介绍</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf="">2026年4月21日，Oracle发布了2026年4月份安全更新，共455个漏洞的补丁程序，CNNVD对这些漏洞进行了收录。本次更新主要涵盖了Oracle Mysql、Oracle Identity Manager Connector、Oracle PeopleSoft Enterprise HCM Shared Components、Oracle PeopleSoft Enterprise FIN Maintenance、Oracle Financial Services Transaction Filtering、Oracle MySQL Shell等。CNNVD对其危害等级进行了评价，其中超危漏洞38个，高危漏洞160个，中危漏洞213个，低危漏洞44个。Oracle多个产品和系统版本受漏洞影响，具体影响范围可访问Oracle官方网站查询：</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf=""><a href="https://www.oracle.com/security-alerts/cpuapr2026.html" target="_blank">https://www.oracle.com/security-alerts/cpuapr2026.html</a></span></p><div data-mpa-template="t" mpa-paragraph-type="title" data-mp-plugin="96weixin"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">二</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">漏洞详情</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" data-mp-plugin="96weixin"><span leaf="">此次更新共455个漏洞的补丁程序，包括102个新增漏洞的补丁程序、8个更新漏洞的补丁程序和345个影响Oracle产品的其他厂商漏洞的补丁程序。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" data-mp-plugin="96weixin"><span leaf="">此次更新共包括102个新增漏洞的补丁程序，其中超危漏洞5个，高危漏洞21个，中危漏洞67个，低危漏洞9个。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="503980899" class="rich_pages wxw-img" data-ratio="14.706967213114755" data-s="300,640" data-type="png" data-w="488" src="https://wechat2rss.xlab.app/img-proxy/?k=65138648&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuOZw5Efn8euSKGRaty05RicTORr2Q9Mb7DRibIrlcKKjBEmt9J7wPATku3Q6buiaKUHicIykQRsDo4DQkZarQV6kVFYmiauxwClhfjQzXdlxStFE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" data-mp-plugin="96weixin"><span leaf="">此次更新共包括8个更新漏洞的补丁程序，其中超危漏洞2个，高危漏洞3个，中危漏洞2个，低危漏洞1个。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="503980900" class="rich_pages wxw-img" data-ratio="1.0512295081967213" data-s="300,640" data-type="png" data-w="488" src="https://wechat2rss.xlab.app/img-proxy/?k=eaf1e193&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuOZw5Efn8esgRaaakPmAjdyRX5sVBhjQLvuvBoXvDibmzbCEKFppLfkjSiapnabPSeN1sfOhKqgabom0EpChplyicaficmoyp3bzduNia0IKrGOw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" data-mp-plugin="96weixin"><span leaf="">此次更新共包括345个影响Oracle产品的其他厂商漏洞的补丁程序，其中超危漏洞31个，高危漏洞136个，中危漏洞144个，低危漏洞34个。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="503980902" class="rich_pages wxw-img" data-ratio="32.70209059233449" data-s="300,640" data-type="png" data-w="574" src="https://wechat2rss.xlab.app/img-proxy/?k=529acedf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuOZw5Efn8etMsxTxhxDj6PLmFwc4sl9GKmrRNEYcmW4lItmLsyhhPCqIOTiabjdZPnhCV6LexyEeXNCcAMdaZGe56H0F6jmWTGddvicuSHjwc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-paragraph-type="title" data-mp-plugin="96weixin"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">三</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">修复建议</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf="">目前，Oracle官方已经发布补丁修复了上述漏洞，建议用户及时确认漏洞影响，尽快采取修补措施。Oracle官方补丁下载地址：</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" data-mp-plugin="96weixin"><span leaf=""><a href="https://www.oracle.com/security-alerts/cpuapr2026.html" target="_blank">https://www.oracle.com/security-alerts/cpuapr2026.html</a></span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf="">CNNVD将继续跟踪上述漏洞的相关情况，及时发布相关信息。如有需要，可与CNNVD联系。联系方式: cnnvd@itsec.gov.cn</span></p><div data-mpa-template="t" mpa-paragraph-type="ignored" data-mp-plugin="96weixin"><div mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;flex: 0 0 auto;height: auto;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: flex;flex-flow: row;text-align: center;justify-content: center;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;width: 45px;vertical-align: top;background-color: rgb(18, 93, 196);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 45px;height: auto;" mpa-from-tpl="t" nodeleaf=""><img data-imgfileid="503963434" alt="图片" class="rich_pages wxw-img __bg_gif" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 45px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=68515072&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1JMd8aMOqNkic25xydKvYcCVEsHXvm506icfXiaFep4AfohjraUj3F2jMfg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=595882eb&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzAxODY1OTM5OQ%3D%3D%26mid%3D2651464829%26idx%3D2%26sn%3De8cee73690e2d610c0fa3cb08b4a33e9">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 24 Apr 2026 10:08:00 +0800</pubDate>
    </item>
    <item>
      <title>信息安全漏洞周报（2026年第16期）</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzAxODY1OTM5OQ==&amp;mid=2651464545&amp;idx=1&amp;sn=9a782e8f5c7644c20b373a07f90a91ab</link>
      <description>根据国家信息安全漏洞库（CNNVD）统计，本周（2026年4月13日至2026年4月19日）安全漏洞情况如下</description>
      <content:encoded><![CDATA[<p>原创 <span>CNNVD</span> <span>2026-04-22 10:50</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=03bb5613&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FuOZw5Efn8evooHtXg51l16YCXw4icMdiapAcicPz3c9yutKnYyoqlVEts4drsM32FbET3XqOqJSAoebNvywThFZzDF4xxAxSICnD850eSVWNpE%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>根据国家信息安全漏洞库（CNNVD）统计，本周（2026年4月13日至2026年4月19日）安全漏洞情况如下</p>
  <div data-mpa-template="t" mpa-paragraph-type="ignored"><div mpa-from-tpl="t"><p data-mpa-powered-by="yiban.io" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: center;visibility: visible;" nodeleaf=""><img alt="图片" class="rich_pages wxw-img __bg_gif" data-aistatus="1" data-imgfileid="503963433" data-ratio="0.1381345926800472" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: bottom;font-size: var(--articleFontsize);letter-spacing: 0.034em;height: auto !important;visibility: visible !important;width: 677px !important;" data-type="gif" data-w="847" src="https://wechat2rss.xlab.app/img-proxy/?k=22c9ee88&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1JjlMnGl5z2XiaAQGZdFulYs0vsE3icB8RUiawPqDSb5lvm8G0drb7iaw7sQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);letter-spacing: 0.544px;text-align: justify;font-size: 16px;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;text-align: center;justify-content: center;display: flex;flex-flow: row;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;transform: rotateZ(19deg);visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;visibility: visible;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 7px;height: auto;visibility: visible;" mpa-from-tpl="t" nodeleaf=""><img data-aistatus="1" alt="图片" class="__bg_gif" data-ratio="4" data-s="300,640" data-type="gif" data-w="36" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 7px !important;visibility: visible !important;" data-imgfileid="503963431" src="https://wechat2rss.xlab.app/img-proxy/?k=e2d135e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1Js3VkKswpUtkoDWibZ1YQl1lIdcctfqePCcSPEdc38SnhJGdqGJUFx9w%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div><div style="-webkit-tap-highlight-color: transparent;padding-right: 8px;padding-left: 8px;outline: 0px;display: inline-block;vertical-align: middle;width: auto;min-width: 5%;flex: 0 0 auto;height: auto;align-self: center;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: justify;color: rgb(18, 93, 196);" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;text-wrap-style: initial;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;" mpa-from-tpl="t"><span leaf="">点击蓝字 关注我们</span></strong></p></div></div><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;transform: rotateZ(199deg);" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 7px;height: auto;" mpa-from-tpl="t" nodeleaf=""><img data-imgfileid="503963432" alt="图片" class="__bg_gif" data-ratio="4" data-s="300,640" data-type="gif" data-w="36" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 7px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=e2d135e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1Js3VkKswpUtkoDWibZ1YQl1lIdcctfqePCcSPEdc38SnhJGdqGJUFx9w%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div><div data-mpa-template="t" mpa-paragraph-type="quote"><div mpa-from-tpl="t" mpa-paragraph-type="quote" data-mp-plugin="96weixin" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;visibility: visible;"><div data-role="outer" mpa-from-tpl="t" data-mp-plugin="96weixin" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;visibility: visible;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 13.5312px;margin-left: 13.5312px;outline: 0px;display: flex;flex-direction: column;border-width: 1px;border-style: solid;border-color: #3f75cf;border-radius: 12px;background-color: #dce8fb;visibility: visible;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;padding: 5px 16px;outline: 0px;align-self: center;background-color: #3f75cf;border-radius: 12px;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;font-size: 15px;letter-spacing: 1.5px;line-height: 15px;color: #ffffff;text-align: center;visibility: visible;"><span style="font-size: 18px;"><strong><span leaf="">漏洞情况</span></strong></span></p></div><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;padding: 10px 20px 15px;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.75em;visibility: visible;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t"><span leaf="">根据国家信息安全漏洞库（CNNVD）统计，本周（2026年4月13日至2026年4月19日）安全漏洞情况如下：</span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t"><strong><span leaf="">公开漏洞情况</span></strong></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t"><span leaf="">本周CNNVD采集安全漏洞1174个。</span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t"><strong><span leaf="">接报漏洞情况</span></strong></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t"><span leaf="">本周CNNVD接报漏洞5761个，其中信息技术产品漏洞（通用型漏洞）741个，网络信息系统漏洞（事件型漏洞）24个，漏洞平台推送漏洞4996个。</span></p></div></div></div></div></div></div><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">一</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">公开漏洞情况</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf="">根据国家信息安全漏洞库（CNNVD）统计，本周新增安全漏洞1174个，漏洞新增数量有所下降。从厂商分布来看微软公司新增漏洞最多，有165个；从漏洞类型来看，资源管理错误类的安全漏洞占比最大，达到5.96%。新增漏洞中，超危漏洞75个，高危漏洞405个，中危漏洞654个，低危漏洞40个。</span></p><div data-mpa-template="t" mpa-paragraph-type="secondTitle"><div mpa-from-tpl="t" mpa-paragraph-type="secondTitle" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="27325" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div data-align="title" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;padding-right: 10px;padding-left: 10px;outline: 0px;background-color: rgba(0, 72, 191, 0.75);display: inline-block;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;display: flex;justify-content: center;align-items: center;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 10px;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;letter-spacing: 2px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(255, 255, 255);font-size: 16px;" mpa-is-content="t"><span leaf="">（一） 安全漏洞增长数量情况</span></span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">本周CNNVD采集安全漏洞1174个。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="image" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-ratio="0.5876494023904383" style="left: 0px;top: 0px;width: 90.6137%;height: 295px;border-width: 1px;border-style: solid;border-color: rgb(229, 228, 228);" data-w="502" src="https://wechat2rss.xlab.app/img-proxy/?k=a4660a34&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FuOZw5Efn8esfVvxCs6r8es60L7tz05HNl84yHTu9dVyia0KZiceMH7Pt0nBdp9aVwRrnIDNiahA1yPSywEgWwgAOs7hqwxWJzicYQ9aicVwehjEw%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg"/></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-size: 14px;"><span leaf="">图1 近五周漏洞新增数量统计图</span></span></p><div data-mpa-template="t" mpa-paragraph-type="secondTitle"><div mpa-from-tpl="t" mpa-paragraph-type="secondTitle" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="27325" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div data-align="title" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;padding-right: 10px;padding-left: 10px;outline: 0px;background-color: rgba(0, 72, 191, 0.75);display: inline-block;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;display: flex;justify-content: center;align-items: center;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 10px;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;letter-spacing: 2px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(255, 255, 255);font-size: 16px;" mpa-is-content="t"><span leaf="">（二） 安全漏洞分布情况</span></span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">从厂商分布来看，微软公司新增漏洞最多，有165个。各厂商漏洞数量分布如表1所示。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表1 新增安全漏洞排名前五厂商统计表</span></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="503980887" data-ratio="0.5962566844919787" data-s="300,640" data-w="374" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=5512101a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuOZw5Efn8etKjBk5We7ocwPiaWumGl6xWMDl0Bm23lvs7iaia4SxRWURZ4WgDswSU2DFHGPicdfeV7KMG9KINRVX96m2BRuCHOBn9PV07dML2Lo%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">本周国内厂商漏洞68个，华为公司漏洞数量最多，有20个。国内厂商漏洞整体修复率为50.00%。请受影响用户关注厂商修复情况，及时下载补丁修复漏洞。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">从漏洞类型来看，资源管理错误类的安全漏洞占比最大，达到5.96%。漏洞类型统计如表2所示。