🎯 CVE-2023-40657 MEDIUM 6.1 🔥 EPSS 2.1%
📄 .md Alle CVEs anzeigen ✕

CVE-2023-40657: Schwachstellen-Eintrag (NVD)

A reflected XSS vulnerability was discovered in the Joomdoc component for Joomla.

Klassifikation & Betroffenheit:
artio joomdoc *
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 🎯 High

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

🛡️ Empfohlene Mitigation: Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid [REF-1482]. Examples of libraries and frameworks that make it easier to generate properly encoded output include Microsoft's Anti-XSS library, the OWASP ESAPI Encoding module, and …
Vollständige Definition bei MITRE ➔
📚 Referenzen & Quellen:
Ausnutzungs-Zeitleiste:
CVSS-Vektor-Analyse: 6.1
AV · Angriffsvektor Netzwerk
AC · Komplexität Gering
PR · Privilegien Keine
UI · Interaktion Erforderlich
S · Scope Verändert
C · Vertraulichkeit Gering
I · Integrität Gering
A · Verfügbarkeit Keine
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Veröffentlicht:14.12.2023
Aktualisiert:17.06.2026 06:18
Assigner (CNA):NVD
Quellen: 🇪🇺 EUVD-Datenbank (ENISA) + 🇺🇸 NVD-Anreicherung · 24-h-Cache
CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

354k+ 🇪🇺 EUVD-Datenbank
17 🔴 Critical im Radar
5 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
0 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-09: 164 2025-10: 316 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 418 2026-03: 652 2026-04: 574 2026-05: 683 2026-06: 942 2026-07: 1333 2026-08: 1329 7.525 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-08-292026-09-13
≥90 %40
≥50 %40
≥10 %30
<10 %304300
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Schweregrad & Status:
Hersteller (Datenbank-weit, 90.597 Einträge):
Quelle:
🔍
7.5 HIGH
EPSS 19.5%
CVE-2026-16826 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-16826 | IBM i 7.3/7.4/7.5/7.6 os command injection

A vulnerability labeled as very critical has been found in IBM i 7.3/7.4/7.5/7.6. This affects an unknown part. Such manipulation leads to os command injection. This vulnerability is listed as CVE-2026-16826. The attack must be carried out

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.6%
CVE-2026-17270 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-17270 | IBM i 7.3/7.4/7.5/7.6 buffer overflow

A vulnerability identified as critical has been detected in IBM i 7.3/7.4/7.5/7.6. Affected by this issue is some unknown functionality. This manipulation causes buffer overflow. This vulnerability is tracked as CVE-2026-17270. The attack i

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.8%
CVE-2026-9736 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-9736 | IBM Netezza Software up to 11.3.0.3 (EUVD-2026-70744)

A vulnerability has been found in IBM Netezza Software up to 11.3.0.3 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to an unknown weakness. This vulnerability is uniquely identif

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 4.5%
CVE-2026-17442 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-17442 | IBM App Connect Enterprise/Integration Bus for z/OS information disclosure

A vulnerability categorized as problematic has been discovered in IBM App Connect Enterprise, Integration Bus for z and OS. Affected by this vulnerability is an unknown functionality. The manipulation results in information disclosure. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 5.5%
CVE-2026-17255 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-17255 | IBM i 7.3/7.4/7.5/7.6 ICMPv6 denial of service

A vulnerability categorized as critical has been discovered in IBM i 7.3/7.4/7.5/7.6. This affects an unknown function of the component ICMPv6. Executing a manipulation can lead to denial of service. This vulnerability is tracked as CVE-202

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.8%
CVE-2026-85664 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-85664 | chroma-core Chroma up to 1.5.9 HNSW Index max_neighbors/ef_construction/ef_search allocation of resources

A vulnerability, which was classified as problematic, was found in chroma-core Chroma up to 1.5.9. The impacted element is an unknown function of the component HNSW Index. Such manipulation of the argument max_neighbors/ef_construction/ef_s

