🛡️ tsecurity.de
Zur Startseite 🔖 Lesezeichen
🎯 FOKUSSIERTE SCHWACHSTELLE: CVE-2026-70628 MEDIUM 5.8 🔥 EPSS 5.6%
Alle CVEs anzeigen ✕

USN-8680-1: FFmpeg vulnerabilities

Adrian Junge discovered that FFmpeg incorrectly handled certain subtitle data. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-70628) Adrian Junge discovered that FFmpeg incorrectl

Angriffsvektor: 🌐 Netzwerk (Remote) • 🔓 Keine Authentifizierung nötig
CWE-Klassifizierung: CWE-94: Code Injection
🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

🟢 SSE Realtime Synchronisiert ⚡ REST API (JSON) 📡 RSS Feed
Ökosystem & Hersteller Bedrohungs-Matrix:
Linux 29
Generic Security 19
Microsoft 10
WordPress 2
Schweregrad & Status:
Hersteller-Filter:
🔍
MEDIUM 5.8 🔥 EPSS 5.6%
Linux
CVE-2026-70628 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8680-1: FFmpeg vulnerabilities

Adrian Junge discovered that FFmpeg incorrectly handled certain subtitle data. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-70628) Adrian Junge discovered that FFmpeg incorrectl

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
MEDIUM 5.8 🔥 EPSS 5.6%
Linux
CVE-2026-70628 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8680-1: FFmpeg vulnerabilities

Adrian Junge discovered that FFmpeg incorrectly handled certain subtitle data. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-70628) Adrian Junge discovered that FFmpeg incorrectl

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 20.1%
Linux
CVE-2026-53224 💻 Lokal 🔓 Keine Authentifizierung nötig

USN-8643-4: Linux kernel vulnerabilities

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Network drivers; - Open vSwitch; - SCTP protocol; (CVE-202

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 20.1%
Linux
CVE-2026-53224 💻 Lokal 🔓 Keine Authentifizierung nötig

USN-8658-3: Linux kernel vulnerabilities

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Open vSwitch; - SCTP protocol; (CVE-2026-53224, CVE-2026-5

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 20.1%
Linux
CVE-2026-53224 💻 Lokal 🔓 Keine Authentifizierung nötig

USN-8643-4: Linux kernel vulnerabilities

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Network drivers; - Open vSwitch; - SCTP protocol; (CVE-202

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 20.1%
Linux
CVE-2026-53224 💻 Lokal 🔓 Keine Authentifizierung nötig

USN-8658-3: Linux kernel vulnerabilities

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Open vSwitch; - SCTP protocol; (CVE-2026-53224, CVE-2026-5

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 24.6%
Microsoft
CVE-2020-24588 💻 Lokal 🔓 Keine Authentifizierung nötig

USN-8666-2: Linux kernel (Azure) vulnerabilities

Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A physically proximate atta

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
HIGH 7.5 🔥 EPSS 24.6%
Microsoft
CVE-2020-24588 💻 Lokal 🔓 Keine Authentifizierung nötig

USN-8666-2: Linux kernel (Azure) vulnerabilities

Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A physically proximate atta

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
HIGH 7.5 🔥 EPSS 26.9%
Linux
CVE-2026-46968 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8681-1: OpenJDK 25 vulnerabilities

It was discovered that the JSSE component of OpenJDK 25 did not correctly authenticate users. A remote attacker could possibly use this issue to read or modify sensitive data. (CVE-2026-46968) It was discovered that the JSSE component of Op

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
MEDIUM 5.8 🔥 EPSS 6.8%
Linux
CVE-2026-3039 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8682-1: Bind vulnerabilities

Vitaly Simonovich discovered that Bind could exhaust memory during GSS-API TKEY negotiation. A remote attacker could possibly use this issue to cause Bind to use excessive resources, leading to a denial of service. (CVE-2026-3039) Shuhan Zh

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 26.9%
Linux
CVE-2026-46968 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8681-1: OpenJDK 25 vulnerabilities

It was discovered that the JSSE component of OpenJDK 25 did not correctly authenticate users. A remote attacker could possibly use this issue to read or modify sensitive data. (CVE-2026-46968) It was discovered that the JSSE component of Op

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
MEDIUM 5.8 🔥 EPSS 6.8%
Linux
CVE-2026-3039 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8682-1: Bind vulnerabilities

