Endpunktsicherheit

Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers ENDPUNKTSICHERHEIT

Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers

Enterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle, Hacking Cat, and Toy...

17. Sep. 2026 Keine Kommentare
🟡 CVE-2026-62280: Medium Schwachstelle ANWENDUNGSSICHERHEIT

🟡 CVE-2026-62280: Medium Schwachstelle

Open Access Management (OpenAM) is an access management solution. From 13.0.0 until 16.1.2, the OAuth2 authorize endpoint's display=wap consent page...

17. Sep. 2026 Keine Kommentare
🟡 CVE-2026-91994: Medium Schwachstelle ANWENDUNGSSICHERHEIT

🟡 CVE-2026-91994: Medium Schwachstelle

Semaphore UI through 2.19.12 exempts GET and HEAD requests from project resource permission checks in GetMustCanMiddleware. Attackers with guest or...

17. Sep. 2026 Keine Kommentare
🟡 CVE-2026-89141: Medium Schwachstelle ENDPUNKTSICHERHEIT

🟡 CVE-2026-89141: Medium Schwachstelle

The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Insecure Direct...

17. Sep. 2026 Keine Kommentare
🟠 CVE-2026-75092: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-75092: High Schwachstelle

A privilege escalation flaw was found in the scan_mysql actor of leapp-upgrade-el9toel10 (provided by leapp-repository). During RHEL 9 to RHEL...

17. Sep. 2026 Keine Kommentare
🟠 CVE-2026-91923: High Schwachstelle ENDPUNKTSICHERHEIT

🟠 CVE-2026-91923: High Schwachstelle

KubeSphere through 4.1.3 contains a server-side request forgery vulnerability in the git credential verification endpoint that accepts unvalidated caller-supplied URLs...

17. Sep. 2026 Keine Kommentare
🟠 CVE-2026-57112: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-57112: High Schwachstelle

PraisonAI is a multi-agent teams system. From praisonaiagents 0.6.0 until 1.6.59 and PraisonAI 3.10.0 until 4.6.59, ToolsMCPServer.run_sse() in src/praisonai-agents/praisonaiagents/mcp/mcp_server.py m...

17. Sep. 2026 Keine Kommentare
🟠 CVE-2026-91924: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-91924: High Schwachstelle

pgweb through 0.17.0 leaves the POST /api/connect endpoint unguarded when connect-backend authorization is configured, allowing attackers to supply arbitrary database...

17. Sep. 2026 Keine Kommentare
🟠 CVE-2026-45048: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-45048: High Schwachstelle

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, SessionRequestHandler in the session management endpoint does not...

17. Sep. 2026 Keine Kommentare
🔴 CVE-2026-62379: Critical Schwachstelle ENDPUNKTSICHERHEIT

🔴 CVE-2026-62379: Critical Schwachstelle

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentication /authservice PLL endpoint accepts a CustomCallback...

17. Sep. 2026 Keine Kommentare