SecBoard

Advisory-Updates

Behördliche Warnungen des BSI — und vor allem ihre Fortschreibungen. Ein Update heißt meist: neue betroffene Versionen, ein Patch ist da, oder die Lücke wird ausgenutzt.

Advisories im Fenster
1827
davon Fortschreibungen
1076
kritisch oder hoch
820
mit belegt ausgenutzter Lücke
52
BetreffSchwereSchwachstellenDatum
Neu
MikroTik RouterOS: Mehrere Schwachstellen
mittel2
CVSS 7.5
17.09.2026
Neu
Budibase: Schwachstelle ermöglicht Offenlegung von Informationen
mittel17.09.2026
Neu
Eclipse Jetty: Schwachstelle ermöglicht Darstellen falscher Informationen und Offenlegung
hoch117.09.2026
Neu
Tanium Endpoint Management: Mehrere Schwachstellen
hoch7
CVSS 8.8
17.09.2026
Neu
Apache Nifi: Mehrere Schwachstellen
hoch517.09.2026
Neu
Cisco Nexus Dashboard: Mehrere Schwachstellen
hoch6
CVSS 9.9
17.09.2026
Neu
drawio: Mehrere Schwachstellen ermöglichen Offenlegung von Informationen
mittel17.09.2026
Neu
Check Point Security Management: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit Administratorrechten
hoch1
CVSS 9.8
17.09.2026
Neu
Jenkins Plugins: Mehrere Schwachstellen
hoch20
CVSS 8.8
17.09.2026
Neu
Dell ECS: Mehrere Schwachstellen
mittel2
CVSS 6.7
17.09.2026
Neu
PJSIP: Mehrere Schwachstellen
hoch17.09.2026
Update
Eclipse Jetty: Schwachstelle ermöglicht Privilegieneskalation
mittel1
CVSS 7.4
17.09.2026
Update
strongSwan (NetworkManager-Plugin): Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
hoch117.09.2026
Update
Dovecot: Mehrere Schwachstellen ermöglichen Denial of Service
mittel217.09.2026
Update
Oracle Construction and Engineering: Mehrere Schwachstellen
hoch317.09.2026
Update
Perl: Mehrere Schwachstellen ermöglichen Codeausführung
hoch217.09.2026
Update
Perl: Schwachstelle ermöglicht Codeausführung
mittel17.09.2026
Neu1× KEV
Cisco ISE und ISE-PIC: Mehrere Schwachstellen
hoch42
CVSS 10
17.09.2026
Neu
Devolutions Remote Desktop Manager: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen und Manipulation von Daten
hoch117.09.2026
Neu
Cisco Secure Firewall Threat Defense: Mehrere Schwachstellen
hoch4
CVSS 8.6
17.09.2026
Neu
Cisco Secure FTD und ASA: Mehrere Schwachstellen
hoch15
CVSS 9.9
17.09.2026
Neu
Internet Systems Consortium BIND: Mehrere Schwachstellen
mittel14
CVSS 7.5
17.09.2026
Neu
Red Hat Enterprise Linux (corosync, libevent, libsoup): Mehrere Schwachstellen
hoch12
CVSS 8.4
17.09.2026
Neu
Keycloak: Mehrere Schwachstellen
mittel6
CVSS 8.1
17.09.2026
Neu1× KEV
Cisco Secure Firewall Management Center: Mehrere Schwachstellen
hoch62
CVSS 10
17.09.2026
Neu
Znuny: Mehrere Schwachstellen
hoch1
CVSS 9.1
17.09.2026
Neu
Drupal Core: Schwachstelle ermöglicht Cross-Site Scripting
mittel17.09.2026
Neu
NoMachine: Mehrere Schwachstellen
hoch317.09.2026
Neu
HP HPLIP: Mehrere Schwachstellen
hoch1017.09.2026
Update
CoreDNS: Schwachstelle ermöglicht Denial of Service
mittel1
CVSS 7.5
17.09.2026
Update
ClamAV: Mehrere Schwachstellen
mittel7
CVSS 7.5
17.09.2026
Neu
Linux Kernel: Mehrere Schwachstellen
mittel19
CVSS 9.8
16.09.2026
Neu
MISP: Mehrere Schwachstellen
mittel416.09.2026
Neu
Arista EOS: Mehrere Schwachstellen
hoch8
CVSS 8.8
16.09.2026
Neu
IBM MQ: Mehrere Schwachstellen
hoch19
CVSS 9.8
16.09.2026
Neu
Ghostscript: Schwachstelle ermöglicht Codeausführung und Manipulation von Daten
hoch1
CVSS 9.8
16.09.2026
Neu1× KEV
Pixel Patchday September 2026: Mehrere Schwachstellen
hoch110
