+49 6151 6290246
image

Seven Critical Vulnerabilities in Apache Traffic Server (up to CVSS 10.0)

An advisory for Apache Traffic Server describes seven critical vulnerabilities, including CVE-2026-58150 and CVE-2026-58162 with a CVSS score of 10.0, as well as CVE-2026-58154/58155, with a CVSS score of 9.2. Patches are available.

CVE-2026-63227: Critical RCE Vulnerability in Koollab LMS (CVSS 9.9)

Analysis of the critical vulnerability CVE-2026-63227 (CVSS 9.9) in Koollab LMS. An insecure file upload allows remote code execution. A patch is available.

WordPress WooCommerce Plugins: Multiple Critical Security Vulnerabilities (CVE-2026-15014, CVE-2026-8457, CVE-2025-10656)

Critical vulnerabilities (CVE-2026-15014, CVE-2026-8457, CVE-2025-10656, CVSS 9.8; CVE-2026-3141, CVSS 9.1) in WordPress plugins for WooCommerce allow attackers to take over accounts, gain unauthorized access, and delete files.

CVE-2026-59549: Critical SQL injection in the WordPress plugin rtMedia

Analysis of the critical SQL injection vulnerability CVE-2026-59549 (CVSS 9.3) in the WordPress plugin rtMedia. Versions up to 4.7.10 are affected. Action required for administrators.

SolarWinds Serv-U: Multiple Critical Vulnerabilities (CVE-2026-28302, CVE-2026-16232)

On July 21, 2026, 15 critical vulnerabilities in SolarWinds Serv-U (CVE-2026-28302) were disclosed. In addition, CVE-2026-16232, CVE-2026-62144, and CVE-2026-62145 (CVSS 9.3) were disclosed. Updates are available.

CVE-2026-42533: Critical Vulnerability in NGINX Due to a Heap Buffer Overflow

Technical Analysis of the Critical Heap Buffer Overflow Vulnerability CVE-2026-42533 in NGINX. Affected Versions, Patches, and Mitigation Measures.

image

Drupal Modules: Critical Vulnerability Leading to Code Execution (CVE-2026-9726) and Information Disclosure (CVE-2026-10768)

Analysis of the critical RCE vulnerability CVE-2026-9726 (AlternativeCommerce Basket) and the information leak CVE-2026-10768 (LocalGov Workflows) in Drupal.

Microsoft Entra ID & Exchange/SharePoint: Multiple Critical Vulnerabilities (CVE-2026-55008, CVE-2026-56164, CVE-2026-55040)

Microsoft Entra ID is introducing passkeys as the default. At the same time, critical zero-day vulnerabilities were disclosed in SharePoint (CVE-2026-56164), AD FS (CVE-2026-55040, CVSS 9.1), and Exchange (CVE-2026-55008). Updates are available.

Microsoft Entra ID: Passkeys Will Become the Standard Starting in September 2026

Starting September 1, 2026, passkeys will become the default sign-in method in Microsoft Entra ID. Learn what the timeline and the phase-out of SMS mean for your organization.

IT Security Policy, Section 390 of SGB V: What Medical Practices Need to Know Now

The IT security policy under Section 390 of SGB V sets new standards for medical and dental practices. Learn about the applicable obligations and how to demonstrate compliance.

SAP Commerce Cloud & NetWeaver: Several Critical Security Vulnerabilities (CVE-2026-44761, CVE-2026-44747, CVE-2026-27690)

Analysis of Critical Vulnerabilities in SAP Commerce Cloud and NetWeaver (CVE-2026-44761 CVSS 9.1, CVE-2026-44747, CVE-2026-27690, CVSS 9.9). OAuth2 credentials, NetWeaver ABAP, and Approuter are affected. Details and mitigation steps.

Red Hat OpenShift AI: Multiple Critical Security Vulnerabilities (CVE-2026-15378, CVE-2026-15143)

Two critical SSRF vulnerabilities (CVE-2026-15378, CVE-2026-15143) with a CVSS score of 9.3 in Red Hat OpenShift AI allow attackers to gain unauthorized access to cloud and Kubernetes systems.


Want to find out more, book a demo or simply exchange ideas? We look forward to hearing from you!

Your personal consultantLukas BaumannCEO

+49 6151 6290246

Get in Touch Now

en_USEnglish