BSI-Sicherheitshinweise
Aktuelle Warnungen des BSI (CERT-Bund) zu Software aus unserem Katalog — mit Link auf die Originalmeldung.
Das BSI veröffentlicht deutlich mehr Hinweise als hier stehen, quer über Software, die die meisten von euch nicht betreiben. Aufgeführt sind die Meldungen, die wir einem Produkt aus unserem Katalog eindeutig zuordnen konnten.
- WID-SEC-W-2026-118025. Aug.
Linux Kernel: Mehrere Schwachstellen
CVE-2026-31429 · CVE-2026-31430
Beim BSI ansehen → - WID-SEC-W-2026-252625. Aug.
ffmpeg: Mehrere Schwachstellen
CVE-2026-66036 · CVE-2026-66037 · CVE-2026-66038 · CVE-2026-66039 · CVE-2026-66040 · CVE-2026-66041
Beim BSI ansehen → - WID-SEC-W-2026-248125. Aug.
Linux Kernel: Schwachstelle ermöglicht Privilegieneskalation
CVE-2026-64600
Beim BSI ansehen → - WID-SEC-W-2026-245225. Aug.
Red Hat Ansible Automation Platform (node-tar, linkify-it, protobufjs, brace-expansion, fast-uri, DOMPurify): Mehrere Schwachstellen
CVE-2026-59873 · CVE-2026-59874 · CVE-2026-48801 · CVE-2026-44289 · CVE-2026-44290 · CVE-2026-44291 · +5
Beim BSI ansehen → - WID-SEC-W-2026-177625. Aug.
Golang Go: Mehrere Schwachstellen
Betrifft:Red Hat Enterprise LinuxRocky LinuxGoFedoraopenSUSE LeapAmazon LinuxOracle LinuxRed Hat OpenShiftCVE-2026-27145 · CVE-2026-42504 · CVE-2026-42507
Beim BSI ansehen → - WID-SEC-W-2026-187025. Aug.
Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service
Betrifft:Ubuntu ServerDebianRed Hat Enterprise LinuxRocky LinuxopenSUSE LeapAmazon LinuxOracle LinuxRed Hat OpenShiftLinux KernelCVE-2026-46316 · CVE-2026-46317 · CVE-2026-46318 · CVE-2026-46319 · CVE-2026-46320 · CVE-2026-46321 · +14
Beim BSI ansehen → - WID-SEC-W-2026-175625. Aug.
Linux Kernel: Schwachstelle ermöglicht Privilegieneskalation und Denial of Service
Betrifft:Ubuntu ServerDebianRed Hat Enterprise LinuxopenSUSE LeapOracle LinuxRed Hat OpenShiftLinux KernelCVE-2026-46242
Beim BSI ansehen → - WID-SEC-W-2026-157125. Aug.
Linux Kernel: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
Betrifft:Ubuntu ServerDebianRed Hat Enterprise LinuxFedoraopenSUSE LeapAmazon LinuxOracle LinuxContainer-Optimized OSLinux KernelCVE-2026-46333
Beim BSI ansehen → - WID-SEC-W-2026-127925. Aug.
Linux Kernel: Mehrere Schwachstellen
Betrifft:Ubuntu ServerDebianRed Hat Enterprise LinuxRocky LinuxopenSUSE LeapOracle LinuxContainer-Optimized OSLinux KernelCVE-2026-31535 · CVE-2026-31536 · CVE-2026-31537 · CVE-2026-31538 · CVE-2026-31539 · CVE-2026-31540 · +145
Beim BSI ansehen → - WID-SEC-W-2025-166525. Aug.
Linux Kernel: Mehrere Schwachstellen
Betrifft:Ubuntu ServerDebianRed Hat Enterprise LinuxRocky LinuxopenSUSE LeapAmazon LinuxOracle LinuxContainer-Optimized OSLinux KernelCVE-2024-50047 · CVE-2025-38468 · CVE-2025-38469 · CVE-2025-38470 · CVE-2025-38471 · CVE-2025-38472 · +24
Beim BSI ansehen → - WID-SEC-W-2026-126725. Aug.
Red Hat Hardened Images RPMs: Mehrere Schwachstellen
CVE-2025-69277 · CVE-2026-2100 · CVE-2026-41989 · CVE-2026-4878
Beim BSI ansehen → - WID-SEC-W-2026-205225. Aug.
cURL: Mehrere Schwachstellen
CVE-2026-10536 · CVE-2026-11352 · CVE-2026-11564 · CVE-2026-11586 · CVE-2026-11856 · CVE-2026-12064 · +4
Beim BSI ansehen → - WID-SEC-W-2025-259525. Aug.
