• Request consultation
  • Newsletter
  • Deutsch Deutsch German de
  • English English English en
  • Italiano Italiano Italian it
  • Nederlands Nederlands Dutch nl
Greenbone
  • Products
    • OPENVAS BASIC
      • OPENVAS BASIC: Order
    • OPENVAS SCAN
    • Upcoming Solutions
      • OPENVAS SECURITY INTELLIGENCE
      • OPENVAS AI
    • Solutions for Your Sector
      • Educational Sector
      • Healthcare Sector
      • Public Sector
    • Technology
      • Feed Comparison
      • Product Comparison
        • OPENVAS vs. Nessus
      • Roadmap & Lifecycle
  • Service & Support
    • Professional Services
    • Documents
    • Technical Support
  • Events
    • Cybersec Europe 2026
    • Webinars
  • Partners
    • MSSP
  • About Greenbone
    • Our History
    • Careers
    • Contact
  • Blog
    • Know-how
      • Attack Vector Timeline
      • Cyberattacks and Defense
      • Cyber Defense Security
      • Cyber Resilience Act
      • Data Security
      • Digital Operational Resilience Act
      • Exposure Management
      • IT and Information Security
      • NIS2 Directive
      • Open Source Vulnerability Management
      • The Vulnerability Timeline
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu
  • Products
    • OPENVAS BASIC
      • OPENVAS BASIC: Order
    • OPENVAS SCAN
    • Upcoming Solutions
      • OPENVAS SECURITY INTELLIGENCE
      • OPENVAS AI
    • Solutions for your sector
      • Educational Sector
      • Healthcare Sector
      • Public Sector
    • Technology
      • Feed Comparison
      • Product Comparison
        • OPENVAS vs. Nessus
      • Roadmap and Lifecycle
    • Request IT Security
  • Service & Support
    • Professional Services
    • Documents
    • Technical Support
  • Events
    • Cybersec Europe 2026
    • Webinars
  • Partners
    • MSSP
  • About Greenbone
    • Our History
    • Careers
    • Contact
    • Newsletter
  • Our Blog
    • Know-how
      • Attack Vector Timeline
      • Cyberattacks and Defense
      • Cyber Defense Security
      • Cyber Resilience Act
      • Data Security
      • Digital Operational Resilience Act
      • Exposure Management
      • IT and Information Security
      • NIS2 Directive
      • Open Source Vulnerability Management
      • The Vulnerability Timeline
  • German
  • English
  • Italian
  • Dutch
Greenbone AG

CIS Benchmarks for Microsoft Environments: Greenbone’s Got You Covered!

Blog

Microsoft technologies are foundational to enterprise IT globally, providing the backbone for operation-critical databases, identity services, core server workloads, and daily productivity applications at many organizations. Greenbone is happy to announce new compliance scans aligned with four CIS Benchmarks for Microsoft environments. CIS Benchmarks provide prescriptive guidance for establishing secure configurations and complement essential security practices such as vulnerability management, endpoint protection, and activity monitoring.

Fortified server module illustration for Greenbone's new Microsoft CIS Benchmark compliance scans

In this article, we briefly review the security focus of each benchmark and explain how Greenbone’s compliance policies help organizations identify configuration gaps across Microsoft Office, SQL Server, and Windows Server systems. OPENVAS SCAN, backed by the industry-leading coverage of the OPENVAS ENTERPRISE FEED, provides the compliance visibility needed to detect insecure settings, prioritize remediation, and strengthen the resilience of Microsoft IT environments.

The new compliance policies for Microsoft IT environments add to Greenbone’s already impressive line of scans:

  • CIS Microsoft Office Enterprise Benchmark v1.2.0
  • CIS Microsoft SQL Server 2022 Benchmark v1.2.1
  • CIS Microsoft Windows Server 2025 Benchmark v2.0.0
  • CIS Microsoft Windows Server 2022 Benchmark v5.0.0

The Importance of IT Compliance in 2026

In 2026, organizations operating in the EU face overlapping cyber security, resilience, privacy, and corporate governance obligations. The Network and Information Systems Directive 2 (NIS2) requires critical infrastructure entities to implement technical, operational, and organizational safeguards. The Digital Operational Resilience Act (DORA) imposes additional ICT risk management and resilience requirements on the financial sector. The GDPR imposes security requirements on organizations that process or store personal data, and the Cyber Resilience Act (CRA) introduces mandatory reporting of actively exploited vulnerabilities and severe product security incidents from September 11, 2026, among other obligations.

Following recognized IT security standards such as CIS Benchmarks helps organizations establish defensible security baselines, produce audit evidence, reduce configuration drift, and demonstrate that governance and risk management duties are implemented consistently.

Talk to Our Sales Team

Whether your organization must meet regulatory requirements or simply wants deeper insight into securing Microsoft IT environments, OPENVAS SCAN provides the compliance visibility needed to identify configuration gaps, reduce risk, and strengthen security. Contact Greenbone’s sales team to discuss how compliance scanning can best support your organization’s regulatory and security governance requirements.

Understanding CIS Microsoft SQL Server 2022 Benchmark v1.2.1

The CIS Microsoft SQL Server 2022 Benchmark v1.2.1 provides prescriptive guidance for the secure configuration of SQL Server 2022 on Microsoft Windows. It is intended for database and system administrators, security specialists, auditors, and deployment personnel responsible for developing, assessing, or securing SQL Server environments.

The benchmark covers installation and patching, attack surface reduction, authentication and authorization, password policies, auditing and logging, application development, and encryption. Greenbone’s compliance scan for CIS Microsoft SQL Server 2022 Benchmark v1.2.1 covers the practical Level 1 profile for the SQL Server Database Engine and AWS RDS, and the Level 2 Database Engine profile with additional defense-in-depth controls.

Understanding CIS Microsoft Windows Server 2025 Benchmark v2.0.0

The CIS Microsoft Windows Server 2025 Benchmark v2.0.0 audits security controls for establishing a hardened configuration of Windows Server 2025. It is designed for Active Directory domain-joined and Entra Hybrid-joined systems that receive policies through Active Directory Group Policy Manager. The policy is not designed for standalone, workgroup, cloud-managed, or cloud-hosted systems.

The benchmark addresses areas such as account and local security policies, system services, Windows Defender Firewall, advanced audit configuration, authentication, remote access, and administrative template settings. Greenbone’s compliance scan for CIS Microsoft Windows Server 2025 Benchmark v2.0.0 covers Level 1 and Level 2 profiles for both Domain Controllers and Member Servers, along with optional Next Generation Windows Security profiles for advanced controls.

Understanding CIS Microsoft Windows Server 2022 Benchmark v5.0.0

The CIS Microsoft Windows Server 2022 Benchmark v5.0.0 audits security controls for establishing a hardened configuration of Windows Server 2022. The Windows Server 2022 benchmark is intended for Active Directory domain-joined and Entra Hybrid-joined systems that receive policies through Active Directory Group Policy Manager. The policy is not designed for standalone, workgroup, cloud-managed, or cloud-hosted systems.

The benchmark addresses areas such as account and local security policies, system services, Windows Defender Firewall, advanced auditing, authentication, remote access, and administrative template settings. Greenbone’s compliance scan for CIS Microsoft Windows Server 2022 Benchmark v5.0.0 covers Level 1 and Level 2 profiles for Domain Controllers and Member Servers, along with optional Next Generation Windows Security profiles containing advanced controls.

Get to Know Greenbone’s Full Suite of Compliance Scans

OPENVAS SCAN’s compliance policies consist of specially selected groups of vulnerability tests used to assess compliance. Whether your organization is required to meet BSI technical standards or simply wants deeper insight into building resilient IT networks and applications, OPENVAS SCAN provides compliance visibility to identify gaps and strengthen security.

Some of the compliance scans in Greenbone’s OPENVAS ENTERPRISE FEED:

  • BSI TR-03116-4: BSI Minimum Standards for the Use of TLS
  • BSI TR-02102-4: BSI Minimum Standards for the Use of SSH
  • CIS Benchmark v1.10 for Kubernetes 1.28 Controller Node
  • CIS Benchmark v1.10 for Kubernetes 1.28 Worker Nodes
  • Compliance profiles for Huawei EulerOS, openEuler, and Huawei Cloud EulerOS
  • CIS Benchmark v3.0.0 (L1) for Microsoft Windows 11 Enterprise
  • CIS Benchmarks v3.0.0 (L1 – Windows) for Google Chrome
  • BSI and CIS Benchmarks for Microsoft Office
  • Policy check for SSH: Post Quantum Cryptography (PQC)
  • Policy check for SSL/TLS: Post Quantum Cryptography (PQC)

Talk to Our Sales Team

Whether your organization must meet regulatory requirements or simply wants deeper insight into securing Microsoft IT environments, OPENVAS SCAN provides the compliance visibility needed to identify configuration gaps, reduce risk, and strengthen security. Contact Greenbone’s sales team to discuss how compliance scanning can best fit your organization’s regulatory and security governance requirements.

Summary

Microsoft platforms support critical business operations, but their extensive configuration options can introduce security gaps when systems are not consistently hardened. CIS Benchmarks are the IT industry standard for practical guidance on establishing secure configurations. Greenbone’s growing list of compliance scans helps organizations identify deviations from these recommended baselines, strengthen governance and audit readiness, and reduce configuration-related risk.

OPENVAS SCAN provides the visibility needed to maintain more resilient Microsoft environments as regulatory and operational security expectations continue to increase. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way for your organization to gain the deepest insight into building resilient IT networks and applications.

