CVE-2026-77549: Schwachstellen-Eintrag (NVD)
A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances.
Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-12 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
CVE-2026-89682 | Linux Kernel up to 6.18.50/7.2.3 nfsd nfsd_file_dispose_list_delayed use after free (Nessus ID 345435)
A vulnerability categorized as very critical has been discovered in Linux Kernel up to 6.18.50/7.2.3. This affects the function nfsd_file_dispose_list_delayed of the component nfsd. Such manipulation leads to use after free. This vulnerabil
CVE-2026-89724 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 FWHT encoder vidioc_s_fmt_vid_out out-of-bounds write (Nessus ID 345436)
A vulnerability has been found in Linux Kernel up to 6.12.108/6.18.49/7.2.3 and classified as very critical. This vulnerability affects the function vidioc_s_fmt_vid_out of the component FWHT encoder. This manipulation causes out-of-bounds
CVE-2026-80990 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 Thunderbolt tbnet_connected_work allocation of resources (Nessus ID 345437)
A vulnerability marked as critical has been reported in Linux Kernel up to 6.12.108/6.18.49/7.2.3. This impacts the function tbnet_connected_work of the component Thunderbolt. This manipulation causes allocation of resources. This vulnerabi
CVE-2026-89706 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 nfsd _nfsd_copy_file_range race condition (Nessus ID 345438)
A vulnerability identified as problematic has been detected in Linux Kernel up to 6.12.108/6.18.49/7.2.3. This vulnerability affects the function _nfsd_copy_file_range of the component nfsd. Performing a manipulation results in race conditi
CVE-2026-89508 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 ucma ucma_set_ib_path use after free (Nessus ID 345439)
A vulnerability described as very critical has been identified in Linux Kernel up to 6.12.108/6.18.49/7.2.3. The impacted element is the function ucma_set_ib_path of the component ucma. Executing a manipulation can lead to use after free. T
CVE-2026-89550 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 SUNRPC svcauth_gss_unwrap_priv len divide by zero (Nessus ID 345441)
A vulnerability classified as critical was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. This impacts the function svcauth_gss_unwrap_priv of the component SUNRPC. Such manipulation of the argument len leads to divide by zero. This vu
CVE-2026-89731 | Linux Kernel up to 6.18.50/7.2.3 cxl_ras cxl_rch_get_aer_info out-of-bounds (Nessus ID 345440)
A vulnerability classified as critical has been found in Linux Kernel up to 6.18.50/7.2.3. This affects the function cxl_rch_get_aer_info of the component cxl_ras. The manipulation leads to out-of-bounds read. This vulnerability is traded a
CVE-2026-89668 | Linux Kernel up to 6.18.49/7.2.3 Nfsd Debugfs init_nfsd use after free (Nessus ID 345443)
A vulnerability, which was classified as very critical, has been found in Linux Kernel up to 6.18.49/7.2.3. The affected element is the function init_nfsd of the component Nfsd Debugfs. This manipulation causes use after free. This vulnerab
CVE-2026-89643 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 Audit audit_del_rule use after free (Nessus ID 345442)
A vulnerability was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. It has been rated as very critical. This impacts the function audit_del_rule of the component Audit. The manipulation leads to use after free. This vulnerability is lis
CVE-2026-89560 | Linux Kernel up to 6.18.49/7.2.3 landlock permission (Nessus ID 345444)
A vulnerability was found in Linux Kernel up to 6.18.49/7.2.3. It has been rated as very critical. This vulnerability affects unknown code of the component landlock. The manipulation leads to permission issues. This vulnerability is uniquel
CVE-2026-89511 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 qede qede_fill_frag_skb null pointer dereference (Nessus ID 345445)
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. Affected is the function qede_fill_frag_skb of the component qede. This manipulation causes null pointer dereference. This vulne
