rehme.infosec | Penetrationtests, Code Audit, Stuttgart - rehme.infosec

Security lab

Visit my lab to explore the security vulnerabilities I’ve identified and publicly disclosed.

Computer things... beep.  Ethical Hacker. Coder.

Something happens...

What’s going on in the world?

Security advisories from CISA

This feed highlights newly added vulnerabilities from the CISA Known Exploited Vulnerabilities (KEV) catalog. The entries represent security flaws that are actively exploited in the wild.

Microsoft / Active Directory Federation Services
Known Exploited Added: 14.07.2026 Due: 28.07.2026
Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance ...
SonicWall / SMA1000 Appliances
Known Exploited Added: 14.07.2026 Due: 17.07.2026
SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk ( ...
SonicWall / SMA1000 Appliances
Known Exploited Added: 14.07.2026 Due: 17.07.2026
SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see ...
Microsoft / SharePoint Server
Known Exploited Added: 14.07.2026 Due: 17.07.2026
Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “For ...
Cisco / IOS
Known Exploited Added: 13.07.2026 Due: 16.07.2026
Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI. Required action: Apply mitigations in accordance with vendor instructions, ensuring comp ...