Endpunktsicherheit
🟡 CVE-2026-86255: Medium Schwachstelle
wger before 2.5 fails to validate the maximum duration of routine date ranges, allowing authenticated users to create routines spanning...
New CrowdStrike ‚FalconFlank‘ zero-day grants SYSTEM privileges
An anonymous security researcher who uses the "Nightmare Eclipse" handle released a CrowdStrike Falcon zero-day exploit named "FalconFlank" that lets...
ENDPUNKTSICHERHEIT
Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on...
🟠 CVE-2026-86173: High Schwachstelle
MindsDB through 26.1.0 contains a server-side request forgery vulnerability in the web crawler handler that allows unauthenticated attackers to fetch...
🟠 CVE-2026-86119: High Schwachstelle
Webstudio through 0.296.0 contains an unauthenticated server-side request forgery vulnerability in the /cgi/image, /cgi/video, and /cgi/asset proxy routes when RESIZE_ORIGIN...
🟠 CVE-2026-86123: High Schwachstelle
SQL Chat contains four unauthenticated API endpoints that accept client-supplied database connection parameters and execute arbitrary SQL queries against attacker-specified...
🔴 CVE-2026-86190: Critical Schwachstelle
WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery...
🔴 CVE-2026-86184: Critical Schwachstelle
Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to authenticate as...
🔴 CVE-2026-86121: Critical Schwachstelle
Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is unset and bind to all interfaces by...
ENDPUNKTSICHERHEIT
Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks
Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads....