🛡️ tsecurity.de
Zur Startseite 🔖 Lesezeichen
🎯 FOKUSSIERTE SCHWACHSTELLE: CVE-2026-70628 MEDIUM 5.8 🔥 EPSS 5.6%
Alle CVEs anzeigen ✕

USN-8680-1: FFmpeg vulnerabilities

Adrian Junge discovered that FFmpeg incorrectly handled certain subtitle data. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-70628) Adrian Junge discovered that FFmpeg incorrectl

Angriffsvektor: 🌐 Netzwerk (Remote) • 🔓 Keine Authentifizierung nötig
CWE-Klassifizierung: CWE-94: Code Injection
🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

🟢 SSE Realtime Synchronisiert ⚡ REST API (JSON) 📡 RSS Feed
Ökosystem & Hersteller Bedrohungs-Matrix:
Linux 33
Generic Security 15
Microsoft 5
Apple 4
WordPress 3
Schweregrad & Status:
Hersteller-Filter:
🔍
MEDIUM 5.8 🔥 EPSS 5.6%
Linux
CVE-2026-70628 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8680-1: FFmpeg vulnerabilities

Adrian Junge discovered that FFmpeg incorrectly handled certain subtitle data. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-70628) Adrian Junge discovered that FFmpeg incorrectl

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 20.1%
Linux
CVE-2026-53224 💻 Lokal 🔓 Keine Authentifizierung nötig

USN-8643-4: Linux kernel vulnerabilities

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Network drivers; - Open vSwitch; - SCTP protocol; (CVE-202

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 20.1%
Linux
CVE-2026-53224 💻 Lokal 🔓 Keine Authentifizierung nötig

USN-8658-3: Linux kernel vulnerabilities

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Open vSwitch; - SCTP protocol; (CVE-2026-53224, CVE-2026-5

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 24.6%
Microsoft
CVE-2020-24588 💻 Lokal 🔓 Keine Authentifizierung nötig

USN-8666-2: Linux kernel (Azure) vulnerabilities

Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A physically proximate atta

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
HIGH 7.5 🔥 EPSS 26.9%
Linux
CVE-2026-46968 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8681-1: OpenJDK 25 vulnerabilities

It was discovered that the JSSE component of OpenJDK 25 did not correctly authenticate users. A remote attacker could possibly use this issue to read or modify sensitive data. (CVE-2026-46968) It was discovered that the JSSE component of Op

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
MEDIUM 5.8 🔥 EPSS 5.6%
Linux
CVE-2026-70628 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8680-1: FFmpeg vulnerabilities

Adrian Junge discovered that FFmpeg incorrectly handled certain subtitle data. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-70628) Adrian Junge discovered that FFmpeg incorrectl

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 20.1%
Linux
CVE-2026-53224 💻 Lokal 🔓 Keine Authentifizierung nötig

USN-8643-4: Linux kernel vulnerabilities

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Network drivers; - Open vSwitch; - SCTP protocol; (CVE-202

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 20.1%
Linux
CVE-2026-53224 💻 Lokal 🔓 Keine Authentifizierung nötig

USN-8658-3: Linux kernel vulnerabilities

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Open vSwitch; - SCTP protocol; (CVE-2026-53224, CVE-2026-5

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 24.6%
Microsoft
CVE-2020-24588 💻 Lokal 🔓 Keine Authentifizierung nötig

USN-8666-2: Linux kernel (Azure) vulnerabilities

Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A physically proximate atta

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
HIGH 7.5 🔥 EPSS 26.9%
Linux
CVE-2026-46968 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8681-1: OpenJDK 25 vulnerabilities

It was discovered that the JSSE component of OpenJDK 25 did not correctly authenticate users. A remote attacker could possibly use this issue to read or modify sensitive data. (CVE-2026-46968) It was discovered that the JSSE component of Op

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 28.9%
Linux
CVE-2026-43804 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

DSA-6463-1 webkit2gtk - security update

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2026-43804 Heiko Kiesel discovered that visiting a website may lead to an app denial-of-service. CVE-2026-64713 Kwak Kiyong and Song Nuri discovered that we

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
CRITICAL 9.8 🔥 EPSS 94.2%
⚠️ CISA KEV Linux
CVE-2026-73570 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

CVE-2026-73570: Zimbra SNMP/logwatch RCE exploited in the wild, malware persists via /dev/shm and zimbra cron

CVE-2026-73570: Zimbra SNMP/logwatch RCE exploited in the wild, malware persists via /dev/shm and zimbra cron I recently handled a Zimbra incident related to CVE-2026-73570, so I’m sharing the cleanup notes in case it helps other admins. CV

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
MEDIUM 5.8 🔥 EPSS 5.6%
Linux
CVE-2026-70628 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8680-1: FFmpeg vulnerabilities

Adrian Junge discovered that FFmpeg incorrectly handled certain subtitle data. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-70628) Adrian Junge discovered that FFmpeg incorrectl

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 20.1%
Linux
CVE-2026-53224 💻 Lokal 🔓 Keine Authentifizierung nötig

USN-8643-4: Linux kernel vulnerabilities

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Network drivers; - Open vSwitch; - SCTP protocol; (CVE-202

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 20.1%
Linux
CVE-2026-53224 💻 Lokal 🔓 Keine Authentifizierung nötig

USN-8658-3: Linux kernel vulnerabilities

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Open vSwitch; - SCTP protocol; (CVE-2026-53224, CVE-2026-5

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 24.6%
Microsoft
CVE-2020-24588 💻 Lokal 🔓 Keine Authentifizierung nötig

USN-8666-2: Linux kernel (Azure) vulnerabilities

Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A physically proximate atta

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
HIGH 7.5 🔥 EPSS 26.9%
Linux
CVE-2026-46968 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8681-1: OpenJDK 25 vulnerabilities

It was discovered that the JSSE component of OpenJDK 25 did not correctly authenticate users. A remote attacker could possibly use this issue to read or modify sensitive data. (CVE-2026-46968) It was discovered that the JSSE component of Op

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
CRITICAL 9.5 🔥 EPSS 76.5%
Generic Security
CVE-2026-42167 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

[remote] CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE

CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE Weiterlesen

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
MEDIUM 5.8 🔥 EPSS 5.6%
Linux
CVE-2026-70628 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8680-1: FFmpeg vulnerabilities

Adrian Junge discovered that FFmpeg incorrectly handled certain subtitle data. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-70628) Adrian Junge discovered that FFmpeg incorrectl

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 20.1%
Linux
CVE-2026-53224 💻 Lokal 🔓 Keine Authentifizierung nötig

USN-8643-4: Linux kernel vulnerabilities

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Network drivers; - Open vSwitch; - SCTP protocol; (CVE-202

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 20.1%
Linux
CVE-2026-53224 💻 Lokal 🔓 Keine Authentifizierung nötig

USN-8658-3: Linux kernel vulnerabilities

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Open vSwitch; - SCTP protocol; (CVE-2026-53224, CVE-2026-5

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 24.6%
Microsoft
CVE-2020-24588 💻 Lokal 🔓 Keine Authentifizierung nötig

USN-8666-2: Linux kernel (Azure) vulnerabilities

Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A physically proximate atta

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
HIGH 7.5 🔥 EPSS 26.9%
Linux
CVE-2026-46968 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8681-1: OpenJDK 25 vulnerabilities

It was discovered that the JSSE component of OpenJDK 25 did not correctly authenticate users. A remote attacker could possibly use this issue to read or modify sensitive data. (CVE-2026-46968) It was discovered that the JSSE component of Op

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 28.9%
Linux
CVE-2026-43804 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

DSA-6463-1 webkit2gtk - security update

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2026-43804 Heiko Kiesel discovered that visiting a website may lead to an app denial-of-service. CVE-2026-64713 Kwak Kiyong and Song Nuri discovered that we

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
CRITICAL 9.8 🔥 EPSS 94.2%
⚠️ CISA KEV Linux
CVE-2026-73570 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

CVE-2026-73570: Zimbra SNMP/logwatch RCE exploited in the wild, malware persists via /dev/shm and zimbra cron

