Endpunktsicherheit
🟠 CVE-2026-90523: High Schwachstelle
A vulnerability was identified in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The affected element is an unknown function of the file...
🟠 CVE-2026-90769: High Schwachstelle
Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated users to perform server-side...
🟠 CVE-2026-90768: High Schwachstelle
CAPEv2 through commit 471ee4b fails to validate task ownership in REST API endpoints, allowing authenticated users to read and delete...
🟠 CVE-2026-90562: High Schwachstelle
LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the...
🟠 CVE-2026-90770: High Schwachstelle
Spug through 3.4.0 contains a remote code execution vulnerability in the ping_check function that interpolates user-supplied monitor addresses directly into...
🔴 CVE-2026-81648: Critical Schwachstelle
The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX...
Microsoft fixes Teams, Outlook launch failures on ARM Windows PCs
Microsoft has fixed a bug that prevented Teams and Outlook from launching on ARM-based Windows devices after installing updates released...
Hackers exploit Tencent app flaw to deploy GrayRabbit malware
Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method for...
🟠 CVE-2026-90647: High Schwachstelle
ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation vulnerability in the IEC...
🟠 CVE-2026-90678: High Schwachstelle
An issue was discovered in HAProxy 3.3.0 through 3.4.4 and in 3.5-dev1 through 3.5-dev5. Exploitation requires an HTTP/3 frontend: HAProxy...