Yama Salısı
Ocak 2026
Her ayın ikinci salısı Microsoft, Adobe, SAP, Siemens ve Schneider Electric toplu yayın yapar; Oracle ocak, nisan, temmuz ve ekimde üçüncü salı. Burada o gün yayımlanan kayıtlar kendi veritabanımızdan, eylem puanına göre sıralı: önce KEV ve istismarı olgun olanlar.
Nasıl hesaplanır: CNA damgası + yayın tarihi (iki günlük pencere, UTC). Üreticinin bülteniyle bire bir eşleşme iddiası yok; ara güncellemeler ayrı günlerde çıkar.
206 kayıt · 3 KEV
Stack'inizi etkileyenler
Bu ayın kayıtlarından stack'inizdeki ürün ve sürümlere uyanlar.
Stack'inize uyanları görmek için giriş yapın; kayıtlar ve bildirimler ücretsiz. →
Microsoft · 13 Ocak
112 · 2 KEV · 1 kritik| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
78Bu hafta | CVE-2026-20963Silahlaştırılmış | Microsoft SharePoint Remote Code Execution Vulnerabilitymicrosoft · sharepoint server · CWE-502 | Kritik9,8 | KEV | %29,6 | 13 Oca 2026 |
54Planlayın | CVE-2026-20805Silahlaştırılmış | Desktop Window Manager Information Disclosure Vulnerabilitymicrosoft · windows 10 1607 · CWE-200 | Orta5,5 | KEV | %7,2 | 13 Oca 2026 |
41Planlayın | CVE-2026-20947İstismar yok | Microsoft SharePoint Server Remote Code Execution Vulnerabilitymicrosoft · sharepoint server · CWE-89 | Yüksek8,8 | — | %18,8 | 13 Oca 2026 |
35İzleyin | CVE-2026-20868İstismar yok | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerabilitymicrosoft · windows 10 1607 · CWE-122 | Yüksek8,8 | — | %1,4 | 13 Oca 2026 |
34İzleyin | CVE-2026-20860İstismar yok | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1607 · CWE-843 | Yüksek7,8 | — | %8,4 | 13 Oca 2026 |
33İzleyin | CVE-2026-20817Kavram kanıtı | Windows Error Reporting Service Elevation of Privilege Vulnerabilitymicrosoft · windows 10 21h2 · CWE-280 | Yüksek7,8 | — | %5,5 | 13 Oca 2026 |
33İzleyin | CVE-2026-20944İstismar yok | Microsoft Word Remote Code Execution Vulnerabilitymicrosoft · 365 apps · CWE-125 | Yüksek8,4 | — | %0,5 | 13 Oca 2026 |
33İzleyin | CVE-2026-20952İstismar yok | Microsoft Office Remote Code Execution Vulnerabilitymicrosoft · 365 apps · CWE-416 | Yüksek8,4 | — | %0,5 | 13 Oca 2026 |
33İzleyin | CVE-2026-20953İstismar yok | Microsoft Office Remote Code Execution Vulnerabilitymicrosoft · 365 apps · CWE-416 | Yüksek8,4 | — | %0,6 | 13 Oca 2026 |
32İzleyin | CVE-2026-20820Kavram kanıtı | Windows Common Log File System Driver Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1607 · CWE-122 | Yüksek7,8 | — | %2,6 | 13 Oca 2026 |
32İzleyin | CVE-2026-20840İstismar yok | Windows NTFS Remote Code Execution Vulnerabilitymicrosoft · windows 10 1607 · CWE-122 | Yüksek7,8 | — | %4,7 | 13 Oca 2026 |
32İzleyin | CVE-2026-20843İstismar yok | Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1607 · CWE-284 | Yüksek7,8 | — | %3,5 | 13 Oca 2026 |
- CVE-2026-2096378Bu hafta
Microsoft SharePoint Remote Code Execution Vulnerability
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %30microsoft · sharepoint server13 Oca 2026
- CVE-2026-2080554Planlayın
Desktop Window Manager Information Disclosure Vulnerability
OrtaCVSS 5,5KEVSilahlaştırılmışEPSS %7microsoft · windows 10 160713 Oca 2026
- CVE-2026-2094741Planlayın
Microsoft SharePoint Server Remote Code Execution Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %19microsoft · sharepoint server13 Oca 2026