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表2 漏洞类型统计表</span></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="503980888" data-ratio="2.27807486631016" data-s="300,640" data-w="374" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=a8254616&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuOZw5Efn8esSSNeuBJVmY3Xw82MXPggt8YOsqheRm9goWfefU3a6neFkjOp8kqmUZn3o8qe3grfl5PHT5NXRsQhsPDPz7kTE9wlxPXAhYqE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-paragraph-type="secondTitle"><div mpa-from-tpl="t" mpa-paragraph-type="secondTitle" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="27325" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div data-align="title" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;padding-right: 10px;padding-left: 10px;outline: 0px;background-color: rgba(0, 72, 191, 0.75);display: inline-block;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;display: flex;justify-content: center;align-items: center;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 10px;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;letter-spacing: 2px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(255, 255, 255);font-size: 16px;" mpa-is-content="t"><span leaf="">（三） 安全漏洞危害等级与修复情况</span></span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">本周共发布超危漏洞75个，高危漏洞405个，中危漏洞654个，低危漏洞40个。相应修复率分别为68.00%、84.20%、72.78%和77.50%。根据补丁信息统计，合计899个漏洞已有修复补丁发布，整体修复率为76.58%。详细情况如表3所示。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表3 漏洞危害等级与修复情况</span></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="503980889" data-ratio="0.5614035087719298" data-s="300,640" data-w="399" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=d9baf392&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuOZw5Efn8evsqleHm0ghWfp5eTSxZZUyqJiaLwRo3EhfVeCoIUAViay5UgWUSugKfnIicR6oxJsP63ZARRRjrskpTxicRVicoXiaicFczyjy6mVueY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-paragraph-type="secondTitle"><div mpa-from-tpl="t" mpa-paragraph-type="secondTitle" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="27325" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div data-align="title" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;padding-right: 10px;padding-left: 10px;outline: 0px;background-color: rgba(0, 72, 191, 0.75);display: inline-block;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;display: flex;justify-content: center;align-items: center;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 10px;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;letter-spacing: 2px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(255, 255, 255);font-size: 16px;" mpa-is-content="t"><span leaf="">（四） 本周重要漏洞实例</span></span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">本周重要漏洞实例如表4所示。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表4 本期重要漏洞实例</span></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="503980890" data-ratio="0.476038338658147" data-s="300,640" data-w="313" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=779f81f3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuOZw5Efn8evKtubtSg1GUq3VPdndfeASNf0sKvyJaIp57Xgjqg3EWYgkzwpbVrycpve4sxdKRNqgER46LicKr0StznS8ckWQYdEV3XkkUHPs%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">1. Microsoft Windows IKE Extension 资源管理错误漏洞（CNNVD-202604-2814）</span></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">Microsoft Windows IKE Extension是美国微软（Microsoft）公司的网络密钥交换扩展。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">Microsoft Windows IKE Extension存在资源管理错误漏洞，该漏洞源于内存双重释放，攻击者利用该漏洞可以远程执行代码。以下产品和版本受到影响：Windows 11 Version 23H2 for ARM64-based Systems,Windows 11 Version 23H2 for x64-based Systems,Windows Server 2022, 23H2 Edition (Server Core installation),Windows 11 Version 24H2 for ARM64-based Systems,Windows 11 Version 24H2 for x64-based Systems,Windows Server 2025,Windows 11 version 26H1 for x64-based Systems,Windows 11 Version 26H1 for ARM64-based Systems,Windows 10 Version 1607 for 32-bit Systems,Windows 10 Version 1607 for x64-based Systems,Windows Server 2016,Windows Server 2016 (Server Core installation),Windows Server 2022 (Server Core installation),Windows 10 Version 21H2 for 32-bit Systems,Windows 10 Version 21H2 for ARM64-based Systems,Windows 10 Version 21H2 for x64-based Systems,Windows 10 Version 22H2 for x64-based Systems,Windows 10 Version 22H2 for ARM64-based Systems,Windows 10 Version 22H2 for 32-bit Systems,Windows Server 2025 (Server Core installation),Windows 11 Version 25H2 for ARM systems,Windows 11 Version 25H2 for x64-based Systems,Windows 10 Version 1809 for 32-bit Systems,Windows 10 Version 1809 for x64-based Systems,Windows Server 2019,Windows Server 2019 (Server Core installation),Windows Server 2022。</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">目前厂商已发布升级补丁以修复漏洞，参考链接：</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf=""><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33824" target="_blank">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33824</a></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">2. Adobe ColdFusion 输入验证错误漏洞（CNNVD-202604-2760）</span></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">Adobe ColdFusion是美国奥多比（Adobe）公司的一套快速应用程序开发平台，该平台包括集成开发环境和脚本语言。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">Adobe ColdFusion 2023.18版本和2025.6及之前版本存在输入验证错误漏洞，该漏洞源于对用户的输入验证不当，攻击者利用该漏洞可以执行任意代码。</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">目前厂商已发布升级补丁以修复漏洞，参考链接：</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf=""><a href="https://helpx.adobe.com/security/products/coldfusion/apsb26-38.html" target="_blank">https://helpx.adobe.com/security/products/coldfusion/apsb26-38.html</a></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">3. Google Chrome 安全漏洞（CNNVD-202604-3115）</span></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">Google Chrome是美国谷歌（Google）公司的一款Web浏览器。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">Google Chrome 147.0.7727.101之前版本存在安全漏洞，该漏洞源于内存释放后重用，攻击者利用该漏洞可以通过特制的HTML页面在沙箱内执行任意代码。</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf="">目前厂商已发布升级补丁以修复漏洞，参考链接：</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf=""><a href="https://www.google.com/chrome/" target="_blank">https://www.google.com/chrome/</a></span></p><div data-mpa-template="t" mpa-paragraph-type="secondTitle"><div mpa-from-tpl="t" mpa-paragraph-type="secondTitle" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="27325" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div data-align="title" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;padding-right: 10px;padding-left: 10px;outline: 0px;background-color: rgba(0, 72, 191, 0.75);display: inline-block;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;display: flex;justify-content: center;align-items: center;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 10px;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;letter-spacing: 2px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(255, 255, 255);font-size: 16px;" mpa-is-content="t"><span leaf="">（五） 本周重要人工智能漏洞实例</span></span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">本周重要人工智能漏洞实例如表5所示。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表5 本期重要人工智能漏洞实例</span></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="503980891" data-ratio="0.476038338658147" data-s="300,640" data-w="313" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=39e07692&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuOZw5Efn8etW7ia9gtw2NDvjhskW93aLFjEJ8CFZZe3ebnvqhlSMfnJ7vibiazhS0rwCIB0PmUsiaYXjHe5H2zNnkzTG0o2WZREaZkYO51icEwu0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">1. PraisonAI 代码注入漏洞（CNNVD-202604-3068）</span></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">PraisonAI是一个低代码多智能体协作框架。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">PraisonAI 4.5.139之前版本存在代码注入漏洞，该漏洞源于工作流引擎会处理不受信任的YAML文件，攻击者利用该漏洞可以执行任意命令和代码。</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">目前厂商已发布升级补丁以修复漏洞，参考链接：</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf=""><a href="https://github.com/MervinPraison/PraisonAI/releases" target="_blank">https://github.com/MervinPraison/PraisonAI/releases</a></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">2. Claude Code 安全漏洞（CNNVD-202604-3565）</span></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">Claude Code是一个开源的终端原生AI编程工具。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">Claude Code 2.1.75之前版本存在安全漏洞，该漏洞源于未验证目录所有权或访问权限，攻击者利用该漏洞可以提升权限。</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">目前厂商已发布升级补丁以修复漏洞，参考链接：</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf=""><a href="https://claude.com/" target="_blank">https://claude.com/</a></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">3. OpenHarness 安全漏洞（CNNVD-202604-3527）</span></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">OpenHarness是一个开源的轻量级智能体开发与运行框架。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">OpenHarness存在安全漏洞，该漏洞源于在权限检查器中路径规范化不正确，攻击者利用该漏洞可以读取敏感文件。</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">目前厂商已发布升级补丁以修复漏洞，参考链接：</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf=""><a href="https://github.com/HKUDS/OpenHarness/releases" target="_blank">https://github.com/HKUDS/OpenHarness/releases</a></span></p><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">二</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">漏洞平台推送情况</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">本周CNNVD接收漏洞平台推送漏洞4996个。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表6 本周漏洞平台推送情况</span></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="503980892" data-ratio="0.597444089456869" data-s="300,640" data-w="313" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=9f542958&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuOZw5Efn8euq6Cj8HsYUsBHKD4Tb2iaVUX7bekZjZTmwibAy7iar48HoKZXkecAMK92e0LLibmibPpwtBL7MuGrjLHzv0k9k7SeakvcGuPYUdH2M%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">三</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">接报漏洞情况</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">本周CNNVD接报漏洞765个，其中信息技术产品漏洞（通用型漏洞）741个，网络信息系统漏洞（事件型漏洞）24个。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表7 本周漏洞报送情况</span></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="503980893" data-ratio="6.2428884026258205" data-s="300,640" data-w="457" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=9b6879bf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuOZw5Efn8evibibOWF6wnEkArCiab1VPzGGVGPYU0HSqc0s819Bic8YTzx0xj0Z8JxQWLGPnlduvBSictjEAfuvVDDPJlRxtfTdiaghxJribu2azHg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">四</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">收录漏洞通报情况</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">本周CNNVD收录漏洞通报192份。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表8 本周漏洞通报情况</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="3.3282275711159737" data-s="300,640" data-type="png" data-w="457" data-imgfileid="503980894" src="https://wechat2rss.xlab.app/img-proxy/?k=32b163ff&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuOZw5Efn8et538ibve6bYkAHcNgM0An9PzMAjb6fAv2vEGFA5icyIGeNLX5ibUY9Os0QBGojLAnnqvH49icXdW4ZTeXXTPm9sfIuq3fz7q81oBY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-paragraph-type="ignored"><div mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;flex: 0 0 auto;height: auto;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: flex;flex-flow: row;text-align: center;justify-content: center;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;width: 45px;vertical-align: top;background-color: rgb(18, 93, 196);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 45px;height: auto;" mpa-from-tpl="t" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img __bg_gif" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 45px !important;visibility: visible !important;" data-imgfileid="503963434" src="https://wechat2rss.xlab.app/img-proxy/?k=68515072&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1JMd8aMOqNkic25xydKvYcCVEsHXvm506icfXiaFep4AfohjraUj3F2jMfg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=f0cca9c0&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzAxODY1OTM5OQ%3D%3D%26mid%3D2651464545%26idx%3D1%26sn%3D9a782e8f5c7644c20b373a07f90a91ab">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 22 Apr 2026 10:50:00 +0800</pubDate>
    </item>
    <item>
      <title>人工智能重要漏洞通报（2026年第五期）</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzAxODY1OTM5OQ==&amp;mid=2651464532&amp;idx=1&amp;sn=780df60bd7c8d777e4a4903a8d1268e2</link>
      <description>根据国家信息安全漏洞库（CNNVD）统计，近期（2026年3月31日至2026年4月15日）共采集重要人工智能漏洞320个。</description>
      <content:encoded><![CDATA[<p>原创 <span>CNNVD</span> <span>2026-04-17 17:02</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=ead33577&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FuOZw5Efn8evXaiavkoTcfapua2mvRRqeFW5EiaMhrUwH8gYzeXgB2Dw5u4kJrYdjHCD1WWuBOxKVE0IemY2Zl6hCaPdffn8rCrOIGr2E9wxUQ%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>根据国家信息安全漏洞库（CNNVD）统计，近期（2026年3月31日至2026年4月15日）共采集重要人工智能漏洞320个。</p>
