Posts Tagged ‘DACH’
Oracle E-Business Suite CVE-2026-46817 Actively Exploited
Oracle E-Business Suite CVE-2026-46817, a critical flaw, is under active exploitation: an unauthenticated attacker with nothing more than HTTP access can take over Oracle Payments — the module that executes your payment runs. CISA added the flaw to its Known Exploited Vulnerabilities catalog on July 15 and gave US federal agencies three days to fix…
Read MoreSonicWall SMA1000 CVE-2026-15409 RCE: Patch by July 17
SonicWall confirmed that the SonicWall SMA1000 CVE-2026-15409 RCE chain is being actively exploited: an unauthenticated attacker can force a target appliance into arbitrary requests, then pivot to full administrator-level command execution — no valid login required at any point. CISA added both flaws to its Known Exploited Vulnerabilities catalog, with a federal remediation deadline of…
Read MoreMicrosoft July 2026 Patch Tuesday Zero-Day Hits SharePoint
The Microsoft July 2026 Patch Tuesday zero-day count is the largest disclosure on record — trackers put the total at 570 to 622 CVEs depending on methodology — and two of the fixed flaws were already being exploited before the patch shipped: one in Active Directory Federation Services, one in SharePoint Server. A separate, publicly…
Read MoreGitea Docker CVE-2026-20896 Auth Bypass
Gitea Docker CVE-2026-20896 is now under active exploitation: a single crafted HTTP header lets an unauthenticated attacker impersonate any user of a self-hosted Gitea instance — including an administrator — and walk away with private repositories and any secrets committed by mistake. What Happened Gitea’s official Docker image ships with REVERSE_PROXY_TRUSTED_PROXIES=*. On deployments that also…
Read MoreLangflow CVE-2026-55255 KEV: AI Agent Flaw Explained
The Langflow CVE-2026-55255 KEV entry, added by CISA on July 7, marks the first time an AI agent orchestration platform has ever appeared in the Known Exploited Vulnerabilities catalog. The flaw carries a CVSS score of just 6.1 from CISA, yet KEVIntel and CIRCL independently score the same bug 9.9, because it lets an authenticated…
Read More
