• Request consultation
  • Newsletter
  • Deutsch Deutsch German de
  • English English English en
  • Italiano Italiano Italian it
  • Nederlands Nederlands Dutch nl
Greenbone
  • Products
    • OPENVAS BASIC
      • OPENVAS BASIC: Order
    • OPENVAS SCAN
    • Upcoming Solutions
      • OPENVAS SECURITY INTELLIGENCE
      • OPENVAS AI
    • Solutions for Your Sector
      • Educational Sector
      • Healthcare Sector
      • Public Sector
    • Technology
      • Feed Comparison
      • Product Comparison
        • OPENVAS vs. Nessus
      • Roadmap & Lifecycle
  • Service & Support
    • Professional Services
    • Documents
    • Technical Support
  • Events
    • MSP GLOBAL 2026
    • Webinars
  • Partners
    • MSSP
  • About Greenbone
    • Our History
    • Careers
    • Contact
  • Blog
    • Know-how
      • Attack Vector Timeline
      • Cyberattacks and Defense
      • Cyber Defense Security
      • Cyber Resilience Act
      • Data Security
      • Digital Operational Resilience Act
      • Exposure Management
      • IT and Information Security
      • NIS2 Directive
      • Open Source Vulnerability Management
      • The Vulnerability Timeline
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu
  • Products
    • OPENVAS BASIC
      • OPENVAS BASIC: Order
    • OPENVAS SCAN
    • Upcoming Solutions
      • OPENVAS SECURITY INTELLIGENCE
      • OPENVAS AI
    • Solutions for your sector
      • Educational Sector
      • Healthcare Sector
      • Public Sector
    • Technology
      • Feed Comparison
      • Product Comparison
        • OPENVAS vs. Nessus
      • Roadmap and Lifecycle
    • Request IT Security
  • Service & Support
    • Professional Services
    • Documents
    • Technical Support
  • Events
    • MSP GLOBAL 2026
    • Webinars
  • Partners
    • MSSP
  • About Greenbone
    • Our History
    • Careers
    • Contact
    • Newsletter
  • Our Blog
    • Know-how
      • Attack Vector Timeline
      • Cyberattacks and Defense
      • Cyber Defense Security
      • Cyber Resilience Act
      • Data Security
      • Digital Operational Resilience Act
      • Exposure Management
      • IT and Information Security
      • NIS2 Directive
      • Open Source Vulnerability Management
      • The Vulnerability Timeline
  • German
  • English
  • Italian
  • Dutch
Joseph Lee

CVE-2026-16232: Check Point SmartConsole Login Process Actively Exploited and More

Blog

Check Point has published three new security advisories addressing flaws in Security Management Server (SMS), Multi-Domain Management (MDM), and other Gaia-related components. The highest-priority issue, CVE-2026-16232 (CVSS 9.1), is an actively exploited authentication bypass affecting Check Point SmartConsole in SMS and MDM products. CVE-2026-16232 was published on July 22nd, 2026, and added to CISA’s Known Exploited Vulnerabilities (KEV) list the same day. The other newly disclosed flaws are CVE-2026-62144 (CVSS 9.1), an authentication bypass and privilege escalation in SMS and MDM, and CVE-2026-62145 (CVSS 7.5) affecting the GaiaOS WebUI management interface of Check Point’s Firewall, MDM, Multi-Domain Log Server.

Check Point security advisory banner: three new CVEs, one actively exploited

Start Your Free Trial

The OPENVAS ENTERPRISE FEED includes a remote banner version check to identify potentially vulnerable instances of Check Point Gaia OS that may host affected components. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way to gain the deepest insight into where software vulnerabilities exist in your organization’s IT infrastructure.

A Risk Assessment of Check Point’s July 2026 Security Update

According to Check Point, exploitation of CVE-2026-16232 only affected a very small number of customers that exposed management servers directly to the internet without IP restrictions. The vulnerabilities are high risk because they affect administrative control paths used to configure security policies, objects, gateways, permissions, and monitoring.

Check Point’s Security Management Server (SMS) manages one security-management domain. SMS sits above the gateways in the control hierarchy stores, objects and policies, and distributes them to managed Security Gateways. Multi-Domain Management (MDM) is the large-scale alternative to a single Security Management Server. It provides isolated management environments for different customers, business units, regions, or security zones.

SmartConsole is the GUI used to connect to and manage SMS, and Security Management Servers manage Security Gateways and monitor security events. Gaia Portal is the web-based interface for Gaia OS, and Check Point says most system configuration tasks can be performed through it.

CVE-2026-16232: Actively Exploited SmartConsole Authentication Bypass

CVSS 9.1 · CriticalActively exploitedIn CISA KEV

An improper authentication vulnerability [CWE-287] in the Check Point SmartConsole login process of SMS and MDM products. CVE-2026-16232 allows a remote, unauthenticated attacker to obtain an application login token and use it to authenticate with full administrative privileges. Remote exploitation requires access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Successful exploitation allows the attacker to modify security policies and configurations.

Other CVEs From Check Point’s July 2026 Advisories

Check Point’s July 2026 security advisories also disclosed two additional CVEs:

The two additional CVEs disclosed in Check Point’s July 2026 advisories, each shown with its CVSS severity band and EPSS exploitation-probability score

CVE-2026-62144
CVSS 9.1 · Critical EPSS 20.6% (97th)

A critical improper authentication [CWE-287] flaw affecting Check Point SMS and MDM. The flaw allows a remote, unauthenticated attacker to execute administrative commands on the Management Server and potentially execute commands on managed Security Gateways. Exploitation requires network access to a Management Server that does not restrict Trusted Clients.

CVE-2026-62145
CVSS 7.5 · High EPSS 7.5% (94th)

A high-severity improper privilege management [CWE-269] flaw in Check Point Gaia Portal. Exploitation requires an authenticated account with read-only Gaia Portal privileges. A successful attacker could execute commands with root privileges, potentially gaining complete control of the affected system.

Affected Products and Mitigation for Check Point Security Management and Gaia OS

The direct remediation path is to apply the appropriate Jumbo Hotfix for the affected component’s current version of Gaia OS. For Check Point SMS, the relevant fixes are R81.20 Jumbo Hotfix Take 158, R82 Jumbo Hotfix Take 118, and R82.10 Jumbo Hotfix Take 36. These hotfixes address the CVEs discussed above, as well as CVE-2026-31431 (CVSS 7.8, aka Copy Fail), CVE-2026-43284 (CVSS 8.8), CVE-2026-43500 (CVSS 7.8, aka Dirty Frag), CVE-2026-46300 (CVSS 7.8, aka Fragnesia), and more. Patch prioritization should focus on SMS and MDM deployments that are reachable from the internet and do not use Trusted Clients restrictions or IP restrictions.

Summary

Check Point issued three new security advisories in July 2026 that disclose two Critical vulnerabilities in Security Management Server and one High-severity Gaia Portal privilege-escalation flaw[1][2][3]. CVE-2026-16232 allows full administrative access on Security Management infrastructure and is known to be actively exploited.

Start Your Free Trial

The OPENVAS ENTERPRISE FEED includes a remote banner version check to identify potentially vulnerable instances of Check Point Gaia OS that may host affected components. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way to gain the deepest insight into where software vulnerabilities exist in your organization’s IT infrastructure.

 

Contact Test Now Buy Here Back to Overview
28. July 2026/by Joseph Lee
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Joseph Lee https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Joseph Lee2026-07-28 15:58:102026-08-03 11:18:12CVE-2026-16232: Check Point SmartConsole Login Process Actively Exploited and More
Joseph Lee

CVE-2026-53359 (aka Januscape): VM Escape Hits Linux KVM/x86

Blog

Januscape, tracked as CVE-2026-53359 (CVSS 8.8), is a use-after-free vulnerability [CWE-825] in the Linux kernel KVM/x86 that can let a guest crash its host and potentially break guest-host isolation. The highest-risk targets are Intel and AMD x86_64 KVM hosts that expose nested virtualization, especially in environments that accept untrusted guests or allow users to create virtual machines. Large global data center operators worldwide now face the complex task of patching vast fleets of KVM hosts while minimizing disruption to customer workloads.

Active exploitation of CVE-2026-53359 has not yet been reported. The vulnerabilities original reporter, Hyunwoo Kim, claims that the bug was used as a zero-day in Google’s kvmCTF and has released a PoC capable of causing Denial of Service (DoS) of all VMs running on the host from within a single guest VM. Detailed technical analysis have also been published [1][2]. Numerous national CERT agencies have issued alerts indicating high global risk [3][4][5][6][7][8][9][10][11][12][13][14][15][16].

Greenbone’s OPENVAS ENTERPRISE FEED includes detection for CVE-2026-53359 on Red Hat Enterprise Linux (RHEL), SUSE and openSUSE, AlmaLinux, Oracle Linux, Rocky Linux, Fedora, and Debian. Greenbone will continue to add vulnerability detection as more Linux distributions issue security advisories. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way to gain the deepest insight into where software vulnerabilities exist in your organization’s IT infrastructure.

Illustration representing CVE-2026-53359 (Januscape), a VM escape vulnerability in Linux KVM/x86 virtualization

A Global Risk Assessment of CVE-2026-53359 (Januscape)

According to the original public disclosure, the flaw has existed for roughly 16 years. Furthermore, all x86 Linux distributions and kernels prior to the fix commit are affected. This means the scope of affected IT infrastructure is very broad, presenting significant global risk. Successful exploitation can result in guest-to-host escape, corruption of the host kernel’s shadow page, DoS, and potentially, compromise of other guest VMs on the same host. For global data center operators, that scope translates into the same challenge repeated across every site: rolling out patches to thousands of KVM hosts without knocking customer workloads offline.

