24h | 7d | 30d

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post

Last activity: 1 hour ago

Bluesky

Profile picture fallback
~Cybergcca~ Security updates released for WatchGuard, Siemens, FreeBSD (RCE), and Ericsson. - IOCs: CVE-2026-4747, CVE-2026-4266, CVE-2026-4652 - #Patch #ThreatIntel #Vulnerability
  • 0
  • 0
  • 0
  • 1h ago

Overview

  • Microsoft
  • Microsoft SharePoint Enterprise Server 2016

13 Jan 2026
Published
19 Mar 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
7.10%

Description

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Statistics

  • 1 Post

Last activity: 3 hours ago

Fediverse

Profile picture fallback

Zwei kritische Schwachstellen beherrschen die Lage für deutsche Unternehmen.
Das BSI warnt vor einer aktiv ausgenutzten Lücke in Microsoft SharePoint. Die CISA hatte die Schwachstelle am 18. März in ihren Katalog ausgenutzter Sicherheitslücken aufgenommen. CERT-EU veröffentlichte am 25. März ein Advisory und verwies auf Maßnahmen aus der ToolShell-Angriffskampagne des Vorjahres. Der CVSS-Score liegt bei 9.8 von 10 und wurde hochgestuft, nachdem sich herausstellte, dass eine Ausnutzung auch ohne Authentifizierung möglich ist.
Parallel dazu hat CERT-Bund am 24. März Alarm wegen zweier Schwachstellen in Citrix NetScaler ADC und NetScaler Gateway geschlagen. CVE-2026-3055 ermöglicht es nicht authentifizierten Angreifern, aktive Session-Token aus dem Speicher betroffener Geräte auszulesen. CVE-2026-4368 kann durch eine Race Condition zur Übernahme fremder Benutzersitzungen führen. Besonders gefährdet sind Systeme, die als SAML Identity Provider konfiguriert sind, also eine in Unternehmensumgebungen weit verbreitete Konfiguration für Single Sign-On. Sicherheitsforscher bewerten eine baldige aktive Ausnutzung als sehr wahrscheinlich.
Sofortmaßnahmen: SharePoint patchen, NetScaler aktualisieren und aktiven Sessions beenden.

Cybersicherheitswarnung 2026-238220-1032 (25.03.2026) | CERT-Bund WID-SEC-2026-0836 (24.03.2026)
CVE-2026-20963 | CVE-2026-3055 | CVE-2026-4368
#Informationssicherheit #CISO #BSI #SharePoint #Citrix #NetScaler #Patchmanagement #NIS2 #CyberSecurity #ITSicherheit

  • 0
  • 0
  • 0
  • 3h ago

Overview

  • TP-Link Systems Inc.
  • Archer AX53 v1.0

03 Feb 2026
Published
16 Mar 2026
Updated

CVSS v4.0
HIGH (8.6)
EPSS
0.01%

KEV

Description

Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tdpserver modules) allows adjacent attackers to cause a segmentation fault or potentially execute arbitrary code via a specially crafted network packet containing a maliciously formed field.This issue affects Archer AX53 v1.0: through 1.3.1 Build 20241120.

Statistics

  • 1 Post

Last activity: 21 hours ago

Bluesky

Profile picture fallback
~Talos~ Cisco Talos disclosed 30 patched vulnerabilities in Canva Affinity, TP-Link routers, and HikVision terminals, including several RCE flaws. - IOCs: CVE-2025-66342, CVE-2025-62673, CVE-2025-66176 - #CVE #ThreatIntel #Vulnerabilities
  • 0
  • 0
  • 0
  • 21h ago

Overview

  • FreeBSD
  • FreeBSD

26 Mar 2026
Published
27 Mar 2026
Updated

CVSS
Pending
EPSS
0.15%

KEV

Description

Each RPCSEC_GSS data packet is validated by a routine which checks a signature in the packet. This routine copies a portion of the packet into a stack buffer, but fails to ensure that the buffer is sufficiently large, and a malicious client can trigger a stack overflow. Notably, this does not require the client to authenticate itself first. As kgssapi.ko's RPCSEC_GSS implementation is vulnerable, remote code execution in the kernel is possible by an authenticated user that is able to send packets to the kernel's NFS server while kgssapi.ko is loaded into the kernel. In userspace, applications which have librpcgss_sec loaded and run an RPC server are vulnerable to remote code execution from any client able to send it packets. We are not aware of any such applications in the FreeBSD base system.

Statistics

  • 1 Post

Last activity: 1 hour ago

Bluesky

Profile picture fallback
~Cybergcca~ Security updates released for WatchGuard, Siemens, FreeBSD (RCE), and Ericsson. - IOCs: CVE-2026-4747, CVE-2026-4266, CVE-2026-4652 - #Patch #ThreatIntel #Vulnerability
  • 0
  • 0
  • 0
  • 1h ago

Overview

  • FreeBSD
  • FreeBSD

26 Mar 2026
Published
26 Mar 2026
Updated

CVSS
Pending
EPSS
0.05%

KEV

Description

On a system exposing an NVMe/TCP target, a remote client can trigger a kernel panic by sending a CONNECT command for an I/O queue with a bogus or stale CNTLID. An attacker with network access to the NVMe/TCP target can trigger an unauthenticated Denial of Service condition on the affected machine.

Statistics

  • 1 Post

Last activity: 1 hour ago

Bluesky

Profile picture fallback
~Cybergcca~ Security updates released for WatchGuard, Siemens, FreeBSD (RCE), and Ericsson. - IOCs: CVE-2026-4747, CVE-2026-4266, CVE-2026-4652 - #Patch #ThreatIntel #Vulnerability
  • 0
  • 0
  • 0
  • 1h ago

Overview

  • Hikvision
  • DS-K1T331

13 Jan 2026
Published
18 Mar 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
0.01%

KEV

Description

There is a Stack overflow Vulnerability in the device Search and Discovery feature of Hikvision Access Control Products. If exploited, an attacker on the same local area network (LAN) could cause the device to malfunction by sending specially crafted packets to an unpatched device.

Statistics

  • 1 Post

Last activity: 21 hours ago

Bluesky

Profile picture fallback
~Talos~ Cisco Talos disclosed 30 patched vulnerabilities in Canva Affinity, TP-Link routers, and HikVision terminals, including several RCE flaws. - IOCs: CVE-2025-66342, CVE-2025-62673, CVE-2025-66176 - #CVE #ThreatIntel #Vulnerabilities
  • 0
  • 0
  • 0
  • 21h ago
Showing 51 to 56 of 56 CVEs