BSI Germany, CERT-Bund WID (RSS)
bsi-de · A · active
https://wid.cert-bund.de/content/public/securityAdvisory/rss
Federal Office for Information Security (Germany), CERT-Bund's WID advisory portal. The /portal/wid/kurzinformationen page is a JS-rendered SPA (WebFetch returns only the header). PRIMARY URL is the RSS feed. For per-advisory detail, fetch `https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-YYYY-NNNN`. **Never cite the kurzinformationen index**, always cite the per-advisory detail URL. 2026-05-08 audit: RSS returned 5 advisories all 2026-05-07 incl. LiteLLM, Checkmk, Linux Kernel. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → rss: python3 tools/fetch_source.py feed https://wid.cert-bund.de/content/public/securityAdvisory/rss 5 (then per-advisory body via api: python3 tools/fetch_source.py bsi-csaf WID-SEC-YYYY-NNNN). AVOID: Do NOT WebFetch the /portal/wid/kurzinformationen index; it is a JS-rendered SPA returning only the header. Never cite the index; cite the per-advisory securityadvisory?name=WID-SEC URL.. | 2026-07-05 admiralty audit: A (HIGH->A), German federal CERT, primary authority; keep active. Cite per-advisory securityadvisory?name=WID-SEC URL; body via bsi-csaf subcommand.
Cited in 43 entries
Citation cadence
Citation days per ISO week (19 weeks of coverage span, total 34).
- CVE-2026-91843, Check Point Security Management / Multi-Domain Security Management / Log Server: unauthenticated stack overflow in the login process reaches root RCE (CVSS 9.8)2026-09-18
- CVE-2026-42016 + CVE-2026-42018, JFrog Artifactory: chaining two previously-patched token flaws turns an unauthenticated request into full administrative control in two API calls, confirmed exploited since mid-August2026-09-12
- Dell Secure Connect Gateway DSA-2026-382: an unauthenticated request replayed indefinitely mints ADMIN tokens, and Dell ships no workaround for any of the 105 flaws2026-09-06
- WatchGuard Fireware OS: two pre-auth RCEs in the iked IKE/VPN daemon plus a pre-auth stack overflow in the deprecated Mobile Security epm service2026-08-31
- CVE-2026-18885 / CVE-2026-18886 / CVE-2026-74820 / CVE-2026-6876, ServiceNow AI Platform: three unauthenticated CVSS 10.0 flaws plus a related Now Platform sandbox escape2026-08-29
- Three new PTC Windchill and FlexPLM CVEs land on the product line already under mass extortion, all three unauthenticated and flagged red by the vendor, and only one has a fixed version anyone outside PTC's login wall can find2026-08-22
- CVE-2026-19586, TP-Link Omada gateways: attacker-supplied data during OpenVPN connection establishment reaches command execution before authentication completes (CVSS 4.0 9.3)2026-08-22
- Wazuh 4.14.6, two cluster-protocol paths to root that bypass the CVE-2026-25770 fix, a DAPI deserialization RCE, and a pre-auth stack overflow on the enrollment port2026-08-10
- Flowise ships three new CVEs into a sunset, an unauthenticated auth bypass that defeats an earlier fix, and cross-workspace credential access, with no vendor left to patch them2026-08-08
- CVE-2026-18574, Check Point Security Management: unauthenticated bypass of management authentication to arbitrary command execution, with no fix for seven end-of-support trains2026-08-05
- BSI and NCSC-NL withdraw SQLite advisories built on LLM-fabricated CVEs, and GitHub's advisory database was still serving one of them2026-08-04
- VMSA-2026-0006, VMware vCenter: unauthenticated Directory Service auth bypass and Syslog traversal RCE (both CVSS 9.8), plus a VMXNET3 guest-to-host escape2026-07-30
- HCSEC-2026-23, HashiCorp Terraform MCP Server leaks its own bearer token to an attacker-supplied address, and its credential cache crosses sessions and tenants (CVE-2026-14869, CVE-2026-16496, CVE-2026-16498)2026-07-30
- CVE-2026-59243, Apache Airflow FAB provider: the Azure AD OAuth login decoded ID tokens with signature verification off by default, letting anyone log in as Admin2026-07-29
- CVE-2026-61511, vBulletin: an arithmetic-only regex filter in front of eval() yields unauthenticated RCE, with a working exploit now public2026-07-28
