Meldingen
10 meldingen uit primaire bronnen. Filter op ernst, type of vendor, of zoek op een CVE-nummer.
Koppelen
Zet de feed in je RSS-lezer, of in Slack (/feed subscribe) of Teams (RSS-connector), dan komen nieuwe meldingen vanzelf in je teamkanaal.
Liever zelf bouwen? De data is ook beschikbaar als JSON: API-specificatie (OpenAPI).
Actief misbruik van zeroday-kwetsbaarheden in Zammad: update nu
Er zijn twee zeroday-kwetsbaarheden ontdekt in Zammad, een softwareproduct voor klantenservice. De kwetsbaarheden hebben de kenmerken CVE-2026-102489 en CVE-2026-102490. Beide kwetsbaarheden worden actief misbruikt en de kans op misbruik en de mogelijke schade zijn hoog.
prio50hoogKwetsbaarheden aangetroffen in Zammad
Er zijn twee zeroday-kwetsbaarheden aangetroffen in Zammad. De eerste kwetsbaarheid heeft het kenmerk CVE-2026-102489 toegekend gekregen. De kwetsbaarheid stelt een ongeauthenticeerde kwaadwillende op afstand in staat om willekeurige code uit te voeren. De kwetsbaarheid is aanwezig in Zammad versies 6.3.0 tot en met 6.
prio45hoogCisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability
A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of…
prio55hoogKwetsbaarheden verholpen in NetScaler ADC en NetScaler Gateway
Citrix heeft 8 kwetsbaarheden verholpen in NetScaler ADC en NetScaler Gateway. De volgende ondersteunde versies van Citrix NetScaler ADC en Citrix NetScaler Gateway zijn kwetsbaar: - Citrix NetScaler ADC en Citrix NetScaler Gateway 14.1 vóór versie 14.1-73.37 - Citrix NetScaler ADC en Citrix NetScaler Gateway 13.1 vóó
prio95kritiekCVE-2026-76504: Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability
Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request. Vereiste actie: Apply mitigations in accordance with vendor instructions,
prio55hoogCVE-2026-86950: Apple Multiple Products Out-of-Bounds Write Vulnerability
Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution. Vereiste actie: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidanc
prio48hoogCVE-2026-88771: Citrix NetScaler Improper Input Validation Vulnerability
Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands. Vereiste actie: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Bas
prio65hoogCVE-2026-88772: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service Vereiste actie: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04
prio65hoogCVE-2026-87902: WordPress Core Remote File Inclusion Vulnerability
WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution. Vereiste actie: Apply mitigations in accordance with vendor in
prio68hoogCVE-2026-65660: Microsoft SharePoint Code Injection Vulnerability
Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network. Vereiste actie: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidan
prio48hoog