Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-14 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
Hackers Actively Exploiting Gitea n-day RCE Vulnerability in the Wild to Hijack Instances
Hackers are actively exploiting a critical Gitea remote code execution vulnerability, tracked as CVE-2026-60004, to compromise internet-facing source-code management servers. Researchers found that a Chinese-speaking threat actor, named Red
[UPDATE] [hoch] WebKitGTK: Schwachstelle ermöglicht Codeausführung
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in WebKitGTK ausnutzen, um eine Speicherbeschädigung zu verursachen und möglicherweise beliebigen Code auszuführen oder einen Denial-of-Service-Zustand auszulösen. Weiterlesen
[UPDATE] [mittel] rsyslog: Schwachstelle ermöglicht Denial of Service
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in rsyslog ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen
[UPDATE] [niedrig] GIMP: Schwachstelle ermöglicht Denial of Service und Offenlegung von Informationen
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in GIMP ausnutzen, um einen Denial of Service Angriff durchzuführen, und um Informationen offenzulegen. Weiterlesen
[UPDATE] [hoch] libTIFF: Schwachstelle ermöglicht Codeausführung
Ein Angreifer kann eine Schwachstelle in libTIFF ausnutzen, um beliebigen Programmcode auszuführen. Weiterlesen
[UPDATE] [hoch] WebKitGTK: Schwachstelle ermöglicht Codeausführung
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in WebKitGTK ausnutzen, um eine Speicherbeschädigung herbeizuführen, was möglicherweise die Ausführung von Code oder einen Denial-of-Service-Zustand ermöglicht. Weiterlesen
Marimo RCE Flaw Lets Hackers Steal AWS Credentials and Pivot to Bastion Host in 8 Seconds
A threat actor exploited a critical pre-authentication remote code execution vulnerability in marimo to harvest AWS credentials, retrieve an SSH private key from AWS Secrets Manager, and authenticate to a bastion host in just eight seconds,
Hackers Actively Exploiting Gitea n-day RCE Vulnerability in the Wild to Hijack Instances
Hackers are actively exploiting a critical Gitea remote code execution vulnerability, tracked as CVE-2026-60004, to compromise internet-facing source-code management servers. Researchers found that a Chinese-speaking threat actor, named Red
Hackers Actively Exploiting Gitea n-day RCE Vulnerability in the Wild to Hijack Instances
Hackers are actively exploiting a critical Gitea remote code execution vulnerability, tracked as CVE-2026-60004, to compromise internet-facing source-code management servers. Researchers found that a Chinese-speaking threat actor, named Red
Marimo RCE Flaw Lets Hackers Steal AWS Credentials and Pivot to Bastion Host in 8 Seconds
A threat actor exploited a critical pre-authentication remote code execution vulnerability in marimo to harvest AWS credentials, retrieve an SSH private key from AWS Secrets Manager, and authenticate to a bastion host in just eight seconds,
Marimo RCE Flaw Lets Hackers Steal AWS Credentials and Pivot to Bastion Host in 8 Seconds
A threat actor exploited a critical pre-authentication remote code execution vulnerability in marimo to harvest AWS credentials, retrieve an SSH private key from AWS Secrets Manager, and authenticate to a bastion host in just eight seconds,
CVE-2026-86087 | IBM Db2 up to 11.5.9/12.1.5 file inclusion (WID-SEC-2026-3308)
A vulnerability was found in IBM Db2 up to 11.5.9/12.1.5. It has been declared as problematic. This vulnerability affects unknown code. The manipulation results in file inclusion. This vulnerability is known as CVE-2026-86087. It is possibl
CVE-2026-87958 | IBM Db2 up to 11.5.9/12.1.5 denial of service (WID-SEC-2026-3308)
A vulnerability was found in IBM Db2 up to 11.5.9/12.1.5. It has been classified as problematic. This affects an unknown part. The manipulation leads to denial of service. This vulnerability is traded as CVE-2026-87958. It is possible to in
CVE-2026-86093 | IBM Db2 up to 11.5.9/12.1.5 buffer overflow (WID-SEC-2026-3308)
A vulnerability was found in IBM Db2 up to 11.5.9/12.1.5 and classified as very critical. Affected by this issue is some unknown functionality. Executing a manipulation can lead to buffer overflow. This vulnerability appears as CVE-2026-860