- Zimbra Collaboration Suite 10.1.20, permanent fix for an SNMP command-injection RCE plus four stored-XSS bugs; NCSC-CH and BSI both flag the release2026-07-22
- Moodle local_o365 plugin: unverified JWT signature on the Teams SSO endpoint lets anyone authenticate as any user (CVE-2026-54733)2026-07-18
- CVE-2026-34038, Coolify: authenticated command injection to RCE and secrets exfiltration (CVSS 9.9)2026-07-03
- CVE-2026-13368, WatchGuard Fireware OS: pre-auth use-after-free RCE in the iked IKEv2/LDAP path (CVSS 9.2)2026-07-03
- Keycloak JWT algorithm confusion (CVE-2026-11800): forging federated identity in the EU public sector's dominant IdP2026-06-28
- CVE-2026-20896, Gitea (Docker): trust-all reverse-proxy default lets an unauthenticated attacker impersonate any user via X-WEBAUTH-USER2026-06-23
- CVE-2026-12789, ILIAS 11.0: unpatched, PoC-public SQL injection in the learning-progress subsystem (DACH education exposure)2026-06-23
- CVE-2026-52806, Gogs self-hosted Git server: argument injection to OS command execution (BSI critical batch)2026-06-20
- CVE-2026-55803 / CVE-2026-55804, Drupal core: PHP object-injection chain in JSON:API, BSI-rated critical2026-06-19
- CVE-2026-20181 / CVE-2026-20190, Cisco Identity Services Engine: unauthenticated credential read chaining to authenticated root command execution2026-06-19
- Cisco ISE CVE-2026-20181 + CVE-2026-20190: an unauthenticated credential-harvest primitive feeding authenticated root code execution on the identity plane2026-06-19
- BSI flags 13 vulnerabilities patched in Zammad 7.1, admin privilege escalation in a DACH public-sector helpdesk platform2026-06-18
- CVE-2026-47895, strongSwan: pre-auth double-free in libstrongswan identity cloning, unauthenticated RCE over EAP (patched 6.0.7)2026-06-10
- CVE-2026-47344 et al. TYPO3 core June release: 13 CVEs across every supported branch (10.4 ELTS → 14.3 LTS)2026-06-10
- CVE-2026-10868, MISP: critical mass-assignment account-takeover in the EU threat-sharing platform2026-06-06
- CVE-2026-10611, MISP: OTP bypass when LDAP mixed-auth and OTP enforcement are both enabled2026-06-04
- CVE-2026-44825, Apache Solr: unauthenticated admin via hardcoded template credentials, no patch yet2026-06-02
- Mautic 7.1.2 / 6.0.9, seven authenticated flaws, including two post-auth RCE paths (SSTI and path-traversal-to-PHP-RCE), an SSRF and an API authorization bypass2026-05-31
- CVE-2026-44939 (+ CVE-2026-41052, CVE-2026-41053), SUSE Rancher: command injection on cluster import, PSA label privilege-escalation, GitHub-App over-inclusive team membership2026-05-29
- ILIAS LMS, nine fixes shipped 2026-05-27, two critical access-control gaps (CVSS 9.8 + 9.3), NCSC.ch flags SOAP interface as primary unauthenticated attack surface2026-05-28
- Keycloak 26.6.2, 16 CVEs including OIDC session fixation (CVE-2026-7507), WebAuthn execute-actions token replay (CVE-2026-37982), introspection audience bypass (CVE-2026-37979) and cross-realm IDOR in Authorization Services (CVE-2026-4630)2026-05-21
- vm2 Node.js sandbox, 12 critical CVEs (CVE-2026-43997 / 43999 / 44005 / 44006 / 44008 / 44009 et al.), sandbox escape to host RCE, upgrade to ≥ 3.11.42026-05-20
- Drupal core "highly critical" pre-patch warning, unauthenticated, zero-complexity, patch window today 17:00–21:00 UTC2026-05-20
- BigBlueButton bbb-web < 3.0.21 / < 3.0.23, three flaws in EU education and government virtual-classroom platform: weak session-token randomness, API checksum bypass, SSRF2026-05-19
- Microsoft Exchange CVE-2026-42897: Active Exploitation Without a Patch2026-05-16
- CVE-2026-42897, Microsoft Exchange Server 2016 / 2019 / SE: stored XSS in OWA, actively exploited, no permanent patch2026-05-16
- CVE-2026-45691, Nextcloud Server / Enterprise Server: 2FA bypass on WebDAV via pre-authenticated session token reuse2026-05-15
- BSI flags Netgate pfSense Community Edition as critical-unpatched, CVE-2025-69690 / CVE-2025-69691 authenticated root RCE, vendor refuses to fix2026-05-11