🎯 CVE-2026-82919 HIGH 7.3 🔥 EPSS 20%
📄 .md Alle CVEs anzeigen ✕

CVE-2026-82919: Schwachstellen-Eintrag (NVD)

A vulnerability was identified in cu silicon up to 0.1.5. Affected by this vulnerability is the function create_app of the file views.py of the component edit Endpoint. Such manipulation leads to missing authentication. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

Improper Control of Generation of Code ('Code Injection') 🎯 Medium

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

🛡️ Empfohlene Mitigation: Refactor your program so that you do not have to dynamically generate code.
Vollständige Definition bei MITRE ➔
📚 Referenzen & Quellen:
Ausnutzungs-Zeitleiste:
CVSS-Vektor-Analyse: 7.3
AV · Angriffsvektor Netzwerk
AC · Komplexität Gering
PR · Privilegien Keine
UI · Interaktion Keine
S · Scope Unverändert
C · Vertraulichkeit Gering
I · Integrität Gering
A · Verfügbarkeit Gering
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Veröffentlicht:31.08.2026
Aktualisiert:01.09.2026 20:48
Assigner (CNA):NVD
Quellen: 🇪🇺 EUVD-Datenbank (ENISA) + 🇺🇸 NVD-Anreicherung · 24-h-Cache
CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

354k+ 🇪🇺 EUVD-Datenbank
7 🔴 Critical im Radar
4 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
0 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-09: 240 2025-10: 316 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 418 2026-03: 652 2026-04: 574 2026-05: 683 2026-06: 942 2026-07: 1333 2026-08: 1329 7.601 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-08-292026-09-05
≥90 %40
≥50 %40
≥10 %30
<10 %304300
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Generic Security 37
Linux 8
VMware 7
WordPress 4
Adobe 2
Google 2
Schweregrad & Status:
Hersteller (Datenbank-weit, 90.597 Einträge):
Quelle:
🔍
7.5 HIGH
EPSS 27.6%
CVE-2026-23131 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-23131 | Linux Kernel up to 6.6.121/6.12.67/6.18.7 lib/kobject.c hp_init_bios_buffer_attribute buffer overflow (Nessus ID 299321 / WID-SEC-2026-0421)

A vulnerability described as critical has been identified in Linux Kernel up to 6.6.121/6.12.67/6.18.7. Affected by this issue is the function hp_init_bios_buffer_attribute in the library lib/kobject.c. The manipulation results in buffer ov

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
8.2 HIGH
EPSS 23%
CVE-2026-23132 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-23132 | Linux Kernel up to 6.18.7 dw_dp_bind privilege escalation (Nessus ID 299318 / WID-SEC-2026-0421)

A vulnerability, which was classified as problematic, was found in Linux Kernel up to 6.18.7. This issue affects the function dw_dp_bind. Such manipulation leads to privilege escalation. This vulnerability is listed as CVE-2026-23132. The a

CWE-269: Privilege Management ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 30.2%
CVE-2026-23130 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-23130 | Linux Kernel up to 6.18.7 wifi ath12k_mac_op_flush race condition (Nessus ID 299231 / WID-SEC-2026-0421)

A vulnerability was found in Linux Kernel up to 6.18.7. It has been rated as critical. This affects the function ath12k_mac_op_flush of the component wifi. Performing a manipulation results in race condition. This vulnerability is identifie

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 20.7%
CVE-2026-23129 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-23129 | Linux Kernel up to 6.12.67/6.18.7 dpll _add reference count (Nessus ID 299219 / WID-SEC-2026-0421)

A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.12.67/6.18.7. Affected by this vulnerability is the function _add of the component dpll. Executing a manipulation can lead to improper update of reference c

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 22.8%
CVE-2026-23127 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-23127 | Linux Kernel up to 6.18.7 lib/refcount.c perf_mmap_rb use after free (Nessus ID 299181 / WID-SEC-2026-0421)

A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.18.7. This vulnerability affects the function perf_mmap_rb in the library lib/refcount.c. Executing a manipulation can lead to use after free. This vulnera

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 23.3%
CVE-2026-23128 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-23128 | Linux Kernel up to 6.18.7 swsusp_arch_resume buffer overflow (Nessus ID 299069 / WID-SEC-2026-0421)

A vulnerability identified as critical has been detected in Linux Kernel up to 5.15.198/6.1.161/6.6.121/6.12.67/6.18.7. Affected by this issue is the function swsusp_arch_resume. The manipulation leads to buffer overflow. This vulnerability