CVE-2026-73570: Zimbra SNMP/logwatch RCE exploited in the wild, malware persists via /dev/shm and zimbra cron I recently handled a Zimbra incident related to CVE-2026-73570, so I’m sharing the cleanup notes in case it helps other admins. CV

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
CRITICAL 9.5 🔥 EPSS 76.5%
Generic Security
CVE-2026-42167 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

[remote] CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE

CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE Weiterlesen

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
HIGH 7.5 🔥 EPSS 27.8%
Linux
CVE-2026-74450 💻 Lokal 🔓 Keine Authentifizierung nötig

CVE-2026-74450 | Linux Kernel up to 7.1.7/7.2-rc5 DPM interface drm/amd/pm amdgpu_dpm_get_pp_table use after free (Nessus ID 339550)

A vulnerability classified as very critical has been found in Linux Kernel up to 7.1.7/7.2-rc5. This vulnerability affects the function amdgpu_dpm_get_pp_table of the file drm/amd/pm of the component DPM interface. The manipulation leads to

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 31%
Linux
CVE-2026-74451 💻 Lokal 🔓 Keine Authentifizierung nötig

CVE-2026-74451 | Linux Kernel up to 6.12.102/6.18.43/7.1.7/7.2-rc5 panthor iface_fw_to_cpu_addr out-of-bounds (Nessus ID 339550)

A vulnerability, which was classified as very critical, was found in Linux Kernel up to 6.12.102/6.18.43/7.1.7/7.2-rc5. This issue affects the function iface_fw_to_cpu_addr of the component panthor. Such manipulation leads to out-of-bounds

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 20%
Linux
CVE-2026-74452 💻 Lokal 🔓 Keine Authentifizierung nötig

CVE-2026-74452 | Linux Kernel up to 6.12.102/6.18.43/7.1.7/7.2-rc5 panthor panthor_fw_load_section_entry heap-based overflow (Nessus ID 339550)

A vulnerability has been found in Linux Kernel up to 6.12.102/6.18.43/7.1.7/7.2-rc5 and classified as very critical. Impacted is the function panthor_fw_load_section_entry of the component panthor. Performing a manipulation results in heap-

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 24.6%
Linux
CVE-2026-74453 💻 Lokal 🔓 Keine Authentifizierung nötig

CVE-2026-74453 | Linux Kernel up to 7.2-rc5 vc4 buffer overflow (Nessus ID 339550)

A vulnerability, which was classified as very critical, has been found in Linux Kernel up to 6.6.150/6.12.102/6.18.43/7.1.7/7.2-rc5. This affects an unknown function of the component vc4. Performing a manipulation results in buffer overflow

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 22.3%
Linux
CVE-2026-74454 💻 Lokal 🔓 Keine Authentifizierung nötig

CVE-2026-74454 | Linux Kernel up to 7.2-rc5 drm/vc4 vc4_overflow_mem_work memory corruption (Nessus ID 339550)

A vulnerability was found in Linux Kernel up to 6.6.150/6.12.102/6.18.43/7.1.7/7.2-rc5 and classified as very critical. The affected element is the function vc4_overflow_mem_work of the file drm/vc4. Executing a manipulation can lead to mem

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 21.1%
Linux
CVE-2026-74457 💻 Lokal 🔓 Keine Authentifizierung nötig

CVE-2026-74457 | Linux Kernel up to 7.2-rc5 peak_usb out-of-bounds (Nessus ID 339550)

A vulnerability was found in Linux Kernel up to 6.6.150/6.12.102/6.18.43/7.1.7/7.2-rc5. It has been declared as critical. This affects the function pcan_usb_pro_handle_canmsg/pcan_usb_pro_handle_error of the component peak_usb. The manipula

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 28.7%
Linux
CVE-2026-74455 💻 Lokal 🔓 Keine Authentifizierung nötig

CVE-2026-74455 | Linux Kernel up to 7.2-rc5 peak_usb pcan_usb_fd_decode_buf buffer overflow (Nessus ID 339550)

