rehme.infosec | Penetrationtests, Code Audit, Stuttgart - rehme.infosec

Security lab

Visit my lab to explore the security vulnerabilities I’ve identified and publicly disclosed.

Computer things... beep.  Ethical Hacker. Coder.

Something happens...

What’s going on in the world?

Security advisories from CISA

This feed highlights newly added vulnerabilities from the CISA Known Exploited Vulnerabilities (KEV) catalog. The entries represent security flaws that are actively exploited in the wild.

Microsoft / Windows Ancillary Function Driver for WinSock
Known Exploited Added: 11.08.2026 Due: 25.08.2026
Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensi ...
Metabase / Metabase
Known Exploited Added: 11.08.2026 Due: 14.08.2026
Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible throug ...
Cisco / Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)
Known Exploited Added: 11.08.2026 Due: 14.08.2026
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. Required action: Apply mitigations in accordance with vendor instructions, ensuring co ...
Progress / LoadMaster
Known Exploited Added: 07.08.2026 Due: 10.08.2026
Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Update ...
JetBrains / TeamCity
Known Exploited Added: 05.08.2026 Due: 08.08.2026
JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Fore ...