Situational news & topics

Current cyber situation from curated feeds

Aggregated from BSI Bürger-CERT, BSI WID, SANS NewsBites, Krebs on Security, The Hacker News and the Allianz für Cyber-Sicherheit.

All news

Editorial

From the blog

Blog

Latest priority advisories

Ranked by priority score — KEV, EPSS, CVSS, recency and CPE relevance.

  • CVE-2023-46604

    [UPDATE] [KEV] [high] Atlassian Produkte (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, und Jira): Mehrere Schwachstellen

    The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or the broker (respectively) to instantiate any class on the classpath. Users are recommended to upgrade both brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3 which fixes this issue.

    Actively exploited2026-09-04 09:58 UTC
  • CVE-2026-21962

    [KEV] [critical] Oracle Fusion Middleware: Mehrere Schwachstellen

    Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in. While the vulnerability is in Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data. Note: Affected version for Weblogic Server Proxy Plug-in for IIS is 12.2.1.4.0 only. CVSS 3.1 Base Score 10.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).

    Actively exploitedCritical2026-08-25 06:16 UTC
  • CVE-2024-38475

    [UPDATE] [KEV] [high] Oracle Communications: Mehrere Schwachstellen

    Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure. Substitutions in server context that use a backreferences or variables as the first segment of the substitution are affected.  Some unsafe RewiteRules will be broken by this change and the rewrite flag "UnsafePrefixStat" can be used to opt back in once ensuring the substitution is appropriately constrained.

    Actively exploited2026-08-12 07:51 UTC
  • CVE-2026-72898

    [UPDATE] [KEV] metabase: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CVE-2026-72898)

    Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.

    Actively exploited2026-08-10 17:55 UTC
  • CVE-2026-48907

    [KEV] [critical] Widget Factory Joomla Content Editor: Schwachstelle ermöglicht Codeausführung

    A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.

    Actively exploitedCritical2026-06-18 10:19 UTC
  • CVE-2026-20079

    [NEW] [KEV] [critical] Cisco Secure Firewall Management Center: Mehrere Schwachstellen

    A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.  This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device. 

    Actively exploitedCritical2026-09-10 09:11 UTC
NEOSEC Intel — NEOSEC Intel