CVE-2026-59304: Schwachstellen-Eintrag (NVD)
Improper caching of the original content type in Spring Cloud Stream Avro.
Spring Cloud Stream 5.0.0 - 5.0.2
Spring Cloud Stream 4.3.0 - 4.3.3
Spring Cloud Stream 4.2.0 - 4.2.6
Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-06 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
Critical N-able N-central Flaw Enables Unauthenticated Pre-Auth Remote Code Execution
N-able has issued an urgent security update for a critical vulnerability in its N-central remote monitoring and management (RMM) platform that could let an unauthenticated attacker execute code on a vulnerable server before logging in. Trac
Hackers Actively Exploiting PaperCut Servers Command Execution Vulnerabilities
Two critical vulnerabilities in PaperCut servers, CVE-2026-81578 and CVE-2026-82078, are being actively exploited, allowing attackers to execute commands, steal credentials, and potentially create privileged accounts within victim networks.
Magento and Adobe Commerce StyleSmuggler 0-Day RCE Actively Exploited in Attacks
Security researchers have discovered an actively exploited, unauthenticated remote code execution vulnerability affecting installations of Magento Open Source and Adobe Commerce. This vulnerability, known as StyleSmuggler, allows attackers
Hackers Exploit PaperCut NG/MF Flaws to Steal Credentials and Deploy Meterpreter
Threat actors are actively exploiting two recently disclosed vulnerabilities in PaperCut NG/MF servers, using the access to execute commands, harvest credentials, conduct reconnaissance, and deploy Metasploit Meterpreter payloads. Researche
[UPDATE] [mittel] Grafana: Schwachstelle ermöglicht Denial of Service
Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Grafana Plugins für SQL Datenquellen ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen
[UPDATE] [mittel] Grafana: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen und Manipulation von Dateien
Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Grafana ausnutzen, um Sicherheitsvorkehrungen zu umgehen, und um Dateien zu manipulieren. Weiterlesen
Magento and Adobe Commerce StyleSmuggler 0-Day RCE Actively Exploited in Attacks
Security researchers have discovered an actively exploited, unauthenticated remote code execution vulnerability affecting installations of Magento Open Source and Adobe Commerce. This vulnerability, known as StyleSmuggler, allows attackers
12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code on Database Servers
A newly disclosed PostgreSQL vulnerability, tracked as CVE-2026-6471 and nicknamed PostGREShell, could allow attackers with low-level replication access to execute arbitrary code on database servers. The flaw in PostgreSQL logical decoding
Hackers Exploit StyleSmuggler Magento and Adobe Commerce Zero-Day for Unauthenticated RCE
A newly disclosed actively exploited zero-day vulnerability in Magento and Adobe Commerce allows unauthenticated attackers to execute code remotely on affected e-commerce stores. The flaw, named StyleSmuggler, was discovered by Sansec’s For
Critical Telerik UI For ASP.Net Ajax Vulnerability Chain: CVE-2026-13181 to CVE-2026-13184
HOC Shorts A high-severity vulnerability chain in Telerik UI for ASP.NET AJAX (RadAsyncUpload) allows unauthenticated attackers to decrypt… This article has been indexed from Hackers Online Club Read the original article: Critical Telerik U
Weekly Cybersecurity Newsletter Bulletin – CrowdStrike Falcon, Chrome 0-Day, GPT-6 Astra, Dropbox Breach and 20+ Stories
This edition of the weekly cybersecurity newsletter bulletin covers critical zero-day discoveries, nation-state router compromises, emerging autonomous AI attack vectors, and major cloud identity incidents. Below are detailed summaries of t
IT Security News Hourly Summary 2026-09-07 08h : 4 posts
4 posts published in the last hour 05:31Zero trust AI agents demand a different kind of security 05:31CrowdStrike Launches SafeMind Agentic AI Cybersecurity System Built With NVIDIA Nemotron 05:0218 ways to check whether data can be trusted
Critical ASUS Control Center CVE-2026-75754 Flaw Allows Unauthenticated Root Access