Vitaly Simonovich discovered that Bind could exhaust memory during GSS-API TKEY negotiation. A remote attacker could possibly use this issue to cause Bind to use excessive resources, leading to a denial of service. (CVE-2026-3039) Shuhan Zh

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
MEDIUM 5.8 🔥 EPSS 2.5%
Linux
CVE-2026-62289 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8683-1: libheif vulnerabilities

Feng Ning discovered that libheif incorrectly handled certain image transforms. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
MEDIUM 5.8 🔥 EPSS 2.5%
Linux
CVE-2026-62289 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8683-1: libheif vulnerabilities

Feng Ning discovered that libheif incorrectly handled certain image transforms. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
MEDIUM 5.8 🔥 EPSS 5.6%
Linux
CVE-2026-70628 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8680-1: FFmpeg vulnerabilities

Adrian Junge discovered that FFmpeg incorrectly handled certain subtitle data. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-70628) Adrian Junge discovered that FFmpeg incorrectl

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 20.1%
Linux
CVE-2026-53224 💻 Lokal 🔓 Keine Authentifizierung nötig

USN-8643-4: Linux kernel vulnerabilities

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Network drivers; - Open vSwitch; - SCTP protocol; (CVE-202

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 20.1%
Linux
CVE-2026-53224 💻 Lokal 🔓 Keine Authentifizierung nötig

USN-8658-3: Linux kernel vulnerabilities

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Open vSwitch; - SCTP protocol; (CVE-2026-53224, CVE-2026-5

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
MEDIUM 5.8 🔥 EPSS 5.6%
Linux
CVE-2026-70628 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8680-1: FFmpeg vulnerabilities

Adrian Junge discovered that FFmpeg incorrectly handled certain subtitle data. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-70628) Adrian Junge discovered that FFmpeg incorrectl

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 24.6%
Microsoft
CVE-2020-24588 💻 Lokal 🔓 Keine Authentifizierung nötig

USN-8666-2: Linux kernel (Azure) vulnerabilities

Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A physically proximate atta

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
HIGH 7.5 🔥 EPSS 20.1%
Linux
CVE-2026-53224 💻 Lokal 🔓 Keine Authentifizierung nötig

USN-8643-4: Linux kernel vulnerabilities

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Network drivers; - Open vSwitch; - SCTP protocol; (CVE-202

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 26.9%
Linux
CVE-2026-46968 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8681-1: OpenJDK 25 vulnerabilities

It was discovered that the JSSE component of OpenJDK 25 did not correctly authenticate users. A remote attacker could possibly use this issue to read or modify sensitive data. (CVE-2026-46968) It was discovered that the JSSE component of Op

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 20.1%
Linux
CVE-2026-53224 💻 Lokal 🔓 Keine Authentifizierung nötig

USN-8658-3: Linux kernel vulnerabilities

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Open vSwitch; - SCTP protocol; (CVE-2026-53224, CVE-2026-5

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
MEDIUM 5.8 🔥 EPSS 6.8%
Linux
CVE-2026-3039 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8682-1: Bind vulnerabilities

Vitaly Simonovich discovered that Bind could exhaust memory during GSS-API TKEY negotiation. A remote attacker could possibly use this issue to cause Bind to use excessive resources, leading to a denial of service. (CVE-2026-3039) Shuhan Zh

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
MEDIUM 5.8 🔥 EPSS 2.5%
Linux
CVE-2026-62289 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8683-1: libheif vulnerabilities

Feng Ning discovered that libheif incorrectly handled certain image transforms. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 24.6%
Microsoft
CVE-2020-24588 💻 Lokal 🔓 Keine Authentifizierung nötig

USN-8666-2: Linux kernel (Azure) vulnerabilities

Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A physically proximate atta

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
HIGH 7.5 🔥 EPSS 26.9%
Linux
CVE-2026-46968 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8681-1: OpenJDK 25 vulnerabilities

It was discovered that the JSSE component of OpenJDK 25 did not correctly authenticate users. A remote attacker could possibly use this issue to read or modify sensitive data. (CVE-2026-46968) It was discovered that the JSSE component of Op

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
MEDIUM 5.8 🔥 EPSS 6.8%
Linux
CVE-2026-3039 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8682-1: Bind vulnerabilities

