>_ AYSOLI CYBERSECURITY

>_ advisories

Security Advisories

Current security warnings and vulnerabilities relevant to SMEs in the DACH region — sorted by year.

2026

HIGH2026-04-15

CVE-2026-41651 – Pack2TheRoot: Privilege Escalation in PackageKit

A 12-year-old vulnerability in the PackageKit daemon allows the installation of malicious packages with root privileges. Attackers can exploit a race condition to bypass package management security validation.

Read more
HIGH2026-04-12

CVE-2026-31431 – Linux Kernel 'Copy Fail': Local Privilege Escalation

A logic flaw in the Linux kernel's cryptographic subsystem allows local attackers to gain root privileges. By manipulating the Page Cache, system binaries can be corrupted in memory – a critical vector for servers and cloud infrastructures.

Read more
CRITICAL2026-04-11

CRITICAL: Unpatched Zero-Day Vulnerability in Adobe Reader (Actively Exploited)

A critical zero-day vulnerability in Adobe Acrobat Reader allows attackers to steal sensitive data and execute malicious code simply by opening a PDF file. Currently, no official security update (patch) exists.

Read more
CRITICAL2026-03-24

Critical Citrix NetScaler Vulnerabilities – Memory Leak & Session Swap (CVE-2026-3055/4368)

Two severe vulnerabilities in Citrix NetScaler ADC/Gateway allow attackers to read sensitive memory contents (tokens/keys) and swap active user sessions. Organisations in CH/FL using Citrix for remote access (VDI) are directly at risk.

Read more
CRITICAL2026-03-09

CVE-2026-21509 – Microsoft 365 Remote Code Execution via OLE Objects

A critical vulnerability in Microsoft 365 Apps (Enterprise/LTSC) enables arbitrary code execution through manipulated OLE objects embedded in Office documents — without requiring enabled macros. A single click on an attachment is sufficient for initial access.

Read more
CRITICAL2026-03-09

Nextcloud Flow – Critical RCE Vulnerability via Windmill Component

A flaw in the Windmill component of Nextcloud's 'Flow' automation app allows attackers to steal administrator tokens and execute arbitrary code with root privileges. Self-hosted Nextcloud instances are fully at risk.

Read more
HIGH2026-03-09

Smishing & Phishing – Fraudsters Impersonate the Swiss Tax Authority (ESTV) During Tax Season 2026

Fraudulent SMS and email messages impersonating the Swiss Federal Tax Administration (ESTV) prompt recipients to 'review their 2025 tax assessment'. Affected are Swiss SMEs, cross-border workers, and companies in Liechtenstein with Swiss VAT obligations.

Read more

Ready to know your attack surface?

Tell us briefly about your project — we'll come back with a concrete proposal.

Request a first call
Security Advisories · AYSOLI CyberSecurity