Anwendungssicherheit
🟠 CVE-2026-50112: High Schwachstelle
SSRF via Metalink Mirror URL Resolution: An authenticated tenant can register a template pointing to an attacker-controlled metalink file containing...
🔴 CVE-2026-77776: Critical Schwachstelle
Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header is read directly at several points...
🔴 CVE-2026-77806: Critical Schwachstelle
SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This...
🔴 CVE-2026-77264: Critical Schwachstelle
The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication...
🔴 CVE-2026-62941: Critical Schwachstelle
Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an instance across projects, the...
🔴 CVE-2026-62940: Critical Schwachstelle
Incus is a system container and virtual machine manager. Prior to version 7.3.0, when migrating an instance to another cluster...
🔴 CVE-2026-62867: Critical Schwachstelle
Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation of user-provided `block.create_options` in storage...
🔴 CVE-2026-48755: Critical Schwachstelle
Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm...
🔴 CVE-2026-77683: Critical Schwachstelle
A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function system of the...
ANWENDUNGSSICHERHEIT
Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution
Update: The story was updated after publication to note that the vulnerability has not been exploited. Although the security bulletin...