BSI security advisories
We list the most recent security advisories from the German BSI (CERT-Bund) that we could match to a product in our catalogue without ambiguity, each linked to the original.
The BSI publishes considerably more advisories than are listed here, across software most of you do not run.
- WID-SEC-W-2026-33199 Oct
Red Hat Enterprise Linux (GNU coreutils unexpand): Schwachstelle ermöglicht DoS und Manipulation von Dateien
CVE-2026-56392
View at the BSI → - WID-SEC-W-2026-28329 Oct
Linux Kernel: Mehrere Schwachstellen
CVE-2026-68451 · CVE-2026-68452 · CVE-2026-68453 · CVE-2026-68454
View at the BSI → - WID-SEC-W-2026-38019 Oct
Checkmk: Schwachstelle ermöglicht Privilegieneskalation
Affects:CheckmkCVE-2026-105331
View at the BSI → - WID-SEC-W-2026-33439 Oct
wpa_supplicant: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
Affects:openSUSE LeapCVE-2026-78807
View at the BSI → - WID-SEC-W-2026-22729 Oct
CPython: Schwachstelle ermöglicht Denial of Service
Affects:Amazon LinuxDebianFedoraContainer-Optimized OSIBM AIXPythonOracle LinuxRocky LinuxRed Hat Enterprise LinuxopenSUSE LeapUbuntu ServerCVE-2026-15308
View at the BSI → - WID-SEC-W-2026-20319 Oct
Linux Kernel: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff
CVE-2026-52908 · CVE-2026-52909 · CVE-2026-52910 · CVE-2026-52911
View at the BSI → - WID-SEC-W-2026-22259 Oct
Red Hat Enterprise Linux (389-ds-base): Mehrere Schwachstellen ermöglichen Codeausführung und DoS
CVE-2026-11610 · CVE-2026-11774
View at the BSI → - WID-SEC-W-2026-25749 Oct
Ruby on Rails: Schwachstelle ermöglicht Offenlegung von Informationen
Affects:DebianCVE-2026-66066
View at the BSI → - WID-SEC-W-2026-31769 Oct
bluez: Schwachstelle ermöglicht Codeausführung
Affects:Ubuntu ServerCVE-2026-85218
View at the BSI → - WID-SEC-W-2026-27209 Oct
Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service
CVE-2026-68081 · CVE-2026-68082
View at the BSI → - WID-SEC-W-2026-22359 Oct
Composer: Mehrere Schwachstellen
Affects:ComposerCVE-2026-59946 · CVE-2026-59947 · CVE-2026-59948
View at the BSI → - WID-SEC-W-2022-04619 Oct
CoreDNS: Mehrere Schwachstellen ermöglichen Denial of Service
CVE-2022-27191 · CVE-2022-28948
View at the BSI → - WID-SEC-W-2026-23869 Oct
BusyBox: Mehrere Schwachstellen ermöglichen Denial of Service
CVE-2026-38752 · CVE-2026-38753 · CVE-2026-38754 · CVE-2026-38755
View at the BSI → - WID-SEC-W-2026-28439 Oct
OpenSSL: Schwachstelle ermöglicht Denial of Service
CVE-2026-14456
View at the BSI → - WID-SEC-W-2026-19779 Oct
Red Hat Enterprise Linux (dracut): Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit Administratorrechten
Affects:Amazon LinuxOracle LinuxRocky LinuxRed Hat Enterprise LinuxRed Hat OpenShiftopenSUSE LeapUbuntu ServerCVE-2026-6893
View at the BSI → - WID-SEC-W-2026-29849 Oct
bluez: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit Administratorrechten
CVE-2026-19774
View at the BSI → - WID-SEC-W-2026-27409 Oct
GNU libc: Schwachstelle ermöglicht Denial of Service
CVE-2026-6368
View at the BSI → - WID-SEC-W-2026-02249 Oct
Grafana: Mehrere Schwachstellen
CVE-2026-21720 · CVE-2026-21721
View at the BSI → - WID-SEC-W-2026-10679 Oct
Apache log4j: Mehrere Schwachstellen ermöglichen Manipulation von Dateien
CVE-2026-34477 · CVE-2026-34478 · CVE-2026-34479 · CVE-2026-34480 · CVE-2026-34481
View at the BSI → - WID-SEC-W-2025-13259 Oct
libxml2: Schwachstelle ermöglicht Denial of Service
Affects:DebianFluentdlibxml2Oracle LinuxRocky LinuxRed Hat Enterprise LinuxopenSUSE LeapUbuntu ServerCVE-2025-6170
View at the BSI → - WID-SEC-W-2026-22829 Oct
CUPS: Schwachstelle ermöglicht Offenlegung von Informationen
Affects:CUPSCVE-2026-107655 · CVE-2026-61702
View at the BSI → - WID-SEC-W-2026-38509 Oct
