Zum Inhalt springen
Auto-CTI

Was hat sich geändert?

Vergleich von 6. Mai 2026 mit dem Vortag 5. Mai 2026.

Neu hinzugekommen

18
NEU Palo Alto Networks
85

PAN-OS-Lücke wird angegriffen, Updates erst in Wochen geplant

Active exploitation of a critical PAN-OS vulnerability with delayed patching (mid-May) creates an extended attack window affecting critical infrastructure and manufacturing supply chains across DACH region.

Kritisch
NEU Vaultwarden
20

CVE-2026-31835

An attacker with only password knowledge can permanently disable WebAuthn 2FA for a user by corrupting backup flags before signature validation—patch immediately to prevent persistent MFA denial.

Hoch EPSS 0%
NEU Vaultwarden
20

CVE-2026-33420

Manager-role users can enumerate all organizational collections and user/group mappings without explicit collection access, enabling targeted credential theft or social engineering against specific teams.

Hoch EPSS 0%
NEU OpenSSL
20

[UPDATE] OpenSSL: Mehrere Schwachstellen

BSI official advisory signals coordinated vulnerability disclosure affecting critical crypto library across DACH infrastructure; patch urgency depends on CVSS/KEV status not provided in this alert.

Hoch
NEU Linux
20

Linux Kernel: Mehrere Schwachstellen

BSI official advisory on multiple kernel flaws affecting Ubuntu deployments; local exploitation path requires access but potential RCE warrants urgent patching review across ESXi hypervisors and Ubuntu guest VMs.

Hoch
NEU Intel
20

[UPDATE] Intel Prozessoren: Mehrere Schwachstellen

BSI formal advisory on Intel processor vulnerabilities signals German federal agency assessment; affects manufacturing environment running Windows Server and virtualized infrastructure.

Hoch
NEU Oracle
0

[UPDATE] Oracle MySQL: Mehrere Schwachstellen

BSI advisory signals multiple MySQL vulnerabilities affecting confidentiality, integrity, and availability; requires patch assessment if MySQL is deployed in non-stated but common manufacturing IT infrastructure.

Mittel

Neu als KEV gelistet

0

Keine Änderungen in dieser Kategorie.

Score-Sprung

0

Keine Änderungen in dieser Kategorie.

Nicht mehr im Report

23
NEU PLC manufacturer (unspecified in alert)
100

CVE-2026-25293

Kritisch CVSS 9.6 EPSS 0%
NEU Microsoft
62

Patch Tuesday - April 2026

April 2026 patch cycle includes zero-day fixes for SharePoint spoofing, Defender elevation-of-privilege, and Windows IKE pre-auth RCE—all directly relevant to manufacturing operations relying on AD, Remote Desktop Gateway, and Defender for Endpoint.

Mittel CVSS 6.5 EPSS 7%
NEU Microsoft, Google, Adobe
52

Patch Tuesday, April 2026 Edition

BlueHammer (Windows Defender zero-day) and SharePoint Server zero-day represent actively exploited flaws requiring immediate patching ahead of standard patch cycles.

Kritisch
NEU Microsoft
20

Microsoft Windows - Kritische Schwachstelle in Windows OLE

BSI RSS feed publication indicates German federal cybersecurity authority has flagged this as critical for DACH organizations; OLE vulnerabilities commonly exploited in supply-chain and manufacturing sector attacks.

Hoch
ESC