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 31.6%
CVE-2026-23126 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-23126 | Linux Kernel up to 6.1.161/6.6.121/6.12.67/6.18.7 Netdevsim Driver nsim_bpf_create_prog protection mechanism (Nessus ID 299071 / WID-SEC-2026-0421)

A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.1.161/6.6.121/6.12.67/6.18.7. This affects the function nsim_bpf_create_prog of the component Netdevsim Driver. Such manipulation leads to protection mecha

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 24.1%
CVE-2026-67276 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-67276 | Mikrotik RouterOS up to 6.49.20/7.23.3/7.24.1 signature verification (EUVD-2026-72024)

A vulnerability classified as very critical was found in Mikrotik RouterOS up to 6.49.20/7.23.3/7.24.1. This impacts an unknown function. Executing a manipulation can lead to improper verification of cryptographic signature. The identificat

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24%
CVE-2026-86206 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-86206 | N-able N-central prior 2026.3 HF3/2026.4 access control (EUVD-2026-72023)

A vulnerability marked as very critical has been reported in N-able N-central. The affected element is an unknown function. This manipulation causes improper access controls. This vulnerability is handled as CVE-2026-86206. The attack can b

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.7%
CVE-2026-67277 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-67277 | Mikrotik RouterOS up to 6.49.20/7.23.3/7.24.1 integer underflow (EUVD-2026-72025)

A vulnerability described as very critical has been identified in Mikrotik RouterOS up to 6.49.20/7.23.3/7.24.1. The impacted element is an unknown function. Such manipulation leads to integer underflow. This vulnerability is uniquely ident

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18%
CVE-2026-67279 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-67279 | Mikrotik RouterOS up to 6.49.20/7.23.3/7.24.1 SSH Connection Protocol improper authentication (EUVD-2026-72027)

A vulnerability, which was classified as very critical, was found in Mikrotik RouterOS up to 6.49.20/7.23.3/7.24.1. Affected by this vulnerability is an unknown functionality of the component SSH Connection Protocol. The manipulation result

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27%
CVE-2026-67278 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-67278 | MikroTik RouterOS up to 6.49.20/7.23.3/7.24.1 certificate validation (EUVD-2026-72026)

A vulnerability, which was classified as problematic, has been found in MikroTik RouterOS up to 6.49.20/7.23.3/7.24.1. Affected is an unknown function. The manipulation leads to improper certificate validation. This vulnerability is referen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.3%
CVE-2026-86060 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-86060 | Mikrotik RouterOS up to 6.49.20/7.23.3/7.24.1 SSH Login privileges management (EUVD-2026-72029)

A vulnerability has been found in Mikrotik RouterOS up to 6.49.20/7.23.3/7.24.1 and classified as very critical. Affected by this issue is some unknown functionality of the component SSH Login. This manipulation causes improper privilege ma

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 5.3%
CVE-2026-67281 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-67281 | Mikrotik RouterOS up to 6.49.20/7.23.3/7.24.1 WebFig information disclosure (EUVD-2026-72028)

A vulnerability classified as problematic has been found in Mikrotik RouterOS up to 6.49.20/7.23.3/7.24.1. This affects an unknown function of the component WebFig. Performing a manipulation results in information disclosure. This vulnerabi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.2%
CVE-2026-86148 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-86148 | Tenda CP3 27.5.57.101 Kylin Apis/system.c SystemAsh AlarmVoiceURL os command injection (EUVD-2026-72030)

A vulnerability was found in Tenda CP3 27.5.57.101 and classified as very critical. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results i

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.9%
CVE-2026-86150 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-86150 | Tenda CP3 27.5.57.101 custom-x/softap/hostapd wpa_passphrase hard-coded credentials (EUVD-2026-72032)

A vulnerability was found in Tenda CP3 27.5.57.101. It has been declared as problematic. Impacted is an unknown function of the file custom-x/softap/hostapd. Such manipulation of the argument wpa_passphrase leads to hard-coded credentials.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21%
CVE-2026-86149 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-86149 | Tenda CP3 27.5.57.101 Net/NetCheckPing.cpp interface_name/host os command injection (EUVD-2026-72031)

A vulnerability was found in Tenda CP3 27.5.57.101. It has been classified as very critical. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os comman

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.3%
CVE-2026-86151 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-86151 | Tenda CP3 27.5.57.101 Network Configuration Management Apis/system.c sub_2F77E8 os command injection (EUVD-2026-72036)

A vulnerability was found in Tenda CP3 27.5.57.101. It has been rated as very critical. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Management. Performing a manipulation r

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.2%
CVE-2026-59304 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
VMware

CVE-2026-59304 | VMware Spring Cloud Stream up to 4.2.6/4.3.3/5.0.2 type confusion (EUVD-2026-67190)

