SecBoard

Advisory-Updates

Behördliche Warnungen des BSI — und vor allem ihre Fortschreibungen. Ein Update heißt meist: neue betroffene Versionen, ein Patch ist da, oder die Lücke wird ausgenutzt.

Advisories im Fenster
1797
davon Fortschreibungen
1070
kritisch oder hoch
801
mit belegt ausgenutzter Lücke
50
BetreffSchwereSchwachstellenDatum
Update
CoreDNS: Schwachstelle ermöglicht Denial of Service
mittel1
CVSS 7.5
17.09.2026
Update
ClamAV: Mehrere Schwachstellen
mittel7
CVSS 7.5
17.09.2026
Neu
Linux Kernel: Mehrere Schwachstellen
mittel19
CVSS 9.8
16.09.2026
Neu
MISP: Mehrere Schwachstellen
mittel416.09.2026
Neu
Arista EOS: Mehrere Schwachstellen
hoch8
CVSS 8.8
16.09.2026
Neu
IBM MQ: Mehrere Schwachstellen
hoch19
CVSS 9.8
16.09.2026
Neu
Ghostscript: Schwachstelle ermöglicht Codeausführung und Manipulation von Daten
hoch1
CVSS 9.8
16.09.2026
Neu1× KEV
Pixel Patchday September 2026: Mehrere Schwachstellen
hoch110
CVSS 9.8
16.09.2026
Neu
GIMP: Schwachstelle ermöglicht Codeausführung und Denial of Service
hoch1
CVSS 7.8
16.09.2026
Neu
Microsoft Edge: Mehrere Schwachstellen
hoch3
CVSS 8.8
16.09.2026
Neu
Aruba EdgeConnect: Mehrere Schwachstellen
hoch39
CVSS 9.9
16.09.2026
Neu1× KEV
Oracle Communications: Mehrere Schwachstellen
hoch31
CVSS 9.8
16.09.2026
Neu
Oracle Supply Chain: Mehrere Schwachstellen
hoch19
CVSS 9.8
16.09.2026
Neu
Oracle Siebel CRM: Mehrere Schwachstellen
hoch63
CVSS 9.1
16.09.2026
Neu
Oracle E-Business Suite: Mehrere Schwachstellen
hoch159
CVSS 9.8
16.09.2026
Neu
Oracle Enterprise Manager: Mehrere Schwachstellen
hoch7
CVSS 9.8
16.09.2026
Neu
Oracle Financial Services Applications: Mehrere Schwachstellen
hoch6
CVSS 8
16.09.2026
Neu
Oracle Hyperion: Mehrere Schwachstellen
hoch102
CVSS 10
16.09.2026
Neu
Oracle Fusion Middleware: Mehrere Schwachstellen
hoch153
CVSS 10
16.09.2026
Neu
Oracle GraalVM: Mehrere Schwachstellen
hoch3
CVSS 8.1
16.09.2026
Neu
Oracle PeopleSoft: Mehrere Schwachstellen
hoch16
CVSS 8.8
16.09.2026
Neu
n8n: Mehrere Schwachstellen
hoch16.09.2026
Neu
Unbound: Mehrere Schwachstellen
hoch9
CVSS 7.5
16.09.2026
Neu
Oracle Database Server: Mehrere Schwachstellen
hoch11
CVSS 8.8
16.09.2026
Neu
Oracle Commerce: Mehrere Schwachstellen
hoch27
CVSS 8.2
16.09.2026
Neu
Oracle VM VirtualBox: Mehrere Schwachstellen
hoch19
CVSS 8.6
16.09.2026
Neu
Oracle Utilities Applications: Mehrere Schwachstellen
hoch2
CVSS 8.2
16.09.2026
Neu
binutils: Schwachstelle ermöglicht Denial of Service
niedrig2
CVSS 3.3
16.09.2026
Neu
Netgate pfSense: Schwachstelle ermöglicht Codeausführung
hoch16.09.2026
Neu
Apache Airflow Providers (FAB, Keycloak, Kafka, Akeyless): Mehrere Schwachstellen
hoch816.09.2026
Neu
BigBlueButton: Schwachstelle ermöglicht Denial of Service
mittel16.09.2026
Neu
QT: Schwachstelle ermöglicht Denial of Service
mittel116.09.2026
Neu
Red Hat Enterprise Linux (firewalld, leapp-repository, tesseract: Mehrere Schwachstellen
mittel3
CVSS 7.3
16.09.2026
Neu
MikroTik RouterOS: Schwachstelle ermöglicht Denial of Service und Offenlegung von Informationen
hoch116.09.2026
Update
Dell integrated Dell Remote Access Controller: Mehrere Schwachstellen
mittel216.09.2026
Update
BusyBox (wget): Schwachstelle ermöglicht Umgehung von Sicherheitsvorkehrungen
mittel116.09.2026
Update
OpenSSH: Mehrere Schwachstellen
hoch2
CVSS 6.8
16.09.2026
Update
GNOME: Mehrere Schwachstellen
mittel416.09.2026
Update
expat: Schwachstelle ermöglicht Denial of Service
mittel116.09.2026
Update