According to a post on Ubuntu’s blog, the primary public PoC effectively demonstrates that a guest VM can crash its hypervisor host. Furthermore, the original report says CVE-2026-53359 was used as a zero-day exploit in the Google kvmCTF.

The Technical Assessment of CVE-2026-53359 (Januscape)

CVE-2026-53359 (CVSS 8.8) affects KVM nested virtualization on Intel and AMD x86_64 systems, while other architectures are not affected. If a cloud provider does not allow nested virtualization, instances are not affected through this path. However, nested virtualization is enabled by default in the Linux kernel. Successful exploitation allows guest-to-host escape, corruption of the host kernel’s shadow page, DoS, and compromise of other VM guests running on the same host.

Ubuntu’s blog notes that system services such as libvirt, lxd, multipass, and incus may allow potential attackers to create virtual machines, which can affect exposure. A separate risk path exists where /dev/kvm permissions are overly broad; if /dev/kvm is world-writable, an unprivileged user can achieve local privilege escalation to gain root-level privileges.

CVE-2026-53359 is a use-after-free in shadow MMU emulation caused by shadow-page reuse when the page role does not match the new use. The affected component is the Linux kernel KVM/x86 shadow paging path in arch/x86/kvm/mmu/mmu.c. The root cause is that the kvm_mmu_get_child_sp() function does not compare roles effectively. The mismatch can leave a stale rmap entry, leading to an exploitable pointer de-reference [CWE-825].

Products Affected by CVE-2026-53359 (Januscape)

All x86 Linux distributions after roughly 2014 and prior to the Linux kernel fix commit are affected, regardless of distribution. Because CVE-2026-53359 is a guest-to-host escape vulnerability, exploitation depends on the the target system being used as a KVM-based hypervisor and having nested virtualization enabled on a guest VM.

For Ubuntu environments, defenders should review Canonical’s Januscape mitigation guidance, which says all Ubuntu releases from Trusty (14.04) through Resolute (26.04) are are affected. While patches for Ubuntu are still pending, instructions for disabling nested virtualization are provided. For Red Hat environments, teams should compare deployed kernels against the fixed builds listed in Red Hat’s security data entry.

Mitigation for CVE-2026-53359 (aka Januscape)

Complete mitigation depends on installing the security updates for the specific Linux distribution. Prioritized mitigation should begin with identifying where nested virtualization is exposed on Linux KVM/x86 hypervisors, especially in multi-tenant environments or deployments that allow untrusted users to create or control guest VMs. Because exploitation may depend on guest control or access to virtualization interfaces, defenders should also review who can create VMs and whether device-node permissions around /dev/kvm expose an additional local privilege escalation path.

Summary

CVE-2026-53359 (aka Januscape; CVSS 8.8) is a high-impact virtualization-boundary vulnerability caused by a use-after-free flaw on Intel and AMD x86_64 Linux KVM deployments with nested virtualization enabled in the Linux kernel. The consequences include guest-to-host escape, and possible compromise of other guest VMs on the same host. At least one public proof-of-concept is available along with detailed technical analysis [1][2]. Active exploitation is not yet confirmed, but the volume of national CERT advisories flagging the flaw as a high global risk tells its own story [3][4][5][6][7][8][9][10][11][12][13][14][15][16].

Detection is already available: Greenbone’s OPENVAS ENTERPRISE FEED covers CVE-2026-53359 across Red Hat Enterprise Linux (RHEL), SUSE and openSUSE, AlmaLinux, Oracle Linux, Rocky Linux, Fedora, and Debian, with more distributions being added as their advisories land. A free two-week trial of OPENVAS SCAN with the OPENVAS ENTERPRISE FEED is the fastest way to see exactly where this vulnerability sits in your organization’s infrastructure.

Contact Test Now Buy Here Back to Overview
23. July 2026/by Joseph Lee
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Joseph Lee https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Joseph Lee2026-07-23 16:59:132026-07-23 16:59:13CVE-2026-53359 (aka Januscape): VM Escape Hits Linux KVM/x86
Joseph Lee

wp2shell: Exploit Chaining for Unauthenticated RCE in WordPress

Blog

A WordPress Core vulnerability chain, publicly nicknamed wp2shell, combines CVE-2026-63030 (CVSS 9.8) and CVE-2026-60137 (CVSS 5.9) for pre-authentication remote code execution (RCE). The exploit chain affects WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2. WordPress 6.8.x before 6.8.6 is affected by CVE-2026-60137 alone. Dozens of proof-of-concept (PoC) exploits have been published for the full exploit chain [1] as well as several detailed technical write ups. In-the-wild exploitation was first widely reported by cyber security firms. Finally both CVEs were added to CISA’s KEV list on July 21st, 2026 [2][3]. Numerous national CERT agencies have issued alerts globally [4][5][6][7][8][9][10][11][12][13][14][15][16][17]. Because WordPress has an estimated 500 million installations globally, wp2shell presents a high degree of risk.

wp2shell: Unauthenticated RCE Exploit Chain in WordPress Core

Greenbone’s OPENVAS ENTERPRISE FEED includes remote banner version checks to identify CVE-2026-63030 and CVE-2026-60137 for Linux [1][2] and Windows [3][4]. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way to gain the deepest insight into where software vulnerabilities exist in your organization’s IT infrastructure.

A Global Risk Assessment of wp2shell Affecting WordPress Core

The exposure is significant because the flaws impact default installations of WordPress Core rather than optional extensions or configurations and allows an unauthenticated attacker to achieve RCE. Searchlight Cyber estimates that more than 500 million websites use WordPress. Additional risk signals include widespread reports of active exploitation and numerous public PoCs.

A Summary of Active wp2shell Exploitation Campaigns

Active exploitation of CVE-2026-60137 and CVE-2026-63030 is now widely reported by numerous cyber security firms and independent sensor operators. Patchstack first classified both vulnerabilities as actively exploited shortly after disclosure [1]. Wordfence recorded probing of the WordPress REST API on July 17th, 2026, followed by a clear SQL-injection attempt 13 minutes later [2]. Several other cyber security companies have also confirmed active exploitation [3][4].

The observed campaigns are opportunistic, targeting WordPress installations across all industries and geographic regions. However, the activity has not been attributed to established threat actors, and no victims have been publicly identified. Confirmed techniques include unauthorized administrator-account creation, malicious-plugin installation, persistent backdoors and web shells, user enumeration, and attempts to obtain database credentials, authentication keys, and other secrets from wp-config.php.

Technical Details for CVE-2026-60137 and CVE-2026-63030

Here are brief details for both vulnerabilities in the wp2shell exploit chain:

  • CVE-2026-63030 (CVSS 9.8): The WordPress Core batch API allows multiple REST calls to be bundled into one request. CVE-2026-63030 is a batch endpoint route confusion issue [CWE-436] associated with /wp-json/batch/v1. The flaw is caused when failed batch sub-requests are not appended to the $matches array resulting in an index offset. The flaw allows an attacker to submit a malicious batch of requests that includes a flawed low-privilege request designed to create an array index offset, followed by a high-privilege request that will be executed without proper authorization. By exploiting CVE-2026-63030, an attacker can not only bypass authorization, but also bypass other WordPress internal checks such as request method, route, and validation schema.
  • CVE-2026-60137 (CVSS 5.9): An SQL-injection flaw caused by improper sanitization [CWE-89] of the author_exclude parameter in WP_Query. WordPress’s posts handler maps the attacker-controlled author_exclude value to the WP_Query::author__not_in parameter, which is only sanitized if provided as an integer array. When facilitated by CVE-2026-63030, attackers can provide malformed request parameters including a string type author_exclude value. The unsanitized value is then injected into an SQL query, where it can execute malicious SQL code.

How the wp2shell Unauthenticated RCE Chain Works

wp2shell is described as an exploit chain that combines CVE-2026-60137 and CVE-2026-63030. In the first stage, CVE-2026-63030 is leveraged to create a REST API batch endpoint route confusion flaw [CWE-436] in WordPress Core to execute unauthenticated commands. In the second stage, that condition is combined with the SQL-injection flaw [CWE-89] tracked as CVE-2026-60137 to further impact target WordPress installations.

Here is a general description of the wp2shell attack flow:

1. Exploit CVE-2026-63030

  • The attacker submits a malicious request to WordPress’s public /wp-json/batch/v1 endpoint. The malformed subrequest triggers a request handler mismatch allowing privileged requests to be executed without proper authorization.
  • The attacker recursively invokes the vulnerable batch endpoint. An initial desynchronization exploit bypasses authorization, while a second desynchronization exploit bypasses parameter validation. This allows a normally unsupported GET request to reach the WordPress posts handler with unvalidated input.

2. Exploit CVE-2026-60137

  • The posts handler maps the attacker-controlled author_exclude value to WP_Query::author__not_in. WordPress sanitizes this value when it is provided as an array but not when it arrives as a string, allowing the value to be injected directly into an SQL query. The attacker may use a blind or UNION SELECT SQL-injection attack to recover sensitive information that can be used for further exploitation. This information includes enumerating the WordPress table prefix, an administrator user ID, existing post IDs, and generated oEmbed-cache row IDs.
  • A UNION SELECT SQL injection can be designed to create legitimate WP_Post objects which are stored in the WordPress object cache. These objects form a chain of legitimate WordPress behaviors that convert the read-oriented SQL injection into database writes and application control-flow changes. Exploitation can allow an attacker to create rogue posts with web shells to achieve RCE with the privileges of the web-server process.
  • Other attack scenarios include creating persistent rogue administrator accounts and using them to upload malicious plugins, theme components, or web shells to achieve RCE with the privileges of the web-server process.