CVE-2026-84651 | Jenkins Project up to 2.567.x REST API permission
A vulnerability labeled as problematic has been found in Jenkins Project Jenkins up to 2.567.x. This impacts an unknown function of the component REST API. Such manipulation leads to permission issues. This vulnerability is listed as CVE-20
CVE-2026-84648 | Jenkins Project Jenkins Plugin up to 2.567.x Log Viewer cross site scripting
A vulnerability was found in Jenkins Project Jenkins Plugin up to 2.567.x and classified as problematic. The affected element is an unknown function of the component Log Viewer. Executing a manipulation can lead to cross site scripting. Thi
CVE-2026-84652 | Jenkins Project up to 2.567.x session fixiation
A vulnerability classified as very critical was found in Jenkins Project Jenkins up to 2.567.x. This affects an unknown part. The manipulation results in session fixiation. This vulnerability is reported as CVE-2026-84652. The attack can be
CVE-2026-65646 | WebPros Plesk prior 18.0.79.8/18.0.80.4 DNS zone management neutralization
A vulnerability was found in WebPros Plesk. It has been declared as critical. This affects the function DNS zone management. The manipulation results in improper neutralization. This vulnerability is cataloged as CVE-2026-65646. The attack
CVE-2026-84646 | Jenkins Project Jenkins Plugin up to 2.567.x permission
A vulnerability categorized as critical has been discovered in Jenkins Project Jenkins Plugin up to 2.567.x. The impacted element is an unknown function. The manipulation results in permission issues. This vulnerability is identified as CVE
CVE-2026-84650 | Jenkins Project up to 2.567.x Transient Field deserialization
A vulnerability identified as problematic has been detected in Jenkins Project Jenkins up to 2.567.x. This affects an unknown function of the component Transient Field. This manipulation causes deserialization. This vulnerability is tracked
CVE-2026-84645 | Jenkins Project up to 2.567.x Stapler config.xml deserialization
A vulnerability, which was classified as critical, has been found in Jenkins Project Jenkins up to 2.567.x. Affected by this vulnerability is an unknown functionality of the file config.xml of the component Stapler. The manipulation leads t
CVE-2026-58616 | Microsoft Edge up to 151.0.4129.86 Copilot Chat race condition
A vulnerability described as problematic has been identified in Microsoft Edge. This impacts an unknown function of the component Copilot Chat. Executing a manipulation can lead to race condition. This vulnerability is handled as CVE-2026-5
China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks
China-linked threat actors UTA0560 and JungleBamboo chained a Google Chrome zero-day with a Windows kernel privilege-escalation flaw in phishing campaigns targeting NGOs and other victims. Volexity documented the operations, detected on Sep
CISA Warns of Critical GitLab Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab flaw, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog after confirming it was exploited in attacks. The issue affects bot
DSA-6496-1 nginx - security update
Multiple vulnerabilities were discovered in nginx, a high-performance web and reverse proxy server, which may result in denial of service, memory disclosure or potentially the execution of arbitrary code. CVE-2026-42533 A heap buffer overfl
VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data
Two security vulnerabilities in VLC media player versions 3.0.0 through 3.0.23 could allow attackers to exploit heap memory issues. These vulnerabilities can be triggered by processing a malicious PNG file or connecting to attacker-controll
CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, warning that these flaws are actively being exploited in the wild. On
cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw
A recently disclosed vulnerability in ConfigServer Security &amp; Firewall (CSF) could allow unauthenticated remote attackers to execute arbitrary commands through the product’s MESSENGER service. This vulnerability, tracked as CVE-2026
Attackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware
Three threat groups are exploiting two Cisco FMC flaws to steal credentials, gain root access and deploy Qilin ransomware. Cisco Talos says three separate threat groups are exploiting two recently patched Secure Firewall Management Center (
[remote] CVE-2026-80428 Unauthenticated PHP Object Injection via Shibboleth - ILIAS < 9.22, 10.0 < 10.10, 11.0 < 11.3 - RCE
CVE-2026-80428 Unauthenticated PHP Object Injection via Shibboleth - ILIAS &lt; 9.22, 10.0 &lt; 10.10, 11.0 &lt; 11.3 - RCE Weiterlesen
Analysis of a SonicWall SMA1000 exploitation toolkit: refactored Rapid7 PoC, LDAP decryptor, appliance-hosted Impacket
The operator's full toolset was recovered from an open directory, so there is a fair bit to pick through. The exploit (cve-2026-15409-exploit.py) is a direct refactor of Rapid7's public PoC, still crediting Ryan Emmons in the head
USN-8745-1: KissFFT vulnerabilities
It was discovered that KissFFT incorrectly handled certain large Fourier transform sizes on 32-bit architectures. An attacker could possibly use this issue to cause KissFFT to crash, resulting in a denial of service, or execute arbitrary co
USN-8745-1: KissFFT vulnerabilities
It was discovered that KissFFT incorrectly handled certain large Fourier transform sizes on 32-bit architectures. An attacker could possibly use this issue to cause KissFFT to crash, resulting in a denial of service, or execute arbitrary co
USN-8744-1: Python vulnerabilities
It was discovered that Python's http.cookies module incorrectly handled control characters in certain cookie operations. An attacker could possibly use this issue to inject arbitrary content. This issue only affected Ubuntu 14.04 LTS,
USN-8744-1: Python vulnerabilities
It was discovered that Python's http.cookies module incorrectly handled control characters in certain cookie operations. An attacker could possibly use this issue to inject arbitrary content. This issue only affected Ubuntu 14.04 LTS,
USN-8743-1: PHP vulnerabilities
It was discovered that PHP incorrectly handled backslash escaping in the PostgreSQL extension. An attacker could use this issue to perform SQL injection attacks. (CVE-2026-17543) It was discovered that PHP incorrectly handled certain inputs
USN-8743-1: PHP vulnerabilities
It was discovered that PHP incorrectly handled backslash escaping in the PostgreSQL extension. An attacker could use this issue to perform SQL injection attacks. (CVE-2026-17543) It was discovered that PHP incorrectly handled certain inputs
USN-8741-1: Flatpak vulnerabilities
It was discovered that Flatpak did not properly validate paths in sandbox-expose options. A malicious or compromised Flatpak app could use app-controlled symlinks to access arbitrary host files and gain code execution in the host context. T
USN-8741-1: Flatpak vulnerabilities
It was discovered that Flatpak did not properly validate paths in sandbox-expose options. A malicious or compromised Flatpak app could use app-controlled symlinks to access arbitrary host files and gain code execution in the host context. T
U.S. CISA adds Microsoft Windows, N-able N-central, and Adobe flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft Windows, N-able N-central, and Adobe flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added th
Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days
Four espionage groups used the BlueMoon Chrome+Windows exploit kit within 12 days. Researchers suspect AI development. Proofpoint published a detailed analysis of a Chrome-and-Windows exploit kit it tracks as BlueMoon that four nation-state
Active exploitation of Cisco Secure Firewall Management Center vulnerabilities
Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software. First, CVE-2026-20079 is an authentication bypass vulnerability in unpatched instances of Cisco’s Secure F
Need guidance on investigating a JBoss Java service on port 28080 — possible Log4Shell angle (CVE-2021-44228), no callback received