  <div data-mpa-template="t" mpa-paragraph-type="ignored" data-mp-plugin="96weixin"><div mpa-from-tpl="t"><p data-mpa-powered-by="yiban.io" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: center;visibility: visible;" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img __bg_gif" data-ratio="0.1381345926800472" data-type="gif" data-w="847" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: bottom;font-size: var(--articleFontsize);letter-spacing: 0.034em;height: auto !important;visibility: visible !important;width: 677px !important;" data-imgfileid="503963433" src="https://wechat2rss.xlab.app/img-proxy/?k=22c9ee88&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1JjlMnGl5z2XiaAQGZdFulYs0vsE3icB8RUiawPqDSb5lvm8G0drb7iaw7sQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);letter-spacing: 0.544px;text-align: justify;font-size: 16px;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;text-align: center;justify-content: center;display: flex;flex-flow: row;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;transform: rotateZ(19deg);visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;visibility: visible;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 7px;height: auto;visibility: visible;" mpa-from-tpl="t" nodeleaf=""><img data-aistatus="1" alt="图片" class="__bg_gif" data-ratio="4" data-s="300,640" data-type="gif" data-w="36" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 7px !important;visibility: visible !important;" data-imgfileid="503963431" src="https://wechat2rss.xlab.app/img-proxy/?k=e2d135e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1Js3VkKswpUtkoDWibZ1YQl1lIdcctfqePCcSPEdc38SnhJGdqGJUFx9w%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div><div style="-webkit-tap-highlight-color: transparent;padding-right: 8px;padding-left: 8px;outline: 0px;display: inline-block;vertical-align: middle;width: auto;min-width: 5%;flex: 0 0 auto;height: auto;align-self: center;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: justify;color: rgb(18, 93, 196);" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;text-wrap-style: initial;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;" mpa-from-tpl="t"><span leaf="">点击蓝字 关注我们</span></strong></p></div></div><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;transform: rotateZ(199deg);" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 7px;height: auto;" mpa-from-tpl="t" nodeleaf=""><img data-imgfileid="503963432" alt="图片" class="__bg_gif" data-ratio="4" data-s="300,640" data-type="gif" data-w="36" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 7px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=e2d135e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1Js3VkKswpUtkoDWibZ1YQl1lIdcctfqePCcSPEdc38SnhJGdqGJUFx9w%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div><div data-mpa-template="t" mpa-paragraph-type="quote" data-mp-plugin="96weixin"><div mpa-from-tpl="t" mpa-paragraph-type="quote" data-mp-plugin="96weixin" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;visibility: visible;"><div data-role="outer" mpa-from-tpl="t" data-mp-plugin="96weixin" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;visibility: visible;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 13.5312px;margin-left: 13.5312px;outline: 0px;display: flex;flex-direction: column;border-width: 1px;border-style: solid;border-color: #3f75cf;border-radius: 12px;background-color: #dce8fb;visibility: visible;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;padding: 5px 16px;outline: 0px;align-self: center;background-color: #3f75cf;border-radius: 12px;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;font-size: 15px;letter-spacing: 1.5px;line-height: 15px;color: #ffffff;text-align: center;visibility: visible;"><span style="font-size: 18px;"><strong><span leaf="">漏洞情况</span></strong></span></p></div><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;padding: 10px 20px 15px;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.75em;visibility: visible;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t"><span leaf="">根据国家信息安全漏洞库（CNNVD）统计，近期（2026年3月31日至2026年4月15日）共采集重要人工智能漏洞320个，CNNVD对这些漏洞进行了收录。本周人工智能类漏洞主要涵盖了OpenClaw、Ollama、MLflow等多个厂商（项目）。CNNVD对其危害等级进行了评价，其中超危漏洞35个，高危漏洞107个，中危漏洞178个。</span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t"><span leaf="">鉴于近期人工智能领域漏洞呈爆发式增长态势，相关系统安全风险急剧攀升，请相关单位及个人尽快开展漏洞消控工作。</span></p></div></div></div></div></div></div><div data-mpa-template="t" mpa-paragraph-type="title" data-mp-plugin="96weixin"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">一</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">人工智能漏洞增长数量情况</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" data-mp-plugin="96weixin"><span leaf="">近期CNNVD采集人工智能漏洞320个。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="image" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.592741935483871" data-w="496" style="left: 0px;top: 0px;width: 86.1111%;height: 294px;border-width: 1px;border-style: solid;border-color: rgb(229, 228, 228);" src="https://wechat2rss.xlab.app/img-proxy/?k=cdc27881&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FuOZw5Efn8esKezicsA9VWRx8HJ557icc3pGzicHeW6ajNJiatApiasq2WCRUicIJMpnqN9meWo2n674EH9LWCSruZlJ0LicoHBXXLDzw0DgDm7icMz0%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg"/></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">图1 近五周漏洞新增数量统计图</span></span></p><div data-mpa-template="t" mpa-paragraph-type="title" data-mp-plugin="96weixin"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">二</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">人工智能漏洞具体情况</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" data-mp-plugin="96weixin"><span leaf="">近期共采集人工智能漏洞320个，包括OpenClaw、Ollama、MLflow等多个厂商（项目）的漏洞。其中超危漏洞35个，高危漏洞107个，中危漏洞178个。具体如表1所示：</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表1 人工智能漏洞列表</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="33.781132075471696" data-s="300,640" data-type="png" data-w="530" data-imgfileid="503980880" src="https://wechat2rss.xlab.app/img-proxy/?k=7dded50a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuOZw5Efn8etkSaMGEI1ibYfvH8hsB1clmpOiars6cgFRmGOO7VOuHOlhtyicMdOibRC4icE4RfLaS84AaEpT1MuPYWjHPhFfMTFbNNtzFP8qAHicM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-paragraph-type="title" data-mp-plugin="96weixin"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">三</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">重要人工智能漏洞实例</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" data-mp-plugin="96weixin"><span leaf="">近期重要漏洞实例如表2所示。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表2 本期重要漏洞实例</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4408284023668639" data-s="300,640" data-type="png" data-w="338" data-imgfileid="503980881" src="https://wechat2rss.xlab.app/img-proxy/?k=f04fbd5b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuOZw5Efn8eutJAI5jc1snnkZ5OHYjSKAlu4hzAdA3InF3l5m5voib6VgFtiagZNWQnMSy8exVRsoYLhpd01LQQxZEfSomAHAp21dgjMFsrJmM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" data-mp-plugin="96weixin"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">1. OpenClaw 操作系统命令注入漏洞（CNNVD-202603-6234）</span></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" data-mp-plugin="96weixin"><span leaf="">OpenClaw是一个开源的智能人工助理。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" data-mp-plugin="96weixin"><span leaf="">OpenClaw 2026.3.13之前版本存在操作系统命令注入漏洞，该漏洞源于未清理路径包含的shell元字符，攻击者利用该漏洞可以远程注入命令。</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">目前厂商已发布升级补丁以修复漏洞，参考链接：</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" data-mp-plugin="96weixin"><span leaf=""><a href="https://github.com/openclaw/openclaw/releases" target="_blank">https://github.com/openclaw/openclaw/releases</a></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" data-mp-plugin="96weixin"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">2. MLflow 操作系统命令注入漏洞（CNNVD-202603-6212）</span></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" data-mp-plugin="96weixin"><span leaf="">MLflow是一个开源简化机器学习的开发平台。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" data-mp-plugin="96weixin"><span leaf="">MLflow存在操作系统命令注入漏洞，该漏洞源于model_uri参数未经适当清理可直接嵌入shell命令，攻击者利用该漏洞可以注入命令和提升权限。</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">目前厂商已发布升级补丁以修复漏洞，参考链接：</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" data-mp-plugin="96weixin"><span leaf=""><a href="https://github.com/mlflow/mlflow/releases" target="_blank">https://github.com/mlflow/mlflow/releases</a></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" data-mp-plugin="96weixin"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">3. LoLLMs 安全漏洞（CNNVD-202604-1398）</span></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" data-mp-plugin="96weixin"><span leaf="">LoLLMs是一个大型语言与多模态系统。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" data-mp-plugin="96weixin"><span leaf="">LoLLMs 2.1.0版本存在安全漏洞，该漏洞源于使用弱密钥签署JSON Web Tokens导致访问控制不当，攻击者利用该漏洞可以离线暴力破解以恢复密钥，进而伪造管理令牌并提升权限。</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf="">目前厂商已发布升级补丁以修复漏洞，参考链接：</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf=""><a href="https://lollms.com/" target="_blank">https://lollms.com/</a></span></p><div data-mpa-template="t" mpa-paragraph-type="ignored" data-mp-plugin="96weixin"><div mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;flex: 0 0 auto;height: auto;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: flex;flex-flow: row;text-align: center;justify-content: center;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;width: 45px;vertical-align: top;background-color: rgb(18, 93, 196);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 45px;height: auto;" mpa-from-tpl="t" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img __bg_gif" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 45px !important;visibility: visible !important;" data-imgfileid="503963434" src="https://wechat2rss.xlab.app/img-proxy/?k=68515072&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1JMd8aMOqNkic25xydKvYcCVEsHXvm506icfXiaFep4AfohjraUj3F2jMfg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=a125a307&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzAxODY1OTM5OQ%3D%3D%26mid%3D2651464532%26idx%3D1%26sn%3D780df60bd7c8d777e4a4903a8d1268e2">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 17 Apr 2026 17:02:00 +0800</pubDate>
    </item>
    <item>
      <title>人工智能重要安全漏洞的通报-openclaw多个安全漏洞</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzAxODY1OTM5OQ==&amp;mid=2651464524&amp;idx=1&amp;sn=f8fcc47f93c2b44a2656b425cff3b86b</link>
      <description>根据国家信息安全漏洞库（CNNVD）统计，自2026年4月3日-2026年4月13日，共采集OpenClaw漏洞63个</description>
      <content:encoded><![CDATA[<p>原创 <span>CNNVD</span> <span>2026-04-16 11:13</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=79bfbd70&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FuOZw5Efn8esrd5rcpWicc71pElXrrbXQHAGZk21OU5iannjLEuSSCQricSyK36X0T3QX0pj33zVGLQYBAEFq9JtvZlCvPkJgjCN0oDhepVc16M%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>根据国家信息安全漏洞库（CNNVD）统计，自2026年4月3日-2026年4月13日，共采集OpenClaw漏洞63个</p>
  <div data-mpa-template="t" mpa-paragraph-type="ignored" data-mp-plugin="96weixin"><div mpa-from-tpl="t"><p data-mpa-powered-by="yiban.io" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: center;visibility: visible;" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img __bg_gif" data-ratio="0.1381345926800472" data-type="gif" data-w="847" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: bottom;font-size: var(--articleFontsize);letter-spacing: 0.034em;height: auto !important;visibility: visible !important;width: 677px !important;" data-imgfileid="503963433" src="https://wechat2rss.xlab.app/img-proxy/?k=22c9ee88&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1JjlMnGl5z2XiaAQGZdFulYs0vsE3icB8RUiawPqDSb5lvm8G0drb7iaw7sQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);letter-spacing: 0.544px;text-align: justify;font-size: 16px;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;text-align: center;justify-content: center;display: flex;flex-flow: row;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;transform: rotateZ(19deg);visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;visibility: visible;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 7px;height: auto;visibility: visible;" mpa-from-tpl="t" nodeleaf=""><img data-aistatus="1" alt="图片" class="__bg_gif" data-ratio="4" data-s="300,640" data-type="gif" data-w="36" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 7px !important;visibility: visible !important;" data-imgfileid="503963431" src="https://wechat2rss.xlab.app/img-proxy/?k=e2d135e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1Js3VkKswpUtkoDWibZ1YQl1lIdcctfqePCcSPEdc38SnhJGdqGJUFx9w%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div><div style="-webkit-tap-highlight-color: transparent;padding-right: 8px;padding-left: 8px;outline: 0px;display: inline-block;vertical-align: middle;width: auto;min-width: 5%;flex: 0 0 auto;height: auto;align-self: center;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: justify;color: rgb(18, 93, 196);" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;text-wrap-style: initial;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;" mpa-from-tpl="t"><span leaf="">点击蓝字 关注我们</span></strong></p></div></div><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;transform: rotateZ(199deg);" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 7px;height: auto;" mpa-from-tpl="t" nodeleaf=""><img data-imgfileid="503963432" alt="图片" class="__bg_gif" data-ratio="4" data-s="300,640" data-type="gif" data-w="36" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 7px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=e2d135e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1Js3VkKswpUtkoDWibZ1YQl1lIdcctfqePCcSPEdc38SnhJGdqGJUFx9w%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div><div data-mpa-template="t" mpa-paragraph-type="quote" data-mp-plugin="96weixin"><div mpa-from-tpl="t" mpa-paragraph-type="quote" data-mp-plugin="96weixin" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;visibility: visible;"><div data-role="outer" mpa-from-tpl="t" data-mp-plugin="96weixin" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;visibility: visible;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 13.5312px;margin-left: 13.5312px;outline: 0px;display: flex;flex-direction: column;border-width: 1px;border-style: solid;border-color: #3f75cf;border-radius: 12px;background-color: #dce8fb;visibility: visible;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;padding: 5px 16px;outline: 0px;align-self: center;background-color: #3f75cf;border-radius: 12px;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;font-size: 15px;letter-spacing: 1.5px;line-height: 15px;color: #ffffff;text-align: center;visibility: visible;"><strong><span style="font-size: 18px;"><span leaf="">漏洞情况</span></span></strong></p></div><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;padding: 10px 20px 15px;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.75em;visibility: visible;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t"><span style="color: rgb(18, 93, 196);font-size: 16px;letter-spacing: normal;background-color: rgb(220, 232, 251);"><span leaf="">根据国家信息安全漏洞库（CNNVD）统计，自2026年4月3日-2026年4月13日，共采集OpenClaw漏洞63个</span></span><span leaf="">，其中高危漏洞19个，中危漏洞43个、低危漏洞1个，包含了访问控制错误、代码问题、路径遍历等多个漏洞类型。