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27%
CVE-2026-85528 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-85528 | Snowflake JDBC Driver up to 4.3.3 connections.toml Account input validation

A vulnerability categorized as problematic has been discovered in Snowflake JDBC Driver up to 4.3.3. This affects an unknown function of the file connections.toml. Such manipulation of the argument Account leads to improper input validation

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.3%
CVE-2026-74237 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-74237 | GFI Exinda AI up to 7.6.4 Iperf Client web_tools_cmd server/options argument injection

A vulnerability, which was classified as problematic, has been found in GFI Exinda AI up to 7.6.4. This affects the function web_tools_cmd of the component Iperf Client. This manipulation of the argument server/options causes argument injec

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.3%
CVE-2026-9744 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-9744 | IBM Netezza Software up to 11.3.0.3 certificate validation (EUVD-2026-70746)

A vulnerability was found in IBM Netezza Software up to 11.3.0.3 and classified as problematic. This affects an unknown part. The manipulation results in improper certificate validation. This vulnerability was named CVE-2026-9744. The attac

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.3%
CVE-2026-85525 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-85525 | Snowflake Go Driver prior 4.7.3 certificate validation

A vulnerability, which was classified as problematic, was found in Snowflake Go Driver, JDBC Driver, Node.js Driver and Python Connector. This affects an unknown part. Such manipulation leads to improper certificate validation. This vulnera

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19%
CVE-2026-90893 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90893 | CIRCL MISP up to 2.5.45 UserSettingsController setHomePage cross-site request forgery (979337b18 / EUVD-2026-77341)

A vulnerability identified as problematic has been detected in CIRCL MISP up to 2.5.45. This impacts the function setHomePage of the component UserSettingsController. This manipulation causes cross-site request forgery. The identification o

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.6%
CVE-2026-90702 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90702 | D-Link DWR-M921 1.1.52 /boafrm/formDiskFormat system partition os command injection (EUVD-2026-77343)

A vulnerability, which was classified as very critical, has been found in D-Link DWR-M921 1.1.52. Impacted is the function system of the file /boafrm/formDiskFormat. This manipulation of the argument partition causes os command injection. T

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 29.8%
CVE-2026-90701 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90701 | subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578 listdoctor.php searchtext sql injection (EUVD-2026-77342)

A vulnerability was found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. It has been classified as critical. The affected element is an unknown function of the file listdoctor.php. Performing

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.6%
CVE-2026-82764 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-82764 | Contec FXA5000 cross-site request forgery (EUVD-2026-77218)

A vulnerability identified as problematic has been detected in Contec FXA5000, FXA5020, FXA5020-, FXE5000, FXE5000-, FXS5000-, FXS5021, FXE4000, FXE4000-WP, FXS4000, FXS4020, FXA3000, FXA3000-, FXA3020, FXA3020-, FXA3200, FXA3200-, FXE3000,

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.5%
CVE-2026-90895 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90895 | MISP up to 2.5.45 CLI Shell FeedsController::view access control (EUVD-2026-77344)

A vulnerability was found in MISP up to 2.5.45. It has been declared as critical. This impacts the function FeedsController::view of the component CLI Shell. The manipulation results in improper access controls. This vulnerability is known

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.7%
CVE-2026-90894 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90894 | Parallels Desktop up to 26.4.0/27.0.0 prl_disp_service prl_disp_service.socket PrlSrv_InstallAppliance sVmParentPath os command injection (EUVD-2026-77346)

A vulnerability was found in Parallels Desktop up to 26.4.0/27.0.0. It has been rated as very critical. Affected is the function PrlSrv_InstallAppliance of the file /var/run/prl_disp_service.socket of the component prl_disp_service. This ma

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22%
CVE-2026-90703 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90703 | D-Link DWR-M921 1.1.52 formDiskCreateShare system folderpath os command injection (EUVD-2026-77345)