Linux Kernel: Mehrere Schwachstellen
Betrifft:Ubuntu ServerDebianRed Hat Enterprise LinuxRocky LinuxopenSUSE LeapAmazon LinuxOracle LinuxContainer-Optimized OSLinux KernelCVE-2025-40178 · CVE-2025-40179 · CVE-2025-40180 · CVE-2025-40181 · CVE-2025-40182 · CVE-2025-40183 · +25
Beim BSI ansehen → - WID-SEC-W-2026-242325. Aug.
CUPS (libcupsfilters, cups-filters): Schwachstelle ermöglicht Denial of Service
CVE-2026-64612
Beim BSI ansehen → - WID-SEC-W-2026-223925. Aug.
Golang Go: Mehrere Schwachstellen ermöglichen Offenlegung von Informationen
Betrifft:Red Hat Enterprise LinuxRocky LinuxGoopenSUSE LeapAmazon LinuxOracle LinuxRed Hat OpenShiftCVE-2026-39822 · CVE-2026-42505
Beim BSI ansehen → - WID-SEC-W-2026-227225. Aug.
CPython: Schwachstelle ermöglicht Denial of Service
CVE-2026-15308
Beim BSI ansehen → - WID-SEC-W-2026-264925. Aug.
Django: Mehrere Schwachstellen
CVE-2026-15307 · CVE-2026-15337 · CVE-2026-15830 · CVE-2026-15920
Beim BSI ansehen → - WID-SEC-W-2026-106425. Aug.
CPython: Mehrere Schwachstellen
Betrifft:Ubuntu ServerRed Hat Enterprise LinuxRocky LinuxPythonFedoraopenSUSE LeapAmazon LinuxOracle LinuxCVE-2026-1502 · CVE-2026-3446
Beim BSI ansehen → - WID-SEC-W-2026-203125. Aug.
Linux Kernel: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff
CVE-2026-52908 · CVE-2026-52909 · CVE-2026-52910 · CVE-2026-52911
Beim BSI ansehen → - WID-SEC-W-2026-204425. Aug.
CPython: Mehrere Schwachstellen
CVE-2026-0864 · CVE-2026-11940
Beim BSI ansehen → - WID-SEC-W-2026-199525. Aug.
NGINX und NGINX Plus: Mehrere Schwachstellen
CVE-2026-11311 · CVE-2026-32682 · CVE-2026-42055 · CVE-2026-42530 · CVE-2026-48142 · CVE-2026-50107
Beim BSI ansehen → - WID-SEC-W-2026-108725. Aug.
CPython: Mehrere Schwachstellen
Betrifft:Ubuntu ServerDebianRed Hat Enterprise LinuxRocky LinuxPythonFedoraopenSUSE LeapOracle LinuxCVE-2026-4786 · CVE-2026-6100
Beim BSI ansehen → - WID-SEC-W-2026-068025. Aug.
Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service
CVE-2026-23239 · CVE-2026-23240
Beim BSI ansehen → - WID-SEC-W-2026-238225. Aug.
Linux Kernel: Schwachstelle ermöglicht Denial of Service
CVE-2026-53366
Beim BSI ansehen → - WID-SEC-W-2026-197125. Aug.
CPython: Mehrere Schwachstellen
CVE-2026-12003 · CVE-2026-3276
Beim BSI ansehen → - WID-SEC-W-2026-179625. Aug.
CPython: Schwachstelle ermöglicht Manipulation von Dateien
CVE-2026-7774
Beim BSI ansehen → - WID-SEC-W-2026-152025. Aug.
CPython: Schwachstelle ermöglicht Manipulation von Daten
CVE-2026-8328
Beim BSI ansehen → - WID-SEC-W-2026-147225. Aug.
CPython: Schwachstelle ermöglicht Denial of Service
CVE-2026-7210
Beim BSI ansehen → - WID-SEC-W-2026-129425. Aug.
Linux Kernel: Mehrere Schwachstellen
CVE-2026-31686 · CVE-2026-31687 · CVE-2026-31688 · CVE-2026-31689 · CVE-2026-31690 · CVE-2026-31691
Beim BSI ansehen → - WID-SEC-W-2026-080925. Aug.
