🎯 CVE-2020-12642 HIGH 7.5 🔥 EPSS 21.7%
📄 .md Alle CVEs anzeigen ✕

CVE-2020-12642: Schwachstellen-Eintrag (NVD)

An issue was discovered in service-api before 4.3.12 and 5.x before 5.1.1 for Report Portal. It allows XXE, with resultant secrets disclosure and SSRF, via JUnit XML launch import.

Klassifikation & Betroffenheit:
reportportal service-api *
Improper Control of Generation of Code ('Code Injection') 🎯 Medium

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

🛡️ Empfohlene Mitigation: Refactor your program so that you do not have to dynamically generate code.
Vollständige Definition bei MITRE ➔
🩹 Patch verfügbar (OSV):
🩹 098cb31d0d523132e05211b0d31a3301e292969d (Commit) 🩹 488241581b4eb897834ab612261259428e31918c (Commit)
📚 Referenzen & Quellen:
Ausnutzungs-Zeitleiste:
CVSS-Vektor-Analyse: 7.5
AV · Angriffsvektor Netzwerk
AC · Komplexität Gering
PR · Privilegien Keine
UI · Interaktion Keine
S · Scope Unverändert
C · Vertraulichkeit Hoch
I · Integrität Keine
A · Verfügbarkeit Keine
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Veröffentlicht:04.05.2020
Aktualisiert:17.06.2026 02:52
Assigner (CNA):NVD
Quellen: 🇪🇺 EUVD-Datenbank (ENISA) + 🇺🇸 NVD-Anreicherung · 24-h-Cache
CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

354k+ 🇪🇺 EUVD-Datenbank
19 🔴 Critical im Radar
11 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
0 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-09: 164 2025-10: 316 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 418 2026-03: 652 2026-04: 574 2026-05: 683 2026-06: 942 2026-07: 1333 2026-08: 1329 7.525 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-08-292026-09-13
≥90 %40
≥50 %40
≥10 %30
<10 %304300
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Generic Security 44
Microsoft 7
Linux 3
Cisco 3
Adobe 2
Google 1
Schweregrad & Status:
Hersteller (Datenbank-weit, 90.597 Einträge):
Quelle:
🔍
7.5 HIGH
EPSS 24.2%
CVE-2026-64826 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-64826 | rConfig up to 8.2.12 download_export filename path traversal

A vulnerability labeled as problematic has been found in rConfig up to 8.2.12. Affected by this issue is the function download_export. The manipulation of the argument filename results in path traversal. This vulnerability is known as CVE-2

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.7%
CVE-2026-73490 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73490 | Flavorjones Loofah up to 2.25.1 HTML5 Sanitizer cross-domain policy

A vulnerability has been found in Flavorjones Loofah up to 2.25.1 and classified as problematic. This affects an unknown function of the component HTML5 Sanitizer. This manipulation causes permissive cross-domain policy with untrusted domai

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.7%
CVE-2026-73427 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73427 | Basecamp Trix up to 2.1.17 StringPiece.fromJSON cross site scripting

A vulnerability, which was classified as problematic, was found in Basecamp Trix up to 2.1.17. The impacted element is the function StringPiece.fromJSON. The manipulation results in cross site scripting. This vulnerability is identified as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.7%
CVE-2026-73430 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-73430 | Eugeny Russh up to 0.62.3 Key Exchange curve25519.rs Curve25519Kex::server_dh unusual condition

A vulnerability described as problematic has been identified in Eugeny Russh up to 0.62.3. This vulnerability affects the function Curve25519Kex::server_dh of the file russh/src/kex/curve25519.rs of the component Key Exchange. Such manipula

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 25.6%
CVE-2026-73429 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73429 | Eugeny russh up to 0.62.3 Curve25519 curve25519.rs compute_shared_secret out-of-bounds

A vulnerability marked as problematic has been reported in Eugeny russh up to 0.62.3. This affects the function Curve25519Kex::compute_shared_secret of the file russh/src/kex/curve25519.rs of the component Curve25519. This manipulation caus

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.7%
CVE-2026-73418 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73418 | nextauthjs next-auth JWT /core/jwt getToken bearer input validation

