[UPDATE] [hoch] Kubernetes: Mehrere Schwachstellen
Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Kubernetes ausnutzen, um Informationen offenzulegen und Sicherheitsmaßnahmen zu umgehen.
● Live advisory feed
Security advisories from 24 sources — CISA, CERT-EU, NCSC-UK, BSI, CERT-FR, NCSC-NL, JPCERT/CC, JVN, HKCERT, the Canadian Cyber Centre, NVD, GitHub, Microsoft, Cisco, Fortinet, Palo Alto Networks and more — normalized, translated to English and flagged against the CISA KEV catalog. One global feed for CSIRTs, SOCs and defenders.
Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Kubernetes ausnutzen, um Informationen offenzulegen und Sicherheitsmaßnahmen zu umgehen.
Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in IBM Langflow Desktop ausnutzen, um beliebigen Programmcode auszuführen.
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in SolarWinds Web Help Desk ausnutzen, um Sicherheitsvorkehrungen zu umgehen.
Ein lokaler Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Daten zu manipulieren und einen Denial-of-Service-Zustand auszulösen.
Adobe heeft kwetsbaarheden verholpen in Adobe Campaign Classic (ACC). De eerste kwetsbaarheid betreft een Incorrect Authorization in de core authorization mechanismen van ACC, waardoor een aanvaller arbitrary code kan uitvoeren zonder enige gebruikersinteractie. Dit betekent dat …
JPCERT-AT-2026-0020 JPCERT/CC 2026-07-15(Initial) 2026-07-31(Update) I. Overview Microsoft has released July 2026 Security Updates to address the vulnerabilities in their products. Attackers leveraging these vulnerabilities may be able to execute arbitrary code remotely witho…
JFrog heeft meerdere kwetsbaarheden verholpen in JFrog Artifactory De kwetsbaarheden betreffen verschillende onderdelen van JFrog Artifactory. - Er is een privilege-escalatie mogelijk doordat het systeem de scope van tokens niet controleert, waardoor een aanvaller zijn rechten ka…
An attacker can exploit multiple vulnerabilities in Red Hat Enterprise Linux (Pillow) to disclose information, conduct a denial of service attack, and manipulate data.
An attacker can exploit multiple vulnerabilities in Node.js to conduct a denial of service attack, bypass security measures, and manipulate files.
A remote, anonymous attacker can exploit multiple vulnerabilities in Red Hat Enterprise Linux to conduct a denial of service attack.
Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contains a vulnerability due to a permissive regular expression.
Network Scanner Tool and Network Scanner Tool Lite provided by Sharp Corporation, with the initial configuration, require no authentication and accept files unlimitedly.
Sharp and Toshiba Tec MFPs (multifunction printers) contain multiple vulnerabilities.
Robotic cleaners DEEBOT PRO M1 and DEEBOT PRO K1VAC, and mobile app ECOVACS PRO App developed by ECOVACS ROBOTICS contain multiple vulnerabilities. They are provided in Japan by Hellohas Robotics Inc.
BaserCMS provided by baserCMS Users Community contains a CSV file injection vulnerability.
Une vulnérabilité a été découverte dans Microsoft Azure. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance.
Multiple security issues were discovered in Incus, a system container and virtual machine manager, which may result in bypass of security restrictions or privilege escalation. https://security-tracker.debian.org/tracker/DSA-6407-1
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. https://security-tracker.debian.org/tracker/DSA-6408-1
Multiple security issues were found in PHP, a widely-used open source general purpose scripting language, which could result in denial of service, SQL injection, information disclosure or the execution of arbitrary code. https://security-tracker.debian.org/tracker/DSA-6406-1
De multiples vulnérabilités ont été découvertes dans Progress MOVEit Transfer. Elles permettent à un attaquant de provoquer une injection de code indirecte à distance (XSS) et un contournement de la politique de sécurité.
De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
De multiples vulnérabilités ont été découvertes dans PHP. Certaines d'entre elles permettent à un attaquant de provoquer une injection SQL (SQLi), un déni de service et un problème de sécurité non spécifié par l'éditeur.
De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, une atteinte à l'intégrité des données et un contournement de la politique de sécurité.
De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité des données et un déni de service.
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. https://security-tracker.debian.org/tracker/DSA-6405-1
De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.