 

Contact Test Now Buy Here Back to Overview
31. July 2026/by Greenbone AG
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Greenbone AG https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Greenbone AG2026-07-31 14:03:422026-07-31 14:03:42CIS Benchmarks for Microsoft Environments: Greenbone’s Got You Covered!
Joseph Lee

Patch Priority: An Emerging Tide of Linux Vulnerabilities Put Users in Hot Water

Blog

Cracked green shield illustration representing a wave of newly disclosed Linux kernel vulnerabilities, headlined Patch Priority: Linux Kernel Risks Keep Rising

Several concerning vulnerabilities affecting Linux have emerged in recent months. The vulnerabilities include CISA Known Exploited Vulnerabilities (KEV) entries for CVE-2026-31431 (aka Copy Fail) [1], and an older flaw, CVE-2022-0492 [2]. However, a wave of concerning new vulnerabilities are associated with publicly available exploits or proof-of-concept (PoC) code. Collectively, the flaws represent local privilege escalation, container escape, arbitrary command execution as root, kernel heap corruption, and remote code execution (RCE). Linux users should regularly scan their infrastructure, conduct assessments to determine exposure, and prioritize patching to reduce risks to critical assets.

A Risk Assessment of Emerging Linux Kernel Vulnerabilities

In recent weeks, the Greenbone blog reviewed Copy Fail, a new actively exploited Linux vulnerability, along with Copy Fail 2 and Dirty Frag. Since then, several new vulnerabilities affecting the Linux kernel and core components have emerged, presenting significant operational risk within the Linux ecosystem.

Start Your Free Trial

Greenbone continuously updates the OPENVAS ENTERPRISE FEED to include detection checks for vulnerabilities dispatched in the latest Linux security advisories. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way to gain the deepest insight into where software vulnerabilities exist in your organization’s Linux infrastructure.

A Technical Assessment of Emerging Linux Vulnerabilities

The following section reviews recently disclosed vulnerabilities affecting the Linux kernel and core components. Each section summarizes the underlying technical cause, available threat intelligence, potential temporary mitigations, and the upstream fixes.

CVE-2026-31705 Affecting ksmbd SMB Server

CVSS 9.8 · CriticalEPSS 0.1% (14th)No known exploitationPatch available

CVE-2026-31705 (CVSS 9.8, EPSS ≥ 31st pctl) is an out-of-bounds write in the Linux kernel ksmbd SMB server’s smb2_get_ea() path. A memset operation for 4-byte alignment runs without checking the remaining space. Exploitation allows compound SMB requests to overwrite adjacent kernel heap memory.

A detailed technical write-up is available online, increasing the risk to defenders [1]. No vendor provided workarounds have been published. However, shutting down KSMBD and/or unloading and blocking the ksmbd kernel module can reasonably prevent attacks from reaching the affected components. Upstream fixes are incorporated into Linux kernel versions 6.1.175, 6.6.136, 6.12.84, 6.18.25, 7.0.2, and 7.1. Greenbone’s OPENVAS ENTERPRISE FEED includes detection for CVE-2026-31705 and continues to add package-level checks as Linux distributions issue security advisories and patches.

CVE-2026-55200 Affecting libssh2

CVSS 8.3 · HighEPSS 0.9% (55th)Public PoC

CVE-2026-55200 (CVSS 8.3, EPSS ≥ 78th pctl) affects libssh2. The flaw is an out-of-bounds write in ssh2_transport_read() caused by an unchecked attacker-controlled packet_length field. A malicious or compromised SSH server can send crafted SSH packets to trigger memory corruption and achieve RCE.

Detailed technical write-ups and PoC exploits are available online, increasing the risk to defenders [1][2]. No workaround mitigation is available except for preventing libssh2 clients from connecting to untrusted SSH servers, such as disabling the service. CVE-2026-55200 affects all libssh2 versions up to and including 1.11.1. No fixed upstream release has yet been published, but the correction is available in upstream commit 97acf3df and has been backported by some Linux distributions. Greenbone’s OPENVAS ENTERPRISE FEED includes detection for CVE-2026-55200 and continues to add package-level checks as Linux distributions issue security advisories and patches.

Fragnesia: CVE-2026-46300 (CVSS 7.5)

CVSS 7.8 · HighEPSS 0.1% (17th)Public PoC

Dubbed Fragnesia, CVE-2026-46300 (CVSS 7.8, EPSS ≥ 83th pctl) is caused by shared-fragment marker loss during skb coalescing in the Linux kernel’s net/skbuff and ESP input paths. Later in-place ESP processing allows decryption of page-cache-backed fragments. The issue is considered a trivial-to-exploit local privilege-escalation risk because it can corrupt page-cached read-only files. Ubuntu says exploitation can elevate a local user to root on affected hosts and that container-escape scenarios are also possible.

Several technical write-ups and PoC exploits are available online, increasing the risk to defenders [1][2][3][4][5]. Temporary mitigation can be achieved by unloading and blocking the esp4 and esp6 kernel modules [6]. CVE-2026-46300 affects Linux kernel versions 3.9 and later. Upstream fixes are incorporated into versions 5.10.257, 5.15.208, 6.1.174, 6.6.141, 6.12.91, 6.18.33, 7.0.10, and 7.1. Greenbone’s OPENVAS ENTERPRISE FEED includes detection for CVE-2026-46300 and continues to add package-level checks as Linux distributions issue security advisories and patches.

ssh-keysign-pwn: CVE-2026-46333 (CVSS 7.1)

CVSS 7.1 · HighEPSS 0.0% (0th)Public PoC

Dubbed ssh-keysign-pwn, CVE-2026-46333 (CVSS 7.1, EPSS ≥ 71st pctl) is a race in Linux kernel ptrace and process-exit handling. The issue centers around dumpability and mm teardown. During a privileged process exit, pidfd_getfd() can duplicate open file descriptors from the dying process. Exploitation can expose sensitive root-owned material, including SSH keys and password hashes. The public proof-of-concept for this issue requires the pidfd_getfd syscall; a system call that can duplicate a file descriptor from another process. The kernel fix requires the CAP_SYS_PTRACE capability to inspect or control another process when the target process is exiting, known as the “no-mm” case.

Several technical write-ups and PoC exploits are available online, increasing the risk to defenders [1][2][3][4][5][6]. Temporary mitigation can be achieved by blocking all unprivileged users or only for users without the CAP_SYS_PTRACE privilege from attaching to other processes using the ptrace() system call [7]. CVE-2026-46333 is a Linux kernel vulnerability rather than an OpenSSH flaw. Patches are incorporated into Linux kernel versions 5.10.256, 5.15.207, 6.1.173, 6.6.139, 6.12.89, 6.18.31, 7.0.8, and 7.1. Greenbone’s OPENVAS ENTERPRISE FEED includes detection for CVE-2026-46333 and continues to add package-level checks as Linux distributions issue security advisories and patches.

DirtyDecrypt / DirtyCBC: CVE-2026-31635 (CVSS 7.5)

CVSS 7.5 · HighEPSS 0.0% (4th)Public PoC

Dubbed DirtyDecrypt (and DirtyCBC), CVE-2026-31635 (CVSS 7.5, EPSS ≥ 53rd pctl) affects Linux kernels with CONFIG_RXGK compiled in and enabled. An inverted bounds check in RxRPC / RxGK response validation allows oversized RESPONSE authenticators to be accepted and passed deeper into processing. Secondary reporting says the flaw can overwrite page-cached privileged files and be used for local privilege escalation to root.

Several technical write-ups and PoC exploits are available online, increasing the risk to defenders [1][2][3][4][5]. No vendor provided workarounds have been published. However, independent researchers have suggested unloading and blocking the rxrpc module as a temporary solution [6]. Upstream fixes for CVE-2026-31635 are incorporated into Linux kernel versions 6.18.23, 6.19.13, and 7.0. Greenbone’s OPENVAS ENTERPRISE FEED includes detection for CVE-2026-31635 and continues to add package-level checks as Linux distributions issue security advisories and patches.

CIFSwitch: CVE-2026-46243 (CVSS 7.1)

CVSS 7.1 · HighEPSS 0.0% (4th)Public PoC

Dubbed CIFSwitch, CVE-2026-46243 (CVSS 7.1, EPSS ≥ 28th pctl) affects cifs_spnego handling in the Linux kernel’s CIFS client. The issue allows userspace to forge cifs.spnego key descriptions through request_key(2) or add_key(2), causing cifs.upcall to trust attacker-controlled authority fields. The flaw allows a low-privilege local user to trigger arbitrary command execution as root.

Several technical write-ups and PoC exploits are available online, increasing the risk to defenders [1][2][3][4]. The temporary workaround is to unload and block the cifs kernel module, remove cifs-utils, or deactivate the cifs.spnego request-key rule [5]. CVE-2026-46243 affects Linux kernel with the CIFS client or cifs-utils, and the cifs.spnego request-key integration. Upstream fixes are incorporated into versions 5.10.258, 5.15.209, 6.1.175, 6.6.142, 6.12.92, 6.18.34, 7.0.11, and 7.1. Greenbone’s OPENVAS ENTERPRISE FEED includes detection for CVE-2026-46243 and continues to add package-level checks as Linux distributions issue security advisories and patches.

PinTheft: CVE-2026-43494 (CVSS 7.8)

CVSS 7.8 · HighEPSS 0.0% (10th)Public PoC

Dubbed PinTheft, CVE-2026-43494 (CVSS 7.8) affects the Linux kernel RDS zerocopy send path. The bug stems from cleanup logic that frees already released pages after op_nents is left nonzero. The exploit chain uses io_uring fixed buffers to overwrite the page cache of a SUID-root binary.

