CVE-2020-10768: Schwachstellen-Eintrag (NVD)
A flaw was found in the Linux Kernel before 5.8-rc1 in the prctl() function, where it can be used to enable indirect branch speculation after it has been disabled. This call incorrectly reports it as being 'force disabled' when it is not and opens the system to Spectre v2 attacks. The highest threat from this vulnerability is to confidentiality.
Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-13 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
CVE-2026-90772 | Amundsen-io Amundsen Frontend up to 4.3.0 ResourceListItem dangerouslySetInnerHTML injection (EUVD-2026-76993)
A vulnerability has been found in Amundsen-io Amundsen Frontend up to 4.3.0 and classified as problematic. This affects the function dangerouslySetInnerHTML of the component ResourceListItem. This manipulation causes injection. This vulnera
CVE-2026-90775 | PostGIS address_standardizer up to 3.7.0 Address Standardizer src/gamma.c Weight out-of-bounds (EUVD-2026-76997)
A vulnerability labeled as critical has been found in PostGIS address_standardizer up to 3.7.0. This impacts an unknown function of the file src/gamma.c of the component Address Standardizer. Such manipulation of the argument Weight leads t
CVE-2026-90773 | dalance procs up to 0.14.12 Command Column escape output (EUVD-2026-76994)
A vulnerability identified as problematic has been detected in dalance procs up to 0.14.12. This affects an unknown function of the component Command Column. This manipulation causes escaping of output. The identification of this vulnerabil
CVE-2026-90774 | orhun rustypaste up to 0.18.0 path traversal (EUVD-2026-76995)
A vulnerability was found in orhun rustypaste up to 0.18.0. It has been declared as problematic. Impacted is an unknown function. Executing a manipulation can lead to path traversal. This vulnerability is handled as CVE-2026-90774. The atta
CVE-2026-90776 | Nodemailer up to 10.0.4 Addressparser resource consumption (EUVD-2026-77000)
A vulnerability classified as problematic was found in Nodemailer up to 10.0.4. This affects an unknown part of the component Addressparser. The manipulation results in resource consumption. This vulnerability is cataloged as CVE-2026-90776
CVE-2026-90515 | SourceCodester School Registration and Fee System 1.0 delete_stud.php selector[] sql injection (EUVD-2026-76998)
A vulnerability classified as critical was found in SourceCodester School Registration and Fee System 1.0. The impacted element is an unknown function of the file /bilal/normal/delete_stud.php. Executing a manipulation of the argument selec
CVE-2026-90779 | SIPp up to 3.7.7 createAuthHeader stack-based overflow (EUVD-2026-77003)
A vulnerability, which was classified as problematic, has been found in SIPp up to 3.7.7. This vulnerability affects the function createAuthHeader. This manipulation causes stack-based buffer overflow. This vulnerability is registered as CV
CVE-2026-90778 | SIPp up to 3.7.7 get_peer_tag buffer overflow (EUVD-2026-77002)
A vulnerability described as problematic has been identified in SIPp up to 3.7.7. Affected by this vulnerability is the function get_peer_tag. Executing a manipulation can lead to buffer overflow. This vulnerability is tracked as CVE-2026-9
CVE-2026-90777 | ESPnet prior 202609 torch.load deserialization (EUVD-2026-77001)
A vulnerability marked as critical has been reported in ESPnet. Affected is the function torch.load. Performing a manipulation results in deserialization. This vulnerability is identified as CVE-2026-90777. The attack can be initiated remot
CVE-2026-90780 | SIPp up to 3.7.7 src/sip_parser.cpp get_header buffer overflow (EUVD-2026-77004)
A vulnerability classified as critical has been found in SIPp up to 3.7.7. Affected by this issue is the function get_header of the file src/sip_parser.cpp. The manipulation leads to buffer overflow. This vulnerability is listed as CVE-2026
CVE-2026-90517 | PHPGurukul Bank Locker Management System 1.0 view-assign-locker.php ltid authorization (EUVD-2026-77005)
A vulnerability, which was classified as problematic, has been found in PHPGurukul Bank Locker Management System 1.0. This affects an unknown function of the file /blms/view-assign-locker.php. The manipulation of the argument ltid leads to
CVE-2026-80935 | Linux Kernel up to 7.2.3 mt7996 mt7996_mcu_get_eeprom addr out-of-bounds write (Nessus ID 345409)
A vulnerability identified as very critical has been detected in Linux Kernel up to 7.2.3. This affects the function mt7996_mcu_get_eeprom of the component mt7996. The manipulation of the argument addr leads to out-of-bounds write. This vul