Obsidian: Mehrere Schwachstellen
Affects:ObsidianCVE-2026-104077 · CVE-2026-104078
View at the BSI → - WID-SEC-W-2026-38499 Oct
Keycloak: Mehrere Schwachstellen
Affects:KeycloakCVE-2026-107604 · CVE-2026-107623 · CVE-2026-107889
View at the BSI → - WID-SEC-W-2026-38489 Oct
Red Hat Enterprise Linux (sssd, tftp, ansible-collection-ansible-posix): Mehrere Schwachstellen
CVE-2026-11837 · CVE-2026-85234 · CVE-2026-87853
View at the BSI → - WID-SEC-W-2026-38479 Oct
Citrix NetScaler ADC und Gateway: Schwachstelle ermöglicht Codeausführung und DoS
Affects:NetScaler ADC / GatewayCVE-2026-107406
View at the BSI → - WID-SEC-W-2026-38469 Oct
Hazelcast: Mehrere Schwachstellen
Affects:HazelcastCVE-2026-107725 · CVE-2026-107726
View at the BSI → - WID-SEC-W-2026-32159 Oct
Red Hat Directory Server und Enterprise Linux (389-ds-base): Mehrere Schwachstellen
CVE-2026-19843 · CVE-2026-18355 · CVE-2026-18453 · CVE-2026-76560 · CVE-2026-18922
View at the BSI → - WID-SEC-W-2026-30149 Oct
GNU libc: Mehrere Schwachstellen
CVE-2026-19499 · CVE-2026-19542 · CVE-2026-77117
View at the BSI → - WID-SEC-W-2026-29059 Oct
bluez: Schwachstelle ermöglicht Denial of Service und Offenlegung von Informationen
CVE-2026-75032
View at the BSI → - WID-SEC-W-2026-38419 Oct
Golang Go: Mehrere Schwachstellen
Affects:GoCVE-2026-56857 · CVE-2026-56866 · CVE-2026-78659 · CVE-2026-78660 · CVE-2026-78663 · CVE-2026-78667 · +9
View at the BSI → - WID-SEC-W-2026-38409 Oct
Nextcloud: Mehrere Schwachstellen
Affects:NextcloudCVE-2026-68493 · CVE-2026-77165 · CVE-2026-77166 · CVE-2026-77169 · CVE-2026-82985
View at the BSI → - WID-SEC-W-2026-38399 Oct
Zammad: Schwachstelle ermöglicht Privilegienerweiterung
Affects:ZammadCVE-2026-102490
View at the BSI → - WID-SEC-W-2026-24299 Oct
Synacor Zimbra: Mehrere Schwachstellen
Affects:Zimbra CollaborationCVE-2026-10631 · CVE-2026-50054 · CVE-2026-50055 · CVE-2026-73570
View at the BSI → - WID-SEC-W-2026-38389 Oct
MariaDB Connector/Node.js: Mehrere Schwachstellen
Affects:MariaDBCVE-2026-107382 · CVE-2026-107383 · CVE-2026-107384 · CVE-2026-107385
View at the BSI → - WID-SEC-W-2026-38379 Oct
IBM DB2: Mehrere Schwachstellen
Affects:IBM Db2CVE-2026-104332 · CVE-2026-104364 · CVE-2026-105464 · CVE-2026-105465 · CVE-2026-105466 · CVE-2026-18166 · +1
View at the BSI → - WID-SEC-W-2026-20529 Oct
cURL: Mehrere Schwachstellen
Affects:Amazon LinuxFedoraIBM AIXcurlOracle LinuxRocky LinuxRed Hat Enterprise LinuxSplunkUbuntu ServerCVE-2026-10536 · CVE-2026-11352 · CVE-2026-11564 · CVE-2026-11586 · CVE-2026-11856 · CVE-2026-12064 · +4
View at the BSI → - WID-SEC-W-2026-38339 Oct
IBM i: Schwachstelle ermöglicht Cross-Site Scripting
Affects:IBM iCVE-2026-93886
View at the BSI → - WID-SEC-W-2026-38309 Oct
MongoDB Treiber: Mehrere Schwachstellen
Affects:MongoDBCVE-2026-106428 · CVE-2026-106429 · CVE-2026-106430 · CVE-2026-106433 · CVE-2026-106434 · CVE-2026-106436 · +7
View at the BSI → - WID-SEC-W-2026-38299 Oct
Snipe-IT: Mehrere Schwachstellen
Affects:Snipe-ITView at the BSI → - WID-SEC-W-2023-31749 Oct
SSH Protokoll: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
Affects:Amazon LinuxDebianFedoraFortiOS (FortiGate)FreeBSDGoIBM AIXIGEL OSJenkinsJunos OSLANCOM LCOSDBeaverGiteaOpenBSDPuTTYOracle LinuxPAN-OSRocky LinuxRed Hat Enterprise LinuxRed Hat OpenShiftopenSUSE LeapSplunkUbuntu ServerCVE-2023-48795
View at the BSI → - WID-SEC-W-2026-24199 Oct
Red Hat Enterprise Linux (sssd, glib, c-ares): Mehrere Schwachstellen
Affects:Amazon LinuxOracle LinuxRocky LinuxRed Hat Enterprise LinuxRed Hat OpenShiftopenSUSE LeapUbuntu ServerCVE-2026-14474 · CVE-2026-14476 · CVE-2026-33630 · CVE-2026-58016
View at the BSI → - WID-SEC-W-2026-38289 Oct
