CVE-2026-63227: Critical RCE Vulnerability in Koollab LMS (CVSS 9.9)
Analysis of the critical vulnerability CVE-2026-63227 (CVSS 9.9) in Koollab LMS. An insecure file upload allows remote code execution. A patch is available.
Read ArticleCurrent security alerts, regulatory guidance and practical knowledge for well-founded cyber risk decisions.
Analysis of the critical vulnerability CVE-2026-63227 (CVSS 9.9) in Koollab LMS. An insecure file upload allows remote code execution. A patch is available.
Read Article
Critical vulnerabilities (CVE-2026-15014, CVE-2026-8457, CVE-2025-10656, CVSS 9.8; CVE-2026-3141, CVSS 9.1) in WordPress plugins for WooCommerce allow attackers to take over accounts, gain unauthorized access, and delete files.
Read Article
Analysis of the critical SQL injection vulnerability CVE-2026-59549 (CVSS 9.3) in the WordPress plugin rtMedia. Versions up to 4.7.10 are affected. Action required for administrators.
Read Article
On July 21, 2026, 15 critical vulnerabilities in SolarWinds Serv-U (CVE-2026-28302) were disclosed. In addition, CVE-2026-16232, CVE-2026-62144, and CVE-2026-62145 (CVSS 9.3) were disclosed. Updates are available.
Read Article
Technical Analysis of the Critical Heap Buffer Overflow Vulnerability CVE-2026-42533 in NGINX. Affected Versions, Patches, and Mitigation Measures.
Read Article
A critical vulnerability (CVE-2026-63030) in WordPress Core allows unauthenticated remote code execution. Versions up to 7.0.1 are affected. Action is required.
Read Article
Analysis of the critical RCE vulnerability CVE-2026-9726 (AlternativeCommerce Basket) and the information leak CVE-2026-10768 (LocalGov Workflows) in Drupal.
Read Article
Microsoft Entra ID is introducing passkeys as the default. At the same time, critical zero-day vulnerabilities were disclosed in SharePoint (CVE-2026-56164), AD FS (CVE-2026-55040, CVSS 9.1), and Exchange (CVE-2026-55008). Updates are available.
Read Article
Starting September 1, 2026, passkeys will become the default sign-in method in Microsoft Entra ID. Learn what the timeline and the phase-out of SMS mean for your organization.
Read Article
The IT security policy under Section 390 of SGB V sets new standards for medical and dental practices. Learn about the applicable obligations and how to demonstrate compliance.
Read Article
Analysis of Critical Vulnerabilities in SAP Commerce Cloud and NetWeaver (CVE-2026-44761 CVSS 9.1, CVE-2026-44747, CVE-2026-27690, CVSS 9.9). OAuth2 credentials, NetWeaver ABAP, and Approuter are affected. Details and mitigation steps.
Read Article
Two critical SSRF vulnerabilities (CVE-2026-15378, CVE-2026-15143) with a CVSS score of 9.3 in Red Hat OpenShift AI allow attackers to gain unauthorized access to cloud and Kubernetes systems.
Read Article
Phishing campaigns exploit the Microsoft 365 OAuth device code flow to take over accounts. The ARToken Kit and a Ghost phishing variant bypass standard MFA. Analysis and protective measures.
Read Article