IT‑Sicherheits‑Digest (2026-07-15)

Aktuelle Security‑News

heise security

  • Ungeschützte Wechselrichter: Hoymiles verspricht Update (2026-07-15 06:26 UTC)
    • Kurz: Angreifer können durch Sicherheitslücken in Hoymiles-Wechselrichtern die Geräte aus der Ferne lahmlegen. Ein Update soll das ändern.
    • Quelle: Link
  • Software-Update Ursache von IT-Problemen der Berliner Justiz (2026-07-15 04:46 UTC)
    • Kurz: Technische Probleme haben die Berliner Gerichte lahmgelegt. Ein fehlerhaftes Software-Update sorgte für einen Totalausfall, der nun schrittweise behoben wird.
    • Quelle: Link
  • Microsoft macht Passkeys zum Standard in Entra ID (2026-07-14 15:35 UTC)
    • Kurz: Microsoft führt Passkeys als Standard-Anmeldemethode in Entra ID ein. SMS- und Sprachanrufe laufen schrittweise aus.
    • Quelle: Link

BleepingComputer

  • US charges alleged operators of Russian bulletproof hosting service (2026-07-15 07:45 UTC)
    • Kurz: U.S. federal prosecutors have unsealed charges against three Russian nationals, accusing them of providing bulletproof hosting (BPH) services to ransomware gangs that caused over $62 million in damages to victims worldwide. […]
    • Quelle: Link
  • SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now (2026-07-14 21:23 UTC)
    • Kurz: SonicWall warns that threat actors have been exploiting two SMA1000 vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, in zero-day attacks and urges customers to install the newly released security updates. […]
    • Quelle: Link
  • Spanish Police take down €140 million cyber fraud ring, arrest four (2026-07-14 20:23 UTC)
    • Kurz: The Spanish Police dismantled a cybercrime and money-laundering organization that made €140 million ($160 million) from investment fraud and business email compromise (BEC) attacks. […]
    • Quelle: Link

The Hacker News

  • Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands (2026-07-15 05:30 UTC)
    • Kurz: SonicWall has warned of active exploitation of two zero-day vulnerabilities impacting Secure Mobile Access (SMA) 1000 series appliances, one of which could be exploited to achieve arbitrary command execution. The vulnerabilities are listed …
    • Quelle: Link
  • Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack (2026-07-14 20:25 UTC)
    • Kurz: Microsoft shipped its largest Patch Tuesday on record today, and two of the fixes close holes that attackers are already exploiting. The release covers 622 of Microsoft’s own CVEs by its Security Update Guide count, more than triple June’s …
    • Quelle: Link
  • SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data (2026-07-14 18:17 UTC)
    • Kurz: SAP has rolled out updates to address multiple vulnerabilities as part of its July 2026 security updates, including a critical flaw in SAP NetWeaver Application Server ABAP. The vulnerability in question is CVE-2026-44747 (CVSS score: 9.9),…
    • Quelle: Link

Neue CVEs (letzte 24h, NVD‑Abgleich)

Fortinet FortiGate (7.4.x)

  • CVE-2026-59835 — CVSS 8.6 (HIGH)
    • Kurz: A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 through 4.4.8 may allow an unauthenticated attacker to access the VNC server of VMs performing scannin…
    • Quelle: Link
  • CVE-2025-53379 — CVSS 7.5 (HIGH)
    • Kurz: A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versions may allow a remote unauthenticated attacker to retrieve sensitive information via a specially cra…
    • Quelle: Link
  • CVE-2026-59837 — CVSS 6.6 (MEDIUM)
    • Kurz: A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all versions, FortiPAM 1.8.0 through 1.8.2, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions…
    • Quelle: Link
  • CVE-2026-23573 — CVSS 6.1 (MEDIUM)
    • Kurz: An Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions, Fo…
    • Quelle: Link
  • CVE-2026-59839 — CVSS 5.5 (MEDIUM)
    • Kurz: A improper limitation of a pathname to a restricted directory (‘path traversal’) vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, For…
    • Quelle: Link
  • CVE-2025-43892 — CVSS 4.3 (MEDIUM)
    • Kurz: A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions may allow an authenticated remote attacker to return a portion of device memory in the redir…
    • Quelle: Link

Atlassian (Jira/Confluence)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

HPE/Aruba Switches

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

VMware ESXi/vCenter (7.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Hinweis

  • CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches).
  • News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.