The two CVEs chained in the wp2shell exploit, CVE-2026-63030 and CVE-2026-60137, each shown with its CVSS severity band and EPSS exploitation-probability score

CVE-2026-63030
CVSS 9.8 · Critical EPSS 98.1% (100th)

A batch endpoint route confusion flaw [CWE-436] in the WordPress Core batch API (/wp-json/batch/v1), caused when failed sub-requests are not appended to the $matches array. An unauthenticated attacker can chain a malformed low-privilege request with a high-privilege one to bypass authorization and other internal validation checks.

CVE-2026-60137
CVSS 5.9 · Medium EPSS 78.0% (100th)

An SQL-injection flaw [CWE-89] caused by improper sanitization of the author_exclude parameter, which WordPress maps to WP_Query::author__not_in but only sanitizes when passed as an integer array. A string-type value lets an attacker inject malicious SQL, and combined with CVE-2026-63030 this enables further exploitation.

Affected Versions and Mitigation for wp2shell

CVE-2026-60137 affects WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2. CVE-2026-63030 affects WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2. WordPress 6.8.x is only vulnerable to CVE-2026-60137, not the full wp2shell chain. The full wp2shell unauthenticated RCE vulnerability is only reported for WordPress Core versions 6.9.x and 7.0.x. That distinction is relevant for risk-based remediation, since exploiting CVE-2026-60137 depends on vulnerability to CVE-2026-63030.

CVE Affected versions Fixed versions

CVE-2026-60137

WordPress 6.8.x before 6.8.6; 6.9.x before 6.9.5; 7.0.x before 7.0.2

6.8.6; 6.9.5; 7.0.2

CVE-2026-63030

WordPress 6.9.x before 6.9.5; 7.0.x before 7.0.2

6.9.5; 7.0.2

The only described mitigation is to update WordPress Core to a fixed release. Users should update affected systems to 6.8.6, 6.9.5, or 7.0.2 as applicable. Greenbone’s OPENVAS ENTERPRISE FEED includes remote banner version checks to identify CVE-2026-63030 and CVE-2026-60137 for Linux [1][2] and Windows [3][4].

Summary

wp2shell is an unauthenticated RCE chain against WordPress Core that combines CVE-2026-63030 with CVE-2026-60137. Risk is amplified by widespread reports of exploitation. Defenders should immediately identify vulnerable WordPress installations and update them to the fixed versions described above.

Greenbone’s OPENVAS ENTERPRISE FEED includes remote banner version checks to identify CVE-2026-63030 and CVE-2026-60137 for Linux [1][2] and Windows [3][4]. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way to gain the deepest insight into where software vulnerabilities exist in your organization’s IT infrastructure.

 

Contact Test Now Buy Here Back to Overview
22. July 2026/by Joseph Lee
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Joseph Lee https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Joseph Lee2026-07-22 12:53:462026-08-03 11:26:38wp2shell: Exploit Chaining for Unauthenticated RCE in WordPress
Greenbone AG

TLS and SSH Security: Greenbone Has Updated Compliance Policies for the BSI’s TR-03116-4 and TR-02102-4

Blog

Glowing green atom illustration with the label 'BSI-Ready TLS & SSH' on a dark green background

Technical guidelines published by government bodies define the highest security standards for protecting the national IT infrastructure. As the cyber security landscape becomes more perilous, it’s even more important for organizations to be diligent about implementing the strictest security standards. Government organizations need to ensure compliance, while private-sector entities can use the standards as benchmarks for their own cyber resilience.

Greenbone is happy to announce updated compliance scans aligned with the German Federal Office for Information Security’s (BSI) minimum standards for hardening TLS and SSH. The policies identify specific TLS and SSH configuration gaps within portions of the respective guidance.

In this article, we review the TR-03116-4 and TR-02102-4 guidelines to understand what’s new. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way for your organization to gain the deepest insight into building resilient IT networks and applications.

The Transport Layer Security (TLS) and Secure Shell (SSH) protocols are among the most fundamental used in today’s networks. Greenbone now offers updated policy scans to measure compliance with selected portions of the BSI’s guidance. The updated guidance standards are:

  • TR-03116-4 (July 2025): BSI Minimum Standard for the Use of Transport Layer Security (TLS)
  • TR-02102-4 (January 2026): BSI Minimum Standard for the Use of Secure Shell (SSH)

These updates add to Greenbone’s already impressive line of compliance policies for OPENVAS SCAN. Although TR-03116-4 and TR-02102-4 do not yet include post-quantum cryptography guidelines, standards for assessing PQC-compliant systems are under development. Greenbone has helped lead the way. Our OPENVAS ENTERPRISE FEED features PQC compliance scans for both TLS and SSH:

  • SSL/TLS: Post Quantum Cryptography (PQC) Policy Check
  • SSH: Post Quantum Cryptography (PQC) Policy Check

Comparison of Greenbone’s new BSI compliance checks for TLS and SSH

TLS
TR-03116-4
BSI TLS Minimum Standard · July 2025
  • ✓Supported and minimum allowed TLS versions
  • ✓TLS 1.2 / 1.3 cipher suites vs. policy allow lists
  • ✓At least one BSI-mandated cipher suite supported
SSH
TR-02102-4
BSI SSH Minimum Standard · January 2026
  • ✓Protocol version, key-exchange, encryption, MAC, host-key algorithms, rekey limit
  • ✓AuthenticationMethods / RequiredAuthentications and PubkeyAuthentication
Neither standard defines PQC compliance yet — both advise starting a hybrid classical + quantum-safe migration now. Greenbone offers separate SSL/TLS PQC and SSH PQC policy checks.

Understanding TR-03116-4 BSI Minimum Standards for the Use of TLS

Part 4 of the TR-03116 series of technical guidelines specifies requirements and recommendations for the use of TLS in federal government applications. TR-03116-4 builds on earlier releases in the series. The standard is generally valid until the end of 2030, although specific timelines for deprecating or implementing certain methods are included. Greenbone’s policy covers selected portions of TR-03116-4; using remote TLS handshakes, the compliance scan assesses selected Chapter 2 controls, including:

  • Supported and minimum allowed TLS versions
  • Configured TLS 1.2 and TLS 1.3 cipher suites against policy allow lists
  • Presence of at least one BSI-mandated cipher suite supported by the server

Other vulnerability tests in the OPENVAS ENTERPRISE FEED separately identify additional risks posed by the remaining guidance areas. Examples include known SAML authentication and XML-signature vulnerabilities, vulnerable S/MIME/CMS implementations in OpenSSL or mail products, and OpenPGP/PGP software detection and product vulnerabilities.

Understanding TR-02102-4 BSI Minimum Standards for the Use of SSH

Part 4 of the BSI’s TR-02102 guideline series specifies the recommended SSH protocol versions, cryptographic algorithms, and key lengths for use in federal government applications. Like TR-03116-4 described above, TR-02102-4 builds on earlier guidance in its series, specifically TR-02102-1.

The Greenbone’s new compliance scans verify selected values read from the SSH server configuration, including:

  • SSH protocol version, allowed key-exchanges, encryption algorithms, MAC, host-key algorithms, and rekey limit
  • Client authentication requirements through AuthenticationMethods or RequiredAuthentications, and PubkeyAuthentication

These authenticated configuration checks provide useful technical evidence, but do not test live authentication behavior or assess client application risks, side channel attacks, implementation flaws, or operational controls associated with all SSH use-cases.

Post Quantum Compliance with Greenbone

Neither TR-03116-4 nor TR-02102-4 define compliance standards for Post Quantum Cryptography (PQC). However, they advise that organizations should prepare now to migrate from classical asymmetric cryptography to quantum-safe cryptography, beginning with hybrid schemes that combine classical and quantum-safe algorithms. Organizations seeking to assess their PQC resilience today can use Greenbone’s existing PQC policy scans:

  • SSL/TLS: Post Quantum Cryptography (PQC) Policy Check
  • SSH: Post Quantum Cryptography (PQC) Policy Check

Get to Know Greenbone’s Full Suite of Compliance Scans

OPENVAS SCAN’s compliance policies consist of specially selected groups of vulnerability tests used to assess compliance. Whether your organization is required to meet BSI technical standards or you simply want deeper insight into building resilient IT networks and applications, OPENVAS SCAN provides compliance visibility to identify gaps and strengthen security.

Some of the compliance scans in Greenbone’s OPENVAS ENTERPRISE FEED:

  • CIS Benchmark for Microsoft SQL Server 2022
  • CIS Benchmark v5.0.0 for Microsoft Windows Server 2022
  • CIS Benchmark v2.0.0 for Microsoft Windows Server 2025
  • CIS Benchmark v1.10 for Kubernetes 1.28 Controller Node
  • CIS Benchmark v1.10 for Kubernetes 1.28 Worker Nodes
  • Compliance profiles for Huawei EulerOS, openEuler, and Huawei Cloud EulerOS
  • CIS Benchmark v3.0.0 (L1) for Microsoft Windows 11 Enterprise
  • CIS Benchmarks v3.0.0 (L1 – Windows) for Google Chrome
  • BSI and CIS Benchmarks for Microsoft Office
  • Policy check for SSH: Post Quantum Cryptography (PQC)
  • Policy check for SSL/TLS: Post Quantum Cryptography (PQC)

Need compliance visibility into your TLS and SSH configurations?

Whether your organization is required to meet BSI technical standards or you simply want deeper insight into building resilient IT networks and applications, OPENVAS SCAN provides the compliance visibility needed to identify gaps and strengthen security. Contact Greenbone’s sales team to discuss how compliance scanning can best fit your organization’s regulatory and security governance requirements.

