Endpunktsicherheit
🟠 CVE-2026-56258: High Schwachstelle
Crawl4AI before 0.8.8 contains an arbitrary file write vulnerability in the screenshot and PDF endpoints that allows unauthenticated attackers to...
🟠 CVE-2025-71337: High Schwachstelle
Flowise before 3.0.10 (affected versions 3.0.7 and earlier) contains an unverified email change vulnerability. An authenticated user can change the...
🟠 CVE-2026-33760: High Schwachstelle
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow's /api/v1/monitor router exposes 7...
ENDPUNKTSICHERHEIT
⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and More
It’s Monday again. This week’s threat list looks painfully familiar: abused integrations, fake tools, poisoned websites, ransomware crews trying to...
ENDPUNKTSICHERHEIT
Malicious npm Packages Pose as PostCSS Tools to Deliver Windows RAT
Cybersecurity researchers have discovered a set of malicious npm packages that are designed to deliver a Windows-based remote access trojan...
🟡 CVE-2026-6062: Medium Luecke in Mattermost Mattermost_Server
Mattermost versions 11.7.x
🟠 CVE-2026-42127: High Schwachstelle
The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory...
🟠 CVE-2026-42129: High Schwachstelle
The Loki datasource plugin's callResource handler contains a path traversal vulnerability. An authenticated Viewer-role user can escape the plugin's resource...
🟠 CVE-2026-54100: High Schwachstelle
A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH...
🟠 CVE-2026-56423: High Luecke in Misp-Project Misp
MISP Core contained broken access-control checks in the bulk deletion flows for Event Reports and Sharing Groups. The affected deleteSelection handlers authorized...