Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-06 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
CVE-2026-74647 | Linux Kernel up to 6.6.151/6.12.103/6.18.44/7.1.8 Fastrpc fastrpc_req_munmap_impl race condition (Nessus ID 343049)
A vulnerability, which was classified as very critical, has been found in Linux Kernel up to 6.6.151/6.12.103/6.18.44/7.1.8. The impacted element is the function fastrpc_req_munmap_impl of the component Fastrpc. This manipulation causes rac
CVE-2026-74648 | Linux Kernel up to 7.1.8 rtl8723bs rtw_cfg80211_monitor_if_xmit_entry out-of-bounds (Nessus ID 343049)
A vulnerability was found in Linux Kernel up to 7.1.8. It has been rated as very critical. This affects the function rtw_cfg80211_monitor_if_xmit_entry of the component rtl8723bs. This manipulation causes out-of-bounds read. The identificat
CVE-2026-74646 | Linux Kernel up to 6.6.151/6.12.103/6.18.44/7.1.8 fastrpc fastrpc_internal_invoke race condition (Nessus ID 343049)
A vulnerability was found in Linux Kernel up to 6.6.151/6.12.103/6.18.44/7.1.8. It has been classified as very critical. Affected by this vulnerability is the function fastrpc_internal_invoke of the component fastrpc. The manipulation leads
CVE-2026-74642 | Linux Kernel up to 6.6.151/6.12.103/6.18.44/7.1.8 ALSA ump_to_endpoint use after free (Nessus ID 343049 / WID-SEC-2026-2970)
A vulnerability classified as very critical was found in Linux Kernel up to 6.6.151/6.12.103/6.18.44/7.1.8. The affected element is the function ump_to_endpoint of the component ALSA. The manipulation results in use after free. This vulnera
CVE-2026-74636 | Linux Kernel up to 7.1.8 tracing trace_event_update_all locking (Nessus ID 343049 / WID-SEC-2026-2970)
A vulnerability described as very critical has been identified in Linux Kernel up to 7.1.8. This issue affects the function trace_event_update_all of the component tracing. Executing a manipulation can lead to improper locking. This vulnera
CVE-2026-74634 | Linux Kernel up to 6.12.103/6.18.44/7.1.8 ring-buffer ring_buffer_subbuf_order_set use after free (Nessus ID 343049 / WID-SEC-2026-2970)
A vulnerability marked as very critical has been reported in Linux Kernel up to 6.12.103/6.18.44/7.1.8. This vulnerability affects the function ring_buffer_subbuf_order_set of the component ring-buffer. Performing a manipulation results in
CVE-2026-74635 | Linux Kernel up to 7.1.8 fbdev bitblit.c bit_cursor out-of-bounds (Nessus ID 343049 / WID-SEC-2026-2970)
A vulnerability, which was classified as problematic, has been found in Linux Kernel up to 7.1.8. This issue affects the function bit_cursor of the file drivers/video/fbdev/core/bitblit.c of the component fbdev. The manipulation leads to ou
CVE-2026-74631 | Linux Kernel up to 7.1.8 smc smc_rx_splice use after free (Nessus ID 343049 / WID-SEC-2026-2970)
A vulnerability identified as very critical has been detected in Linux Kernel up to 6.1.182/6.6.151/6.12.103/6.18.44/7.1.8. Affected by this issue is the function smc_rx_splice of the component smc. This manipulation causes use after free.