Hi everyone, I'm working on an authorized penetration testing case study/lab, and I'm currently stuck while investigating TCP/28080. Looking for guidance on what I should investigate next. Nmap: 28080/tcp open http JBoss Enterpris
Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."Microsoft notes that 2 of the vulnerabiliti
CVE-2025-25249 Exploitation Delivers PivotC2, a FortiGate Post-Exploitation RAT
New research: PivotC2, an AI-assisted Node.js RAT built specifically for post-exploitation on FortiGate. SOCKS5/HTTP tunneling, port forwarding, config harvesting, credential decryption, and an autonomous "auto-mode." Delivered vi
DSA-6487-1 strongswan - security update
Multiple vulnerabilities were found in strongSwan, an IKE/IPsec suite. CVE-2026-78123 An undefined memory access vulnerability in the openssl plugin when handling PKCS#7 containers, that can result in a crash. CVE-2026-78124 A memory leak i
ProFTPD mod_sql post-authentication SQLi RCE
Topic: ProFTPD mod_sql post-authentication SQLi RCE Risk: Medium Text:#!/usr/bin/env python3 """ CVE-2026-42167 — ProFTPD mod_sql post-authentication SQL injection -&gt; RCE postauth_stor_r... Weiterlesen
CVE-2026-75757 | Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an attacker who controls a sibling subdomain rebind an admin's session to a different actor, tenant, or authorization mode. AshAdmin's client JavaScript read its state cookies (tenant, actor_resource, actor_primary_key, actor_action, actor_domain, actor_authorizing, actor_paused) by matching the cookie name with an unanchored regular expression (new RegE
Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an attacker who controls a sibling subdomain rebind an admin's session to a different actor, tenant, or authorization mode. AshAdmin'
CVE-2026-82605 | A vulnerability has been found in BareBones BBEdit up to 15.5.5. The affected element is an unknown function of the component Lasso Language Tokenizer. Such manipulation leads to infinite loop. The attack can be executed remotely. Upgrading to version 16.0 is sufficient to fix this issue. The affected component should be upgraded.
A vulnerability has been found in BareBones BBEdit up to 15.5.5. The affected element is an unknown function of the component Lasso Language Tokenizer. Such manipulation leads to infinite loop. The attack can be executed remotely. Upgrading
CVE-2026-82604 | A flaw has been found in BareBones BBEdit up to 15.5.5. Impacted is an unknown function of the component Java Language Module. This manipulation causes uncontrolled recursion. Remote exploitation of the attack is possible. Upgrading to version 16.0 is recommended to address this issue. You should upgrade the affected component.
A flaw has been found in BareBones BBEdit up to 15.5.5. Impacted is an unknown function of the component Java Language Module. This manipulation causes uncontrolled recursion. Remote exploitation of the attack is possible. Upgrading to vers
CVE-2026-82603 | A vulnerability was detected in SeaCMS up to 13.6. This issue affects some unknown processing of the file /member.php?action=del_pl of the component Comment Cache. The manipulation of the argument itype/vid results in path traversal. The attack may be launched remotely. The exploit is now public and may be used.
A vulnerability was detected in SeaCMS up to 13.6. This issue affects some unknown processing of the file /member.php?action=del_pl of the component Comment Cache. The manipulation of the argument itype/vid results in path traversal. The at
CVE-2026-82602 | A security vulnerability has been detected in SeaCMS up to 13.6. This vulnerability affects unknown code of the file /ass.php. The manipulation leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
A security vulnerability has been detected in SeaCMS up to 13.6. This vulnerability affects unknown code of the file /ass.php. The manipulation leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclo
CVE-2026-82601 | A weakness has been identified in SeaCMS up to 13.6. This affects an unknown part of the file /err.php. Executing a manipulation of the argument errtxt can lead to cross site scripting. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.