CVE-2026-89640 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 cifs cifs_remap_file_range toctou (Nessus ID 345413)
A vulnerability was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. It has been classified as very critical. The impacted element is the function cifs_remap_file_range of the component cifs. Performing a manipulation results in time-of-
CVE-2026-80944 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 mwifiex wait_event_interruptible_timeout data_buf stack-based overflow (Nessus ID 345411)
A vulnerability was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. It has been classified as very critical. This issue affects the function wait_event_interruptible_timeout of the component mwifiex. The manipulation of the argument dat
CVE-2026-89482 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 nvme-tcp nvme_tcp_setup_cmd_pdu out-of-bounds write (Nessus ID 345412)
A vulnerability categorized as very critical has been discovered in Linux Kernel up to 6.12.108/6.18.49/7.2.3. This impacts the function nvme_tcp_setup_cmd_pdu of the component nvme-tcp. Such manipulation leads to out-of-bounds write. This
CVE-2026-80940 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 rtw88 rtw_pci_probe memory leak (Nessus ID 345414)
A vulnerability labeled as critical has been found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. The affected element is the function rtw_pci_probe of the component rtw88. Such manipulation leads to memory leak. This vulnerability is refere
CVE-2026-81524 | MongoDB C Driver up to 2.5.0 os command injection (Nessus ID 345458 / WID-SEC-2026-3066)
A vulnerability described as critical has been identified in MongoDB C Driver up to 2.5.0. This impacts an unknown function. Executing a manipulation can lead to os command injection. The identification of this vulnerability is CVE-2026-815
CVE-2026-84963 | MongoDB C Driver up to 1.30.8/2.5.1 JSON Parsing missing initialization (Nessus ID 345458 / WID-SEC-2026-3209)
A vulnerability was found in MongoDB C Driver up to 1.30.8/2.5.1. It has been declared as problematic. The impacted element is an unknown function of the component JSON Parsing. The manipulation results in missing initialization of a variab
GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read – Exploited Within 24 Hours
CVE-2026-85706, a CVSS 10.0 GitLab path traversal, was under active exploitation within 24 hours of disclosure. GitLab disclosed CVE-2026-85706 (CVSS score of 10.0) on September 10, 2026, a path traversal vulnerability in its repository com
GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read – Exploited Within 24 Hours
CVE-2026-85706, a CVSS 10.0 GitLab path traversal, was under active exploitation within 24 hours of disclosure. GitLab disclosed CVE-2026-85706 (CVSS score of 10.0) on September 10, 2026, a path traversal vulnerability in its repository com
Plesk Backup Manager Flaw Lets Low-Privileged Users Gain Root Access to Servers
A newly disclosed vulnerability in Plesk Backup Manager could allow low-privileged users to escalate privileges and gain full root access on affected Linux servers. Tracked as CVE-2026-68488, the flaw stems from a symlink race condition dur
Plesk Backup Manager Flaw Lets Low-Privileged Users Gain Root Access to Servers
A newly disclosed vulnerability in Plesk Backup Manager could allow low-privileged users to escalate privileges and gain full root access on affected Linux servers. Tracked as CVE-2026-68488, the flaw stems from a symlink race condition dur
Plesk Backup Manager Flaw Lets Low-Privileged Users Gain Root Access to Servers
A newly disclosed vulnerability in Plesk Backup Manager could allow low-privileged users to escalate privileges and gain full root access on affected Linux servers. Tracked as CVE-2026-68488, the flaw stems from a symlink race condition dur
Microsoft-Patchday: 966 Schwachstellen, davon 105 kritisch - BornCity
... Windows 10, Windows 11 und Windows Server zu erlangen. Dabei werde eine frühere Korrektur für die Lücke CVE-2026-69414 umgangen. Microsoft ... Weiterlesen
Sogou Input Method: Chinesische <b>Hacker</b> nutzen CVE-2026-51990 - Börse Express
UNC3569 nutzte CVE-2026-51990 gegen Sogou-Nutzer. Tencent schloss die kritische Lücke im April mit Version 16.3.0.3498. Weiterlesen
CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following rep
Multiple VLC Media Player Vulnerabilities Allow Attackers to Corrupt or Read Heap Memory
