Anwendungssicherheit
ANWENDUNGSSICHERHEIT
On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email
Microsoft has disclosed a new security vulnerability impacting on-premise versions of Exchange Server that it said has come under active...
🟡 CVE-2026-48245: Medium Schwachstelle
Open ISES Tickets before 3.44.2 embeds a hardcoded Google Maps API key in tables.php that is committed to the public...
🟡 CVE-2026-48244: Medium Schwachstelle
Open ISES Tickets before 3.44.2 embeds a hardcoded Google Maps API key in settings.inc.php that is committed to the public...
🟡 CVE-2026-48243: Medium Schwachstelle
Open ISES Tickets before 3.44.2 embeds a hardcoded WhitePages reverse-phone API key in wp1.php that is committed to the public...
🟡 CVE-2026-22678: Medium Schwachstelle
Webmin before 2.641 contains a stored cross-site scripting vulnerability in the email template description field of the System and Server...
ANWENDUNGSSICHERHEIT
TanStack Supply Chain Attack Hits Two OpenAI Employee Devices, Forces macOS Updates
OpenAI has disclosed that two of its employee devices in its corporate environment were impacted via the Mini Shai-Hulud supply...
🔴 CVE-2026-39531: Critical Schwachstelle
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit WP Directory Kit...
ANWENDUNGSSICHERHEIT
Funnel Builder Flaw Under Active Exploitation Enables WooCommerce Checkout Skimming
A critical security vulnerability impacting the Funnel Builder plugin for WordPress has come under active exploitation in the wild to...
🔴 CVE-2026-48207: Critical Schwachstelle
Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documented DeserializationPolicy validation hooks during reduce-state restoration and...
🔴 CVE-2026-34910: Critical Schwachstelle
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices...