SecBoard

Advisory-Updates

Behördliche Warnungen des BSI — und vor allem ihre Fortschreibungen. Ein Update heißt meist: neue betroffene Versionen, ein Patch ist da, oder die Lücke wird ausgenutzt.

Advisories im Fenster
1827
davon Fortschreibungen
1076
kritisch oder hoch
820
mit belegt ausgenutzter Lücke
52
BetreffSchwereSchwachstellenDatum
Neu
Eclipse Jetty: Schwachstelle ermöglicht Darstellen falscher Informationen und Offenlegung
hoch117.09.2026
Neu
Tanium Endpoint Management: Mehrere Schwachstellen
hoch7
CVSS 8.8
17.09.2026
Neu
Apache Nifi: Mehrere Schwachstellen
hoch517.09.2026
Neu
Cisco Nexus Dashboard: Mehrere Schwachstellen
hoch6
CVSS 9.9
17.09.2026
Neu
Check Point Security Management: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit Administratorrechten
hoch1
CVSS 9.8
17.09.2026
Neu
Jenkins Plugins: Mehrere Schwachstellen
hoch20
CVSS 8.8
17.09.2026
Neu
PJSIP: Mehrere Schwachstellen
hoch17.09.2026
Update
strongSwan (NetworkManager-Plugin): Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
hoch117.09.2026
Update
Oracle Construction and Engineering: Mehrere Schwachstellen
hoch317.09.2026
Update
Perl: Mehrere Schwachstellen ermöglichen Codeausführung
hoch217.09.2026
Neu1× KEV
Cisco ISE und ISE-PIC: Mehrere Schwachstellen
hoch42
CVSS 10
17.09.2026
Neu
Devolutions Remote Desktop Manager: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen und Manipulation von Daten
hoch117.09.2026
Neu
Cisco Secure Firewall Threat Defense: Mehrere Schwachstellen
hoch4
CVSS 8.6
17.09.2026
Neu
Cisco Secure FTD und ASA: Mehrere Schwachstellen
hoch15
CVSS 9.9
17.09.2026
Neu
Red Hat Enterprise Linux (corosync, libevent, libsoup): Mehrere Schwachstellen
hoch12
CVSS 8.4
17.09.2026
Neu1× KEV
Cisco Secure Firewall Management Center: Mehrere Schwachstellen
hoch62
CVSS 10
17.09.2026
Neu
Znuny: Mehrere Schwachstellen
hoch1
CVSS 9.1
17.09.2026
Neu
NoMachine: Mehrere Schwachstellen
hoch317.09.2026
Neu
HP HPLIP: Mehrere Schwachstellen
hoch1017.09.2026
Neu
Arista EOS: Mehrere Schwachstellen
hoch8
CVSS 8.8
16.09.2026
Neu
IBM MQ: Mehrere Schwachstellen
hoch19
CVSS 9.8
16.09.2026
Neu
Ghostscript: Schwachstelle ermöglicht Codeausführung und Manipulation von Daten
hoch1
CVSS 9.8
16.09.2026
Neu1× KEV
Pixel Patchday September 2026: Mehrere Schwachstellen
hoch110
CVSS 9.8
16.09.2026
Neu
GIMP: Schwachstelle ermöglicht Codeausführung und Denial of Service
hoch1
CVSS 7.8
16.09.2026
Neu
Microsoft Edge: Mehrere Schwachstellen
hoch3
CVSS 8.8
16.09.2026
Neu
Aruba EdgeConnect: Mehrere Schwachstellen
hoch39
CVSS 9.9
16.09.2026
Neu1× KEV
Oracle Communications: Mehrere Schwachstellen
hoch31
CVSS 9.8
16.09.2026
Neu
Oracle Supply Chain: Mehrere Schwachstellen
hoch19
CVSS 9.8
16.09.2026
Neu
Oracle Siebel CRM: Mehrere Schwachstellen
hoch63
CVSS 9.1
16.09.2026
Neu
Oracle E-Business Suite: Mehrere Schwachstellen
hoch159
CVSS 9.8
16.09.2026
Neu
Oracle Enterprise Manager: Mehrere Schwachstellen
hoch7
CVSS 9.8
16.09.2026
Neu
Oracle Financial Services Applications: Mehrere Schwachstellen
hoch6
CVSS 8
16.09.2026
Neu
Oracle Hyperion: Mehrere Schwachstellen
hoch102
CVSS 10
16.09.2026
Neu
Oracle Fusion Middleware: Mehrere Schwachstellen
hoch153
CVSS 10
16.09.2026
Neu
Oracle GraalVM: Mehrere Schwachstellen
hoch3
CVSS 8.1
16.09.2026
Neu
Oracle PeopleSoft: Mehrere Schwachstellen
hoch16
CVSS 8.8
