🛡️ tsecurity.de
Zur Startseite 🔖 Lesezeichen
🎯 FOKUSSIERTE SCHWACHSTELLE: CVE-2026-42167 CRITICAL 9.5 🔥 EPSS 76.5%
Alle CVEs anzeigen ✕

[remote] CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE

CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE Weiterlesen

Angriffsvektor: 🌐 Netzwerk (Remote) • 🔓 Keine Authentifizierung nötig
CWE-Klassifizierung: CWE-89: SQL Injection
🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

🟢 SSE Realtime Synchronisiert ⚡ REST API (JSON) 📡 RSS Feed
Ökosystem & Hersteller Bedrohungs-Matrix:
Generic Security 28
WordPress 4
Linux 4
Microsoft 4
Apache 2
Schweregrad & Status:
Hersteller-Filter:
🔍
CRITICAL 9.5 🔥 EPSS 76.5%
Generic Security
CVE-2026-42167 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

[remote] CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE

CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE Weiterlesen

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
CRITICAL 9.5 🔥 EPSS 76.5%
Generic Security
CVE-2026-42167 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

[remote] CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE

CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE Weiterlesen

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
HIGH 7.5 🔥 EPSS 25.5%
Generic Security
CVE-2026-60004 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Gitea flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Oracle HTTP Server and Oracle Weblogic Se

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
CRITICAL 9.8 🔥 EPSS 89.5%
⚠️ CISA KEV Generic Security
CVE-2026-60004 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004)

Attackers have begun exploiting CVE-2026-60004, a critical code injection vulnerability in the Gitea Git platform, CISA confirmed on Tuesday by adding the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. The KEV entry doe

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
HIGH 7.5 🔥 EPSS 30.2%
Generic Security
CVE-2026-73570 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

Exploited Zimbra Flaw Highlights Shrinking Window to Patch

CISA issued a three-day deadline for agencies to patch a Zimbra security vulnerability, CVE-2026-73570, which allows full takeover of a user's communications. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
HIGH 7.5 🔥 EPSS 30.2%
Generic Security
CVE-2026-73570 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

Exploited Zimbra Flaw Highlights Shrinking Window to Patch

CISA issued a three-day deadline for agencies to patch a Zimbra security vulnerability, CVE-2026-73570, which allows full takeover of a user's communications. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
CRITICAL 9.5 🔥 EPSS 64.4%
Generic Security
CVE-2026-18963 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any user account by forcing

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
CRITICAL 9.8 🔥 EPSS 95.4%
⚠️ CISA KEV Generic Security
CVE-2026-21962 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
CRITICAL 9.5 🔥 EPSS 57.5%
WordPress
CVE-2026-61979 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as any WordPress user, including administrato

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
CRITICAL 9.5 🔥 EPSS 64.4%
Generic Security
CVE-2026-18963 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any user account by forcing

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
CRITICAL 9.8 🔥 EPSS 95.4%
⚠️ CISA KEV Generic Security
CVE-2026-21962 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
CRITICAL 9.8 🔥 EPSS 89.5%
⚠️ CISA KEV Generic Security
CVE-2026-60004 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation efforts targeting a recently patched critical security flaw impacting Gitea. The vulnerability in question is CVE-2026-60004 (CVSS sco

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
CRITICAL 9.5 🔥 EPSS 57.5%
WordPress
CVE-2026-61979 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as any WordPress user, including administrato

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
CRITICAL 9.5 🔥 EPSS 77.4%
Generic Security
CVE-2026-19912 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code

The CERT Coordination Center (CERT/CC) has disclosed two unpatched vulnerabilities in Kaltura's HTML5 video player library that allow a remote, unauthenticated attacker to read arbitrary files from a server and execute code on it. The

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
HIGH 7.5 🔥 EPSS 28.6%
Linux
CVE-2019-1068 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScale

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
CRITICAL 9.8 🔥 EPSS 89.5%
⚠️ CISA KEV Generic Security
CVE-2026-60004 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation efforts targeting a recently patched critical security flaw impacting Gitea. The vulnerability in question is CVE-2026-60004 (CVSS sco

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
CRITICAL 9.5 🔥 EPSS 77.4%
Generic Security
CVE-2026-19912 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code

The CERT Coordination Center (CERT/CC) has disclosed two unpatched vulnerabilities in Kaltura's HTML5 video player library that allow a remote, unauthenticated attacker to read arbitrary files from a server and execute code on it. The

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
HIGH 7.5 🔥 EPSS 28.6%
Linux
CVE-2019-1068 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScale

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 28.7%
Apache
CVE-2021-44228 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

Vulnerability Management: Process, Tools and Best Practices for Enterprise (2026)

By HOC Team  |  Last updated: August 2026  |  Read time: ~24 min In December 2021, the Apache Log4Shell vulnerability (CVE-2021-44228) was published. Within 12 hours, scanning for vulnerable systems had begun at scale. Within 72 hours, expl

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
HIGH 7.5 🔥 EPSS 28.7%
Apache
CVE-2021-44228 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

Vulnerability Management: Process, Tools and Best Practices for Enterprise (2026)

By HOC Team  |  Last updated: August 2026  |  Read time: ~24 min In December 2021, the Apache Log4Shell vulnerability (CVE-2021-44228) was published. Within 12 hours, scanning for vulnerable systems had begun at scale. Within 72 hours, expl

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
CRITICAL 9.8 🔥 EPSS 95.4%
⚠️ CISA KEV Microsoft
CVE-2026-21962 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw

The US Cybersecurity and Infrastructure Security Agency (CISA) just dished out another three-day deadline for patching an actively exploited vulnerability, the most urgent in its wheelhouse. The culprit: a max-severity Oracle bug affecting

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
CRITICAL 9.8 🔥 EPSS 95.4%
⚠️ CISA KEV Microsoft
CVE-2026-21962 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw

The US Cybersecurity and Infrastructure Security Agency (CISA) just dished out another three-day deadline for patching an actively exploited vulnerability, the most urgent in its wheelhouse. The culprit: a max-severity Oracle bug affecting

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
CRITICAL 9.5 🔥 EPSS 67.5%
Generic Security
CVE-2026-60004 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

CISA Warns of Exploited Gitea Vulnerability

CVE-2026-60004 is a remote code execution vulnerability patched by Gitea developers in late July with the release of version 1.27.1. The post CISA Warns of Exploited Gitea Vulnerability appeared first on SecurityWeek. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
CRITICAL 9.5 🔥 EPSS 67.5%
Generic Security
CVE-2026-60004 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

CISA Warns of Exploited Gitea Vulnerability

CVE-2026-60004 is a remote code execution vulnerability patched by Gitea developers in late July with the release of version 1.27.1. The post CISA Warns of Exploited Gitea Vulnerability appeared first on SecurityWeek. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
CRITICAL 9.8 🔥 EPSS 87.1%
⚠️ CISA KEV Generic Security
CVE-2026-8452 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

Recent Citrix NetScaler Vulnerability Exploited in the Wild

CISA is urging government agencies to immediately patch the Citrix NetScaler vulnerability tracked as CVE-2026-8452. The post Recent Citrix NetScaler Vulnerability Exploited in the Wild appeared first on SecurityWeek. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
CRITICAL 9.8 🔥 EPSS 87.1%
⚠️ CISA KEV Generic Security
CVE-2026-8452 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

Recent Citrix NetScaler Vulnerability Exploited in the Wild

CISA is urging government agencies to immediately patch the Citrix NetScaler vulnerability tracked as CVE-2026-8452. The post Recent Citrix NetScaler Vulnerability Exploited in the Wild appeared first on SecurityWeek. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
CRITICAL 9.5 🔥 EPSS 64.4%
Generic Security
CVE-2026-18963 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any user account by forcing

