SchwachstelleSANS @RISK2026-06-18 00:00 UTC
@RISK®: The Consensus Security Vulnerability Alert: Vol. 26, Num. 24
Providing a reliable, weekly summary of newly discovered attack vectors, vulnerabilities with active exploits, and explanations of how recent attacks worked
Eigenanreicherung — kein Mirror der Originalquelle
Providing a reliable, weekly summary of newly discovered attack vectors, vulnerabilities with active exploits, and explanations of how recent attacks worked
Quelle: SANS @RISK. NEOSEC Intel zeigt aus lizenzrechtlichen Gründen keine 1:1-Spiegelung. Volltext und Experten-Einordnung beim Original.
Verknüpfte Empfehlungen
- CVE-2025-10263AMD ARM und EPYC Prozessoren: Mehrere Schwachstellen
- CVE-2025-10263ARM: CVE-2025-10263 Completion of affected memory accesses might not be guaranteed by completion of a TLBI [kernel]
- CVE-2026-10520Ivanti Sentry — Ivanti Sentry OS Command Injection Vulnerability
- CVE-2026-11645Google Chrome / Microsoft Edge: Mehrere Schwachstellen
- CVE-2026-11645Google Chromium V8 — Google Chromium V8 Out-of-Bounds Read and Write Vulnerability
- CVE-2026-11645Debian chromium: security update
- CVE-2026-11645Chromium: CVE-2026-11645 Out of bounds memory access in V8
- CVE-2026-12027Google Chrome / Microsoft Edge: Mehrere Schwachstellen
- CVE-2026-12027Debian chromium: security update
- CVE-2026-12027cve.org:CVE-2026-12027
- CVE-2026-20253Splunk Enterprise: Mehrere Schwachstellen
- CVE-2026-20253Splunk Enterprise — Splunk Enterprise Missing Authentication for Critical Function Vulnerability
- CVE-2026-20262cvelistv5:CVE-2026-20262
- CVE-2026-20262Cisco SD-WAN Manager: Schwachstelle ermöglicht Manipulation von Dateien
- CVE-2026-20262Cisco Catalyst SD-WAN Manager — Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability
- CVE-2026-25089Fortinet FortiSandbox: Schwachstelle ermöglicht Befehlsausführung
- CVE-2026-25089Fortinet FortiSandbox — Fortinet FortiSandbox OS Command Injection Vulnerability
- CVE-2026-26142cvelistv5:CVE-2026-26142
- CVE-2026-26142Nuance PowerScribe Remote Code Execution Vulnerability
- CVE-2026-26240cvelistv5:CVE-2026-26240
- CVE-2026-26240QNAP NAS: Mehrere Schwachstellen
- CVE-2026-26241cvelistv5:CVE-2026-26241
- CVE-2026-30120cve.org:CVE-2026-30120
- CVE-2026-30121cve.org:CVE-2026-30121
- CVE-2026-34182OpenSSL: Mehrere Schwachstellen
- CVE-2026-34182Debian openssl: security update
- CVE-2026-34182cve.org:CVE-2026-34182
- CVE-2026-34182OpenSSL vulnerabilities
- CVE-2026-34182OpenSSL vulnerabilities
- CVE-2026-34182CMS AuthEnvelopedData Processing May Accept Forged Messages
- CVE-2026-35273Oracle PeopleSoft Enterprise PeopleTools — Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability
- CVE-2026-42904cvelistv5:CVE-2026-42904
- CVE-2026-42904Windows TCP/IP Elevation of Privilege Vulnerability
- CVE-2026-44170cvelistv5:CVE-2026-44170
- CVE-2026-44170MariaDB: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff
- CVE-2026-44172cve.org:CVE-2026-44172
- CVE-2026-44172MariaDB: mysql_real_escape_string() incorrectly handled big5
- CVE-2026-44172MariaDB: mysql_real_escape_string() incorrectly handled big5
- CVE-2026-44172MariaDB: mysql_real_escape_string() incorrectly handled big5
- CVE-2026-44631Apache HTTP Server: Mehrere Schwachstellen
- CVE-2026-44631cve.org:CVE-2026-44631
