CVE-2026-58066: Critical Vulnerability in Rocket.Chat Allows Account Takeover
A critical vulnerability (CVE-2026-58066) in Rocket.Chat with a CVSS score of 9.8 allows attackers to take over any account via SAML SSO. Patches are available.
Seven Critical Vulnerabilities in Apache Traffic Server (up to CVSS 10.0)
An advisory for Apache Traffic Server describes seven critical vulnerabilities, including CVE-2026-58150 and CVE-2026-58162 with a CVSS score of 10.0, as well as CVE-2026-58154/58155, with a CVSS score of 9.2. Patches are available.
CVE-2026-63227: Critical RCE Vulnerability in Koollab LMS (CVSS 9.9)
Analysis of the critical vulnerability CVE-2026-63227 (CVSS 9.9) in Koollab LMS. An insecure file upload allows remote code execution. A patch is available.
WordPress WooCommerce Plugins: Multiple Critical Security Vulnerabilities (CVE-2026-15014, CVE-2026-8457, CVE-2025-10656)
Critical vulnerabilities (CVE-2026-15014, CVE-2026-8457, CVE-2025-10656, CVSS 9.8; CVE-2026-3141, CVSS 9.1) in WordPress plugins for WooCommerce allow attackers to take over accounts, gain unauthorized access, and delete files.
CVE-2026-59549: Critical SQL injection in the WordPress plugin rtMedia
Analysis of the critical SQL injection vulnerability CVE-2026-59549 (CVSS 9.3) in the WordPress plugin rtMedia. Versions up to 4.7.10 are affected. Action required for administrators.
SolarWinds Serv-U: Multiple Critical Vulnerabilities (CVE-2026-28302, CVE-2026-16232)
On July 21, 2026, 15 critical vulnerabilities in SolarWinds Serv-U (CVE-2026-28302) were disclosed. In addition, CVE-2026-16232, CVE-2026-62144, and CVE-2026-62145 (CVSS 9.3) were disclosed. Updates are available.
CVE-2026-42533: Critical Vulnerability in NGINX Due to a Heap Buffer Overflow
Technical Analysis of the Critical Heap Buffer Overflow Vulnerability CVE-2026-42533 in NGINX. Affected Versions, Patches, and Mitigation Measures.
Critical RCE Vulnerability in WordPress Core (CVE-2026-63030)
A critical vulnerability (CVE-2026-63030) in WordPress Core allows unauthenticated remote code execution. Versions up to 7.0.1 are affected. Action is required.
Drupal Modules: Critical Vulnerability Leading to Code Execution (CVE-2026-9726) and Information Disclosure (CVE-2026-10768)
Analysis of the critical RCE vulnerability CVE-2026-9726 (AlternativeCommerce Basket) and the information leak CVE-2026-10768 (LocalGov Workflows) in Drupal.
Microsoft Entra ID & Exchange/SharePoint: Multiple Critical Vulnerabilities (CVE-2026-55008, CVE-2026-56164, CVE-2026-55040)
Microsoft Entra ID is introducing passkeys as the default. At the same time, critical zero-day vulnerabilities were disclosed in SharePoint (CVE-2026-56164), AD FS (CVE-2026-55040, CVSS 9.1), and Exchange (CVE-2026-55008). Updates are available.
Microsoft Entra ID: Passkeys Will Become the Standard Starting in September 2026
Starting September 1, 2026, passkeys will become the default sign-in method in Microsoft Entra ID. Learn what the timeline and the phase-out of SMS mean for your organization.
IT Security Policy, Section 390 of SGB V: What Medical Practices Need to Know Now
The IT security policy under Section 390 of SGB V sets new standards for medical and dental practices. Learn about the applicable obligations and how to demonstrate compliance.
SAP Commerce Cloud & NetWeaver: Several Critical Security Vulnerabilities (CVE-2026-44761, CVE-2026-44747, CVE-2026-27690)
Analysis of Critical Vulnerabilities in SAP Commerce Cloud and NetWeaver (CVE-2026-44761 CVSS 9.1, CVE-2026-44747, CVE-2026-27690, CVSS 9.9). OAuth2 credentials, NetWeaver ABAP, and Approuter are affected. Details and mitigation steps.
Red Hat OpenShift AI: Multiple Critical Security Vulnerabilities (CVE-2026-15378, CVE-2026-15143)
Two critical SSRF vulnerabilities (CVE-2026-15378, CVE-2026-15143) with a CVSS score of 9.3 in Red Hat OpenShift AI allow attackers to gain unauthorized access to cloud and Kubernetes systems.