vllm: Mehrere Schwachstellen
Affects:vLLMView at the BSI → - WID-SEC-W-2026-38279 Oct
GStreamer: Mehrere Schwachstellen
Affects:GStreamerCVE-2026-86476
View at the BSI → - WID-SEC-W-2026-38269 Oct
Xen: Schwachstelle ermöglicht Denial of Service
Affects:XenCVE-2026-98375
View at the BSI → - WID-SEC-W-2026-38229 Oct
Linux Kernel: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff
Affects:Linux KernelCVE-2026-98375 · CVE-2026-98376 · CVE-2026-98377 · CVE-2026-98378 · CVE-2026-98379 · CVE-2026-98380 · +4
View at the BSI → - WID-SEC-W-2026-34349 Oct
Eclipse Jetty: Schwachstelle ermöglicht Darstellen falscher Informationen und Offenlegung
Affects:Eclipse JettyCVE-2026-19203
View at the BSI → - WID-SEC-W-2026-37619 Oct
Google Chrome / Microsoft Edge: Mehrere Schwachstellen
CVE-2026-102322 · CVE-2026-106179 · CVE-2026-106180 · CVE-2026-106181 · CVE-2026-106182 · CVE-2026-106183 · +241
View at the BSI → - WID-SEC-W-2026-09429 Oct
xz: Schwachstelle ermöglicht Codeausführung
Affects:DebianContainer-Optimized OSOracle LinuxRocky LinuxRed Hat Enterprise LinuxopenSUSE LeapUbuntu ServerCVE-2026-34743
View at the BSI → - WID-SEC-W-2026-23139 Oct
Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service
CVE-2026-53364 · CVE-2026-53365
View at the BSI → - WID-SEC-W-2026-25499 Oct
Samba: Mehrere Schwachstellen
CVE-2026-58216 · CVE-2026-58218 · CVE-2026-58221 · CVE-2026-58222 · CVE-2026-58224 · CVE-2026-6949
View at the BSI → - WID-SEC-W-2023-30119 Oct
BusyBox: Mehrere Schwachstellen
CVE-2023-42363 · CVE-2023-42364 · CVE-2023-42365 · CVE-2023-42366
View at the BSI → - WID-SEC-W-2026-30949 Oct
rsyslog: Schwachstelle ermöglicht Denial of Service
CVE-2026-78002
View at the BSI → - WID-SEC-W-2026-22929 Oct
Apache log4j und Log4cxx: Mehrere Schwachstellen ermöglichen Manipulation von Dateien
Affects:IBM Db2CVE-2026-40023 · CVE-2026-49844
View at the BSI → - WID-SEC-W-2026-21589 Oct
Linux Kernel: Schwachstelle ermöglicht Erlangen von Administratorrechten
CVE-2026-52943
View at the BSI → - WID-SEC-W-2026-21269 Oct
gzip: Mehrere Schwachstellen
CVE-2026-41991 · CVE-2026-41992
View at the BSI → - WID-SEC-W-2026-21199 Oct
Linux Kernel: Mehrere Schwachstellen
CVE-2026-53278 · CVE-2026-53279 · CVE-2026-53280 · CVE-2026-53281 · CVE-2026-53282 · CVE-2026-53283 · +42
View at the BSI → - WID-SEC-W-2026-20659 Oct
cURL: Mehrere Schwachstellen
Affects:Amazon LinuxFedoraIBM AIXcurlOracle LinuxRocky LinuxRed Hat Enterprise LinuxSplunkUbuntu ServerCVE-2026-8286 · CVE-2026-8458 · CVE-2026-8924 · CVE-2026-8925 · CVE-2026-8926 · CVE-2026-8927 · +2
View at the BSI → - WID-SEC-W-2026-34209 Oct
Internet Systems Consortium BIND: Mehrere Schwachstellen
CVE-2026-19033 · CVE-2026-19662 · CVE-2026-19666 · CVE-2026-19667 · CVE-2026-19668 · CVE-2026-19941 · +8
View at the BSI → - WID-SEC-W-2026-16269 Oct
Internet Systems Consortium BIND: Mehrere Schwachstellen
Affects:Amazon LinuxDebianF5 BIG-IPFedoraIBM AIXIBM iBIND 9Oracle LinuxRocky LinuxRed Hat Enterprise LinuxopenSUSE LeapUbuntu ServerCVE-2026-3039 · CVE-2026-3592 · CVE-2026-5946 · CVE-2026-5950 · CVE-2026-3593 · CVE-2026-5947
View at the BSI → - WID-SEC-W-2026-26029 Oct
docker: Schwachstelle ermöglicht Manipulation von Dateien
CVE-2026-17106
View at the BSI →
How to read this
An entry here means the BSI published a security advisory for that product. It says nothing about whether your version is affected — that is in the original advisory. And if a product is missing here, that does not mean it is safe: it means we had no unambiguous match.
This page sends nothing: the advisories are free to read here, no account needed. BSI advisories by email are part of Pro. The update email about new versions comes with your subscriptions and is free.