Citrix issues critical security updates for its NetScaler devices
CSO Online 20.08.2026 18:54
Citrix is urging its NetScaler ADC and NetScaler Gateway customers to quickly patch two critical security holes, one involving a memory overflow vulnerability leading to unpredictable behavior or denial of service, and the other allowing authentication bypass.
Citrix said in an advisory that supported versions of customer-managed NetScaler ADC and NetScaler Gateway, including certain FIPS and NDcPP builds, as well as SecurAccess ZTNA Hybrid (formerly Secure Private Access Hybrid) deployments that use customer-managed NetScaler instances, are affected. Citrix-managed cloud services and Citrix-managed Adaptive Authentication have already been updated.
Berlin: Hackerangriff bedroht Tausende Wohngeldzahlungen
Spiegel Online 20.08.2026 14:38
Fast eine Woche nach einer Cyberattacke sind Teile der Berliner Verwaltung noch nicht wieder arbeitsfähig. Für manche Berlinerinnen und Berliner hat das spürbare Folgen.
Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE
The Hacker News 20.08.2026 13:48
Cybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source sandbox with more than 2,900 stars and 190 forks on GitHub, that could allow attackers to escape the confines of the isolated environment.
The vulnerability ("GHSA-864f-rcv7-6rh4"), which has yet to be assigned a CVE identifier, impacts all versions of the library before and including 7.0.0.
Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers
The Hacker News 20.08.2026 13:35
Citrix has released updates to address two security flaws impacting NetScaler ADC and NetScaler Gateway deployments, including a critical-severity authentication bypass vulnerability.
According to the cloud computing and virtualization technology company, the issues affect customer-managed NetScaler ADC and NetScaler Gateway, including certain FIPS and NDcPP builds, as well as SecurAccess
Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution
The Hacker News 20.08.2026 13:24
A now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish Computer Emergency Response Team (CERT Polska).
The vulnerability in question is CVE-2026-73570 (CVSS score: 8.9), which refers to a case of command injection that can lead to remote code execution.
"A remote code execution vulnerability exists in Zimbra
Microsoft behebt Sicherheitslücke: KI-Assistent Copilot verrät Schwachstellen
Heise Security 20.08.2026 12:18
Sicherheitsforscher haben Microsofts KI-Assistenten dazu gebracht, seine eigenen Schutzmechanismen offenzulegen.
Softwareprojekte gefährdet: Angriffe auf Gitlab beobachtet
Golem 20.08.2026 10:26
Angreifer können durch eine Sicherheitslücke auf Gitlab-Instanzen verheerende Schäden anrichten. Attacken laufen bereits. (Sicherheitslücke, KI)
Citrix: Kritische Lücke erlaubt Umgehung der Authentifizierung
Heise Security 20.08.2026 09:53
In Netscaler ADC und Gateway von Citrix können Angreifer mehrere Lücken missbrauchen. Sie können etwa unbefugt Zugriff erlangen.
Angriffsversuche auf GitLab-Lücke beobachtet
Heise Security 20.08.2026 09:41
Attacken auf eine jüngst außerplanmäßig geschlossene Lücke in GitLab wurden beobachtet. Angreifer können etwa Projekte löschen.
Cisco-Sicherheitslücken: Angreifer können Anmeldung von Secure Workload umgehen
Heise Security 20.08.2026 07:41
Es sind wichtige Sicherheitsupdates für unter anderem Cisco BroadWorks, Crosswork Security und Secure Workload erschienen.
Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code
The Hacker News 20.08.2026 06:04
Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution.
The vulnerability, tracked as CVE-2026-32475, carries a CVSS score of 9.0 out of 10.0. It has been described as a case of unrestricted upload of a file with a dangerous type.
"The flaw lives in the Forms module's File