Endpunktsicherheit
🟠 CVE-2026-35563: High Luecke in Apache Directory_Ldap_Api
It was identified that the LDAP client implementation in version 2.1.7 does not verify if the server certificate matches the...
🟠 CVE-2026-49298: High Luecke in Apache Airflow
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to...
🟠 CVE-2026-42359: High Luecke in Apache Airflow
A bug in Apache Airflow's XCom PATCH endpoint `PATCH /api/v2/xcomEntries/{key}` allowed an authenticated UI/API user with XCom write permission on...
Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks
A threat actor tracked as DriveSurge has been operating large-scale malware distribution campaigns using ClickFix and FakeUpdates techniques on compromised...
ENDPUNKTSICHERHEIT
OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack
Cybersecurity researchers have disclosed details of a new malicious supply chain campaign that's targeting developers using OpenAI Codex through a...
🟡 CVE-2026-10177: Medium Schwachstelle
A security vulnerability has been detected in Aider-AI Aider 0.86.3. This affects the function requests.get of the file api_docs.py of...
🟡 CVE-2026-45192: Medium Luecke in Apache Airflow
A bug in the GET `/api/v2/connections/{connection_id}` REST API endpoint in Apache Airflow allowed an authenticated UI/API user with Connection-read permission...
🟠 CVE-2026-10243: High Schwachstelle
A security vulnerability has been detected in code-projects Smart Parking System 1.0. Affected is an unknown function of the component...
🟠 CVE-2026-10236: High Schwachstelle
A vulnerability has been found in SourceCodester Water Billing Management System 1.0. This issue affects some unknown processing of the...
🟠 CVE-2026-32325: High Schwachstelle
Privilege chaining issue exists in ServerView Agents for Windows V11.60.04 and earlier. If this vulnerability is exploited, a local authenticated...