Several detailed write-ups and PoC exploits are available online, increasing the risk to defenders [1][2][3][4]. Workaround mitigation can be achieved by ensuring that the rds module is unloaded and blocked from automatic loading [5]. CVE-2026-43494 affects Linux kernel versions 4.17 and later with the RDS subsystem. Upstream fixes are incorporated into Linux kernel versions 5.10.258, 5.15.209, 6.1.175, 6.6.141, 6.12.91, 6.18.33, 7.0.10, and 7.1. Greenbone’s OPENVAS ENTERPRISE FEED includes detection for CVE-2026-43494 and continues to add package-level checks as Linux distributions issue security advisories and patches.

GhostLock: CVE-2026-43499 (CVSS 7.8)

CVSS 7.8 · HighEPSS 0.0% (7th)Public PoC

Dubbed GhostLock, CVE-2026-43499 (CVSS 7.8) is a use-after-free in the Linux kernel rtmutex slowlock and proxy-lock rollback path. The remove_waiter() function leaves a dangling pointer and unsafe locking state. Red Hat and Ubuntu describe local privilege-escalation and denial-of-service impact [1][2], and Nebula says container escape is also possible on unpatched systems.

Several detailed technical write-ups and PoC exploits are available online, increasing the risk to defenders [1][2][3][4]. No workaround mitigation is available. CVE-2026-43499 affects Linux kernel versions 2.6.39 and later with upstream fixes incorporated into versions 5.10.261, 5.15.212, 6.1.175, 6.6.140, 6.12.86, 6.18.27, 7.0.4, and 7.1. Greenbone’s OPENVAS ENTERPRISE FEED includes detection for CVE-2026-43499 and continues to add package-level checks as Linux distributions issue security advisories and patches.

Mitigation for Emerging Linux Vulnerabilities

Organizations should prioritize patching for emerging Linux vulnerabilities based on the operational and business value of affected assets, the reachability of affected systems, each flaw’s technical details, and threat intelligence, including known active exploitation and the existence of PoC exploits.

Mitigating vulnerabilities found in the upstream Linux kernel depends on either implementing effective workarounds or installing updates in downstream Linux distributions when they become available. Where technical workarounds are not available, defenders must upgrade to fixed kernel builds.

Summary

Recent Linux kernel and core component vulnerabilities have exposed organizations to new risks. The potential impacts include local privilege escalation, container escape, arbitrary command execution, memory corruption, and RCE. Publicly available technical analyses and proof-of-concept exploits increase the urgency. When prioritizing patches, defenders must identify all affected systems and consider asset criticality, business risk, reachability, and exploitability.

Start Your Free Trial

Greenbone provides package-level detection via local authenticated scans for all emerging Linux risks mentioned in this article. Greenbone continuously updates the OPENVAS ENTERPRISE FEED to include detection checks for vulnerabilities dispatched in the latest Linux security advisories. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way to gain the deepest insight into where software vulnerabilities exist in your organization’s Linux infrastructure.

 

Contact Test Now Buy Here Back to Overview
30. July 2026/by Joseph Lee
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Joseph Lee https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Joseph Lee2026-07-30 14:08:532026-07-30 14:08:53Patch Priority: An Emerging Tide of Linux Vulnerabilities Put Users in Hot Water
Joseph Lee

Patch Now! Back-to-Back Synacor Zimbra Updates Fix Two Sets of Critical Vulnerabilities

Blog

In July 2026, Zimbra released two security patches for multiple vulnerabilities affecting the Classic Web Client and other components of Zimbra Collaboration Suite (ZCS). Version 10.1.19 addressed a stored cross-site scripting (XSS) flaw that has not been assigned a CVE. Version 10.1.20 fixed a command-injection issue in the SNMP monitoring component, four additional stored XSS issues in the Classic Web Client, and numerous other flaws.

None of the new vulnerabilities are yet reported as actively exploited, and proof-of-concept (PoC) exploits are not publicly available. However, Zimbra has been a hot target for nation-state exploit campaigns in the past. Previous ZCS flaws have appeared 18 times on CISA’s KEV list. Five of those KEV listed CVEs are associated with ransomware attacks. In July 2026, U.S. and allied security agencies warned that the Russian state-backed group LAUNDRY BEAR has been exploiting ZCS vulnerabilities since at least July 2025[1][2].

Banner graphic for the Zimbra critical patches blog post, reading 'Critical Zimbra Flaws Fixed, Update Now'

Most of the security issues described in the 10.1.19 and 10.1.20 updates are not associated with a CVE. However, the pathway to mitigation is clear — users must update to the most recent version of Zimbra Collaboration Suite (ZCS) for protection. The OPENVAS ENTERPRISE FEED includes separate remote banner version checks to identify instances missing the 10.1.19 and 10.1.20 patches [1][2]. Users should upgrade to ZCS 10.1.20 as soon as possible.

A Risk Assessment of Zimbra Collaboration Suite Vulnerabilities

For organizations still using the Classic Web Client, the new flaws present significant risk. The 10.1.19 update addresses a stored XSS issue that can be triggered when a user opens a specially crafted email. The vulnerability has not been associated with a published CVE as of July 27th, 2026, but Zimbra has declared it a critical severity issue. Successful exploitation could expose mailbox information, session data, or account settings, potentially enabling account compromise and data theft.

The 10.1.20 patch addresses four additional stored XSS issues in the Classic Web Client, a command-injection vulnerability in the SNMP component, and flaws affecting mail forwarding restrictions, Exchange Web Services (EWS) access controls, mailbox delegation, and the Zimbra integration for Nextcloud.

Details of New Security Issues Impacting ZCS

Technical details for the security issues disclosed in both the ZCS 10.1.19 and 10.1.20 updates are limited. Also, CVEs have not been published for many of the described flaws.

Fixed in ZCS 10.1.19 (Released on July 7th, 2026):

  • Classic Web Client stored XSS fixed in 10.1.19 (no CVE assigned): The flaw can be triggered by opening a specially crafted email. Exploitation allows an attacker to execute a malicious script in a user session and potentially expose mailbox information, session data, or account settings.

Fixed in ZCS 10.1.20 (Released on July 20th, 2026):

  • SNMP monitoring (no CVE assigned): A command-injection vulnerability in the SNMP monitoring component when SNMP notifications are enabled.
  • Classic Web Client stored XSS issues (no CVE assigned): Attachment filenames, crafted fields, and attachments can be designed to to trigger XSS on user’s systems when they view a malicious email.
  • CVE-2026-50055 (CVE reserved but not published): A mail-forwarding restriction bypass could allow authenticated users to exfiltrate email despite forwarding restrictions being enabled.
  • CVE-2026-10631 (CVE reserved but not published): An Exchange Web Services extension access-controls issue can have an undisclosed impact related to access controls.
  • CVE-2026-50054 (CVE reserved but not published): A mailbox delegation authorization issue with undisclosed details.
  • Nextcloud integration SSRF (no CVE assigned): A Server Side Request Forgery (SSRF) vulnerability in the Nextcloud integration for ZCS.

Mitigation for New Vulnerabilities in Zimbra Collaboration Suite

Users who have deployed the Classic Web Client should upgrade to ZCS v10.1.20 as soon as possible due to the risk of attacker-controlled XSS. The vendor has not described any workarounds. The OPENVAS ENTERPRISE FEED includes separate remote banner version checks to uncover instances missing the 10.1.19 and 10.1.20 patches [1][2].

Summary

Zimbra addressed multiple security issues in July 2026, issuing two security patches for ZCS. The updates address flaws in multiple components. The most critical issues are session-level XSS risk in the Classic Web Client. Other high-risk vulnerabilities include configuration-dependent command injection in SNMP monitoring and access-control or authorization weaknesses that can affect email exposure and delegated access. No active exploitation has been reported, although ZCS has been targeted by Advanced Persistent Threat (APT) actors in the past and is reportedly still an active target.

Start Your Free Trial

Most of the security issues described in the 10.1.19 and 10.1.20 updates are not associated with a CVE. However, the pathway to mitigation is clear – users must update to the most recent version of ZCS for protection. The OPENVAS ENTERPRISE FEED includes separate remote banner version checks to uncover instances missing the 10.1.19 and 10.1.20 patches [1][2]. Users should upgrade to ZCS 10.1.20 as soon as possible.

 

Contact Test Now Buy Here Back to Overview
29. July 2026/by Joseph Lee
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Joseph Lee https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Joseph Lee2026-07-29 14:31:092026-07-29 14:35:52Patch Now! Back-to-Back Synacor Zimbra Updates Fix Two Sets of Critical Vulnerabilities
Joseph Lee

CVE-2026-16232: Check Point SmartConsole Login Process Actively Exploited and More

Blog

Check Point has published three new security advisories addressing flaws in Security Management Server (SMS), Multi-Domain Management (MDM), and other Gaia-related components. The highest-priority issue, CVE-2026-16232 (CVSS 9.1), is an actively exploited authentication bypass affecting Check Point SmartConsole in SMS and MDM products. CVE-2026-16232 was published on July 22nd, 2026, and added to CISA’s Known Exploited Vulnerabilities (KEV) list the same day. The other newly disclosed flaws are CVE-2026-62144 (CVSS 9.1), an authentication bypass and privilege escalation in SMS and MDM, and CVE-2026-62145 (CVSS 7.5) affecting the GaiaOS WebUI management interface of Check Point’s Firewall, MDM, Multi-Domain Log Server.