A vulnerability was found in Linux Kernel up to 6.6.150/6.12.102/6.18.43/7.1.7/7.2-rc5. It has been classified as very critical. The impacted element is the function pcan_usb_fd_decode_buf of the component peak_usb. The manipulation leads t

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 25%
Linux
CVE-2026-74458 💻 Lokal 🔓 Keine Authentifizierung nötig

CVE-2026-74458 | Linux Kernel up to 7.2-rc5 kvaser_usb_leaf kvaser_usb_leaf_wait_cmd buffer overflow (Nessus ID 339550)

A vulnerability was found in Linux Kernel up to 6.6.150/6.12.102/6.18.43/7.1.7/7.2-rc5. It has been rated as very critical. This impacts the function kvaser_usb_leaf_wait_cmd of the component kvaser_usb_leaf. This manipulation causes buffer

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 32.2%
Apple
CVE-2022-42863 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

CVE-2022-42863 | Apple tvOS up to 16.1.1 WebKit memory corruption (HT213535 / EUVD-2022-45926)

A vulnerability was found in Apple tvOS up to 16.1.1. It has been declared as critical. This vulnerability affects unknown code of the component WebKit. Executing a manipulation can lead to memory corruption. This vulnerability is handled a

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
HIGH 7.5 🔥 EPSS 32.2%
Apple
CVE-2022-42863 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

CVE-2022-42863 | Apple macOS up to 13.0 WebKit memory corruption (HT213532 / EUVD-2022-45926)

A vulnerability classified as critical has been found in Apple macOS. Impacted is an unknown function of the component WebKit. Performing a manipulation results in memory corruption. This vulnerability is identified as CVE-2022-42863. The a

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
HIGH 7.5 🔥 EPSS 32.2%
Apple
CVE-2022-42863 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

CVE-2022-42863 | Apple Safari up to 16.1 WebKit memory corruption (HT213537 / EUVD-2022-45926)

A vulnerability labeled as critical has been found in Apple Safari up to 16.1. Impacted is an unknown function of the component WebKit. Such manipulation leads to memory corruption. This vulnerability is uniquely identified as CVE-2022-4286

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
HIGH 7.5 🔥 EPSS 25.9%
Apple
CVE-2022-42864 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

CVE-2022-42864 | Apple iOS/iPadOS up to 16.1.2 IOHIDFamily race condition (HT213530 / EUVD-2022-45927)

A vulnerability classified as critical was found in Apple iOS and iPadOS up to 16.1.2. This issue affects some unknown processing of the component IOHIDFamily. The manipulation results in race condition. This vulnerability is known as CVE-2

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
HIGH 7.5 🔥 EPSS 22.9%
Linux
CVE-2026-74460 💻 Lokal 🔓 Keine Authentifizierung nötig

CVE-2026-74460 | Linux Kernel up to 7.2-rc5 ems_usb ems_usb_read_bulk_callback buffer overflow (Nessus ID 339550)

A vulnerability categorized as very critical has been discovered in Linux Kernel up to 6.6.150/6.12.102/6.18.43/7.1.7/7.2-rc5. Affected is the function ems_usb_read_bulk_callback of the component ems_usb. Such manipulation leads to buffer o

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 19.8%
Linux
CVE-2026-74464 💻 Lokal 🔓 Keine Authentifizierung nötig

CVE-2026-74464 | Linux Kernel up to 7.2-rc5 openvswitch ovs_ct_execute memory leak (Nessus ID 339550)

A vulnerability labeled as critical has been found in Linux Kernel up to 6.6.150/6.12.102/6.18.43/7.1.7/7.2-rc5. Affected by this issue is the function ovs_ct_execute of the component openvswitch. Executing a manipulation can lead to memory

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 32.1%
Linux
CVE-2026-74468 💻 Lokal 🔓 Keine Authentifizierung nötig

CVE-2026-74468 | Linux Kernel up to 7.2-rc5 GPIO PCH spinlock_rt.c pch_irq_type locking (Nessus ID 339550)