A vulnerability was found in nextauthjs next-auth. It has been rated as problematic. This vulnerability affects the function getToken of the file /core/jwt of the component JWT. The manipulation of the argument bearer leads to improper inpu

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.3%
CVE-2026-73425 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73425 | Withastro Astro up to 8.1.1 Image index.ts remotePatternToRegex incorrect regex

A vulnerability was found in Withastro Astro up to 8.1.1. It has been declared as critical. This affects the function remotePatternToRegex of the file packages/integrations/netlify/src/index.ts of the component Image Handler. Such manipulat

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.7%
CVE-2026-73419 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73419 | nextauthjs next-auth/core OAuth/OIDC Anti-CSRF Check cross-site request forgery

A vulnerability described as problematic has been identified in nextauthjs next-auth and core. Affected by this vulnerability is an unknown functionality of the component OAuth/OIDC Anti-CSRF Check. The manipulation results in cross-site re

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.8%
CVE-2026-73423 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73423 | withastro Astro up to 7.0.5 Hono Pipeline ActionHandler.handle cross-site request forgery

A vulnerability marked as problematic has been reported in withastro Astro up to 7.0.5. Affected is the function ActionHandler.handle of the component Hono Pipeline. The manipulation leads to cross-site request forgery. This vulnerability i

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.2%
CVE-2026-73422 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73422 | withastro Astro up to 7.0.x View Transition CSS Generator transition.ts renderTransition cross site scripting

A vulnerability labeled as problematic has been found in withastro Astro up to 7.0.x. This impacts the function renderTransition of the file packages/astro/src/runtime/server/transition.ts of the component View Transition CSS Generator. Exe

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.1%
CVE-2026-49467 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-49467 | smp46 Pingvin Share X up to 1.18.0 TOTP Settings auth.service.ts authenticateUser improper synchronization

A vulnerability was found in smp46 Pingvin Share X up to 1.18.0. It has been rated as critical. This impacts the function authenticateUser of the file auth.service.ts of the component TOTP Settings. The manipulation leads to improper synchr

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.2%
CVE-2026-73415 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73415 | Jupyter JupyterLab up to 4.5.9/4.6.1 ImageViewer widget.ts cross site scripting

A vulnerability classified as problematic was found in Jupyter JupyterLab up to 4.5.9/4.6.1. The impacted element is an unknown function of the file packages/imageviewer/src/widget.ts of the component ImageViewer. Executing a manipulation c

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.8%
CVE-2026-73414 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73414 | ericcornelissen Shescape up to 2.1.13/3.0.0 src/internal/win/cmd.js getEscapeFunction os command injection

A vulnerability described as critical has been identified in ericcornelissen Shescape up to 2.1.13/3.0.0. Impacted is the function getEscapeFunction of the file src/internal/win/cmd.js. Such manipulation leads to os command injection. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.1%
CVE-2026-73413 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73413 | ericcornelissen Shescape up to 2.1.13/3.0.0 src/internal/compose.js compose resource consumption

A vulnerability marked as problematic has been reported in ericcornelissen Shescape up to 2.1.13/3.0.0. This issue affects the function compose of the file src/internal/compose.js. This manipulation causes resource consumption. The identifi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.9%
CVE-2026-73412 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73412 | ericcornelissen Shescape up to 2.1.13/3.0.0 escape output

A vulnerability labeled as problematic has been found in ericcornelissen Shescape up to 2.1.13/3.0.0. This vulnerability affects the function escape. The manipulation results in escaping of output. This vulnerability was named CVE-2026-7341

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 6.3%
CVE-2026-73411 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73411 | ericcornelissen Shescape up to 2.1.13/3.0.0 dash.js getEscapeFunction information disclosure

A vulnerability was found in ericcornelissen Shescape up to 2.1.13/3.0.0. It has been classified as problematic. This impacts the function getEscapeFunction of the file src/internal/unix/dash.js. This manipulation causes information disclos

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.6%
CVE-2026-73294 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73294 | Semaphoreui Semaphore up to 2.18.16/2.19.5-beta1 Git Repository GetLastRemoteCommitHash upload-pack os command injection