Check Point security advisory banner: three new CVEs, one actively exploited

Start Your Free Trial

The OPENVAS ENTERPRISE FEED includes a remote banner version check to identify potentially vulnerable instances of Check Point Gaia OS that may host affected components. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way to gain the deepest insight into where software vulnerabilities exist in your organization’s IT infrastructure.

A Risk Assessment of Check Point’s July 2026 Security Update

According to Check Point, exploitation of CVE-2026-16232 only affected a very small number of customers that exposed management servers directly to the internet without IP restrictions. The vulnerabilities are high risk because they affect administrative control paths used to configure security policies, objects, gateways, permissions, and monitoring.

Check Point’s Security Management Server (SMS) manages one security-management domain. SMS sits above the gateways in the control hierarchy stores, objects and policies, and distributes them to managed Security Gateways. Multi-Domain Management (MDM) is the large-scale alternative to a single Security Management Server. It provides isolated management environments for different customers, business units, regions, or security zones.

SmartConsole is the GUI used to connect to and manage SMS, and Security Management Servers manage Security Gateways and monitor security events. Gaia Portal is the web-based interface for Gaia OS, and Check Point says most system configuration tasks can be performed through it.

CVE-2026-16232: Actively Exploited SmartConsole Authentication Bypass

CVSS 9.1 · CriticalActively exploitedIn CISA KEV

An improper authentication vulnerability [CWE-287] in the Check Point SmartConsole login process of SMS and MDM products. CVE-2026-16232 allows a remote, unauthenticated attacker to obtain an application login token and use it to authenticate with full administrative privileges. Remote exploitation requires access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Successful exploitation allows the attacker to modify security policies and configurations.

Other CVEs From Check Point’s July 2026 Advisories

Check Point’s July 2026 security advisories also disclosed two additional CVEs:

The two additional CVEs disclosed in Check Point’s July 2026 advisories, each shown with its CVSS severity band and EPSS exploitation-probability score

CVE-2026-62144
CVSS 9.1 · Critical EPSS 20.6% (97th)

A critical improper authentication [CWE-287] flaw affecting Check Point SMS and MDM. The flaw allows a remote, unauthenticated attacker to execute administrative commands on the Management Server and potentially execute commands on managed Security Gateways. Exploitation requires network access to a Management Server that does not restrict Trusted Clients.

CVE-2026-62145
CVSS 7.5 · High EPSS 7.5% (94th)

A high-severity improper privilege management [CWE-269] flaw in Check Point Gaia Portal. Exploitation requires an authenticated account with read-only Gaia Portal privileges. A successful attacker could execute commands with root privileges, potentially gaining complete control of the affected system.

Affected Products and Mitigation for Check Point Security Management and Gaia OS

The direct remediation path is to apply the appropriate Jumbo Hotfix for the affected component’s current version of Gaia OS. For Check Point SMS, the relevant fixes are R81.20 Jumbo Hotfix Take 158, R82 Jumbo Hotfix Take 118, and R82.10 Jumbo Hotfix Take 36. These hotfixes address the CVEs discussed above, as well as CVE-2026-31431 (CVSS 7.8, aka Copy Fail), CVE-2026-43284 (CVSS 8.8), CVE-2026-43500 (CVSS 7.8, aka Dirty Frag), CVE-2026-46300 (CVSS 7.8, aka Fragnesia), and more. Patch prioritization should focus on SMS and MDM deployments that are reachable from the internet and do not use Trusted Clients restrictions or IP restrictions.

Summary

Check Point issued three new security advisories in July 2026 that disclose two Critical vulnerabilities in Security Management Server and one High-severity Gaia Portal privilege-escalation flaw[1][2][3]. CVE-2026-16232 allows full administrative access on Security Management infrastructure and is known to be actively exploited.

Start Your Free Trial

The OPENVAS ENTERPRISE FEED includes a remote banner version check to identify potentially vulnerable instances of Check Point Gaia OS that may host affected components. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way to gain the deepest insight into where software vulnerabilities exist in your organization’s IT infrastructure.

 

Contact Test Now Buy Here Back to Overview
28. July 2026/by Joseph Lee
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Joseph Lee https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Joseph Lee2026-07-28 15:58:102026-07-28 15:58:10CVE-2026-16232: Check Point SmartConsole Login Process Actively Exploited and More
Joseph Lee

CVE-2026-53359 (aka Januscape): VM Escape Hits Linux KVM/x86

Blog

Januscape, tracked as CVE-2026-53359 (CVSS 8.8), is a use-after-free vulnerability [CWE-825] in the Linux kernel KVM/x86 that can let a guest crash its host and potentially break guest-host isolation. The highest-risk targets are Intel and AMD x86_64 KVM hosts that expose nested virtualization, especially in environments that accept untrusted guests or allow users to create virtual machines. Large global data center operators worldwide now face the complex task of patching vast fleets of KVM hosts while minimizing disruption to customer workloads.

Active exploitation of CVE-2026-53359 has not yet been reported. The vulnerabilities original reporter, Hyunwoo Kim, claims that the bug was used as a zero-day in Google’s kvmCTF and has released a PoC capable of causing Denial of Service (DoS) of all VMs running on the host from within a single guest VM. Detailed technical analysis have also been published [1][2]. Numerous national CERT agencies have issued alerts indicating high global risk [3][4][5][6][7][8][9][10][11][12][13][14][15][16].

Greenbone’s OPENVAS ENTERPRISE FEED includes detection for CVE-2026-53359 on Red Hat Enterprise Linux (RHEL), SUSE and openSUSE, AlmaLinux, Oracle Linux, Rocky Linux, Fedora, and Debian. Greenbone will continue to add vulnerability detection as more Linux distributions issue security advisories. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way to gain the deepest insight into where software vulnerabilities exist in your organization’s IT infrastructure.

Illustration representing CVE-2026-53359 (Januscape), a VM escape vulnerability in Linux KVM/x86 virtualization

A Global Risk Assessment of CVE-2026-53359 (Januscape)

According to the original public disclosure, the flaw has existed for roughly 16 years. Furthermore, all x86 Linux distributions and kernels prior to the fix commit are affected. This means the scope of affected IT infrastructure is very broad, presenting significant global risk. Successful exploitation can result in guest-to-host escape, corruption of the host kernel’s shadow page, DoS, and potentially, compromise of other guest VMs on the same host. For global data center operators, that scope translates into the same challenge repeated across every site: rolling out patches to thousands of KVM hosts without knocking customer workloads offline.

According to a post on Ubuntu’s blog, the primary public PoC effectively demonstrates that a guest VM can crash its hypervisor host. Furthermore, the original report says CVE-2026-53359 was used as a zero-day exploit in the Google kvmCTF.

The Technical Assessment of CVE-2026-53359 (Januscape)

CVE-2026-53359 (CVSS 8.8) affects KVM nested virtualization on Intel and AMD x86_64 systems, while other architectures are not affected. If a cloud provider does not allow nested virtualization, instances are not affected through this path. However, nested virtualization is enabled by default in the Linux kernel. Successful exploitation allows guest-to-host escape, corruption of the host kernel’s shadow page, DoS, and compromise of other VM guests running on the same host.

Ubuntu’s blog notes that system services such as libvirt, lxd, multipass, and incus may allow potential attackers to create virtual machines, which can affect exposure. A separate risk path exists where /dev/kvm permissions are overly broad; if /dev/kvm is world-writable, an unprivileged user can achieve local privilege escalation to gain root-level privileges.

CVE-2026-53359 is a use-after-free in shadow MMU emulation caused by shadow-page reuse when the page role does not match the new use. The affected component is the Linux kernel KVM/x86 shadow paging path in arch/x86/kvm/mmu/mmu.c. The root cause is that the kvm_mmu_get_child_sp() function does not compare roles effectively. The mismatch can leave a stale rmap entry, leading to an exploitable pointer de-reference [CWE-825].

Products Affected by CVE-2026-53359 (Januscape)

All x86 Linux distributions after roughly 2014 and prior to the Linux kernel fix commit are affected, regardless of distribution. Because CVE-2026-53359 is a guest-to-host escape vulnerability, exploitation depends on the the target system being used as a KVM-based hypervisor and having nested virtualization enabled on a guest VM.

For Ubuntu environments, defenders should review Canonical’s Januscape mitigation guidance, which says all Ubuntu releases from Trusty (14.04) through Resolute (26.04) are are affected. While patches for Ubuntu are still pending, instructions for disabling nested virtualization are provided. For Red Hat environments, teams should compare deployed kernels against the fixed builds listed in Red Hat’s security data entry.

Mitigation for CVE-2026-53359 (aka Januscape)

Complete mitigation depends on installing the security updates for the specific Linux distribution. Prioritized mitigation should begin with identifying where nested virtualization is exposed on Linux KVM/x86 hypervisors, especially in multi-tenant environments or deployments that allow untrusted users to create or control guest VMs. Because exploitation may depend on guest control or access to virtualization interfaces, defenders should also review who can create VMs and whether device-node permissions around /dev/kvm expose an additional local privilege escalation path.

Summary

CVE-2026-53359 (aka Januscape; CVSS 8.8) is a high-impact virtualization-boundary vulnerability caused by a use-after-free flaw on Intel and AMD x86_64 Linux KVM deployments with nested virtualization enabled in the Linux kernel. The consequences include guest-to-host escape, and possible compromise of other guest VMs on the same host. At least one public proof-of-concept is available along with detailed technical analysis [1][2]. Active exploitation is not yet confirmed, but the volume of national CERT advisories flagging the flaw as a high global risk tells its own story [3][4][5][6][7][8][9][10][11][12][13][14][15][16].

