CVE-2026-85044: Schwachstellen-Eintrag (NVD)
Use of released resource in Mobile in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-05 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions. This article has been indexed from SecurityWeek Read the original article: Elementor Pro WordP
CVE-2026-72658 | Elastic Kibana up to 8.19.19/9.4.4 Vega cross-site request forgery (EUVD-2026-58269)
A vulnerability described as problematic has been identified in Elastic Kibana up to 8.19.19/9.4.4. This issue affects some unknown processing of the component Vega Handler. Executing a manipulation can lead to cross-site request forgery. T
CVE-2026-68758 | JFrog Artifactory up to 7.146.34/7.161.15 privileges management
A vulnerability has been found in JFrog Artifactory up to 7.146.34/7.161.15 and classified as problematic. The impacted element is an unknown function. This manipulation causes improper privilege management. This vulnerability is tracked as
CVE-2026-72660 | Elastic Kibana up to 8.19.19/9.3.7/9.4.4 uncaught exception
A vulnerability marked as problematic has been reported in Elastic Kibana up to 8.19.19/9.3.7/9.4.4. This vulnerability affects unknown code. Performing a manipulation results in uncaught exception. This vulnerability is cataloged as CVE-20
CVE-2026-68759 | JFrog Artifactory up to 7.146.34/7.161.15 improper authentication
A vulnerability was found in JFrog Artifactory up to 7.146.34/7.161.15 and classified as critical. This affects an unknown function. Such manipulation leads to improper authentication. This vulnerability is listed as CVE-2026-68759. The att
CVE-2026-49089 | Elastic Kibana up to 8.19.19/9.4.4 Connector Reporting allocation of resources
A vulnerability was found in Elastic Kibana up to 8.19.19/9.4.4. It has been rated as problematic. This issue affects some unknown processing of the component Connector Reporting. This manipulation causes allocation of resources. This vulne
CVE-2026-72663 | Elastic Kibana up to 8.19.19/9.4.4 TSVB Visualization algorithmic complexity
A vulnerability labeled as problematic has been found in Elastic Kibana up to 8.19.19/9.4.4. This affects an unknown part of the component TSVB Visualization. Such manipulation leads to inefficient algorithmic complexity. This vulnerability
CVE-2026-72650 | Elastic Kibana up to 8.19.19/9.4.4 Alerting authorization
A vulnerability was found in Elastic Kibana up to 8.19.19/9.4.4. It has been rated as problematic. Affected is an unknown function of the component Alerting. The manipulation leads to authorization bypass. This vulnerability is referenced a
CVE-2026-72661 | Elastic Kibana up to 8.19.18/9.3.7/9.4.3 Elastic Defend endpoint response actions authorization
A vulnerability, which was classified as problematic, was found in Elastic Kibana up to 8.19.18/9.3.7/9.4.3. Impacted is an unknown function of the component Elastic Defend endpoint response actions. The manipulation results in missing auth
CVE-2026-72653 | Elastic Kibana allocation of resources
A vulnerability classified as problematic was found in Elastic Kibana. This vulnerability affects unknown code. Executing a manipulation can lead to allocation of resources. This vulnerability appears as CVE-2026-72653. The attack may be pe
CVE-2026-72659 | Elastic Kibana up to 8.19.19/9.4.4 Visualization allocation of resources
A vulnerability, which was classified as problematic, has been found in Elastic Kibana up to 8.19.19/9.4.4. This issue affects some unknown processing of the component Visualization. The manipulation leads to allocation of resources. This v
CVE-2026-72631 | Elastic Kibana up to 9.4.4/9.5.0 Fleet privileges management (EUVD-2026-58220)
A vulnerability was found in Elastic Kibana up to 9.4.4/9.5.0. It has been rated as problematic. The impacted element is an unknown function of the component Fleet. Performing a manipulation results in improper privilege management. This vu
CVE-2026-72651 | Elastic Kibana up to 8.19.19/9.4.4 Alerting Feature allocation of resources
A vulnerability classified as problematic has been found in Elastic Kibana up to 8.19.19/9.4.4. This affects an unknown part of the component Alerting Feature. Performing a manipulation results in allocation of resources. This vulnerability
CVE-2026-49096 | Elastic Kibana up to 8.19.19/9.3.4/9.4.0/9.4.1 Cases uncaught exception
A vulnerability was found in Elastic Kibana up to 8.19.19/9.3.4/9.4.0/9.4.1 and classified as problematic. This issue affects some unknown processing of the component Cases. The manipulation results in uncaught exception. This vulnerability
CVE-2026-72630 | Elastic Kibana Fleet authorization (EUVD-2026-58290)
