Meldingen
420 meldingen uit primaire bronnen. Filter op ernst, type of vendor, of zoek op een CVE-nummer of productnaam. Bulkpublicaties (BSI-updates, Patch Tuesday) staan als één regel.
Koppelen
Zet de feed in je RSS-lezer, of in Slack (/feed subscribe) of Teams (RSS-connector), dan komen nieuwe meldingen vanzelf in je teamkanaal.
Liever zelf bouwen? Dezelfde selectie als JSON, of de volledige API-specificatie (OpenAPI).
2026-012: Critical Vulnerabilities in Check Point Products
On 9 September 2026, Check Point released emergency security updates addressing two critical vulnerabilities affecting Check Point Security Gateway, Security Management Server, and Spark Firewall deployments configured to use Remote Access VPN or Site-to-Site VPN. Both vulnerabilities carry a CVSS score of 9.8 and coul
15laagThe Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE
Learn how root access on a compromised K8s node allows attackers to utilize SPIFFE/SPIRE metadata to spoof and harvest co-located workload identities. The post The Machine With Many Faces:…
0laagKritieke kwetsbaarheden in Check Point VPN-producten actief misbruikt: update nu
Er zijn 2 kritieke kwetsbaarheden in Check Point VPN-producten, met de kenmerken CVE-2026-85102 en CVE-2026-85103. Het gaat om 2 ernstige kwetsbaarheden met een CVSS-score van 9,8. Het NCSC beoordeelt de kans op misbruik en de mogelijke schade als hoog. Er is actief misbruik waargenomen van CVE-2026-85102, het advies i
70kritiekKwetsbaarheden in Adobe Illustrator met risico op code-uitvoering: update onmiddellijk
Er zijn 3 kwetsbaarheden gevonden in Adobe Illustrator. Deze kwetsbaarheden hebben een CVSS-score van 7,8 tot 8,6 en zijn beoordeeld als medium kans op misbruik en hoge mogelijke schade. Ze maken het mogelijk dat een aanvaller via speciaal gemaakte bestanden schadelijke code kan uitvoeren op jouw computer.
20laagCVE-2026-67277: MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
MikroTik RouterOS contains a missing authentication for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service. Vereiste actie: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Bas
63hoogCVE-2026-86060: MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacker to change the trusted RouterOS policy mask, leading to privilege escalation. Vereiste actie: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-
55hoogActive exploitation of Cisco Secure Firewall Management Center vulnerabilities
Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software.
52hoog- 0laag
- 0laag
- 0laag
- 0laag
- 0laag
- 0laag
- 0laag
- 8laag
- 0laag
2026-011: Critical Vulnerabilities in SAP Kernel and NetWeaver Message Server
On 8 September 2026, as part of its September Security Patch Day, SAP released Security Notes addressing two critical vulnerabilities affecting a broad range of SAP products[3]. The most severe, CVE-2026-44756 (CVSS 10.0), is a memory corruption vulnerability in SAP Extended Passport (EPP) processing, nicknamed "OVERPA
15laagKwetsbaarheden in Adobe Photoshop Desktop met risico op misbruik: update direct
Er zijn meerdere kwetsbaarheden gevonden in Adobe Photoshop Desktop met een CVSS-score tot 8,6. Deze kwetsbaarheden zijn beoordeeld als van normale urgentie om te handelen. Er zijn geen meldingen van actief misbruik. Het NCSC adviseert alsnog om de beschikbare updates van Adobe zo snel mogelijk te installeren om risico
5laagKwetsbaarheden in Adobe Commerce met risico op misbruik: update onmiddellijk
Er zijn meerdere kwetsbaarheden gevonden in Adobe Commerce. Het NCSC beoordeelt de kans op misbruik als middelmatig en de mogelijke schade als hoog. Het advies is om de beschikbare updates van Adobe zo snel mogelijk te installeren om risico’s te beperken.
20laagActief misbruik zero-day kwetsbaarheid in Google Chrome V8 - update nu
Er is een zero-day kwetsbaarheid gevonden in de V8 JavaScript engine van Google Chrome. Deze kwetsbaarheid, bekend als CVE-2026-87491, wordt actief misbruikt en kan ernstige schade veroorzaken. Het NCSC adviseert om de nieuwste updates van Google Chrome zo snel mogelijk te installeren.
68hoogUntracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
An investigation into how cybercriminals used YouTube gaming lures and SEO poisoning to deliver multi-payload malware to enterprise networks. The post Untracked Nightmares: The Threats Hiding Behind…
0laagMicrosoft verhelpt ernstige kwetsbaarheden in Windows en Office
Deze Patch Tuesday heeft Microsoft een groot aantal kwetsbaarheden verholpen in verschillende producten. Microsoft meldt dat twee kwetsbaarheden in Windows worden misbruikt. Een aanvaller moet hiervoor al beperkte toegang tot het systeem hebben en kan vervolgens meer rechten verkrijgen. Daarnaast zijn kwetsbaarheden ve
20laagCVE-2025-25249: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets. Vereiste actie: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prio
55hoogCVE-2026-87491: Google Chromium V8 Out of Bounds Write Vulnerability
Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Vere
48hoogCVE-2026-19490: Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass aut
65hoogCVE-2026-20079: Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device
85kritiekMicrosoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."
27middelSeptember 2026 Security Update
Ivanti releases standard security patches on the second Tuesday of every month. In today’s rapidly evolving technology and threat landscape, we believe responsible transparency should be a…
0laagKwetsbaarheden in MikroTik RouterOS actief misbruikt: update nu
Er zijn meerdere ernstige kwetsbaarheden gevonden in MikroTik RouterOS. Deze kwetsbaarheden worden actief misbruikt en is vooral gericht op routers met publiek toegankelijke SSH-diensten. Het NCSC adviseert om de updates van MikroTik zo snel mogelijk te installeren om risico’s te beperken.
50hoogCisco Secure Email Secure/Multipurpose Internet Mail Extensions Ciphertext Decryption Vulnerabilities
Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain…
0laag