Vitaly Simonovich discovered that Bind could exhaust memory during GSS-API TKEY negotiation. A remote attacker could possibly use this issue to cause Bind to use excessive resources, leading to a denial of service. (CVE-2026-3039) Shuhan Zh

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
MEDIUM 5.8 🔥 EPSS 2.5%
Linux
CVE-2026-62289 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8683-1: libheif vulnerabilities

Feng Ning discovered that libheif incorrectly handled certain image transforms. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 28.9%
Linux
CVE-2026-43804 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

DSA-6463-1 webkit2gtk - security update

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2026-43804 Heiko Kiesel discovered that visiting a website may lead to an app denial-of-service. CVE-2026-64713 Kwak Kiyong and Song Nuri discovered that we

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 28.9%
Linux
CVE-2026-43804 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

DSA-6463-1 webkit2gtk - security update

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2026-43804 Heiko Kiesel discovered that visiting a website may lead to an app denial-of-service. CVE-2026-64713 Kwak Kiyong and Song Nuri discovered that we

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
CRITICAL 9.8 🔥 EPSS 94.2%
⚠️ CISA KEV Linux
CVE-2026-73570 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

CVE-2026-73570: Zimbra SNMP/logwatch RCE exploited in the wild, malware persists via /dev/shm and zimbra cron

CVE-2026-73570: Zimbra SNMP/logwatch RCE exploited in the wild, malware persists via /dev/shm and zimbra cron I recently handled a Zimbra incident related to CVE-2026-73570, so I’m sharing the cleanup notes in case it helps other admins. CV

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
CRITICAL 9.8 🔥 EPSS 94.2%
⚠️ CISA KEV Linux
CVE-2026-73570 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

CVE-2026-73570: Zimbra SNMP/logwatch RCE exploited in the wild, malware persists via /dev/shm and zimbra cron

CVE-2026-73570: Zimbra SNMP/logwatch RCE exploited in the wild, malware persists via /dev/shm and zimbra cron I recently handled a Zimbra incident related to CVE-2026-73570, so I’m sharing the cleanup notes in case it helps other admins. CV

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
CRITICAL 9.5 🔥 EPSS 76.5%
Generic Security
CVE-2026-42167 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

[remote] CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE

CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE Weiterlesen

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
CRITICAL 9.5 🔥 EPSS 76.5%
Generic Security
CVE-2026-42167 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

[remote] CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE

CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE Weiterlesen

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
CRITICAL 9.5 🔥 EPSS 58%
Microsoft
CVE-2026-69836 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

Microsoft Reverses Its Own ‘Exploitation’ Warning on Entra ID Flaw CVE-2026-69836

Microsoft disclosed and fixed a maximum-severity remote code execution vulnerability in Entra ID, its cloud identity platform, on August 20, then quietly reversed the advisory's exploitation status a day later - leaving enterprise defe

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
HIGH 7.5 🔥 EPSS 30.2%
Generic Security
CVE-2026-73570 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

274 Zimbra Servers Compromised as 8,200 Remain Unpatched

Attackers have compromised at least 274 Zimbra servers, while thousands of unpatched systems remain potentially exposed. The Shadowserver Foundation said it identified 274 compromised internet-facing Zimbra instances on Aug. 22, up from 155

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
CRITICAL 9.5 🔥 EPSS 63.7%
WordPress
CVE-2026-19632 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig

Critical WordPress TranslatePress Flaw Lets Attackers Take Over Admin Accounts

A critical vulnerability in the TranslatePress multilingual WordPress plugin could enable unauthenticated attackers to take control of administrator accounts and fully compromise affected websites. This vulnerability, tracked as CVE-2026-19

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
HIGH 7.5 🔥 EPSS 23.2%
Linux
CVE-2026-66152 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

SonicWall NetExtender Flaw Lets Attackers Write Arbitrary Files as Root

SonicWall has released security updates for two high-severity vulnerabilities in its NetExtender Linux Client. One of these is a path traversal flaw that could allow attackers to write arbitrary files with root privileges. The most severe i

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
CRITICAL 9.5 🔥 EPSS 62.8%
Microsoft
CVE-2026-57909 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

Critical WatchGuard Agent Flaws Let Unauthenticated Attackers Execute Remote Code