➤ Contact Sales

Summary

Germany’s BSI sets the technical requirements for federal government IT infrastructure. Other national governments around the world publish their own security forecasts and guidelines. While private institutions are not typically required to implement these guidelines, they offer reliable insight for implementing resilient IT architecture.

The Transport Layer Security (TLS) and Secure Shell (SSH) are two of the most fundamental protocols used in today’s IT networks. Greenbone is happy to announce updated compliance scans for selected portions of the BSI’s minimum standards for hardening TLS and SSH according to TR-03116-4 and TR-02102-4. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way for your organization to gain the deepest insight into building resilient IT networks and applications.

 

Contact Test Now Buy Here Back to Overview
21. July 2026/by Greenbone AG
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Greenbone AG https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Greenbone AG2026-07-21 13:49:062026-07-21 13:49:06TLS and SSH Security: Greenbone Has Updated Compliance Policies for the BSI’s TR-03116-4 and TR-02102-4
Greenbone AG

Greenbone’s OPENVAS SCAN Now Supports the Nutanix AHV Hypervisor

Blog

Users appreciate when software can easily integrate into their existing IT environment. For vendors, this means supporting a cross-platform mix of operating systems and infrastructure. Greenbone is excited to expand our virtualization platform support, bringing Nutanix AHV into our family of supported hypervisors. This addition adds flexibility for deploying OPENVAS SCAN and extends Greenbone’s already diverse support for hypervisors that also includes Microsoft Hyper-V, Oracle VirtualBox, VMware vSphere (ESXi) and and Workstation Pro, Huawei FusionCompute, and Proxmox VE. Our wide range of hypervisor support ensures that defenders can run our solution in virtually any IT environment.

A free trial of Greenbone’s OPENVAS BASIC is available for Nutanix users and others to scan their IT infrastructure for vulnerabilities and stay ahead of cyber attacks. For a full breakdown of our product offerings, check out our solution comparison.

In the rest of this article, we will discuss how to integrate OPENVAS SCAN virtual appliances on the Nutanix AHV Type-1 hypervisor.

OPENVAS SCAN now on Nutanix AHV

The OPENVAS SCAN Virtual Appliance Now Supports the Nutanix AHV Type-1 Hypervisor

Greenbone is excited to add support for Nutanix AHV virtualization. AHV (short for Acropolis Hypervisor) is the native hypervisor of the Nutanix Cloud Infrastructure platform. As a Type-1 hypervisor, AHV runs directly on the host’s hardware. This puts virtualized appliances closer to the underlying hardware and delivers high performance, low latency operation. The overall impact is a faster and more reliable virtualization environment. By contrast, Type-2 hypervisors run on top of a standard desktop operating system, which is not optimized for efficiency and reliability.

Nutanix is built on top of the Linux kernel’s KVM hypervisor and QEMU hardware emulator. The same open-source virtualization stack that underpins much of the modern data center and public cloud. Unlike traditional hypervisors, AHV is included at no additional licensing cost with the Nutanix Cloud Infrastructure platform and is managed through Nutanix Prism.

Whether you are an existing Greenbone enterprise customer looking for new virtualization options, or already running Nutanix AHV and seeking support, Greenbone now has you covered.

How to Set up OPENVAS SCAN on Nutanix AHV

Customers can request a Nutanix-ready instance of the OPENVAS SCAN virtual appliance from a member of the Greenbone sales team. This specialized image is delivered in the QEMU Copy-On-Write (QCOW) format, optimized for Nutanix AHV. Once you receive the .qcow file, complete the following steps in Nutanix Prism to install and configure the OPENVAS SCAN virtual appliance:

  1. Log in to the Nutanix AHV web interface and open the settings menu in the upper right corner.
  2. Select Image Configuration and click Upload Image. Give the image a name, set Image Type to DISK, choose Upload a file, select the QCOW file of the appliance, and click Save.
  3. Switch to the VM view from the drop-down menu in the upper left corner and click Create VM.
  4. Enter a name for the virtual machine, then set the number of virtual CPUs and cores, the amount of memory, and select UEFI as the boot configuration. The appliance requires the EFI/UEFI boot mode.
  5. Click Add New Disk, select Clone from Image Service as the operation, choose SATA as the bus type, select the image you uploaded in step 1, and click Add.
  6. Under Network Adapters (NIC), click Add New NIC and add at least one network interface, then click Save. The import can take up to 10 minutes.
  7. Once imported, select the appliance from the Table tab, click Power on, and complete the OPENVAS SCAN setup process.

Note

When using the community edition of Nutanix AHV, the combination of UEFI and the default network interface can cause issues at startup. As a workaround, add an e1000 network interface via SSH on the Nutanix host:

$ acli vm.nic_create NAMEOFVIRTUALMACHINE model=e1000 network=NAMEOFNETWORK

Full step-by-step instructions, including screenshots, are available in the Greenbone documentation.

Which Hypervisors Does the OPENVAS SCAN Virtual Appliance Support?

Here is an overview of the supported hypervisors and resource requirements for the OPENVAS SCAN virtual appliance.

The OPENVAS SCAN virtual appliance requires the following resources:

  • 2 virtual CPUs
  • 12 GB RAM
  • 500 GB virtual hard disk (can be dynamically allocated)

Hypervisors officially supported by the OPENVAS SCAN virtual appliance, with Type-1 and Type-2 classification and the newly added Nutanix AHV

Appliance resources 2 virtual CPUs | 12 GB RAM | 500 GB virtual disk
Nutanix AHV New
v6.8 or higher

Type-1 hypervisor

Proxmox VE
v8.0 or higher

Type-1 hypervisor

VMware vSphere (ESXi)
v7.0 or higher

Type-1 hypervisor

Huawei FusionCompute
v8.0

Type-1 hypervisor

Microsoft Hyper-V
Server 2016+ (gen 2 VM, config v8.0+)

Type-1 hypervisor

Oracle VirtualBox
v7.0 or higher

Type-2 hypervisor

VMware Workstation Pro
v17.0 or higher

Type-2 hypervisor

Summary

Greenbone has added support for deploying our OPENVAS SCAN virtual appliance on the Nutanix AHV Type-1 hypervisor, giving adding to our industry leading flexibility. This new capability extends the virtualization options, ensuring users can confidently integrate OPENVAS SCAN into any IT environment — including the growing number of data centers built on Nutanix. A free trial of Greenbone’s OPENVAS BASIC is available for Nutanix users and others to scan their IT infrastructure for emerging threats and stay ahead of cyber attacks.

 

Contact Test Now Buy Here Back to Overview
20. July 2026/by Greenbone AG
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Greenbone AG https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Greenbone AG2026-07-20 14:29:332026-07-20 14:29:33Greenbone’s OPENVAS SCAN Now Supports the Nutanix AHV Hypervisor
Joseph Lee

CTX696604: Multiple New Flaws Affecting Citrix NetScaler ADC and NetScaler Gateway

Blog

Citrix security advisory CTX696604 covers six vulnerabilities in customer-managed NetScaler ADC and NetScaler Gateway. NetScaler Gateway is used to authenticate remote users and connect them to internal network resources, and NetScaler ADC load balancing is a core feature used to distribute requests and improve availability. The highest-risk issues in the bulletin can lead to memory overread, denial of service (DoS), and arbitrary file read. However, specific configurations must be present for the flaws to be exploitable.

The bulletin applies only to customer-managed NetScaler ADC and NetScaler Gateway. Citrix cloud services have already been upgraded by Citrix. In some cases, exploitation requires specific deployments or enabled features, such as SAML IDP, Gateway services, AAA virtual server exposure, Oracle or DNS roles, management access on NSIP or SNIP, and protocol options attached to virtual servers or services.

There is no evidence of active exploitation for the CVEs included in the CTX696604 advisory, and no public proof-of-concept (PoC) exploits have been released. However the same affected products were actively exploited in March, 2026. In total, Citrix Netscaler has been added to CISA’s KEV list 22 times since late 2021, shockingly 7 times associated with ransomware attacks. Multiple national CERT alerts have been issued for the new CVEs, indicating a high level of global risk [1][2][3][4][5][6][7][8][9][10][11][12][13].

CTX696604 advisory: multiple new vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway

The OPENVAS ENTERPRISE FEED includes a remote banner check that identifies vulnerable NetScaler ADC and NetScaler Gateway installations affected by the CVEs in Citrix advisory CTX696604. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way to gain the deepest insight into where software vulnerabilities exist in your organization’s IT infrastructure.

Vulnerability Details for Citrix Bulletin CTX696604

The six CVEs in the bulletin can cause memory overread, DoS, and arbitrary file read. In each case, the vendor ties exploitability to a specific configuration, which narrows exposure but does not eliminate the need for patching. The most operationally sensitive issues are those that are unauthenticated and network-reachable.

The six CVEs disclosed in Citrix advisory CTX696604, each shown with its CVSS severity band and EPSS exploitation-probability score

CVE-2026-8452 CVSS 9.8 · Critical EPSS 0.5% (39th)

An unauthenticated, remotely exploitable memory overread [CWE-119] flaw that can result in unexpected behavior or denial-of-service. The flaw affects devices using SSL VPN, ICA Proxy, CVPN, RDP Proxy, or an AAA virtual server.

CVE-2026-8655 CVSS 9.8 · Critical EPSS 0.5% (40th)

An unauthenticated, remotely exploitable memory overread [CWE-119] flaw affecting NetScaler ADC only when configured as an Oracle or DNS proxy load balancer, or as a recursive DNS resolver, leading to unexpected behavior or denial-of-service.

CVE-2026-8451 CVSS 7.5 · High EPSS 15.7% (97th)

An unauthenticated, remotely exploitable out-of-bounds read [CWE-125] that can disclose sensitive information. The flaw only affects NetScaler ADC or NetScaler Gateway when configured as a SAML identity provider.