- CVE-2026-2086835İzleyin
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %1microsoft · windows 10 160713 Oca 2026
- CVE-2026-2086034İzleyin
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
YüksekCVSS 7,8İstismar yokEPSS %8microsoft · windows 10 160713 Oca 2026
- CVE-2026-2081733İzleyin
Windows Error Reporting Service Elevation of Privilege Vulnerability
YüksekCVSS 7,8Kavram kanıtıEPSS %6microsoft · windows 10 21h213 Oca 2026
- CVE-2026-2094433İzleyin
Microsoft Word Remote Code Execution Vulnerability
YüksekCVSS 8,4İstismar yokEPSS %1microsoft · 365 apps13 Oca 2026
- CVE-2026-2095233İzleyin
Microsoft Office Remote Code Execution Vulnerability
YüksekCVSS 8,4İstismar yokEPSS %1microsoft · 365 apps13 Oca 2026
- CVE-2026-2095333İzleyin
Microsoft Office Remote Code Execution Vulnerability
YüksekCVSS 8,4İstismar yokEPSS %1microsoft · 365 apps13 Oca 2026
- CVE-2026-2082032İzleyin
Windows Common Log File System Driver Elevation of Privilege Vulnerability
YüksekCVSS 7,8Kavram kanıtıEPSS %3microsoft · windows 10 160713 Oca 2026
- CVE-2026-2084032İzleyin
Windows NTFS Remote Code Execution Vulnerability
YüksekCVSS 7,8İstismar yokEPSS %5microsoft · windows 10 160713 Oca 2026
- CVE-2026-2084332İzleyin
Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability
YüksekCVSS 7,8İstismar yokEPSS %3microsoft · windows 10 160713 Oca 2026
+100 kayıt dahaÜreticinin tüm kayıtları
Adobe · 13 Ocak
25 · 0 KEV · 0 kritik| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
34İzleyin | CVE-2026-21267İstismar yok | Dreamweaver Desktop | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)adobe · dreamweaver · CWE-78 | Yüksek8,6 | — | %0,8 | 13 Oca 2026 |
34İzleyin | CVE-2026-21268İstismar yok | Dreamweaver Desktop | Improper Input Validation (CWE-20)adobe · dreamweaver · CWE-20 | Yüksek8,6 | — | %0,2 | 13 Oca 2026 |
34İzleyin | CVE-2026-21271İstismar yok | Dreamweaver Desktop | Improper Input Validation (CWE-20)adobe · dreamweaver · CWE-20 | Yüksek8,6 | — | %0,2 | 13 Oca 2026 |
34İzleyin | CVE-2026-21272İstismar yok | Dreamweaver Desktop | Improper Input Validation (CWE-20)adobe · dreamweaver · CWE-20 | Yüksek8,6 | — | %0,2 | 13 Oca 2026 |
34İzleyin | CVE-2026-21280İstismar yok | Illustrator | Untrusted Search Path (CWE-426)adobe · illustrator · CWE-426 | Yüksek8,6 | — | %0,3 | 13 Oca 2026 |
31İzleyin | CVE-2026-21274İstismar yok | Dreamweaver Desktop | Incorrect Authorization (CWE-863)adobe · dreamweaver · CWE-863 | Yüksek7,8 | — | %0,2 | 13 Oca 2026 |
31İzleyin | CVE-2026-21275İstismar yok | InDesign Desktop | Access of Uninitialized Pointer (CWE-824)adobe · indesign · CWE-824 | Yüksek7,8 | — | %0,2 | 13 Oca 2026 |
31İzleyin | CVE-2026-21276İstismar yok | InDesign Desktop | Access of Uninitialized Pointer (CWE-824)adobe · indesign · CWE-824 | Yüksek7,8 | — | %0,2 | 13 Oca 2026 |
31İzleyin | CVE-2026-21277İstismar yok | InDesign Desktop | Heap-based Buffer Overflow (CWE-122)adobe · indesign · CWE-122 | Yüksek7,8 | — | %0,3 | 13 Oca 2026 |
31İzleyin | CVE-2026-21281İstismar yok | InCopy | Heap-based Buffer Overflow (CWE-122)adobe · incopy · CWE-122 | Yüksek7,8 | — | %0,2 | 13 Oca 2026 |
31İzleyin | CVE-2026-21283İstismar yok | Bridge | Heap-based Buffer Overflow (CWE-122)adobe · bridge · CWE-122 | Yüksek7,8 | — | %0,3 | 13 Oca 2026 |