OpenClaw多个版本受到漏洞影响。目前，OpenClaw官方已经发布了更新修复漏洞，建议用户及时确认是否受到漏洞影响，尽快采取修补措施。</span></p></div></div></div></div></div></div><div data-mpa-template="t" mpa-paragraph-type="title" data-mp-plugin="96weixin"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">一</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">漏洞介绍</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf="">OpenClaw是一个开源的智能人工助理，可运行在PC或服务器等多种终端设备上，能够直接通过微信、Telegram、Discord、Slack、iMessage等聊天平台接收指令并执行操作。OpenClaw拥有大量用户群体，影响范围涉及多个行业和领域，攻击者利用漏洞可在未授权状态下获取目标敏感数据，提升权限、或远程执行代码。OpenClaw 2026.4.14之前多个版本均受到漏洞影响。</span></p><div data-mpa-template="t" mpa-paragraph-type="title" data-mp-plugin="96weixin"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">二</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">漏洞详情</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" data-mp-plugin="96weixin"><span leaf="">自2026年4月3日-2026年4月13日，国家信息安全漏洞库（CNNVD）共采集OpenClaw漏洞63个，其中高危漏洞19个、中危漏洞43个、低危漏洞1个。参考链接：<a href="https://github.com/openclaw/openclaw/releases" target="_blank">https://github.com/openclaw/openclaw/releases</a></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="7.27069351230425" data-s="300,640" data-type="png" data-w="447" data-imgfileid="503980867" src="https://wechat2rss.xlab.app/img-proxy/?k=077536fb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuOZw5Efn8euicW3gXU3YRmJp9Lgl49BfA2bAHk8vYNvtUiae50WvKo00o4iaCgtULiapiacvl4GWJmIpNGibc7RJCDVLnuia4Xv4vCkeGeg4Is3Dib8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-paragraph-type="title" data-mp-plugin="96weixin"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">三</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">修复建议</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf="">目前，OpenClaw官方已经发布了更新修复漏洞，建议用户及时确认是否受到漏洞影响，尽快采取修补措施。OpenClaw官方公告地址：</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" data-mp-plugin="96weixin"><span leaf=""><a href="https://openclaw.ai/" target="_blank">https://openclaw.ai/</a></span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf="">CNNVD将继续跟踪上述漏洞的相关情况，及时发布相关信息。如有需要，可与CNNVD联系。联系方式: cnnvd@itsec.gov.cn</span></p><div data-mpa-template="t" mpa-paragraph-type="ignored" data-mp-plugin="96weixin"><div mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;flex: 0 0 auto;height: auto;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: flex;flex-flow: row;text-align: center;justify-content: center;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;width: 45px;vertical-align: top;background-color: rgb(18, 93, 196);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 45px;height: auto;" mpa-from-tpl="t" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img __bg_gif" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 45px !important;visibility: visible !important;" data-imgfileid="503963434" src="https://wechat2rss.xlab.app/img-proxy/?k=68515072&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1JMd8aMOqNkic25xydKvYcCVEsHXvm506icfXiaFep4AfohjraUj3F2jMfg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=fe9052fe&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzAxODY1OTM5OQ%3D%3D%26mid%3D2651464524%26idx%3D1%26sn%3Df8fcc47f93c2b44a2656b425cff3b86b">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 16 Apr 2026 11:13:00 +0800</pubDate>
    </item>
    <item>
      <title>CNNVD关于微软多个安全漏洞的通报</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzAxODY1OTM5OQ==&amp;mid=2651464524&amp;idx=2&amp;sn=83ce0ccfea8f9723da6dd8c09fb865a3</link>
      <description>近日，微软官方发布了多个安全漏洞的公告，其中微软产品本身漏洞166个，影响到微软产品的其他厂商漏洞29个。</description>
      <content:encoded><![CDATA[<p><span>CNNVD</span> <span>2026-04-16 11:13</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=2acb8980&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FuOZw5Efn8esGKMdtt1KbzM2dEq1kKPOB13ia79Sz9DSdo5qnCgz97oWYmhDUHZ4sMf2hXar2IlVhYZWPlW4Dchv2Nndu3y017EQUhnbQ7EIM%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>近日，微软官方发布了多个安全漏洞的公告，其中微软产品本身漏洞166个，影响到微软产品的其他厂商漏洞29个。</p>
  <div data-mpa-template="t" mpa-paragraph-type="ignored"><div mpa-from-tpl="t"><p data-mpa-powered-by="yiban.io" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: center;visibility: visible;"><img alt="图片" class="rich_pages wxw-img __bg_gif" data-galleryid="" data-imgfileid="503963433" data-ratio="0.1381345926800472" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: bottom;font-size: var(--articleFontsize);letter-spacing: 0.034em;height: auto !important;visibility: visible !important;width: 677px !important;" data-type="gif" data-w="847" src="https://wechat2rss.xlab.app/img-proxy/?k=22c9ee88&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1JjlMnGl5z2XiaAQGZdFulYs0vsE3icB8RUiawPqDSb5lvm8G0drb7iaw7sQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);letter-spacing: 0.544px;text-align: justify;font-size: 16px;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;text-align: center;justify-content: center;display: flex;flex-flow: row;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;transform: rotateZ(19deg);visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;visibility: visible;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 7px;height: auto;visibility: visible;" mpa-from-tpl="t"><img data-imgfileid="503963431" data-ratio="4" data-s="300,640" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 7px !important;visibility: visible !important;" data-type="gif" data-w="36" class="__bg_gif" alt="图片" src="https://wechat2rss.xlab.app/img-proxy/?k=e2d135e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1Js3VkKswpUtkoDWibZ1YQl1lIdcctfqePCcSPEdc38SnhJGdqGJUFx9w%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div><div style="-webkit-tap-highlight-color: transparent;padding-right: 8px;padding-left: 8px;outline: 0px;display: inline-block;vertical-align: middle;width: auto;min-width: 5%;flex: 0 0 auto;height: auto;align-self: center;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: justify;color: rgb(18, 93, 196);" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;text-wrap-style: initial;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;" mpa-from-tpl="t">点击蓝字 关注我们</strong></p></div></div><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;transform: rotateZ(199deg);" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 7px;height: auto;" mpa-from-tpl="t"><img data-imgfileid="503963432" data-ratio="4" data-s="300,640" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 7px !important;visibility: visible !important;" data-type="gif" data-w="36" class="__bg_gif" alt="图片" src="https://wechat2rss.xlab.app/img-proxy/?k=e2d135e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1Js3VkKswpUtkoDWibZ1YQl1lIdcctfqePCcSPEdc38SnhJGdqGJUFx9w%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div><div data-mpa-template="t" mpa-paragraph-type="quote"><div mpa-from-tpl="t" mpa-paragraph-type="quote" data-mp-plugin="96weixin" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;visibility: visible;"><div data-role="outer" mpa-from-tpl="t" data-mp-plugin="96weixin" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;visibility: visible;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 13.5312px;margin-left: 13.5312px;outline: 0px;display: flex;flex-direction: column;border-width: 1px;border-style: solid;border-color: #3f75cf;border-radius: 12px;background-color: #dce8fb;visibility: visible;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;padding: 5px 16px;outline: 0px;align-self: center;background-color: #3f75cf;border-radius: 12px;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;font-size: 15px;letter-spacing: 1.5px;line-height: 15px;color: #ffffff;text-align: center;visibility: visible;"><span style="font-size: 18px;"><strong>漏洞情况</strong></span></p></div><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;padding: 10px 20px 15px;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.75em;visibility: visible;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t">近日，微软官方发布了多个安全漏洞的公告，其中微软产品本身漏洞166个，影响到微软产品的其他厂商漏洞29个。微软Microsoft Windows 、Microsoft GitHub Copilot and Visual Studio Code、Microsoft Windows Encrypting File System、Microsoft Windows Local Security Authority Subsystem Service等多个产品和系统受漏洞影响。目前，微软官方已经发布了漏洞修复补丁，建议用户及时确认是否受到漏洞影响，尽快采取修补措施。</p></div></div></div></div></div></div><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t">一</span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;">漏洞介绍</strong></span></p></h2></p></div></div></div></div><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body">2026年4月14日，微软发布了2026年4月份安全更新，共195个漏洞的补丁程序，CNNVD对这些漏洞进行了收录。本次更新主要涵盖了Microsoft Windows 、Microsoft GitHub Copilot and Visual Studio Code、Microsoft Windows Encrypting File System、Microsoft Windows Local Security Authority Subsystem Service、Microsoft Power Apps、Microsoft Windows GDI等。CNNVD对其危害等级进行了评价，其中超危漏洞3个，高危漏洞125个，中危漏洞57个，低危漏洞10个。微软多个产品和系统版本受漏洞影响，具体影响范围可访问微软官方网站查询：</p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><a href="https://portal.msrc.microsoft.com/zh-cn/security-guidance" target="_blank">https://portal.msrc.microsoft.com/zh-cn/security-guidance</a></p><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t">二</span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;">漏洞详情</strong></span></p></h2></p></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;">此次更新共195个漏洞的补丁程序，包括165个新增漏洞的补丁程序、1个更新漏洞的补丁程序和29个影响微软产品的其他厂商漏洞的补丁程序。</p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;">此次更新共包括165个新增漏洞的补丁程序，其中超危漏洞2个，高危漏洞123个，中危漏洞40个。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="503980871" data-ratio="29.301339285714285" data-s="300,640" style="" data-type="png" data-w="448" src="https://wechat2rss.xlab.app/img-proxy/?k=a9835361&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuOZw5Efn8evf7I54ibE9WA6MnXwUTE5icUkuqCITdJslIwyKrLWjdvwW5ApqbrJFFc6bHfN1ecIxR0Dn7fKF1j9wQib9EKIe5KewRsChbbFiaa8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;">此次更新共包括1个更新漏洞的补丁程序，其中中危漏洞1个。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="503980872" data-ratio="0.234375" data-s="300,640" style="" data-type="png" data-w="448" src="https://wechat2rss.xlab.app/img-proxy/?k=1a2f38d2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuOZw5Efn8etC3fzEYibGLotxFkhy127FPY510wTLfmKUCdL5XrRklwZu73yplnhTZTcpCbOabgH808c2BiaOsLoTn6kFRq4TQshpCzIa9CW9c%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;">此次更新共包括29个影响微软产品的其他厂商漏洞的补丁程序，其中超危漏洞1个，高危漏洞2个，中危漏洞16个，低危漏洞10个。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="503980873" data-ratio="2.8707865168539324" data-s="300,640" style="" data-type="png" data-w="534" src="https://wechat2rss.xlab.app/img-proxy/?k=c11eaa77&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuOZw5Efn8eu1ibrBc6YNbrQphCZRoDhjKAk9ibRbPKicPmc8UW2rAZAxniaNe2IvL8bAib5xdGOzoAQsPQAL0ehEQ2z7rlPmHbDtD7EBCqK0ib4no%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t">三</span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;">修复建议</strong></span></p></h2></p></div></div></div></div><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body">目前，微软官方已经发布补丁修复了上述漏洞，建议用户及时确认漏洞影响，尽快采取修补措施。微软官方补丁下载地址：</p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><a href="https://msrc.microsoft.com/update-guide/en-us" target="_blank">https://msrc.microsoft.com/update-guide/en-us</a></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body">CNNVD将继续跟踪上述漏洞的相关情况，及时发布相关信息。如有需要，可与CNNVD联系。联系方式: cnnvd@itsec.gov.cn</p><div data-mpa-template="t" mpa-paragraph-type="ignored"><div mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;flex: 0 0 auto;height: auto;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: flex;flex-flow: row;text-align: center;justify-content: center;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;width: 45px;vertical-align: top;background-color: rgb(18, 93, 196);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 45px;height: auto;" mpa-from-tpl="t"><img class="rich_pages wxw-img __bg_gif" data-imgfileid="503963434" data-ratio="0.1503267973856209" data-s="300,640" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 45px !important;visibility: visible !important;" data-type="gif" data-w="306" alt="图片" src="https://wechat2rss.xlab.app/img-proxy/?k=68515072&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1JMd8aMOqNkic25xydKvYcCVEsHXvm506icfXiaFep4AfohjraUj3F2jMfg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=7bd10354&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzAxODY1OTM5OQ%3D%3D%26mid%3D2651464524%26idx%3D2%26sn%3D83ce0ccfea8f9723da6dd8c09fb865a3">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 16 Apr 2026 11:13:00 +0800</pubDate>
