🎯 CVE-2026-51724 CRITICAL 9.8 🔥 EPSS 62.9%
📄 .md Alle CVEs anzeigen ✕

CVE-2026-51724: Schwachstellen-Eintrag (NVD)

Incorrect access control in the delSmartQosCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Smart QoS rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Improper Control of Generation of Code ('Code Injection') 🎯 Medium

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

🛡️ Empfohlene Mitigation: Refactor your program so that you do not have to dynamically generate code.
Vollständige Definition bei MITRE ➔
📚 Referenzen & Quellen:
Ausnutzungs-Zeitleiste:
CVSS-Vektor-Analyse: 9.8
AV · Angriffsvektor Netzwerk
AC · Komplexität Gering
PR · Privilegien Keine
UI · Interaktion Keine
S · Scope Unverändert
C · Vertraulichkeit Hoch
I · Integrität Hoch
A · Verfügbarkeit Hoch
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Veröffentlicht:31.08.2026
Aktualisiert:01.09.2026 15:17
Assigner (CNA):NVD
Quellen: 🇪🇺 EUVD-Datenbank (ENISA) + 🇺🇸 NVD-Anreicherung · 24-h-Cache
CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

354k+ 🇪🇺 EUVD-Datenbank
11 🔴 Critical im Radar
8 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
0 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-09: 240 2025-10: 316 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 418 2026-03: 652 2026-04: 574 2026-05: 683 2026-06: 942 2026-07: 1333 2026-08: 1329 7.601 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-08-292026-09-06
≥90 %40
≥50 %40
≥10 %30
<10 %304297
📈 EPSS-Riser (7 Tage) CVE-2023-29073 ↑ 0.1 %
Frühindikator · FIRST.org
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Generic Security 40
WordPress 7
Linux 5
Adobe 3
Google 3
VMware 1
Schweregrad & Status:
Hersteller (Datenbank-weit, 90.597 Einträge):
Quelle:
🔍
7.5 HIGH
EPSS 29.8%
CVE-2026-85394 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-85394 | mpdavis python-jose up to 3.5.0 HMAC initialization input validation (EUVD-2026-70671 / Nessus ID 343059)

A vulnerability, which was classified as critical, has been found in mpdavis python-jose up to 3.5.0. This issue affects the function HMAC initialization. The manipulation leads to improper input validation. This vulnerability is uniquely i

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.8%
CVE-2026-80749 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-80749 | Linux Kernel up to 6.12.104/6.18.45/7.1.9 HDMI Connector drm/connector/hdmi memory corruption (Nessus ID 343062)

A vulnerability was found in Linux Kernel up to 6.12.104/6.18.45/7.1.9 and classified as problematic. This vulnerability affects unknown code of the file drm/connector/hdmi of the component HDMI Connector. The manipulation results in memory

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 30.5%
CVE-2026-84989 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-84989 | ntop ntopng up to 6.7.260717 Tag Management tag.lua improper authorization (Nessus ID 343065)

A vulnerability identified as problematic has been detected in ntop ntopng up to 6.7.260717. The impacted element is an unknown function of the file /lua/rest/v2/delete/tag/tag.lua of the component Tag Management. This manipulation causes i

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.7%
CVE-2026-80750 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-80750 | Linux Kernel up to 6.18.45/7.1.9 pmdomain scpsys_get_bus_protection_legacy use after free (Nessus ID 343066)

A vulnerability was found in Linux Kernel up to 6.18.45/7.1.9. It has been classified as very critical. This issue affects the function scpsys_get_bus_protection_legacy of the component pmdomain. This manipulation causes use after free. Thi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 26.8%
CVE-2026-80729 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-80729 | Linux Kernel up to 7.1.8 huge_memory mm/huge_memory __folio_split state issue (Nessus ID 343067)

A vulnerability described as very critical has been identified in Linux Kernel up to 7.1.8. Impacted is the function __folio_split of the file mm/huge_memory of the component huge_memory. Executing a manipulation can lead to state issue. Th

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
8.2 HIGH
EPSS 26.2%
CVE-2020-15876 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2020-15876 | LibreNMS 1.65 ajax_table.php sort sql injection

A vulnerability was found in LibreNMS 1.65. It has been classified as critical. Affected is an unknown function of the file ajax_table.php. This manipulation of the argument sort causes sql injection. This vulnerability is handled as CVE-20