CVE-2026-20212: Nexus-9000-Switches per S1HAL per root über TCP 43210/43211 angreifbar
LONDON (IT BOLTWISE) – Eine als kritisch eingestufte Schwachstelle (CVE-2026-20212, CVSS 9,8) betrifft Cisco Nexus 9000 Switches mit Silicon-One-ASICs. Unauthentifizierte Angreifer können per TCP 43210 und 43211 im Default-Layer-3-VRF belie
CVE-2026-74625 | Linux Kernel up to 7.1.8 Bridge nf_ct_bridge_pre _nfct memory leak (Nessus ID 343049 / WID-SEC-2026-2970)
A vulnerability was found in Linux Kernel up to 7.1.8. It has been classified as critical. This affects the function nf_ct_bridge_pre of the component Bridge. Performing a manipulation of the argument _nfct results in memory leak. This vuln
CVE-2026-74630 | Linux Kernel up to 7.1.8 ipv6 in6_dev_get ip6_ptr use after free (Nessus ID 343049 / WID-SEC-2026-2970)
A vulnerability labeled as very critical has been found in Linux Kernel up to 7.1.8. Affected is the function in6_dev_get of the component ipv6. The manipulation of the argument ip6_ptr results in use after free. This vulnerability is catal
CVE-2026-74624 | Linux Kernel up to 6.6.151/6.12.103/6.18.44/7.1.8 Netfilter Conntrack nf_ct_l4proto_log_invalid deadlock (Nessus ID 343049 / WID-SEC-2026-2970)
A vulnerability classified as critical has been found in Linux Kernel up to 6.6.151/6.12.103/6.18.44/7.1.8. This affects the function nf_ct_l4proto_log_invalid of the component Netfilter Conntrack. Performing a manipulation results in deadl
CVE-2026-74623 | Linux Kernel up to 7.1.8 atlantic aq_vec_deinit memory leak (Nessus ID 343049 / WID-SEC-2026-2970)
A vulnerability categorized as problematic has been discovered in Linux Kernel up to 6.1.182/6.6.151/6.12.103/6.18.44/7.1.8. This affects the function aq_vec_deinit of the component atlantic. Executing a manipulation can lead to memory leak
CVE-2026-74621 | Linux Kernel up to 6.6.151/6.12.103/6.18.44/7.1.8 act_ct net/sched/act_ct.c tcf_ct_handle_fragments memory leak (Nessus ID 343049 / WID-SEC-2026-2970)
A vulnerability classified as critical has been found in Linux Kernel up to 6.6.151/6.12.103/6.18.44/7.1.8. Affected is the function tcf_ct_handle_fragments of the file net/sched/act_ct.c of the component act_ct. This manipulation causes me
CVE-2026-74620 | Linux Kernel up to 7.1.8 act_gact/act_police net/sched tcf_action_check_ctrlact TCA_GACT_PROB.paction/TCA_POLICE_RESULT input validation (Nessus ID 343049 / WID-SEC-2026-2970)
A vulnerability was found in Linux Kernel up to 7.1.8 and classified as problematic. Affected by this issue is the function tcf_action_check_ctrlact of the file net/sched of the component act_gact/act_police. Executing a manipulation of the
CVE-2026-74619 | Linux Kernel up to 6.6.151/6.12.103/6.18.44/7.1.8 overlayfs fs/overlayfs/super.c ovl_fill_super user_ns improper authorization (Nessus ID 343049 / WID-SEC-2026-2970)
A vulnerability was found in Linux Kernel up to 6.6.151/6.12.103/6.18.44/7.1.8. It has been declared as very critical. The affected element is the function ovl_fill_super of the file fs/overlayfs/super.c of the component overlayfs. Such man
CVE-2026-74618 | Linux Kernel up to 6.12.103/6.18.44/7.1.8 binfmt_misc fs/binfmt_misc.c bm_fill_super user_ns improper authorization (Nessus ID 343049 / WID-SEC-2026-2970)
A vulnerability described as critical has been identified in Linux Kernel up to 6.12.103/6.18.44/7.1.8. This impacts the function bm_fill_super of the file fs/binfmt_misc.c of the component binfmt_misc. The manipulation of the argument user
CVE-2026-80728 | Linux Kernel up to 6.6.151/6.12.103/6.18.44/7.1.8 amdgpu drm/amdgpu vcn_v4_0_sw_fini memory corruption (Nessus ID 343049)
A vulnerability identified as critical has been detected in Linux Kernel up to 6.6.151/6.12.103/6.18.44/7.1.8. This affects the function vcn_v4_0_sw_fini of the file drm/amdgpu of the component amdgpu. This manipulation causes memory corrup
CVE-2026-74616 | Linux Kernel up to 7.1.8 XDP xdpf_clone buffer overflow (Nessus ID 343049 / WID-SEC-2026-2970)
A vulnerability marked as very critical has been reported in Linux Kernel up to 7.1.8. This affects the function xdpf_clone of the component XDP. The manipulation leads to buffer overflow. This vulnerability is documented as CVE-2026-74616.
CVE-2026-74615 | Linux Kernel up to 7.1.8 VXLAN vxlan_changelink use after free (Nessus ID 343049 / WID-SEC-2026-2970)
A vulnerability has been found in Linux Kernel up to 7.1.8 and classified as very critical. Affected by this vulnerability is the function vxlan_changelink of the component VXLAN. Performing a manipulation results in use after free. This vu
IDScan sued over 153 million licence breach, FalconFlank zero-day hijacks CrowdStrike, Magento stores backdoored with no patch
Identity verification firm IDScan faces multiple lawsuits and investigations after hackers allegedly breached it. The criminals offered over 153 million U.S. and Canadian driver's license scans for sale. Nightmare Eclipse releases Falc
0patch liefert drei Jahre Support für Microsoft Office 2021 - BornCity
Windows 7/Server 2008 R2: 0Patch-Support bis Januar 2027 · Windows 10 ... 0patch Fix für Windows Server Telephony Schwachstelle CVE-2026-20931 Weiterlesen
ProFTPD mod_sql post-authentication SQLi RCE
Topic: ProFTPD mod_sql post-authentication SQLi RCE Risk: Medium Text:#!/usr/bin/env python3 """ CVE-2026-42167 — ProFTPD mod_sql post-authentication SQL injection -&gt; RCE postauth_stor_r... Weiterlesen
A New Magento Zero-Day Is Breaking Into Online Stores Right Now
Online stores running Magento Open Source and Adobe Commerce are being broken into through a security flaw that has no patch, no CVE number and, as of Saturday, no acknowledgment from Adobe. The company that found it says it went public b
Docker CVE-2026-34040: AuthZ-Bypass erlaubt Root-Container nach Größen-Check
LONDON (IT BOLTWISE) – Eine lang zurückliegende Schwachstelle im Docker Engine AuthZ-Middleware-Pfad ermöglicht nach aktueller Analyse einen Authentifizierungs-Umgehungsweg. Ein übergroßer API-Request wird vor dem Policy-Plugin abgeschnitte
ASUS Control Center Flaw Allows Attackers to Gain Full Admin Control of the System
ASUS has issued an urgent security update for ASUS Control Center Enterprise (ACC) after researchers uncovered a maximum-severity vulnerability that lets remote attackers seize complete administrative control over the platform and every dev
ASUS Control Center Flaw Allows Attackers to Gain Full Admin Control of the System
ASUS has issued an urgent security update for ASUS Control Center Enterprise (ACC) after researchers uncovered a maximum-severity vulnerability that lets remote attackers seize complete administrative control over the platform and every dev
ASUS Control Center Flaw Allows Attackers to Gain Full Admin Control of the System
ASUS has issued an urgent security update for ASUS Control Center Enterprise (ACC) after researchers uncovered a maximum-severity vulnerability that lets remote attackers seize complete administrative control over the platform and every dev
Hackers Actively Exploiting Magento and Adobe Commerce 0-Day RCE Vulnerability
A newly discovered zero-day vulnerability in Magento Open Source and Adobe Commerce is being actively exploited by attackers to seize full control of online stores, and there is still no official patch available. Dutch e-commerce security f
Hackers Actively Exploiting Magento and Adobe Commerce 0-Day RCE Vulnerability
A newly discovered zero-day vulnerability in Magento Open Source and Adobe Commerce is being actively exploited by attackers to seize full control of online stores, and there is still no official patch available. Dutch e-commerce security f
Magento-Backdoor „StyleSmuggler“: Ungepatchte Zero-Day trifft Adobe Commerce
LONDON (IT BOLTWISE) – Eine ungesicherte Zero-Day-Lücke in Magento Open Source und Adobe Commerce wird offenbar aktiv ausgenutzt. Die Sicherheitsfirma Sansec nennt die Schwachstelle „StyleSmuggler“ und beschreibt eine Kette, die ohne Login
PaperCut Flaws Exploited in Attacks on U.S. and European Schools
Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-20
Broadcom schließt kritische Lücke in VMware Workstation und Fusion (CVE-2026-59346)
LONDON (IT BOLTWISE) – Broadcom hat Sicherheitsupdates für VMware Workstation und VMware Fusion veröffentlicht und schließt dabei zwei Lücken, darunter einen kritischen Integer-Overflow mit CVSS 9,3. Unter bestimmten Bedingungen kann ein An
Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions. The post Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites appeared first o
12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers
A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged replication accounts to execute attacker-controlled code, escalate to database superuser, and establish persistent backdoors on affected servers. Tracked as
12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers
A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged replication accounts to execute attacker-controlled code, escalate to database superuser, and establish persistent backdoors on affected servers. Tracked as
12-Year-Old PostgreSQL Flaw Lets Backup Accounts Execute Code and Take Over Databases
A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged backup and replication accounts to execute arbitrary code, escalate to database superuser privileges, and establish persistent access on vulnerable servers.
U.S. CISA adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Google Chromium V8 flaw, trac
Google’s Chrome Update Patches Sixth Zero-Day Exploited in 2026
Chrome users have another actively exploited zero-day to worry about, and this one sits inside the engine that powers much of the modern web. Google has patched CVE-2026-85046, a high-severity type confusion vulnerability in Chrome’s V8 Jav
CVE-2026-19949 Leaves Millions of WordPress Sites Running Vulnerable Plugin Versions
A WordPress backup tool designed to help sites recover from trouble can instead become the trigger for an attack. Researchers disclosed a high-severity SQL injection vulnerability in the All-in-One WP Migration and Backup plugin that affect
HPE Patches Critical RCE Vulnerabilities in AOS-CX
Nearly two dozen issues, tracked collectively as CVE-2026-73749 (CVSS score of 9.8), were addressed with the updates. The post HPE Patches Critical RCE Vulnerabilities in AOS-CX appeared first on SecurityWeek. Weiterlesen
Nightmare Eclipse drops a CrowdStrike zero-day.
