SchwachstelleSANS @RISK2026-07-30 00:00 UTC
@RISK®: The Consensus Security Vulnerability Alert: Vol. 26, Num. 29
Providing a reliable, weekly summary of newly discovered attack vectors, vulnerabilities with active exploits, and explanations of how recent attacks worked
Eigenanreicherung — kein Mirror der Originalquelle
Providing a reliable, weekly summary of newly discovered attack vectors, vulnerabilities with active exploits, and explanations of how recent attacks worked
Quelle: SANS @RISK. NEOSEC Intel zeigt aus lizenzrechtlichen Gründen keine 1:1-Spiegelung. Volltext und Experten-Einordnung beim Original.
Verknüpfte Empfehlungen
- CVE-2021-27137DD-WRT DD-WRT — DD-WRT Stack-Based Buffer Overflow Vulnerability
- CVE-2021-27137cvelistv5:CVE-2021-27137
- CVE-2025-43325CVE-2025-43325
- CVE-2025-43325Apple macOS (Tahoe, Sonoma und Sequoia): Mehrere Schwachstellen
- CVE-2025-43325Apple macOS Sequoia, Sonoma und Tahoe: Mehrere Schwachstellen
- CVE-2025-66390cve.org:CVE-2025-66390
- CVE-2025-66390cvelistv5:CVE-2025-66390
- CVE-2026-13072cvelistv5:CVE-2026-13072
- CVE-2026-13072cve.org:CVE-2026-13072
- CVE-2026-13072MongoDB: Mehrere Schwachstellen
- CVE-2026-16232Check Point SmartConsole: Mehrere Schwachstellen
- CVE-2026-16232Check Point SmartConsole — Check Point SmartConsole Improper Authentication Vulnerability
- CVE-2026-16232cvelistv5:CVE-2026-16232
- CVE-2026-16624cve.org:CVE-2026-16624
- CVE-2026-16624cvelistv5:CVE-2026-16624
- CVE-2026-16812Arista VeloCloud Orchestrator — Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability
- CVE-2026-16812cvelistv5:CVE-2026-16812
- CVE-2026-28302SolarWinds Serv-U: Mehrere Schwachstellen
- CVE-2026-28302cve.org:CVE-2026-28302
- CVE-2026-28302cvelistv5:CVE-2026-28302
- CVE-2026-28304cve.org:CVE-2026-28304
- CVE-2026-28304cvelistv5:CVE-2026-28304
- CVE-2026-28310cve.org:CVE-2026-28310
- CVE-2026-28310cvelistv5:CVE-2026-28310
- CVE-2026-28312cve.org:CVE-2026-28312
- CVE-2026-28312cvelistv5:CVE-2026-28312
- CVE-2026-28314cve.org:CVE-2026-28314
- CVE-2026-28314cvelistv5:CVE-2026-28314
- CVE-2026-28316cve.org:CVE-2026-28316
- CVE-2026-28316cvelistv5:CVE-2026-28316
- CVE-2026-28317cve.org:CVE-2026-28317
- CVE-2026-28317cvelistv5:CVE-2026-28317
- CVE-2026-28321cve.org:CVE-2026-28321
- CVE-2026-28321cvelistv5:CVE-2026-28321
- CVE-2026-28849cvelistv5:CVE-2026-28849
- CVE-2026-28849cve.org:CVE-2026-28849
- CVE-2026-28900cvelistv5:CVE-2026-28900
- CVE-2026-28900cve.org:CVE-2026-28900
- CVE-2026-28914cve.org:CVE-2026-28914
- CVE-2026-28914cvelistv5:CVE-2026-28914
- CVE-2026-28914A logic issue was addressed with improved file handling. This issue is fixed in macOS Tahoe 26.5. A maliciously crafted ZIP archive may bypass Gatekeeper che…
- CVE-2026-40712cvelistv5:CVE-2026-40712
- CVE-2026-40712cve.org:CVE-2026-40712
- CVE-2026-42533cve.org:CVE-2026-42533
- CVE-2026-42533NGINX NGINX Plus: Mehrere Schwachstellen
- CVE-2026-42533NGINX Map directive and Regex matching vulnerability
- CVE-2026-42533nginx vulnerabilities
- CVE-2026-42533nginx regression
- CVE-2026-42533NGINX Map directive and Regex matching vulnerability
- CVE-2026-42533NGINX Map directive and Regex matching vulnerability
- CVE-2026-42533cvelistv5:CVE-2026-42533
- CVE-2026-42990cve.org:CVE-2026-42990
- CVE-2026-42990cvelistv5:CVE-2026-42990
- CVE-2026-42990SQL Server ODBC driver Elevation of Privilege Vulnerability
- CVE-2026-42990Microsoft Windows Produkte: Mehrere Schwachstellen
- CVE-2026-46738cve.org:CVE-2026-46738
- CVE-2026-46738cvelistv5:CVE-2026-46738
- CVE-2026-47391PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool execution
- CVE-2026-47391cve.org:CVE-2026-47391