A vulnerability, which was classified as very critical, was found in D-Link DWR-M921 1.1.52. The affected element is the function system of the file /boafrm/formDiskCreateShare. Such manipulation of the argument folderpath leads to os comma

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.5 CRITICAL
EPSS 78.7%
CVE-2026-3854 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

GitHub Pays $100,000 Bounty for Critical RCE Flaw in Git Push Pipeline

GitHub has awarded security researcher Saif Ghani a $100,000 bug bounty after the disclosure of CVE-2026-3854, a critical remote code execution vulnerability affecting GitHub’s Git push processing pipeline. The reward is reportedly the larg

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 6.1%
CVE-2026-87439 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-87439 | Google Chrome up to 152.0.7977.82 ServiceWorker information disclosure (WID-SEC-2026-3238)

A vulnerability, which was classified as problematic, has been found in Google Chrome. Impacted is an unknown function of the component ServiceWorker. The manipulation leads to information disclosure. This vulnerability is uniquely identifi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.3%
CVE-2026-87438 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-87438 | Google Chrome up to 152.0.7977.82 WebGL out-of-bounds write (Nessus ID 343962 / WID-SEC-2026-3238)

A vulnerability was found in Google Chrome. It has been declared as critical. The impacted element is an unknown function of the component WebGL. Such manipulation leads to out-of-bounds write. This vulnerability is listed as CVE-2026-87438

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 6%
CVE-2026-87437 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-87437 | Google Chrome up to 152.0.7977.82 Frames information disclosure (WID-SEC-2026-3238)

A vulnerability labeled as problematic has been found in Google Chrome. This vulnerability affects unknown code of the component Frames. Such manipulation leads to information disclosure. This vulnerability is documented as CVE-2026-87437.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.8%
CVE-2026-87436 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-87436 | Google Chrome up to 152.0.7977.82 Browser access control (WID-SEC-2026-3238)

A vulnerability classified as critical was found in Google Chrome. This issue affects some unknown processing of the component Browser. Executing a manipulation can lead to improper access controls. This vulnerability is handled as CVE-2026

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 5.6%
CVE-2026-87435 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-87435 | Google Chrome up to 152.0.7977.82 ControlledFrame information disclosure (WID-SEC-2026-3238)

A vulnerability classified as problematic has been found in Google Chrome. This vulnerability affects unknown code of the component ControlledFrame. Performing a manipulation results in information disclosure. This vulnerability is known as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.3%
CVE-2026-87433 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-87433 | Google Chrome up to 152.0.7977.82 FileAPI race condition (WID-SEC-2026-3238)

A vulnerability marked as critical has been reported in Google Chrome. Affected by this issue is some unknown functionality of the component FileAPI. This manipulation causes race condition. This vulnerability appears as CVE-2026-87433. The

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.3%
CVE-2026-87432 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-87432 | Google Chrome up to 152.0.7977.82 Navigation improper authorization (WID-SEC-2026-3238)

A vulnerability labeled as problematic has been found in Google Chrome. Affected by this vulnerability is an unknown functionality of the component Navigation. The manipulation results in improper authorization. This vulnerability is report

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.2%
CVE-2026-87434 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-87434 | Google Chrome up to 152.0.7977.82 CORS improper authorization (WID-SEC-2026-3238)

A vulnerability described as critical has been identified in Google Chrome. This affects an unknown part of the component CORS. Such manipulation leads to improper authorization. This vulnerability is traded as CVE-2026-87434. The attack ma

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.5%
CVE-2026-87431 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-87431 | Google Chrome up to 152.0.7977.82 Extensions improper authorization (WID-SEC-2026-3238)

A vulnerability identified as problematic has been detected in Google Chrome. Affected is an unknown function of the component Extensions. The manipulation leads to improper authorization. This vulnerability is documented as CVE-2026-87431.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.5%
CVE-2026-87430 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-87430 | Google Chrome up to 152.0.7977.82 WebRTC buffer overflow (WID-SEC-2026-3238)