CVE-2026-10816 CVSS 7.5 · High EPSS 0.4% (34th)

An unauthenticated, remotely exploitable external control of file name or path [CWE-73] flaw enabling arbitrary file read. Requires access to the NetScaler IP, Cluster Management IP, or subnet IP address with management access enabled.

CVE-2026-10817 CVSS 7.5 · High EPSS 0.4% (34th)

An unauthenticated, remotely exploitable out-of-bounds read [CWE-125] that can result in arbitrary file read and potential disclosure of sensitive information. Only affects configurations where TCP Timestamp is enabled in a TCP profile attached to a virtual server or service.

CVE-2026-13474 CVSS 7.5 · High EPSS 0.5% (38th)

An unauthenticated, remotely exploitable denial-of-service [CWE-401] triggered by malformed HTTP/2 requests. Only affects configurations where HTTP/2 is enabled in an HTTP profile attached to an affected virtual server or service.

CVE-2026-8452 and CVE-2026-8655 are both potentially high-impact, remotely exploitable flaws that do not require authentication. They both affect service endpoints that are typically unrestricted. CVE-2026-8451 can result in the disclosure of sensitive information that could be leveraged in subsequent attacks. While CVE-2026-10816 is also remotely exploitable without authentication, management access to the affected device must be enabled.

Start Your Free Trial

The OPENVAS ENTERPRISE FEED includes a remote banner check to identify vulnerable NetScaler ADC and NetScaler Gateway installations affected by the CVEs discussed in Citrix advisory CTX696604. Grab a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED to gain the deepest insight into where software vulnerabilities exist in your organization’s IT infrastructure.

Affected Products and Versions

The advisory affects multiple customer-managed NetScaler product lines, including standard releases and FIPS or NDcPP builds. According to the vendor, Secure Private Access Hybrid deployments using NetScaler instances are also affected. The impact is configuration-dependent, so defenders should validate both version status and whether the listed services or profiles are enabled.

Product Affected versions Fixed version

NetScaler ADC and NetScaler Gateway

14.1 before 14.1-72.61; 13.1 before 13.1-63.18

14.1-72.61; 13.1-63.18

NetScaler ADC FIPS

before 14.1-72.61 FIPS

14.1-72.61 FIPS

NetScaler ADC FIPS and NDcPP

before 13.1-37.272

13.1-37.272

Mitigating Citrix NetScaler CVEs from Bulletin CTX696604

The fixed releases listed by the vendor in the table above provide the most effective remediation path. Organizations running affected devices should move to the corresponding fixed version for their release train. No workarounds are described in the vendor bulletin.

For CVE-2026-13474, the Cyber Security Agency of Singapore recommends setting the Http2SmallWndTimeout parameter to 30 seconds as an added mitigation. That guidance is specific to the HTTP/2-related issue and does not replace the vendor fix.

Defenders should check whether the affected features are enabled, because the vulnerable conditions depend on deployment state. Security teams should validate SAML IDP configurations; Gateway and AAA virtual servers; Oracle and DNS roles; management access exposure on NSIP or SNIP; TCP Timestamp settings in profiles; and HTTP/2 settings in HTTP profiles. Where those functions are not required, disabling them reduces exposure while patching is scheduled.

Summary

The Citrix CTX696604 advisory describes six NetScaler ADC and NetScaler Gateway vulnerabilities that affect customer-managed deployments and certain Secure Private Access Hybrid instances. The highest-risk CVEs are configuration-dependent. However, these include unauthenticated network-reachable impacts such as unexpected behavior, sensitive information disclosure, DoS, and arbitrary file read conditions. Available evidence does not indicate active exploitation or that a public PoC exists. However, multiple national CERT alerts have been issued for the CVEs [1][2][3][4][5][6][7][8][9][10][11][12][13].

Organizations should scan their infrastructure for affected appliances, confirm whether the vulnerable features are enabled, and apply the fixed releases for their product line without delay. The OPENVAS ENTERPRISE FEED includes a remote banner check to identify vulnerable NetScaler ADC and NetScaler Gateway installations affected by the CVEs discussed in Citrix advisory CTX696604. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way to gain the deepest insight into where software vulnerabilities exist in your organization’s IT infrastructure.

 

Contact Test Now Buy Here Back to Overview
16. July 2026/by Joseph Lee
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Joseph Lee https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Joseph Lee2026-07-16 15:43:262026-08-03 11:44:56CTX696604: Multiple New Flaws Affecting Citrix NetScaler ADC and NetScaler Gateway
Joseph Lee

BeyondTrust BT26-03: Critical and High-Severity Flaws in Remote Support and Privileged Remote Access

Blog

BeyondTrust advisory BT26-03, issued on July 6th, 2026, describes multiple new vulnerabilities in BeyondTrust Remote Support (RS) and BeyondTrust Privileged Remote Access (PRA). The vulnerabilities include two critical flaws exploitable without authentication and additional high-severity issues in network communication and web application components. All the flaws require specific configurations for exploitation, but BeyondTrust has not disclosed the configuration details.

According to BeyondTrust, the issues were found through internal AI-driven vulnerability research using publicly available AI models, and they were fixed before exploitation. The vendor also claims that the flaws were not exploited or known outside the company prior to remediation.

BeyondTrust BT26-03-Security-Bulletin: critical and high severity flaws in Remote Support and Privileged Remote Access

There is no evidence that any of the CVEs have been exploited in the wild, and no public proof-of-concept (PoC) exploits have been published. CISA has added three vulnerabilities affecting BeyondTrust RS and PRA to its KEV Catalog since late 2024, indicating that the products are popular targets for attackers. CVE-2026-1731 was added in early 2026 and is associated with ransomware attacks. Numerous national CERT agencies have issued alerts [1][2][3][4][5][6][7][8][9], indicating high global risk.

BeyondTrust BT26-03 advisory: critical and high-severity vulnerabilities in Remote Support and Privileged Remote Access

OPENVAS ENTERPRISE FEED includes a remote banner version check covering CVE-2026-40138, CVE-2026-40140, and CVE-2026-40141 in BeyondTrust PRA, and a separate remote banner version check for CVE-2026-40138, CVE-2026-40139, CVE-2026-40140, and CVE-2026-40141 in BeyondTrust RS. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way to gain the deepest insight into where software vulnerabilities exist in your organization’s IT infrastructure.

Vulnerabilities Disclosed in the BeyondTrust BT26-03 Advisory

The BeyondTrust BT26-03 advisory covers two critical and two high-severity CVEs across two products: BeyondTrust RS and PRA. There is no evidence of exploitation in the wild, and no publicly available PoC exploits exist for any of the CVEs disclosed in BT26-03. All of the flaws have been assigned moderate EPSS scores: 36th – 48th percentiles.

The four CVEs disclosed in BeyondTrust BT26-03, each shown with its CVSS severity band and EPSS exploitation-probability score

CVE-2026-40141 CVSS 9.9 · Critical EPSS 0.5% (40th)

An improper neutralization of special elements in data-query logic [CWE-943] flaw in a web application component of BeyondTrust RS and PRA. An authenticated attacker with specific permissions could access or manipulate resources and data outside the intended authorization boundary.

CVE-2026-40139 CVSS 9.8 · Critical EPSS 0.7% (48th)

An improper authentication [CWE-287] flaw in BeyondTrust RS. A remote, unauthenticated attacker could bypass access controls when a specific authentication configuration is enabled, which BeyondTrust does not publicly identify.

CVE-2026-40138 CVSS 8.1 · High EPSS 0.4% (36th)

An improper authentication [CWE-287] flaw in BeyondTrust RS and PRA. A remote, unauthenticated attacker could bypass access controls and reach elevated accounts when a specific authentication configuration is enabled, which BeyondTrust does not publicly identify.

CVE-2026-40140 CVSS 7.5 · High EPSS 0.6% (44th)

An uncontrolled resource consumption [CWE-400] flaw in the network communication subsystem of BeyondTrust RS and PRA. A remote, unauthenticated attacker could trigger a denial-of-service and disrupt appliance availability.

Affected Products and Versions

BeyondTrust states that all cloud-hosted RS and PRA instances were patched as of April 21st, 2026. For self-hosted deployments, the vendor directs customers to apply the April security rollup patch or upgrade to the fixed product versions. The supplied evidence identifies RS 25.3.2 and earlier and PRA 25.3.2 and earlier as affected. BeyondTrust provides no workarounds for the vulnerabilities.

Product CVEs Affected versions Fixed versions

BeyondTrust Remote Support

CVE-2026-40138, CVE-2026-40139, CVE-2026-40140, CVE-2026-40141

RS 25.3.2 or earlier

RS 25.3.3 or later; Security Rollup April 2026 25 RS or Security Rollup April 2026 24 RS, depending on the RS version

BeyondTrust Privileged Remote Access

CVE-2026-40138, CVE-2026-40140, CVE-2026-40141

PRA 25.3.2 or earlier

PRA 25.3.3 or later; Security Rollup April 2026 25 PRA or Security Rollup April 2026 24 PRA, depending on the PRA version

BeyondTrust Remote Support (RS) is an enterprise-grade remote support tool used by IT service desks, help desks, and support teams to connect to and control remote systems and devices. In operational terms, that means the product often sits on a path used for remote troubleshooting, administrative support, and endpoint interaction.

BeyondTrust Privileged Remote Access (PRA) is used to manage remote access to critical systems for privileged users and third-party vendors. The product includes session monitoring, auditing, recording, and least-privilege controls. BeyondTrust also describes the B Series Appliance as the central communication point for secure remote access, handling session brokering, authentication, logging, auditing, and encryption.

