Cloud-Sicherheit
🟡 CVE-2026-11397: Medium Schwachstelle
The WP Import Export Lite plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to and...
🟠 CVE-2026-10055: High Schwachstelle
In Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker-controlled URL from any client connected to the...
🔴 CVE-2026-20896: Critical Schwachstelle
Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a...
CLOUD-SICHERHEIT
‚Cordyceps‘: Mushrooming Malicious Pull Requests Threaten Developer Workflows
The CI/CD workflow weakness affects Microsoft's Azure Sentinel, Google's AI Agent Development Kit, Apache's Doris analytics database, Cloudflare's Workers SDK,...
CLOUD-SICHERHEIT
Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices
Security firm runZero has disclosed seven vulnerabilities in FatFs, a small filesystem library that lets a device read and write the FAT and...
CLOUD-SICHERHEIT
‚Cordyceps‘: Mushrooming Malicious Pull Requests Threaten Developer Workflows
The CI/CD workflow weakness affects Microsoft's Azure Sentinel, Google's AI Agent Development Kit, Apache's Doris analytics database, Cloudflare's Workers SDK,...
CLOUD-SICHERHEIT
Microsoft Accelerates Post-Quantum Cryptography Shift to 2029
Microsoft on Tuesday said it's accelerating its quantum safe security roadmap, stating technology advances in quantum computing are making it...
CLOUD-SICHERHEIT
Critical Cursor Flaws Could Let Prompt Injection Escape Sandbox and Run Commands
Two flaws in Cursor, an AI code editor, could let a single, ordinary-looking prompt break out of the editor's safety...
CLOUD-SICHERHEIT
Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign Classic
Adobe has released patches for multiple maximum-severity security flaws impacting Adobe ColdFusion and Adobe Campaign Classic. The ColdFusion updates "resolves...
🟠 CVE-2026-27957: High Schwachstelle
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, an authenticated command injection...