Exchange-Sicherheitslücke: Wegen Proof-of-Concept Angriffe wahrscheinlich
Für eine hochriskante Lücke in Exchange, die die Systemübernahme erlaubt, ist Exploit-Code erschienen. Admins müssen updaten. Weiterlesen
Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
Exchange-Sicherheitslücke: Wegen Proof-of-Concept Angriffe wahrscheinlich
Für eine hochriskante Lücke in Exchange, die die Systemübernahme erlaubt, ist Exploit-Code erschienen. Admins müssen updaten. Weiterlesen
AppEnumGuard v1.2
CVE-2025-31207 mitigation and sandboxed tester for rootless and rootHide jailbreaks on iOS 15–18.4.1 Weiterlesen
Veeam ONE mit kritischer Schwachstelle CVE-2026-65641 (CVSS 9.3)
[English]Kurze Information für Nutzer und Administratoren, die auf Veeam ONE setzen. Es gibt eine kritische Schwachstelle CVE-2026-65641 (CVSS 9.3) in Veeam ONE, die eventuell Anmeldedaten verrät. Veeam ONE sollte daher unverzüglich auf die
Sicherheitslücken in Microsoft SharePoint werden von Hackern angegriffen
Das Sicherheitsunternehmen Defused warnt davor, dass Hacker begonnen haben, zwei kritische Sicherheitslücken in Microsoft SharePoint mit den Bezeichnungen CVE-2026-55040 und CVE-2026-63520 auszunutzen. Laut Bleeping Computer sind weltweit m
Exchange-Sicherheitslücke: Wegen Proof-of-Concept Angriffe wahrscheinlich
Für eine hochriskante Lücke in Exchange, die die Systemübernahme erlaubt, ist Exploit-Code erschienen. Admins müssen updaten. Weiterlesen
AppEnumGuard v1.2
CVE-2025-31207 mitigation and sandboxed tester for rootless and rootHide jailbreaks on iOS 15–18.4.1 Weiterlesen
USN-8666-2: Linux kernel (Azure) vulnerabilities
Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A physically proximate atta
USN-8681-1: OpenJDK 25 vulnerabilities
It was discovered that the JSSE component of OpenJDK 25 did not correctly authenticate users. A remote attacker could possibly use this issue to read or modify sensitive data. (CVE-2026-46968) It was discovered that the JSSE component of Op
USN-8682-1: Bind vulnerabilities
Vitaly Simonovich discovered that Bind could exhaust memory during GSS-API TKEY negotiation. A remote attacker could possibly use this issue to cause Bind to use excessive resources, leading to a denial of service. (CVE-2026-3039) Shuhan Zh
USN-8683-1: libheif vulnerabilities
Feng Ning discovered that libheif incorrectly handled certain image transforms. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.
USN-8684-1: Perl vulnerabilities
It was discovered that Perl incorrectly handled certain arguments to Socket and pack/unpack functions. An attacker could possibly use this issue to read sensitive information from memory. (CVE-2026-12087, CVE-2026-57432) It was discovered t
USN-8686-1: openCryptoki vulnerabilities
It was discovered that primitive decoders in openCryptoki produced integer underflows when the encoded length was zero. An attacker could possibly use this issue to trigger out-of-bounds reads. (CVE-2026-40253) It was discovered that openCr
USN-8687-1: p11-kit vulnerabilities
It was discovered that p11-kit incorrectly handled certain RPC messages. A local attacker could use this issue to cause p11-kit to crash, resulting in a denial of service. (CVE-2026-13757) It was discovered that p11-kit incorrectly handled
USN-8666-2: Linux kernel (Azure) vulnerabilities
Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A physically proximate atta
USN-8681-1: OpenJDK 25 vulnerabilities
It was discovered that the JSSE component of OpenJDK 25 did not correctly authenticate users. A remote attacker could possibly use this issue to read or modify sensitive data. (CVE-2026-46968) It was discovered that the JSSE component of Op
USN-8682-1: Bind vulnerabilities
Vitaly Simonovich discovered that Bind could exhaust memory during GSS-API TKEY negotiation. A remote attacker could possibly use this issue to cause Bind to use excessive resources, leading to a denial of service. (CVE-2026-3039) Shuhan Zh
USN-8683-1: libheif vulnerabilities
Feng Ning discovered that libheif incorrectly handled certain image transforms. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.
USN-8684-1: Perl vulnerabilities
It was discovered that Perl incorrectly handled certain arguments to Socket and pack/unpack functions. An attacker could possibly use this issue to read sensitive information from memory. (CVE-2026-12087, CVE-2026-57432) It was discovered t
USN-8686-1: openCryptoki vulnerabilities
It was discovered that primitive decoders in openCryptoki produced integer underflows when the encoded length was zero. An attacker could possibly use this issue to trigger out-of-bounds reads. (CVE-2026-40253) It was discovered that openCr
USN-8687-1: p11-kit vulnerabilities
It was discovered that p11-kit incorrectly handled certain RPC messages. A local attacker could use this issue to cause p11-kit to crash, resulting in a denial of service. (CVE-2026-13757) It was discovered that p11-kit incorrectly handled
USN-8666-2: Linux kernel (Azure) vulnerabilities
Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A physically proximate atta
USN-8681-1: OpenJDK 25 vulnerabilities
It was discovered that the JSSE component of OpenJDK 25 did not correctly authenticate users. A remote attacker could possibly use this issue to read or modify sensitive data. (CVE-2026-46968) It was discovered that the JSSE component of Op
USN-8682-1: Bind vulnerabilities
Vitaly Simonovich discovered that Bind could exhaust memory during GSS-API TKEY negotiation. A remote attacker could possibly use this issue to cause Bind to use excessive resources, leading to a denial of service. (CVE-2026-3039) Shuhan Zh
USN-8683-1: libheif vulnerabilities
Feng Ning discovered that libheif incorrectly handled certain image transforms. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.
USN-8684-1: Perl vulnerabilities
It was discovered that Perl incorrectly handled certain arguments to Socket and pack/unpack functions. An attacker could possibly use this issue to read sensitive information from memory. (CVE-2026-12087, CVE-2026-57432) It was discovered t
USN-8686-1: openCryptoki vulnerabilities
It was discovered that primitive decoders in openCryptoki produced integer underflows when the encoded length was zero. An attacker could possibly use this issue to trigger out-of-bounds reads. (CVE-2026-40253) It was discovered that openCr
USN-8687-1: p11-kit vulnerabilities
It was discovered that p11-kit incorrectly handled certain RPC messages. A local attacker could use this issue to cause p11-kit to crash, resulting in a denial of service. (CVE-2026-13757) It was discovered that p11-kit incorrectly handled
DSA-6463-1 webkit2gtk - security update
The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2026-43804 Heiko Kiesel discovered that visiting a website may lead to an app denial-of-service. CVE-2026-64713 Kwak Kiyong and Song Nuri discovered that we
USN-8666-2: Linux kernel (Azure) vulnerabilities
Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A physically proximate atta
USN-8681-1: OpenJDK 25 vulnerabilities
It was discovered that the JSSE component of OpenJDK 25 did not correctly authenticate users. A remote attacker could possibly use this issue to read or modify sensitive data. (CVE-2026-46968) It was discovered that the JSSE component of Op
USN-8682-1: Bind vulnerabilities
Vitaly Simonovich discovered that Bind could exhaust memory during GSS-API TKEY negotiation. A remote attacker could possibly use this issue to cause Bind to use excessive resources, leading to a denial of service. (CVE-2026-3039) Shuhan Zh
USN-8683-1: libheif vulnerabilities
Feng Ning discovered that libheif incorrectly handled certain image transforms. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.
USN-8684-1: Perl vulnerabilities
It was discovered that Perl incorrectly handled certain arguments to Socket and pack/unpack functions. An attacker could possibly use this issue to read sensitive information from memory. (CVE-2026-12087, CVE-2026-57432) It was discovered t
USN-8686-1: openCryptoki vulnerabilities
It was discovered that primitive decoders in openCryptoki produced integer underflows when the encoded length was zero. An attacker could possibly use this issue to trigger out-of-bounds reads. (CVE-2026-40253) It was discovered that openCr
USN-8687-1: p11-kit vulnerabilities
It was discovered that p11-kit incorrectly handled certain RPC messages. A local attacker could use this issue to cause p11-kit to crash, resulting in a denial of service. (CVE-2026-13757) It was discovered that p11-kit incorrectly handled
DSA-6463-1 webkit2gtk - security update
The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2026-43804 Heiko Kiesel discovered that visiting a website may lead to an app denial-of-service. CVE-2026-64713 Kwak Kiyong and Song Nuri discovered that we