Detection is already available: Greenbone’s OPENVAS ENTERPRISE FEED covers CVE-2026-53359 across Red Hat Enterprise Linux (RHEL), SUSE and openSUSE, AlmaLinux, Oracle Linux, Rocky Linux, Fedora, and Debian, with more distributions being added as their advisories land. A free two-week trial of OPENVAS SCAN with the OPENVAS ENTERPRISE FEED is the fastest way to see exactly where this vulnerability sits in your organization’s infrastructure.

Contact Test Now Buy Here Back to Overview
23. July 2026/by Joseph Lee
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Joseph Lee https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Joseph Lee2026-07-23 16:59:132026-07-23 16:59:13CVE-2026-53359 (aka Januscape): VM Escape Hits Linux KVM/x86
Joseph Lee

wp2shell: Exploit Chaining for Unauthenticated RCE in WordPress

Blog

A WordPress Core vulnerability chain, publicly nicknamed wp2shell, combines CVE-2026-63030 (CVSS 9.8) and CVE-2026-60137 (CVSS 5.9) for pre-authentication remote code execution (RCE). The exploit chain affects WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2. WordPress 6.8.x before 6.8.6 is affected by CVE-2026-60137 alone. Dozens of proof-of-concept (PoC) exploits have been published for the full exploit chain [1] as well as several detailed technical write ups. In-the-wild exploitation was first widely reported by cyber security firms. Finally both CVEs were added to CISA’s KEV list on July 21st, 2026 [2][3]. Numerous national CERT agencies have issued alerts globally [4][5][6][7][8][9][10][11][12][13][14][15][16][17]. Because WordPress has an estimated 500 million installations globally, wp2shell presents a high degree of risk.

wp2shell: Unauthenticated RCE Exploit Chain in WordPress Core

Greenbone’s OPENVAS ENTERPRISE FEED includes remote banner version checks to identify CVE-2026-63030 and CVE-2026-60137 for Linux [1][2] and Windows [3][4]. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way to gain the deepest insight into where software vulnerabilities exist in your organization’s IT infrastructure.

A Global Risk Assessment of wp2shell Affecting WordPress Core

The exposure is significant because the flaws impact default installations of WordPress Core rather than optional extensions or configurations and allows an unauthenticated attacker to achieve RCE. Searchlight Cyber estimates that more than 500 million websites use WordPress. Additional risk signals include widespread reports of active exploitation and numerous public PoCs.

A Summary of Active wp2shell Exploitation Campaigns

Active exploitation of CVE-2026-60137 and CVE-2026-63030 is now widely reported by numerous cyber security firms and independent sensor operators. Patchstack first classified both vulnerabilities as actively exploited shortly after disclosure [1]. Wordfence recorded probing of the WordPress REST API on July 17th, 2026, followed by a clear SQL-injection attempt 13 minutes later [2]. Several other cyber security companies have also confirmed active exploitation [3][4].

The observed campaigns are opportunistic, targeting WordPress installations across all industries and geographic regions. However, the activity has not been attributed to established threat actors, and no victims have been publicly identified. Confirmed techniques include unauthorized administrator-account creation, malicious-plugin installation, persistent backdoors and web shells, user enumeration, and attempts to obtain database credentials, authentication keys, and other secrets from wp-config.php.

Technical Details for CVE-2026-60137 and CVE-2026-63030

Here are brief details for both vulnerabilities in the wp2shell exploit chain:

  • CVE-2026-63030 (CVSS 9.8): The WordPress Core batch API allows multiple REST calls to be bundled into one request. CVE-2026-63030 is a batch endpoint route confusion issue [CWE-436] associated with /wp-json/batch/v1. The flaw is caused when failed batch sub-requests are not appended to the $matches array resulting in an index offset. The flaw allows an attacker to submit a malicious batch of requests that includes a flawed low-privilege request designed to create an array index offset, followed by a high-privilege request that will be executed without proper authorization. By exploiting CVE-2026-63030, an attacker can not only bypass authorization, but also bypass other WordPress internal checks such as request method, route, and validation schema.
  • CVE-2026-60137 (CVSS 5.9): An SQL-injection flaw caused by improper sanitization [CWE-89] of the author_exclude parameter in WP_Query. WordPress’s posts handler maps the attacker-controlled author_exclude value to the WP_Query::author__not_in parameter, which is only sanitized if provided as an integer array. When facilitated by CVE-2026-63030, attackers can provide malformed request parameters including a string type author_exclude value. The unsanitized value is then injected into an SQL query, where it can execute malicious SQL code.

How the wp2shell Unauthenticated RCE Chain Works

wp2shell is described as an exploit chain that combines CVE-2026-60137 and CVE-2026-63030. In the first stage, CVE-2026-63030 is leveraged to create a REST API batch endpoint route confusion flaw [CWE-436] in WordPress Core to execute unauthenticated commands. In the second stage, that condition is combined with the SQL-injection flaw [CWE-89] tracked as CVE-2026-60137 to further impact target WordPress installations.

Here is a general description of the wp2shell attack flow:

1. Exploit CVE-2026-63030

  • The attacker submits a malicious request to WordPress’s public /wp-json/batch/v1 endpoint. The malformed subrequest triggers a request handler mismatch allowing privileged requests to be executed without proper authorization.
  • The attacker recursively invokes the vulnerable batch endpoint. An initial desynchronization exploit bypasses authorization, while a second desynchronization exploit bypasses parameter validation. This allows a normally unsupported GET request to reach the WordPress posts handler with unvalidated input.

2. Exploit CVE-2026-60137

  • The posts handler maps the attacker-controlled author_exclude value to WP_Query::author__not_in. WordPress sanitizes this value when it is provided as an array but not when it arrives as a string, allowing the value to be injected directly into an SQL query. The attacker may use a blind or UNION SELECT SQL-injection attack to recover sensitive information that can be used for further exploitation. This information includes enumerating the WordPress table prefix, an administrator user ID, existing post IDs, and generated oEmbed-cache row IDs.
  • A UNION SELECT SQL injection can be designed to create legitimate WP_Post objects which are stored in the WordPress object cache. These objects form a chain of legitimate WordPress behaviors that convert the read-oriented SQL injection into database writes and application control-flow changes. Exploitation can allow an attacker to create rogue posts with web shells to achieve RCE with the privileges of the web-server process.
  • Other attack scenarios include creating persistent rogue administrator accounts and using them to upload malicious plugins, theme components, or web shells to achieve RCE with the privileges of the web-server process.

The two CVEs chained in the wp2shell exploit, CVE-2026-63030 and CVE-2026-60137, each shown with its CVSS severity band and EPSS exploitation-probability score

CVE-2026-63030
CVSS 9.8 · Critical EPSS 8.9% (95th)

A batch endpoint route confusion flaw [CWE-436] in the WordPress Core batch API (/wp-json/batch/v1), caused when failed sub-requests are not appended to the $matches array. An unauthenticated attacker can chain a malformed low-privilege request with a high-privilege one to bypass authorization and other internal validation checks.

CVE-2026-60137
CVSS 5.9 · Medium EPSS 4.0% (89th)

An SQL-injection flaw [CWE-89] caused by improper sanitization of the author_exclude parameter, which WordPress maps to WP_Query::author__not_in but only sanitizes when passed as an integer array. A string-type value lets an attacker inject malicious SQL, and combined with CVE-2026-63030 this enables further exploitation.

Affected Versions and Mitigation for wp2shell

CVE-2026-60137 affects WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2. CVE-2026-63030 affects WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2. WordPress 6.8.x is only vulnerable to CVE-2026-60137, not the full wp2shell chain. The full wp2shell unauthenticated RCE vulnerability is only reported for WordPress Core versions 6.9.x and 7.0.x. That distinction is relevant for risk-based remediation, since exploiting CVE-2026-60137 depends on vulnerability to CVE-2026-63030.

CVE Affected versions Fixed versions

CVE-2026-60137

WordPress 6.8.x before 6.8.6; 6.9.x before 6.9.5; 7.0.x before 7.0.2

6.8.6; 6.9.5; 7.0.2

CVE-2026-63030

WordPress 6.9.x before 6.9.5; 7.0.x before 7.0.2

6.9.5; 7.0.2

The only described mitigation is to update WordPress Core to a fixed release. Users should update affected systems to 6.8.6, 6.9.5, or 7.0.2 as applicable. Greenbone’s OPENVAS ENTERPRISE FEED includes remote banner version checks to identify CVE-2026-63030 and CVE-2026-60137 for Linux [1][2] and Windows [3][4].

Summary

wp2shell is an unauthenticated RCE chain against WordPress Core that combines CVE-2026-63030 with CVE-2026-60137. Risk is amplified by widespread reports of exploitation. Defenders should immediately identify vulnerable WordPress installations and update them to the fixed versions described above.

Greenbone’s OPENVAS ENTERPRISE FEED includes remote banner version checks to identify CVE-2026-63030 and CVE-2026-60137 for Linux [1][2] and Windows [3][4]. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way to gain the deepest insight into where software vulnerabilities exist in your organization’s IT infrastructure.

 

Contact Test Now Buy Here Back to Overview
22. July 2026/by Joseph Lee
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Joseph Lee https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Joseph Lee2026-07-22 12:53:462026-07-22 14:32:21wp2shell: Exploit Chaining for Unauthenticated RCE in WordPress
Greenbone AG

TLS and SSH Security: Greenbone Has Updated Compliance Policies for the BSI’s TR-03116-4 and TR-02102-4

Blog

Glowing green atom illustration with the label 'BSI-Ready TLS & SSH' on a dark green background

Technical guidelines published by government bodies define the highest security standards for protecting the national IT infrastructure. As the cyber security landscape becomes more perilous, it’s even more important for organizations to be diligent about implementing the strictest security standards. Government organizations need to ensure compliance, while private-sector entities can use the standards as benchmarks for their own cyber resilience.