De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
Summary The AWS Amplify Studio amplify-codegen-ui is a package that generates front-end code from UI Builder entities (components, forms, views, and themes) primarily used in AWS Amplify Studio for component previews and in AWS Command Line Interface (AWS CLI) for generating comp…
Serial number: AV26-765 Date: July 30, 2026 As of July 30, 2026, Gladinet is affected by vulnerabilities in the following product: CentreStack Prior to 17.5 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as the…
Impact In its default configuration, a Rails application that displays image variants may allow an unauthenticated attacker to read arbitrary files from the server, including the process environment. That environment typically holds secret_key_base and often credentials for exter…
Serial number: AV26-764 Date: July 30, 2026 As of July 30, 2026, PHP Group is affected by vulnerabilities in the following product: PHP Prior to 8.2.33 Prior to 8.3.33 Prior to 8.4.24 Prior to 8.5.9 The Cyber Centre encourages users and administrators to review the provided web l…
Serial number: AV26-763 Date: July 30, 2026 As of July 30, 2026, VMware is affected by vulnerabilities in the following products: Cloud Foundation 5.x 9.0.x.x 9.1.x.x Prior to 5.2.3 ESX Prior to ESXi-9.0.2.0100-25595025 Prior to ESXi-9.1.0.0-25370933 Prior to ESXi-9.1.0.0200-2555…
Summary MessagePack::Buffer#clear shifts out every chunk and returns its 4 KiB rmem page to the shared pool, but does not reset the buffer's rmem cursor (rmem_last, rmem_end, rmem_owner). The next write sees "unused rmem space" left over from the freed page and hands back a slice…
Summary is_url_safe in v1.0.3 contains an SSRF bypass. remove_at_symbol_in_string is applied to the raw URL string before new URL() parses it. This strips the @ that separates userinfo from host, corrupting the hostname so internal IPs are never checked. Vulnerability In helpe…
Serial number: AV26-762 Date: July 30, 2026 As of July 30, 2026, Phoenix Contact is affected by vulnerabilities in the following products: CHARX SEC-3000 Prior to 1.9.1 CHARX SEC-3050 Prior to 1.9.1 CHARX SEC-3100 Prior to 1.9.1 CHARX SEC-3150 Prior to 1.9.1 The Cyber Centre enco…
Summary The HTTP modules that DO call the SSRF guard (http.get, http.request, http.batch) validate only the initial URL, then issue the request with aiohttp's default allow_redirects=True and perform no per-hop revalidation. An attacker hosts a public URL that 302-redirects to an…
Summary Numerous HTTP-emitting modules (core.api.http_get, core.api.http_post, graphql.query/graphql.mutation, monitor.http_check, communication.slack_send, notification.{discord,slack,teams}.send_message, ai.vision_analyze [anthropic path], verify.visual_diff, browser.proxy_rota…
Summary The standalone flyto-verification service exposes POST /run with no authentication, on all interfaces (0.0.0.0:8344 per the shipped Dockerfile). The request body's callback_url is used verbatim for an outbound POST that **unconditionally attaches X-Internal-Key: $FLYTO_RU…
Summary llm.chat reads the operator's provider key from the environment (OPENAI_API_KEY, ANTHROPIC_API_KEY, ...) and sends it in the Authorization: Bearer header to base_url, a parameter the caller controls. base_url is only checked against the SSRF guard, and the guard allows a…
Summary The capability policy denies the env.get and env.load_dotenv modules by default, with the stated reason that they read arbitrary host environment variables (API keys, DSNs) and are a secret-exfil risk. But the workflow engine's variable resolver expands ${env.VAR} for an…
Summary image.download fetches a URL and writes the response to disk. It does not use the central path guard (validate_path_with_env_config, which confines writes to FLYTO_SANDBOX_DIR); instead it confines the output to output_dir, but output_dir is itself a caller parameter. Si…
Summary lib.url.fetch() follows HTTP redirects (follow_redirects=True). httpx strips only Authorization and Cookie when a redirect crosses the origin, so any other caller-supplied credential header (a session token such as Redfish's X-Auth-Token, an API key, ...) was still sent t…
Summary Vulnerability: Missing Session Ownership Validation in the Ruby MCP SDK's Streamable and SSE HTTP transport implementation. Any attacker with a stolen session ID can execute tools with the victim's session. This is a silent attack - the victim's session is compromised and…
Summary An unauthenticated remote attacker can force any MCP Ruby SDK server using MCP::Server::Transports::StreamableHTTPTransport to allocate gigabytes of memory by sending a single oversized JSON-RPC POST. The transport reads the entire HTTP body into a Ruby String and parses…
Summary In its default configuration, MCP::Server::Transports::StreamableHTTPTransport never expires sessions. Every successful initialize request stores a new ServerSession and a session record under a fresh UUID, and the only path that removes them is an explicit client-issued…
Summary The stdio transports in MCP::Server::Transports::StdioTransport and MCP::Client::Stdio read newline-delimited JSON-RPC frames using IO#gets with no limit argument. CRuby's IO#gets with no limit reads from the current position until the next separator (\n) with no upper b…
Summary MCP::Server::Transports::StreamableHTTPTransport (the Rack-mountable Streamable HTTP transport in the mcp gem) processes every incoming JSON-RPC request without ever inspecting the HTTP Host or Origin request headers. There is no AllowedHosts/AllowedOrigins allowlist and…
Serial number: AV26-761 Date: July 30, 2026 As of July 30, 2026, WebPros is affected by a vulnerability in the following product: Plesk Prior to 18.0.79.4 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they …
Summary OliveTin's checkShellArgumentSafety() function maintains a blocklist of argument types unsafe for Shell mode actions, but does not include regex:-prefixed types. Because regex: support was added independently via typeSafetyCheckRegex(), any Shell mode action using a regex…
Summary The synchronous execution RPCs StartActionAndWait and StartActionByGetAndWait return the full LogEntry for the just-executed action without checking whether the caller is allowed to read that action's logs. OliveTin's ACL model separates exec from logs. A deployment can…