IT‑Sicherheits‑Digest (2026-09-09)

Aktuelle Security‑News

heise security

  • Schweiz baut Alternative zu Microsoft 365 auf (2026-09-08 13:26 UTC)
    • Kurz: Die Schweizer Bundeskanzlei startet ein Programm für eine souveräne Arbeitsplatzsoftware. Rund 3000 Beschäftigte sollen sie nutzen.
    • Quelle: Link
  • „WeWorm“: Zero-Click-Wurm hätte alle Konten von WeChat übernehmen können (2026-09-08 12:27 UTC)
    • Kurz: Eine KI hat eine Schwachstelle in WeChat gefunden, über die man in kürzester Zeit eine Milliarde Konten hätte übernehmen können. Sie ist bereits geschlossen.
    • Quelle: Link

BleepingComputer

  • New Microsoft Defender ‘ShieldCrash’ zero-day grants SYSTEM access (2026-09-09 07:30 UTC)
    • Kurz: An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named “ShieldCrash” right after Microsoft rolled out its September 2026 Patch Tuesday security updates. […]
    • Quelle: Link
  • Google warns of new Chrome zero-day bug exploited in attacks (2026-09-09 06:25 UTC)
    • Kurz: Google has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh such vulnerability patched since the start of the year. […]
    • Quelle: Link
  • Microsoft adds age-awareness APIs that can tell if users are children, teens, or adults (2026-09-09 01:16 UTC)
    • Kurz: Microsoft is adding new age-awareness APIs to Windows 11 that will allow apps to determine whether someone is a child, teenager, or adult without exposing their exact date of birth. […]
    • Quelle: Link

The Hacker News

  • Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days (2026-09-09 04:41 UTC)
    • Kurz: Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild. These include 723 flaws in Wi…
    • Quelle: Link
  • N-able N-central Pre-Auth RCE Flaw Exploited in the Wild (2026-09-09 04:27 UTC)
    • Kurz: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch …
    • Quelle: Link
  • Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution (2026-09-08 16:20 UTC)
    • Kurz: A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster un…
    • Quelle: Link

Neue CVEs (letzte 24h, NVD‑Abgleich)

Fortinet FortiGate (7.4.x)

  • CVE-2026-26084 — CVSS 9.9 (CRITICAL)
    • Kurz: A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to …
    • Quelle: Link
  • CVE-2026-84393 — CVSS 8.1 (HIGH)
    • Kurz: A improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6, FortiProxy 7.6.2 through 7.6.6 may allow attacker to information disclosure via
    • Quelle: Link
  • CVE-2026-84387 — CVSS 7.2 (HIGH)
    • Kurz: A improper neutralization of special elements used in a command (‘command injection’) vulnerability in Fortinet FortiSandbox 5.2.0, FortiSandbox 5.0.0 through 5.0.6, FortiSandbox 4.4.0 through 4.4.9 may allow attacker to…
    • Quelle: Link
  • CVE-2026-84385 — CVSS 5.4 (MEDIUM)
    • Kurz: A improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.6, FortiSOAR PaaS 7.5.0 through 7.5.3, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 thr…
    • Quelle: Link
  • CVE-2026-84386 — CVSS 5.1 (MEDIUM)
    • Kurz: A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all versions may allow attacker to improper access control via
    • Quelle: Link
  • CVE-2026-22575 — CVSS 4.9 (MEDIUM)
    • Kurz: An improper access control vulnerability in Fortinet FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.10, FortiManager 7.2 all versions, FortiManager Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.4.1 th…
    • Quelle: Link

Atlassian (Jira/Confluence)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

HPE/Aruba Switches

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

VMware ESXi/vCenter (7.x)

  • Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h.

Hinweis

  • CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches).
  • News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.