WatchGuard has revealed two critical vulnerabilities in its Windows WatchGuard Agent, which could allow unauthenticated attackers to execute arbitrary code on affected endpoints. These vulnerabilities, tracked as CVE-2026-57910 and CVE-2026

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
CRITICAL 9.5 🔥 EPSS 63.7%
WordPress
CVE-2026-19632 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

Critical WordPress TranslatePress Bug Enables Complete Site Takeover

A critical vulnerability in the TranslatePress multilingual plugin, installed on over 400,000 WordPress sites, allows unauthenticated attackers to hijack administrator accounts and seize full control of affected websites. Tracked as CVE-202

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
CRITICAL 9.5 🔥 EPSS 77.8%
Generic Security
CVE-2026-65105 💻 Lokal 🔓 Keine Authentifizierung nötig

NVIDIA NemoClaw Flaw Lets Attackers Hijack AI Agents Through DNS Rebinding

A critical vulnerability in NVIDIA NemoClaw, tracked as CVE-2026-65105, could let attackers hijack AI agents after a victim visits a malicious website. The issue combines an insecure Ollama network configuration with DNS rebinding, allowing

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
CRITICAL 9.5 🔥 EPSS 78%
Microsoft
CVE-2026-55040 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

Microsoft SharePoint Flaws Chain to Unauthenticated Remote Code Execution

Microsoft SharePoint Server administrators are being urged to apply updates immediately after researchers observed attackers probing a two-vulnerability chain that could deliver unauthenticated remote code execution against internet-exposed

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
CRITICAL 9.5 🔥 EPSS 62.8%
Microsoft
CVE-2026-57909 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

Critical WatchGuard Agent Flaws Let Remote Attackers Execute Arbitrary Code

WatchGuard has disclosed two critical vulnerabilities in its Windows-based WatchGuard Agent that could allow unauthenticated attackers to execute arbitrary code on vulnerable endpoints. The flaws, tracked as CVE-2026-57910 and CVE-2026-5790

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
HIGH 8.0 🔥 EPSS 19.7%
Generic Security
CVE-2026-75149 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

Marimo schließt MCP-Code-Injection: CVE-2026-75149 im Edit-Modus

LONDON (IT BOLTWISE) – Marimo hat eine Sicherheitslücke in seinem Notebook-Ökosystem behoben, die im Edit-Modus eine MCP-Kommandosequenz als lokalen Subprozess starten kann. Betroffen ist CVE-2026-75149, bewertet mit CVSS v4 8,7 und CVSS v3

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
CRITICAL 9.5 🔥 EPSS 67.5%
Generic Security
CVE-2026-60004 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

CISA warnt: Gitea-RCE-Kritikalität CVE-2026-60004 wird aktiv ausgenutzt

LONDON (IT BOLTWISE) – Die US-Sicherheitsbehörde CISA warnt vor aktiver Ausnutzung einer kürzlich gepatchten Gitea-Schwachstelle. Betroffen ist CVE-2026-60004 mit einem CVSS-Score von 9,8, die Remote Code Execution über das diffpatch-Interf

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
CRITICAL 9.5 🔥 EPSS 67.5%
Generic Security
CVE-2026-60004 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

Gitea-RCE (CVE-2026-60004) wird aktiv ausgenutzt: Crypto-Miner-ähnlicher Dropper nach Patch

LONDON (IT BOLTWISE) – Die US-Behörde CISA warnt vor aktiver Ausnutzung einer kürzlich gepatchten Gitea-Sicherheitslücke. Betroffen ist CVE-2026-60004 mit einem CVSS-Score von 9,8, die Remote Code Execution über den diffpatch-Endpunkt ermög

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
CRITICAL 9.5 🔥 EPSS 60.7%
Microsoft
CVE-2026-75604 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

Critical Next.js Vulnerabilities Enables Remote Code Execution Attacks

Two critical Next.js flaws allow unauthenticated remote code execution on Windows-hosted applications using the Image Optimization API to process AVIF images. The first flaw, tracked as CVE-2026-75604, affects Next.js applications that use

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
CRITICAL 9.8 🔥 EPSS 89.5%
⚠️ CISA KEV Generic Security
CVE-2026-60004 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

CISA Warns of Gitea Code Injection Vulnerability Exploited in Attacks

The Cybersecurity and Infrastructure Security Agency has added a newly disclosed Gitea vulnerability to its Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. The flaw, tracked as CVE-2026-60004, affects Gi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
CRITICAL 9.5 🔥 EPSS 62.8%
Microsoft
CVE-2026-57909 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

