Endpunktsicherheit

🟠 CVE-2026-56231: High Schwachstelle ENDPUNKTSICHERHEIT

🟠 CVE-2026-56231: High Schwachstelle

Capgo before 12.128.2 contains a broken object level authorization (BOLA) vulnerability in the POST /build/start/:jobId and POST /build/cancel/:jobId endpoints. The...

26. Juni 2026 Keine Kommentare
🟠 CVE-2026-56223: High Schwachstelle ENDPUNKTSICHERHEIT

🟠 CVE-2026-56223: High Schwachstelle

Capgo before 12.128.2 contains a cross-domain SSO account takeover vulnerability in the provision-user endpoint that allows attackers to merge arbitrary...

26. Juni 2026 Keine Kommentare
🔴 CVE-2026-56237: Critical Schwachstelle ENDPUNKTSICHERHEIT

🔴 CVE-2026-56237: Critical Schwachstelle

Capgo before 12.128.2 contains a broken authentication vulnerability in its API key generation mechanism. API keys are exposed in frontend...

26. Juni 2026 Keine Kommentare
Malicious Edge extension abuses Native Messaging as bridge to malware ENDPUNKTSICHERHEIT

Malicious Edge extension abuses Native Messaging as bridge to malware

A malicious Microsoft Edge extension dubbed 'Edgecution' has been used in a ransomware attack to escape the browser sandbox and...

25. Juni 2026 Keine Kommentare
Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered ENDPUNKTSICHERHEIT

Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered

A coordinated law enforcement operation, in partnership with private sector companies, including Bitdefender, Bitsight, ESET, and Microsoft, has resulted in...

25. Juni 2026 Keine Kommentare
🟠 CVE-2026-13007: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-13007: High Schwachstelle

Tenable Identity Exposure contains multiple unauthenticated API endpoints under /w/api/* that expose sensitive application configuration data including cleartext LDAP credentials,...

25. Juni 2026 Keine Kommentare
🟠 CVE-2026-56322: High Schwachstelle ENDPUNKTSICHERHEIT

🟠 CVE-2026-56322: High Schwachstelle

Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /updates endpoint that resolves the defaultChannel parameter before enforcing...

25. Juni 2026 Keine Kommentare
🟠 CVE-2026-56248: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-56248: High Schwachstelle

Cap-go capgo (capgo-backend) before 12.128.12 contains an unauthenticated denial-of-service vulnerability arising from the audit_logs table's Row-Level Security (RLS) policy when...

25. Juni 2026 Keine Kommentare
🟠 CVE-2026-45732: High Luecke in N8N N8N ANWENDUNGSSICHERHEIT

🟠 CVE-2026-45732: High Luecke in N8N N8N

n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, the OAuth1 and OAuth2 credential reconnect...

25. Juni 2026 Keine Kommentare
🟠 CVE-2026-56784: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-56784: High Schwachstelle

OpenRemote before 1.25.0 contains an insecure direct object reference (IDOR) vulnerability in the bulk alarm deletion endpoint that allows authenticated...

25. Juni 2026 Keine Kommentare