TianoCore EDK2: Schwachstelle ermöglicht Denial of Service
mittel116.09.2026
Update
Red Hat Enterprise Linux: Schwachstelle ermöglicht Darstellen falscher Informationen
mittel116.09.2026
Update
expat: Mehrere Schwachstellen ermöglichen Denial of Service
mittel316.09.2026
Update
Linux Kernel: Schwachstelle ermöglicht Denial of Service
mittel116.09.2026
Update
OpenSSH: Schwachstelle ermöglicht Codeausführung
hoch1
CVSS 8.1
16.09.2026
Update
GNU libc: Mehrere Schwachstellen
hoch3
CVSS 8.4
16.09.2026
Update
SSH Protokoll: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
mittel1
CVSS 5.9
16.09.2026
Update
BusyBox: Schwachstelle ermöglicht Codeausführung
hoch1
CVSS 9.8
16.09.2026
Update
BusyBox: Schwachstelle ermöglicht Codeausführung
hoch416.09.2026
Update
BusyBox: Mehrere Schwachstellen
hoch16.09.2026
Neu
Google Chrome: Mehrere Schwachstellen
hoch42
CVSS 9.6
16.09.2026
Neu
Camunda: Schwachstelle ermöglicht Denial of Service
mittel1
CVSS 5.3
16.09.2026
Neu
[UNGEPATCHT] [mittel] Podman: Schwachstelle ermöglicht Manipulation von Dateien
1
CVSS 5.5
16.09.2026
Neu
vllm: Schwachstelle ermöglicht Denial of Service
mittel1
CVSS 5.3
16.09.2026
Neu
Atlassian Bamboo, Bitbucket, Confluence, Fisheye/Crucible, Jira Software und Jira Service Management: Mehrere Schwachstellen
hoch64
CVSS 9.1
16.09.2026
Neu
Mozilla Firefox und Thunderbird: Mehrere Schwachstellen
hoch78
CVSS 8.8
16.09.2026
Neu
Octopus Deploy: Schwachstelle ermöglicht Manipulation von Dateien und potenziell Codeausführung
mittel116.09.2026
Neu
NGINX: Schwachstelle ermöglicht Denial of Service
mittel1
CVSS 6.5
16.09.2026
Neu
Devolutions Server: Mehrere Schwachstellen
hoch416.09.2026
Neu
[UNGEPATCHT] [mittel] Keycloak: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
1
CVSS 6.4
16.09.2026
Update
OpenBao: Mehrere Schwachstellen
mittel4
CVSS 6.8
16.09.2026
Update
xwiki (Live Data): Schwachstelle ermöglicht Privilegieneskalation
mittel116.09.2026
Update
IBM WebSphere Application Server: Mehrere Schwachstellen
mittel216.09.2026
Update
Flowise: Mehrere Schwachstellen
hoch1
CVSS 7.1
16.09.2026
Neu
MISP: Mehrere Schwachstellen
hoch815.09.2026
Neu
ZScaler Client Connector: Mehrere Schwachstellen ermöglichen Umgehen von Sicherheitsvorkehrungen
hoch2
CVSS 8.1
15.09.2026
Neu
Arista EOS: Mehrere Schwachstellen
mittel5
CVSS 5.9
15.09.2026
Neu
Python: Schwachstelle ermöglicht Manipulation und Offenlegung von Daten
mittel115.09.2026
Neu
MikroTik RouterOS: Mehrere Schwachstellen
mittel2
CVSS 6.9
15.09.2026
Neu
IBM MQ: Mehrere Schwachstellen
hoch9
CVSS 8.8
15.09.2026
Neu
[UNGEPATCHT] [mittel] binutils: Mehrere Schwachstellen
10
CVSS 5.3
15.09.2026
Neu
[UNGEPATCHT] [mittel] System Security Services Daemon (SSSD): Mehrere Schwachstellen ermöglichen Denial of Service
3
CVSS 5.5
15.09.2026
Neu
Fleet: Schwachstelle ermöglicht Offenlegung von Informationen
niedrig15.09.2026
Neu
Mattermost Server: Mehrere Schwachstellen
niedrig3
CVSS 6.5
15.09.2026
Neu
ffmpeg: Mehrere Schwachstellen
mittel2
CVSS 6.3
15.09.2026
Neu
IBM i: Mehrere Schwachstellen
mittel8
CVSS 6.1
15.09.2026
Neu
GIMP Plugins: Mehrere Schwachstellen ermöglichen Codeausführung und DoS
mittel3
CVSS 7.8
15.09.2026
Neu
vllm: Schwachstelle ermöglicht Denial of Service
niedrig1
CVSS 4.3
15.09.2026
Neu
Governikus AusweisApp2: Schwachstelle ermöglicht Cross-Site Scripting
niedrig1
CVSS 4.3
15.09.2026
Neu
Grafana: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen und Offenlegung von Informationen
