SolarWinds Serv-U: Multiple Critical Vulnerabilities (CVE-2026-28302, CVE-2026-16232)
On July 21, 2026, 15 critical vulnerabilities in SolarWinds Serv-U (CVE-2026-28302) were disclosed. In addition, CVE-2026-16232, CVE-2026-62144, and CVE-2026-62145 (CVSS 9.3) were disclosed. Updates are available.
CVE-2026-42533: Critical Vulnerability in NGINX Due to a Heap Buffer Overflow
Technical Analysis of the Critical Heap Buffer Overflow Vulnerability CVE-2026-42533 in NGINX. Affected Versions, Patches, and Mitigation Measures.
Critical RCE Vulnerability in WordPress Core (CVE-2026-63030)
A critical vulnerability (CVE-2026-63030) in WordPress Core allows unauthenticated remote code execution. Versions up to 7.0.1 are affected. Action is required.
Drupal Modules: Critical Vulnerability Leading to Code Execution (CVE-2026-9726) and Information Disclosure (CVE-2026-10768)
Analysis of the critical RCE vulnerability CVE-2026-9726 (AlternativeCommerce Basket) and the information leak CVE-2026-10768 (LocalGov Workflows) in Drupal.
Microsoft Entra ID & Exchange/SharePoint: Multiple Critical Vulnerabilities (CVE-2026-55008, CVE-2026-56164, CVE-2026-55040)
Microsoft Entra ID is introducing passkeys as the default. At the same time, critical zero-day vulnerabilities were disclosed in SharePoint (CVE-2026-56164), AD FS (CVE-2026-55040, CVSS 9.1), and Exchange (CVE-2026-55008). Updates are available.
Microsoft Entra ID: Passkeys Will Become the Standard Starting in September 2026
Starting September 1, 2026, passkeys will become the default sign-in method in Microsoft Entra ID. Learn what the timeline and the phase-out of SMS mean for your organization.
IT Security Policy, Section 390 of SGB V: What Medical Practices Need to Know Now
The IT security policy under Section 390 of SGB V sets new standards for medical and dental practices. Learn about the applicable obligations and how to demonstrate compliance.
SAP Commerce Cloud & NetWeaver: Several Critical Security Vulnerabilities (CVE-2026-44761, CVE-2026-44747, CVE-2026-27690)
Analysis of Critical Vulnerabilities in SAP Commerce Cloud and NetWeaver (CVE-2026-44761 CVSS 9.1, CVE-2026-44747, CVE-2026-27690, CVSS 9.9). OAuth2 credentials, NetWeaver ABAP, and Approuter are affected. Details and mitigation steps.
Red Hat OpenShift AI: Multiple Critical Security Vulnerabilities (CVE-2026-15378, CVE-2026-15143)
Two critical SSRF vulnerabilities (CVE-2026-15378, CVE-2026-15143) with a CVSS score of 9.3 in Red Hat OpenShift AI allow attackers to gain unauthorized access to cloud and Kubernetes systems.
Microsoft 365: Phishing Campaign Bypasses MFA by Exploiting the OAuth Protocol
Phishing campaigns exploit the Microsoft 365 OAuth device code flow to take over accounts. The ARToken Kit and a Ghost phishing variant bypass standard MFA. Analysis and protective measures.
WPFunnels: Critical RCE Vulnerability (CVE-2026-14345, CVSS 9.8)
Critical RCE vulnerability (CVSS 9.8) in the WordPress plugin WPFunnels: CVE-2026-14345 allows unauthenticated code execution. Update to version 3.12.8.
Plesk: Multiple Critical Security Vulnerabilities (CVE-2026-48614, CVE-2026-56843)
Critical vulnerabilities in Plesk (CVE-2026-48614, CVE-2026-56843, CVSS 9.9) allow for privilege escalation and password disclosure. A patch is available for CVE-2026-56843.
Adobe ColdFusion: Multiple Critical Security Vulnerabilities (CVE-2026-48316, CVE-2026-48282)
Analysis of critical vulnerabilities in Adobe ColdFusion (CVSS 10.0), including CVE-2026-48316 and CVE-2026-48282. CISA warns of active exploitation. Patches are available.
Gitea: Three Critical Security Vulnerabilities (CVE-2026-58426, -20896, -22874)
Three critical Gitea vulnerabilities: CVE-2026-58426 (data access), CVE-2026-20896 (account takeover), CVE-2026-22874 (SSRF). Updating to version 1.26.4 is recommended.