CVSS 9.8
16.09.2026
Neu
GIMP: Schwachstelle ermöglicht Codeausführung und Denial of Service
hoch1
CVSS 7.8
16.09.2026
Neu
Microsoft Edge: Mehrere Schwachstellen
hoch3
CVSS 8.8
16.09.2026
Neu
Aruba EdgeConnect: Mehrere Schwachstellen
hoch39
CVSS 9.9
16.09.2026
Neu1× KEV
Oracle Communications: Mehrere Schwachstellen
hoch31
CVSS 9.8
16.09.2026
Neu
Oracle Supply Chain: Mehrere Schwachstellen
hoch19
CVSS 9.8
16.09.2026
Neu
Oracle Siebel CRM: Mehrere Schwachstellen
hoch63
CVSS 9.1
16.09.2026
Neu
Oracle E-Business Suite: Mehrere Schwachstellen
hoch159
CVSS 9.8
16.09.2026
Neu
Oracle Enterprise Manager: Mehrere Schwachstellen
hoch7
CVSS 9.8
16.09.2026
Neu
Oracle Financial Services Applications: Mehrere Schwachstellen
hoch6
CVSS 8
16.09.2026
Neu
Oracle Hyperion: Mehrere Schwachstellen
hoch102
CVSS 10
16.09.2026
Neu
Oracle Fusion Middleware: Mehrere Schwachstellen
hoch153
CVSS 10
16.09.2026
Neu
Oracle GraalVM: Mehrere Schwachstellen
hoch3
CVSS 8.1
16.09.2026
Neu
Oracle PeopleSoft: Mehrere Schwachstellen
hoch16
CVSS 8.8
16.09.2026
Neu
n8n: Mehrere Schwachstellen
hoch16.09.2026
Neu
Unbound: Mehrere Schwachstellen
hoch9
CVSS 7.5
16.09.2026
Neu
Oracle Database Server: Mehrere Schwachstellen
hoch11
CVSS 8.8
16.09.2026
Neu
Oracle Commerce: Mehrere Schwachstellen
hoch27
CVSS 8.2
16.09.2026
Neu
Oracle VM VirtualBox: Mehrere Schwachstellen
hoch19
CVSS 8.6
16.09.2026
Neu
Oracle Utilities Applications: Mehrere Schwachstellen
hoch2
CVSS 8.2
16.09.2026
Neu
Netgate pfSense: Schwachstelle ermöglicht Codeausführung
hoch16.09.2026
Neu
Apache Airflow Providers (FAB, Keycloak, Kafka, Akeyless): Mehrere Schwachstellen
hoch816.09.2026
Neu
BigBlueButton: Schwachstelle ermöglicht Denial of Service
mittel16.09.2026
Neu
QT: Schwachstelle ermöglicht Denial of Service
mittel116.09.2026
Neu
Red Hat Enterprise Linux (firewalld, leapp-repository, tesseract: Mehrere Schwachstellen
mittel3
CVSS 7.3
16.09.2026
Neu
MikroTik RouterOS: Schwachstelle ermöglicht Denial of Service und Offenlegung von Informationen
hoch116.09.2026
Update
Dell integrated Dell Remote Access Controller: Mehrere Schwachstellen
mittel216.09.2026
Update
BusyBox (wget): Schwachstelle ermöglicht Umgehung von Sicherheitsvorkehrungen
mittel116.09.2026
Update
OpenSSH: Mehrere Schwachstellen
hoch2
CVSS 6.8
16.09.2026
Update
GNOME: Mehrere Schwachstellen
mittel416.09.2026
Update
expat: Schwachstelle ermöglicht Denial of Service
mittel116.09.2026
Update
TianoCore EDK2: Schwachstelle ermöglicht Denial of Service
mittel116.09.2026
Update
Red Hat Enterprise Linux: Schwachstelle ermöglicht Darstellen falscher Informationen
mittel116.09.2026
Update
expat: Mehrere Schwachstellen ermöglichen Denial of Service
mittel316.09.2026
Update
Linux Kernel: Schwachstelle ermöglicht Denial of Service
mittel116.09.2026
Update
OpenSSH: Schwachstelle ermöglicht Codeausführung
hoch1
CVSS 8.1
16.09.2026
Update
GNU libc: Mehrere Schwachstellen
hoch3
CVSS 8.4
16.09.2026
Update
SSH Protokoll: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
mittel1
CVSS 5.9
16.09.2026
Update
BusyBox: Schwachstelle ermöglicht Codeausführung
hoch1
CVSS 9.8
16.09.2026
Update
BusyBox: Schwachstelle ermöglicht Codeausführung
hoch416.09.2026
Update
BusyBox: Mehrere Schwachstellen
hoch16.09.2026
Neu
Google Chrome: Mehrere Schwachstellen
hoch42
CVSS 9.6
16.09.2026
Neu
Camunda: Schwachstelle ermöglicht Denial of Service
mittel1