mittel1
CVSS 7.1
15.09.2026
Neu
WP Royal Royal Elementor Addons: Schwachstelle ermöglicht Manipulation von Dateien
mittel1
CVSS 5.4
15.09.2026
Neu1× KEV
Cisco Secure Email Gateway: Mehrere Schwachstellen
hoch6
CVSS 9.8
15.09.2026
Neu1× KEV
Apple iOS, iPadOS, macOS Tahoe, macOS Golden Gate, macOS Sequoia und Safari: Mehrere Schwachstellen
hoch273
CVSS 10
15.09.2026
Neu
IBM DB2: Schwachstelle ermöglicht Manipulation von Dateien
mittel1
CVSS 7.5
15.09.2026
Neu
Langflow: Mehrere Schwachstellen
hoch2
CVSS 9.6
15.09.2026
Neu
Octopus Deploy Server: Schwachstelle ermöglicht Codeausführung
hoch115.09.2026
Neu
Microsoft Windows 11 (Secure Kernel Mode): Schwachstelle ermöglicht Privilegieneskalation
hoch1
CVSS 8.2
15.09.2026
Neu
Apple Xcode: Schwachstelle ermöglicht Offenlegung von Informationen
mittel1
CVSS 5.5
15.09.2026
Update
KDE "Konsole": Schwachstelle ermöglicht Codeausführung
hoch115.09.2026
Update
Linux Kernel: Mehrere Schwachstellen
mittel19
CVSS 9.1
15.09.2026
Update
WebKitGTK: Schwachstelle ermöglicht Codeausführung
hoch1
CVSS 8.8
15.09.2026
Update
Apple iOS und iPadOS: Mehrere Schwachstellen
mittel97
CVSS 9.8
15.09.2026
Update
Red Hat Enterprise Linux (libinput): Schwachstelle ermöglicht Privilegieneskalation
mittel1
CVSS 7.4
15.09.2026
Update
xwiki: Schwachstelle ermöglicht Offenlegung von Informationen
mittel115.09.2026
Update
Linux Kernel: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
mittel115.09.2026
Neu
Citrix Systems Workspace App Windows: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff
mittel214.09.2026
Neu
Microsoft Edge: Schwachstelle ermöglicht Cross-Site Scripting
mittel1
CVSS 6.1
14.09.2026
Neu
WP Royal Royal Elementor Addons: Schwachstelle ermöglicht Offenlegung von Informationen
mittel1
CVSS 5.3
14.09.2026
Neu
wpa_supplicant: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
mittel1
CVSS 7.1
14.09.2026
Neu
Puppet Enterprise: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit Administratorrechten
mittel114.09.2026
Neu
[UNGEPATCHT] [mittel] Net-SNMP: Schwachstelle ermöglicht Denial of Service
1
CVSS 7.5
14.09.2026
Neu
libarchive: Schwachstelle ermöglicht Denial of Service
niedrig1
CVSS 2.5
14.09.2026
Neu
FRRouting Project FRRouting: Schwachstelle ermöglicht Privilegieneskalation
mittel1
CVSS 6.7
14.09.2026
Neu
libTIFF: Schwachstelle ermöglicht Denial of Service
mittel1
CVSS 6.1
14.09.2026
Neu
Red Hat Certificate System for RHEL (Dogtag PKI): Schwachstelle ermöglicht Offenlegung von Informationen
mittel1
CVSS 5.8
14.09.2026
Neu
memcached: Schwachstelle ermöglicht Denial of Service
mittel1
CVSS 5.3
14.09.2026
Neu
CPython: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
mittel114.09.2026
Neu
PCRE2 (Perl Compatible Regular Expressions): Mehrere Schwachstellen
hoch7
CVSS 8.2
14.09.2026
Update
Angular: Mehrere Schwachstellen
hoch3
CVSS 6.1
14.09.2026
Neu
Red Hat Enterprise Linux (libgit2): Schwachstelle ermöglicht Denial of Service
mittel1
CVSS 7.5
14.09.2026
Neu
QT: Schwachstelle ermöglicht Denial of Service
mittel114.09.2026
Neu
ffmpeg: Mehrere Schwachstellen ermöglichen Denial of Service
niedrig2
CVSS 2.9
14.09.2026
Neu
CyberPanel: Mehrere Schwachstellen
niedrig3
CVSS 7.7
14.09.2026
Neu
Squid: Mehrere Schwachstellen
hoch414.09.2026
Neu
vim: Schwachstelle ermöglicht Codeausführung
mittel14.09.2026
Neu
vllm: Mehrere Schwachstellen ermöglichen
mittel14.09.2026
Neu
Flowise: Mehrere Schwachstellen
mittel2
CVSS 6.5