    </item>
    <item>
      <title>信息安全漏洞周报（2026年第15期）</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzAxODY1OTM5OQ==&amp;mid=2651464512&amp;idx=1&amp;sn=a253f6b63d7207fc75c7397a41db39d3</link>
      <description>根据国家信息安全漏洞库（CNNVD）统计，本周（2026年4月6日至2026年4月12日）安全漏洞情况如下</description>
      <content:encoded><![CDATA[<p>原创 <span>CNNVD</span> <span>2026-04-15 09:30</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=b8915f5a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FuOZw5Efn8euvgIQRRLk3zLVgBD1Z61yoGZuy4by6ockX1G8yh8NYIaFVlehAglOwZqe4WdlaicLKwDjRMqnPUkebXMDUrPUSFvpBx9tnbOJw%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>根据国家信息安全漏洞库（CNNVD）统计，本周（2026年4月6日至2026年4月12日）安全漏洞情况如下</p>
  <div data-mpa-template="t" mpa-paragraph-type="ignored"><div mpa-from-tpl="t"><p data-mpa-powered-by="yiban.io" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: center;visibility: visible;" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img __bg_gif" data-ratio="0.1381345926800472" data-type="gif" data-w="847" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: bottom;font-size: var(--articleFontsize);letter-spacing: 0.034em;height: auto !important;visibility: visible !important;width: 677px !important;" data-imgfileid="503963433" src="https://wechat2rss.xlab.app/img-proxy/?k=22c9ee88&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1JjlMnGl5z2XiaAQGZdFulYs0vsE3icB8RUiawPqDSb5lvm8G0drb7iaw7sQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);letter-spacing: 0.544px;text-align: justify;font-size: 16px;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;text-align: center;justify-content: center;display: flex;flex-flow: row;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;transform: rotateZ(19deg);visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;visibility: visible;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 7px;height: auto;visibility: visible;" mpa-from-tpl="t" nodeleaf=""><img data-aistatus="1" alt="图片" class="__bg_gif" data-ratio="4" data-s="300,640" data-type="gif" data-w="36" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 7px !important;visibility: visible !important;" data-imgfileid="503963431" src="https://wechat2rss.xlab.app/img-proxy/?k=e2d135e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1Js3VkKswpUtkoDWibZ1YQl1lIdcctfqePCcSPEdc38SnhJGdqGJUFx9w%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div><div style="-webkit-tap-highlight-color: transparent;padding-right: 8px;padding-left: 8px;outline: 0px;display: inline-block;vertical-align: middle;width: auto;min-width: 5%;flex: 0 0 auto;height: auto;align-self: center;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: justify;color: rgb(18, 93, 196);" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;text-wrap-style: initial;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;" mpa-from-tpl="t"><span leaf="">点击蓝字 关注我们</span></strong></p></div></div><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;transform: rotateZ(199deg);" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 7px;height: auto;" mpa-from-tpl="t" nodeleaf=""><img data-imgfileid="503963432" alt="图片" class="__bg_gif" data-ratio="4" data-s="300,640" data-type="gif" data-w="36" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 7px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=e2d135e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1Js3VkKswpUtkoDWibZ1YQl1lIdcctfqePCcSPEdc38SnhJGdqGJUFx9w%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div><div data-mpa-template="t" mpa-paragraph-type="quote"><div mpa-from-tpl="t" mpa-paragraph-type="quote" data-mp-plugin="96weixin" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;visibility: visible;"><div data-role="outer" mpa-from-tpl="t" data-mp-plugin="96weixin" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;visibility: visible;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 13.5312px;margin-left: 13.5312px;outline: 0px;display: flex;flex-direction: column;border-width: 1px;border-style: solid;border-color: #3f75cf;border-radius: 12px;background-color: #dce8fb;visibility: visible;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;padding: 5px 16px;outline: 0px;align-self: center;background-color: #3f75cf;border-radius: 12px;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;font-size: 15px;letter-spacing: 1.5px;line-height: 15px;color: #ffffff;text-align: center;visibility: visible;"><span style="font-size: 18px;"><strong><span leaf="">漏洞情况</span></strong></span></p></div><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;padding: 10px 20px 15px;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.75em;visibility: visible;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t"><span leaf="">根据国家信息安全漏洞库（CNNVD）统计，本周（2026年4月6日至2026年4月12日）安全漏洞情况如下：</span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t"><strong><span leaf="">公开漏洞情况</span></strong></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t"><span leaf="">本周CNNVD采集安全漏洞1604个。</span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t"><strong><span leaf="">接报漏洞情况</span></strong></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t"><span leaf="">本周CNNVD接报漏洞5620个，其中信息技术产品漏洞（通用型漏洞）611个，网络信息系统漏洞（事件型漏洞）12个，漏洞平台推送漏洞4997个。</span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t"><strong><span leaf="">重大漏洞通报</span></strong></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t"><span leaf="">Apache ActiveMQ安全漏洞（CNNVD-202604-1392、CVE-2026-34197）：成功利用漏洞的攻击者，可在目标系统远程执行代码。Apache ActiveMQ 多个版本均受此漏洞影响。目前，Apache官方已发布新版本修复了该漏洞，建议用户及时确认产品版本，尽快采取修补措施。</span></p></div></div></div></div></div></div><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">一</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">公开漏洞情况</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf="">根据国家信息安全漏洞库（CNNVD）统计，本周新增安全漏洞1604个，漏洞新增数量有所上升。从厂商分布来看WordPress基金会新增漏洞最多，有277个；从漏洞类型来看，跨站脚本类的安全漏洞占比最大，达到6.80%。新增漏洞中，超危漏洞92个，高危漏洞433个，中危漏洞1015个，低危漏洞64个。</span></p><div data-mpa-template="t" mpa-paragraph-type="secondTitle"><div mpa-from-tpl="t" mpa-paragraph-type="secondTitle" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="27325" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div data-align="title" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;padding-right: 10px;padding-left: 10px;outline: 0px;background-color: rgba(0, 72, 191, 0.75);display: inline-block;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;display: flex;justify-content: center;align-items: center;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 10px;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;letter-spacing: 2px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(255, 255, 255);font-size: 16px;" mpa-is-content="t"><span leaf="">（一） 安全漏洞增长数量情况</span></span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">本周CNNVD采集安全漏洞1604个。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="image" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.597165991902834" data-w="494" style="left: 0px;top: 0px;width: 89.1697%;height: 295px;border-width: 1px;border-style: solid;border-color: rgb(229, 228, 228);" src="https://wechat2rss.xlab.app/img-proxy/?k=19220802&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FuOZw5Efn8etEdW7XfjczsdSmI0zdJhfYmHcWqSfgaYv9juTY9Z8aPNA1SQrParQgVjbVzoKzqs4CiaSmQFVRJEmRxEvAibWRQPCKjUekVewrk%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg"/></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">图1 近五周漏洞新增数量统计图</span></span></p><div data-mpa-template="t" mpa-paragraph-type="secondTitle"><div mpa-from-tpl="t" mpa-paragraph-type="secondTitle" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="27325" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div data-align="title" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;padding-right: 10px;padding-left: 10px;outline: 0px;background-color: rgba(0, 72, 191, 0.75);display: inline-block;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;display: flex;justify-content: center;align-items: center;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 10px;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;letter-spacing: 2px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(255, 255, 255);font-size: 16px;" mpa-is-content="t"><span leaf="">（二） 安全漏洞分布情况</span></span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">从厂商分布来看，WordPress基金会新增漏洞最多，有277个。各厂商漏洞数量分布如表1所示。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表1 新增安全漏洞排名前五厂商统计表</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6143250688705234" data-s="300,640" data-type="png" data-w="363" data-imgfileid="503980853" src="https://wechat2rss.xlab.app/img-proxy/?k=f149ecdf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuOZw5Efn8esfod5Vs4ribiampkG7XBca4Gw3GaBklZoMs8snDOg6acTIuNFJUcXH5WCZ02yibqoPBG9jpL77eTsRpfQicJOicYbiahXQrlI3Ob1fw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">本周国内厂商漏洞139个，友讯公司漏洞数量最多，有41个。国内厂商漏洞整体修复率为12.95%。请受影响用户关注厂商修复情况，及时下载补丁修复漏洞。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">从漏洞类型来看，跨站脚本类的安全漏洞占比最大，达到6.80%。漏洞类型统计如表2所示。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表2 漏洞类型统计表</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="2.7548209366391183" data-s="300,640" data-type="png" data-w="363" data-imgfileid="503980854" src="https://wechat2rss.xlab.app/img-proxy/?k=12185e5d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuOZw5Efn8etk9fZBuXD3NHZUSTLicrxgTxGzu4gZPTxEiaA7rfeKMZCZtwgmnb91YLKibdaEqgNDA3gpa7EBxPGj7tVuNncws7ToLYTEVIpibSg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-paragraph-type="secondTitle"><div mpa-from-tpl="t" mpa-paragraph-type="secondTitle" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="27325" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div data-align="title" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;padding-right: 10px;padding-left: 10px;outline: 0px;background-color: rgba(0, 72, 191, 0.75);display: inline-block;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;display: flex;justify-content: center;align-items: center;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 10px;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;letter-spacing: 2px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(255, 255, 255);font-size: 16px;" mpa-is-content="t"><span leaf="">（三） 安全漏洞危害等级与修复情况</span></span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">本周共发布超危漏洞92个，高危漏洞433个，中危漏洞1015个，低危漏洞64个。相应修复率分别为55.43%、63.97%、69.46%和76.56%。根据补丁信息统计，合计1082个漏洞已有修复补丁发布，整体修复率为67.46%。详细情况如表3所示。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表3 漏洞危害等级与修复情况</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5833333333333334" data-s="300,640" data-type="png" data-w="384" data-imgfileid="503980855" src="https://wechat2rss.xlab.app/img-proxy/?k=00ae7948&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuOZw5Efn8eu36Kky1egPiaFHLMyKk1FsP2BFu3mQhBeOia8ySBYpfrxKqPiaKyMDrOAl6ePFWQxVm0ibEVgbN01ibTsD0cfEM6rShzdqp0KOf2t4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-paragraph-type="secondTitle"><div mpa-from-tpl="t" mpa-paragraph-type="secondTitle" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="27325" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div data-align="title" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;padding-right: 10px;padding-left: 10px;outline: 0px;background-color: rgba(0, 72, 191, 0.75);display: inline-block;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;display: flex;justify-content: center;align-items: center;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 10px;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;letter-spacing: 2px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(255, 255, 255);font-size: 16px;" mpa-is-content="t"><span leaf="">（四） 本周重要漏洞实例</span></span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">本周重要漏洞实例如表4所示。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表4 本期重要漏洞实例</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4901315789473684" data-s="300,640" data-type="png" data-w="304" data-imgfileid="503980856" src="https://wechat2rss.xlab.app/img-proxy/?k=ef2d9a22&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuOZw5Efn8eskA2FEWfpjtibUJ92lEk52hy6bH0m7F5LCTg9mEXKq8ezCIyIbbD0SlK4wsiaMGGpameaAsyJhCmg092HJnibr0iackm6KlIBVqiaY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">1. WordPress plugin Ninja Forms - File Uploads 代码问题漏洞（CNNVD-202604-1403）</span></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">WordPress和WordPress plugin都是WordPress基金会的产品。WordPress是一套使用PHP语言开发的博客平台，该平台具有在基于PHP和MySQL的服务器上架设个人博客网站的功能。WordPress plugin Ninja Forms - File Uploads是一个应用插件。