ASUS has issued a security bulletin regarding a critical vulnerability in ASUS Control Center Enterprise (ACC), identified as CVE-2026-75754. This flaw affects ACC version 4.0.0.2 and earlier, allowing for unauthenticated root access. Criti
Critical ASUS Control Center Flaw Lets Unauthenticated Attackers Gain Root Access
ASUS has released a security update for a critical vulnerability in ASUS Control Center Enterprise (ACC), warning that unauthenticated attackers could exploit the flaw to obtain root-level access on affected systems. Tracked as CVE-2026-757
Critical ASUS Control Center CVE-2026-75754 Flaw Allows Unauthenticated Root Access
ASUS has issued a security bulletin regarding a critical vulnerability in ASUS Control Center Enterprise (ACC), identified as CVE-2026-75754. This flaw affects ACC version 4.0.0.2 and earlier, allowing for unauthenticated root access. Criti
Critical ASUS Control Center CVE-2026-75754 Flaw Allows Unauthenticated Root Access
ASUS has issued a security bulletin regarding a critical vulnerability in ASUS Control Center Enterprise (ACC), identified as CVE-2026-75754. This flaw affects ACC version 4.0.0.2 and earlier, allowing for unauthenticated root access. Criti
Weekly Cybersecurity Newsletter Bulletin – CrowdStrike Falcon, Chrome 0-Day, GPT-6 Astra, Dropbox Breach and 20+ Stories
This edition of the weekly cybersecurity newsletter bulletin covers critical zero-day discoveries, nation-state router compromises, emerging autonomous AI attack vectors, and major cloud identity incidents. Below are detailed summaries of t
Weekly Cybersecurity Newsletter Bulletin – CrowdStrike Falcon, Chrome 0-Day, GPT-6 Astra, Dropbox Breach and 20+ Stories
This edition of the weekly cybersecurity newsletter bulletin covers critical zero-day discoveries, nation-state router compromises, emerging autonomous AI attack vectors, and major cloud identity incidents. Below are detailed summaries of t
CVE-2026-20212: Nexus-9000-Switches per S1HAL per root über TCP 43210/43211 angreifbar
LONDON (IT BOLTWISE) – Eine als kritisch eingestufte Schwachstelle (CVE-2026-20212, CVSS 9,8) betrifft Cisco Nexus 9000 Switches mit Silicon-One-ASICs. Unauthentifizierte Angreifer können per TCP 43210 und 43211 im Default-Layer-3-VRF belie
0patch liefert drei Jahre Support für Microsoft Office 2021 - BornCity
Windows 7/Server 2008 R2: 0Patch-Support bis Januar 2027 · Windows 10 ... 0patch Fix für Windows Server Telephony Schwachstelle CVE-2026-20931 Weiterlesen
Docker CVE-2026-34040: AuthZ-Bypass erlaubt Root-Container nach Größen-Check
LONDON (IT BOLTWISE) – Eine lang zurückliegende Schwachstelle im Docker Engine AuthZ-Middleware-Pfad ermöglicht nach aktueller Analyse einen Authentifizierungs-Umgehungsweg. Ein übergroßer API-Request wird vor dem Policy-Plugin abgeschnitte
ASUS Control Center Flaw Allows Attackers to Gain Full Admin Control of the System
ASUS has issued an urgent security update for ASUS Control Center Enterprise (ACC) after researchers uncovered a maximum-severity vulnerability that lets remote attackers seize complete administrative control over the platform and every dev
ASUS Control Center Flaw Allows Attackers to Gain Full Admin Control of the System
ASUS has issued an urgent security update for ASUS Control Center Enterprise (ACC) after researchers uncovered a maximum-severity vulnerability that lets remote attackers seize complete administrative control over the platform and every dev
Hackers Actively Exploiting Magento and Adobe Commerce 0-Day RCE Vulnerability
A newly discovered zero-day vulnerability in Magento Open Source and Adobe Commerce is being actively exploited by attackers to seize full control of online stores, and there is still no official patch available. Dutch e-commerce security f
Hackers Actively Exploiting Magento and Adobe Commerce 0-Day RCE Vulnerability
A newly discovered zero-day vulnerability in Magento Open Source and Adobe Commerce is being actively exploited by attackers to seize full control of online stores, and there is still no official patch available. Dutch e-commerce security f
Magento-Backdoor „StyleSmuggler“: Ungepatchte Zero-Day trifft Adobe Commerce