31İzleyin | CVE-2026-21287İstismar yok | Substance3D - Stager | Use After Free (CWE-416)adobe · substance 3d stager · CWE-416 | Yüksek7,8 | — | %0,2 | 13 Oca 2026 |
- CVE-2026-2126734İzleyin
Dreamweaver Desktop | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
YüksekCVSS 8,6İstismar yokEPSS %1adobe · dreamweaver13 Oca 2026
- CVE-2026-2126834İzleyin
Dreamweaver Desktop | Improper Input Validation (CWE-20)
YüksekCVSS 8,6İstismar yokEPSS %0adobe · dreamweaver13 Oca 2026
- CVE-2026-2127134İzleyin
Dreamweaver Desktop | Improper Input Validation (CWE-20)
YüksekCVSS 8,6İstismar yokEPSS %0adobe · dreamweaver13 Oca 2026
- CVE-2026-2127234İzleyin
Dreamweaver Desktop | Improper Input Validation (CWE-20)
YüksekCVSS 8,6İstismar yokEPSS %0adobe · dreamweaver13 Oca 2026
- CVE-2026-2128034İzleyin
Illustrator | Untrusted Search Path (CWE-426)
YüksekCVSS 8,6İstismar yokEPSS %0adobe · illustrator13 Oca 2026
- CVE-2026-2127431İzleyin
Dreamweaver Desktop | Incorrect Authorization (CWE-863)
YüksekCVSS 7,8İstismar yokEPSS %0adobe · dreamweaver13 Oca 2026
- CVE-2026-2127531İzleyin
InDesign Desktop | Access of Uninitialized Pointer (CWE-824)
YüksekCVSS 7,8İstismar yokEPSS %0adobe · indesign13 Oca 2026
- CVE-2026-2127631İzleyin
InDesign Desktop | Access of Uninitialized Pointer (CWE-824)
YüksekCVSS 7,8İstismar yokEPSS %0adobe · indesign13 Oca 2026
- CVE-2026-2127731İzleyin
InDesign Desktop | Heap-based Buffer Overflow (CWE-122)
YüksekCVSS 7,8İstismar yokEPSS %0adobe · indesign13 Oca 2026
- CVE-2026-2128131İzleyin
InCopy | Heap-based Buffer Overflow (CWE-122)
YüksekCVSS 7,8İstismar yokEPSS %0adobe · incopy13 Oca 2026
- CVE-2026-2128331İzleyin
Bridge | Heap-based Buffer Overflow (CWE-122)
YüksekCVSS 7,8İstismar yokEPSS %0adobe · bridge13 Oca 2026
- CVE-2026-2128731İzleyin
Substance3D - Stager | Use After Free (CWE-416)
YüksekCVSS 7,8İstismar yokEPSS %0adobe · substance 3d stager13 Oca 2026
+13 kayıt dahaÜreticinin tüm kayıtları
SAP · 13 Ocak
0 · 0 KEV · 0 kritikBu pencerede kayıt yok.
Siemens · 13 Ocak
3 · 0 KEV · 1 kritik| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2025-40805İstismar yok | Affected devices do not properly enforce user authentication on specific API endpoints.siemens · industrial edge cloud device (iecd) · CWE-639 | Kritik10,0 | — | %0,7 | 13 Oca 2026 |
34İzleyin | CVE-2025-40944İstismar yok | A vulnerability has been identified in SIMATIC ET 200AL IM 157-1 PN (6ES7157-1AB00-0AB0) (All versions), SIMATIC ET 200MP IM 155-5 PN HF (6Esiemens · simatic et 200al im 157-1 pn · CWE-400 | Yüksek8,7 | — | %0,4 | 13 Oca 2026 |
29İzleyin | CVE-2025-40942İstismar yok | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.4).siemens · telecontrol server basic · CWE-250 | Yüksek7,3 | — | %0,2 | 13 Oca 2026 |
- CVE-2025-4080540Planlayın
Affected devices do not properly enforce user authentication on specific API endpoints.
KritikCVSS 10,0İstismar yokEPSS %1siemens · industrial edge cloud device (iecd)13 Oca 2026
- CVE-2025-4094434İzleyin
A vulnerability has been identified in SIMATIC ET 200AL IM 157-1 PN (6ES7157-1AB00-0AB0) (All versions), SIMATIC ET 200MP IM 155-5 PN HF (6E
YüksekCVSS 8,7İstismar yokEPSS %0siemens · simatic et 200al im 157-1 pn13 Oca 2026
- CVE-2025-4094229İzleyin
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.4).