A vulnerability was found in VMware Spring Cloud Stream up to 4.2.6/4.3.3/5.0.2. It has been classified as problematic. This affects an unknown part. Performing a manipulation results in type confusion. This vulnerability is reported as CVE

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30%
CVE-2026-13732 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-13732 | Red Hat Enterprise Linux STABS debug format parser gdb/stabsread.c read_member_functions out-of-bounds write

A vulnerability was found in Red Hat Enterprise Linux. It has been declared as problematic. Impacted is the function read_member_functions of the file gdb/stabsread.c of the component STABS debug format parser. Such manipulation leads to ou

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 25.2%
CVE-2026-82877 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-82877 | ILIAS up to 9.21/10.9/11.2 SOAP Import addFile path traversal

A vulnerability, which was classified as problematic, was found in ILIAS up to 9.21/10.9/11.2. The impacted element is the function addFile of the component SOAP Import. Executing a manipulation can lead to path traversal. The identificatio

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.8%
CVE-2026-59306 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
VMware

CVE-2026-59306 | VMware Spring Cloud Stream up to 4.2.6/4.3.3/5.0.2 deserialization

A vulnerability was found in VMware Spring Cloud Stream up to 4.2.6/4.3.3/5.0.2. It has been declared as problematic. This vulnerability affects unknown code. Executing a manipulation can lead to deserialization. This vulnerability appears

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.4%
CVE-2026-47844 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-47844 | Spring Reactor Netty up to 1.0.52/1.2.18/1.3.6 exposure of resource

A vulnerability categorized as critical has been discovered in Spring Reactor Netty up to 1.0.52/1.2.18/1.3.6. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to exposure of resource. This vulne

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.3%
CVE-2026-59303 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
VMware

CVE-2026-59303 | VMware Spring Cloud Stream up to 4.2.6/4.3.3/5.0.2 allocation of resources (EUVD-2026-67189)

A vulnerability was found in VMware Spring Cloud Stream up to 4.2.6/4.3.3/5.0.2 and classified as problematic. Affected by this issue is some unknown functionality. Such manipulation leads to allocation of resources. This vulnerability is d

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.6%
CVE-2026-59305 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
VMware

CVE-2026-59305 | VMware Spring Cloud Stream up to 4.2.6/4.3.3/5.0.2 Partition Interceptor incorrect behavior order

A vulnerability, which was classified as problematic, was found in VMware Spring Cloud Stream up to 4.2.6/4.3.3/5.0.2. Affected is an unknown function of the component Partition Interceptor. The manipulation results in incorrect behavior or

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.7%
CVE-2026-59301 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
VMware

CVE-2026-59301 | VMware Spring Cloud Function up to 4.2.7/4.3.4/5.0.3 log file (EUVD-2026-67187)

A vulnerability was found in VMware Spring Cloud Function up to 4.2.7/4.3.4/5.0.3. It has been classified as problematic. Affected is an unknown function. This manipulation causes sensitive information in log files. This vulnerability appea

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.2%
CVE-2026-47859 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-47859 | Spring Integration up to 7.1.0 RFC6587SyslogDeserializer allocation of resources (EUVD-2026-66825)

A vulnerability, which was classified as critical, was found in Spring Integration up to 5.5.21/6.4.12/6.5.10/7.0.5/7.1.0. This issue affects some unknown processing of the component RFC6587SyslogDeserializer. The manipulation results in al

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.9%
CVE-2026-18482 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18482 | Klarso Neo.mjs FileSystemService FileSystemService.mjs checkSyntax/runPlaywrightTest absolutePath os command injection (88c77fc4 / EUVD-2026-63326)

A vulnerability was found in Klarso Neo.mjs and classified as problematic. Affected by this vulnerability is the function checkSyntax/runPlaywrightTest of the file FileSystemService.mjs of the component FileSystemService. Executing a manipu

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.1%
CVE-2026-18296 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18296 | GStreamer MRF File Parser heap-based overflow (Nessus ID 339182)

A vulnerability described as critical has been identified in GStreamer. This affects an unknown part of the component MRF File Parser. Such manipulation leads to heap-based buffer overflow. This vulnerability is documented as CVE-2026-18296

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 5.5%
CVE-2026-76956 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-76956 | libexpat project Libexpat up to 2.8.3 denial of service (WID-SEC-2026-2944)

A vulnerability classified as problematic was found in libexpat project Libexpat up to 2.8.3. Impacted is an unknown function. Such manipulation leads to denial of service. This vulnerability is documented as CVE-2026-76956. The attack can

