🛡️ tsecurity.de
Zur Startseite 🔖 Lesezeichen
🎯 FOKUSSIERTE SCHWACHSTELLE: CVE-2026-66036 MEDIUM 5.8 🔥 EPSS 3%
Alle CVEs anzeigen ✕

USN-8671-1: FFmpeg vulnerabilities

Adrian Junge was discovered that FFmpeg incorrectly handled certain media files. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-66036, CVE-2026-66039) Adrian Junge discovered that

Angriffsvektor: 🌐 Netzwerk (Remote) • 🔓 Keine Authentifizierung nötig
CWE-Klassifizierung: CWE-94: Code Injection
🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

🟢 SSE Realtime Synchronisiert ⚡ REST API (JSON) 📡 RSS Feed
Ökosystem & Hersteller Bedrohungs-Matrix:
Linux 10
Generic Security 3
Apache 1
Schweregrad & Status:
Hersteller-Filter:
🔍
MEDIUM 5.8 🔥 EPSS 3%
Linux
CVE-2026-66036 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8671-1: FFmpeg vulnerabilities

Adrian Junge was discovered that FFmpeg incorrectly handled certain media files. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-66036, CVE-2026-66039) Adrian Junge discovered that

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
MEDIUM 5.8 🔥 EPSS 3%
Linux
CVE-2026-66036 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8671-1: FFmpeg vulnerabilities

Adrian Junge was discovered that FFmpeg incorrectly handled certain media files. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-66036, CVE-2026-66039) Adrian Junge discovered that

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 28.9%
Linux
CVE-2026-43804 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

DSA-6463-1 webkit2gtk - security update

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2026-43804 Heiko Kiesel discovered that visiting a website may lead to an app denial-of-service. CVE-2026-64713 Kwak Kiyong and Song Nuri discovered that we

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 28.9%
Linux
CVE-2026-43804 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

DSA-6463-1 webkit2gtk - security update

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2026-43804 Heiko Kiesel discovered that visiting a website may lead to an app denial-of-service. CVE-2026-64713 Kwak Kiyong and Song Nuri discovered that we

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
MEDIUM 5.8 🔥 EPSS 3%
Linux
CVE-2026-66036 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8671-1: FFmpeg vulnerabilities

Adrian Junge was discovered that FFmpeg incorrectly handled certain media files. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-66036, CVE-2026-66039) Adrian Junge discovered that

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
MEDIUM 5.8 🔥 EPSS 3%
Linux
CVE-2026-66036 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8671-1: FFmpeg vulnerabilities

Adrian Junge was discovered that FFmpeg incorrectly handled certain media files. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-66036, CVE-2026-66039) Adrian Junge discovered that

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
MEDIUM 5.8 🔥 EPSS 3%
Linux
CVE-2026-66036 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8671-1: FFmpeg vulnerabilities

Adrian Junge was discovered that FFmpeg incorrectly handled certain media files. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-66036, CVE-2026-66039) Adrian Junge discovered that

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
MEDIUM 5.8 🔥 EPSS 3%
Linux
CVE-2026-66036 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8671-1: FFmpeg vulnerabilities

Adrian Junge was discovered that FFmpeg incorrectly handled certain media files. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-66036, CVE-2026-66039) Adrian Junge discovered that

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 28.9%
Linux
CVE-2026-43804 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

DSA-6463-1 webkit2gtk - security update

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2026-43804 Heiko Kiesel discovered that visiting a website may lead to an app denial-of-service. CVE-2026-64713 Kwak Kiyong and Song Nuri discovered that we

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 28.9%
Linux
CVE-2026-43804 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

DSA-6463-1 webkit2gtk - security update

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2026-43804 Heiko Kiesel discovered that visiting a website may lead to an app denial-of-service. CVE-2026-64713 Kwak Kiyong and Song Nuri discovered that we

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 30.2%
Generic Security
CVE-2026-73570 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

Exploited Zimbra Flaw Highlights Shrinking Window to Patch

CISA has issued a three-day deadline for agencies to patch a Zimbra security vulnerability, CVE-2026-73570, which allows full takeover of a user's communications. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
CRITICAL 9.5 🔥 EPSS 64.4%
Generic Security
CVE-2026-18963 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any user account by forcing

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
HIGH 7.5 🔥 EPSS 28.7%
Apache
CVE-2021-44228 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

Vulnerability Management: Process, Tools and Best Practices for Enterprise (2026)

By HOC Team  |  Last updated: August 2026  |  Read time: ~24 min In December 2021, the Apache Log4Shell vulnerability (CVE-2021-44228) was published. Within 12 hours, scanning for vulnerable systems had begun at scale. Within 72 hours, expl

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
CRITICAL 9.5 🔥 EPSS 64.4%
Generic Security
CVE-2026-18963 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any user account by forcing

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.