16.09.2026
Neu
n8n: Mehrere Schwachstellen
hoch16.09.2026
Neu
Unbound: Mehrere Schwachstellen
hoch9
CVSS 7.5
16.09.2026
Neu
Oracle Database Server: Mehrere Schwachstellen
hoch11
CVSS 8.8
16.09.2026
Neu
Oracle Commerce: Mehrere Schwachstellen
hoch27
CVSS 8.2
16.09.2026
Neu
Oracle VM VirtualBox: Mehrere Schwachstellen
hoch19
CVSS 8.6
16.09.2026
Neu
Oracle Utilities Applications: Mehrere Schwachstellen
hoch2
CVSS 8.2
16.09.2026
Neu
Netgate pfSense: Schwachstelle ermöglicht Codeausführung
hoch16.09.2026
Neu
Apache Airflow Providers (FAB, Keycloak, Kafka, Akeyless): Mehrere Schwachstellen
hoch816.09.2026
Neu
MikroTik RouterOS: Schwachstelle ermöglicht Denial of Service und Offenlegung von Informationen
hoch116.09.2026
Update
OpenSSH: Mehrere Schwachstellen
hoch2
CVSS 6.8
16.09.2026
Update
OpenSSH: Schwachstelle ermöglicht Codeausführung
hoch1
CVSS 8.1
16.09.2026
Update
GNU libc: Mehrere Schwachstellen
hoch3
CVSS 8.4
16.09.2026
Update
BusyBox: Schwachstelle ermöglicht Codeausführung
hoch1
CVSS 9.8
16.09.2026
Update
BusyBox: Schwachstelle ermöglicht Codeausführung
hoch416.09.2026
Update
BusyBox: Mehrere Schwachstellen
hoch16.09.2026
Neu
Google Chrome: Mehrere Schwachstellen
hoch42
CVSS 9.6
16.09.2026
Neu
Atlassian Bamboo, Bitbucket, Confluence, Fisheye/Crucible, Jira Software und Jira Service Management: Mehrere Schwachstellen
hoch64
CVSS 9.1
16.09.2026
Neu
Mozilla Firefox und Thunderbird: Mehrere Schwachstellen
hoch78
CVSS 8.8
16.09.2026
Neu
Devolutions Server: Mehrere Schwachstellen
hoch416.09.2026
Update
Flowise: Mehrere Schwachstellen
hoch1
CVSS 7.1
16.09.2026
Neu
MISP: Mehrere Schwachstellen
hoch815.09.2026
Neu
ZScaler Client Connector: Mehrere Schwachstellen ermöglichen Umgehen von Sicherheitsvorkehrungen
hoch2
CVSS 8.1
15.09.2026
Neu
IBM MQ: Mehrere Schwachstellen
hoch9
CVSS 8.8
15.09.2026
Neu1× KEV
Cisco Secure Email Gateway: Mehrere Schwachstellen
hoch6
CVSS 9.8
15.09.2026
Neu1× KEV
Apple iOS, iPadOS, macOS Tahoe, macOS Golden Gate, macOS Sequoia und Safari: Mehrere Schwachstellen
hoch273
CVSS 10
15.09.2026
Neu
Langflow: Mehrere Schwachstellen
hoch2
CVSS 9.6
15.09.2026
Neu
Octopus Deploy Server: Schwachstelle ermöglicht Codeausführung
hoch115.09.2026
Neu
Microsoft Windows 11 (Secure Kernel Mode): Schwachstelle ermöglicht Privilegieneskalation
hoch1
CVSS 8.2
15.09.2026
Update
KDE "Konsole": Schwachstelle ermöglicht Codeausführung
hoch115.09.2026
Update
WebKitGTK: Schwachstelle ermöglicht Codeausführung
hoch1
CVSS 8.8
15.09.2026
Neu
PCRE2 (Perl Compatible Regular Expressions): Mehrere Schwachstellen
hoch7
CVSS 8.2
14.09.2026
Update
Angular: Mehrere Schwachstellen
hoch3
CVSS 6.1
14.09.2026
Neu
Squid: Mehrere Schwachstellen
hoch414.09.2026
Neu
Strapi: Schwachstelle ermöglicht Cross-Site Scripting
hoch1
CVSS 8.7
14.09.2026
Update
Apache ActiveMQ: Mehrere Schwachstellen
hoch3
CVSS 8.8
14.09.2026
Update1× KEV
Apache ActiveMQ, Client, Broker und Web: Mehrere Schwachstellen
hoch2
CVSS 8.8
14.09.2026
Update
Google Chrome/Microsoft Edge: Mehrere Schwachstellen
hoch2514.09.2026
Update
Google Chrome: Schwachstelle ermöglicht nicht spezifizierten Angriff
hoch114.09.2026
Update
Google Chrome / Microsoft Edge: Mehrere Schwachstellen
hoch314.09.2026
Update
Google Chrome und Microsoft Edge: Mehrere Schwachstellen
hoch214.09.2026
Update