Extortion group leaks alleged Manchester Airports Group data. France's CNIL fines hospital over 2025 data breach. Weiterlesen
PostgreSQL Hit by 12-Year-Old Vulnerability Allowing Server Takeover
PostGREShell (CVE-2026-6471) is a 12-year-old PostgreSQL flaw that lets low-privileged attackers execute code and take over servers. Cyera researchers found a severe PostgreSQL vulnerability, dubbed PostGREShell and tracked as CVE-2026-6471
Sangoma Switchvox Vulnerabilities Exploited in the Wild
Tracked as CVE-2026-9586, the unauthenticated SQL injection flaw can be exploited remotely for arbitrary code execution. The post Sangoma Switchvox Vulnerabilities Exploited in the Wild appeared first on SecurityWeek. Weiterlesen
[NEU] [niedrig] Checkmk: Schwachstelle ermöglicht Denial of Service
Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Checkmk Agent Receiver ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen
[NEU] [UNGEPATCHT] [mittel] xpdf: Schwachstelle ermöglicht Denial of Service
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in xpdf ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen
[NEU] [mittel] Dell integrated Dell Remote Access Controller: Schwachstelle ermöglicht Codeausführung
Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Dell integrated Dell Remote Access Controller ausnutzen, um beliebigen Programmcode auszuführen. Weiterlesen
[NEU] [mittel] Ollama: Schwachstelle ermöglicht Offenlegung von Informationen
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Ollama ausnutzen, um Informationen offenzulegen. Weiterlesen
[NEU] [hoch] util-linux: Schwachstelle ermöglicht Privilegieneskalation
Ein lokaler Angreifer kann eine Schwachstelle in util-linux ausnutzen, um seine Privilegien zu erhöhen. Weiterlesen
[NEU] [hoch] GeoNetwork: Schwachstelle ermöglicht Manipulation von Dateien
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in GeoNetwork ausnutzen, um Dateien zu manipulieren. Weiterlesen
[NEU] [UNGEPATCHT] [mittel] bluez: Schwachstelle ermöglicht Codeausführung
Ein Angreifer in Bluetooth-Reichweite kann eine Schwachstelle in bluez ausnutzen, um beliebigen Programmcode auszuführen. Weiterlesen
12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover
Dubbed PostGREShell, CVE-2026-6471 turns low-level replication access into code execution, permanent superuser privileges and a persistent database backdoor. The post 12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover ap
[UPDATE] [hoch] Dell BSAFE: Schwachstelle ermöglicht Denial of Service
Ein Angreifer kann eine Schwachstelle in Dell BSAFE ausnutzen, um einen Denial of Service zu verursachen Weiterlesen
Google Patches 6th Chrome Zero-Day of 2026
Google’s Chrome 152 security update resolves 12 vulnerabilities, including a high-severity type confusion flaw in the V8 engine. The post Google Patches 6th Chrome Zero-Day of 2026 appeared first on SecurityWeek. Weiterlesen
[UPDATE] [mittel] Red Hat Enterprise Linux (iperf3): Schwachstelle ermöglicht Denial of Service
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen
Google fixes actively exploited Chrome V8 zero-day vulnerability
Google has released a Chrome security update addressing 12 vulnerabilities, including a high-severity V8 flaw that is being actively exploited in attacks. The fixes are included in Chrome 152.0.7977.82/.83 for Windows and macOS and version
CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers’ crosshairs. The vulnerabilities are as follows – C
HP Easy Start for macOS: CVE-2026-12554 / CVE-2026-12555 / CVE-2026-12556
Posted by Nir Yehoshua on Sep 03Hello Full Disclosure list, Cipher Security Labs has published technical details for three High-severity vulnerabilities affecting HP Easy Start for macOS. The issues were coordinated with HP and are addresse
Attackers exploit zero-days in consistently besieged SonicWall product
SonicWall customers are grappling with yet another pair of actively exploited zero-day vulnerabilities in SonicWall SMA 1000 appliances, a product that’s been besieged with recurring defects and attacks over the past nine months. The vendo
Serious vulnerability threatens tens of thousands of Exchange servers
A serious vulnerability was recently discovered in Exchange Server 2016, Exchange Server 2016, and Exchange Server Subscription Edition (SE). The vulnerability is designated CVE-2026-62911 and can be exploited by hackers to gain full access