Netzwerksicherheit

🟠 CVE-2026-86185: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-86185: High Schwachstelle

Bilibili Desktop through 1.18.0 disables TLS certificate verification process-wide and executes unsigned remote JavaScript configuration without integrity checks. An attacker...

07. Sep. 2026 Keine Kommentare
🟠 CVE-2026-86119: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-86119: High Schwachstelle

Webstudio through 0.296.0 contains an unauthenticated server-side request forgery vulnerability in the /cgi/image, /cgi/video, and /cgi/asset proxy routes when RESIZE_ORIGIN...

07. Sep. 2026 Keine Kommentare
🟠 CVE-2026-86123: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-86123: High Schwachstelle

SQL Chat contains four unauthenticated API endpoints that accept client-supplied database connection parameters and execute arbitrary SQL queries against attacker-specified...

07. Sep. 2026 Keine Kommentare
⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More NETZWERKSICHERHEIT

⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More

The boring parts caused most of the trouble. A router shipped ready to listen. A fake check turned the user...

06. Sep. 2026 Keine Kommentare
Authorities Turn Sality’s P2P Network Against Itself, Cutting Off New Malware Payloads NETZWERKSICHERHEIT

Authorities Turn Sality’s P2P Network Against Itself, Cutting Off New Malware Payloads

The U.S. Department of Justice (DoJ) on Tuesday announced the takedown of a long-standing peer-to-peer (P2P) botnet known as Sality...

06. Sep. 2026 Keine Kommentare
🟡 CVE-2026-81666: Medium Schwachstelle NETZWERKSICHERHEIT

🟡 CVE-2026-81666: Medium Schwachstelle

An integer overflow was found in Corosync's handling of membership commit token messages. The length-validation check for these messages can...

06. Sep. 2026 Keine Kommentare
🟠 CVE-2026-19224: High Schwachstelle NETZWERKSICHERHEIT

🟠 CVE-2026-19224: High Schwachstelle

The Hummingbird Performance WordPress plugin before 3.21.2 does not restrict a network-wide setting to network administrators, allowing an administrator of...

06. Sep. 2026 Keine Kommentare
🟠 CVE-2026-85609: High Schwachstelle CLOUD-SICHERHEIT

🟠 CVE-2026-85609: High Schwachstelle

Openpanel before 2.3.0 contains an unauthenticated full-read server-side request forgery (SSRF) vulnerability in the GET /tools/site-checker endpoint (apps/api/src/controllers/tools.controller.ts). Th...

06. Sep. 2026 Keine Kommentare
🟠 CVE-2026-76169: High Schwachstelle NETZWERKSICHERHEIT

🟠 CVE-2026-76169: High Schwachstelle

fastify versions >= 4.0.0 and before 5.12.2 can route a malformed URL sent under one plugin prefix to the custom...

06. Sep. 2026 Keine Kommentare
🟠 CVE-2026-81665: High Schwachstelle NETZWERKSICHERHEIT

🟠 CVE-2026-81665: High Schwachstelle

A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembly. When processing fragmented multicast messages, the...

06. Sep. 2026 Keine Kommentare