KRITIS-Nachweispflicht nach § 39 BSIG: Die wichtigsten Änderungen für Betreiber
Das BSI-Gesetz (BSIG) ändert mit § 39 die Nachweispflichten für KRITIS-Betreiber. Erfahren Sie, was der neue 3-Jahres-Zyklus und das Mängel-Monitoring bedeuten.
CVE-2026-18691: Vulnerability in MongoDB Server Allows Takeover of Cluster Nodes
Analysis of the critical vulnerability CVE-2026-18691 (CVSS 9.0) in MongoDB Server. Details on the risk of compromise to replica sets and recommended actions.
CVE-2026-58231: Critical Vulnerability in SAP Commerce Cloud (CVSS 10.0)
Analyse der kritischen RCE-Schwachstelle CVE-2026-58231 (CVSS 10.0) in SAP Commerce Cloud. Betroffene Versionen, verfügbare Patches und empfohlene Maßnahmen für Unternehmen.
Critical Vulnerabilities in WordPress Plugins (CVE-2026-28005, CVE-2026-6235)
Critical vulnerabilities (CVE-2026-28005, CVE-2026-6235, CVSS 9.8) in the WordPress plugins Kadence WooCommerce Email Designer and Sendmachine allow unauthenticated privilege escalation.
CVE-2026-66447: Critical SQL Injection in the WordPress File Upload Plugin
Analysis of the critical vulnerability CVE-2026-66447 (CVSS 9.3) in the WordPress File Upload plugin. Affected versions include <= 5.1.7. Details and Actions.
IT Security Status in Under 30 Seconds: Instant Overview with the LocateRisk MCP Interface
AI-Powered IT Security Analysis When senior management requests an assessment of the IT security situation on short notice, every minute counts. LocateRisk provides an interface based on the Model Context Protocol (MCP) for this purpose. As currently the only provider in the field of External Attack Surface Management (EASM), LocateRisk enables direct machine-to-machine communication between the security platform and artificial intelligence. The result: a comprehensive, presentation-ready overview of the external attack surface in under 30 seconds.
CVE-2026-41452: Critical Vulnerability in Krayin CRM Allows Account Takeover
A critical vulnerability (CVE-2026-41452) in Krayin CRM 2.2.4 allows unauthenticated attackers to completely take over the admin account.
CVE-2026-58066: Critical Vulnerability in Rocket.Chat Allows Account Takeover
A critical vulnerability (CVE-2026-58066) in Rocket.Chat with a CVSS score of 9.8 allows attackers to take over any account via SAML SSO. Patches are available.
Seven Critical Vulnerabilities in Apache Traffic Server (up to CVSS 10.0)
An advisory for Apache Traffic Server describes seven critical vulnerabilities, including CVE-2026-58150 and CVE-2026-58162 with a CVSS score of 10.0, as well as CVE-2026-58154/58155, with a CVSS score of 9.2. Patches are available.
CVE-2026-63227: Critical RCE Vulnerability in Koollab LMS (CVSS 9.9)
Analysis of the critical vulnerability CVE-2026-63227 (CVSS 9.9) in Koollab LMS. An insecure file upload allows remote code execution. A patch is available.
WordPress WooCommerce Plugins: Multiple Critical Security Vulnerabilities (CVE-2026-15014, CVE-2026-8457, CVE-2025-10656)
Critical vulnerabilities (CVE-2026-15014, CVE-2026-8457, CVE-2025-10656, CVSS 9.8; CVE-2026-3141, CVSS 9.1) in WordPress plugins for WooCommerce allow attackers to take over accounts, gain unauthorized access, and delete files.
CVE-2026-59549: Critical SQL injection in the WordPress plugin rtMedia
Analysis of the critical SQL injection vulnerability CVE-2026-59549 (CVSS 9.3) in the WordPress plugin rtMedia. Versions up to 4.7.10 are affected. Action required for administrators.
SolarWinds Serv-U: Multiple Critical Vulnerabilities (CVE-2026-28302, CVE-2026-16232)
On July 21, 2026, 15 critical vulnerabilities in SolarWinds Serv-U (CVE-2026-28302) were disclosed. In addition, CVE-2026-16232, CVE-2026-62144, and CVE-2026-62145 (CVSS 9.3) were disclosed. Updates are available.
CVE-2026-42533: Critical Vulnerability in NGINX Due to a Heap Buffer Overflow
Technical Analysis of the Critical Heap Buffer Overflow Vulnerability CVE-2026-42533 in NGINX. Affected Versions, Patches, and Mitigation Measures.