Start Your Free Trial

The OPENVAS ENTERPRISE FEED includes remote banner version checks for CVE-2026-40138, CVE-2026-40139, CVE-2026-40140, and CVE-2026-40141 across BeyondTrust RS [1] and PRA [2]. Grab a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED to gain the deepest insight into where software vulnerabilities exist in your organization’s IT infrastructure.

Summary

BT26-03 consolidates four confirmed vulnerabilities across BeyondTrust Remote Support and BeyondTrust Privileged Remote Access. The most important issues are the two critical pre-authentication flaws, followed by the high-severity vulnerabilities in the network communication and web application components. Although none of the CVEs are known to have been exploited in the wild and no public PoC exploit exists, CISA has added three vulnerabilities affecting BeyondTrust RS and PRA to its KEV Catalog since late 2024. CVE-2026-1731 was added in early 2026 and is associated with ransomware attacks. Numerous national CERT agencies have issued alerts, indicating high global risk. Greenbone’s OPENVAS ENTERPRISE FEED provides remote banner version checks for the BT26-03 CVEs, helping defenders identify affected BeyondTrust RS and PRA appliances and prioritize remediation.

 

Contact Test Now Buy Here Back to Overview
15. July 2026/by Joseph Lee
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Joseph Lee https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Joseph Lee2026-07-15 10:59:032026-08-03 11:54:47BeyondTrust BT26-03: Critical and High-Severity Flaws in Remote Support and Privileged Remote Access
Joseph Lee

CVE-2026-48282: CVSS 10 Flaw in Adobe ColdFusion Is Actively Exploited and More

Blog

CVE-2026-48282 (CVSS 10) is a critical path traversal vulnerability [CWE-22] in Adobe ColdFusion. According to Adobe’s Security Bulletin [APSB26-68], the issue affects ColdFusion 2025 Update 9 and earlier, and ColdFusion 2023 Update 20 and earlier. Exploitation is network-based, which increases the risk to exposed ColdFusion instances, and exploitation does not require authentication. A successful attack allows arbitrary remote code execution (RCE) in the context of the current user.

KEVIntel captured honeypot attacks targeting CVE-2026-48282, indicating that active exploitation may be underway, and CISA has added the flaw to their Known Actively Exploited (KEV) list. Watchtowr Labs has published a public Proof-of-Concept (PoC) exploit with full technical root-cause analysis. Multiple national CERT alerts have been issued for CVE-2026-48282, indicating high concern globally [1][2][3][4][5][6][7][8].

CVE-2026-48282-adobe-coldfusion-exploited

In total, 11 CVEs were disclosed in Adobe’s APSB26-68 advisory, and six of those were assigned the highest possible CVSS severity rating. The OPENVAS ENTERPRISE FEED includes a remote_banner check for CVE-2026-48282 and all other CVEs disclosed in Adobe’s APSB26-68 advisory affecting Adobe ColdFusion. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way to gain the deepest insight into where software vulnerabilities exist in your organization’s IT infrastructure.

A Risk Assessment of CVE-2026-48282 in Adobe ColdFusion

CVSS 10 · CriticalActively exploitedIn CISA KEVPublic PoC

Adobe has assigned CVE-2026-48282 the highest CVSS severity rating. The primary defensive concern is that a path traversal [CWE-22] issue in a web-facing application server can allow an attacker to move outside intended directory boundaries and reach sensitive resources. Adobe reports that CVE-2026-48282 can lead to arbitrary RCE in the context of the current user. Because exploitation does not require privileges or user interaction, externally reachable instances carry the highest exposure.

Adobe ColdFusion is an enterprise application server used to build, deploy, and scale data-driven web applications, APIs, intranet portals, administrative systems, and cloud-connected business applications. The exploitation reporting should be treated as operationally significant even without additional technical detail.

Mitigating CVE-2026-48282 in Adobe ColdFusion

CVE-2026-48282 is remediated by updating to ColdFusion 2025 Update 10 or ColdFusion 2023 Update 21. Adobe does not provide any alternative workarounds or compensating controls. Where instances are externally reachable, remediation should be prioritized. The OPENVAS ENTERPRISE FEED includes a remote_banner check to identify Adobe ColdFusion instances affected by CVE-2026-48282.

Start Your Free Trial

The OPENVAS ENTERPRISE FEED includes a remote_banner check for CVE-2026-48282 and every other CVE in Adobe’s APSB26-68 advisory. Grab a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED to gain the deepest insight into where software vulnerabilities exist in your organization’s IT infrastructure.

Other CVEs From Adobe’s APSB26-68 Advisory

Adobe’s Security Bulletin [APSB26-68] covered a total of 11 CVEs. Six of these were assigned the highest CVSS criticality score. There are no reports of active exploitation for the CVEs described below, and no detailed technical analysis or PoC are available. All CVEs in the security bulletin affect the same product scope. Therefore, the mitigation described above covers all the vulnerabilities.

The ten additional CVEs disclosed in Adobe APSB26-68, each shown with its CVSS severity band and EPSS exploitation-probability score

CVE-2026-48276 CVSS 10 · Critical EPSS 0.9% (56th)

An Unrestricted Upload of File with Dangerous Type vulnerability [CWE-434] allows arbitrary RCE in the context of the current user.

CVE-2026-48277 CVSS 10 · Critical EPSS 0.9% (54th)

An Improper Input Validation vulnerability [CWE-20] allows arbitrary RCE in the context of the current user.

CVE-2026-48281 CVSS 10 · Critical EPSS 0.9% (54th)

An Improper Input Validation vulnerability [CWE-20] allows arbitrary RCE in the context of the current user.

CVE-2026-48316 CVSS 10 · Critical EPSS 1.4% (69th)

An Improper Input Validation vulnerability [CWE-20] allows arbitrary RCE in the context of the current user.

CVE-2026-48283 CVSS 10 · Critical EPSS 0.6% (46th)

An Unrestricted Upload of File with Dangerous Type vulnerability [CWE-434] allows arbitrary RCE in the context of the current user.

CVE-2026-48313 CVSS 9.3 · Critical EPSS 1.6% (73rd)

A Path Traversal vulnerability [CWE-22] allows arbitrary file system read and limited write access. An attacker could access sensitive files and directories outside the intended access scope.

CVE-2026-48315 CVSS 9.3 · Critical EPSS 0.5% (42nd)

An Improper Input Validation vulnerability [CWE-20] allows arbitrary RCE in the context of the current user. An attacker can inject malicious scripts into a web page, potentially gaining elevated access or control over the victim’s account or session. Exploitation requires the target to open a malicious file.

CVE-2026-48307 CVSS 8.8 · High EPSS 0.3% (23rd)

A reflected Cross-Site Scripting (XSS) vulnerability [CWE-79] allows an attacker to inject malicious scripts into a web page, potentially resulting in arbitrary code execution on the system of victims who open a malicious link.

CVE-2026-48285 CVSS 8.6 · High EPSS 0.4% (35th)

A Server-Side Request Forgery (SSRF) vulnerability [CWE-918] allows an attacker to bypass security measures and gain unauthorized read access.

CVE-2026-48314 CVSS 6.5 · Medium EPSS 0.3% (25th)

A Path Traversal vulnerability [CWE-22] allows an attacker to gain limited read and write access to unauthorized files or directories outside the intended restrictions.

Summary

Adobe’s Security Bulletin [APSB26-68] covered a total of 11 CVEs. Six of these were assigned the highest CVSS criticality score. In-the-wild exploitation has been reported for CVE-2026-48282, which potentially allows arbitrary RCE in the current user context. The affected scope is ColdFusion 2025 Update 9 and earlier, and ColdFusion 2023 Update 20 and earlier. Adobe’s fixed versions are ColdFusion 2025 Update 10 and ColdFusion 2023 Update 21.

The OPENVAS ENTERPRISE FEED includes a remote_banner check for CVE-2026-48282 and all other CVEs disclosed in Adobe’s APSB26-68 advisory affecting Adobe ColdFusion. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way to gain the deepest insight into where software vulnerabilities exist in your organization’s IT infrastructure.

 

Contact Test Now Buy Here Back to Overview
13. July 2026/by Joseph Lee
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Joseph Lee https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Joseph Lee2026-07-13 14:55:492026-07-14 13:16:45CVE-2026-48282: CVSS 10 Flaw in Adobe ColdFusion Is Actively Exploited and More
Joseph Lee

June 2026 Threat Report: Technical Debt Demands Visibility

Blog

June 2026 Threat Report: technical debt demands visibility

The true impact that cyber security aware AI will have on the global threat landscape remains to be seen. By some reports, the CVE output for software made by major vendors is on the rise. This June 2026 threat report only scratches the surface of the major cyber security threats from this month. The month brought a concentrated wave of actively exploited enterprise vulnerabilities, with CISA logging multiple new additions to its Known Exploited Vulnerabilities (KEV) catalog throughout the month. At least one new critical perimeter network exploit was tied to an active ransomware affiliate.

Greenbone’s vulnerability coverage extends far beyond major, headline-grabbing IT security events, such as the ones in this monthly threat report, and keeps pace with the onslaught of AI driven disclosures. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way to gain the deepest insight into where software vulnerabilities exist in your organization’s IT infrastructure.

Here are some of the top emerging threats to enterprise IT security from June 2026.