CVE-2026-41586 | hyperledger fabric up to 2.2.26 Channel.java readObject deserialization (WID-SEC-2026-3308)
A vulnerability labeled as critical has been found in hyperledger fabric up to 2.2.26. This affects the function readObject of the file Channel.java. Executing a manipulation can lead to deserialization. This vulnerability appears as CVE-20
CVE-2026-17463 | IBM Db2 up to 11.5.9/12.1.5 resource consumption (WID-SEC-2026-3308)
A vulnerability classified as critical was found in IBM Db2 up to 11.5.9/12.1.5. Affected by this issue is some unknown functionality. Executing a manipulation can lead to resource consumption. This vulnerability is registered as CVE-2026-1
CVE-2026-16702 | IBM Db2 up to 11.5.9/12.1.5 null pointer dereference (WID-SEC-2026-3308)
A vulnerability, which was classified as critical, has been found in IBM Db2 up to 11.5.9/12.1.5. This affects an unknown part. The manipulation leads to null pointer dereference. This vulnerability is documented as CVE-2026-16702. The atta
CVE-2026-53587 | libgit2 up to 1.8.5/1.9.4 Smart Protocol Transport smart_pkt.c set_data input validation (Nessus ID 345712 / WID-SEC-2026-3333)
A vulnerability described as problematic has been identified in libgit2 up to 1.8.5/1.9.4. This affects the function set_data of the file src/libgit2/transports/smart_pkt.c of the component Smart Protocol Transport. The manipulation results
WooCommerce Plugin Bug Lets Remote Attackers Create Admin Accounts and Take Over Sites
A critical security flaw in the WooCommerce Wholesale Lead Capture plugin is being actively exploited, allowing remote attackers to upload malicious files and potentially take full control of vulnerable WordPress sites. The vulnerability, t
[UPDATE] [mittel] Red Hat Enterprise Linux (libgit2): Schwachstelle ermöglicht Denial of Service
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen
[UPDATE] [mittel] memcached: Schwachstelle ermöglicht Denial of Service
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in memcached ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen
Hackers Exploit Marimo RCE to Steal AWS Credentials and Reach Bastion Host in 8 Seconds
Threat actors have been observed exploiting a critical remote code execution vulnerability in the Marimo notebook platform to steal AWS credentials and authenticate to an SSH bastion host within eight seconds. The attack, documented by the
Hackers Exploit Marimo RCE to Steal AWS Credentials and Reach Bastion Host in 8 Seconds
Threat actors have been observed exploiting a critical remote code execution vulnerability in the Marimo notebook platform to steal AWS credentials and authenticate to an SSH bastion host within eight seconds. The attack, documented by the
Marimo RCE Flaw Lets Hackers Steal AWS Credentials and Pivot to Bastion Host in 8 Seconds
A threat actor exploited a pre-authentication remote code execution flaw in marimo to harvest AWS credentials, retrieve an SSH private key from AWS Secrets Manager, and authenticate to a bastion host in eight seconds. Tracked as CVE-2026-39
CVE-2026-76461 bei Cisco Secure Email Gateway: Root-Command-Ausführung aktiv ausgenutzt
LONDON (IT BOLTWISE) – Cisco warnt vor einer kritischen Schwachstelle in der AsyncOS-Implementierung des Cisco Secure Email Gateway, die bereits aktiv ausgenutzt wird. Die Lücke mit der Kennung CVE-2026-76461 erreicht einen CVSS-Wert von 9,
Schwachstelle in LiteSpeed Enterprise: Root-Zugriff für Shared-Hosting-Accounts möglich
LONDON (IT BOLTWISE) – Eine kritische Sicherheitslücke in LiteSpeed Web Server Enterprise könnte es Nutzern mit niedrigem Privileg auf Shared-Hosting-Servern ermöglichen, Root-Zugriff zu erlangen. Betroffen sind Versionen vor 6.3.7; cPanel
Cisco AsyncOS: CVE-2026-76461 wird aktiv ausgenutzt – Patch bis 17. September 2026
LONDON (IT BOLTWISE) – Cisco warnt, dass die Lücke in AsyncOS für den Secure Email Gateway bereits aktiv ausgenutzt wird. Die Schwachstelle CVE-2026-76461 (CVSS 9,8/10) kann laut Hersteller einem unauthentifizierten Angreifer das Ausführen
Linux Kernel ZcopyReaper Vulnerability Lets Local Attackers Gain Root Privileges
Security researchers have disclosed a local privilege escalation vulnerability in the Linux kernel related to the Reliable Datagram Sockets (RDS) zero-copy send path. This vulnerability could let an unprivileged local attacker gain root pri
