Threat Log
-
Act now GNU libc
GNU libc
WID-SEC-2026-1190Affects you if you run a Linux server. GNU libc is on every single one of them.
The C standard library is the foundation under almost every program on a Linux server. A remote, anonymous attacker can manipulate files here, take down a service, or carry out other, unspecified attacks. When the base wobbles, everything above it wobbles.
No workaround is known for this gap. Only the update helps.
Update glibc through your distribution's package manager and restart affected services.
- Affected
- GNU libc
- Actively exploited
- not on the KEV list
- Published
- Fri, 07 Aug 2026 11:21:05 GMT
Sources: BSI CERT-Bund
-
Act now OpenSSL
OpenSSL
WID-SEC-2026-1852Affects you if you use OpenSSL. You do, because it sits under everything.
OpenSSL sits under every service on these servers. The advisory describes remote code execution and the bypass of security measures. This does not affect one service, it affects the foundation of the entire stack.
The source names no individual CVE numbers, no CVSS score, and no specific versions. BSI rates the severity as high. For this advisory no workaround is known, only the update helps.
Update OpenSSL to the latest version your package manager offers. Then restart every service that links against it.
- Affected
- OpenSSL
- Actively exploited
- not on the KEV list
- Published
- Thu, 06 Aug 2026 09:43:33 GMT
Sources: BSI CERT-Bund
-
This week NGINX NGINX Plus
NGINX Plus
WID-SEC-2026-2383Affects you if you run NGINX Plus as your web server and have not touched the installation since the last update.
NGINX Plus is the commercial variant of the web server I run myself. The advisory describes several vulnerabilities that together allow remote code execution, data manipulation, denial of service, and information disclosure. That is a broad spectrum, and it hits the web server directly, not some optional module on the side.
No workaround is known for these flaws. Only the update helps.
Update NGINX Plus to the current version as soon as your support entitlement provides the packages.
- Affected
- NGINX NGINX Plus
- Actively exploited
- not on the KEV list
- Published
- Thu, 06 Aug 2026 08:51:38 GMT
Sources: BSI CERT-Bund
-
This week WordPress
WordPress Core
WID-SEC-2026-2701Affects you if you run WordPress. All of my customers do.
An attacker can exploit multiple vulnerabilities in WordPress to conduct a cross-site scripting attack, to elevate privileges, to disclose information, and to bypass security controls.
The dataset lists no specific versions, no CVE entry, and no fixed version. The BSI rates the situation as high. In the WordPress core, XSS and privilege escalation are rarely alone, they chain together. That makes this relevant even when individual scores are missing.
Update WordPress to the latest available version. Then verify the update went through.
- Affected
- WordPress
- Actively exploited
- not on the KEV list
- Published
- Fri, 07 Aug 2026 10:21:06 GMT
Sources: BSI CERT-Bund
-
This week OpenSSL
OpenSSL
WID-SEC-2024-1240Affects you if you run OpenSSL on a server. You do, because it sits under everything.
OpenSSL sits under every service on my systems. The advisory describes a remote, anonymous attacker who can execute code, manipulate data, disclose information, and take services down. This concerns the entire foundation of the stack, not a single application.
No workaround is known for this flaw. Only the update helps.
Update OpenSSL and restart every service linked against it.
- Affected
- OpenSSL
- Actively exploited
- not on the KEV list
- Published
- Thu, 06 Aug 2026 09:41:11 GMT
Sources: BSI CERT-Bund
-
This week FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More
FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More
CVE-2025-15028Affects you if you run the FormGent plugin and your forms are open to visitors. That is the normal case.
The plugin does not sufficiently strip input from form fields and renders it unescaped. Anyone who submits a form can deposit scripts that run in the browser of whoever later views the submission. In the worst case, that is an administrator.
The flaw is unauthenticated, but exploitation requires someone to trigger the injected script. That lowers the likelihood but does not change the fact that a stranger with no account can plant malicious code.
Update the plugin to the latest version. If the dataset provides no workaround, that is exactly the case: only the update helps.
- Affected
- FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More
- CVSS
- 7.2
source security@wordfence.com - Likely to be exploited
- 0.19 %
percentile 8.8 - Type
- CWE-79
- Actively exploited
- not on the KEV list
- Published
- 2026-08-05
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
This week Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons
Element Pack Addons for Elementor
CVE-2026-0673Affects you if you use the Element Pack Addons for Elementor plugin and the bundled contact form is reachable.
The plugin's contact form writes user input into mail headers without checking it. Anyone who submits the form can inject additional header lines and abuse the form for their own purposes. No account needed.