A vulnerability was found in Elastic Kibana. It has been declared as problematic. The affected element is an unknown function of the component Fleet. Such manipulation leads to incorrect authorization. This vulnerability is referenced as CV
CVE-2026-72629 | Elastic Kibana up to 8.19.19/9.4.4/9.5.0 authorization
A vulnerability categorized as critical has been discovered in Elastic Kibana up to 8.19.19/9.4.4/9.5.0. Impacted is an unknown function. Such manipulation leads to authorization bypass. This vulnerability is listed as CVE-2026-72629. The a
CVE-2026-72657 | Elastic Fleet Server up to 8.19.19/9.4.4/9.5.0 authorization
A vulnerability identified as problematic has been detected in Elastic Fleet Server up to 8.19.19/9.4.4/9.5.0. Affected by this issue is some unknown functionality. This manipulation causes authorization bypass. This vulnerability is tracke
CVE-2026-72656 | Elastic Elasticsearch up to 8.17.9 ES|QL Query Processing memory allocation (WID-SEC-2026-2841)
A vulnerability categorized as problematic has been discovered in Elastic Elasticsearch up to 8.17.9. Affected by this vulnerability is an unknown functionality of the component ES|QL Query Processing. The manipulation results in uncontroll
CVE-2026-72681 | Elastic Kibana up to 9.4.3 Agent Builder privileges management (EUVD-2026-58255)
A vulnerability was found in Elastic Kibana up to 9.4.3. It has been declared as critical. Affected is an unknown function of the component Agent Builder. The manipulation results in improper privilege management. This vulnerability is know
CVE-2026-72680 | Elastic Kibana up to 9.4.4 Agent Builder API Endpoint privileges management
A vulnerability was found in Elastic Kibana up to 9.4.4. It has been classified as problematic. This impacts an unknown function of the component Agent Builder API Endpoint. The manipulation leads to improper privilege management. This vuln
CVE-2026-72671 | Elastic Kibana Machine Learning privileges management
A vulnerability was found in Elastic Kibana and classified as problematic. This affects an unknown part of the component Machine Learning. The manipulation results in improper privilege management. This vulnerability is known as CVE-2026-72
CVE-2026-72670 | Elastic Kibana up to 8.19.19/9.4.4 Fleet proxy privileges management
A vulnerability has been found in Elastic Kibana up to 8.19.19/9.4.4 and classified as problematic. Affected by this issue is some unknown functionality of the component Fleet proxy. The manipulation leads to improper privilege management.
CVE-2026-72669 | Elastic Kibana up to 8.19.18/9.4.4 Observability Onboarding Flow privileges management
A vulnerability, which was classified as critical, was found in Elastic Kibana up to 8.19.18/9.4.4. Affected by this vulnerability is an unknown functionality of the component Observability Onboarding Flow. Executing a manipulation can lead
Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions. The post Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites appeared first o
PaperCut-Schwachstellen: Angreifer stehlen Anmeldedaten an Schulen und Universitäten
LONDON (IT BOLTWISE) – Angreifer nutzen neu gemeldete PaperCut-Schwachstellen, um an Schulen und Universitäten in den USA und Europa Zugangsdaten auszuspähen. In den Beobachtungen wurden CVE-2026-81578 und CVE-2026-82078 für Authentifizieru
12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers
A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged replication accounts to execute attacker-controlled code, escalate to database superuser, and establish persistent backdoors on affected servers. Tracked as
Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities
Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting C
12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers
A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged replication accounts to execute attacker-controlled code, escalate to database superuser, and establish persistent backdoors on affected servers. Tracked as
12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers
A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged replication accounts to execute attacker-controlled code, escalate to database superuser, and establish persistent backdoors on affected servers. Tracked as
12-Year-Old PostgreSQL Flaw Lets Backup Accounts Execute Code and Take Over Databases
A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged backup and replication accounts to execute arbitrary code, escalate to database superuser privileges, and establish persistent access on vulnerable servers.