- CVE-2026-44631Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflow
- CVE-2026-44815cvelistv5:CVE-2026-44815
- CVE-2026-44815DHCP Client Service Remote Code Execution Vulnerability
- CVE-2026-44990Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`
- CVE-2026-44990cve.org:CVE-2026-44990
- CVE-2026-45602cvelistv5:CVE-2026-45602
- CVE-2026-45602Windows Dynamic Host Configuration Protocol (DHCP) Tampering Vulnerability
- CVE-2026-45657cvelistv5:CVE-2026-45657
- CVE-2026-45657Windows Kernel Remote Code Execution Vulnerability
- CVE-2026-46316Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service
- CVE-2026-46316cve.org:CVE-2026-46316
- CVE-2026-46614Fission router exposes /fission-function/<ns>/<name> on its public listener, allowing invocation of any function without an HTTPTrigger
- CVE-2026-46614cve.org:CVE-2026-46614
- CVE-2026-46716Nezha Monitoring: RoleMember can run shell on every server (cross-tenant RCE) via POST /api/v1/cron
- CVE-2026-46716cve.org:CVE-2026-46716
- CVE-2026-47131vm2: Mehrere Schwachstellen
- CVE-2026-47131cve.org:CVE-2026-47131
- CVE-2026-47137cve.org:CVE-2026-47137
- CVE-2026-47140cve.org:CVE-2026-47140
- CVE-2026-47208cve.org:CVE-2026-47208
- CVE-2026-47281cvelistv5:CVE-2026-47281
- CVE-2026-47281Visual Studio Code Elevation of Privilege Vulnerability
- CVE-2026-47281Microsoft DeveloperTools: Mehrere Schwachstellen
- CVE-2026-47291cvelistv5:CVE-2026-47291
- CVE-2026-47291HTTP.sys Remote Code Execution Vulnerability
- CVE-2026-47643cvelistv5:CVE-2026-47643
- CVE-2026-47643cve.org:CVE-2026-47643
- CVE-2026-47643Azure Stack Edge Remote Code Execution Vulnerability
- CVE-2026-48713cve.org:CVE-2026-48713
- CVE-2026-48714cve.org:CVE-2026-48714
- CVE-2026-49261MariaDB: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff
- CVE-2026-49261cve.org:CVE-2026-49261
- CVE-2026-49261MariaDB server has unsafe parameter handling in `wsrep_notify_cmd`
- CVE-2026-49261MariaDB server has unsafe parameter handling in `wsrep_notify_cmd`
- CVE-2026-49261MariaDB server has unsafe parameter handling in `wsrep_notify_cmd`
- CVE-2026-53471cve.org:CVE-2026-53471
- CVE-2026-54420LiteSpeed cPanel Plugin — LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability
- CVE-2026-9698Debian libdbi-perl: security update
- CVE-2026-9698cve.org:CVE-2026-9698
- CVE-2026-9698DBI versions before 1.648 for Perl saved errors in a limited-sized buffer
Mehr zu @RISK®
Weitere News-Einträge
- Schwachstellesans-atrisk-mail2026-08-27@RISK®: The Consensus Security Vulnerability Alert: Vol. 26, Num. 33
- Schwachstellesans-atrisk-mail2026-08-20@RISK®: The Consensus Security Vulnerability Alert: Vol. 26, Num. 32
- Schwachstellesans-atrisk-mail2026-08-13@RISK®: The Consensus Security Vulnerability Alert: Vol. 26, Num. 31
- Schwachstellesans-atrisk-mail2026-08-06@RISK®: The Consensus Security Vulnerability Alert: Vol. 26, Num. 30
- Schwachstellesans-atrisk-mail2026-07-30@RISK®: The Consensus Security Vulnerability Alert: Vol. 26, Num. 29
- Schwachstellesans-atrisk-mail2026-07-23@RISK®: The Consensus Security Vulnerability Alert: Vol. 26, Num. 28
- Schwachstellesans-atrisk-mail2026-07-16@RISK®: The Consensus Security Vulnerability Alert: Vol. 26, Num. 27
- Schwachstellesans-atrisk-mail2026-07-09@RISK®: The Consensus Security Vulnerability Alert: Vol. 26, Num. 26
ID