MEDIUMVulnerability
Global

EBA sets out plans to harmonise Sepa reporting

·Source: Finextra

Updated:

Executive Summary

The European Banking Authority (EBA) today published a Decision harmonising how National Competent Authorities (NCAs) report under the SEPA Regulation.

Analysis

The European Banking Authority (EBA) today published a Decision harmonising how National Competent Authorities (NCAs) report under the SEPA Regulation.
Source Attribution

Originally published by Finextra on Apr 13, 2026.

Related Threats

LOWVulnerabilityNEW

CVE-2026-107332 - Insecure default file permissions on cached credentials in AWS Toolkit for Visual Studio Code

<p><b>Bulletin ID:</b> 2026-129-AWS <br> <b>Scope:</b> AWS <br> <b>Content Type:</b> Important (requires attention) <br> <b>Publication Date:</b> 10/08/2026 10:30 PM PDT</p> <p><b>Description:</b></p> <p>AWS Toolkit for Visual Studio Code is an open source extension that lets developers work with AWS services, including Amazon CodeCatalyst, from within Visual Studio Code. We identified CVE-2026-10

CVE-2026-107332
AWS Security Bulletins
HIGHVulnerability

NVD HIGH: CVE-2026-104078 — Obsidian Desktop before 1.14.0 contains a filter bypass vulnerability in the bun...

Obsidian Desktop before 1.14.0 contains a filter bypass vulnerability in the bundled MathJax 3.2.2 Safe component that allows attackers to execute arbitrary code by embedding a crafted \href value with a TAB byte in the URL scheme, causing filterURL to produce an empty protocol that bypasses the configured safeProtocols restrictions. Attackers can craft a note containing a malicious MathJax formul

CVE-2026-104078
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-104077 — Obsidian Desktop before 1.14.0 contains a remote code execution vulnerability th...

Obsidian Desktop before 1.14.0 contains a remote code execution vulnerability that allows attackers to craft malicious Markdown notes exploiting insufficient sanitization of the data-background-iframe attribute, which bypasses DOMPurify and is processed by the bundled Reveal.js 4.3.1 within the Slides core plugin, allowing a javascript: URL to execute in the resulting background iframe. Because No

CVE-2026-104077
NIST NVD