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">WordPress plugin Ninja Forms - File Uploads 3.3.26版本及之前版本存在代码问题漏洞，该漏洞源于NF_FU_AJAX_Controllers_Uploads::handle_upload函数缺少文件类型验证，攻击者利用该漏洞可以上传任意文件，从而远程执行代码。</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">目前厂商已发布升级补丁以修复漏洞，参考链接：</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf=""><a href="https://ninjaforms.com/extensions/file-uploads/" target="_blank">https://ninjaforms.com/extensions/file-uploads/</a></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">2. Google Chrome 资源管理错误漏洞（CNNVD-202604-1457）</span></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">Google Chrome是美国谷歌（Google）公司的一款Web浏览器。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">Google Chrome 147.0.7727.55之前版本存在资源管理错误漏洞，该漏洞源于内存释放后重用，攻击者利用该漏洞可以执行任意代码。</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">目前厂商已发布升级补丁以修复漏洞，参考链接：</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf=""><a href="https://www.google.com/chrome/" target="_blank">https://www.google.com/chrome/</a></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">3. Red Hat Quay 代码问题漏洞（CNNVD-202604-1607）</span></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">Red Hat Quay是美国红帽（Red Hat）公司的一款分布式容器镜像仓库，具有构建、分布和部署容器的功能。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">Red Hat Quay存在代码问题漏洞，该漏洞源于数据存储格式允许被篡改，攻击者利用该漏洞可以在服务器上执行任意代码。</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf="">目前厂商已发布升级补丁以修复漏洞，参考链接：</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf=""><a href="https://access.redhat.com/security/cve/CVE-2026-32590" target="_blank">https://access.redhat.com/security/cve/CVE-2026-32590</a></span></p><div data-mpa-template="t" mpa-paragraph-type="secondTitle"><div mpa-from-tpl="t" mpa-paragraph-type="secondTitle" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="27325" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div data-align="title" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;padding-right: 10px;padding-left: 10px;outline: 0px;background-color: rgba(0, 72, 191, 0.75);display: inline-block;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;display: flex;justify-content: center;align-items: center;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 10px;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;letter-spacing: 2px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(255, 255, 255);font-size: 16px;" mpa-is-content="t"><span leaf="">（五） 本周重要人工智能漏洞实例</span></span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">本周重要人工智能漏洞实例如表5所示。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表5 本期重要人工智能漏洞实例</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4901315789473684" data-s="300,640" data-type="png" data-w="304" data-imgfileid="503980857" src="https://wechat2rss.xlab.app/img-proxy/?k=d6b87de4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuOZw5Efn8euvZz5ibugwwur7aN2s8kGyOAtuNFktWIxkiay4QLtC4HibaDerjcgyHiaiaeUN9kp5iaNkDIjUjbm0UYSG6DbzjPpZZ29iao1dWkXfiaM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">1. LoLLMs 安全漏洞（CNNVD-202604-1398）</span></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">LoLLMs是一个大型语言与多模态系统。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">lollms 2.1.0版本存在安全漏洞，该漏洞源于使用弱密钥签署JSON Web Tokens导致访问控制不当，攻击者利用该漏洞可以执行离线暴力破解以恢复密钥，进而伪造管理令牌并提升权限。</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">目前厂商已发布升级补丁以修复漏洞，参考链接：</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf=""><a href="https://lollms.com/" target="_blank">https://lollms.com/</a></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">2. PraisonAI 代码问题漏洞（CNNVD-202604-1921）</span></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">PraisonAI是一个低代码多智能体协作框架。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">PraisonAI 1.5.128之前版本存在代码问题漏洞，该漏洞源于web_crawl函数未对URL进行任何验证，攻击者利用该漏洞可以获取敏感信息。</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">目前厂商已发布升级补丁以修复漏洞，参考链接：</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf=""><a href="https://github.com/MervinPraison/PraisonAI/releases" target="_blank">https://github.com/MervinPraison/PraisonAI/releases</a></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">3. OpenClaw 安全漏洞（CNNVD-202604-1939）</span></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">OpenClaw是一个开源的智能人工助理。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">OpenClaw 2026.3.22之前版本存在安全漏洞，该漏洞源于对权限的范围验证不足，攻击者利用该漏洞可以提升权限和远程执行代码。</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf="">目前厂商已发布升级补丁以修复漏洞，参考链接：</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf=""><a href="https://github.com/openclaw/openclaw/releases" target="_blank">https://github.com/openclaw/openclaw/releases</a></span></p><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">二</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">漏洞平台推送情况</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">本周CNNVD接收漏洞平台推送漏洞4997个。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表6 本周漏洞平台推送情况</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4934210526315789" data-s="300,640" data-type="png" data-w="304" data-imgfileid="503980858" src="https://wechat2rss.xlab.app/img-proxy/?k=d0f433d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuOZw5Efn8evJJvqUGPhUWwZTcsTLJqSGEyeOZrF8bYeiaRXawuMl6gDmxOKbo3TdfT6eu0F3zzmC0QupicKOTDdtspqJ1CRrodXlTdwe33QMU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">三</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">接报漏洞情况</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">本周CNNVD接报漏洞623个，其中信息技术产品漏洞（通用型漏洞）611个，网络信息系统漏洞（事件型漏洞）12个。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表7 本周漏洞报送情况</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="7.083516483516483" data-s="300,640" data-type="png" data-w="455" data-imgfileid="503980860" src="https://wechat2rss.xlab.app/img-proxy/?k=c5bfe57c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuOZw5Efn8ettYZDlRDZjodyOKcauYyPDg35OGu3oIOM5UahZic42YXxHg4mbib40LPevgRIfc0MhfqgqibAU3RkicmgL55ibJOiciaQ970cic5zwxMA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">四</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">收录漏洞通报情况</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">本周CNNVD收录漏洞通报222份。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表8 本周漏洞通报情况</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="3.9934065934065934" data-s="300,640" data-type="png" data-w="455" data-imgfileid="503980861" src="https://wechat2rss.xlab.app/img-proxy/?k=64305596&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuOZw5Efn8esnrUxF6BBib4kThx88ez78wO9opPicmWxQ689hLpDibmCyfr3Uua18k7Mvk4pzibnFxQ6H3kOCNQmTEZkG8fchcx6CUuEC2EnUDPo%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">五</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">重大漏洞通报</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px 0px 16px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-size: 17px;"><strong><span leaf="">CNNVD关于Apache ActiveMQ安全漏洞的通报</span></strong></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">近日，国家信息安全漏洞库（CNNVD）收到关于Apache ActiveMQ安全漏洞（CNNVD-202604-1392、CVE-2026-34197）情况的报送。成功利用漏洞的攻击者，可在目标系统远程执行代码。Apache ActiveMQ 多个版本均受此漏洞影响。目前，Apache官方已发布新版本修复了该漏洞，建议用户及时确认产品版本，尽快采取修补措施。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">1.漏洞介绍</span></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">Apache ActiveMQ是美国阿帕奇（Apache）基金会的一套开源的消息中间件，它支持Java消息服务、集群、Spring Framework等。Apache ActiveMQ存在安全漏洞，该漏洞源于Jolokia JMX-HTTP的输入验证不当导致，攻击者可以通过 ActiveMQ 的 Jolokia API 调用管理操作，诱使代理服务器获取远程配置文件并执行任意系统命令。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">2.危害影响</span></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">Apache ActiveMQ 5.19.4之前版本和6.0.0至6.2.3之前版本均受此漏洞影响。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">3.修复建议</span></span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf="">目前，Apache官方已发布新版本修复了该漏洞，建议用户及时确认产品版本，尽快采取修补措施。官方更新链接：</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf=""><a href="https://activemq.apache.org/download.html" target="_blank">https://activemq.apache.org/download.html</a></span></p><div data-mpa-template="t" mpa-paragraph-type="ignored"><div mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;flex: 0 0 auto;height: auto;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: flex;flex-flow: row;text-align: center;justify-content: center;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;width: 45px;vertical-align: top;background-color: rgb(18, 93, 196);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 45px;height: auto;" mpa-from-tpl="t" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img __bg_gif" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 45px !important;visibility: visible !important;" data-imgfileid="503963434" src="https://wechat2rss.xlab.app/img-proxy/?k=68515072&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1JMd8aMOqNkic25xydKvYcCVEsHXvm506icfXiaFep4AfohjraUj3F2jMfg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=ac8c54dc&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzAxODY1OTM5OQ%3D%3D%26mid%3D2651464512%26idx%3D1%26sn%3Da253f6b63d7207fc75c7397a41db39d3">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 15 Apr 2026 09:30:00 +0800</pubDate>
    </item>
    <item>
      <title>CNNVD关于Apache ActiveMQ安全漏洞的通报</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzAxODY1OTM5OQ==&amp;mid=2651464498&amp;idx=1&amp;sn=09c54446877d56a05e739a137f68a7ac</link>
      <description>近日，国家信息安全漏洞库（CNNVD）收到关于Apache ActiveMQ安全漏洞（CNNVD-202604-1392、CVE-2026-34197）情况的报送。</description>
      <content:encoded><![CDATA[<p>原创 <span>CNNVD</span> <span>2026-04-09 18:35</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=8b8c0fc8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FuOZw5Efn8evLy4icop80Dcjg41gUHVkAZZBBMncuibWIg2INcpc2qalZk7fhibmMK8K2GZC9nQ7cTt6KPwAaUFfF0D5P5rISqichEPZp8qVLzgA%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>近日，国家信息安全漏洞库（CNNVD）收到关于Apache ActiveMQ安全漏洞（CNNVD-202604-1392、CVE-2026-34197）情况的报送。</p>
  <div data-mpa-template="t" mpa-paragraph-type="ignored"><div mpa-from-tpl="t"><p data-mpa-powered-by="yiban.io" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: center;visibility: visible;" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img __bg_gif" data-ratio="0.1381345926800472" data-type="gif" data-w="847" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: bottom;font-size: var(--articleFontsize);letter-spacing: 0.034em;height: auto !important;visibility: visible !important;width: 677px !important;" data-imgfileid="503963433" src="https://wechat2rss.xlab.app/img-proxy/?k=22c9ee88&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1JjlMnGl5z2XiaAQGZdFulYs0vsE3icB8RUiawPqDSb5lvm8G0drb7iaw7sQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);letter-spacing: 0.544px;text-align: justify;font-size: 16px;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;text-align: center;justify-content: center;display: flex;flex-flow: row;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;transform: rotateZ(19deg);visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;visibility: visible;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 7px;height: auto;visibility: visible;" mpa-from-tpl="t" nodeleaf=""><img data-aistatus="1" alt="图片" class="__bg_gif" data-ratio="4" data-s="300,640" data-type="gif" data-w="36" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 7px !important;visibility: visible !important;" data-imgfileid="503963431" src="https://wechat2rss.xlab.app/img-proxy/?k=e2d135e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1Js3VkKswpUtkoDWibZ1YQl1lIdcctfqePCcSPEdc38SnhJGdqGJUFx9w%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div><div style="-webkit-tap-highlight-color: transparent;padding-right: 8px;padding-left: 8px;outline: 0px;display: inline-block;vertical-align: middle;width: auto;min-width: 5%;flex: 0 0 auto;height: auto;align-self: center;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: justify;color: rgb(18, 93, 196);" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;text-wrap-style: initial;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;" mpa-from-tpl="t"><span leaf="">点击蓝字 关注我们</span></strong></p></div></div><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;transform: rotateZ(199deg);" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 7px;height: auto;" mpa-from-tpl="t" nodeleaf=""><img data-imgfileid="503963432" alt="图片" class="__bg_gif" data-ratio="4" data-s="300,640" data-type="gif" data-w="36" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 7px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=e2d135e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1Js3VkKswpUtkoDWibZ1YQl1lIdcctfqePCcSPEdc38SnhJGdqGJUFx9w%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div><div data-mpa-template="t" mpa-paragraph-type="quote"><div mpa-from-tpl="t" mpa-paragraph-type="quote" data-mp-plugin="96weixin" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;visibility: visible;"><div data-role="outer" mpa-from-tpl="t" data-mp-plugin="96weixin" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;visibility: visible;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 13.5312px;margin-left: 13.5312px;outline: 0px;display: flex;flex-direction: column;border-width: 1px;border-style: solid;border-color: #3f75cf;border-radius: 12px;background-color: #dce8fb;visibility: visible;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;padding: 5px 16px;outline: 0px;align-self: center;background-color: #3f75cf;border-radius: 12px;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;font-size: 15px;letter-spacing: 1.5px;line-height: 15px;color: #ffffff;text-align: center;visibility: visible;"><span style="font-size: 18px;"><strong><span leaf="">漏洞情况</span></strong></span></p></div><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;padding: 10px 20px 15px;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.75em;visibility: visible;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t"><span leaf="">近日，国家信息安全漏洞库（CNNVD）收到关于Apache ActiveMQ安全漏洞（CNNVD-202604-1392、CVE-2026-34197）情况的报送。