Seite wählen

21.08.2026

Citrix issues critical security updates for its NetScaler devices

CSO Online 20.08.2026 18:54
Citrix is urging its NetScaler ADC and NetScaler Gateway customers to quickly patch two critical security holes, one involving a memory overflow vulnerability leading to unpredictable behavior or denial of service, and the other allowing authentication bypass.
Citrix said in an advisory that supported versions of customer-managed NetScaler ADC and NetScaler Gateway, including certain FIPS and NDcPP builds, as well as SecurAccess ZTNA Hybrid (formerly Secure Private Access Hybrid) deployments that use customer-managed NetScaler instances, are affected. Citrix-managed cloud services and Citrix-managed Adaptive Authentication have already been updated.

Berlin: Hackerangriff bedroht Tausende Wohngeldzahlungen

Spiegel Online 20.08.2026 14:38
Fast eine Woche nach einer Cyberattacke sind Teile der Berliner Verwaltung noch nicht wieder arbeitsfähig. Für manche Berlinerinnen und Berliner hat das spürbare Folgen.

Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE

The Hacker News 20.08.2026 13:48
Cybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source sandbox with more than 2,900 stars and 190 forks on GitHub, that could allow attackers to escape the confines of the isolated environment.

The vulnerability ("GHSA-864f-rcv7-6rh4"), which has yet to be assigned a CVE identifier, impacts all versions of the library before and including 7.0.0.

Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers

The Hacker News 20.08.2026 13:35
Citrix has released updates to address two security flaws impacting NetScaler ADC and NetScaler Gateway deployments, including a critical-severity authentication bypass vulnerability.

According to the cloud computing and virtualization technology company, the issues affect customer-managed NetScaler ADC and NetScaler Gateway, including certain FIPS and NDcPP builds, as well as SecurAccess

Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution

The Hacker News 20.08.2026 13:24
A now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish Computer Emergency Response Team (CERT Polska).

The vulnerability in question is CVE-2026-73570 (CVSS score: 8.9), which refers to a case of command injection that can lead to remote code execution.

"A remote code execution vulnerability exists in Zimbra

Microsoft behebt Sicherheitslücke: KI-Assistent Copilot verrät Schwachstellen

Heise Security 20.08.2026 12:18
Sicherheitsforscher haben Microsofts KI-Assistenten dazu gebracht, seine eigenen Schutzmechanismen offenzulegen.

Softwareprojekte gefährdet: Angriffe auf Gitlab beobachtet

Golem 20.08.2026 10:26
Angreifer können durch eine Sicherheitslücke auf Gitlab-Instanzen verheerende Schäden anrichten. Attacken laufen bereits. (Sicherheitslücke, KI)

Citrix: Kritische Lücke erlaubt Umgehung der Authentifizierung

Heise Security 20.08.2026 09:53
In Netscaler ADC und Gateway von Citrix können Angreifer mehrere Lücken missbrauchen. Sie können etwa unbefugt Zugriff erlangen.

Angriffsversuche auf GitLab-Lücke beobachtet

Heise Security 20.08.2026 09:41
Attacken auf eine jüngst außerplanmäßig geschlossene Lücke in GitLab wurden beobachtet. Angreifer können etwa Projekte löschen.

Cisco-Sicherheitslücken: Angreifer können Anmeldung von Secure Workload umgehen

Heise Security 20.08.2026 07:41
Es sind wichtige Sicherheitsupdates für unter anderem Cisco BroadWorks, Crosswork Security und Secure Workload erschienen.

Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code

The Hacker News 20.08.2026 06:04
Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution.

The vulnerability, tracked as CVE-2026-32475, carries a CVSS score of 9.0 out of 10.0. It has been described as a case of unrestricted upload of a file with a dangerous type.

"The flaw lives in the Forms module's File