A vulnerability categorized as critical has been discovered in Google Chrome. This impacts an unknown function of the component WebRTC. Executing a manipulation can lead to buffer overflow. This vulnerability is registered as CVE-2026-87430

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.2%
CVE-2026-87429 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-87429 | Google Chrome up to 152.0.7977.82 ServiceWorker access control (WID-SEC-2026-3238)

A vulnerability was found in Google Chrome. It has been rated as critical. This affects an unknown function of the component ServiceWorker. Performing a manipulation results in improper access controls. This vulnerability is cataloged as CV

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.8%
CVE-2026-87876 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-87876 | Red Hat Enterprise Linux/OpenShift Container Platform Scheduler/ACL Validation access control (WID-SEC-2026-3282)

A vulnerability was found in Red Hat Enterprise Linux and OpenShift Container Platform. It has been rated as critical. Impacted is an unknown function of the component Scheduler/ACL Validation. Performing a manipulation results in improper

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 19.6%
CVE-2026-87875 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-87875 | Red Hat CUPS SNMP Supply Parser cups/transcode.c cupsUTF32ToUTF8 out-of-bounds (EUVD-2026-75085 / WID-SEC-2026-3282)

A vulnerability was found in Red Hat CUPS. It has been declared as problematic. This issue affects the function cupsUTF32ToUTF8 of the file cups/transcode.c of the component SNMP Supply Parser. Such manipulation leads to out-of-bounds read.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.5%
CVE-2026-81011 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-81011 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 hp-bioscfg hp_init_bios_package_attribute out-of-bounds (Nessus ID 345340)

A vulnerability, which was classified as problematic, was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. Affected is the function hp_init_bios_package_attribute of the component hp-bioscfg. Such manipulation leads to out-of-bounds read

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 29.8%
CVE-2026-89612 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89612 | Linux Kernel up to 7.2.3 ntfs parse_ntfs_boot_sector memory corruption (Nessus ID 345341)

A vulnerability labeled as critical has been found in Linux Kernel up to 7.2.3. This affects the function parse_ntfs_boot_sector of the component ntfs. Executing a manipulation can lead to memory corruption. This vulnerability is handled as

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 20.4%
CVE-2026-89574 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89574 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 dm array element_at buffer overflow (Nessus ID 345342)

A vulnerability was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. It has been rated as very critical. Affected is the function element_at of the component dm array. Performing a manipulation results in buffer overflow. This vulnerabil

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 22.2%
CVE-2026-89613 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89613 | Linux Kernel up to 7.2.3 ntfs input validation (Nessus ID 345345)

A vulnerability marked as critical has been reported in Linux Kernel up to 7.2.3. This impacts an unknown function of the component ntfs. The manipulation leads to improper input validation. This vulnerability is uniquely identified as CVE-

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
5.8 MEDIUM
EPSS 6.5%
CVE-2026-89454 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89454 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 plda plda_init_interrupts denial of service (Nessus ID 345344)

A vulnerability was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. It has been rated as critical. Affected by this vulnerability is the function plda_init_interrupts of the component plda. This manipulation causes denial of service. Th

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 24.6%
CVE-2026-89521 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89521 | Linux Kernel up to 7.2.3 Core Scheduling pick_next_task toctou (Nessus ID 345343)

A vulnerability classified as very critical was found in Linux Kernel up to 7.2.3. This vulnerability affects the function pick_next_task of the component Core Scheduling. Executing a manipulation can lead to time-of-check time-of-use. The

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 28%
CVE-2026-49855 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-49855 | tornadoweb Tornado up to 6.5.5 Decompression memory allocation (Nessus ID 345570)

A vulnerability has been found in tornadoweb Tornado up to 6.5.5 and classified as problematic. This issue affects some unknown processing of the component Decompression. Performing a manipulation results in uncontrolled memory allocation.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.7%
CVE-2026-49853 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-49853 | tornadoweb Tornado up to 6.5.5 Redirect redirect (Nessus ID 345570)