LONDON (IT BOLTWISE) – Eine ungesicherte Zero-Day-Lücke in Magento Open Source und Adobe Commerce wird offenbar aktiv ausgenutzt. Die Sicherheitsfirma Sansec nennt die Schwachstelle „StyleSmuggler“ und beschreibt eine Kette, die ohne Login
PaperCut Flaws Exploited in Attacks on U.S. and European Schools
Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-20
PaperCut Flaws Exploited in Attacks on U.S. and European Schools
Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-20
Broadcom schließt kritische Lücke in VMware Workstation und Fusion (CVE-2026-59346)
LONDON (IT BOLTWISE) – Broadcom hat Sicherheitsupdates für VMware Workstation und VMware Fusion veröffentlicht und schließt dabei zwei Lücken, darunter einen kritischen Integer-Overflow mit CVSS 9,3. Unter bestimmten Bedingungen kann ein An
Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions. The post Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites appeared first o
12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers
A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged replication accounts to execute attacker-controlled code, escalate to database superuser, and establish persistent backdoors on affected servers. Tracked as
U.S. CISA adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Google Chromium V8 flaw, trac
Google’s Chrome Update Patches Sixth Zero-Day Exploited in 2026
Chrome users have another actively exploited zero-day to worry about, and this one sits inside the engine that powers much of the modern web. Google has patched CVE-2026-85046, a high-severity type confusion vulnerability in Chrome’s V8 Jav
CVE-2026-19949 Leaves Millions of WordPress Sites Running Vulnerable Plugin Versions
A WordPress backup tool designed to help sites recover from trouble can instead become the trigger for an attack. Researchers disclosed a high-severity SQL injection vulnerability in the All-in-One WP Migration and Backup plugin that affect
HPE Patches Critical RCE Vulnerabilities in AOS-CX
Nearly two dozen issues, tracked collectively as CVE-2026-73749 (CVSS score of 9.8), were addressed with the updates. The post HPE Patches Critical RCE Vulnerabilities in AOS-CX appeared first on SecurityWeek. Weiterlesen
Nightmare Eclipse drops a CrowdStrike zero-day.
Extortion group leaks alleged Manchester Airports Group data. France's CNIL fines hospital over 2025 data breach. Weiterlesen
Sangoma Switchvox Vulnerabilities Exploited in the Wild
Tracked as CVE-2026-9586, the unauthenticated SQL injection flaw can be exploited remotely for arbitrary code execution. The post Sangoma Switchvox Vulnerabilities Exploited in the Wild appeared first on SecurityWeek. Weiterlesen
[NEU] [niedrig] Checkmk: Schwachstelle ermöglicht Denial of Service
Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Checkmk Agent Receiver ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen
[NEU] [mittel] Dell integrated Dell Remote Access Controller: Schwachstelle ermöglicht Codeausführung
Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Dell integrated Dell Remote Access Controller ausnutzen, um beliebigen Programmcode auszuführen. Weiterlesen
[NEU] [UNGEPATCHT] [mittel] xpdf: Schwachstelle ermöglicht Denial of Service
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in xpdf ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen
[NEU] [mittel] Ollama: Schwachstelle ermöglicht Offenlegung von Informationen
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Ollama ausnutzen, um Informationen offenzulegen. Weiterlesen
[NEU] [hoch] util-linux: Schwachstelle ermöglicht Privilegieneskalation
Ein lokaler Angreifer kann eine Schwachstelle in util-linux ausnutzen, um seine Privilegien zu erhöhen. Weiterlesen
[NEU] [UNGEPATCHT] [mittel] bluez: Schwachstelle ermöglicht Codeausführung
Ein Angreifer in Bluetooth-Reichweite kann eine Schwachstelle in bluez ausnutzen, um beliebigen Programmcode auszuführen. Weiterlesen
[NEU] [hoch] GeoNetwork: Schwachstelle ermöglicht Manipulation von Dateien
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in GeoNetwork ausnutzen, um Dateien zu manipulieren. Weiterlesen
12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover
Dubbed PostGREShell, CVE-2026-6471 turns low-level replication access into code execution, permanent superuser privileges and a persistent database backdoor. The post 12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover ap
[UPDATE] [hoch] Dell BSAFE: Schwachstelle ermöglicht Denial of Service
Ein Angreifer kann eine Schwachstelle in Dell BSAFE ausnutzen, um einen Denial of Service zu verursachen Weiterlesen
Google Patches 6th Chrome Zero-Day of 2026
Google’s Chrome 152 security update resolves 12 vulnerabilities, including a high-severity type confusion flaw in the V8 engine. The post Google Patches 6th Chrome Zero-Day of 2026 appeared first on SecurityWeek. Weiterlesen
Google fixes actively exploited Chrome V8 zero-day vulnerability
Google has released a Chrome security update addressing 12 vulnerabilities, including a high-severity V8 flaw that is being actively exploited in attacks. The fixes are included in Chrome 152.0.7977.82/.83 for Windows and macOS and version
CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers’ crosshairs. The vulnerabilities are as follows – C
HP Easy Start for macOS: CVE-2026-12554 / CVE-2026-12555 / CVE-2026-12556
Posted by Nir Yehoshua on Sep 03Hello Full Disclosure list, Cipher Security Labs has published technical details for three High-severity vulnerabilities affecting HP Easy Start for macOS. The issues were coordinated with HP and are addresse
Attackers exploit zero-days in consistently besieged SonicWall product
SonicWall customers are grappling with yet another pair of actively exploited zero-day vulnerabilities in SonicWall SMA 1000 appliances, a product that’s been besieged with recurring defects and attacks over the past nine months. The vendo
Serious vulnerability threatens tens of thousands of Exchange servers
A serious vulnerability was recently discovered in Exchange Server 2016, Exchange Server 2016, and Exchange Server Subscription Edition (SE). The vulnerability is designated CVE-2026-62911 and can be exploited by hackers to gain full access
Tycon Systems TPDIN-Monitor-WEB3
View CSAF Summary Successful exploitation of these vulnerabilities could allow for an attacker to perform a man-in-the-middle (MitM) attack, cause a factory reset, wipe credentials, or retrieve sensitive information. The following versions
Rockwell Automation 1756-ENBT Module
View CSAF Summary Successful exploitation of this vulnerability could crash the module. The device requires a restart to recover. The following versions of Rockwell Automation 1756-ENBT Module are affected: 1756-ENBT module vers:all/* (CVE-
OPCFoundation OPC UA LocalDiscoveryServer (LDS)
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to take control of a high-privilege terminal during installation and run arbitrary commands. The following versions of OPCFoundation OPC UA LocalDiscove
IXON VPN Client
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to perform remote code execution on the computer running the client with elevated privileges. The following versions of IXON VPN Client are affected: VP
Rockwell Automation ControlFLASH
View CSAF Summary Successful exploitation of this vulnerability could give an attacker the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level. The following ve
CVE-2026-84115 in Cleo Harmony: JWT Refresh Token Handler Flaw Exposes Remote Attack Risk
A critical vulnerability identified as CVE-2026-84115 affects Cleo Harmony versions through 5.8.1.10, with the weakness tied to the platform’s JWT Refresh Token Handler and the /api/connections endpoint. MITRE documented the issue on Sept
SonicWall Warns of Two Actively Exploited SMA1000 Zero-Days, One Rated Maximum Severity
SonicWall disclosed this week that attackers are chaining two previously unknown vulnerabilities in its SMA1000 secure access appliances to run commands on unpatched devices, and urged customers to install an emergency hotfix. The more seve
WhatsApp-Schwachstelle: Zugriff auf Fotos bei gesperrtem Android-Handy
Eine Schwachstelle in WhatsApp für Android ermöglicht es, bei einem eingehenden Videoanruf auf private Fotos zuzugreifen, ohne das Gerät zu entsperren. Weiterlesen