Greenbone is happy to announce updated compliance scans aligned with the German Federal Office for Information Security’s (BSI) minimum standards for hardening TLS and SSH. The policies identify specific TLS and SSH configuration gaps within portions of the respective guidance.

In this article, we review the TR-03116-4 and TR-02102-4 guidelines to understand what’s new. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way for your organization to gain the deepest insight into building resilient IT networks and applications.

The Transport Layer Security (TLS) and Secure Shell (SSH) protocols are among the most fundamental used in today’s networks. Greenbone now offers updated policy scans to measure compliance with selected portions of the BSI’s guidance. The updated guidance standards are:

  • TR-03116-4 (July 2025): BSI Minimum Standard for the Use of Transport Layer Security (TLS)
  • TR-02102-4 (January 2026): BSI Minimum Standard for the Use of Secure Shell (SSH)

These updates add to Greenbone’s already impressive line of compliance policies for OPENVAS SCAN. Although TR-03116-4 and TR-02102-4 do not yet include post-quantum cryptography guidelines, standards for assessing PQC-compliant systems are under development. Greenbone has helped lead the way. Our OPENVAS ENTERPRISE FEED features PQC compliance scans for both TLS and SSH:

  • SSL/TLS: Post Quantum Cryptography (PQC) Policy Check
  • SSH: Post Quantum Cryptography (PQC) Policy Check

Comparison of Greenbone’s new BSI compliance checks for TLS and SSH

TLS
TR-03116-4
BSI TLS Minimum Standard · July 2025
  • ✓Supported and minimum allowed TLS versions
  • ✓TLS 1.2 / 1.3 cipher suites vs. policy allow lists
  • ✓At least one BSI-mandated cipher suite supported
SSH
TR-02102-4
BSI SSH Minimum Standard · January 2026
  • ✓Protocol version, key-exchange, encryption, MAC, host-key algorithms, rekey limit
  • ✓AuthenticationMethods / RequiredAuthentications and PubkeyAuthentication
Neither standard defines PQC compliance yet — both advise starting a hybrid classical + quantum-safe migration now. Greenbone offers separate SSL/TLS PQC and SSH PQC policy checks.

Understanding TR-03116-4 BSI Minimum Standards for the Use of TLS

Part 4 of the TR-03116 series of technical guidelines specifies requirements and recommendations for the use of TLS in federal government applications. TR-03116-4 builds on earlier releases in the series. The standard is generally valid until the end of 2030, although specific timelines for deprecating or implementing certain methods are included. Greenbone’s policy covers selected portions of TR-03116-4; using remote TLS handshakes, the compliance scan assesses selected Chapter 2 controls, including:

  • Supported and minimum allowed TLS versions
  • Configured TLS 1.2 and TLS 1.3 cipher suites against policy allow lists
  • Presence of at least one BSI-mandated cipher suite supported by the server

Other vulnerability tests in the OPENVAS ENTERPRISE FEED separately identify additional risks posed by the remaining guidance areas. Examples include known SAML authentication and XML-signature vulnerabilities, vulnerable S/MIME/CMS implementations in OpenSSL or mail products, and OpenPGP/PGP software detection and product vulnerabilities.

Understanding TR-02102-4 BSI Minimum Standards for the Use of SSH

Part 4 of the BSI’s TR-02102 guideline series specifies the recommended SSH protocol versions, cryptographic algorithms, and key lengths for use in federal government applications. Like TR-03116-4 described above, TR-02102-4 builds on earlier guidance in its series, specifically TR-02102-1.

The Greenbone’s new compliance scans verify selected values read from the SSH server configuration, including:

  • SSH protocol version, allowed key-exchanges, encryption algorithms, MAC, host-key algorithms, and rekey limit
  • Client authentication requirements through AuthenticationMethods or RequiredAuthentications, and PubkeyAuthentication

These authenticated configuration checks provide useful technical evidence, but do not test live authentication behavior or assess client application risks, side channel attacks, implementation flaws, or operational controls associated with all SSH use-cases.

Post Quantum Compliance with Greenbone

Neither TR-03116-4 nor TR-02102-4 define compliance standards for Post Quantum Cryptography (PQC). However, they advise that organizations should prepare now to migrate from classical asymmetric cryptography to quantum-safe cryptography, beginning with hybrid schemes that combine classical and quantum-safe algorithms. Organizations seeking to assess their PQC resilience today can use Greenbone’s existing PQC policy scans:

  • SSL/TLS: Post Quantum Cryptography (PQC) Policy Check
  • SSH: Post Quantum Cryptography (PQC) Policy Check

Get to Know Greenbone’s Full Suite of Compliance Scans

OPENVAS SCAN’s compliance policies consist of specially selected groups of vulnerability tests used to assess compliance. Whether your organization is required to meet BSI technical standards or you simply want deeper insight into building resilient IT networks and applications, OPENVAS SCAN provides compliance visibility to identify gaps and strengthen security.

Some of the compliance scans in Greenbone’s OPENVAS ENTERPRISE FEED:

  • CIS Benchmark for Microsoft SQL Server 2022
  • CIS Benchmark v5.0.0 for Microsoft Windows Server 2022
  • CIS Benchmark v2.0.0 for Microsoft Windows Server 2025
  • CIS Benchmark v1.10 for Kubernetes 1.28 Controller Node
  • CIS Benchmark v1.10 for Kubernetes 1.28 Worker Nodes
  • Compliance profiles for Huawei EulerOS, openEuler, and Huawei Cloud EulerOS
  • CIS Benchmark v3.0.0 (L1) for Microsoft Windows 11 Enterprise
  • CIS Benchmarks v3.0.0 (L1 – Windows) for Google Chrome
  • BSI and CIS Benchmarks for Microsoft Office
  • Policy check for SSH: Post Quantum Cryptography (PQC)
  • Policy check for SSL/TLS: Post Quantum Cryptography (PQC)

Need compliance visibility into your TLS and SSH configurations?

Whether your organization is required to meet BSI technical standards or you simply want deeper insight into building resilient IT networks and applications, OPENVAS SCAN provides the compliance visibility needed to identify gaps and strengthen security. Contact Greenbone’s sales team to discuss how compliance scanning can best fit your organization’s regulatory and security governance requirements.

➤ Contact Sales

Summary

Germany’s BSI sets the technical requirements for federal government IT infrastructure. Other national governments around the world publish their own security forecasts and guidelines. While private institutions are not typically required to implement these guidelines, they offer reliable insight for implementing resilient IT architecture.

The Transport Layer Security (TLS) and Secure Shell (SSH) are two of the most fundamental protocols used in today’s IT networks. Greenbone is happy to announce updated compliance scans for selected portions of the BSI’s minimum standards for hardening TLS and SSH according to TR-03116-4 and TR-02102-4. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way for your organization to gain the deepest insight into building resilient IT networks and applications.

 

Contact Test Now Buy Here Back to Overview
21. July 2026/by Greenbone AG
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Greenbone AG https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Greenbone AG2026-07-21 13:49:062026-07-21 13:49:06TLS and SSH Security: Greenbone Has Updated Compliance Policies for the BSI’s TR-03116-4 and TR-02102-4
Greenbone AG

Greenbone’s OPENVAS SCAN Now Supports the Nutanix AHV Hypervisor

Blog

Users appreciate when software can easily integrate into their existing IT environment. For vendors, this means supporting a cross-platform mix of operating systems and infrastructure. Greenbone is excited to expand our virtualization platform support, bringing Nutanix AHV into our family of supported hypervisors. This addition adds flexibility for deploying OPENVAS SCAN and extends Greenbone’s already diverse support for hypervisors that also includes Microsoft Hyper-V, Oracle VirtualBox, VMware vSphere (ESXi) and and Workstation Pro, Huawei FusionCompute, and Proxmox VE. Our wide range of hypervisor support ensures that defenders can run our solution in virtually any IT environment.

A free trial of Greenbone’s OPENVAS BASIC is available for Nutanix users and others to scan their IT infrastructure for vulnerabilities and stay ahead of cyber attacks. For a full breakdown of our product offerings, check out our solution comparison.

In the rest of this article, we will discuss how to integrate OPENVAS SCAN virtual appliances on the Nutanix AHV Type-1 hypervisor.

OPENVAS SCAN now on Nutanix AHV

The OPENVAS SCAN Virtual Appliance Now Supports the Nutanix AHV Type-1 Hypervisor

Greenbone is excited to add support for Nutanix AHV virtualization. AHV (short for Acropolis Hypervisor) is the native hypervisor of the Nutanix Cloud Infrastructure platform. As a Type-1 hypervisor, AHV runs directly on the host’s hardware. This puts virtualized appliances closer to the underlying hardware and delivers high performance, low latency operation. The overall impact is a faster and more reliable virtualization environment. By contrast, Type-2 hypervisors run on top of a standard desktop operating system, which is not optimized for efficiency and reliability.

Nutanix is built on top of the Linux kernel’s KVM hypervisor and QEMU hardware emulator. The same open-source virtualization stack that underpins much of the modern data center and public cloud. Unlike traditional hypervisors, AHV is included at no additional licensing cost with the Nutanix Cloud Infrastructure platform and is managed through Nutanix Prism.

Whether you are an existing Greenbone enterprise customer looking for new virtualization options, or already running Nutanix AHV and seeking support, Greenbone now has you covered.

How to Set up OPENVAS SCAN on Nutanix AHV

Customers can request a Nutanix-ready instance of the OPENVAS SCAN virtual appliance from a member of the Greenbone sales team. This specialized image is delivered in the QEMU Copy-On-Write (QCOW) format, optimized for Nutanix AHV. Once you receive the .qcow file, complete the following steps in Nutanix Prism to install and configure the OPENVAS SCAN virtual appliance:

  1. Log in to the Nutanix AHV web interface and open the settings menu in the upper right corner.
  2. Select Image Configuration and click Upload Image. Give the image a name, set Image Type to DISK, choose Upload a file, select the QCOW file of the appliance, and click Save.
  3. Switch to the VM view from the drop-down menu in the upper left corner and click Create VM.
  4. Enter a name for the virtual machine, then set the number of virtual CPUs and cores, the amount of memory, and select UEFI as the boot configuration. The appliance requires the EFI/UEFI boot mode.
  5. Click Add New Disk, select Clone from Image Service as the operation, choose SATA as the bus type, select the image you uploaded in step 1, and click Add.
  6. Under Network Adapters (NIC), click Add New NIC and add at least one network interface, then click Save. The import can take up to 10 minutes.
  7. Once imported, select the appliance from the Table tab, click Power on, and complete the OPENVAS SCAN setup process.

Note

When using the community edition of Nutanix AHV, the combination of UEFI and the default network interface can cause issues at startup. As a workaround, add an e1000 network interface via SSH on the Nutanix host:

$ acli vm.nic_create NAMEOFVIRTUALMACHINE model=e1000 network=NAMEOFNETWORK

Full step-by-step instructions, including screenshots, are available in the Greenbone documentation.

Which Hypervisors Does the OPENVAS SCAN Virtual Appliance Support?

Here is an overview of the supported hypervisors and resource requirements for the OPENVAS SCAN virtual appliance.

The OPENVAS SCAN virtual appliance requires the following resources:

  • 2 virtual CPUs
  • 12 GB RAM
  • 500 GB virtual hard disk (can be dynamically allocated)

Hypervisors officially supported by the OPENVAS SCAN virtual appliance, with Type-1 and Type-2 classification and the newly added Nutanix AHV

Appliance resources 2 virtual CPUs | 12 GB RAM | 500 GB virtual disk
Nutanix AHV New
v6.8 or higher

Type-1 hypervisor

Proxmox VE
v8.0 or higher

Type-1 hypervisor

VMware vSphere (ESXi)
v7.0 or higher

Type-1 hypervisor

Huawei FusionCompute
v8.0

Type-1 hypervisor

Microsoft Hyper-V
Server 2016+ (gen 2 VM, config v8.0+)

Type-1 hypervisor

Oracle VirtualBox
v7.0 or higher

Type-2 hypervisor

VMware Workstation Pro
v17.0 or higher

Type-2 hypervisor

Summary

Greenbone has added support for deploying our OPENVAS SCAN virtual appliance on the Nutanix AHV Type-1 hypervisor, giving adding to our industry leading flexibility. This new capability extends the virtualization options, ensuring users can confidently integrate OPENVAS SCAN into any IT environment — including the growing number of data centers built on Nutanix. A free trial of Greenbone’s OPENVAS BASIC is available for Nutanix users and others to scan their IT infrastructure for emerging threats and stay ahead of cyber attacks.

 

Contact Test Now Buy Here Back to Overview
20. July 2026/by Greenbone AG
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Greenbone AG https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Greenbone AG2026-07-20 14:29:332026-07-20 14:29:33Greenbone’s OPENVAS SCAN Now Supports the Nutanix AHV Hypervisor
Joseph Lee

CTX696604: Multiple New Flaws Affecting Citrix NetScaler ADC and NetScaler Gateway

Blog

Citrix security advisory CTX696604 covers six vulnerabilities in customer-managed NetScaler ADC and NetScaler Gateway. NetScaler Gateway is used to authenticate remote users and connect them to internal network resources, and NetScaler ADC load balancing is a core feature used to distribute requests and improve availability. The highest-risk issues in the bulletin can lead to memory overread, denial of service (DoS), and arbitrary file read. However, specific configurations must be present for the flaws to be exploitable.

The bulletin applies only to customer-managed NetScaler ADC and NetScaler Gateway. Citrix cloud services have already been upgraded by Citrix. In some cases, exploitation requires specific deployments or enabled features, such as SAML IDP, Gateway services, AAA virtual server exposure, Oracle or DNS roles, management access on NSIP or SNIP, and protocol options attached to virtual servers or services.

There is no evidence of active exploitation for the CVEs included in the CTX696604 advisory, and no public proof-of-concept (PoC) exploits have been released. However the same affected products were actively exploited in March, 2026. In total, Citrix Netscaler has been added to CISA’s KEV list 22 times since late 2021, shockingly 7 times associated with ransomware attacks. Multiple national CERT alerts have been issued for the new CVEs, indicating a high level of global risk [1][2][3][4][5][6][7][8][9][10][11][12][13].

CTX696604 advisory: multiple new vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway

The OPENVAS ENTERPRISE FEED includes a remote banner check that identifies vulnerable NetScaler ADC and NetScaler Gateway installations affected by the CVEs in Citrix advisory CTX696604. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way to gain the deepest insight into where software vulnerabilities exist in your organization’s IT infrastructure.

Vulnerability Details for Citrix Bulletin CTX696604

The six CVEs in the bulletin can cause memory overread, DoS, and arbitrary file read. In each case, the vendor ties exploitability to a specific configuration, which narrows exposure but does not eliminate the need for patching. The most operationally sensitive issues are those that are unauthenticated and network-reachable.

The six CVEs disclosed in Citrix advisory CTX696604, each shown with its CVSS severity band and EPSS exploitation-probability score

CVE-2026-8452 CVSS 9.8 · Critical EPSS 0.5% (39th)

An unauthenticated, remotely exploitable memory overread [CWE-119] flaw that can result in unexpected behavior or denial-of-service. The flaw affects devices using SSL VPN, ICA Proxy, CVPN, RDP Proxy, or an AAA virtual server.

CVE-2026-8655 CVSS 9.8 · Critical EPSS 0.5% (37th)

An unauthenticated, remotely exploitable memory overread [CWE-119] flaw affecting NetScaler ADC only when configured as an Oracle or DNS proxy load balancer, or as a recursive DNS resolver, leading to unexpected behavior or denial-of-service.

CVE-2026-8451 CVSS 7.5 · High EPSS 0.5% (39th)

An unauthenticated, remotely exploitable out-of-bounds read [CWE-125] that can disclose sensitive information. The flaw only affects NetScaler ADC or NetScaler Gateway when configured as a SAML identity provider.

CVE-2026-10816 CVSS 7.5 · High EPSS 0.4% (33rd)

An unauthenticated, remotely exploitable external control of file name or path [CWE-73] flaw enabling arbitrary file read. Requires access to the NetScaler IP, Cluster Management IP, or subnet IP address with management access enabled.

CVE-2026-10817 CVSS 7.5 · High EPSS 0.4% (33rd)

An unauthenticated, remotely exploitable out-of-bounds read [CWE-125] that can result in arbitrary file read and potential disclosure of sensitive information. Only affects configurations where TCP Timestamp is enabled in a TCP profile attached to a virtual server or service.

CVE-2026-13474 CVSS 7.5 · High EPSS 0.4% (36th)

An unauthenticated, remotely exploitable denial-of-service [CWE-401] triggered by malformed HTTP/2 requests. Only affects configurations where HTTP/2 is enabled in an HTTP profile attached to an affected virtual server or service.

CVE-2026-8452 and CVE-2026-8655 are both potentially high-impact, remotely exploitable flaws that do not require authentication. They both affect service endpoints that are typically unrestricted. CVE-2026-8451 can result in the disclosure of sensitive information that could be leveraged in subsequent attacks. While CVE-2026-10816 is also remotely exploitable without authentication, management access to the affected device must be enabled.

Start Your Free Trial

The OPENVAS ENTERPRISE FEED includes a remote banner check to identify vulnerable NetScaler ADC and NetScaler Gateway installations affected by the CVEs discussed in Citrix advisory CTX696604. Grab a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED to gain the deepest insight into where software vulnerabilities exist in your organization’s IT infrastructure.

Affected Products and Versions

The advisory affects multiple customer-managed NetScaler product lines, including standard releases and FIPS or NDcPP builds. According to the vendor, Secure Private Access Hybrid deployments using NetScaler instances are also affected. The impact is configuration-dependent, so defenders should validate both version status and whether the listed services or profiles are enabled.

Product Affected versions Fixed version

NetScaler ADC and NetScaler Gateway

14.1 before 14.1-72.61; 13.1 before 13.1-63.18

14.1-72.61; 13.1-63.18

NetScaler ADC FIPS

before 14.1-72.61 FIPS

14.1-72.61 FIPS

NetScaler ADC FIPS and NDcPP

before 13.1-37.272

13.1-37.272

Mitigating Citrix NetScaler CVEs from Bulletin CTX696604

The fixed releases listed by the vendor in the table above provide the most effective remediation path. Organizations running affected devices should move to the corresponding fixed version for their release train. No workarounds are described in the vendor bulletin.

For CVE-2026-13474, the Cyber Security Agency of Singapore recommends setting the Http2SmallWndTimeout parameter to 30 seconds as an added mitigation. That guidance is specific to the HTTP/2-related issue and does not replace the vendor fix.