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 18.5%
CVE-2026-77790 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-77790 | RegistrationMagic Plugin up to 6.0.8.9 on WordPress sql injection

A vulnerability was found in RegistrationMagic Plugin up to 6.0.8.9 on WordPress. It has been declared as problematic. Affected is an unknown function. Such manipulation leads to sql injection. This vulnerability is uniquely identified as C

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
7.5 HIGH
EPSS 23.2%
CVE-2026-75415 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-75415 | AntFlow 2.0.0 JiMuMDCCommonsRequestLoggingFilter.java access control

A vulnerability classified as critical has been found in AntFlow 2.0.0. This vulnerability affects unknown code of the file JiMuMDCCommonsRequestLoggingFilter.java. Performing a manipulation results in improper access controls. This vulnera

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.8%
CVE-2026-75414 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-75414 | AntFlow 2.0.0 ActivitiTest.java os command injection

A vulnerability identified as problematic has been detected in AntFlow 2.0.0. Affected is an unknown function of the file ActivitiTest.java. The manipulation leads to os command injection. This vulnerability is traded as CVE-2026-75414. It

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31%
CVE-2025-61165 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-61165 | Cohere 1.1.5 batch_upload unrestricted upload

A vulnerability, which was classified as critical, was found in Cohere 1.1.5. This affects an unknown part of the file /v1/my_drive/batch_upload. Such manipulation leads to unrestricted upload. This vulnerability is documented as CVE-2025-6

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.7%
CVE-2025-61162 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-61162 | Cohere North AI 1.1.5 /api/internal/v1/users USER_ID access control

A vulnerability, which was classified as critical, has been found in Cohere North AI 1.1.5. Affected by this issue is some unknown functionality of the file /api/internal/v1/users. This manipulation of the argument USER_ID causes improper a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 6.8%
CVE-2025-61164 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-61164 | Cohere North AI 1.1.5 WebSocket Endpoint information disclosure

A vulnerability classified as problematic was found in Cohere North AI 1.1.5. Affected by this vulnerability is an unknown functionality of the component WebSocket Endpoint. The manipulation results in information disclosure. This vulnerabi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.1%
CVE-2025-61163 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2025-61163 | Cohere North AI 1.1.5 cross-domain policy

A vulnerability identified as problematic has been detected in Cohere North AI 1.1.5. The affected element is an unknown function. This manipulation causes permissive cross-domain policy with untrusted domains. The identification of this vu

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 19.1%
CVE-2020-15878 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2020-15878 | LibreNMS 1.65 ajax_table.php address sql injection

A vulnerability was found in LibreNMS 1.65. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file ajax_table.php. Such manipulation of the argument address leads to sql injection. This vuln

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.7%
CVE-2026-80530 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-80530 | Linux Kernel up to 6.12.104/6.18.45/7.1.9 xfs xmi_can_exchange_reflink_flags unnecessary privileges

A vulnerability identified as problematic has been detected in Linux Kernel up to 6.12.104/6.18.45/7.1.9. This issue affects the function xmi_can_exchange_reflink_flags of the component xfs. Performing a manipulation results in execution wi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 25.3%
CVE-2026-75754 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

ASUS Control Center Flaw Allows Attackers to Gain Full Admin Control of the System

ASUS has issued an urgent security update for ASUS Control Center Enterprise (ACC) after researchers uncovered a maximum-severity vulnerability that lets remote attackers seize complete administrative control over the platform and every dev

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.6%
CVE-2026-71514 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-71514 | NLTK up to 3.10.2 CrubadanCorpusReader _load_lang_ngrams crubadan_code path traversal (Nessus ID 339014)

A vulnerability was found in NLTK up to 3.10.2. It has been classified as problematic. Affected by this issue is the function _load_lang_ngrams of the component CrubadanCorpusReader. Performing a manipulation of the argument crubadan_code r

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20%
CVE-2026-75931 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-75931 | fastify fast-uri up to 2.4.4/3.1.5/4.1.2 URI Parser parse/resolve/normalize/equal interpretation conflict

A vulnerability was found in fastify fast-uri up to 2.4.4/3.1.5/4.1.2 and classified as problematic. Impacted is the function parse/resolve/normalize/equal of the component URI Parser. The manipulation results in interpretation conflict. Th