CVE-2026-20253: Unauthenticated RCE in Splunk Enterprise Actively Exploited

CVSS 9.8 · CriticalActively exploitedIn CISA KEVPublic PoC

CVE-2026-20253 (CVSS 9.8, EPSS ≥ 95th pctl) allows an unauthenticated remote attacker to create or truncate arbitrary files in Splunk Enterprise 10.2 before 10.2.4 and 10.0 before 10.0.7. The flaw is due to missing authentication [CWE-306] on a PostgreSQL sidecar service endpoint. Splunk confirmed limited in-the-wild exploitation, and CISA has added the flaw to KEV. A full technical description with PoC exploit code has been published by WatchTowr demonstrating unauthenticated RCE. Shadowserver tracked more than 1,400 internet-exposed Splunk instances.

CVE-2026-20253 is patched in Splunk Enterprise 10.2.4 and 10.0.7, and customers should upgrade immediately. If patching is not possible, exploitation can be prevented by disabling the PostgreSQL sidecar service. However, disabling the service may disrupt Edge Processor, OpAmp, or SPL2 data pipelines. The OPENVAS ENTERPRISE FEED includes a remote analysis check and a separate remote banner check to identify affected instances.

CVE-2026-28318: SolarWinds Serv-U Exploited in DoS Attacks

CVSS 7.5 · HighActively exploitedIn CISA KEVPublic PoC

CVE-2026-28318 (CVSS 7.5, EPSS ≥ 60th pctl) allows an unauthenticated remote attacker to cause a denial of service (DoS) in SolarWinds Serv-U Managed File Transfer and FTP Server. CISA added the flaw to its KEV catalog; however, no campaign attribution has been made. A technical description has been published. Exploitation is achieved by simply including the Content-Encoding: deflate request header and can crash the Serv-U service. The flaw is caused by uncontrolled resource consumption [CWE-400] in crafted HTTP POST request handling.

There is significant risk of operational disruption to exposed file transfer servers used in regulated sectors such as healthcare, finance, and government. Exposed Serv-U instances were originally reported to be more than 12,000 by Shodan and roughly 3,000 by Shadowserver. However, Shodan detection had since fallen to less than 10,000 by the end of June.

SolarWinds advises customers to install Serv-U 15.5.4 Hotfix 1 immediately. If patching cannot be done right away, users can block POST requests containing the Content-Encoding: deflate header without losing any functionality. The OPENVAS ENTERPRISE FEED includes a remote banner check to detect vulnerable instances.

Living on the Edge: Emerging Threats to Perimeter Security

Vulnerabilities in network perimeter devices are particularly high risk because they are exposed to attack by arbitrary remote attackers. According to the latest Verizon DBIR 2026 report, exploiting publicly exposed software vulnerabilities is now the most common vector for initial access globally. Here are some of the most critical emerging threats to perimeter devices in June 2026.

CVE-2026-50751: Check Point Security Gateway Exploited in Ransomware Attacks

CVSS 9.3 · CriticalActively exploitedIn CISA KEVPublic PoCRansomware-linked

CVE-2026-50751 (CVSS 9.3, EPSS ≥ 98th pctl) and CVE-2026-50752 (CVSS 7.4, EPSS ≥ 90th pctl) affect Check Point VPN Remote Access, Mobile Access, Security Gateways, and Spark Firewalls. CVE-2026-50751 is being actively exploited with at least one post-compromise case linked to a Qilin ransomware affiliate. CISA has added CVE-2026-50751 to its KEV catalog. The first attacks were observed on May 7, 2026. A few dozen organizations have been targeted globally. PoC exploit code and a full technical description are publicly available for CVE-2026-50751. CVE-2026-50752 is not reported as actively exploited.

The CVEs are described below:

  • CVE-2026-50751 (CVSS 9.3, EPSS ≥ 98th pctl): Unauthenticated remote attackers can establish VPN access through a logic-flow and certificate-validation weakness in IKEv1 deployments.
  • CVE-2026-50752 (CVSS 7.4, EPSS ≥ 90th pctl): Could allow unauthenticated attackers to conduct adversary-in-the-middle attacks against VPN site-to-site connections.

Check Point has published recommendations for removing support for legacy protocols, upgrading affected instances to fixed versions, and provides additional security hardening advice [1][2]. The OPENVAS ENTERPRISE FEED includes remote banner detection for Gaia, Check Point’s unified security OS for Security Gateways, Security Management products, Software Blades, Check Point appliances, and Open Servers. Check Point Gaia version R80.20, R80.40, R81, R81.10, R81.20, R82, and R82.10 are affected.

Three CVSS 10 Flaws in Ubiquiti UniFi OS Allow Unauthenticated RCE

CVSS 10 · CriticalExploited as zero-dayIn CISA KEV

Three new CVSS 10 flaws affecting UniFi OS systems have been published and added to CISA’s KEV list. The flaws collectively allow attackers to modify underlying operating-system files and accounts, and execute commands. User reports indicate the flaws were likely exploited as zero-days to create rogue administrator accounts. Risk is elevated because UniFi OS devices centrally manage network infrastructure, making successful compromise a potential path for lateral movement into enterprise environments.

The CVEs are described below:

  • CVE-2026-34908 (CVSS 10): An attacker with network access can exploit an improper access control vulnerability [CWE-284] in UniFi OS devices to make unauthorized changes to the system.
  • CVE-2026-34909 (CVSS 10): An attacker with network access can exploit a path traversal vulnerability [CWE-22] in UniFi OS devices to access and manipulate files on the underlying system and access underlying accounts.
  • CVE-2026-34910 (CVSS 10): An attacker with network access can exploit an improper input validation vulnerability [CWE-20] in UniFi OS devices to execute command injection attacks.

Bishop Fox published a full technical analysis showing that CVE-2026-34908 and CVE-2026-34909 form an authentication gateway bypass caused by crafted NGINX request handling. Exploitation exposes internal routes and enables command injection via CVE-2026-34910.

Exploitation of all aforementioned CVEs has been validated against UniFi OS version 5.0.6. Ubiquiti fixed the vulnerabilities in UniFi OS Server version 5.0.8, released on May 21, 2026. No workarounds are available. The OPENVAS ENTERPRISE FEED includes a remote vulnerability check and remote banner check for Ubiquiti UniFi OS on various devices and an additional remote vulnerability check and remote banner check for Ubiquiti UniFi OS Server version 5.0.6 and prior.

Squidbleed (CVE-2026-47729) Memory Leak Has Public PoC

CVSS 6.5 · MediumPublic PoCNo ITW exploitation

CVE-2026-47729 (CVSS 6.5), also known as Squidbleed, allows an authorized Squid proxy user to leak another user’s cleartext HTTP request data. The flaw is caused by a heap over-read in the FTP directory-listing parser. Leaked data may include credentials, session tokens, API keys, and Authorization headers. Public proof-of-concept exploit code and a full technical description are available. However, in-the-wild exploitation has not been reported. Surprisingly, despite having a GitHub Security Advisory referencing the CVE by ID, CVE-2026-47729 has not been published to MITRE’s CVE.org or NIST NVD as of July 1st, 2026.

The flaw affects shared proxy environments where Squid can inspect cleartext HTTP or terminate TLS altogether, and all Squid versions dating back to a 1997 FTP parser change. Exploitation requires the Squid instance to be able to reach an attacker-controlled FTP server on TCP port 21. The flaw is fixed in the Squid 7.6 June 2026 release but can also be mitigated by disabling FTP support if not required. The OPENVAS ENTERPRISE FEED includes package-level detection for Linux distributions that have issued security advisories and a remote banner detection for affected versions of Squid proxy.

CVE-2026-10520 and CVE-2026-10523 in Ivanti Sentry

CVSS 10 · CriticalActively exploitedIn CISA KEVPublic PoC

CVE-2026-10520 (CVSS 10) and CVE-2026-10523 (CVSS 9.8) allow a remote, unauthenticated attacker to achieve root-level RCE and create arbitrary administrative accounts in Ivanti Sentry. CVE-2026-10520 has been added to CISA’s KEV catalog after reported exploitation attempts against honeypots. watchTowr published a full technical analysis including a public PoC exploit. Shadowserver reported large-scale exploitation of CVE-2026-10520, identifying 19 vulnerable instances in its scans with at least two identified as compromised.

  • CVE-2026-10520 (CVSS 10): An OS command injection vulnerability [CWE-78] allows a remote, unauthenticated user to achieve root-level remote code execution.
  • CVE-2026-10523 (CVSS 9.8): An authentication bypass vulnerability [CWE-288] allows a remote, unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access.

Exploitation requires access to the management port 8443. Affected versions include Ivanti Sentry 10.5.1, 10.6.1, 10.7.0, and prior versions, with fixes available in 10.5.2, 10.6.2, and 10.7.1. Greenbone’s OPENVAS ENTERPRISE FEED includes an active check and a remote banner check that cover both CVEs.

The HTTP/2 Bomb: DoS against All Major Web Servers

CVSS 7.5 · HighPublic PoCMulti-vendor DoS

HTTP/2 Bomb is a remote, unauthenticated denial-of-service (DoS) technique against HTTP/2 server implementations. The flaw affects the default HTTP/2 configurations in Apache HTTP Server, NGINX, Microsoft IIS, Envoy Proxy, and Cloudflare Pingora, among other digital products that package them. A detailed technical write-up is available, and Calif’s HTTP/2 Bomb companion repository lists self-contained per-server PoCs and Docker labs for major affected web servers, increasing the risk. HTTP/3 is not reported as directly vulnerable to the current HTTP/2 Bomb technique.

