Netzwerksicherheit
🟠 CVE-2026-74882: High Schwachstelle
openssl_encrypt versions before 1.4.0 contain an insecure default configuration that trusts the entire RFC 1918 private address space in IntegrityProxyConfig...
🟠 CVE-2026-16138: High Schwachstelle
In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted file metadata can allow a user...
🟠 CVE-2026-74802: High Schwachstelle
SiYuan versions before 3.7.4 contain a cross-site WebSocket hijacking vulnerability in the admin-only /ws/network/proxy endpoint that explicitly disables origin validation...
🔴 CVE-2026-74895: Critical Schwachstelle
openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process isolation mode for plugin execution. Attackers can...
🔴 CVE-2026-74891: Critical Schwachstelle
openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server configuration files. Attackers on the same network can access...
NETZWERKSICHERHEIT
Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies
Cybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed Evooo1Bot that derives its core functionality from the Mirai...
NETZWERKSICHERHEIT
Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic
Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers...
🟠 CVE-2026-18653: High Schwachstelle
The WP Directory Kit WordPress plugin before 1.5.7 does not sanitise and escape a parameter before using it in a...
🟠 CVE-2026-17533: High Schwachstelle
The All-in-One WP Migration and Backup WordPress plugin before 7.108 does not restrict its migration import functionality to network administrators...
🟠 CVE-2026-19982: High Schwachstelle
A security vulnerability has been detected in GL.iNet BE9300 and MT6000 4.8.x. This vulnerability affects unknown code of the component...