A vulnerability labeled as problematic has been found in tornadoweb Tornado up to 6.5.5. Impacted is an unknown function of the component Redirect. The manipulation of the argument Authorization/auth_username/auth_password/auth_mode results

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.5 CRITICAL
EPSS 60.1%
CVE-2026-61511 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Critical vBulletin Pre-Auth RCE Flaw Enables Arbitrary PHP Code Execution

A critical vulnerability in vBulletin lets unauthenticated remote attackers execute arbitrary PHP code on a vulnerable forum server, creating a direct path to server compromise. Tracked as CVE-2026-61511, the issue affects vBulletin 6.2.1 a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.1%
CVE-2026-85706 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CISA warnt: GitLab-Schlagloch CVE-2026-85706 aktiv ausgenutzt

USA / LONDON (IT BOLTWISE) – Die US-Cybersicherheitsbehörde CISA meldet, dass Angreifer eine GitLab-Sicherheitslücke maximaler Schwere (CVE-2026-85706) bereits ausnutzen. Betroffen ist ein DevSecOps-Feature, bei dem fehlende Authentifizieru

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.5 CRITICAL
EPSS 78.7%
CVE-2026-3854 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

GitHub Pays $100,000 Bounty for Critical RCE Flaw in Git Push Pipeline

GitHub has awarded security researcher Saif Ghani a $100,000 bug bounty after the disclosure of CVE-2026-3854, a critical remote code execution vulnerability affecting GitHub’s Git push processing pipeline. The reward is reportedly the larg

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.5 CRITICAL
EPSS 78.7%
CVE-2026-3854 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

GitHub Pays $100,000 Bounty for Critical RCE Flaw in Git Push Pipeline

GitHub has awarded security researcher Saif Ghani a $100,000 bug bounty after the disclosure of CVE-2026-3854, a critical remote code execution vulnerability affecting GitHub’s Git push processing pipeline. The reward is reportedly the larg

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.5 CRITICAL
EPSS 79.3%
CVE-2026-51990 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor

China-linked threat actors tracked as UNC3569 have exploited a critical one-click remote code execution vulnerability in Tencent’s Sogou Input Method for Windows to deploy the GRAYRABBIT backdoor on targeted systems. Tracked as CVE-2026-519

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
9.5 CRITICAL
EPSS 79.3%
CVE-2026-51990 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor

China-linked threat actors tracked as UNC3569 have exploited a critical one-click remote code execution vulnerability in Tencent’s Sogou Input Method for Windows to deploy the GRAYRABBIT backdoor on targeted systems. Tracked as CVE-2026-519

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 26.5%
CVE-2026-89049 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

Critical AWS Flaw Lets Attackers Bypass Port Forwarding Restrictions and Steal IAM Credentials

A critical vulnerability in the AWS Systems Manager (SSM) Agent could allow authorized attackers to bypass Session Manager port-forwarding restrictions, access link-local services, and steal temporary IAM credentials assigned to Amazon EC2

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.5 CRITICAL
EPSS 78.7%
CVE-2026-3854 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

GitHub Pays $100,000 Bounty for Critical RCE Flaw Triggered by a Single Git Push

GitHub has reportedly awarded a $100,000 bug bounty to security researcher Saif Ghani for identifying a critical remote code execution vulnerability that could be triggered through a specially crafted Git repository operation. The flaw, tra

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.6%
CVE-2026-85102 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Critical Check Point VPN Flaws Could Face Large-Scale Exploitation, NCSC Warns

The Netherlands’ National Cyber Security Center (NCSC) has warned organizations to urgently patch two critical vulnerabilities in Check Point VPN products, saying widespread exploitation attempts are likely to begin soon. Tracked as CVE-202

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

Weekly Cybersecurity Newsletter Bulletin – Microsoft 0-day, FortiOS, PAN-OS Flaw, Revolut Data Breach, and 20+ Stories

