Meldingen
117 meldingen uit primaire bronnen, ernst middel en hoger. Filter op ernst, type of vendor, of zoek op een CVE-nummer of productnaam. Bulkpublicaties (BSI-updates, Patch Tuesday) staan als één regel.
Koppelen
Zet de feed in je RSS-lezer, of in Slack (/feed subscribe) of Teams (RSS-connector), dan komen nieuwe meldingen vanzelf in je teamkanaal.
Liever zelf bouwen? Dezelfde selectie als JSON, of de volledige API-specificatie (OpenAPI).
- 35middel
CVE-2026-88771: Citrix NetScaler Improper Input Validation Vulnerability
Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands. Vereiste actie: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Bas
65hoogCVE-2026-88772: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service Vereiste actie: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04
65hoogCVE-2026-67279: Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060. Vereiste actie: Apply mitigations in accord
40middelCVE-2026-65660: Microsoft SharePoint Code Injection Vulnerability
Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network. Vereiste actie: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidan
48hoogCVE-2026-87902: WordPress Core Remote File Inclusion Vulnerability
WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution. Vereiste actie: Apply mitigations in accordance with vendor in
68hoogKwetsbaarheid in WordPress wordt actief misbruikt: update nu
Er is een kwetsbaarheid gevonden in WordPress met het kenmerk CVE-2026-87902. Deze kwetsbaarheid kan een hoog risico vormen omdat een aanvaller zonder inloggegevens mogelijk schadelijke acties kan uitvoeren op de server waar de WordPress website op draait. De kans op misbruik wordt als ‘normaal’ beoordeeld met de mogel
88kritiekKwetsbaarheid verholpen in WordPress
De ontwikkelaars van WordPress hebben een kwetsbaarheid verholpen in WordPress. Een kwaadwillende kan de kwetsbaarheid met kenmerk CVE-2026-87902 misbruiken, om zonder authenticatie een lokaal PHP-bestand buiten de actieve themamappen door WordPress te laten inladen. Onder bepaalde voorwaarden met betrekking tot het a
83kritiekKwetsbaarheden verholpen in Adobe Campaign Classic
Adobe heeft 18 kritieke kwetsbaarheden verholpen in Adobe Campaign Classic. De kwetsbaarheden betreffen onder meer code- en OS-command-injectie, SQL-injectie, onvoldoende autorisatie, onvoldoende invoervalidatie en Server-Side Request Forgery (SSRF). Alle 18 kwetsbaarheden zijn als kritiek aangemerkt en tien kunnen zon
30middelCVE-2026-71362: Adobe Commerce and Magento Incorrect Authorization Vulnerability
Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction. Vereiste actie: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’
75kritiekCVE-2026-5430: WSO2 Multiple Products Path Traversal Vulnerability
WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution. Vereiste actie: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritiz
55hoog- 70kritiek
Kwetsbaarheden verholpen in IBM Langflow OSS en IBM MQ Appliance
IBM heeft 12 kwetsbaarheden verholpen in IBM MQ, IBM MQ Appliance en Langflow OSS. De kwetsbaarheden kunnen leiden tot het uitvoeren van willekeurige code of commando's. Vier kwetsbaarheden zijn als kritiek aangemerkt en kunnen zonder authenticatie en gebruikersinteractie op afstand worden misbruikt. De kwetsbaarheid
30middelKwetsbaarheid verholpen in F5 Networks BIG-IP Access Policy Manager
F5 Networks heeft een kwetsbaarheid verholpen in BIG-IP Access Policy Manager (APM). De kwetsbaarheid stelt een ongeauthenticeerde kwaadwillende in staat om malafide code uit te voeren. Hiertoe dient de kwaadwillende malafide netwerkverkeer naar het kwetsbare systeem te versturen. BIG-IP APM-systemen zijn alleen kwetsb
30middelKwetsbaarheden verholpen in Adobe Connect en Adobe Connect Android Mobile App
Adobe heeft 9 kwetsbaarheden verholpen in Adobe Connect en de Adobe Connect Android Mobile App. De kwetsbaarheden zijn verholpen in Adobe Connect 12.12 en Adobe Connect Android Mobile App 4.5. De kwetsbaarheden betreffen verschillende beveiligingsproblemen in Adobe Connect, waaronder SQL-injectie, Cross-Site Scripting
30middelKwetsbaarheden verholpen in Adobe Experience Manager Forms JEE