Two security vulnerabilities in VLC Media Player could allow attackers to corrupt heap memory or disclose sensitive data from a victim’s memory. The flaws, tracked as CVE-2026-56711 and CVE-2026-73324, affect VLC Media Player versions 3.0.0
Multiple VLC Media Player Vulnerabilities Allow Attackers to Corrupt or Read Heap Memory
Two security vulnerabilities in VLC Media Player could allow attackers to corrupt heap memory or disclose sensitive data from a victim’s memory. The flaws, tracked as CVE-2026-56711 and CVE-2026-73324, affect VLC Media Player versions 3.0.0
China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks
China-linked threat actors UTA0560 and JungleBamboo chained a Google Chrome zero-day with a Windows kernel privilege-escalation flaw in phishing campaigns targeting NGOs and other victims. Volexity documented the operations, detected on Sep
China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks
China-linked threat actors UTA0560 and JungleBamboo chained a Google Chrome zero-day with a Windows kernel privilege-escalation flaw in phishing campaigns targeting NGOs and other victims. Volexity documented the operations, detected on Sep
CISA Warns of Critical GitLab Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab flaw, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog after confirming it was exploited in attacks. The issue affects bot
CISA Warns of Critical GitLab Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab flaw, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog after confirming it was exploited in attacks. The issue affects bot
CISA Warns of Critical GitLab Path Traversal Flaw Exploited to Read Arbitrary Server Files
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab path traversal vulnerability, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog after evidence that the flaw is being activ
CISA Warns of GitLab Path Traversal Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab vulnerability, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog, warning that attackers are actively exploiting the flaw.
CISA Warns of GitLab Path Traversal Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab vulnerability, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog, warning that attackers are actively exploiting the flaw.
Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
Ravie LakshmananSep 11, 2026Vulnerability / Malware Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC)
GitLab schließt CVE-2026-85706 mit CVSS 10, aktive In-the-Wild-Probes
LONDON (IT BOLTWISE) – GitLab hat mehrere Sicherheitslücken gepatcht, darunter eine Schwachstelle mit CVSS 10,0 (CVE-2026-85706), die bereits innerhalb von Stunden nach der Veröffentlichung von Angreifern abgefragt wurde. Betroffen sind bes
VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data
Two security vulnerabilities in VLC Media Player could enable attackers to corrupt memory or extract sensitive data from affected systems by persuading users to open a specially crafted image file or media playlist. The flaws, tracked as CV
CISA Warns MikroTik RouterOS Flaw Is Exploited to Escalate Privileges
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical MikroTik RouterOS privilege-escalation vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, warning that the flaw is being actively exploit
VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data
Two security vulnerabilities in VLC media player versions 3.0.0 through 3.0.23 could allow attackers to exploit heap memory issues. These vulnerabilities can be triggered by processing a malicious PNG file or connecting to attacker-controll
VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data
Two security vulnerabilities in VLC media player versions 3.0.0 through 3.0.23 could allow attackers to exploit heap memory issues. These vulnerabilities can be triggered by processing a malicious PNG file or connecting to attacker-controll
CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, warning that these flaws are actively being exploited in the wild. On
CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, warning that these flaws are actively being exploited in the wild. On
cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw
A recently disclosed vulnerability in ConfigServer Security &amp; Firewall (CSF) could allow unauthenticated remote attackers to execute arbitrary commands through the product’s MESSENGER service. This vulnerability, tracked as CVE-2026
cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw
A recently disclosed vulnerability in ConfigServer Security &amp; Firewall (CSF) could allow unauthenticated remote attackers to execute arbitrary commands through the product’s MESSENGER service. This vulnerability, tracked as CVE-2026
Check Point Patches Critical VPN Vulnerabilities
Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution. The post Check Point Patches Critical VPN Vulnerabilities appeared first on SecurityWeek. Weiterlesen
Attackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware
Three threat groups are exploiting two Cisco FMC flaws to steal credentials, gain root access and deploy Qilin ransomware. Cisco Talos says three separate threat groups are exploiting two recently patched Secure Firewall Management Center (
Critical ConfigServer Security & Firewall Flaw Lets Remote Attackers Execute Arbitrary Commands
A critical vulnerability in ConfigServer Security &amp; Firewall (CSF) could allow unauthenticated remote attackers to execute arbitrary commands on vulnerable servers. Tracked as CVE-2026-65638, the flaw affects CSF versions 14.00 thro
Imperva Customers Protected Against StyleSmuggler (CVE-2026-75650) in Adobe Commerce and Magento Open Source
TL;DR: CVE-2026-75650, dubbed StyleSmuggler, is a critical vulnerability affecting Adobe Commerce and Magento Open Source. The vulnerability allows an unauthenticated attacker to inject malicious PHP code into Magento’s template system and
[NEU] [mittel] Fortra GoAnywhere MFT: Schwachstelle ermöglicht Offenlegung von Informationen
Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Fortra GoAnywhere MFT ausnutzen, um Informationen offenzulegen. Weiterlesen
[NEU] [hoch] Palo Alto Networks Cortex XDR Broker VM: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit Administratorrechten
Ein Angreifer aus einem angrenzenden Netzwerk kann eine Schwachstelle in Palo Alto Networks Cortex XDR Broker VM ausnutzen, um beliebigen Programmcode mit Administratorrechten auszuführen. Weiterlesen
[NEU] [niedrig] Laravel: Schwachstelle ermöglicht Cross-Site Scripting
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Laravel ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen. Weiterlesen
Active exploitation of Cisco Secure Firewall Management Center vulnerabilities
Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software. First, CVE-2026-20079 is an authentication bypass vulnerability in unpatched instances of Cisco’s Secure F
Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."Microsoft notes that 2 of the vulnerabiliti
N-able issues patch for zero-day flaw
Security researchers warned the company of unusual threat activity in a recently patched N-able environment. Weiterlesen
Attackers Exploit Unpatched Magento Zero-Day to Backdoor Online Stores
Attackers are exploiting an unpatched remote code execution flaw in Adobe Commerce and Magento Open Source to install persistent backdoors on e-commerce sites, Dutch security firm Sansec reported, with the first intrusions observed Sept. 4
Nightmare Eclipse drops a CrowdStrike zero-day.
Extortion group leaks alleged Manchester Airports Group data. France's CNIL fines hospital over 2025 data breach. Weiterlesen
CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers’ crosshairs. The vulnerabilities are as follows – C
CVE-2026-75757 | Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an attacker who controls a sibling subdomain rebind an admin's session to a different actor, tenant, or authorization mode. AshAdmin's client JavaScript read its state cookies (tenant, actor_resource, actor_primary_key, actor_action, actor_domain, actor_authorizing, actor_paused) by matching the cookie name with an unanchored regular expression (new RegE
Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an attacker who controls a sibling subdomain rebind an admin's session to a different actor, tenant, or authorization mode. AshAdmin'
CVE-2026-82605 | A vulnerability has been found in BareBones BBEdit up to 15.5.5. The affected element is an unknown function of the component Lasso Language Tokenizer. Such manipulation leads to infinite loop. The attack can be executed remotely. Upgrading to version 16.0 is sufficient to fix this issue. The affected component should be upgraded.
A vulnerability has been found in BareBones BBEdit up to 15.5.5. The affected element is an unknown function of the component Lasso Language Tokenizer. Such manipulation leads to infinite loop. The attack can be executed remotely. Upgrading