- CVE-2026-47391cvelistv5:CVE-2026-47391
- CVE-2026-47391PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool execution
- CVE-2026-47393PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default
- CVE-2026-47393cve.org:CVE-2026-47393
- CVE-2026-47393cvelistv5:CVE-2026-47393
- CVE-2026-47393PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default
- CVE-2026-47396PraisonAI call server exposes unauthenticated agent listing, invocation, and deletion when CALL_SERVER_TOKEN is unset
- CVE-2026-47396PraisonAI call server exposes unauthenticated agent listing, invocation, and deletion when CALL_SERVER_TOKEN is unset
- CVE-2026-47396cve.org:CVE-2026-47396
- CVE-2026-47396cvelistv5:CVE-2026-47396
- CVE-2026-47410cve.org:CVE-2026-47410
- CVE-2026-47410cvelistv5:CVE-2026-47410
- CVE-2026-47410praisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-me", allowing token forgery for any user when PLATFORM_ENV is unset
- CVE-2026-47410praisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-me", allowing token forgery for any user when PLATFORM_ENV is unset
- CVE-2026-47413praisonai-platform: Any workspace member can add arbitrary user as owner via POST /workspaces/{id}/members
- CVE-2026-47413praisonai-platform: Any workspace member can add arbitrary user as owner via POST /workspaces/{id}/members
- CVE-2026-47413cve.org:CVE-2026-47413
- CVE-2026-47413cvelistv5:CVE-2026-47413
- CVE-2026-47416praisonai-platform: Any workspace member can promote themselves or others to owner via PATCH /workspaces/{id}/members/{user_id}
- CVE-2026-47416praisonai-platform: Any workspace member can promote themselves or others to owner via PATCH /workspaces/{id}/members/{user_id}
- CVE-2026-47416cve.org:CVE-2026-47416
- CVE-2026-47416cvelistv5:CVE-2026-47416
- CVE-2026-47668DbGate: Unauthenticated Remote Code Execution via JSON Script Runner
- CVE-2026-47668cve.org:CVE-2026-47668
- CVE-2026-47668cvelistv5:CVE-2026-47668
- CVE-2026-50447cve.org:CVE-2026-50447
- CVE-2026-50447cvelistv5:CVE-2026-50447
- CVE-2026-50447Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability
- CVE-2026-50517cve.org:CVE-2026-50517
- CVE-2026-50517Microsoft Azure, Copilot, Exchange, Surface: Mehrere Schwachstellen
- CVE-2026-50517cvelistv5:CVE-2026-50517
- CVE-2026-50517Microsoft M365 Copilot Remote Code Execution Vulnerability
- CVE-2026-54120Microsoft Surface Remote Code Execution Vulnerability
- CVE-2026-54120cve.org:CVE-2026-54120
- CVE-2026-54120cvelistv5:CVE-2026-54120
- CVE-2026-56159cve.org:CVE-2026-56159
- CVE-2026-56159DHCP Server Service Remote Code Execution Vulnerability
- CVE-2026-56159cvelistv5:CVE-2026-56159
- CVE-2026-56163Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
- CVE-2026-56163cvelistv5:CVE-2026-56163
- CVE-2026-56163cve.org:CVE-2026-56163
- CVE-2026-56165cve.org:CVE-2026-56165
- CVE-2026-56165cvelistv5:CVE-2026-56165
- CVE-2026-56165Microsoft Account Remote Code Execution Vulnerability
- CVE-2026-56191cve.org:CVE-2026-56191
- CVE-2026-56191Microsoft Exchange Online Tampering Vulnerability
- CVE-2026-56191cvelistv5:CVE-2026-56191
- CVE-2026-57106Data Quality Elevation of Privilege Vulnerability
- CVE-2026-57106cve.org:CVE-2026-57106
- CVE-2026-57106cvelistv5:CVE-2026-57106
- CVE-2026-58275cve.org:CVE-2026-58275
- CVE-2026-58275Azure DNS Elevation of Privilege Vulnerability
- CVE-2026-58275cvelistv5:CVE-2026-58275
- CVE-2026-58630cve.org:CVE-2026-58630
- CVE-2026-58630Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability
- CVE-2026-58630cvelistv5:CVE-2026-58630
- CVE-2026-60137cvelistv5:CVE-2026-60137
- CVE-2026-60137WordPress Core — WordPress Core SQL Injection Vulnerability