U.S. CISA adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Google Chromium V8 flaw, trac
Google’s Chrome Update Patches Sixth Zero-Day Exploited in 2026
Chrome users have another actively exploited zero-day to worry about, and this one sits inside the engine that powers much of the modern web. Google has patched CVE-2026-85046, a high-severity type confusion vulnerability in Chrome’s V8 Jav
CVE-2026-19949 Leaves Millions of WordPress Sites Running Vulnerable Plugin Versions
A WordPress backup tool designed to help sites recover from trouble can instead become the trigger for an attack. Researchers disclosed a high-severity SQL injection vulnerability in the All-in-One WP Migration and Backup plugin that affect
PostgreSQL stoppt Codeausführung via Logical Decoding: neuer Whitelist-Parameter
LONDON (IT BOLTWISE) – PostgreSQL schließt eine seit 2014 bekannte Schwachstelle (CVE-2026-6471), die mit dem REPLICATION-Attribut beliebigen Code im Backend-Prozess ausführen konnte. Die Absicherung erfolgt über einen neuen Parameter outpu
PostgreSQL fixiert CVE-2026-6471: REPLICATION-Benutzer können Code als DB-User ausführen
LONDON (IT BOLTWISE) – PostgreSQL hat ein Sicherheitsproblem mit der logischen Replikation geschlossen, das einem Konto mit REPLICATION-Attribut die Ausführung beliebigen Codes als OS-User des Datenbankservers ermöglicht. Betroffen sind Ver
HPE Patches Critical RCE Vulnerabilities in AOS-CX
Nearly two dozen issues, tracked collectively as CVE-2026-73749 (CVSS score of 9.8), were addressed with the updates. The post HPE Patches Critical RCE Vulnerabilities in AOS-CX appeared first on SecurityWeek. Weiterlesen
Nightmare Eclipse drops a CrowdStrike zero-day.
Extortion group leaks alleged Manchester Airports Group data. France's CNIL fines hospital over 2025 data breach. Weiterlesen
PostgreSQL Hit by 12-Year-Old Vulnerability Allowing Server Takeover
PostGREShell (CVE-2026-6471) is a 12-year-old PostgreSQL flaw that lets low-privileged attackers execute code and take over servers. Cyera researchers found a severe PostgreSQL vulnerability, dubbed PostGREShell and tracked as CVE-2026-6471
PostgreSQL Hit by 12-Year-Old Vulnerability Allowing Server Takeover
PostGREShell (CVE-2026-6471) is a 12-year-old PostgreSQL flaw that lets low-privileged attackers execute code and take over servers. Cyera researchers found a severe PostgreSQL vulnerability, dubbed PostGREShell and tracked as CVE-2026-6471
Sangoma Switchvox Vulnerabilities Exploited in the Wild
Tracked as CVE-2026-9586, the unauthenticated SQL injection flaw can be exploited remotely for arbitrary code execution. The post Sangoma Switchvox Vulnerabilities Exploited in the Wild appeared first on SecurityWeek. Weiterlesen
[NEU] [niedrig] Checkmk: Schwachstelle ermöglicht Denial of Service
Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Checkmk Agent Receiver ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen
Multiple TP-Link Archer Vulnerabilities Allow Attackers to Execute Remote Code
TP-Link has disclosed two security vulnerabilities in its Archer AX55 v4 router that could let attackers on the local network crash a service, steal administrator credentials, and potentially execute remote code on affected devices. The fla
Multiple TP-Link Archer Vulnerabilities Allow Attackers to Execute Remote Code
TP-Link has disclosed two security vulnerabilities in its Archer AX55 v4 router that could let attackers on the local network crash a service, steal administrator credentials, and potentially execute remote code on affected devices. The fla
[NEU] [UNGEPATCHT] [mittel] xpdf: Schwachstelle ermöglicht Denial of Service
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in xpdf ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen
[NEU] [mittel] Dell integrated Dell Remote Access Controller: Schwachstelle ermöglicht Codeausführung
Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Dell integrated Dell Remote Access Controller ausnutzen, um beliebigen Programmcode auszuführen. Weiterlesen
[NEU] [mittel] Ollama: Schwachstelle ermöglicht Offenlegung von Informationen
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Ollama ausnutzen, um Informationen offenzulegen. Weiterlesen
[NEU] [hoch] util-linux: Schwachstelle ermöglicht Privilegieneskalation
Ein lokaler Angreifer kann eine Schwachstelle in util-linux ausnutzen, um seine Privilegien zu erhöhen. Weiterlesen
[NEU] [hoch] GeoNetwork: Schwachstelle ermöglicht Manipulation von Dateien
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in GeoNetwork ausnutzen, um Dateien zu manipulieren. Weiterlesen
[NEU] [UNGEPATCHT] [mittel] bluez: Schwachstelle ermöglicht Codeausführung
Ein Angreifer in Bluetooth-Reichweite kann eine Schwachstelle in bluez ausnutzen, um beliebigen Programmcode auszuführen. Weiterlesen
12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover
Dubbed PostGREShell, CVE-2026-6471 turns low-level replication access into code execution, permanent superuser privileges and a persistent database backdoor. The post 12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover ap
[UPDATE] [hoch] Dell BSAFE: Schwachstelle ermöglicht Denial of Service
Ein Angreifer kann eine Schwachstelle in Dell BSAFE ausnutzen, um einen Denial of Service zu verursachen Weiterlesen
Google Patches 6th Chrome Zero-Day of 2026
Google’s Chrome 152 security update resolves 12 vulnerabilities, including a high-severity type confusion flaw in the V8 engine. The post Google Patches 6th Chrome Zero-Day of 2026 appeared first on SecurityWeek. Weiterlesen
WordPress: Super Forms und Elementor Pro von RCE-Angriffen betroffen
LONDON (IT BOLTWISE) – Angreifer nutzen zwei kritische Lücken in WordPress-Plugins, um ohne Anmeldung Dateien mit PHP-Inhalt hochzuladen und anschließend Remote Code Execution auszuführen. Laut Wordfence wurden bereits über 250.000 bzw. 190
[UPDATE] [mittel] Red Hat Enterprise Linux (iperf3): Schwachstelle ermöglicht Denial of Service
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen
Google fixes actively exploited Chrome V8 zero-day vulnerability
Google has released a Chrome security update addressing 12 vulnerabilities, including a high-severity V8 flaw that is being actively exploited in attacks. The fixes are included in Chrome 152.0.7977.82/.83 for Windows and macOS and version
Google fixes the sixth actively exploited Chrome zero-day of 2026
Google patched 12 Chrome flaws, including an actively exploited V8 zero-day that could enable remote code execution through a crafted webpage. Google released a Chrome security update fixing 12 vulnerabilities, including CVE-2026-85046 (CVS
Google fixes the sixth actively exploited Chrome zero-day of 2026
Google patched 12 Chrome flaws, including an actively exploited V8 zero-day that could enable remote code execution through a crafted webpage. Google released a Chrome security update fixing 12 vulnerabilities, including CVE-2026-85046 (CVS
Chrome-Update schließt V8-Zero-Day: CVE-2026-85046 aktiv ausgenutzt
LONDON (IT BOLTWISE) – Google hat ein Chrome-Update veröffentlicht, das zwölf Sicherheitslücken schließt. Im Fokus steht CVE-2026-85046, eine V8-Type-Confusion-Fehlerspur (CVSS: 8,8), die nach Angaben der Beschreibung bereits aktiv in freie
CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers’ crosshairs. The vulnerabilities are as follows – C
HP Easy Start for macOS: CVE-2026-12554 / CVE-2026-12555 / CVE-2026-12556
Posted by Nir Yehoshua on Sep 03Hello Full Disclosure list, Cipher Security Labs has published technical details for three High-severity vulnerabilities affecting HP Easy Start for macOS. The issues were coordinated with HP and are addresse