rehme.infosec | Penetrationtests, Code Audit, Stuttgart - rehme.infosec

Security lab

Visit my lab to explore the security vulnerabilities I’ve identified and publicly disclosed.

Computer things... beep.  Ethical Hacker. Coder.

Something happens...

What’s going on in the world?

Security advisories from CISA

This feed highlights newly added vulnerabilities from the CISA Known Exploited Vulnerabilities (KEV) catalog. The entries represent security flaws that are actively exploited in the wild.

Citrix / NetScaler
Known Exploited Added: 09.09.2026 Due: 12.09.2026
Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass authentication. Required action: Apply mitigations in ...
Google / Chromium V8
Known Exploited Added: 09.09.2026 Due: 23.09.2026
Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. Required action: Apply mitigations in accordance with v ...
Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
Known Exploited Added: 09.09.2026 Due: 12.09.2026
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating ...
Fortinet / Multiple Products
Known Exploited Added: 09.09.2026 Due: 12.09.2026
Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL i ...
Microsoft / Windows
Known Exploited Added: 08.09.2026 Due: 22.09.2026
Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Tria ...