CVSS 5.3
16.09.2026
Neu
vllm: Schwachstelle ermöglicht Denial of Service
mittel1
CVSS 5.3
16.09.2026
Neu
Atlassian Bamboo, Bitbucket, Confluence, Fisheye/Crucible, Jira Software und Jira Service Management: Mehrere Schwachstellen
hoch64
CVSS 9.1
16.09.2026
Neu
Mozilla Firefox und Thunderbird: Mehrere Schwachstellen
hoch78
CVSS 8.8
16.09.2026
Neu
Octopus Deploy: Schwachstelle ermöglicht Manipulation von Dateien und potenziell Codeausführung
mittel116.09.2026
Neu
NGINX: Schwachstelle ermöglicht Denial of Service
mittel1
CVSS 6.5
16.09.2026
Neu
Devolutions Server: Mehrere Schwachstellen
hoch416.09.2026
Update
OpenBao: Mehrere Schwachstellen
mittel4
CVSS 6.8
16.09.2026
Update
xwiki (Live Data): Schwachstelle ermöglicht Privilegieneskalation
mittel116.09.2026
Update
IBM WebSphere Application Server: Mehrere Schwachstellen
mittel216.09.2026
Update
Flowise: Mehrere Schwachstellen
hoch1
CVSS 7.1
16.09.2026
Neu
MISP: Mehrere Schwachstellen
hoch815.09.2026
Neu
ZScaler Client Connector: Mehrere Schwachstellen ermöglichen Umgehen von Sicherheitsvorkehrungen
hoch2
CVSS 8.1
15.09.2026
Neu
Arista EOS: Mehrere Schwachstellen
mittel5
CVSS 5.9
15.09.2026
Neu
Python: Schwachstelle ermöglicht Manipulation und Offenlegung von Daten
mittel115.09.2026
Neu
MikroTik RouterOS: Mehrere Schwachstellen
mittel2
CVSS 6.9
15.09.2026
Neu
IBM MQ: Mehrere Schwachstellen
hoch9
CVSS 8.8
15.09.2026
Neu
ffmpeg: Mehrere Schwachstellen
mittel2
CVSS 6.3
15.09.2026
Neu
IBM i: Mehrere Schwachstellen
mittel8
CVSS 6.1
15.09.2026
Neu
GIMP Plugins: Mehrere Schwachstellen ermöglichen Codeausführung und DoS
mittel3
CVSS 7.8
15.09.2026
Neu
Grafana: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen und Offenlegung von Informationen
mittel1
CVSS 7.1
15.09.2026
Neu
WP Royal Royal Elementor Addons: Schwachstelle ermöglicht Manipulation von Dateien
mittel1
CVSS 5.4
15.09.2026
Neu1× KEV
Cisco Secure Email Gateway: Mehrere Schwachstellen
hoch6
CVSS 9.8
15.09.2026
Neu1× KEV
Apple iOS, iPadOS, macOS Tahoe, macOS Golden Gate, macOS Sequoia und Safari: Mehrere Schwachstellen
hoch273
CVSS 10
15.09.2026
Neu
IBM DB2: Schwachstelle ermöglicht Manipulation von Dateien
mittel1
CVSS 7.5
15.09.2026
Neu
Langflow: Mehrere Schwachstellen
hoch2
CVSS 9.6
15.09.2026
Neu
Octopus Deploy Server: Schwachstelle ermöglicht Codeausführung
hoch115.09.2026
Neu
Microsoft Windows 11 (Secure Kernel Mode): Schwachstelle ermöglicht Privilegieneskalation
hoch1
CVSS 8.2
15.09.2026
Neu
Apple Xcode: Schwachstelle ermöglicht Offenlegung von Informationen
mittel1
CVSS 5.5
15.09.2026
Update
KDE "Konsole": Schwachstelle ermöglicht Codeausführung
hoch115.09.2026
Update
Linux Kernel: Mehrere Schwachstellen
mittel19
CVSS 9.1
15.09.2026
Update
WebKitGTK: Schwachstelle ermöglicht Codeausführung
hoch1
CVSS 8.8
15.09.2026
Update
Apple iOS und iPadOS: Mehrere Schwachstellen
mittel97
CVSS 9.8
15.09.2026
Update
Red Hat Enterprise Linux (libinput): Schwachstelle ermöglicht Privilegieneskalation
mittel1
CVSS 7.4
15.09.2026
Update
xwiki: Schwachstelle ermöglicht Offenlegung von Informationen
mittel115.09.2026
Update
Linux Kernel: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
mittel115.09.2026
Neu
Citrix Systems Workspace App Windows: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff
mittel214.09.2026
Neu
Microsoft Edge: Schwachstelle ermöglicht Cross-Site Scripting
mittel1
CVSS 6.1
14.09.2026