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.3%
CVE-2026-8619 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-8619 | TP-Link Archer MR600/TL-MR100/TL-MR150/TL-MR6400 2/3.2/8.0 HTTP service null pointer dereference

A vulnerability described as critical has been identified in TP-Link Archer MR600, TL-MR100, TL-MR150 and TL-MR6400 2/3.2/8.0. This vulnerability affects unknown code of the component HTTP service. The manipulation results in null pointer d

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.4%
CVE-2026-19507 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-19507 | RDK RDK-B WebUI rdkb-2025q4-kirkstone.04.10.26 check.jst resource consumption

A vulnerability has been found in RDK RDK-B WebUI rdkb-2025q4-kirkstone.04.10.26 and classified as problematic. This issue affects some unknown processing of the file check.jst of the component WebUI. Performing a manipulation results in re

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.9%
CVE-2026-19509 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-19509 | RDK RDK-B WebUI rdkb-2025q4-kirkstone ajaxSet_wireless_network_configuration.jst ssid_number input validation

A vulnerability has been found in RDK RDK-B WebUI rdkb-2025q4-kirkstone and classified as problematic. The affected element is an unknown function of the file ajaxSet_wireless_network_configuration.jst of the component WebUI. Performing a m

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.2%
CVE-2026-19506 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-19506 | RDK WebUI rdkb-2025q4-kirkstone.04.10.26 check.jst race condition

A vulnerability identified as critical has been detected in RDK WebUI rdkb-2025q4-kirkstone.04.10.26. This impacts an unknown function of the file check.jst. This manipulation causes race condition. This vulnerability is registered as CVE-2

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.5%
CVE-2026-19508 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-19508 | RDK B WebUI rdkb-2025q4-kirkstone Multipart Form-Data Parser jst_post.c memory corruption

A vulnerability labeled as very critical has been found in RDK B WebUI rdkb-2025q4-kirkstone. Affected is an unknown function of the file jst_post.c of the component Multipart Form-Data Parser. Such manipulation leads to memory corruption.

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.3%
CVE-2026-18289 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18289 | OriginLab OriginPro OPJ File Parser out-of-bounds write

A vulnerability labeled as critical has been found in OriginLab OriginPro. Affected by this vulnerability is an unknown functionality of the component OPJ File Parser. Such manipulation leads to out-of-bounds write. This vulnerability is do

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.8%
CVE-2026-19505 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-19505 | RDK WebUI rdkb-2025q4-kirkstone.04.10.26 jst_functions.c signature verification

A vulnerability categorized as very critical has been discovered in RDK WebUI rdkb-2025q4-kirkstone.04.10.26. This affects an unknown function of the file jst_functions.c. The manipulation results in improper verification of cryptographic s

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.5%
CVE-2026-18295 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18295 | GStreamer MRF File Parser out-of-bounds write (Nessus ID 339182)

A vulnerability classified as critical has been found in GStreamer. This vulnerability affects unknown code of the component MRF File Parser. Performing a manipulation results in out-of-bounds write. This vulnerability is reported as CVE-20

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Adobe

Magento-Backdoor „StyleSmuggler“: Ungepatchte Zero-Day trifft Adobe Commerce

LONDON (IT BOLTWISE) – Eine ungesicherte Zero-Day-Lücke in Magento Open Source und Adobe Commerce wird offenbar aktiv ausgenutzt. Die Sicherheitsfirma Sansec nennt die Schwachstelle „StyleSmuggler“ und beschreibt eine Kette, die ohne Login

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Adobe

Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store&#039;s server without logging in, Dutch e-commerce security company Sansec said in an advi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.4%
CVE-2026-81578 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

PaperCut Flaws Exploited in Attacks on U.S. and European Schools

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-20

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.4%
CVE-2026-81578 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

PaperCut Flaws Exploited in Attacks on U.S. and European Schools

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-20

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.4%
CVE-2026-81578 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

PaperCut Flaws Exploited in Attacks on U.S. and European Schools

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-20

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.0 CRITICAL
EPSS 64.4%
CVE-2026-59346 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
VMware

Broadcom schließt kritische Lücke in VMware Workstation und Fusion (CVE-2026-59346)

LONDON (IT BOLTWISE) – Broadcom hat Sicherheitsupdates für VMware Workstation und VMware Fusion veröffentlicht und schließt dabei zwei Lücken, darunter einen kritischen Integer-Overflow mit CVSS 9,3. Unter bestimmten Bedingungen kann ein An

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 82.5%
CVE-2026-32475 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