- CVE-2026-60137WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
- CVE-2026-60137WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
- CVE-2026-60137WordPress: Mehrere Schwachstellen ermöglichen Codeausführung
- CVE-2026-60137Debian wordpress: security update
- CVE-2026-62144cve.org:CVE-2026-62144
- CVE-2026-62144cvelistv5:CVE-2026-62144
- CVE-2026-62825Azure Key Vault Elevation of Privilege Vulnerability
- CVE-2026-62825cvelistv5:CVE-2026-62825
- CVE-2026-62825cve.org:CVE-2026-62825
- CVE-2026-62835cvelistv5:CVE-2026-62835
- CVE-2026-62835Microsoft Azure Portal: Schwachstelle ermöglicht Offenlegung von Informationen
- CVE-2026-62835Azure Portal Information Disclosure Vulnerability
- CVE-2026-62835cve.org:CVE-2026-62835
- CVE-2026-63030cvelistv5:CVE-2026-63030
- CVE-2026-63030WordPress Core — WordPress Core Interpretation Conflict Vulnerability
- CVE-2026-63030WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
- CVE-2026-63030WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
- CVE-2026-64319cvelistv5:CVE-2026-64319
- CVE-2026-64319Linux Kernel: Mehrere Schwachstellen
- CVE-2026-64319nvmet-auth: validate reply message payload bounds against transfer length
- CVE-2026-64319cve.org:CVE-2026-64319
- CVE-2026-64606cve.org:CVE-2026-64606
- CVE-2026-64606cvelistv5:CVE-2026-64606
- CVE-2026-64608cvelistv5:CVE-2026-64608
- CVE-2026-64608cve.org:CVE-2026-64608
- CVE-2026-64609cve.org:CVE-2026-64609
- CVE-2026-64609cvelistv5:CVE-2026-64609
- CVE-2026-64812cve.org:CVE-2026-64812
- CVE-2026-64812cvelistv5:CVE-2026-64812
- CVE-2026-64812JetBrains IntelliJ IDEA: Mehrere Schwachstellen
- CVE-2026-64813cve.org:CVE-2026-64813
- CVE-2026-64813cvelistv5:CVE-2026-64813
- CVE-2026-64878cvelistv5:CVE-2026-64878
- CVE-2026-64878cve.org:CVE-2026-64878
- CVE-2026-64879cve.org:CVE-2026-64879
- CVE-2026-64879cvelistv5:CVE-2026-64879
- CVE-2026-65008cve.org:CVE-2026-65008
- CVE-2026-65008cvelistv5:CVE-2026-65008
- CVE-2026-65057cve.org:CVE-2026-65057
- CVE-2026-65057cvelistv5:CVE-2026-65057
- CVE-2026-6516cve.org:CVE-2026-6516
- CVE-2026-6516cvelistv5:CVE-2026-6516
- CVE-2026-65590n8n: computer-use Shell Sandbox Not Enforced on Linux and Windows
- CVE-2026-65590cvelistv5:CVE-2026-65590
- CVE-2026-65590cve.org:CVE-2026-65590
- CVE-2026-65605cve.org:CVE-2026-65605
- CVE-2026-65605cvelistv5:CVE-2026-65605
- CVE-2026-65606cve.org:CVE-2026-65606
- CVE-2026-65606cvelistv5:CVE-2026-65606
- CVE-2026-65687cve.org:CVE-2026-65687
- CVE-2026-65687cvelistv5:CVE-2026-65687
- CVE-2026-65689cve.org:CVE-2026-65689
- CVE-2026-65689cvelistv5:CVE-2026-65689
- CVE-2026-65907cvelistv5:CVE-2026-65907
- CVE-2026-65907cve.org:CVE-2026-65907
- CVE-2026-65907JetBrains TeamCity: Mehrere Schwachstellen ermöglichen Codeausführung
Mehr zu @RISK®
Weitere News-Einträge
- Schwachstellesans-atrisk-mail2026-08-27@RISK®: The Consensus Security Vulnerability Alert: Vol. 26, Num. 33
- Schwachstellesans-atrisk-mail2026-08-20@RISK®: The Consensus Security Vulnerability Alert: Vol. 26, Num. 32
- Schwachstellesans-atrisk-mail2026-08-13@RISK®: The Consensus Security Vulnerability Alert: Vol. 26, Num. 31
- Schwachstellesans-atrisk-mail2026-08-06@RISK®: The Consensus Security Vulnerability Alert: Vol. 26, Num. 30
- Schwachstellesans-atrisk-mail2026-07-23@RISK®: The Consensus Security Vulnerability Alert: Vol. 26, Num. 28
- Schwachstellesans-atrisk-mail2026-07-16@RISK®: The Consensus Security Vulnerability Alert: Vol. 26, Num. 27
- Schwachstellesans-atrisk-mail2026-07-09@RISK®: The Consensus Security Vulnerability Alert: Vol. 26, Num. 26
- Schwachstellesans-atrisk-mail2026-06-25@RISK®: The Consensus Security Vulnerability Alert: Vol. 26, Num. 25
ID