Endpunktsicherheit
🟠 CVE-2026-65310: High Schwachstelle
ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configuration endpoint without any...
🟠 CVE-2026-14319: High Schwachstelle
The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurring-donation records,...
🟠 CVE-2026-56672: High Schwachstelle
ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/{file} served user-controlled HTML and SVG...
🟠 CVE-2026-56670: High Schwachstelle
ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, the /view endpoint...
🟠 CVE-2026-16236: High Schwachstelle
The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5.3.0....
🔴 CVE-2026-14483: Critical Schwachstelle
The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all...
ENDPUNKTSICHERHEIT
HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked...
ENDPUNKTSICHERHEIT
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT)...
🟠 CVE-2026-16524: High Schwachstelle
A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric. This failed validation lets...
🟠 CVE-2026-16526: High Schwachstelle
A flaw in the PCP linux_sockets module exposes an unsecured internal connection. An attacker with initial code execution can exploit...