成功利用漏洞的攻击者，可在目标系统远程执行代码。Apache ActiveMQ 多个版本均受此漏洞影响。目前，Apache官方已发布新版本修复了该漏洞，建议用户及时确认产品版本，尽快采取修补措施。</span></p></div></div></div></div></div></div><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">一</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">漏洞介绍</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf="">Apache ActiveMQ是美国阿帕奇（Apache）基金会的一套开源的消息中间件，它支持Java消息服务、集群、Spring Framework等。Apache ActiveMQ存在安全漏洞，该漏洞源于Jolokia JMX-HTTP的输入验证不当导致，攻击者可以通过 ActiveMQ 的 Jolokia API 调用管理操作，诱使代理服务器获取远程配置文件并执行任意系统命令。</span></p><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">二</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">危害影响</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf="">Apache ActiveMQ 5.19.4之前版本和6.0.0至6.2.3之前版本均受此漏洞影响。</span></p><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">三</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">修复建议</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf="">目前，Apache官方已发布新版本修复了该漏洞，建议用户及时确认产品版本，尽快采取修补措施。官方更新链接：</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf=""><a href="https://activemq.apache.org/download.html" target="_blank">https://activemq.apache.org/download.html</a></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">本通报由CNNVD技术支撑单位——深信服科技股份有限公司、三六零数字安全科技集团有限公司、广州纬安科技有限公司、奇安信网神信息技术（北京）股份有限公司、中国联合网络通信有限公司深圳市分公司、贵州粟字科技有限公司、甘肃青鸾信息技术有限公司、天翼云科技有限公司、华易数安科技(吉林省)有限公司、山东新潮信息技术有限公司、郑州云智信安安全技术有限公司、北京中测安华科技有限公司、广东财贸职业学院、上海矢安科技有限公司、杭州迪普科技股份有限公司、深圳市博通智能技术有限公司、北京山石网科信息技术有限公司、新基信息技术集团股份有限公司、西安尚易安华信息科技有限责任公司、成都卫士通信息安全技术有限公司、南京共美科技有限公司、江西诚韬科技有限公司等技术支撑单位提供支持。</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf="">CNNVD将继续跟踪上述漏洞的相关情况，及时发布相关信息。如有需要，可与CNNVD联系。联系方式: cnnvd@itsec.gov.cn</span></p><div data-mpa-template="t" mpa-paragraph-type="ignored"><div mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;flex: 0 0 auto;height: auto;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: flex;flex-flow: row;text-align: center;justify-content: center;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;width: 45px;vertical-align: top;background-color: rgb(18, 93, 196);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 45px;height: auto;" mpa-from-tpl="t" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img __bg_gif" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 45px !important;visibility: visible !important;" data-imgfileid="503963434" src="https://wechat2rss.xlab.app/img-proxy/?k=68515072&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1JMd8aMOqNkic25xydKvYcCVEsHXvm506icfXiaFep4AfohjraUj3F2jMfg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=afd1809a&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzAxODY1OTM5OQ%3D%3D%26mid%3D2651464498%26idx%3D1%26sn%3D09c54446877d56a05e739a137f68a7ac">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 09 Apr 2026 18:35:00 +0800</pubDate>
    </item>
    <item>
      <title>信息安全漏洞周报（2026年第14期）</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzAxODY1OTM5OQ==&amp;mid=2651464494&amp;idx=1&amp;sn=0b5e5b630287cfb070129cd3f22f6c27</link>
      <description>根据国家信息安全漏洞库（CNNVD）统计，本周（2026年3月30日至2026年4月5日）安全漏洞情况如下</description>
      <content:encoded><![CDATA[<p>原创 <span>CNNVD</span> <span>2026-04-08 16:54</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=acb26a74&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FuOZw5Efn8esYRibL9DibkKGIoVUMPib2SSGm9LpXA5ibUO1ia8Uzpq68m3jQiajZGib5jIBP7UWd3xt6xHvU72q3JLIqYjg9qw8TxVVK4WB8ficBdRk%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>根据国家信息安全漏洞库（CNNVD）统计，本周（2026年3月30日至2026年4月5日）安全漏洞情况如下</p>
  <div data-mpa-template="t" mpa-paragraph-type="ignored"><div mpa-from-tpl="t"><p data-mpa-powered-by="yiban.io" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: center;visibility: visible;" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img __bg_gif" data-ratio="0.1381345926800472" data-type="gif" data-w="847" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: bottom;font-size: var(--articleFontsize);letter-spacing: 0.034em;height: auto !important;visibility: visible !important;width: 677px !important;" data-imgfileid="503963433" src="https://wechat2rss.xlab.app/img-proxy/?k=22c9ee88&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1JjlMnGl5z2XiaAQGZdFulYs0vsE3icB8RUiawPqDSb5lvm8G0drb7iaw7sQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p><div style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);letter-spacing: 0.544px;text-align: justify;font-size: 16px;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;text-align: center;justify-content: center;display: flex;flex-flow: row;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;transform: rotateZ(19deg);visibility: visible;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;visibility: visible;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 7px;height: auto;visibility: visible;" mpa-from-tpl="t" nodeleaf=""><img data-aistatus="1" alt="图片" class="__bg_gif" data-ratio="4" data-s="300,640" data-type="gif" data-w="36" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 7px !important;visibility: visible !important;" data-imgfileid="503963431" src="https://wechat2rss.xlab.app/img-proxy/?k=e2d135e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1Js3VkKswpUtkoDWibZ1YQl1lIdcctfqePCcSPEdc38SnhJGdqGJUFx9w%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div><div style="-webkit-tap-highlight-color: transparent;padding-right: 8px;padding-left: 8px;outline: 0px;display: inline-block;vertical-align: middle;width: auto;min-width: 5%;flex: 0 0 auto;height: auto;align-self: center;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;text-align: justify;color: rgb(18, 93, 196);" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;text-wrap-style: initial;"><strong style="-webkit-tap-highlight-color: transparent;outline: 0px;" mpa-from-tpl="t"><span leaf="">点击蓝字 关注我们</span></strong></p></div></div><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 0 0 0%;height: auto;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;transform: rotateZ(199deg);" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 7px;height: auto;" mpa-from-tpl="t" nodeleaf=""><img data-imgfileid="503963432" alt="图片" class="__bg_gif" data-ratio="4" data-s="300,640" data-type="gif" data-w="36" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 7px !important;visibility: visible !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=e2d135e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1Js3VkKswpUtkoDWibZ1YQl1lIdcctfqePCcSPEdc38SnhJGdqGJUFx9w%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div><div data-mpa-template="t" mpa-paragraph-type="quote"><div mpa-from-tpl="t" mpa-paragraph-type="quote" data-mp-plugin="96weixin" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;visibility: visible;"><div data-role="outer" mpa-from-tpl="t" data-mp-plugin="96weixin" style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 16px;visibility: visible;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 13.5312px;margin-left: 13.5312px;outline: 0px;display: flex;flex-direction: column;border-width: 1px;border-style: solid;border-color: #3f75cf;border-radius: 12px;background-color: #dce8fb;visibility: visible;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;padding: 5px 16px;outline: 0px;align-self: center;background-color: #3f75cf;border-radius: 12px;visibility: visible;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;font-size: 15px;letter-spacing: 1.5px;line-height: 15px;color: #ffffff;text-align: center;visibility: visible;"><span style="font-size: 18px;"><strong><span leaf="">漏洞情况</span></strong></span></p></div><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;padding: 10px 20px 15px;outline: 0px;visibility: visible;"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 1.75em;visibility: visible;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t"><span leaf="">根据国家信息安全漏洞库（CNNVD）统计，本周（2026年3月30日至2026年4月5日）安全漏洞情况如下：</span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t"><strong><span leaf="">公开漏洞情况</span></strong></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t"><span leaf="">本周CNNVD采集安全漏洞1298个。</span></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t"><strong><span leaf="">接报漏洞情况</span></strong></p><p style="-webkit-tap-highlight-color: transparent;outline: 0px;color: #125dc4;letter-spacing: normal;visibility: visible;" mpa-is-content="t"><span leaf="">本周CNNVD接报漏洞4733个，其中信息技术产品漏洞（通用型漏洞）769个，网络信息系统漏洞（事件型漏洞）28个，漏洞平台推送漏洞3936个。</span></p></div></div></div></div></div></div><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">一</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">公开漏洞情况</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf="">根据国家信息安全漏洞库（CNNVD）统计，本周新增安全漏洞1298个，漏洞新增数量有所下降。从厂商分布来看Linux基金会新增漏洞最多，有91个；从漏洞类型来看，跨站脚本类的安全漏洞占比最大，达到8.47%。新增漏洞中，超危漏洞82个，高危漏洞352个，中危漏洞805个，低危漏洞59个。</span></p><div data-mpa-template="t" mpa-paragraph-type="secondTitle"><div mpa-from-tpl="t" mpa-paragraph-type="secondTitle" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="27325" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div data-align="title" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;padding-right: 10px;padding-left: 10px;outline: 0px;background-color: rgba(0, 72, 191, 0.75);display: inline-block;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;display: flex;justify-content: center;align-items: center;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 10px;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;letter-spacing: 2px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(255, 255, 255);font-size: 16px;" mpa-is-content="t"><span leaf="">（一） 安全漏洞增长数量情况</span></span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">本周CNNVD采集安全漏洞1298个。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="image" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.6020408163265306" data-w="490" style="left: 0px;top: 0px;width: 88.4477%;height: 295px;border-width: 1px;border-style: solid;border-color: rgb(229, 228, 228);" src="https://wechat2rss.xlab.app/img-proxy/?k=abd9b52a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FuOZw5Efn8evsZh6JUS0YG451fVEIOc9UIkPibEEeXibsFyR1dJJCicsFfojQ2xVib45K3zHASQFnvHG4r4oXSym9IqbggVJu7Lj5ricnKeX49RV4%2F640%3Fwx_fmt%3Dother%26from%3Dappmsg"/></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">图1 近五周漏洞新增数量统计图</span></span></p><div data-mpa-template="t" mpa-paragraph-type="secondTitle"><div mpa-from-tpl="t" mpa-paragraph-type="secondTitle" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="27325" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div data-align="title" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;padding-right: 10px;padding-left: 10px;outline: 0px;background-color: rgba(0, 72, 191, 0.75);display: inline-block;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;display: flex;justify-content: center;align-items: center;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 10px;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;letter-spacing: 2px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(255, 255, 255);font-size: 16px;" mpa-is-content="t"><span leaf="">（二） 安全漏洞分布情况</span></span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">从厂商分布来看，Linux基金会新增漏洞最多，有91个。各厂商漏洞数量分布如表1所示。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表1 新增安全漏洞排名前五厂商统计表</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5822454308093995" data-s="300,640" data-type="png" data-w="383" data-imgfileid="503980834" src="https://wechat2rss.xlab.app/img-proxy/?k=0ac8b805&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuOZw5Efn8etufFDRREZXNox5BETxiaQRbbfZrttjn2uYFSlwvutaQWdN3iaoRmqbptxfWEbfYDY4bycSFDVXOfDTRHHd9ia9U9ibuKgOSiauamvg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">本周国内厂商漏洞65个，腾达公司漏洞数量最多，有16个。国内厂商漏洞整体修复率为32.31%。请受影响用户关注厂商修复情况，及时下载补丁修复漏洞。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">从漏洞类型来看，跨站脚本类的安全漏洞占比最大，达到8.47%。漏洞类型统计如表2所示。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表2 漏洞类型统计表</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="2.514360313315927" data-s="300,640" data-type="png" data-w="383" data-imgfileid="503980835" src="https://wechat2rss.xlab.app/img-proxy/?k=051c7d83&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuOZw5Efn8es6gTKVNvhrqBemFiaXtkyFFSiar2ia9BRnZex5Vxeh3By1htuFicswdvabOdsj55qalt7dLDvZNtLxmOwdk8ibX8bWHdbL00OfWDrg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-paragraph-type="secondTitle"><div mpa-from-tpl="t" mpa-paragraph-type="secondTitle" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="27325" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div data-align="title" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;padding-right: 10px;padding-left: 10px;outline: 0px;background-color: rgba(0, 72, 191, 0.75);display: inline-block;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;display: flex;justify-content: center;align-items: center;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 10px;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;letter-spacing: 2px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(255, 255, 255);font-size: 16px;" mpa-is-content="t"><span leaf="">（三） 安全漏洞危害等级与修复情况</span></span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">本周共发布超危漏洞82个，高危漏洞352个，中危漏洞805个，低危漏洞59个。