IT‑Sicherheits‑Digest (2026-07-19)

Aktuelle Security‑News

heise security

  • Keine neuen, nicht bereits gestern gelisteten Meldungen im 36h-Fenster.

BleepingComputer

  • Update now: 7-Zip fixes RCE flaw exploitable with malicious archives (2026-07-18 19:32 UTC)
    • Kurz: 7-Zip version 26.02 was released to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted compressed files. […]
    • Quelle: Link
  • WordPress Core “wp2shell” RCE flaws get public exploits, patch now (2026-07-18 17:22 UTC)
    • Kurz: Public exploits have been released for the critical “wp2shell” remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators patch their sites immediately. […]
    • Quelle: Link
  • Microsoft warns of surge in ACR Stealer attacks on customers (2026-07-18 14:17 UTC)
    • Kurz: Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise customers. […]
    • Quelle: Link

The Hacker News

  • Keine neuen, nicht bereits gestern gelisteten Meldungen im 36h-Fenster.

Lageeinschätzung

  • Heute sind nur wenige frische, nicht doppelte Meldungen im 36h-Fenster aufgelaufen. Das ist typisch nach Wochenenden/Feiertagen oder wenn Feeds erst später am Vormittag aktualisieren.
  • Ausgeblendet: 81 ältere oder bereits gestern verwendete Feed-Einträge.

Neue CVEs (letzte 24h, NVD‑Abgleich)

Fortinet FortiGate (7.4.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Atlassian (Jira/Confluence)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

HPE/Aruba Switches

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

VMware ESXi/vCenter (7.x)

  • CVE-2026-47865 — CVSS 9.8 (CRITICAL)
    • Kurz: VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism. Affected versions: 31.…
    • Quelle: Link
  • CVE-2026-47867 — CVSS 8.7 (HIGH)
    • Kurz: VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious user with network access may be able to access the Avi Control plane and execute code remotely. Affected versions: 32.1.1 (fixed in 32.…
    • Quelle: Link
  • CVE-2026-47869 — CVSS 8.7 (HIGH)
    • Kurz: VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious authenticated user with network access may be able to inject and execute code. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 throu…
    • Quelle: Link
  • CVE-2026-47866 — CVSS 8.3 (HIGH)
    • Kurz: VMware Avi Load Balancer contains an authorization bypass vulnerability. A malicious actor on the network can access a limited subset of the Avi Control Plane without proper authorization. Affected versions: 32.1.1 (fixe…
    • Quelle: Link
  • CVE-2026-47868 — CVSS 7.8 (HIGH)
    • Kurz: VMware Avi Load Balancer contains a local privilege escalation vulnerability. A malicious user with local access may be able to escalate their privileges to run code as root. Affected versions: 32.1.1 (fixed in 32.1.2) 3…
    • Quelle: Link
  • CVE-2026-47870 — CVSS 7.1 (HIGH)
    • Kurz: VMware Avi Load Balancer contains a privilege escalation vulnerability. A malicious authenticated user with network access may be able to execute remote code. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31…
    • Quelle: Link

Hinweis

  • CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches).
  • News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.