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 29.9%
CVE-2026-78468 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-78468 | FluentCRM Pro Plugin up to 3.1.12 on WordPress sql injection

This issue is likely a false positive. Please verify the cited sources and consider not including this entry. Weiterlesen

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
7.5 HIGH
EPSS 21.6%
CVE-2026-19913 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-19913 | Kaltura HTML5 Video Player up to 2.103 html5lib mwEmbedLoader.php ServiceUrl input validation

A vulnerability, which was classified as problematic, was found in Kaltura HTML5 Video Player up to 2.103. The impacted element is an unknown function of the file mwEmbedLoader.php of the component html5lib. Such manipulation of the argumen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.4%
CVE-2026-19912 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-19912 | Kaltura HTML5 Video Player/html5 library up to 2.45/2.103 html5lib mwEmbedLoader.php unserialize ServiceUrl/uiconf_id input validation

A vulnerability, which was classified as critical, has been found in Kaltura HTML5 Video Player and html5 library up to 2.45/2.103. The affected element is the function unserialize of the file mwEmbedLoader.php of the component html5lib. Th

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.4%
CVE-2026-12878 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-12878 | Octopus Deploy Codefresh up to 2.11.14 API Endpoint permission

A vulnerability marked as critical has been reported in Octopus Deploy Codefresh up to 2.11.14. Impacted is an unknown function of the component API Endpoint. This manipulation causes permission issues. This vulnerability appears as CVE-202

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22%
CVE-2026-78467 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-78467 | Fluent Support Pro Plugin up to 2.3.1 on WordPress improper authorization

Further investigation has shown that this issues is a false-positive. Please review the sources mentioned and consider not using this entry at all. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
5.8 MEDIUM
EPSS 3.5%
CVE-2026-78675 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-78675 | gitpython-developers GitPython up to 3.1.58 Merge Includes .gitmodules submodules information disclosure

A vulnerability identified as problematic has been detected in gitpython-developers GitPython up to 3.1.58. The impacted element is the function submodules of the file .gitmodules of the component Merge Includes. The manipulation leads to i

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 20%
CVE-2026-78466 💻 Lokal 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-78466 | Fluent Boards Pro Plugin up to 2.0.11 on WordPress privilege escalation

This issue was flagged as a false-positive. Please consult the sources mentioned and consider not using this entry at all. Weiterlesen

CWE-269: Privilege Management ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
7.5 HIGH
EPSS 28.4%
CVE-2026-34491 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-34491 | Johnson Controls Metasys prior 14.1.5/15.0.1 cross site scripting

A vulnerability classified as problematic was found in Johnson Controls Metasys. This issue affects some unknown processing. Such manipulation leads to cross site scripting. This vulnerability is uniquely identified as CVE-2026-34491. The a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Adobe

Hackers Actively Exploiting Magento and Adobe Commerce 0-Day RCE Vulnerability

A newly discovered zero-day vulnerability in Magento Open Source and Adobe Commerce is being actively exploited by attackers to seize full control of online stores, and there is still no official patch available. Dutch e-commerce security f

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Adobe

Hackers Actively Exploiting Magento and Adobe Commerce 0-Day RCE Vulnerability

A newly discovered zero-day vulnerability in Magento Open Source and Adobe Commerce is being actively exploited by attackers to seize full control of online stores, and there is still no official patch available. Dutch e-commerce security f

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Adobe

Magento-Backdoor „StyleSmuggler“: Ungepatchte Zero-Day trifft Adobe Commerce

LONDON (IT BOLTWISE) – Eine ungesicherte Zero-Day-Lücke in Magento Open Source und Adobe Commerce wird offenbar aktiv ausgenutzt. Die Sicherheitsfirma Sansec nennt die Schwachstelle „StyleSmuggler“ und beschreibt eine Kette, die ohne Login

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.4%
CVE-2026-81578 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

PaperCut Flaws Exploited in Attacks on U.S. and European Schools

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-20

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.4%
CVE-2026-81578 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

PaperCut Flaws Exploited in Attacks on U.S. and European Schools

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-20

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.0 CRITICAL
EPSS 64.4%
CVE-2026-59346 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
VMware