Google Chrome/Microsoft Edge: Mehrere Schwachstellen
hoch1214.09.2026
Update
Google Chrome / Microsoft Edge: Mehrere Schwachstellen ermöglichen Codeausführung
hoch214.09.2026
Update
Google Chrome / Microsoft Edge: Mehrere Schwachstellen
hoch314.09.2026
Update
TYPO3 Extensions: Mehrere Schwachstellen
hoch4
CVSS 8.8
14.09.2026
Update
Extreme Networks IQ Engine: Mehrere Schwachstellen
hoch3
CVSS 8.8
14.09.2026
Update
MediaWiki: Mehrere Schwachstellen
hoch11
CVSS 3.1
14.09.2026
Update
ILIAS: Mehrere Schwachstellen
hoch1
CVSS 3.3
14.09.2026
Update1× KEV
JFrog Artifactory: Mehrere Schwachstellen
hoch13
CVSS 8.8
14.09.2026
Update
Samsung Exynos: Mehrere Schwachstellen
hoch5
CVSS 4.2
14.09.2026
Neu
Linux Kernel: Mehrere Schwachstellen
hoch431
CVSS 9.8
14.09.2026
Update
Android Patchday Juni 2026: Mehrere Schwachstellen
hoch22
CVSS 7.8
11.09.2026
Neu
MongoDB: Mehrere Schwachstellen
hoch17
CVSS 8.3
11.09.2026
Update
Apache ActiveMQ: Mehrere Schwachstellen
hoch6
CVSS 8.8
11.09.2026
Update
Red Hat Enterprise Linux (Advanced Cluster Management): Mehrere Schwachstellen
hoch311.09.2026
Update
Apache HTTP Server: Mehrere Schwachstellen ermöglichen HTTP Response Splitting
hoch211.09.2026
Neu
Angular: Mehrere Schwachstellen
hoch5
CVSS 4
11.09.2026
Neu1× KEV
GitLab: Mehrere Schwachstellen
hoch18
CVSS 10
11.09.2026
Neu
Flowise: Mehrere Schwachstellen
hoch11.09.2026
Neu
libvirt: Schwachstelle ermöglicht Privilegieneskalation
hoch1
CVSS 5.5
11.09.2026
Neu
Langflow: Schwachstelle ermöglicht Codeausführung
hoch11.09.2026
Neu
IBM DB2: Mehrere Schwachstellen
hoch7
CVSS 9.8
11.09.2026
Neu
IBM MQ Appliance (Axios Node.js): Mehrere Schwachstellen
hoch10
CVSS 8.7
11.09.2026
Update
Red Hat Enterprise Linux (pacemaker): Schwachstelle ermöglicht Denial of Service
hoch1
CVSS 8.6
11.09.2026
Update
Red Hat Enterprise Linux (libsoup): Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen und Datenmanipulation
hoch1
CVSS 8.2
10.09.2026
Update
Podman: Schwachstelle ermöglicht Manipulation von Dateien
hoch1
CVSS 8.1
10.09.2026
Update
Red Hat Enterprise Linux (libsoup): Mehrere Schwachstellen
hoch9
CVSS 9
10.09.2026
Update
Node.js: Mehrere Schwachstellen
hoch710.09.2026
Update
Apache Portable Runtime (APR): Mehrere Schwachstellen
hoch310.09.2026
Update
python-cryptography: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
hoch10.09.2026
Neu
Red Hat Enterprise Linux (postgis, virtuoso-opensource): Mehrere Schwachstellen
hoch2
CVSS 8.1
10.09.2026
Neu
Check Point Security Gateway, Spark Firewall und Security Management: Mehrere Schwachstellen ermöglichen Codeausführung
hoch2
CVSS 9.8
10.09.2026
Neu
GeoNetwork: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
hoch110.09.2026
Neu
Joplin: Mehrere Schwachstellen
hoch1210.09.2026
Neu
Palo Alto Networks Cortex XDR Broker VM: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit Administratorrechten
hoch110.09.2026
Neu
Palo Alto Networks PAN-OS: Mehrere Schwachstellen
hoch310.09.2026
Neu
Linux Kernel: Mehrere Schwachstellen
hoch12
CVSS 8.8
10.09.2026
Neu
Red Hat Enterprise Linux (lxml): Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
hoch1
CVSS 8.2
10.09.2026
Neu
Netty: Mehrere Schwachstellen
hoch10.09.2026
Neu
PackageKit: Mehrere Schwachstellen
hoch2
CVSS 7.1
10.09.2026
Neu
Apache ActiveMQ Artemis: Mehrere Schwachstellen
hoch7
CVSS 9.8
10.09.2026