A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.6.150/6.12.102/6.18.43/7.1.7/7.2-rc5. Impacted is the function pch_irq_type of the file kernel/locking/spinlock_rt.c of the component GPIO PCH. This m

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 31.8%
Generic Security
CVE-2026-63075 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

CVE-2026-63075 | OpenSSL up to 3.4.6/3.5.7/3.6.3/4.0.1 QUIC allocation of resources (WID-SEC-2026-3034)

A vulnerability was found in OpenSSL up to 3.4.6/3.5.7/3.6.3/4.0.1. It has been classified as problematic. Affected by this vulnerability is an unknown functionality of the component QUIC. Performing a manipulation results in allocation of

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
HIGH 7.5 🔥 EPSS 19.4%
Generic Security
CVE-2025-10903 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

CVE-2025-10903 | GitLab up to 19.1.6/19.2.4/19.3.0 SCIM User Provisioning infinite loop (WID-SEC-2026-3029)

A vulnerability described as problematic has been identified in GitLab up to 19.1.6/19.2.4/19.3.0. This impacts an unknown function of the component SCIM User Provisioning. The manipulation results in infinite loop. This vulnerability was n

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
HIGH 7.5 🔥 EPSS 27.2%
Generic Security
CVE-2026-63076 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

CVE-2026-63076 | OpenSSL up to 4.0.1 CMP OSSL_CMP_SRV_process_request protectionAlg null pointer dereference (WID-SEC-2026-3034)

A vulnerability, which was classified as problematic, was found in OpenSSL up to 3.0.21/3.4.6/3.5.7/3.6.3/4.0.1. This affects the function OSSL_CMP_SRV_process_request of the component CMP. The manipulation of the argument protectionAlg res

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
HIGH 7.5 🔥 EPSS 26.9%
Generic Security
CVE-2026-3035 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

CVE-2026-3035 | GitLab up to 19.1.6/19.2.4/19.3.0 Terminal improper authorization (WID-SEC-2026-3029)

A vulnerability was found in GitLab up to 19.1.6/19.2.4/19.3.0 and classified as critical. This issue affects some unknown processing of the component Terminal. The manipulation results in improper authorization. This vulnerability is catal

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
HIGH 7.5 🔥 EPSS 24%
Generic Security
CVE-2026-18252 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

CVE-2026-18252 | GitLab up to 19.1.6/19.2.4/19.3.0 Claude Agent permission (WID-SEC-2026-3029)

A vulnerability labeled as problematic has been found in GitLab up to 19.1.6/19.2.4/19.3.0. The impacted element is an unknown function of the component Claude Agent. Executing a manipulation can lead to permission issues. This vulnerabilit

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
HIGH 7.5 🔥 EPSS 27.6%
Generic Security
CVE-2026-15387 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

CVE-2026-15387 | GitLab up to 19.1.6/19.2.4/19.3.0 Pipeline Execution Policy privileges management (WID-SEC-2026-3029)

A vulnerability identified as problematic has been detected in GitLab up to 19.1.6/19.2.4/19.3.0. The affected element is an unknown function of the component Pipeline Execution Policy. Performing a manipulation results in improper privileg

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
HIGH 7.5 🔥 EPSS 21.7%
Generic Security
CVE-2026-8508 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

Reverse Engineering CVE-2026-8508: From Zyxel Captive Portal to Facebook Identity Trust Bypass with full firmware emulation

submitted by /u/TheReedemer69 [link] [comments] Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
CRITICAL 9.5 🔥 EPSS 73.4%
Generic Security
CVE-2026-72898 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

CVE-2026-72898: Critical Metabase Unauthenticated SQL Injection Vulnerability

CVE-2026-72898 is a critical unauthenticated SQL injection in Metabase's password-reset functionality. Learn more about it. The post CVE-2026-72898: Critical Metabase Unauthenticated SQL Injection Vulnerability appeared first on OffSec

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
CRITICAL 9.5 🔥 EPSS 77.8%
Generic Security
CVE-2026-65105 💻 Lokal 🔓 Keine Authentifizierung nötig

