Qilin actors are deliberately exploiting an authentication bypass vulnerability as an entry point into production environments,an indicator of ransomware campaigns targeting the industrial sector.
The alert describes active in-the-wild exploitation (webshell installation, persistent infection) rather than patch availability alone,critical for security of internet-facing WordPress instances.
CVE-2026-50522 is already under active exploitation and is the third SharePoint vulnerability in July 2026 to come under attack immediately after disclosure; prior variants were weaponized as zero-days before patching.
A local privilege escalation flaw in Windows WMI allows local attackers to escalate from low-privilege to SYSTEM-level access; affects Windows Server 2022/2019 and all AD-joined clients in hybrid DACH infrastructure.
A local privilege escalation vulnerability in Windows WMI requires already-compromised low-privilege accounts for exploitation, but poses significant risk in multi-user production environments.
Russian intelligence-linked APTs are actively exploiting misconfigured routers as entry points into European critical-infrastructure organisations; this is an active, ongoing campaign pattern with direct relevance to EU/DACH regions.
MFA bypass in ADSelfService Plus allows attackers to compromise AD-integrated authentication and gain unauthorized access to enterprise-wide resources.
SANDWORM exploits AI coding assistants and LLM toolchains as novel supply-chain attack vectors by fingerprinting runtime behavior of developer workstations and CI automation,a qualitatively new threat class for organizations conducting internal software development.
Critical
NEW North Korea (state-sponsored), Russia (beneficiary) C3
North Korean IT worker networks directly finance Russia's war effort through sanctions evasion; this demonstrates an operationalized alliance between North Korea and Russia that elevates DACH organizations as potential targets for retaliation or espionage.
The vulnerability enables remote code execution via specially crafted HTML pages without prior authentication, requiring immediate patch prioritization for all Chrome installations in production environments.
The Qilin ransomware group is actively exploiting a critical authentication bypass flaw in Palo Alto PAN-OS GlobalProtect to infiltrate networks, indicating an ongoing campaign against enterprise environments.
The vulnerability enables remote code execution within the Chrome sandbox via crafted HTML pages, but is a standard patch update with no evidence of active exploitation in the wild.
The vulnerability allows local attackers to exploit heap corruption via malicious files; it requires local access and is therefore primarily relevant in scenarios involving untrusted file handling or USB access.
Kratos platform automated approximately 15,000 phishing campaigns per month; BKA dismantling reveals operational vulnerability of centralized phishing-as-a-service infrastructure in German jurisdiction.
BSI warning for multiple unspecified vulnerabilities in Chrome and Edge , patch details are missing; follow-up advisories with CVE numbers and CVSS scores are to be expected.
HollowGraph abuses Microsoft's legitimate Calendar service as a bidirectional command-and-control channel, bypassing traditional email and network-based detection and blurring the line between legitimate cloud operations and malware communication.
The BSI/BürgerCERT advisory discloses multiple vulnerabilities in widely-used browsers without technical details, likely coordinating with vendors ahead of public disclosure.
The BSI warning covers multiple unspecified vulnerabilities in Firefox/Thunderbird without CVE details or active exploitation confirmation; unclear whether public exploits exist or if this is an aggregated patch summary.
wp2shell vulnerabilities in WordPress Core enable unauthenticated remote code execution; exploitation activity began within hours of patch release, and compromised sites are used as delivery mechanisms for credential theft, malware, and fraud.
Unknown threat actors are actively exploiting multiple SonicWall SMA1000 zero-days to deploy custom malware on VPN appliances , a direct attack vector against remote access infrastructure.
OilRig APT exploits Outlook calendar events as a steganographic C2 channel and leverages DNS AAAA records for configuration recovery,a novel abuse pattern of Microsoft-hosted services.
A leading remote access provider was ordered by German financial regulator to pay damages , a signal for increased liability of security failures in critical B2B tools.
The alert describes a known operational issue with WSUS synchronization without new security or exploit implications, but only administrative measures to resolve delays.
BSI warning on generic Linux kernel DoS vulnerabilities without specific CVE references or exploit status , requires contextualisation and link to specific patches.
The vulnerability allows unauthenticated attackers to expose user responses and cause system unavailability through crafted HTTP requests , a critical risk for SAP-based ERP infrastructure.
The vulnerability requires authentication and exploits memory management errors, which means lower exploitation risk for ERP systems with restricted network access, but becomes critical if user accounts are compromised.
The vulnerability enables authentication bypass through manipulated HTTP headers without requiring user interaction , organizations with cloud-based SAP deployments should prioritize reviewing their Approuter configuration.
The vulnerability affects a simulation environment, not production systems directly; however, it poses a risk to engineering workstations and development workflows in manufacturing operations.
The vulnerability requires authentication and manual processing of a malicious archive file, which limits attack surface in typical production environments but is relevant for SAP administrators and change-management workflows.
Russian state-sponsored APTs are actively exploiting poorly secured routers in critical infrastructure using seven-year-old known vulnerabilities, signaling a coordinated campaign focused on persistent network presence.
The vulnerability requires already-high privileges for exploitation and is limited to confidentiality impact, indicating relatively constrained risk in typical deployment scenarios.
Reflected XSS in SAP NetWeaver enables JavaScript execution in the victim's browser under certain conditions, leading to session theft and authenticated actions in the user's context.
The vulnerability allows restricted authenticated users to access information from other entities and escalate privileges without authorization checks being performed.
BSI warning of multiple critical Windows vulnerabilities with potential for privilege escalation and code execution , the exact CVE portfolio and patch date must be obtained from the official BSI WID entry.
The article is a patch announcement without CVE numbers, active exploitation details, or affected customer groups, and provides no strategic information beyond standard patch advisory.
The alert generically describes 16 partially critical SAP flaws without specific CVE numbers, affected product versions, or exploitability details , it is a pure patch announcement without operational added value.
The BSI warning describes multiple 7-Zip vulnerabilities without specific CVE numbers or CVSS scores; further details on exploitability and affected versions are required.
An authentication bypass (CVE-2026-55040) was chained by Rapid7 Labs with a separate RCE vulnerability to achieve unauthenticated remote code execution; patching the bypass breaks the exploit chain.
Eleven forgotten Microsoft-signed UEFI bootloaders can bypass Secure Boot and enable malicious code execution during system startup, independent of the installed operating system.
Attackers exploit OAuth Client ID spoofing to validate stolen credentials against Microsoft Entra ID without detection, as no successful sign-in event is logged.
The Patch Day aggregates multiple vulnerabilities (RCE, DoS, information disclosure, SQL injection, XSS) with varying impacts and requires prioritized patch management.
New phishing kits use advanced social engineering techniques to bypass multi-factor authentication, posing an immediate threat to organizations relying on Microsoft 365.
ShinyHunters-associated campaigns exploit vishing attacks to compromise OAuth access to Salesforce instances, combined with supply-chain attacks through trusted integrations such as Salesloft and Gainsight.
BSI warning on multiple Linux kernel CVEs without specific CVE identifiers in this notice; likely a summary of ongoing or newly disclosed vulnerabilities.