The exploit uses legitimate HTTP/2 features in a way the HPACK header compression spec did not constrain. Affected web servers failed to enforce the extra limits needed to make those features safe. Exploitation has a reported memory amplification of between 70:1 and 5.7K:1 and allows consuming 32 GB to 64 GB of server memory within seconds. The root cause is flawed HTTP/2 request handling, where HPACK-driven cookie expansion triggers excessive memory allocation and data amplification. Calif.io also states that the deeper root cause is a protocol specification issue. The major products related to HTTP/2 Bomb are described below:

  • CVE-2026-49975 (CVSS 7.5) — Apache HTTP Server mod_http2: Apache HTTP Server versions 2.4.17 through 2.4.67 are affected and the issue is fixed in Apache HTTP Server version 2.4.68.
  • CVE-2026-47774 (CVSS 7.5) — Envoy Proxy: Envoy versions before 1.35.11, 1.36.7, 1.37.3, and 1.38.1 are affected.
  • CVE-2026-49160 (CVSS 7.5) — Microsoft HTTP.sys / IIS: Affects Microsoft HTTP.sys, the Windows HTTP stack used by IIS and other Windows HTTP services. Microsoft addressed the issue in its June 9th, 2026 security updates.
  • No CVE assigned — nginx: All nginx versions before 1.29.8 are affected and the issue is fixed in nginx 1.29.8. Red Hat states that upstream nginx did not assign a CVE for HTTP/2 Bomb.

Quang Luong of Calif.IO attributes the discovery of HTTP/2 Bomb to OpenAI Codex. Many additional CVEs are expected to emerge as hardware and software vendors patch their products. Greenbone includes numerous vulnerability tests to detect HTTP/2 Bomb across a wide range of Linux distributions and other affected products. This includes detection for affected Apache HTTP Server products (CVE-2026-49975), Envoy Proxy (CVE-2026-47774), Microsoft IIS (CVE-2026-49160), and nginx despite the lack of CVE coverage.

Multiple Critical Flaws in SAP SE and SAP NetWeaver AS ABAP, and ABAP Platform

CVSS 9.9 · CriticalNo known exploitationPatch available

Three new critical flaws affecting SAP products have been published. Collectively, the flaws impact NetWeaver AS ABAP and ABAP Platform, SAP NetWeaver Application Server Java Web Container, SAP Commerce Cloud, and SAP Data Hub. Risk is elevated because the flaws can allow unauthorized access, sensitive data exposure, file modification, application crashes, memory corruption, arbitrary code execution, and connection hijacking without user interaction in several cases. No active exploitation has been observed in the wild. Public PoC exploits or a full public exploit chain are not available. Mitigate by applying SAP’s June 2026 Security Patch Day updates immediately.

Details on the three CVEs are included below:

  • CVE-2026-44748 (CVSS 9.9): An authenticated attacker with normal privileges can obtain a valid signed message and send modified signed XML documents to the verifier. This can result in acceptance of tampered identity information, leading to unauthorized access to sensitive user data and disruption of normal system usage. SAP NetWeaver AS ABAP version 7.02, 7.31, 7.40, 7.50, 7.51, 7.52, 7.53, 7.54, 7.55, 7.56, 7.57, 7.58, 8.16, 9.18, and 9.19 are affected. The OPENVAS ENTERPRISE FEED includes a remote banner check to identify affected instances.
  • CVE-2026-27671 (CVSS 9.8): Due to improper RFC protocol validation in the SAP Kernel, an unauthenticated attacker can send a crafted RFC request that exploits logical errors in memory management, leading to memory corruption. SAP NetWeaver AS ABAP version 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 9.16, 9.18, and 9.19 are affected. The OPENVAS ENTERPRISE FEED includes a remote banner check to identify affected instances.
  • CVE-2026-40128 (CVSS 9.0): An unauthenticated attacker can craft a malicious HTTP logon request that manipulates file inclusion parameters. Exploitation enables path traversal and processing of the included file and allows the attacker to view or modify sensitive information or render any part of the local system unavailable. SAP NetWeaver AS Java version 7.50 is affected. The OPENVAS ENTERPRISE FEED includes a remote banner check to identify affected instances.

Summary

June 2026 underscored accelerating enterprise risk from actively exploited flaws in Splunk, SolarWinds Serv-U, Check Point gateways, Ubiquiti UniFi OS, Ivanti Sentry, Squid, HTTP/2 implementations, and SAP platforms. Public PoCs, KEV listings, ransomware links, and exposed internet-facing assets reinforce the need for rapid patching, compensating controls, and continuous vulnerability detection across perimeter and core infrastructure.

Greenbone’s OPENVAS BASIC is available free of charge and includes a two-week trial of the OPENVAS ENTERPRISE FEED — giving your security team immediate access to automated vulnerability detection for the CVEs covered in this report and tens of thousands more. Start your free trial today.

 

Contact Test Now Buy Here Back to Overview
9. July 2026/by Joseph Lee
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Joseph Lee https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Joseph Lee2026-07-09 15:05:342026-07-09 15:24:53June 2026 Threat Report: Technical Debt Demands Visibility
Greenbone AG

Sovereignty was a promise. Now it’s becoming a test criterion.

Blog

EU as a symbol of digital sovereignty – Greenbone explains the CADA sovereignty levels

On June 3, 2026, the European Commission proposed the Cloud and AI Development Act (CADA)—the centerpiece of its new Tech Sovereignty Package. At its core: a four-tier model that public contracting authorities will use in the future to assess how sovereign a cloud provider truly is—not just where the data is located, but who owns the provider, who controls it, and which legal system it is subject to.

CADA is still a proposal, not yet law, but the direction is remarkably clear. Commission Vice President Henna Virkkunen has stated publicly that providers subject to the U.S. CLOUD Act will face structural difficulties in reaching the top two levels—regardless of where their data centers are located in Europe. The CLOUD Act allows U.S. authorities to access data from U.S. companies, no matter where in the world that data is located. Anyone subject to this law can hardly credibly promise “no influence by a third country.” That is precisely the test for Level 4.

The four levels, briefly explained

An overview of the four CADA sovereignty levels

L1

EU Location

Data and infrastructure are located in the EU. No additional requirements regarding ownership, personnel, or the software supply chain.

✓ Available to U.S. hyperscalers with an EU region

L2

Independence & Transparency

Additionally: verifiable independence from third countries and transparency throughout the entire software supply chain.

⚠ Depends on ownership structure and transparency requirements

L3

EU Ownership & EU Control

The provider must be based in the EU, EU-owned, and under EU control—including requirements regarding the citizenship of its staff.

✗ Structurally unfeasible under the U.S. CLOUD Act

L4

Complete digital sovereignty

Full transparency and control over the entire software supply chain, with no influence from third countries. The highest degree of digital independence recognized by the regulatory framework.

✗ Structurally unachievable under the U.S. CLOUD Act

Why this doesn’t end with cloud infrastructure

CADA is explicitly written for the public procurement of cloud services. But the underlying question is not specific to the cloud. It is: Who controls the software running in critical infrastructure—and to which legal system is that party accountable?

This question applies with equal validity to every security-critical software component. And hardly any component sits deeper at the heart of IT security architecture than the vulnerability management system, which knows where every vulnerability in a country’s infrastructure lies.

Who supplies this software, who controls it, and who—in case of doubt—could be forced to grant access or remain silent—this is no longer an academic question. It is the very question that CADA is now making binding for cloud providers.

Applying this standard: Where does Greenbone stand?

We are not a cloud provider as defined by CADA and will therefore not be “CADA-certified.” But if you apply the same criteria to an IT security system, a clear picture emerges:

  • Control & Legal System: Greenbone is a company founded in Germany and firmly rooted in Europe. We are subject to German and European law, not the U.S. CLOUD Act.
  • Staff: Our development and operations team is based in Germany and the EU.
  • Software Supply Chain: OPENVAS is open source. Not “auditable upon request”—but fully transparent to everyone, at any time. This is a stronger position than “auditable software,” as required by CADA for Levels 2/3.
  • Disclosure Requirements: Because we are not subject to U.S. law, there is no legal framework through which we could be forced into tacit cooperation with third-country authorities—the kind of “hidden disclosure” that CADA aims to protect against.

Many established companies are based in the U.S. This structural reality is what makes CADA measurable for the first time. An EU data center region does not change this as long as the parent company is subject to the CLOUD Act.

What this means for you

CADA is not yet in effect. But for the first time, the Commission has precisely defined what “digital sovereignty” actually means—in four verifiable stages rather than in marketing jargon. For government agencies, KRITIS operators, and public contracting authorities, this will likely become a requirement in their specifications.

Those who are already built on this foundation today won’t have to migrate tomorrow.

 

Contact Try for Free Buy Here Back to Overview
8. July 2026/by Greenbone AG
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Greenbone AG https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Greenbone AG2026-07-08 11:28:562026-07-08 11:28:56Sovereignty was a promise. Now it’s becoming a test criterion.
Page 2 of 512345

Search

Search Search

Archive

  • 2026
  • 2025

Newsletter

Subscribe Now

OPENVAS BASIC

Our entry-level enterprise product

Test 14 Days Free of Charge

Products & Solutions

  • OPENVAS PRODUCTS
  • OPENVAS SECURITY INTELLIGENCE
  • OPENVAS SCAN
  • OPENVAS BASIC
  • OPENVAS FREE
  • OPENVAS AI
ISO9001-EN

Service & Support

  • Professional Services
  • Documents
  • Technical Support
  • FAQ
  • Warranty
  • Cyber Resilience Act
ISO27001-EN

About us

  • About Greenbone
  • Partners
  • MSSP
  • License information
  • Privacy Statement
  • Terms & Conditions
ISO14001-EN

Contact with us

  • Contact
  • Newsletter
  • Media Contact
  • Careers
  • Security Response
  • Imprint
  • Grounding Page

Community

  • Community Portal
  • Community Forum
© Copyright - Greenbone AG 2020-2026
  • Link to LinkedIn
Scroll to top Scroll to top Scroll to top
Contact
Request IT Security Contact Us Subscribe to Newsletter Follow on LinkedIn