Linux Kernel: Mehrere Schwachstellen
CVE-2026-23271 · CVE-2026-23272 · CVE-2026-23273 · CVE-2026-23274 · CVE-2026-23275 · CVE-2026-23276 · +2
Beim BSI ansehen → - WID-SEC-W-2026-168425. Aug.
Linux Kernel (Bluetooth): Mehrere Schwachstellen ermöglichen Denial of Service
CVE-2026-45834 · CVE-2026-45835 · CVE-2026-45836
Beim BSI ansehen → - WID-SEC-W-2024-376225. Aug.
Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service
Betrifft:Ubuntu ServerDebianRed Hat Enterprise LinuxRocky LinuxAmazon LinuxOracle LinuxRed Hat OpenShiftLinux KernelCVE-2024-53172 · CVE-2024-53176 · CVE-2024-53178 · CVE-2024-53179 · CVE-2024-53180 · CVE-2024-53181 · +273
Beim BSI ansehen → - WID-SEC-W-2025-151725. Aug.
Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service
CVE-2025-38238 · CVE-2025-38241 · CVE-2025-38242 · CVE-2025-38243 · CVE-2025-38244 · CVE-2025-38245 · +19
Beim BSI ansehen → - WID-SEC-W-2026-253325. Aug.
Erlang/OTP: Mehrere Schwachstellen
CVE-2026-42792 · CVE-2026-54890 · CVE-2026-55737 · CVE-2026-58227 · CVE-2026-59251 · CVE-2026-59250 · +2
Beim BSI ansehen → - WID-SEC-W-2026-161025. Aug.
Red Hat Enterprise Linux (JWCrypto und python-markdown): Mehrere Schwachstellen ermöglichen Denial of Service
CVE-2025-69534 · CVE-2026-39373
Beim BSI ansehen → - WID-SEC-W-2026-152725. Aug.
NGINX Open Source and NGINX Plus: Mehrere Schwachstellen
Betrifft:Ubuntu ServerDebianRed Hat Enterprise LinuxRocky LinuxnginxFedoraopenSUSE LeapAmazon LinuxOracle LinuxCVE-2026-40460 · CVE-2026-40701 · CVE-2026-42926 · CVE-2026-42934 · CVE-2026-42945 · CVE-2026-42946
Beim BSI ansehen → - WID-SEC-W-2026-251625. Aug.
libssh2: Mehrere Schwachstellen
CVE-2026-66032 · CVE-2026-66033 · CVE-2026-66034 · CVE-2026-66035
Beim BSI ansehen → - WID-SEC-W-2026-133225. Aug.
libssh2: Schwachstelle ermöglicht Denial of Service
CVE-2026-7598
Beim BSI ansehen → - WID-SEC-W-2026-209925. Aug.
libssh2: Mehrere Schwachstellen
CVE-2026-58050 · CVE-2026-58051
Beim BSI ansehen → - WID-SEC-W-2026-199625. Aug.
libssh2: Mehrere Schwachstellen
CVE-2026-55199 · CVE-2026-55200
Beim BSI ansehen → - WID-SEC-W-2025-292925. Aug.
Linux Kernel: Mehrere Schwachstellen
Betrifft:Ubuntu ServerDebianRed Hat Enterprise LinuxRocky LinuxopenSUSE LeapAmazon LinuxOracle LinuxLinux KernelCVE-2022-50712 · CVE-2022-50713 · CVE-2022-50714 · CVE-2022-50715 · CVE-2022-50716 · CVE-2022-50717 · +201
Beim BSI ansehen → - WID-SEC-W-2025-054525. Aug.
Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service
Betrifft:Ubuntu ServerDebianRed Hat Enterprise LinuxRocky LinuxAmazon LinuxOracle LinuxContainer-Optimized OSLinux KernelCVE-2024-58087 · CVE-2024-58088 · CVE-2024-58089 · CVE-2025-21844 · CVE-2025-21845 · CVE-2025-21846 · +20
Beim BSI ansehen → - WID-SEC-W-2026-139325. Aug.
LibreOffice: Schwachstelle ermöglicht nicht spezifizierten Angriff
CVE-2026-4430
Beim BSI ansehen → - WID-SEC-W-2026-252225. Aug.
vim: Mehrere Schwachstellen
Betrifft:VimCVE-2026-73076 · CVE-2026-73072 · CVE-2026-73071
Beim BSI ansehen → - WID-SEC-W-2026-086025. Aug.
