Recent changes

Favicon for wid.cert-bund.de

Drupal Automated Logout Extension Vulnerability Allows File Manipulation

CERT-Bund has issued a security advisory regarding a vulnerability in Drupal's Automated Logout Extension. The vulnerability allows remote, anonymous attackers to manipulate files. Affected versions include Open Source Drupal Automated Logout <1.7.0 and <2.0.2.

Priority review Notice Cybersecurity
Favicon for wid.cert-bund.de

IBM QRadar SIEM Critical Vulnerabilities

CERT-Bund has issued a security advisory regarding critical vulnerabilities in IBM QRadar SIEM, versions prior to 7.5.0 UP15. These vulnerabilities, with a CVSS Base Score of 9.8, allow for remote code execution, information disclosure, denial of service, and file manipulation.

Urgent Notice Cybersecurity
Favicon for wid.cert-bund.de

Jenkins Vulnerabilities Allow Code Execution and Info Disclosure

CERT-Bund has issued a security advisory for Jenkins, detailing multiple vulnerabilities with a high CVSS base score. These vulnerabilities allow attackers to execute arbitrary code, bypass security measures, and disclose confidential information. Affected versions include Jenkins weekly <2.555 and Jenkins LTS <2.541.3.

Priority review Notice Cybersecurity
Favicon for wid.cert-bund.de

Ubiquiti UniFi Vulnerabilities Allow Privilege Escalation

CERT-Bund has issued a security advisory for Ubiquiti UniFi Network Application, detailing vulnerabilities that allow for privilege escalation. The advisory assigns a critical CVSS Base Score of 10.0 and a high CVSS Temporal Score of 8.7, indicating a significant security risk. Affected versions include UniFi Network Application <10.1.89, <10.2.97, <9.0.118, and UniFi Express <4.0.13.

Urgent Notice Cybersecurity
Favicon for wid.cert-bund.de

Xpdf Vulnerability Allows Denial of Service

CERT-Bund has issued a security advisory regarding a denial-of-service vulnerability in the Xpdf PDF viewer. The vulnerability affects versions of Xpdf on Linux, UNIX, and Windows systems. The advisory provides information on the vulnerability and mitigation, noting a CVSS base score of 2.9.

Routine Notice Cybersecurity
Favicon for wid.cert-bund.de

Dell Secure Connect Gateway Policy Manager Critical Vulnerabilities

CERT-Bund has issued a security advisory for Dell Secure Connect Gateway Policy Manager, detailing critical vulnerabilities (CVSS Base Score 9.8) that could allow remote attacks. The advisory affects versions prior to 5.34.00.14 and recommends mitigation.

Urgent Notice Cybersecurity
Favicon for wid.cert-bund.de

libarchive Vulnerability Allows Denial-of-Service

CERT-Bund has issued a security advisory regarding a vulnerability in the libarchive library, which allows for denial-of-service attacks. The vulnerability affects various operating systems including Linux, UNIX, and Windows, and specific versions of Red Hat Enterprise Linux. Mitigation measures are available.

Priority review Notice Cybersecurity
Favicon for wid.cert-bund.de

Samba Vulnerability Allows Information Disclosure

CERT-Bund has issued an advisory regarding a Samba vulnerability (WID-SEC-2026-0780) that allows local attackers to disclose information. The vulnerability affects Open Source Samba versions prior to 4.24.0 and has a CVSS Base Score of 5.5.

Priority review Notice Cybersecurity
Favicon for wid.cert-bund.de

Microsoft Dynamics 365 SQL Injection Vulnerability

CERT-Bund has issued a security advisory for Microsoft Dynamics 365 Customer Engagement regarding a critical SQL injection vulnerability (CVSS 8.8). The vulnerability allows authenticated remote attackers to execute arbitrary SQL commands, potentially leading to privilege escalation or operating system command execution.

Priority review Notice Cybersecurity
Favicon for wid.cert-bund.de

Keycloak Vulnerabilities: Info Disclosure and Privilege Escalation

CERT-Bund has issued a security advisory regarding critical vulnerabilities in Keycloak versions prior to 26.5.6. These vulnerabilities allow for remote information disclosure and privilege escalation. Mitigation is available.

Urgent Notice Cybersecurity

Showing 21–30 of 143 changes

1 2 3 4 5 15

Get Germany alerts

Daily digest of regulatory changes. AI-summarized, no noise.

Free. Unsubscribe anytime.