Cyber Resilience
← All news

[UPDATE] [hoch] Oracle Solaris Drittanbieterkomponenten: Mehrere Schwachstellen

Our takeCERT-Bund updated its advisory on multiple third-party component flaws in Oracle Solaris. Update if you run it.
Sources (23)
What this means for you — Security leader:Apply the Oracle Solaris third-party component updates in CERT-Bund WID-SEC-2026-2455 on self-managed Solaris hosts; remote anonymous or authenticated attackers can exploit several bundled components. Inventory which of those components you actually run before elevating the whole estate.
What this means for you — Lean IT orgs:You almost certainly do not run Oracle Solaris and can ignore this. If a vendor or hosted service you depend on might, ask them whether these third-party component updates are applied.
What this means for you — MSP:Check client inventories for Oracle Solaris — most lean and mid-market estates will have none. For the few that do, schedule the third-party component patches and note the remote anonymous paths called out in the advisory.
What this means for you — Researcher:CERT-Bund WID-SEC-2026-2455 covers multiple third-party component flaws in Oracle Solaris with remote anonymous or authenticated attack paths. Map the affected components to upstream CVEs in Oracle’s advisory for exploitability detail.