Broadcom schließt kritische Lücke in VMware Workstation und Fusion (CVE-2026-59346)

LONDON (IT BOLTWISE) – Broadcom hat Sicherheitsupdates für VMware Workstation und VMware Fusion veröffentlicht und schließt dabei zwei Lücken, darunter einen kritischen Integer-Overflow mit CVSS 9,3. Unter bestimmten Bedingungen kann ein An

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.5%
CVE-2026-32475 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites

Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions. The post Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites appeared first o

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
7.5 HIGH
EPSS 30.4%
CVE-2026-81578 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

PaperCut-Schwachstellen: Angreifer stehlen Anmeldedaten an Schulen und Universitäten

LONDON (IT BOLTWISE) – Angreifer nutzen neu gemeldete PaperCut-Schwachstellen, um an Schulen und Universitäten in den USA und Europa Zugangsdaten auszuspähen. In den Beobachtungen wurden CVE-2026-81578 und CVE-2026-82078 für Authentifizieru

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.4%
CVE-2026-6471 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers

A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged replication accounts to execute attacker-controlled code, escalate to database superuser, and establish persistent backdoors on affected servers. Tracked as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.4%
CVE-2026-6471 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers

A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged replication accounts to execute attacker-controlled code, escalate to database superuser, and establish persistent backdoors on affected servers. Tracked as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.4%
CVE-2026-6471 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

12-Year-Old PostgreSQL Flaw Lets Backup Accounts Execute Code and Take Over Databases

A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged backup and replication accounts to execute arbitrary code, escalate to database superuser privileges, and establish persistent access on vulnerable servers.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.8%
CVE-2026-85046 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

U.S. CISA adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Google Chromium V8 flaw, trac

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 82.8%
CVE-2026-85046 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

Google’s Chrome Update Patches Sixth Zero-Day Exploited in 2026

Chrome users have another actively exploited zero-day to worry about, and this one sits inside the engine that powers much of the modern web. Google has patched CVE-2026-85046, a high-severity type confusion vulnerability in Chrome’s V8 Jav

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 32.7%
CVE-2026-19949 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-19949 Leaves Millions of WordPress Sites Running Vulnerable Plugin Versions

A WordPress backup tool designed to help sites recover from trouble can instead become the trigger for an attack. Researchers disclosed a high-severity SQL injection vulnerability in the All-in-One WP Migration and Backup plugin that affect

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
7.5 HIGH
EPSS 18.4%
CVE-2026-6471 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

PostgreSQL stoppt Codeausführung via Logical Decoding: neuer Whitelist-Parameter

LONDON (IT BOLTWISE) – PostgreSQL schließt eine seit 2014 bekannte Schwachstelle (CVE-2026-6471), die mit dem REPLICATION-Attribut beliebigen Code im Backend-Prozess ausführen konnte. Die Absicherung erfolgt über einen neuen Parameter outpu

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.4%
CVE-2026-6471 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

PostgreSQL fixiert CVE-2026-6471: REPLICATION-Benutzer können Code als DB-User ausführen

LONDON (IT BOLTWISE) – PostgreSQL hat ein Sicherheitsproblem mit der logischen Replikation geschlossen, das einem Konto mit REPLICATION-Attribut die Ausführung beliebigen Codes als OS-User des Datenbankservers ermöglicht. Betroffen sind Ver

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.5 CRITICAL
EPSS 64.3%
CVE-2026-73749 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

HPE Patches Critical RCE Vulnerabilities in AOS-CX

Nearly two dozen issues, tracked collectively as CVE-2026-73749 (CVSS score of 9.8), were addressed with the updates. The post HPE Patches Critical RCE Vulnerabilities in AOS-CX appeared first on SecurityWeek. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Nightmare Eclipse drops a CrowdStrike zero-day.