Update the plugin to the latest version. If you do not use the contact form, disable the widget in the Elementor settings.
Update the plugin, disable the widget if the form is unused.
- Affected
- Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons
- CVSS
- 5.3
source security@wordfence.com - Likely to be exploited
- 0.21 %
percentile 11.3 - Type
- CWE-93
- Actively exploited
- not on the KEV list
- Published
- 2026-08-06
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation. -
Act now TrueBooker – Appointment Booking and Scheduler System
TrueBooker
CVE-2026-13161Affects you if you run the TrueBooker plugin in version 1.2.2 or earlier and the booking page is publicly reachable.
A SQL injection through a parameter that is reachable without authentication. The nonce guard does not help, because the nonce is visible to every visitor on the booking page. A stranger can read the database without an account.
Update to the latest version. If the dataset provides no workaround, that holds here: For this gap no workaround is known, only the update helps.
Update the plugin to the latest version. For this gap no workaround is known, only the update helps.
- Affected
- TrueBooker – Appointment Booking and Scheduler System
- CVSS
- 7.5
source security@wordfence.com - Likely to be exploited
- 0.45 %
percentile 37.2 - Type
- CWE-89
- Actively exploited
- not on the KEV list
- Published
- 2026-07-27
Sources: NVD · EPSS · Wordfence
Includes data from the CVE Program, © MITRE Corporation.
596 checked and dismissed, with reasons
- 160 advisoriesProdukt kommt in keinem der von mir betreuten Systeme vor.
- 11 advisoriesArbeitsplatzsoftware, nicht Serverbetrieb. Gehoert nicht in dieses Lagebild.
- 8 advisoriesKernel-Abwandlung fuer Hardware oder Cloud-Plattformen, die hier nicht vorkommt.
- 8 advisoriesKeine Virtualisierungs- oder Orchestrierungsschicht in den betreuten Systemen.
- 7 advisoriesIch betreibe keine Windows-Server. Warum, steht auf der Startseite.
- 6 advisoriesKeine Netzwerkgeraete dieser Hersteller im Bestand.
- 5 advisoriesKein Java-Anwendungsserver im Bestand.
- 1 advisoriesBetreibt unter meinen Kunden niemand.
- bsi:https://wid.cert-bund.de/portal/wid/securityadvisory?namSamba wird in Georges Umgebung nicht betrieben und ist dort selten, daher betrifft dieser Vorgang die Kunden nicht.
- bsi:https://wid.cert-bund.de/portal/wid/securityadvisory?namLinux-Kernel-Meldungen sind häufig und meist lokale Rechteausweitung, was auf Georges gehärteten Systemen ohne unbefugte Konten keine akute Handlungsnotwendigkeit darstellt.
- bsi:https://wid.cert-bund.de/portal/wid/securityadvisory?namLinux-Kernel-Meldung mit Denial of Service und nicht spezifizierten Auswirkungen, was auf Georges Systemen ohne lokale Angreifer keine akute Relevanz hat.
- bsi:https://wid.cert-bund.de/portal/wid/securityadvisory?namLinux-Kernel-Meldung mit Denial of Service und nicht spezifizierten Auswirkungen, was auf Georges Systemen ohne lokale Angreifer keine akute Relevanz hat.
- bsi:https://wid.cert-bund.de/portal/wid/securityadvisory?namLinux-Kernel-Meldung mit Denial of Service und nicht spezifizierten Auswirkungen, was auf Georges Systemen ohne lokale Angreifer keine akute Relevanz hat.
- bsi:https://wid.cert-bund.de/portal/wid/securityadvisory?namLinux-Kernel-Meldung mit lokalem Angreifer und nicht spezifizierten Angriffen, was auf Georges gehärteten Systemen ohne unbefugte Konten keine akute Handlungsnotwendigkeit darstellt.
- bsi:https://wid.cert-bund.de/portal/wid/securityadvisory?namLinux-Kernel-Meldung mit Denial of Service und Datenmanipulation, was auf Georges Systemen ohne lokale Angreifer keine akute Relevanz hat.
- bsi:https://wid.cert-bund.de/portal/wid/securityadvisory?namLinux-Kernel-Meldung mit nicht spezifizierten Angriffen und möglicher Denial-of-Service-Bedingung, was auf Georges Systemen ohne lokale Angreifer keine akute Relevanz hat.
- bsi:https://wid.cert-bund.de/portal/wid/securityadvisory?namLinux-Kernel-Meldung mit nicht spezifizierten Angriffen und möglicher Denial-of-Service-Bedingung, was auf Georges Systemen ohne lokale Angreifer keine akute Relevanz hat.