NVIDIA NemoClaw Vulnerability Lets Attackers Hijack AI Agents via DNS Rebinding

A critical vulnerability in NVIDIA NemoClaw, tracked as CVE-2026-65105, could enable attackers to gain persistent control of locally deployed AI agents through a single visit to a malicious website. Researchers Elad Luz and Ofek Itach from

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
CRITICAL 9.5 🔥 EPSS 63.7%
WordPress
CVE-2026-19632 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig

Critical WordPress TranslatePress Flaw Lets Attackers Take Over Admin Accounts

A critical vulnerability in the TranslatePress multilingual WordPress plugin could enable unauthenticated attackers to take control of administrator accounts and fully compromise affected websites. This vulnerability, tracked as CVE-2026-19

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
HIGH 7.5 🔥 EPSS 23.2%
Linux
CVE-2026-66152 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

SonicWall NetExtender Flaw Lets Attackers Write Arbitrary Files as Root

SonicWall has released security updates for two high-severity vulnerabilities in its NetExtender Linux Client. One of these is a path traversal flaw that could allow attackers to write arbitrary files with root privileges. The most severe i

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
CRITICAL 9.5 🔥 EPSS 62.8%
Microsoft
CVE-2026-57909 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

Critical WatchGuard Agent Flaws Let Unauthenticated Attackers Execute Remote Code

WatchGuard has revealed two critical vulnerabilities in its Windows WatchGuard Agent, which could allow unauthenticated attackers to execute arbitrary code on affected endpoints. These vulnerabilities, tracked as CVE-2026-57910 and CVE-2026

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
HIGH 7.5 🔥 EPSS 31.4%
Generic Security
CVE-2026-21962 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

U.S. CISA adds maximum-severity Oracle flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Oracle flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Oracle HTTP Server and Oracle Weblogic S

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
CRITICAL 9.8 🔥 EPSS 57.5%
WordPress
CVE-2026-61979 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as Vulnerable

Two CVSS 9.8 miniOrange SAML WordPress plugin auth bypasses were exploited while paid editions never appeared in any vulnerability database. Manual patch required. Two critical authentication bypass vulnerabilities in the miniOrange SAML 2.

CWE-287: Improper Authentication ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
HIGH 7.5 🔥 EPSS 25.5%
Generic Security
CVE-2026-60004 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Gitea flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Oracle HTTP Server and Oracle Weblogic Se

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
CRITICAL 9.5 🔥 EPSS 73.4%
Generic Security
CVE-2026-72898 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

CVE-2026-72898: Critical Metabase Unauthenticated SQL Injection Vulnerability

CVE-2026-72898 is a critical unauthenticated SQL injection in Metabase's password-reset functionality. Learn more about it. The post CVE-2026-72898: Critical Metabase Unauthenticated SQL Injection Vulnerability appeared first on OffSec

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
CRITICAL 9.5 🔥 EPSS 77.8%
Generic Security
CVE-2026-65105 💻 Lokal 🔓 Keine Authentifizierung nötig

NVIDIA NemoClaw Vulnerability Lets Attackers Hijack AI Agents via DNS Rebinding

A critical vulnerability in NVIDIA NemoClaw, tracked as CVE-2026-65105, could enable attackers to gain persistent control of locally deployed AI agents through a single visit to a malicious website. Researchers Elad Luz and Ofek Itach from

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
CRITICAL 9.5 🔥 EPSS 63.7%
WordPress
CVE-2026-19632 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig

Critical WordPress TranslatePress Flaw Lets Attackers Take Over Admin Accounts

A critical vulnerability in the TranslatePress multilingual WordPress plugin could enable unauthenticated attackers to take control of administrator accounts and fully compromise affected websites. This vulnerability, tracked as CVE-2026-19

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
HIGH 7.5 🔥 EPSS 23.2%
Linux
CVE-2026-66152 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

SonicWall NetExtender Flaw Lets Attackers Write Arbitrary Files as Root

SonicWall has released security updates for two high-severity vulnerabilities in its NetExtender Linux Client. One of these is a path traversal flaw that could allow attackers to write arbitrary files with root privileges. The most severe i

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.