Elementor Pro WordPress Flaw Exploited to Upload Webshells and Execute Commands

  A critical vulnerability in the Elementor Pro WordPress plugin is being actively exploited to upload malicious PHP files and execute commands remotely on the affected websites. The vulnerability, tracked as CVE-2026-32475, affects the Ele

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
7.5 HIGH
EPSS 22.4%
CVE-2026-59346 💻 Lokal 🔓 Keine Authentifizierung nötig
VMware

Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.5 CRITICAL
EPSS 72.1%
CVE-2026-9586 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Switchvox Vulnerability Triggers Active Exploitation Risk

  Sangoma Switchvox CVE-2026-9586 is a serious unauthenticated SQL injection flaw that can lead to remote code execution, and Horizon3 says it has already seen real-world exploitation attempts. The issue was patched in Switchvox 8.4.0.2, ma

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.3%
CVE-2023-49105 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CISA Flags Old ownCloud Flaw After Reported Philippine Nuclear Data Theft

CISA added CVE-2023-49105 to its exploited-flaws catalog after researchers tied the old ownCloud bug to reported Philippine nuclear data theft. This article has been indexed from Security Archives – TechRepublic Read the original article: C

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.5%
CVE-2026-32475 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites

Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions. This article has been indexed from SecurityWeek Read the original article: Elementor Pro WordP

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
7.5 HIGH
EPSS 18.5%
CVE-2026-32475 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites

Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions. The post Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites appeared first o

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
7.5 HIGH
EPSS 30.4%
CVE-2026-81578 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

PaperCut-Schwachstellen: Angreifer stehlen Anmeldedaten an Schulen und Universitäten

LONDON (IT BOLTWISE) – Angreifer nutzen neu gemeldete PaperCut-Schwachstellen, um an Schulen und Universitäten in den USA und Europa Zugangsdaten auszuspähen. In den Beobachtungen wurden CVE-2026-81578 und CVE-2026-82078 für Authentifizieru

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.4%
CVE-2026-6471 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers

A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged replication accounts to execute attacker-controlled code, escalate to database superuser, and establish persistent backdoors on affected servers. Tracked as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.4%
CVE-2026-6471 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers

A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged replication accounts to execute attacker-controlled code, escalate to database superuser, and establish persistent backdoors on affected servers. Tracked as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.4%
CVE-2026-6471 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

12-Year-Old PostgreSQL Flaw Lets Backup Accounts Execute Code and Take Over Databases

A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged backup and replication accounts to execute arbitrary code, escalate to database superuser privileges, and establish persistent access on vulnerable servers.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.8%
CVE-2026-85046 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

U.S. CISA adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Google Chromium V8 flaw, trac

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 82.8%
CVE-2026-85046 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

Google’s Chrome Update Patches Sixth Zero-Day Exploited in 2026

Chrome users have another actively exploited zero-day to worry about, and this one sits inside the engine that powers much of the modern web. Google has patched CVE-2026-85046, a high-severity type confusion vulnerability in Chrome’s V8 Jav

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 32.7%
CVE-2026-19949 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-19949 Leaves Millions of WordPress Sites Running Vulnerable Plugin Versions

A WordPress backup tool designed to help sites recover from trouble can instead become the trigger for an attack. Researchers disclosed a high-severity SQL injection vulnerability in the All-in-One WP Migration and Backup plugin that affect

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
7.5 HIGH
EPSS 18.4%
CVE-2026-6471 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

PostgreSQL stoppt Codeausführung via Logical Decoding: neuer Whitelist-Parameter

LONDON (IT BOLTWISE) – PostgreSQL schließt eine seit 2014 bekannte Schwachstelle (CVE-2026-6471), die mit dem REPLICATION-Attribut beliebigen Code im Backend-Prozess ausführen konnte. Die Absicherung erfolgt über einen neuen Parameter outpu

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.4%
CVE-2026-6471 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

PostgreSQL fixiert CVE-2026-6471: REPLICATION-Benutzer können Code als DB-User ausführen

LONDON (IT BOLTWISE) – PostgreSQL hat ein Sicherheitsproblem mit der logischen Replikation geschlossen, das einem Konto mit REPLICATION-Attribut die Ausführung beliebigen Codes als OS-User des Datenbankservers ermöglicht. Betroffen sind Ver

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.5 CRITICAL
EPSS 64.3%
CVE-2026-73749 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

HPE Patches Critical RCE Vulnerabilities in AOS-CX

Nearly two dozen issues, tracked collectively as CVE-2026-73749 (CVSS score of 9.8), were addressed with the updates. The post HPE Patches Critical RCE Vulnerabilities in AOS-CX appeared first on SecurityWeek. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.