Adobe heeft 6 kwetsbaarheden verholpen in Adobe Experience Manager (AEM) Forms op Java Enterprise Edition (JEE), waaronder AEM 6.5 Forms en AEM 6.5 LTS Forms. De kwetsbaarheden betreffen verschillende beveiligingsproblemen, waaronder onjuiste autorisatie, onvoldoende invoervalidatie, Server-Side Request Forgery (SSRF),
30middelKwetsbaarheden verholpen in SolarWinds Observability Self-Hosted
SolarWinds heeft kwetsbaarheden verholpen in SolarWinds Observability Self-Hosted. De kwetsbaarheden maken ongeauthenticeerde remote code execution mogelijk. Eén kwetsbaarheid ontstaat door deserialisatie van onbetrouwbare data tijdens het gebruik van een specifieke communicatiemodus binnen de software. De andere kwets
25middelKwetsbaarheden verholpen in Check Point VPN-producten
Check Point heeft twee kritieke kwetsbaarheden verholpen in Quantum Security Gateway en Security Management. De kwetsbaarheid met kenmerk CVE-2026-85102 heeft een CVSS-score van 9,8. De kwetsbaarheid bevindt zich in het VPN-onderhandelingsproces van de Quantum Security Gateway en wordt veroorzaakt door onjuiste validat
95kritiekKwetsbaarheid verholpen in Check Point Security Management en Log Servers
Check Point heeft een kwetsbaarheid verholpen in Security Management en Log Servers. De kwetsbaarheid betreft een pre-authentication directory-traversal-kwetsbaarheid in de Check Point Management Web Service, waarmee ongeauthenticeerde aanvallers scripts vanaf een willekeurig pad kunnen uitvoeren. De kwetsbaarheid kan
25middelKwetsbaarheid in F5 Networks BIG-IP APM met actief misbruik
Er is een ernstige kwetsbaarheid gevonden in F5 Networks BIG-IP Access Policy Manager (APM) met een CVSS-score van 9,8. Deze kwetsbaarheid wordt actief misbruikt en kan aanzienlijke schade veroorzaken.
35middelKwetsbaarheid verholpen in VeloCloud Orchestrator (VCO) on-premises
VeloCloud heeft een kwetsbaarheid verholpen in VeloCloud Orchestrator (VCO) on-premises. De kwetsbaarheid in VCO stelt externe aanvallers in staat om toegang te krijgen tot geprivilegieerde interne functionaliteit, wat de vertrouwelijkheid, integriteit en beschikbaarheid kan aantasten. De kwetsbaarheid wordt actief uit
25middelCVE-2026-85102: Check Point Multiple Products Improper Certificate Validation Vulnerability
Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway. Vereiste actie: Apply mitigations in accordance with vendor ins
65hoogCVE-2026-93952: Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data manag
55hoogCVE-2026-94127: F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability
F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution. Vereiste actie: Apply mitigations in accordance with vendor instructions, ensuring c
55hoogCVE-2026-93616: Check Point Multiple Products Path Traversal Vulnerability
Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute arbitrary scripts. Vereiste actie: Apply mitigations in accordance with vendor instru
65hoogCVE-2026-7273: Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability
Zyxel GS1900 series switches contain a stack-based buffer overflow vulnerability in the CGI program which could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request. Vereiste actie: Apply mitigations in accordance with vendor instructions, ensur
48hoogKwetsbaarheid verholpen in Check Point's Security Management and Log Servers
Check Point heeft een kwetsbaarheid verholpen in Check Point's Security Management and Log Servers. De kwetsbaarheid betreft een stack overflow die optreedt tijdens het ongeauthenticeerde inlogproces. Een aanvaller kan deze kwetsbaarheid op afstand misbruiken om willekeurige code uit te voeren met rootrechten. Hierdoor
25middelCVE-2026-53266: Linux Kernel Out-of-Bounds Write Vulnerability
Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). User
48hoogCVE-2025-39964: Linux Kernel Race Condition Vulnerability
Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state. Vereiste actie: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA
40middelCVE-2025-39682: Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability
Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causing subsequent TLS records to be processed using incorrect zero-copy and
55hoog