A weakness has been identified in SeaCMS up to 13.6. This affects an unknown part of the file /err.php. Executing a manipulation of the argument errtxt can lead to cross site scripting. The attack can be launched remotely. The exploit has b
CVE-2026-75760 | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In AshAi.Changes.Vectorize, when the embedding provider call fails the change added a changeset error whose message inspected the raw error term (An error occurred while generating embeddings: #{inspect(error)}). A plain-string add_error produces an Ash.Error.Changes.InvalidChange
Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In AshAi.Changes.Vectorize, when the embedding provider ca
CVE-2026-82580 | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses internal error text to chat users. In AshAi.ToolLoop and AshAi.Tools, an exception raised while executing a tool was serialized verbatim with Exception.message/1 into the tool-result content. That content is appended to the conversation, emitted as a {:tool_result, ...} stream event, and sent back to the model, which typically relays it to the user. No
Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses internal error text to chat users. In AshAi.ToolLoop and AshAi.Tools, an exception raised while executing a tool was serialized verb
CVE-2026-82579 | Loop with Unreachable Exit Condition (Infinite Loop) vulnerability in ash-project ash_ai allows an attacker who can influence a model's output to hang the tool loop and drive unbounded, repeated model requests. AshAi.ToolLoop classifies a model response of :tool_calls, then filters the calls through normalize_tool_calls/2 and unprocessed_tool_calls/2. Both can empty the list: a call missing a valid name, or one reusing a tool_call_id that already has a resul
Loop with Unreachable Exit Condition (Infinite Loop) vulnerability in ash-project ash_ai allows an attacker who can influence a model's output to hang the tool loop and drive unbounded, repeated model requests. AshAi.ToolLoop classifies a
CVE-2026-82564 | Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_ai allows a caller of an identity-configured tool to update or destroy records it never identified, including every row in the table. In AshAi.Tool.Execution, identity_filter/3 built the update/destroy filter directly from the raw tool arguments as [{key, Map.get(arguments, to_string(key))}] and passed it to Ash.Query.do_filter/2. A map value is parsed as a predicate expression
Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_ai allows a caller of an identity-configured tool to update or destroy records it never identified, including every row in the table. In AshAi.Tool.Execution
CVE-2026-82600 | A security flaw has been discovered in SeaCMS up to 13.6. Affected by this issue is some unknown functionality of the file /zyapi.php?ac=videolist. Performing a manipulation of the argument ids results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
A security flaw has been discovered in SeaCMS up to 13.6. Affected by this issue is some unknown functionality of the file /zyapi.php?ac=videolist. Performing a manipulation of the argument ids results in sql injection. The attack can be in
CVE-2026-81315 | Origin Validation Error vulnerability in ash-project ash_ai allows a malicious web page to bypass the MCP server's DNS-rebinding protection and issue cross-site requests to a user's local MCP server with that user's actor. In AshAi.Mcp.Server, with the default allowed_origins: nil, origin_allowed?/3 accepts an origin when uri.host == conn.host and the forwarded scheme is https. Both values are attacker-controlled: conn.host comes from the Host header and the
Origin Validation Error vulnerability in ash-project ash_ai allows a malicious web page to bypass the MCP server's DNS-rebinding protection and issue cross-site requests to a user's local MCP server with that user's actor. In AshAi.Mcp.Ser
CVE-2026-77956 | Improper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code. AshAi.Actions.Prompt evaluates prompt content through EEx.eval_string/2. The documented prompt: fn input, context -> ... end form lets the prompt content be built from action arguments, so when a prompt action's text incorporates request data, that attacker-controlled text is compiled and run as
Improper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code. AshAi.Actions.Prompt evaluates prompt content through EEx.eval_string/2.
CVE-2026-82599 | A vulnerability was identified in SeaCMS up to 13.6. Affected by this vulnerability is the function unlink of the file /member.php?action=chgpwdsubmit of the component Avatar Upload. Such manipulation of the argument oldpic leads to path traversal. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
A vulnerability was identified in SeaCMS up to 13.6. Affected by this vulnerability is the function unlink of the file /member.php?action=chgpwdsubmit of the component Avatar Upload. Such manipulation of the argument oldpic leads to path tr
CVE-2026-82598 | A vulnerability was determined in SeaCMS up to 13.6. Affected is the function parseIf of the file search.php of the component Template Engine. This manipulation of the argument searchtype causes code injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
A vulnerability was determined in SeaCMS up to 13.6. Affected is the function parseIf of the file search.php of the component Template Engine. This manipulation of the argument searchtype causes code injection. It is possible to initiate th
CVE-2026-82597 | A vulnerability was identified in TOTOLINK NR1800X 9.1.0u.6681_B20230703. This affects the function setUssd of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ussd leads to command injection. The attack can be initiated remotely. The exploit is publicly available and might be used.
A vulnerability was identified in TOTOLINK NR1800X 9.1.0u.6681_B20230703. This affects the function setUssd of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ussd leads to command injection. The attack can be initiated remo