🛡️ tsecurity.de
Zur Startseite 🔖 Lesezeichen
🎯 FOKUSSIERTE SCHWACHSTELLE: CVE-2026-65641 CRITICAL 9.3 🔥 EPSS 69.6%
Alle CVEs anzeigen ✕

Veeam ONE mit kritischer Schwachstelle CVE-2026-65641 (CVSS 9.3)

[English]Kurze Information für Nutzer und Administratoren, die auf Veeam ONE setzen. Es gibt eine kritische Schwachstelle CVE-2026-65641 (CVSS 9.3) in Veeam ONE, die eventuell Anmeldedaten verrät. Veeam ONE sollte daher unverzüglich auf die

Angriffsvektor: 🌐 Netzwerk (Remote) • 🔓 Keine Authentifizierung nötig
CWE-Klassifizierung: CWE-94: Code Injection
🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

🟢 SSE Realtime Synchronisiert ⚡ REST API (JSON) 📡 RSS Feed
Ökosystem & Hersteller Bedrohungs-Matrix:
Linux 21
Microsoft 5
Generic Security 1
Apple 1
Schweregrad & Status:
Hersteller-Filter:
🔍
CRITICAL 9.3 🔥 EPSS 69.6%
Generic Security
CVE-2026-65641 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

Veeam ONE mit kritischer Schwachstelle CVE-2026-65641 (CVSS 9.3)

[English]Kurze Information für Nutzer und Administratoren, die auf Veeam ONE setzen. Es gibt eine kritische Schwachstelle CVE-2026-65641 (CVSS 9.3) in Veeam ONE, die eventuell Anmeldedaten verrät. Veeam ONE sollte daher unverzüglich auf die

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
HIGH 7.5 🔥 EPSS 31%
Microsoft
CVE-2026-55040 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

Sicherheitslücken in Microsoft SharePoint werden von Hackern angegriffen

Das Sicherheitsunternehmen Defused warnt davor, dass Hacker begonnen haben, zwei kritische Sicherheitslücken in Microsoft SharePoint mit den Bezeichnungen CVE-2026-55040 und CVE-2026-63520 auszunutzen. Laut Bleeping Computer sind weltweit m

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
HIGH 7.5 🔥 EPSS 28.7%
Microsoft
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

Exchange-Sicherheitslücke: Wegen Proof-of-Concept Angriffe wahrscheinlich

Für eine hochriskante Lücke in Exchange, die die Systemübernahme erlaubt, ist Exploit-Code erschienen. Admins müssen updaten. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
HIGH 7.5 🔥 EPSS 28.1%
Apple
CVE-2025-31207 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

AppEnumGuard v1.2

CVE-2025-31207 mitigation and sandboxed tester for rootless and rootHide jailbreaks on iOS 15–18.4.1 Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
HIGH 7.5 🔥 EPSS 20.1%
Linux
CVE-2026-53224 💻 Lokal 🔓 Keine Authentifizierung nötig

USN-8658-3: Linux kernel vulnerabilities

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Open vSwitch; - SCTP protocol; (CVE-2026-53224, CVE-2026-5

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 20.1%
Linux
CVE-2026-53224 💻 Lokal 🔓 Keine Authentifizierung nötig

USN-8658-3: Linux kernel vulnerabilities

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Open vSwitch; - SCTP protocol; (CVE-2026-53224, CVE-2026-5

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 24.6%
Microsoft
CVE-2020-24588 💻 Lokal 🔓 Keine Authentifizierung nötig

USN-8666-2: Linux kernel (Azure) vulnerabilities

Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A physically proximate atta

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
HIGH 7.5 🔥 EPSS 24.6%
Microsoft
CVE-2020-24588 💻 Lokal 🔓 Keine Authentifizierung nötig

USN-8666-2: Linux kernel (Azure) vulnerabilities

Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A physically proximate atta

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
HIGH 7.5 🔥 EPSS 26.9%
Linux
CVE-2026-46968 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8681-1: OpenJDK 25 vulnerabilities

It was discovered that the JSSE component of OpenJDK 25 did not correctly authenticate users. A remote attacker could possibly use this issue to read or modify sensitive data. (CVE-2026-46968) It was discovered that the JSSE component of Op

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 26.9%
Linux
CVE-2026-46968 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8681-1: OpenJDK 25 vulnerabilities

It was discovered that the JSSE component of OpenJDK 25 did not correctly authenticate users. A remote attacker could possibly use this issue to read or modify sensitive data. (CVE-2026-46968) It was discovered that the JSSE component of Op

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
MEDIUM 5.8 🔥 EPSS 6.8%
Linux
CVE-2026-3039 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8682-1: Bind vulnerabilities

Vitaly Simonovich discovered that Bind could exhaust memory during GSS-API TKEY negotiation. A remote attacker could possibly use this issue to cause Bind to use excessive resources, leading to a denial of service. (CVE-2026-3039) Shuhan Zh

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
MEDIUM 5.8 🔥 EPSS 6.8%
Linux
CVE-2026-3039 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8682-1: Bind vulnerabilities