NGINX und NGINX Plus: Mehrere Schwachstellen
Betrifft:Ubuntu ServerDebianRed Hat Enterprise LinuxRocky LinuxnginxFedoraopenSUSE LeapAmazon LinuxOracle LinuxCVE-2026-27651 · CVE-2026-27654 · CVE-2026-27784 · CVE-2026-32647 · CVE-2026-28755 · CVE-2026-28753
Beim BSI ansehen → - WID-SEC-W-2026-256425. Aug.
IBM WebSphere Application Server und Application Server Liberty: Mehrere Schwachstellen
Betrifft:IBM iCVE-2026-14446 · CVE-2026-14512 · CVE-2026-14515 · CVE-2026-14528 · CVE-2026-14529 · CVE-2026-14974 · +10
Beim BSI ansehen → - WID-SEC-W-2026-240425. Aug.
IBM WebSphere Application Server: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
Betrifft:IBM iCVE-2026-10842
Beim BSI ansehen → - WID-SEC-W-2026-265825. Aug.
X.Org X11 (libXfont2): Mehrere Schwachstellen ermöglichen Privilegieneskalation und Denial of Service
CVE-2026-44950 · CVE-2026-59679
Beim BSI ansehen → - WID-SEC-W-2026-300225. Aug.
libTIFF: Mehrere Schwachstellen
Betrifft:LibTIFFCVE-2026-52490 · CVE-2026-52492
Beim BSI ansehen → - WID-SEC-W-2026-300125. Aug.
Django: Mehrere Schwachstellen
Betrifft:DjangoCVE-2026-54623 · CVE-2026-54625
Beim BSI ansehen → - WID-SEC-W-2026-300025. Aug.
Red Hat Enterprise Linux (Apicurio Registry): Mehrere Schwachstellen
Betrifft:Red Hat Enterprise LinuxCVE-2026-12975 · CVE-2026-12992 · CVE-2026-12993 · CVE-2026-41240 · CVE-2026-44496 · CVE-2026-49978
Beim BSI ansehen → - WID-SEC-W-2026-299925. Aug.
Contao: Mehrere Schwachstellen
Betrifft:ContaoBeim BSI ansehen → - WID-SEC-W-2026-299825. Aug.
ZScaler Client Connector: Mehrere Schwachstellen
Betrifft:Zscaler Client ConnectorCVE-2026-59564 · CVE-2026-59565 · CVE-2026-59566 · CVE-2026-59567 · CVE-2026-59568
Beim BSI ansehen → - WID-SEC-W-2026-298525. Aug.
Checkmk: Schwachstelle ermöglicht Offenlegung von Informationen
Betrifft:CheckmkCVE-2026-17548
Beim BSI ansehen → - WID-SEC-W-2023-060025. Aug.
Red Hat OpenShift: Schwachstelle ermöglicht Manipulation von Dateien
Betrifft:Red Hat OpenShiftCVE-2022-4318
Beim BSI ansehen → - WID-SEC-W-2026-299625. Aug.
Zammad: Mehrere Schwachstellen
Betrifft:ZammadBeim BSI ansehen → - WID-SEC-W-2026-166125. Aug.
NGINX Open Source und NGINX Plus: Schwachstelle ermöglicht Denial of Service und potenziell Codeausführung
Betrifft:Ubuntu ServerDebianRed Hat Enterprise LinuxRocky LinuxnginxopenSUSE LeapAmazon LinuxOracle LinuxCVE-2026-9256
Beim BSI ansehen → - WID-SEC-W-2026-299525. Aug.
Langflow OSS: Mehrere Schwachstellen
Betrifft:LangflowCVE-2026-18729 · CVE-2026-19286 · CVE-2026-19295
Beim BSI ansehen → - WID-SEC-W-2026-299325. Aug.
Hashicorp Vault: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
Betrifft:HashiCorp VaultCVE-2026-5006
Beim BSI ansehen → - WID-SEC-W-2026-219025. Aug.
Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service
CVE-2026-53357 · CVE-2026-53358
Beim BSI ansehen →
Wie das gemeint ist
Eine Meldung hier heißt: Das BSI hat für dieses Produkt einen Sicherheitshinweis veröffentlicht. Sie sagt nichts darüber, ob deine Version betroffen ist — das steht in der Originalmeldung. Und wenn ein Produkt hier fehlt, heißt das nicht, dass es sicher ist: Es heißt, dass wir keine eindeutige Zuordnung hatten.
Diese Hinweise lösen keine Mails aus. Update- und Security-Mails bekommst du weiterhin über deine Abos.