A vulnerability, which was classified as problematic, was found in Semaphoreui Semaphore up to 2.18.16/2.19.5-beta1. This impacts the function GetLastRemoteCommitHash of the component Git Repository Handler. Such manipulation of the argumen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.7%
CVE-2026-73299 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-73299 | Microsoft Prompty up to 0.1.4/2.0.0-beta.4 TypeScript Nunjucks Renderer code injection

A vulnerability labeled as critical has been found in Microsoft Prompty up to 0.1.4/2.0.0-beta.4. This issue affects some unknown processing of the component TypeScript Nunjucks Renderer. Executing a manipulation can lead to code injection.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 19.1%
CVE-2026-73292 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73292 | SemaphoreUI Semaphore up to 2.18.20 Password Endpoint cross-site request forgery

A vulnerability was found in SemaphoreUI Semaphore up to 2.18.20. It has been classified as problematic. Affected by this issue is some unknown functionality of the component Password Endpoint. The manipulation leads to cross-site request f

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.7%
CVE-2026-73293 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73293 | SemaphoreUI Semaphore up to 2.18.18/2.19.5-beta4 Role Management /api/project/{id}/roles ProjectMiddleware/GetProjectOrGlobalRoleBySlug privileges management

A vulnerability has been found in SemaphoreUI Semaphore up to 2.18.18/2.19.5-beta4 and classified as problematic. Affected is the function ProjectMiddleware/GetProjectOrGlobalRoleBySlug of the file /api/project/{id}/roles of the component R

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.3%
CVE-2026-68488 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Linux

Plesk Backup Manager Flaw Lets Low-Privileged Users Gain Root Access to Servers

A newly disclosed vulnerability in Plesk Backup Manager could allow low-privileged users to escalate privileges and gain full root access on affected Linux servers. Tracked as CVE-2026-68488, the flaw stems from a symlink race condition dur

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 25.3%
CVE-2026-68488 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Linux

Plesk Backup Manager Flaw Lets Low-Privileged Users Gain Root Access to Servers

A newly disclosed vulnerability in Plesk Backup Manager could allow low-privileged users to escalate privileges and gain full root access on affected Linux servers. Tracked as CVE-2026-68488, the flaw stems from a symlink race condition dur

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 25.3%
CVE-2026-68488 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Linux

Plesk Backup Manager Flaw Lets Low-Privileged Users Gain Root Access to Servers

A newly disclosed vulnerability in Plesk Backup Manager could allow low-privileged users to escalate privileges and gain full root access on affected Linux servers. Tracked as CVE-2026-68488, the flaw stems from a symlink race condition dur

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 32.8%
CVE-2026-69414 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

Microsoft-Patchday: 966 Schwachstellen, davon 105 kritisch - BornCity

... Windows 10, Windows 11 und Windows Server zu erlangen. Dabei werde eine frühere Korrektur für die Lücke CVE-2026-69414 umgangen. Microsoft ... Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 27.3%
CVE-2026-51990 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

Sogou Input Method: Chinesische <b>Hacker</b> nutzen CVE-2026-51990 - Börse Express

UNC3569 nutzte CVE-2026-51990 gegen Sogou-Nutzer. Tencent schloss die kritische Lücke im April mit Version 16.3.0.3498. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 89.1%
CVE-2026-42016 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following rep

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.2%
CVE-2026-56711 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Multiple VLC Media Player Vulnerabilities Allow Attackers to Corrupt or Read Heap Memory

Two security vulnerabilities in VLC Media Player could allow attackers to corrupt heap memory or disclose sensitive data from a victim’s memory. The flaws, tracked as CVE-2026-56711 and CVE-2026-73324, affect VLC Media Player versions 3.0.0

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.2%
CVE-2026-56711 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Multiple VLC Media Player Vulnerabilities Allow Attackers to Corrupt or Read Heap Memory

Two security vulnerabilities in VLC Media Player could allow attackers to corrupt heap memory or disclose sensitive data from a victim’s memory. The flaws, tracked as CVE-2026-56711 and CVE-2026-73324, affect VLC Media Player versions 3.0.0