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
CRITICAL 9.5 🔥 EPSS 64.4%
Generic Security
CVE-2026-18963 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any user account by forcing

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
CRITICAL 9.8 🔥 EPSS 95.4%
⚠️ CISA KEV Generic Security
CVE-2026-21962 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
CRITICAL 9.5 🔥 EPSS 57.5%
WordPress
CVE-2026-61979 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as any WordPress user, including administrato

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
CRITICAL 9.8 🔥 EPSS 95.4%
⚠️ CISA KEV Generic Security
CVE-2026-21962 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
CRITICAL 9.5 🔥 EPSS 57.5%
WordPress
CVE-2026-61979 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as any WordPress user, including administrato

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
CRITICAL 9.8 🔥 EPSS 89.5%
⚠️ CISA KEV Generic Security
CVE-2026-60004 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation efforts targeting a recently patched critical security flaw impacting Gitea. The vulnerability in question is CVE-2026-60004 (CVSS sco

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
CRITICAL 9.5 🔥 EPSS 77.4%
Generic Security
CVE-2026-19912 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code

The CERT Coordination Center (CERT/CC) has disclosed two unpatched vulnerabilities in Kaltura's HTML5 video player library that allow a remote, unauthenticated attacker to read arbitrary files from a server and execute code on it. The

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
CRITICAL 9.8 🔥 EPSS 89.5%
⚠️ CISA KEV Generic Security
CVE-2026-60004 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation efforts targeting a recently patched critical security flaw impacting Gitea. The vulnerability in question is CVE-2026-60004 (CVSS sco

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
HIGH 7.5 🔥 EPSS 28.6%
Linux
CVE-2019-1068 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScale

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
CRITICAL 9.5 🔥 EPSS 77.4%
Generic Security
CVE-2026-19912 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code

The CERT Coordination Center (CERT/CC) has disclosed two unpatched vulnerabilities in Kaltura's HTML5 video player library that allow a remote, unauthenticated attacker to read arbitrary files from a server and execute code on it. The

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
HIGH 7.5 🔥 EPSS 28.6%
Linux
CVE-2019-1068 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScale

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
CRITICAL 9.8 🔥 EPSS 95.4%
⚠️ CISA KEV Microsoft
CVE-2026-21962 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw

The US Cybersecurity and Infrastructure Security Agency (CISA) just dished out another three-day deadline for patching an actively exploited vulnerability, the most urgent in its wheelhouse. The culprit: a max-severity Oracle bug affecting

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
CRITICAL 9.8 🔥 EPSS 95.4%
⚠️ CISA KEV Microsoft
CVE-2026-21962 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw

The US Cybersecurity and Infrastructure Security Agency (CISA) just dished out another three-day deadline for patching an actively exploited vulnerability, the most urgent in its wheelhouse. The culprit: a max-severity Oracle bug affecting

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
CRITICAL 9.3 🔥 EPSS 69.6%
Generic Security
CVE-2026-65641 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

Veeam ONE mit kritischer Schwachstelle CVE-2026-65641 (CVSS 9.3)

[English]Kurze Information für Nutzer und Administratoren, die auf Veeam ONE setzen. Es gibt eine kritische Schwachstelle CVE-2026-65641 (CVSS 9.3) in Veeam ONE, die eventuell Anmeldedaten verrät. Veeam ONE sollte daher unverzüglich auf die

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
CRITICAL 9.3 🔥 EPSS 69.6%
Generic Security
CVE-2026-65641 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

Veeam ONE mit kritischer Schwachstelle CVE-2026-65641 (CVSS 9.3)

[English]Kurze Information für Nutzer und Administratoren, die auf Veeam ONE setzen. Es gibt eine kritische Schwachstelle CVE-2026-65641 (CVSS 9.3) in Veeam ONE, die eventuell Anmeldedaten verrät. Veeam ONE sollte daher unverzüglich auf die

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.