Neu
WP Royal Royal Elementor Addons: Schwachstelle ermöglicht Offenlegung von Informationen
mittel1
CVSS 5.3
14.09.2026
Neu
wpa_supplicant: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
mittel1
CVSS 7.1
14.09.2026
Neu
Puppet Enterprise: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit Administratorrechten
mittel114.09.2026
Neu
FRRouting Project FRRouting: Schwachstelle ermöglicht Privilegieneskalation
mittel1
CVSS 6.7
14.09.2026
Neu
libTIFF: Schwachstelle ermöglicht Denial of Service
mittel1
CVSS 6.1
14.09.2026
Neu
Red Hat Certificate System for RHEL (Dogtag PKI): Schwachstelle ermöglicht Offenlegung von Informationen
mittel1
CVSS 5.8
14.09.2026
Neu
memcached: Schwachstelle ermöglicht Denial of Service
mittel1
CVSS 5.3
14.09.2026
Neu
CPython: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
mittel114.09.2026
Neu
PCRE2 (Perl Compatible Regular Expressions): Mehrere Schwachstellen
hoch7
CVSS 8.2
14.09.2026
Update
Angular: Mehrere Schwachstellen
hoch3
CVSS 6.1
14.09.2026
Neu
Red Hat Enterprise Linux (libgit2): Schwachstelle ermöglicht Denial of Service
mittel1
CVSS 7.5
14.09.2026
Neu
QT: Schwachstelle ermöglicht Denial of Service
mittel114.09.2026
Neu
Squid: Mehrere Schwachstellen
hoch414.09.2026
Neu
vim: Schwachstelle ermöglicht Codeausführung
mittel14.09.2026
Neu
vllm: Mehrere Schwachstellen ermöglichen
mittel14.09.2026
Neu
Flowise: Mehrere Schwachstellen
mittel2
CVSS 6.5
14.09.2026
Neu
Strapi: Schwachstelle ermöglicht Cross-Site Scripting
hoch1
CVSS 8.7
14.09.2026
Neu
HAProxy: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
mittel1
CVSS 7.5
14.09.2026
Neu
Red Hat Enterprise Linux (libkcapi): Mehrere Schwachstellen
mittel3
CVSS 7.3
14.09.2026
Update
Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service
mittel34
CVSS 9.8
14.09.2026
Update
Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service oder unspezifischer Angriff
mittel63
CVSS 10
14.09.2026
Update
Apache ActiveMQ: Mehrere Schwachstellen
hoch3
CVSS 8.8
14.09.2026
Update1× KEV
Apache ActiveMQ, Client, Broker und Web: Mehrere Schwachstellen
hoch2
CVSS 8.8
14.09.2026
Update
libpng: Schwachstelle ermöglicht Codeausführung
mittel114.09.2026
Update
FasterXML Jackson: Schwachstelle ermöglicht Denial of Service
mittel114.09.2026
Update
Red Hat OpenShift Service Mesh (Kiali): Schwachstelle ermöglicht Denial of Service
mittel1
CVSS 7.5
14.09.2026
Update
Apache Cassandra (Netty): Schwachstelle ermöglicht Denial of Service
mittel114.09.2026
Update
Red Hat Enterprise Linux (CivetWeb library): Schwachstelle ermöglicht Denial of Service
mittel114.09.2026
Update
Google Chrome/Microsoft Edge: Mehrere Schwachstellen
hoch2514.09.2026
Update
CPython: Schwachstelle ermöglicht Denial of Service
mittel114.09.2026
Update
Google Chrome: Schwachstelle ermöglicht nicht spezifizierten Angriff
hoch114.09.2026
Update
Google Chrome / Microsoft Edge: Mehrere Schwachstellen
hoch314.09.2026
Update
expat: Schwachstelle ermöglicht Denial of Service
mittel1
CVSS 7.5
14.09.2026
Update
Google Chrome und Microsoft Edge: Mehrere Schwachstellen
hoch214.09.2026

1699 Treffer, 150 gezeigt · Fenster: 90 Tage

Meldungsart und Schwere stammen unverändert aus der Kennzeichnung des BSI, nicht aus einer Einschätzung von uns. Die Zahl der Schwachstellen wird aus dem Advisory-Text gezählt; „ausgenutzt“ heißt, dass mindestens eine davon im KEV-Katalog der CISA steht.