Defenders should check whether the affected features are enabled, because the vulnerable conditions depend on deployment state. Security teams should validate SAML IDP configurations; Gateway and AAA virtual servers; Oracle and DNS roles; management access exposure on NSIP or SNIP; TCP Timestamp settings in profiles; and HTTP/2 settings in HTTP profiles. Where those functions are not required, disabling them reduces exposure while patching is scheduled.

Summary

The Citrix CTX696604 advisory describes six NetScaler ADC and NetScaler Gateway vulnerabilities that affect customer-managed deployments and certain Secure Private Access Hybrid instances. The highest-risk CVEs are configuration-dependent. However, these include unauthenticated network-reachable impacts such as unexpected behavior, sensitive information disclosure, DoS, and arbitrary file read conditions. Available evidence does not indicate active exploitation or that a public PoC exists. However, multiple national CERT alerts have been issued for the CVEs [1][2][3][4][5][6][7][8][9][10][11][12][13].

Organizations should scan their infrastructure for affected appliances, confirm whether the vulnerable features are enabled, and apply the fixed releases for their product line without delay. The OPENVAS ENTERPRISE FEED includes a remote banner check to identify vulnerable NetScaler ADC and NetScaler Gateway installations affected by the CVEs discussed in Citrix advisory CTX696604. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way to gain the deepest insight into where software vulnerabilities exist in your organization’s IT infrastructure.

 

Contact Test Now Buy Here Back to Overview
16. July 2026/by Joseph Lee
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Joseph Lee https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Joseph Lee2026-07-16 15:43:262026-07-16 15:43:26CTX696604: Multiple New Flaws Affecting Citrix NetScaler ADC and NetScaler Gateway
Joseph Lee

BeyondTrust BT26-03: Critical and High-Severity Flaws in Remote Support and Privileged Remote Access

Blog

BeyondTrust advisory BT26-03, issued on July 6th, 2026, describes multiple new vulnerabilities in BeyondTrust Remote Support (RS) and BeyondTrust Privileged Remote Access (PRA). The vulnerabilities include two critical flaws exploitable without authentication and additional high-severity issues in network communication and web application components. All the flaws require specific configurations for exploitation, but BeyondTrust has not disclosed the configuration details.

According to BeyondTrust, the issues were found through internal AI-driven vulnerability research using publicly available AI models, and they were fixed before exploitation. The vendor also claims that the flaws were not exploited or known outside the company prior to remediation.

BeyondTrust BT26-03-Security-Bulletin: critical and high severity flaws in Remote Support and Privileged Remote Access

There is no evidence that any of the CVEs have been exploited in the wild, and no public proof-of-concept (PoC) exploits have been published. CISA has added three vulnerabilities affecting BeyondTrust RS and PRA to its KEV Catalog since late 2024, indicating that the products are popular targets for attackers. CVE-2026-1731 was added in early 2026 and is associated with ransomware attacks. Numerous national CERT agencies have issued alerts [1][2][3][4][5][6][7][8][9], indicating high global risk.

BeyondTrust BT26-03 advisory: critical and high-severity vulnerabilities in Remote Support and Privileged Remote Access

OPENVAS ENTERPRISE FEED includes a remote banner version check covering CVE-2026-40138, CVE-2026-40140, and CVE-2026-40141 in BeyondTrust PRA, and a separate remote banner version check for CVE-2026-40138, CVE-2026-40139, CVE-2026-40140, and CVE-2026-40141 in BeyondTrust RS. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way to gain the deepest insight into where software vulnerabilities exist in your organization’s IT infrastructure.

Vulnerabilities Disclosed in the BeyondTrust BT26-03 Advisory

The BeyondTrust BT26-03 advisory covers two critical and two high-severity CVEs across two products: BeyondTrust RS and PRA. There is no evidence of exploitation in the wild, and no publicly available PoC exploits exist for any of the CVEs disclosed in BT26-03. All of the flaws have been assigned moderate EPSS scores: 34th – 47th percentiles.

The four CVEs disclosed in BeyondTrust BT26-03, each shown with its CVSS severity band and EPSS exploitation-probability score

CVE-2026-40141 CVSS 9.9 · Critical EPSS 0.5% (38th)

An improper neutralization of special elements in data-query logic [CWE-943] flaw in a web application component of BeyondTrust RS and PRA. An authenticated attacker with specific permissions could access or manipulate resources and data outside the intended authorization boundary.

CVE-2026-40139 CVSS 9.8 · Critical EPSS 0.7% (47th)

An improper authentication [CWE-287] flaw in BeyondTrust RS. A remote, unauthenticated attacker could bypass access controls when a specific authentication configuration is enabled, which BeyondTrust does not publicly identify.

CVE-2026-40138 CVSS 8.1 · High EPSS 0.4% (34th)

An improper authentication [CWE-287] flaw in BeyondTrust RS and PRA. A remote, unauthenticated attacker could bypass access controls and reach elevated accounts when a specific authentication configuration is enabled, which BeyondTrust does not publicly identify.

CVE-2026-40140 CVSS 7.5 · High EPSS 0.6% (43rd)

An uncontrolled resource consumption [CWE-400] flaw in the network communication subsystem of BeyondTrust RS and PRA. A remote, unauthenticated attacker could trigger a denial-of-service and disrupt appliance availability.

Affected Products and Versions

BeyondTrust states that all cloud-hosted RS and PRA instances were patched as of April 21st, 2026. For self-hosted deployments, the vendor directs customers to apply the April security rollup patch or upgrade to the fixed product versions. The supplied evidence identifies RS 25.3.2 and earlier and PRA 25.3.2 and earlier as affected. BeyondTrust provides no workarounds for the vulnerabilities.

Product CVEs Affected versions Fixed versions

BeyondTrust Remote Support

CVE-2026-40138, CVE-2026-40139, CVE-2026-40140, CVE-2026-40141

RS 25.3.2 or earlier

RS 25.3.3 or later; Security Rollup April 2026 25 RS or Security Rollup April 2026 24 RS, depending on the RS version

BeyondTrust Privileged Remote Access

CVE-2026-40138, CVE-2026-40140, CVE-2026-40141

PRA 25.3.2 or earlier

PRA 25.3.3 or later; Security Rollup April 2026 25 PRA or Security Rollup April 2026 24 PRA, depending on the PRA version

BeyondTrust Remote Support (RS) is an enterprise-grade remote support tool used by IT service desks, help desks, and support teams to connect to and control remote systems and devices. In operational terms, that means the product often sits on a path used for remote troubleshooting, administrative support, and endpoint interaction.

BeyondTrust Privileged Remote Access (PRA) is used to manage remote access to critical systems for privileged users and third-party vendors. The product includes session monitoring, auditing, recording, and least-privilege controls. BeyondTrust also describes the B Series Appliance as the central communication point for secure remote access, handling session brokering, authentication, logging, auditing, and encryption.

Start Your Free Trial

The OPENVAS ENTERPRISE FEED includes remote banner version checks for CVE-2026-40138, CVE-2026-40139, CVE-2026-40140, and CVE-2026-40141 across BeyondTrust RS [1] and PRA [2]. Grab a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED to gain the deepest insight into where software vulnerabilities exist in your organization’s IT infrastructure.

Summary

BT26-03 consolidates four confirmed vulnerabilities across BeyondTrust Remote Support and BeyondTrust Privileged Remote Access. The most important issues are the two critical pre-authentication flaws, followed by the high-severity vulnerabilities in the network communication and web application components. Although none of the CVEs are known to have been exploited in the wild and no public PoC exploit exists, CISA has added three vulnerabilities affecting BeyondTrust RS and PRA to its KEV Catalog since late 2024. CVE-2026-1731 was added in early 2026 and is associated with ransomware attacks. Numerous national CERT agencies have issued alerts, indicating high global risk. Greenbone’s OPENVAS ENTERPRISE FEED provides remote banner version checks for the BT26-03 CVEs, helping defenders identify affected BeyondTrust RS and PRA appliances and prioritize remediation.

 

Contact Test Now Buy Here Back to Overview
15. July 2026/by Joseph Lee
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Joseph Lee https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Joseph Lee2026-07-15 10:59:032026-07-15 10:59:03BeyondTrust BT26-03: Critical and High-Severity Flaws in Remote Support and Privileged Remote Access
Page 1 of 41234

Search

Search Search

Archive

  • 2026
  • 2025

Newsletter

Subscribe Now

OPENVAS BASIC

Our entry-level enterprise product

Test 14 Days Free of Charge

Products & Solutions

  • OPENVAS PRODUCTS
  • OPENVAS SECURITY INTELLIGENCE
  • OPENVAS SCAN
  • OPENVAS BASIC
  • OPENVAS FREE
  • OPENVAS AI
ISO9001-EN

Service & Support

  • Professional Services
  • Documents
  • Technical Support
  • FAQ
  • Warranty
  • Cyber Resilience Act
ISO27001-EN

About us

  • About Greenbone
  • Partners
  • MSSP
  • License information
  • Privacy Statement
  • Terms & Conditions
ISO14001-EN

Contact with us

  • Contact
  • Newsletter
  • Media Contact
  • Careers
  • Security Response
  • Imprint
  • Grounding Page

Community

  • Community Portal
  • Community Forum
© Copyright - Greenbone AG 2020-2026
  • Link to LinkedIn
Scroll to top Scroll to top Scroll to top
Contact
Request IT Security Contact Us Subscribe to Newsletter Follow on LinkedIn