+49 6151 6290246
image

CVE-2026-42533: Critical Vulnerability in NGINX Due to a Heap Buffer Overflow

Technical Analysis of the Critical Heap Buffer Overflow Vulnerability CVE-2026-42533 in NGINX. Affected Versions, Patches, and Mitigation Measures.

Critical RCE Vulnerability in WordPress Core (CVE-2026-63030)

A critical vulnerability (CVE-2026-63030) in WordPress Core allows unauthenticated remote code execution. Versions up to 7.0.1 are affected. Action is required.

Drupal Modules: Critical Vulnerability Leading to Code Execution (CVE-2026-9726) and Information Disclosure (CVE-2026-10768)

Analysis of the critical RCE vulnerability CVE-2026-9726 (AlternativeCommerce Basket) and the information leak CVE-2026-10768 (LocalGov Workflows) in Drupal.

Microsoft Entra ID & Exchange/SharePoint: Multiple Critical Vulnerabilities (CVE-2026-55008, CVE-2026-56164, CVE-2026-55040)

Microsoft Entra ID is introducing passkeys as the default. At the same time, critical zero-day vulnerabilities were disclosed in SharePoint (CVE-2026-56164), AD FS (CVE-2026-55040, CVSS 9.1), and Exchange (CVE-2026-55008). Updates are available.

Microsoft Entra ID: Passkeys Will Become the Standard Starting in September 2026

Starting September 1, 2026, passkeys will become the default sign-in method in Microsoft Entra ID. Learn what the timeline and the phase-out of SMS mean for your organization.

IT Security Policy, Section 390 of SGB V: What Medical Practices Need to Know Now

The IT security policy under Section 390 of SGB V sets new standards for medical and dental practices. Learn about the applicable obligations and how to demonstrate compliance.

image

Red Hat OpenShift AI: Multiple Critical Security Vulnerabilities (CVE-2026-15378, CVE-2026-15143)

Two critical SSRF vulnerabilities (CVE-2026-15378, CVE-2026-15143) with a CVSS score of 9.3 in Red Hat OpenShift AI allow attackers to gain unauthorized access to cloud and Kubernetes systems.

Microsoft 365: Phishing Campaign Bypasses MFA by Exploiting the OAuth Protocol

Phishing campaigns exploit the Microsoft 365 OAuth device code flow to take over accounts. The ARToken Kit and a Ghost phishing variant bypass standard MFA. Analysis and protective measures.

WPFunnels: Critical RCE Vulnerability (CVE-2026-14345, CVSS 9.8)

Critical RCE vulnerability (CVSS 9.8) in the WordPress plugin WPFunnels: CVE-2026-14345 allows unauthenticated code execution. Update to version 3.12.8.

Plesk: Multiple Critical Security Vulnerabilities (CVE-2026-48614, CVE-2026-56843)

Critical vulnerabilities in Plesk (CVE-2026-48614, CVE-2026-56843, CVSS 9.9) allow for privilege escalation and password disclosure. A patch is available for CVE-2026-56843.

Adobe ColdFusion: Multiple Critical Security Vulnerabilities (CVE-2026-48316, CVE-2026-48282)

Analysis of critical vulnerabilities in Adobe ColdFusion (CVSS 10.0), including CVE-2026-48316 and CVE-2026-48282. CISA warns of active exploitation. Patches are available.

Gitea: Three Critical Security Vulnerabilities (CVE-2026-58426, -20896, -22874)

Three critical Gitea vulnerabilities: CVE-2026-58426 (data access), CVE-2026-20896 (account takeover), CVE-2026-22874 (SSRF). Updating to version 1.26.4 is recommended.


Want to find out more, book a demo or simply exchange ideas? We look forward to hearing from you!

Your personal consultantLukas BaumannCEO

+49 6151 6290246

Get in Touch Now

en_USEnglish