Linux Kernel ZcopyReaper Vulnerability Lets Local Attackers Gain Root Privileges
Security researchers have disclosed a local privilege escalation vulnerability in the Linux kernel related to the Reliable Datagram Sockets (RDS) zero-copy send path. This vulnerability could let an unprivileged local attacker gain root pri
Non-Zero-Day VPN Flaw Left Japan ‘s Government Shared Network Platform Exposed: 246,000 Records at Risk
Japan ‘s Digital Agency disclosed a VPN breach exposing 246,000 government employee records across 23 ministries. Detected June 25, publicly disclosed September 11. Japan ‘s Digital Agency disclosed that attackers exploited a vulnerability
GRIMWEDGE nutzt Chrome-Windows Patch-Gap: Mehrstufige Zero-Day Kette im Fokus
LONDON (IT BOLTWISE) – Ein von Volexity beobachteter chinesisch zugeordneter Angriffscluster nutzt eine Spear-Phishing-Kampagne, um eine mehrstufige Zero-Day-Chain aus Chrome- und Windows-Schwächen auszulösen. Der Einstieg erfolgt über eine
Nintendo Switch Vulnerability Lets Nearby Attackers Run Unauthorized Code via QR Codes
Nintendo has patched a high-severity vulnerability in the Nintendo Switch that could allow nearby attackers to execute unauthorized code or access information stored on affected consoles by abusing QR-code-based local wireless connections.
GRIMWEDGE & BlueMoon: Chrome-Windows-Zero-Day-Kette über reflektiertes XSS
LONDON (IT BOLTWISE) – Forschende ordnen einen Spear-Phishing-Angriff zu, der eine reflektierte XSS-Schwachstelle auf einer U.S.-Uni-Webseite missbraucht. Die Angreifer kombinieren drei zuvor gepatchte Lücken in Google Chrome und Windows, u
Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation
An unauthenticated attacker can exploit CVE-2026-76461 to execute arbitrary commands on the underlying OS with root privileges. The post Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation appeared first on SecurityWee
A maximum severity GitLab flaw could turn your CI/CD server into an attacker’s treasure trove
Yet another security vulnerability has been discovered in GitLab infrastructure, this one a perfect 10 in severity. CVE-2026-85706, the second flaw GitLab has disclosed in just a month, is a maximum-severity vulnerability that allows attack
A maximum severity GitLab flaw could turn your CI/CD server into an attacker’s treasure trove
Yet another security vulnerability has been discovered in GitLab infrastructure, this one a perfect 10 in severity. CVE-2026-85706, the second flaw GitLab has disclosed in just a month, is a maximum-severity vulnerability that allows attack
Angriffe auf öffentlich erreichbare Vite-Dev-Server: Hacker suchen AWS- und Azure-Geheimnisse
LONDON (IT BOLTWISE) – Eine groß angelegte Scanning-Kampagne zielt auf öffentlich erreichbare Vite-Entwicklungsserver. Laut F5 missbrauchen Angreifer eine Schwachstelle CVE-2026-39364, um Datei- und Zugriffsbeschränkungen zu umgehen und sen
Red Heron nutzt Gitea-RCE und Rootkit SIXZUT für 13 kompromittierte Ziele
LONDON (IT BOLTWISE) – Ein mutmaßlich China-gebundenes Akteurscluster soll eine neu offengelegte Schwachstelle in Gitea (CVE-2026-60004) schnell zu einem automatisierten Angriffsframework ausgebaut haben. Dabei wird von 1.386 gescannten Git
GitLab warnt nach „In-the-wild“-Hinweisen vor Path-Traversal (CVE-2026-85706)
LONDON (IT BOLTWISE) – Hinweise auf „In-the-wild“-Ausnutzung rücken eine GitLab-Schwachstelle mit maximaler Kritikalität in den Fokus. Betroffen ist CVE-2026-85706, das Angreifern unter bestimmten Bedingungen den Zugriff auf beliebige Datei
September Patch Tuesday: 963 CVEs, 2 exploited flaws, 1 message
Microsoft’s September 2026 Patch Tuesday is the year’s largest release, with 963 CVEs requiring customer action, 106 rated critical. Two are already exploited: CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Advanced Local
[NEU] [mittel] Microsoft Edge: Schwachstelle ermöglicht Cross-Site Scripting
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Microsoft Edge ausnutzen, um einen Spoofing- und einen Cross-Site-Scripting-Angriff durchzuführen. Weiterlesen
[NEU] [mittel] wpa_supplicant: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
Ein lokaler Angreifer kann eine Schwachstelle in wpa_supplicant ausnutzen, um Sicherheitsvorkehrungen zu umgehen. Weiterlesen
[NEU] [mittel] Puppet Enterprise: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit Administratorrechten
Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Puppet Enterprise ausnutzen, um beliebigen Programmcode mit Administratorrechten auszuführen, was zu einer vollständigen Kompromittierung des Systems führt. Weiterlesen
[NEU] [UNGEPATCHT] [mittel] Net-SNMP: Schwachstelle ermöglicht Denial of Service
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Net-SNMP ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen
[NEU] [niedrig] libarchive: Schwachstelle ermöglicht Denial of Service
Ein lokaler Angreifer kann eine Schwachstelle in libarchive ausnutzen, um den Speicher zu beschädigen und einen Denial-of-Service-Zustand herbeizuführen. Weiterlesen
[NEU] [mittel] FRRouting Project FRRouting: Schwachstelle ermöglicht Privilegieneskalation
Ein lokaler Angreifer kann eine Schwachstelle in FRRouting Project FRRouting ausnutzen, um seine Privilegien zu erhöhen. Weiterlesen
[NEU] [mittel] Red Hat Certificate System for RHEL (Dogtag PKI): Schwachstelle ermöglicht Offenlegung von Informationen
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Certificate System und Red Hat Enterprise Linux ausnutzen, um Informationen offenzulegen. Weiterlesen
Logitech Options+ flaw lets attackers gain Windows SYSTEM privileges
A vulnerability in Logitech Options+ allows a standard Windows user to gain SYSTEM-level privileges by exploiting a weakness in the software’s updater service. Tracked as CVE-2026-12518, the issue requires no administrator rights, network a
[NEU] [UNGEPATCHT] [niedrig] CUPS: Schwachstelle ermöglicht Codeausführung
Ein lokaler Angreifer kann eine Schwachstelle in CUPS ausnutzen, um beliebigen Programmcode auszuführen. Weiterlesen
[NEU] [mittel] HAProxy: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in HAProxy ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Daten zu manipulieren und einen Denial-of-Service-Zustand auszulösen. Weiterlesen
[NEU] [hoch] Strapi: Schwachstelle ermöglicht Cross-Site Scripting
Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Strapi ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen. Weiterlesen
Nintendo warns of Switch code execution flaw via on-screen QR codes
Nintendo has patched a high-severity Nintendo Switch vulnerability that could allow a nearby attacker to execute unauthorized code or access information stored on the console. The flaw, tracked as CVE-2026-82079, affects Switch systems runn
[UPDATE] [mittel] WithSecure Endpoint Protection: Schwachstelle ermöglicht Denial of Service
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in WithSecure Endpoint Protection ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen
CISA warnt: GitLab-Schlagloch CVE-2026-85706 aktiv ausgenutzt
USA / LONDON (IT BOLTWISE) – Die US-Cybersicherheitsbehörde CISA meldet, dass Angreifer eine GitLab-Sicherheitslücke maximaler Schwere (CVE-2026-85706) bereits ausnutzen. Betroffen ist ein DevSecOps-Feature, bei dem fehlende Authentifizieru
GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read – Exploited Within 24 Hours
CVE-2026-85706, a CVSS 10.0 GitLab path traversal, was under active exploitation within 24 hours of disclosure. GitLab disclosed CVE-2026-85706 (CVSS score of 10.0) on September 10, 2026, a path traversal vulnerability in its repository com
Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
Ravie LakshmananSep 11, 2026Vulnerability / Malware Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC)
Imperva Customers Protected Against StyleSmuggler (CVE-2026-75650) in Adobe Commerce and Magento Open Source
TL;DR: CVE-2026-75650, dubbed StyleSmuggler, is a critical vulnerability affecting Adobe Commerce and Magento Open Source. The vulnerability allows an unauthenticated attacker to inject malicious PHP code into Magento’s template system and
Active exploitation of Cisco Secure Firewall Management Center vulnerabilities
Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software. First, CVE-2026-20079 is an authentication bypass vulnerability in unpatched instances of Cisco’s Secure F
Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."Microsoft notes that 2 of the vulnerabiliti
Nightmare Eclipse drops a CrowdStrike zero-day.
Extortion group leaks alleged Manchester Airports Group data. France's CNIL fines hospital over 2025 data breach. Weiterlesen