14.09.2026
Neu
[UNGEPATCHT] [niedrig] CUPS: Schwachstelle ermöglicht Codeausführung
14.09.2026
Neu
Strapi: Schwachstelle ermöglicht Cross-Site Scripting
hoch1
CVSS 8.7
14.09.2026
Neu
HAProxy: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
mittel1
CVSS 7.5
14.09.2026
Neu
Red Hat Enterprise Linux (libkcapi): Mehrere Schwachstellen
mittel3
CVSS 7.3
14.09.2026
Update
Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service
mittel34
CVSS 9.8
14.09.2026
Update
Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service oder unspezifischer Angriff
mittel63
CVSS 10
14.09.2026
Update
Apache ActiveMQ: Mehrere Schwachstellen
hoch3
CVSS 8.8
14.09.2026
Update1× KEV
Apache ActiveMQ, Client, Broker und Web: Mehrere Schwachstellen
hoch2
CVSS 8.8
14.09.2026
Update
libpng: Schwachstelle ermöglicht Codeausführung
mittel114.09.2026
Update
FasterXML Jackson: Schwachstelle ermöglicht Denial of Service
mittel114.09.2026
Update
Red Hat OpenShift Service Mesh (Kiali): Schwachstelle ermöglicht Denial of Service
mittel1
CVSS 7.5
14.09.2026
Update
Apache Cassandra (Netty): Schwachstelle ermöglicht Denial of Service
mittel114.09.2026
Update
Red Hat Enterprise Linux (CivetWeb library): Schwachstelle ermöglicht Denial of Service
mittel114.09.2026
Update
Google Chrome/Microsoft Edge: Mehrere Schwachstellen
hoch2514.09.2026
Update
CPython: Schwachstelle ermöglicht Denial of Service
mittel114.09.2026
Update
Google Chrome: Schwachstelle ermöglicht nicht spezifizierten Angriff
hoch114.09.2026
Update
Google Chrome / Microsoft Edge: Mehrere Schwachstellen
hoch314.09.2026
Update
expat: Schwachstelle ermöglicht Denial of Service
mittel1
CVSS 7.5
14.09.2026
Update
Google Chrome und Microsoft Edge: Mehrere Schwachstellen
hoch214.09.2026
Update
Samsung Exynos: Mehrere Schwachstellen
mittel16
CVSS 7.8
14.09.2026
Update
Google Chrome/Microsoft Edge: Mehrere Schwachstellen
hoch1214.09.2026
Update
OpenSC: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff
niedrig2
CVSS 3.8
14.09.2026
Update
Bouncy Castle: Schwachstelle ermöglicht Denial of Service
mittel114.09.2026
Update
Google Chrome / Microsoft Edge: Mehrere Schwachstellen ermöglichen Codeausführung
hoch214.09.2026
Update
Google Chrome / Microsoft Edge: Mehrere Schwachstellen
hoch314.09.2026
Update
WithSecure Endpoint Protection: Schwachstelle ermöglicht Denial of Service
mittel1
CVSS 3.7
14.09.2026
Update
IBM App Connect Enterprise: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
mittel114.09.2026
Update
Red Hat Enterprise Linux (c-ares): Schwachstelle ermöglicht Denial of Service
niedrig114.09.2026
Update
MediaWiki: Mehrere Schwachstellen ermöglichen Cross-Site Scripting
niedrig8
CVSS 5.4
14.09.2026
Update
TYPO3 Extensions: Mehrere Schwachstellen
hoch4
CVSS 8.8
14.09.2026
Update
Extreme Networks IQ Engine: Mehrere Schwachstellen
hoch3
CVSS 8.8
14.09.2026
Update
Paessler PRTG: Schwachstelle ermöglicht Offenlegung von Informationen
mittel1
CVSS 8.6
14.09.2026
Update
TYPO3 Extension(Femanager): Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
mittel1
CVSS 4.2
14.09.2026
Update
Samsung Exynos: Mehrere Schwachstellen
mittel3
CVSS 2.8
14.09.2026

1797 Treffer, 150 gezeigt · Fenster: 90 Tage

Meldungsart und Schwere stammen unverändert aus der Kennzeichnung des BSI, nicht aus einer Einschätzung von uns. Die Zahl der Schwachstellen wird aus dem Advisory-Text gezählt; „ausgenutzt“ heißt, dass mindestens eine davon im KEV-Katalog der CISA steht.