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 💻 Lokal 🔓 Keine Authentifizierung nötig
Microsoft

China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks

China-linked threat actors UTA0560 and JungleBamboo chained a Google Chrome zero-day with a Windows kernel privilege-escalation flaw in phishing campaigns targeting NGOs and other victims. Volexity documented the operations, detected on Sep

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 💻 Lokal 🔓 Keine Authentifizierung nötig
Microsoft

China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks

China-linked threat actors UTA0560 and JungleBamboo chained a Google Chrome zero-day with a Windows kernel privilege-escalation flaw in phishing campaigns targeting NGOs and other victims. Volexity documented the operations, detected on Sep

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 32.1%
CVE-2026-85706 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CISA Warns of Critical GitLab Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab flaw, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog after confirming it was exploited in attacks. The issue affects bot

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.1%
CVE-2026-85706 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CISA Warns of Critical GitLab Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab flaw, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog after confirming it was exploited in attacks. The issue affects bot

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 96.1%
CVE-2026-85706 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CISA Warns of Critical GitLab Path Traversal Flaw Exploited to Read Arbitrary Server Files

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab path traversal vulnerability, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog after evidence that the flaw is being activ

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.1%
CVE-2026-85706 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CISA Warns of GitLab Path Traversal Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab vulnerability, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog, warning that attackers are actively exploiting the flaw.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.1%
CVE-2026-85706 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CISA Warns of GitLab Path Traversal Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab vulnerability, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog, warning that attackers are actively exploiting the flaw.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 25.9%
CVE-2026-20079 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Cisco

Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

Ravie LakshmananSep 11, 2026Vulnerability / Malware Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC)

CWE-287: Improper Authentication ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Management-Interface vom Internet trennen und ACLs auf vertrauenswürdige IPs beschränken.
10.0 CRITICAL
EPSS 79.1%
CVE-2026-85706 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

GitLab schließt CVE-2026-85706 mit CVSS 10, aktive In-the-Wild-Probes

LONDON (IT BOLTWISE) – GitLab hat mehrere Sicherheitslücken gepatcht, darunter eine Schwachstelle mit CVSS 10,0 (CVE-2026-85706), die bereits innerhalb von Stunden nach der Veröffentlichung von Angreifern abgefragt wurde. Betroffen sind bes

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.2%
CVE-2026-56711 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC Media Player could enable attackers to corrupt memory or extract sensitive data from affected systems by persuading users to open a specially crafted image file or media playlist. The flaws, tracked as CV

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 90.3%
CVE-2026-86060 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CISA Warns MikroTik RouterOS Flaw Is Exploited to Escalate Privileges

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical MikroTik RouterOS privilege-escalation vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, warning that the flaw is being actively exploit

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.2%
CVE-2026-56711 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0 through 3.0.23 could allow attackers to exploit heap memory issues. These vulnerabilities can be triggered by processing a malicious PNG file or connecting to attacker-controll

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.2%
CVE-2026-56711 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0 through 3.0.23 could allow attackers to exploit heap memory issues. These vulnerabilities can be triggered by processing a malicious PNG file or connecting to attacker-controll

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 89.7%
CVE-2026-67277 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, warning that these flaws are actively being exploited in the wild. On

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 89.7%
CVE-2026-67277 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, warning that these flaws are actively being exploited in the wild. On

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.5 CRITICAL
EPSS 79.9%
CVE-2026-65638 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security &amp;amp; Firewall (CSF) could allow unauthenticated remote attackers to execute arbitrary commands through the product’s MESSENGER service. This vulnerability, tracked as CVE-2026

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.5 CRITICAL
EPSS 79.9%
CVE-2026-65638 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security &amp;amp; Firewall (CSF) could allow unauthenticated remote attackers to execute arbitrary commands through the product’s MESSENGER service. This vulnerability, tracked as CVE-2026

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.5 CRITICAL
EPSS 74.6%
CVE-2026-85102 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Check Point Patches Critical VPN Vulnerabilities

Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution. The post Check Point Patches Critical VPN Vulnerabilities appeared first on SecurityWeek. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.5 CRITICAL
EPSS 57.9%
CVE-2026-20079 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Cisco

Attackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware

Three threat groups are exploiting two Cisco FMC flaws to steal credentials, gain root access and deploy Qilin ransomware. Cisco Talos says three separate threat groups are exploiting two recently patched Secure Firewall Management Center (

CWE-287: Improper Authentication ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Management-Interface vom Internet trennen und ACLs auf vertrauenswürdige IPs beschränken.
9.5 CRITICAL
EPSS 79.9%
CVE-2026-65638 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Critical ConfigServer Security &amp; Firewall Flaw Lets Remote Attackers Execute Arbitrary Commands

A critical vulnerability in ConfigServer Security &amp;amp; Firewall (CSF) could allow unauthenticated remote attackers to execute arbitrary commands on vulnerable servers. Tracked as CVE-2026-65638, the flaw affects CSF versions 14.00 thro

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.5 CRITICAL
EPSS 56.1%
CVE-2026-75650 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Adobe

Imperva Customers Protected Against StyleSmuggler (CVE-2026-75650) in Adobe Commerce and Magento Open Source

TL;DR: CVE-2026-75650, dubbed StyleSmuggler, is a critical vulnerability affecting Adobe Commerce and Magento Open Source. The vulnerability allows an unauthenticated attacker to inject malicious PHP code into Magento’s template system and

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

[UPDATE] [mittel] Golang Go "FIPS OpenSSL": Schwachstelle ermöglicht nicht spezifizierten Angriff

Ein lokaler Angreifer kann eine Schwachstelle in der Golang Go Komponente &quot;FIPS OpenSSL&quot; ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

[NEU] [mittel] Fortra GoAnywhere MFT: Schwachstelle ermöglicht Offenlegung von Informationen

Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Fortra GoAnywhere MFT ausnutzen, um Informationen offenzulegen. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

[NEU] [hoch] GeoNetwork: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen

Ein entfernter, anonymer Angreifer kann eine Schwachstelle in GeoNetwork ausnutzen, um Sicherheitsvorkehrungen zu umgehen und so Daten offenzulegen oder zu manipulieren. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

[NEU] [hoch] Palo Alto Networks Cortex XDR Broker VM: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit Administratorrechten

Ein Angreifer aus einem angrenzenden Netzwerk kann eine Schwachstelle in Palo Alto Networks Cortex XDR Broker VM ausnutzen, um beliebigen Programmcode mit Administratorrechten auszuführen. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 2.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

[NEU] [niedrig] Laravel: Schwachstelle ermöglicht Cross-Site Scripting

Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Laravel ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen. Weiterlesen

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.1%
CVE-2026-75650 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

U.S. CISA adds Microsoft Windows, N-able N-central, and Adobe flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft Windows, N-able N-central, and Adobe flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added th

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
9.5 CRITICAL
EPSS 57.9%
CVE-2026-20079 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Cisco

Active exploitation of Cisco Secure Firewall Management Center vulnerabilities

Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software. First, CVE-2026-20079 is an authentication bypass vulnerability in unpatched instances of Cisco’s Secure F

CWE-287: Improper Authentication ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Management-Interface vom Internet trennen und ACLs auf vertrauenswürdige IPs beschränken.
9.8 CRITICAL
⚠️ KEV
EPSS 87.1%
CVE-2026-81963 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities

Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as &quot;critical.&quot;Microsoft notes that 2 of the vulnerabiliti

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

N-able issues patch for zero-day flaw

Security researchers warned the company of unusual threat activity in a recently patched N-able environment. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Adobe

Attackers Exploit Unpatched Magento Zero-Day to Backdoor Online Stores

Attackers are exploiting an unpatched remote code execution flaw in Adobe Commerce and Magento Open Source to install persistent backdoors on e-commerce sites, Dutch security firm Sansec reported, with the first intrusions observed Sept. 4

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Nightmare Eclipse drops a CrowdStrike zero-day.

Extortion group leaks alleged Manchester Airports Group data. France&#039;s CNIL fines hospital over 2025 data breach. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.