Neu
Arista EOS: Mehrere Schwachstellen
hoch23
CVSS 10
10.09.2026
Neu
Budibase: Mehrere Schwachstellen
kritisch10.09.2026
Neu
Kyverno: Mehrere Schwachstellen
hoch10.09.2026
Neu
Drupal Erweiterungen: Mehrere Schwachstellen
hoch2010.09.2026
Neu
Palo Alto Networks GlobalProtect App: Schwachstelle ermöglicht Privilegieneskalation
hoch110.09.2026
Update2× KEV
Cisco Secure Firewall Management Center: Mehrere Schwachstellen
kritisch7
CVSS 10
10.09.2026
Update1× KEV
Fortinet FortiOS: Schwachstelle ermöglicht Codeausführung
hoch1
CVSS 8.1
10.09.2026
Neu
Tor: Mehrere Schwachstellen
hoch1
CVSS 6.5
09.09.2026
Neu
OPNsense: Schwachstelle ermöglicht Privilegieneskalation
hoch1
CVSS 9
09.09.2026
Neu
cPanel cPanel/WHM: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit Administratorrechten
hoch109.09.2026
Neu
Dell OpenManage Server Administrator: Mehrere Schwachstellen
hoch21
CVSS 7.8
09.09.2026
Neu
Ivanti Neurons for ITSM: Mehrere Schwachstellen ermöglichen Codeausführung
hoch8
CVSS 9.9
09.09.2026
Neu
Microsoft SQL Server: Mehrere Schwachstellen
hoch62
CVSS 8.8
09.09.2026
Neu
Ivanti Endpoint Manager Mobile: Schwachstelle ermöglicht Erlangen von Administratorrechten
hoch1
CVSS 8.8
09.09.2026
Neu
Ivanti Sentry: Schwachstelle ermöglicht Erlangen von Administratorrechten
hoch1
CVSS 8.1
09.09.2026
Neu
Microsoft Exchange Server: Mehrere Schwachstellen
hoch9
CVSS 9.3
09.09.2026
Neu
Microsoft Dynamics 365 und Microsoft Power Automate Desktop: Mehrere Schwachstellen
hoch4
CVSS 8.8
09.09.2026
Neu
Apache Camel K: Mehrere Schwachstellen
hoch3
CVSS 9.8
09.09.2026
Neu
Microsoft Azure, Entra und Azure CLI : Mehrere Schwachstellen
hoch11
CVSS 10
09.09.2026
Neu
Apache Airflow: Schwachstelle ermöglicht Erlangen von Benutzerrechten
hoch1
CVSS 9.1
09.09.2026
Neu
Fortinet FortiSandbox: Mehrere Schwachstellen
hoch2
CVSS 9.9
09.09.2026
Neu
Lenovo BIOS: Mehrere Schwachstellen
hoch7
CVSS 8.2
09.09.2026
Neu
Lenovo XClarity Integrator für WAC und OneCLI: Mehrere Schwachstellen
hoch409.09.2026
Neu
Tanium Endpoint Management Server, Data Service, Enforce, Comply: Mehrere Schwachstellen
hoch21
CVSS 8.5
09.09.2026
Neu
Android Patchday September 2026: Mehrere Schwachstellen
hoch180
CVSS 9.8
09.09.2026
Neu
Adobe ColdFusion: Mehrere Schwachstellen
hoch8
CVSS 9.1
09.09.2026
Neu
Adobe Acrobat und Acrobat Reader: Mehrere Schwachstellen
hoch32
CVSS 8.8
09.09.2026
Neu
Xen: Mehrere Schwachstellen
hoch6
CVSS 8.8
09.09.2026
Neu
Adobe Creative Cloud (Illustrator und Animate): Mehrere Schwachstellen ermöglichen Codeausführung
hoch4
CVSS 8.6
09.09.2026
Neu1× KEV
Adobe Magento: Mehrere Schwachstellen
hoch9
CVSS 10
09.09.2026
Neu
Adobe Photoshop: Mehrere Schwachstellen ermöglichen Codeausführung
hoch8
CVSS 8.6
09.09.2026
Neu
Adobe Experience Manager: Mehrere Schwachstellen
hoch109
CVSS 9.9
09.09.2026
Neu2× KEV
Microsoft Windows: Mehrere Schwachstellen
kritisch735
CVSS 9.8
09.09.2026
Neu
Microsoft Entwicklerwerkzeuge: Mehrere Schwachstellen ermöglichen Privilegieneskalation
hoch24
CVSS 9.6
09.09.2026

820 Treffer, 150 gezeigt · Fenster: 90 Tage

Meldungsart und Schwere stammen unverändert aus der Kennzeichnung des BSI, nicht aus einer Einschätzung von uns. Die Zahl der Schwachstellen wird aus dem Advisory-Text gezählt; „ausgenutzt“ heißt, dass mindestens eine davon im KEV-Katalog der CISA steht.