相应修复率分别为85.37%、62.78%、69.32%和59.32%。根据补丁信息统计，合计884个漏洞已有修复补丁发布，整体修复率为68.10%。详细情况如表3所示。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表3 漏洞危害等级与修复情况</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5397590361445783" data-s="300,640" data-type="png" data-w="415" data-imgfileid="503980836" src="https://wechat2rss.xlab.app/img-proxy/?k=1473535a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuOZw5Efn8euvJYo9znpsiastNHdFBKPnF3IqPziaX50oKkYB0QyusqQMBH54Gzv8jgrnMibsdiaevrpbh41kEVOcLKpHuo384OslyichCe3LSOks%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-paragraph-type="secondTitle"><div mpa-from-tpl="t" mpa-paragraph-type="secondTitle" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="27325" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div data-align="title" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;padding-right: 10px;padding-left: 10px;outline: 0px;background-color: rgba(0, 72, 191, 0.75);display: inline-block;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;display: flex;justify-content: center;align-items: center;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 10px;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;letter-spacing: 2px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(255, 255, 255);font-size: 16px;" mpa-is-content="t"><span leaf="">（四） 本周重要漏洞实例</span></span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">本周重要漏洞实例如表4所示。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表4 本期重要漏洞实例</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4950166112956811" data-s="300,640" data-type="png" data-w="301" data-imgfileid="503980837" src="https://wechat2rss.xlab.app/img-proxy/?k=36226ca8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuOZw5Efn8evjXweCKNHk3pRBribibBEPTOC42jmxW84sNuND8qiaxhLclGqUCC8lNNV5AEZg9QXX1HhbWoicAMCzlMlqPRcWINj5KpFucbpdooE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">1. WordPress plugin Everest Forms Pro 代码注入漏洞（CNNVD-202603-6285）</span></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">WordPress和WordPress plugin都是WordPress基金会的产品。WordPress是一套使用PHP语言开发的博客平台，该平台具有在基于PHP和MySQL的服务器上架设个人博客网站的功能。WordPress plugin Everest Forms Pro是一个应用插件。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">WordPress plugin Everest Forms Pro 1.9.12版本及之前版本存在代码注入漏洞，该漏洞源于未正确转义用户提交的表单字段，攻击者利用该漏洞可以远程执行代码。</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">目前厂商已发布升级补丁以修复漏洞，参考链接：</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf=""><a href="https://wordpress.org/plugins/" target="_blank">https://wordpress.org/plugins/</a></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">2. Apache Airflow 信任管理问题漏洞（CNNVD-202603-5905）</span></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">Apache Airflow是美国阿帕奇（Apache）基金会的一套具有创建、管理和监控工作流程功能的开源平台，该平台具有可扩展和动态监控等功能。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">Apache Airflow 1.10.0至1.12.0之前版本存在信任管理问题漏洞，该漏洞源于对证书验证不当，攻击者利用该漏洞可以窃取凭据。</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">目前厂商已发布升级补丁以修复漏洞，参考链接：</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf=""><a href="https://lists.apache.org/thread/hn17yqsgsdtl81llvhf80rkp53hnz5nb" target="_blank">https://lists.apache.org/thread/hn17yqsgsdtl81llvhf80rkp53hnz5nb</a></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">3. Cisco Evolved Programmable Network Manager 安全漏洞（CNNVD-202604-096）</span></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">Cisco Evolved Programmable Network Manager是美国思科（Cisco）公司的一套网络管理解决方案。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">Cisco Evolved Programmable Network Manager存在安全漏洞，该漏洞源于对受影响设备REST API端点授权检查不当，攻击者利用该漏洞可以访问未授权的敏感信息。</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf="">目前厂商已发布升级补丁以修复漏洞，参考链接：</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf=""><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-epnm-improp-auth-mUwFWUU3" target="_blank">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-epnm-improp-auth-mUwFWUU3</a></span></p><div data-mpa-template="t" mpa-paragraph-type="secondTitle"><div mpa-from-tpl="t" mpa-paragraph-type="secondTitle" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="27325" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div data-align="title" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;padding-right: 10px;padding-left: 10px;outline: 0px;background-color: rgba(0, 72, 191, 0.75);display: inline-block;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;display: flex;justify-content: center;align-items: center;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-right: 10px;outline: 0px;"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;clear: both;min-height: 1em;letter-spacing: 2px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;color: rgb(255, 255, 255);font-size: 16px;" mpa-is-content="t"><span leaf="">（五） 本周重要人工智能漏洞实例</span></span></p></div></div></div></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">本周重要人工智能漏洞实例如表5所示。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表5 本期重要人工智能漏洞实例</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4950166112956811" data-s="300,640" data-type="png" data-w="301" data-imgfileid="503980838" src="https://wechat2rss.xlab.app/img-proxy/?k=73e07b5e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuOZw5Efn8evUNjL5AfdLCc4lGehr2WNbgfX6Lo1EwnicPQrPAlPD0jFthflzzK0uYt1KzhVafL8SZ7ib2rfWAF9pJqAu7utlBX4hg4ZiczgXnc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">1. OpenClaw 操作系统命令注入漏洞（CNNVD-202603-6234）</span></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">OpenClaw是一个开源的智能人工助理。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">OpenClaw 2026.3.13之前版本存在操作系统命令注入漏洞，该漏洞源于未对附件中包含的路径进行过滤和清理，攻击者利用该漏洞可以远程注入命令。</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">目前厂商已发布升级补丁以修复漏洞，参考链接：</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf=""><a href="https://github.com/openclaw/openclaw/releases" target="_blank">https://github.com/openclaw/openclaw/releases</a></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">2. NVIDIA BioNeMo 代码问题漏洞（CNNVD-202603-6154）</span></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">NVIDIA BioNeMo是美国英伟达（NVIDIA）公司的一个面向生物医药领域的生成式AI模型开发与训练平台。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">NVIDIA BioNeMo存在代码问题漏洞，该漏洞源于在处理用户输入或外部模型数据时没有对反序列化过程进行充分的验证，攻击者利用该漏洞可以执行代码、获取敏感信息和篡改数据。</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">目前厂商已发布升级补丁以修复漏洞，参考链接：</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf=""><a href="https://nvidia.custhelp.com/app/answers/detail/a_id/5808" target="_blank">https://nvidia.custhelp.com/app/answers/detail/a_id/5808</a></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span style="font-weight: 700;font-size: 16px;color: rgb(18, 93, 196);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">3. LangChain 安全漏洞（CNNVD-202603-6269）</span></span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">LangChain是一个开源的用于开发由大型语言模型（LLM）提供支持的应用软件框架。</span></p><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">LangChain 1.2.22之前版本存在安全漏洞，该漏洞源于未对目录遍历或绝对路径注入进行验证，攻击者利用该漏洞可以读取主机文件系统上的任意文件。</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf="">目前厂商已发布升级补丁以修复漏洞，参考链接：</span></p><p style="margin: 0px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span leaf=""><a href="https://github.com/langchain-ai/langchain/releases" target="_blank">https://github.com/langchain-ai/langchain/releases</a></span></p><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">二</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">漏洞平台推送情况</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">本周CNNVD接收漏洞平台推送漏洞3936个。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表6 本周漏洞平台推送情况</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4983388704318937" data-s="300,640" data-type="png" data-w="301" data-imgfileid="503980839" src="https://wechat2rss.xlab.app/img-proxy/?k=7e1456fb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuOZw5Efn8espBUAfeAOoEXZRbwicQiccuRAbnA55FlicdcHvIh9q1V1GLROyjJ4Et5mJb1T9JIJEjqswoUTb3xmF1AuKrsc4bibxqGTKdS0gdzk%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">三</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">接报漏洞情况</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">本周CNNVD接报漏洞797个，其中信息技术产品漏洞（通用型漏洞）769个，网络信息系统漏洞（事件型漏洞）28个。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表7 本周漏洞报送情况</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="6.615079365079365" data-s="300,640" data-type="png" data-w="504" data-imgfileid="503980842" src="https://wechat2rss.xlab.app/img-proxy/?k=b048ea03&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FuOZw5Efn8euCnhmGaw7iaKfTibvH39uWCoFkneoKefJlFSBr1OS1iakd5cEx8pUpoDG5Lt38ZzTMCkBAAdhxENuSrO4mmlMjd8P6Df3hmJxfuE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-paragraph-type="title"><div mpa-from-tpl="t" mpa-paragraph-type="title" style="-webkit-tap-highlight-color: transparent;margin-bottom: 24px;outline: 0px;color: rgba(0, 0, 0, 0.9);font-size: 17px;letter-spacing: 0.544px;text-align: justify;"><div data-support="96编辑器" data-style-id="2" mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><div mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;font-size: 16px;"><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;border-width: 0px;border-style: none;border-color: rgb(71, 122, 200);"><h2 style="-webkit-tap-highlight-color: transparent;margin-top: 8px;outline: 0px;font-weight: 400;font-size: 16px;line-height: 28px;color: rgb(71, 122, 200);min-height: 34px;border-bottom: 2px solid rgb(71, 122, 200);"><span data-form="0" data-num="2" data-digit="1" mpa-none-contnet="t" style="-webkit-tap-highlight-color: transparent;margin-right: 8px;padding: 4px 10px;outline: 0px;background-color: rgb(71, 122, 200);border-radius: 90% 90% 75% 10%;color: rgb(255, 255, 255);display: block;float: left;line-height: 20px;" mpa-none-content="t"><span leaf="">四</span></span><p mpa-from-tpl="t" style="-webkit-tap-highlight-color: transparent;margin-bottom: unset;outline: 0px;"><span style="-webkit-tap-highlight-color: transparent;outline: 0px;font-size: 18px;"><strong mpa-from-tpl="t" mpa-is-content="t" style="-webkit-tap-highlight-color: transparent;outline: 0px;"><span leaf="">收录漏洞通报情况</span></strong></span></p></h2></p></div></div></div></div><p style="margin: 0px 0px 16px;text-align: left;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;"><span leaf="">本周CNNVD收录漏洞通报229份。</span></p><p style="margin: 0px;text-align: center;color: rgb(0, 0, 0);letter-spacing: 0.5px;font-size: 16px;line-height: 1.75;" mpa-paragraph-type="body"><span style="font-weight: 400;font-size: 14px;color: rgb(0, 0, 0);letter-spacing: 0.5px;line-height: 1.75em;"><span leaf="">表8 本周漏洞通报情况</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="3.9846491228070176" data-s="300,640" data-type="png" data-w="456" data-imgfileid="503980843" src="https://wechat2rss.xlab.app/img-proxy/?k=384f984a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FuOZw5Efn8esrQPK9VPBDhh15OqV3icbCuEAfv75sMF6IXZPeVdAUMFmfAjIVtT0aZjLicy79LotxsTd5xT1B2MUteHboRGgTnmaYhe2YUQVqY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div data-mpa-template="t" mpa-paragraph-type="ignored"><div mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;margin-top: 10px;margin-bottom: 10px;outline: 0px;display: flex;flex-flow: row;text-align: left;justify-content: flex-start;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;flex: 0 0 auto;height: auto;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: flex;flex-flow: row;text-align: center;justify-content: center;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;display: inline-block;width: 45px;vertical-align: top;background-color: rgb(18, 93, 196);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;" mpa-from-tpl="t"><div style="-webkit-tap-highlight-color: transparent;outline: 0px;line-height: 0;" mpa-from-tpl="t"><p style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;display: inline-block;line-height: 0;width: 45px;height: auto;" mpa-from-tpl="t" nodeleaf=""><img data-aistatus="1" alt="图片" class="rich_pages wxw-img __bg_gif" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="-webkit-tap-highlight-color: transparent;outline: 0px;vertical-align: middle;height: auto !important;width: 45px !important;visibility: visible !important;" data-imgfileid="503963434" src="https://wechat2rss.xlab.app/img-proxy/?k=68515072&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2Fg1thw9GoocfpeKv1eicF4icEx1vUX4LQ1JMd8aMOqNkic25xydKvYcCVEsHXvm506icfXiaFep4AfohjraUj3F2jMfg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=d7fc2b87&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzAxODY1OTM5OQ%3D%3D%26mid%3D2651464494%26idx%3D1%26sn%3D0b5e5b630287cfb070129cd3f22f6c27">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 08 Apr 2026 16:54:00 +0800</pubDate>
    </item>
  </channel>
</rss>