- bsi:https://wid.cert-bund.de/portal/wid/securityadvisory?namLinux-Kernel-Meldung mit nicht spezifizierten Angriffen und möglicher Denial-of-Service-Bedingung, was auf Georges Systemen ohne lokale Angreifer keine akute Relevanz hat.
- bsi:https://wid.cert-bund.de/portal/wid/securityadvisory?namLinux-Kernel-Meldung mit nicht spezifizierten Angriffen und möglicher Denial-of-Service-Bedingung, was auf Georges Systemen ohne lokale Angreifer keine akute Relevanz hat.
- bsi:https://wid.cert-bund.de/portal/wid/securityadvisory?namLinux-Kernel-Meldung mit nicht spezifizierten Angriffen und möglicher Denial-of-Service-Bedingung, was auf Georges Systemen ohne lokale Angreifer keine akute Relevanz hat.
- bsi:https://wid.cert-bund.de/portal/wid/securityadvisory?namLinux-Kernel-Meldung mit nicht spezifizierten Angriffen und möglicher Denial-of-Service-Bedingung, was auf Georges Systemen ohne lokale Angreifer keine akute Relevanz hat.
- bsi:https://wid.cert-bund.de/portal/wid/securityadvisory?namLinux-Kernel-Meldung mit nicht spezifizierten Angriffen und möglicher Denial-of-Service-Bedingung, was auf Georges Systemen ohne lokale Angreifer keine akute Relevanz hat.
- bsi:https://wid.cert-bund.de/portal/wid/securityadvisory?namLinux-Kernel-Meldung mit nicht spezifizierten Angriffen und möglicher Denial-of-Service-Bedingung, was auf Georges Systemen ohne lokale Angreifer keine akute Relevanz hat.
- bsi:https://wid.cert-bund.de/portal/wid/securityadvisory?namLinux-Kernel-Meldung mit nicht spezifizierten Angriffen und möglicher Denial-of-Service-Bedingung, was auf Georges Systemen ohne lokale Angreifer keine akute Relevanz hat.
- bsi:https://wid.cert-bund.de/portal/wid/securityadvisory?namLinux-Kernel-Meldung mit Denial of Service und potenzieller Codeausführung, aber ohne spezifische entfernte Angriffsvektoren, was auf Georges Systemen ohne lokale Angreifer keine akute Relevanz hat.
- bsi:https://wid.cert-bund.de/portal/wid/securityadvisory?namLinux-Kernel-Meldung mit lokalem Angreifer und Rechteausweitung, was auf Georges gehärteten Systemen ohne unbefugte Konten keine akute Handlungsnotwendigkeit darstellt.
- bsi:https://wid.cert-bund.de/portal/wid/securityadvisory?namLinux-Kernel-Meldung mit lokalem Angreifer und Administratorrechten, was auf Georges gehärteten Systemen ohne unbefugte Konten keine akute Handlungsnotwendigkeit darstellt.
- bsi:https://wid.cert-bund.de/portal/wid/securityadvisory?namdnsmasq wird in Georges Umgebung nicht betrieben, daher betrifft dieser Vorgang die Kunden nicht.
- bsi:https://wid.cert-bund.de/portal/wid/securityadvisory?namLinux-Kernel-Meldung mit lokalem Angreifer und Administratorrechten, was auf Georges gehärteten Systemen ohne unbefugte Konten keine akute Handlungsnotwendigkeit darstellt.
- bsi:https://wid.cert-bund.de/portal/wid/securityadvisory?namUnbound wird in Georges Umgebung nicht betrieben, daher betrifft dieser Vorgang die Kunden nicht.
- bsi:https://wid.cert-bund.de/portal/wid/securityadvisory?namLinux-Kernel-Meldung mit lokalem Angreifer und Privilegieneskalation, was auf Georges gehärteten Systemen ohne unbefugte Konten keine akute Handlungsnotwendigkeit darstellt.
- bsi:https://wid.cert-bund.de/portal/wid/securityadvisory?namLinux-Kernel-Meldung mit Denial of Service und nicht spezifizierten Auswirkungen, was auf Georges Systemen ohne lokale Angreifer keine akute Relevanz hat.
- bsi:https://wid.cert-bund.de/portal/wid/securityadvisory?namLinux-Kernel-Meldung mit Denial of Service und nicht spezifizierten Auswirkungen, was auf Georges Systemen ohne lokale Angreifer keine akute Relevanz hat.