Extortion group leaks alleged Manchester Airports Group data. France&#039;s CNIL fines hospital over 2025 data breach. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.3%
CVE-2023-49105 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CISA Flags Old ownCloud Flaw After Reported Philippine Nuclear Data Theft

CISA added CVE-2023-49105 to its exploited-flaws catalog after researchers tied the old ownCloud bug to reported Philippine nuclear data theft. The post CISA Flags Old ownCloud Flaw After Reported Philippine Nuclear Data Theft appeared firs

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.4%
CVE-2026-6471 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

PostgreSQL Hit by 12-Year-Old Vulnerability Allowing Server Takeover

PostGREShell (CVE-2026-6471) is a 12-year-old PostgreSQL flaw that lets low-privileged attackers execute code and take over servers. Cyera researchers found a severe PostgreSQL vulnerability, dubbed PostGREShell and tracked as CVE-2026-6471

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.4%
CVE-2026-6471 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

PostgreSQL Hit by 12-Year-Old Vulnerability Allowing Server Takeover

PostGREShell (CVE-2026-6471) is a 12-year-old PostgreSQL flaw that lets low-privileged attackers execute code and take over servers. Cyera researchers found a severe PostgreSQL vulnerability, dubbed PostGREShell and tracked as CVE-2026-6471

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 89.1%
CVE-2026-9586 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Sangoma Switchvox Vulnerabilities Exploited in the Wild

Tracked as CVE-2026-9586, the unauthenticated SQL injection flaw can be exploited remotely for arbitrary code execution. The post Sangoma Switchvox Vulnerabilities Exploited in the Wild appeared first on SecurityWeek. Weiterlesen

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 2.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

[NEU] [niedrig] Checkmk: Schwachstelle ermöglicht Denial of Service

Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Checkmk Agent Receiver ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 2.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

[NEU] [UNGEPATCHT] [mittel] xpdf: Schwachstelle ermöglicht Denial of Service

Ein entfernter, anonymer Angreifer kann eine Schwachstelle in xpdf ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

[NEU] [mittel] Dell integrated Dell Remote Access Controller: Schwachstelle ermöglicht Codeausführung

Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Dell integrated Dell Remote Access Controller ausnutzen, um beliebigen Programmcode auszuführen. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

[NEU] [mittel] Ollama: Schwachstelle ermöglicht Offenlegung von Informationen

Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Ollama ausnutzen, um Informationen offenzulegen. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Linux

[NEU] [hoch] util-linux: Schwachstelle ermöglicht Privilegieneskalation

Ein lokaler Angreifer kann eine Schwachstelle in util-linux ausnutzen, um seine Privilegien zu erhöhen. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 28.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

[NEU] [hoch] GeoNetwork: Schwachstelle ermöglicht Manipulation von Dateien

Ein entfernter, anonymer Angreifer kann eine Schwachstelle in GeoNetwork ausnutzen, um Dateien zu manipulieren. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

[NEU] [UNGEPATCHT] [mittel] bluez: Schwachstelle ermöglicht Codeausführung

Ein Angreifer in Bluetooth-Reichweite kann eine Schwachstelle in bluez ausnutzen, um beliebigen Programmcode auszuführen. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 82.8%
CVE-2026-85046 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

Google patches actively exploited Chrome zero-day (CVE-2026-85046)

Google has patched 12 vulnerabilities affecting its popular Chrome browser, among them CVE-2026-85046, which has been exploited in the wild. “Google is aware that an exploit for CVE-2026-85046 exists in the wild,” the company said in a Thur

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 18.4%
CVE-2026-6471 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover

Dubbed PostGREShell, CVE-2026-6471 turns low-level replication access into code execution, permanent superuser privileges and a persistent database backdoor. The post 12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover ap

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 2.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

[UPDATE] [hoch] Dell BSAFE: Schwachstelle ermöglicht Denial of Service

Ein Angreifer kann eine Schwachstelle in Dell BSAFE ausnutzen, um einen Denial of Service zu verursachen Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

Google Patches 6th Chrome Zero-Day of 2026

Google’s Chrome 152 security update resolves 12 vulnerabilities, including a high-severity type confusion flaw in the V8 engine. The post Google Patches 6th Chrome Zero-Day of 2026 appeared first on SecurityWeek. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.5 CRITICAL
EPSS 55.5%
CVE-2026-14894 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

WordPress: Super Forms und Elementor Pro von RCE-Angriffen betroffen

LONDON (IT BOLTWISE) – Angreifer nutzen zwei kritische Lücken in WordPress-Plugins, um ohne Anmeldung Dateien mit PHP-Inhalt hochzuladen und anschließend Remote Code Execution auszuführen. Laut Wordfence wurden bereits über 250.000 bzw. 190

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.