This week’s roundup covers a massive Microsoft Patch Tuesday with two exploited zero-days, active FortiGate exploitation, a critical PAN-OS root-level RCE flaw, the Revolut KYC data breach, and more than 20 other stories spanning AI-driven

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

Weekly Cybersecurity Newsletter Bulletin – Microsoft 0-day, FortiOS, PAN-OS Flaw, Revolut Data Breach, and 20+ Stories

This week’s roundup covers a massive Microsoft Patch Tuesday with two exploited zero-days, active FortiGate exploitation, a critical PAN-OS root-level RCE flaw, the Revolut KYC data breach, and more than 20 other stories spanning AI-driven

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
10.0 CRITICAL
EPSS 79.1%
CVE-2026-85706 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read – Exploited Within 24 Hours

CVE-2026-85706, a CVSS 10.0 GitLab path traversal, was under active exploitation within 24 hours of disclosure. GitLab disclosed CVE-2026-85706 (CVSS score of 10.0) on September 10, 2026, a path traversal vulnerability in its repository com

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 💻 Lokal 🔓 Keine Authentifizierung nötig
Microsoft

China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks

China-linked threat actors UTA0560 and JungleBamboo chained a Google Chrome zero-day with a Windows kernel privilege-escalation flaw in phishing campaigns targeting NGOs and other victims. Volexity documented the operations, detected on Sep

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 💻 Lokal 🔓 Keine Authentifizierung nötig
Microsoft

China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks

China-linked threat actors UTA0560 and JungleBamboo chained a Google Chrome zero-day with a Windows kernel privilege-escalation flaw in phishing campaigns targeting NGOs and other victims. Volexity documented the operations, detected on Sep

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 32.1%
CVE-2026-85706 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CISA Warns of Critical GitLab Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab flaw, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog after confirming it was exploited in attacks. The issue affects bot

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.1%
CVE-2026-85706 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CISA Warns of Critical GitLab Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab flaw, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog after confirming it was exploited in attacks. The issue affects bot

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
10.0 CRITICAL
EPSS 79.1%
CVE-2026-85706 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

GitLab schließt CVE-2026-85706 mit CVSS 10, aktive In-the-Wild-Probes

LONDON (IT BOLTWISE) – GitLab hat mehrere Sicherheitslücken gepatcht, darunter eine Schwachstelle mit CVSS 10,0 (CVE-2026-85706), die bereits innerhalb von Stunden nach der Veröffentlichung von Angreifern abgefragt wurde. Betroffen sind bes

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.5 CRITICAL
EPSS 57.9%
CVE-2026-20079 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Cisco

Attackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware

Three threat groups are exploiting two Cisco FMC flaws to steal credentials, gain root access and deploy Qilin ransomware. Cisco Talos says three separate threat groups are exploiting two recently patched Secure Firewall Management Center (

CWE-287: Improper Authentication ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Management-Interface vom Internet trennen und ACLs auf vertrauenswürdige IPs beschränken.
9.5 CRITICAL
EPSS 56.1%
CVE-2026-75650 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Adobe

Imperva Customers Protected Against StyleSmuggler (CVE-2026-75650) in Adobe Commerce and Magento Open Source

TL;DR: CVE-2026-75650, dubbed StyleSmuggler, is a critical vulnerability affecting Adobe Commerce and Magento Open Source. The vulnerability allows an unauthenticated attacker to inject malicious PHP code into Magento’s template system and

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.5 CRITICAL
EPSS 57.9%
CVE-2026-20079 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Cisco

Active exploitation of Cisco Secure Firewall Management Center vulnerabilities

Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software. First, CVE-2026-20079 is an authentication bypass vulnerability in unpatched instances of Cisco’s Secure F

CWE-287: Improper Authentication ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Management-Interface vom Internet trennen und ACLs auf vertrauenswürdige IPs beschränken.
9.8 CRITICAL
⚠️ KEV
EPSS 87.1%
CVE-2026-81963 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities

Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as &quot;critical.&quot;Microsoft notes that 2 of the vulnerabiliti

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.