YüksekCVSS 7,3İstismar yokEPSS %0siemens · telecontrol server basic13 Oca 2026
Schneider Electric · 13 Ocak
0 · 0 KEV · 0 kritikBu pencerede kayıt yok.
Oracle (Critical Patch Update) · 20 Ocak
66 · 1 KEV · 2 kritik| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
92Hemen | CVE-2026-21962Silahlaştırılmış | Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Serveoracle · http server · CWE-284 | Kritik10,0 | KEV | %73,2 | 20 Oca 2026 |
39İzleyin | CVE-2026-21969İstismar yok | Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Supplier Portal).oracle · agile product lifecycle management for process | Kritik9,8 | — | %0,5 | 20 Oca 2026 |
34İzleyin | CVE-2026-21967İstismar yok | Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Opera Servlet).oracle · hospitality opera 5 | Yüksek8,6 | — | %0,3 | 20 Oca 2026 |
32İzleyin | CVE-2026-21955Kavram kanıtı | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).oracle · vm virtualbox · CWE-400 | Yüksek8,2 | — | %0,3 | 20 Oca 2026 |
32İzleyin | CVE-2026-21956İstismar yok | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).oracle · vm virtualbox · CWE-400 | Yüksek8,2 | — | %0,3 | 20 Oca 2026 |
32İzleyin | CVE-2026-21973İstismar yok | Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applications (component: Security Management Syoracle · flexcube investor servicing | Yüksek8,1 | — | %0,3 | 20 Oca 2026 |
32İzleyin | CVE-2026-21987İstismar yok | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).oracle · vm virtualbox | Yüksek8,2 | — | %0,2 | 20 Oca 2026 |
32İzleyin | CVE-2026-21988İstismar yok | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).oracle · vm virtualbox | Yüksek8,2 | — | %0,2 | 20 Oca 2026 |
32İzleyin | CVE-2026-21989İstismar yok | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).oracle · vm virtualbox | Yüksek8,1 | — | %0,2 | 20 Oca 2026 |
32İzleyin | CVE-2026-21990İstismar yok | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).oracle · vm virtualbox | Yüksek8,2 | — | %0,2 | 20 Oca 2026 |
30İzleyin | CVE-2026-21926İstismar yok | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure).oracle · siebel customer relationship management deployment | Yüksek7,5 | — | %0,4 | 20 Oca 2026 |
30İzleyin | CVE-2026-21940İstismar yok | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: User and User Group).oracle · supply chain products suite · CWE-200 | Yüksek7,5 | — | %0,4 | 20 Oca 2026 |
- CVE-2026-2196292Hemen
Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Serve
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %73oracle · http server20 Oca 2026
- CVE-2026-2196939İzleyin
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Supplier Portal).
KritikCVSS 9,8İstismar yokEPSS %0oracle · agile product lifecycle management for process20 Oca 2026
- CVE-2026-2196734İzleyin
Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Opera Servlet).
YüksekCVSS 8,6İstismar yokEPSS %0oracle · hospitality opera 520 Oca 2026
- CVE-2026-2195532İzleyin
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).
YüksekCVSS 8,2Kavram kanıtıEPSS %0oracle · vm virtualbox20 Oca 2026
- CVE-2026-2195632İzleyin
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).
YüksekCVSS 8,2İstismar yokEPSS %0oracle · vm virtualbox20 Oca 2026
- CVE-2026-2197332İzleyin
Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applications (component: Security Management Sy
YüksekCVSS 8,1İstismar yokEPSS %0oracle · flexcube investor servicing20 Oca 2026
- CVE-2026-2198732İzleyin
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).
YüksekCVSS 8,2İstismar yokEPSS %0oracle · vm virtualbox20 Oca 2026
- CVE-2026-2198832İzleyin
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).
YüksekCVSS 8,2İstismar yokEPSS %0oracle · vm virtualbox20 Oca 2026
- CVE-2026-2198932İzleyin
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).
YüksekCVSS 8,1İstismar yokEPSS %0oracle · vm virtualbox20 Oca 2026
- CVE-2026-2199032İzleyin
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).
YüksekCVSS 8,2İstismar yokEPSS %0oracle · vm virtualbox20 Oca 2026
- CVE-2026-2192630İzleyin
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure).
YüksekCVSS 7,5İstismar yokEPSS %0oracle · siebel customer relationship management deployment20 Oca 2026
- CVE-2026-2194030İzleyin
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: User and User Group).
YüksekCVSS 7,5İstismar yokEPSS %0oracle · supply chain products suite20 Oca 2026
+54 kayıt dahaÜreticinin tüm kayıtları