Vitaly Simonovich discovered that Bind could exhaust memory during GSS-API TKEY negotiation. A remote attacker could possibly use this issue to cause Bind to use excessive resources, leading to a denial of service. (CVE-2026-3039) Shuhan Zh

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
MEDIUM 5.8 🔥 EPSS 2.5%
Linux
CVE-2026-62289 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8683-1: libheif vulnerabilities

Feng Ning discovered that libheif incorrectly handled certain image transforms. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
MEDIUM 5.8 🔥 EPSS 2.5%
Linux
CVE-2026-62289 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8683-1: libheif vulnerabilities

Feng Ning discovered that libheif incorrectly handled certain image transforms. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 29.6%
Linux
CVE-2026-12087 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8684-1: Perl vulnerabilities

It was discovered that Perl incorrectly handled certain arguments to Socket and pack/unpack functions. An attacker could possibly use this issue to read sensitive information from memory. (CVE-2026-12087, CVE-2026-57432) It was discovered t

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 29.6%
Linux
CVE-2026-12087 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8684-1: Perl vulnerabilities

It was discovered that Perl incorrectly handled certain arguments to Socket and pack/unpack functions. An attacker could possibly use this issue to read sensitive information from memory. (CVE-2026-12087, CVE-2026-57432) It was discovered t

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 26.9%
Linux
CVE-2026-40253 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8686-1: openCryptoki vulnerabilities

It was discovered that primitive decoders in openCryptoki produced integer underflows when the encoded length was zero. An attacker could possibly use this issue to trigger out-of-bounds reads. (CVE-2026-40253) It was discovered that openCr

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 26.9%
Linux
CVE-2026-40253 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8686-1: openCryptoki vulnerabilities

It was discovered that primitive decoders in openCryptoki produced integer underflows when the encoded length was zero. An attacker could possibly use this issue to trigger out-of-bounds reads. (CVE-2026-40253) It was discovered that openCr

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 20.1%
Linux
CVE-2026-53224 💻 Lokal 🔓 Keine Authentifizierung nötig

USN-8658-3: Linux kernel vulnerabilities

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Open vSwitch; - SCTP protocol; (CVE-2026-53224, CVE-2026-5

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 24.6%
Microsoft
CVE-2020-24588 💻 Lokal 🔓 Keine Authentifizierung nötig

USN-8666-2: Linux kernel (Azure) vulnerabilities

Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A physically proximate atta

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
HIGH 7.5 🔥 EPSS 26.9%
Linux
CVE-2026-46968 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8681-1: OpenJDK 25 vulnerabilities

It was discovered that the JSSE component of OpenJDK 25 did not correctly authenticate users. A remote attacker could possibly use this issue to read or modify sensitive data. (CVE-2026-46968) It was discovered that the JSSE component of Op

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
MEDIUM 5.8 🔥 EPSS 6.8%
Linux
CVE-2026-3039 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8682-1: Bind vulnerabilities

Vitaly Simonovich discovered that Bind could exhaust memory during GSS-API TKEY negotiation. A remote attacker could possibly use this issue to cause Bind to use excessive resources, leading to a denial of service. (CVE-2026-3039) Shuhan Zh

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
MEDIUM 5.8 🔥 EPSS 2.5%
Linux
CVE-2026-62289 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8683-1: libheif vulnerabilities

Feng Ning discovered that libheif incorrectly handled certain image transforms. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 29.6%
Linux
CVE-2026-12087 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8684-1: Perl vulnerabilities

It was discovered that Perl incorrectly handled certain arguments to Socket and pack/unpack functions. An attacker could possibly use this issue to read sensitive information from memory. (CVE-2026-12087, CVE-2026-57432) It was discovered t

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 26.9%
Linux
CVE-2026-40253 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

USN-8686-1: openCryptoki vulnerabilities

It was discovered that primitive decoders in openCryptoki produced integer underflows when the encoded length was zero. An attacker could possibly use this issue to trigger out-of-bounds reads. (CVE-2026-40253) It was discovered that openCr

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 28.9%
Linux
CVE-2026-43804 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

DSA-6463-1 webkit2gtk - security update

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2026-43804 Heiko Kiesel discovered that visiting a website may lead to an app denial-of-service. CVE-2026-64713 Kwak Kiyong and Song Nuri discovered that we

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
HIGH 7.5 🔥 EPSS 28.9%
Linux
CVE-2026-43804 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

DSA-6463-1 webkit2gtk - security update

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2026-43804 Heiko Kiesel discovered that visiting a website may lead to an app denial-of-service. CVE-2026-64713 Kwak Kiyong and Song Nuri discovered that we

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
CRITICAL 9.8 🔥 EPSS 94.2%
⚠️ CISA KEV Linux
CVE-2026-73570 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

CVE-2026-73570: Zimbra SNMP/logwatch RCE exploited in the wild, malware persists via /dev/shm and zimbra cron

CVE-2026-73570: Zimbra SNMP RCE abused to deploy coin-miner malware CVE-2026-73570 is a Remote Code Execution issue in Zimbra Collaboration Suite (ZCS), related to SNMP notification/logwatch handling. In short, an unauthenticated attacker c

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.