WatchGuard Agent for Windows Vulnerability Allows Code Execution with Elevated Privileges

WatchGuard has disclosed two critical vulnerabilities in its Windows-based WatchGuard Agent that could allow unauthenticated attackers to execute arbitrary code with elevated privileges. The flaws, tracked as CVE-2026-57910 and CVE-2026-579

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
HIGH 7.5 🔥 EPSS 30.2%
Generic Security
CVE-2026-73570 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

274 Zimbra Servers Compromised as 8,200 Remain Unpatched

Attackers exploited CVE-2026-73570 to compromise 274 Zimbra servers, while 8,200 systems remain unpatched. Learn what administrators should check. This article has been indexed from eSecurity Planet Read the original article: 274 Zimbra Ser

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
CRITICAL 9.8 🔥 EPSS 89.5%
⚠️ CISA KEV Generic Security
CVE-2026-60004 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

CISA Warns of Gitea Code Injection Vulnerability Exploited in Attacks

The Cybersecurity and Infrastructure Security Agency has added a newly disclosed Gitea vulnerability to its Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. The flaw, tracked as CVE-2026-60004, affects Gi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
CRITICAL 9.8 🔥 EPSS 87.1%
⚠️ CISA KEV Generic Security
CVE-2026-8452 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

Recent Citrix NetScaler Vulnerability Exploited in the Wild

CISA is urging government agencies to immediately patch the Citrix NetScaler vulnerability tracked as CVE-2026-8452. This article has been indexed from SecurityWeek Read the original article: Recent Citrix NetScaler Vulnerability Exploited

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
HIGH 7.5 🔥 EPSS 28.7%
Generic Security
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

[UPDATE] [kritisch] GeoServer: Schwachstelle ermöglicht SQL-Injection und potenziell Codeausführung

Ein entfernter, anonymer Angreifer kann eine Schwachstelle in GeoServer ausnutzen, um einen SQL-Injection Angriff durchzuführen, und potenziell um beliebigen Programmcode auszuführen. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
HIGH 7.5 🔥 EPSS 28.7%
Generic Security
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

[NEU] [mittel] Dell BIOS: Schwachstelle ermöglicht Manipulation von Daten

Ein lokaler Angreifer kann eine Schwachstelle in Dell BIOS ausnutzen, um Daten zu manipulieren. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
HIGH 7.5 🔥 EPSS 28.7%
Generic Security
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

[NEU] [UNGEPATCHT] [mittel] RPM: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit Benutzerrechten

Ein lokaler Angreifer kann eine Schwachstelle in RPM ausnutzen, um beliebigen Programmcode mit Benutzerrechten auszuführen. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
MEDIUM 5.8 🔥 EPSS 2.7%
Generic Security
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

[UPDATE] [mittel] Erlang/OTP: Schwachstelle ermöglicht Denial of Service

Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Erlang/OTP ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
HIGH 7.5 🔥 EPSS 28.7%
Generic Security
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

[UPDATE] [mittel] LibreOffice: Schwachstelle ermöglicht Codeausführung

Ein entfernter, anonymer Angreifer kann eine Schwachstelle in LibreOffice ausnutzen, um beliebigen Programmcode auszuführen. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
HIGH 7.5 🔥 EPSS 28.7%
Generic Security
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

[NEU] [mittel] bluez: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit Administratorrechten

Ein Angreifer in Bluetooth-Reichweite kann eine Schwachstelle in bluez ausnutzen, um beliebigen Programmcode mit Administratorrechten auszuführen. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
HIGH 7.5 🔥 EPSS 28.7%
Generic Security
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

[NEU] [mittel] Devolutions Remote Desktop Manager: Schwachstelle ermöglicht Manipulation von Daten

Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Devolutions Remote Desktop Manager ausnutzen, um Daten zu manipulieren. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
HIGH 7.5 🔥 EPSS 28.7%
Generic Security
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

[NEU] [mittel] FasterXML Jackson: Schwachstelle ermöglicht Offenlegung von Informationen

Ein entfernter, anonymer Angreifer kann eine Schwachstelle in FasterXML Jackson ausnutzen, um Informationen offenzulegen. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.