CVE-2026-85381: Schwachstellen-Eintrag (NVD)
A security vulnerability has been detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This issue affects some unknown processing of the file App/Home/Controller/ChapterController.class.php of the component Chapter Controller. Such manipulation of the argument content leads to authorization bypass. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The project was informed of the problem early through an issue report but has not responded yet.
Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-06 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
Mathspace-Datenleck trifft 1,07 Mio. Nutzer: Metabase-Schwachstelle als Ursache
LONDON (IT BOLTWISE) – Mathspace meldet ein Sicherheitsereignis, das insgesamt 1.079.819 Nutzer in Australien und Neuseeland betrifft. Ursache soll eine Schwachstelle in einer selbst gehosteten Metabase-Installation gewesen sein, über die A
[NEU] [mittel] PackageKit: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
Ein lokaler Angreifer kann eine Schwachstelle in PackageKit ausnutzen, um Sicherheitsvorkehrungen zu umgehen. Weiterlesen
[NEU] [mittel] CoreDNS: Schwachstelle ermöglicht Manipulation von DNS Einträgen
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in CoreDNS ausnutzen, um DNS Einträge zu manipulieren. Weiterlesen
[NEU] [mittel] Bruno: Schwachstelle ermöglicht Offenlegung von Informationen
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Bruno ausnutzen, um Informationen offenzulegen. Weiterlesen
N-able Released Hotfix for RCE Vulnerability Affecting Platform
N-able has released N-central 2026.3 Hotfix 4 to fix CVE-2026-86218. This critical vulnerability could allow an unauthenticated attacker to execute code remotely on an exposed N-central server. The update, identified as build 2026.3.1.14, w
CVE-2026-14297 | Nordic Semiconductor ASA nRF Connect SDK up to 3.3.0 buffer overflow (EUVD-2026-72299)
A vulnerability was found in Nordic Semiconductor ASA nRF Connect SDK up to 3.3.0. It has been rated as problematic. Impacted is an unknown function. Performing a manipulation results in buffer overflow. This vulnerability is known as CVE-2
CVE-2026-86284 | jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132 CommonController.java getOption tableName/columnName information disclosure (EUVD-2026-72298)
A vulnerability identified as problematic has been detected in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. Affected by this vulnerability is the function getOption of the file travel/src/main/jav
CVE-2026-84732 | OpenVPN up to 2.6.22/2.7.6 integer overflow (EUVD-2026-72302)
A vulnerability was found in OpenVPN up to 2.6.22/2.7.6. It has been declared as critical. This issue affects some unknown processing. Such manipulation leads to integer overflow. This vulnerability is traded as CVE-2026-84732. The attack m
CVE-2026-18796 | Nordic Semiconductor ASA nRF5340 risky encryption (EUVD-2026-72300)
A vulnerability was found in Nordic Semiconductor ASA nRF5340. It has been classified as problematic. This vulnerability affects unknown code. This manipulation causes risky cryptographic algorithm. This vulnerability appears as CVE-2026-18
CVE-2026-86288 | ModelCloud GPTQModel up to 7.2.0 Triton dequantization kernel tritonv2.py g_idx out-of-bounds (Issue 2949 / EUVD-2026-72303)
A vulnerability described as critical has been identified in ModelCloud GPTQModel up to 7.2.0. This vulnerability affects unknown code of the file gptqmodel/nn_modules/qlinear/tritonv2.py of the component Triton dequantization kernel. Such
CVE-2026-86285 | BookStack up to 26.05.2 Attachment Edit Endpoint AttachmentController.php getUpdateForm ID access control (EUVD-2026-72301)
A vulnerability labeled as problematic has been found in BookStack up to 26.05.2. Affected by this issue is the function AttachmentController::getUpdateForm of the file app/Uploads/Controllers/AttachmentController.php of the component Attac
CVE-2026-84186 | PrestaShop Tools::getRemoteAddr access control (EUVD-2026-72305)
A vulnerability categorized as problematic has been discovered in PrestaShop. The affected element is the function Tools::getRemoteAddr. Executing a manipulation can lead to improper access controls. This vulnerability is handled as CVE-202
CVE-2026-86332 | odh-dashboard privileges management (EUVD-2026-72304)
A vulnerability was found in odh-dashboard and classified as problematic. This affects an unknown part. The manipulation results in improper privilege management. This vulnerability is reported as CVE-2026-86332. The attack can be launched
CVE-2026-86289 | Ollama up to 0.31.1 GGUF Decoder fs/ggml/gguf.go readGGUFV1String integer overflow (Issue 17033 / EUVD-2026-72306)
A vulnerability classified as problematic has been found in Ollama up to 0.31.1. This issue affects the function readGGUFV1String of the file fs/ggml/gguf.go of the component GGUF Decoder. Performing a manipulation results in integer overfl
CVE-2026-84173 | Eclipse Ankaios up to 1.0.1 Control Interface improper authorization (EUVD-2026-72323)
A vulnerability marked as critical has been reported in Eclipse Ankaios up to 1.0.1. This impacts an unknown function of the component Control Interface. This manipulation causes improper authorization. The identification of this vulnerabil
CVE-2026-86342 | CIRCL MISP up to 2.5.45 Freetext Feed Preview access control (dedb4b297 / EUVD-2026-72319)
A vulnerability identified as problematic has been detected in CIRCL MISP up to 2.5.45. The impacted element is an unknown function of the component Freetext Feed Preview. The manipulation leads to improper access controls. This vulnerabili
CVE-2026-86290 | SourceCodester Online Voting System 1.0 ajax.php?action=save_category Category sql injection (EUVD-2026-72318)
A vulnerability has been found in SourceCodester Online Voting System 1.0 and classified as critical. This affects an unknown function of the file /voting/ajax.php?action=save_category. This manipulation of the argument Category causes sql
CVE-2026-86293 | SourceCodester Simple Traffic Offense System 1.0 Deletion Endpoint delete-user.php ID missing authentication (EUVD-2026-72324)
A vulnerability was found in SourceCodester Simple Traffic Offense System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file delete-user.php of the component Deletion Endpoint. Exec
CVE-2026-77698 | Zohocorp ManageEngine Endpoint Central 11.4.2508.13/11.4.2528.34 Agent privileges management (EUVD-2026-72325)
A vulnerability described as critical has been identified in Zohocorp ManageEngine Endpoint Central 11.4.2508.13/11.4.2528.34. Affected is an unknown function of the component Agent. Such manipulation leads to improper privilege management.
N-able Released Hotfix for RCE Vulnerability Affecting Platform
N-able has released N-central 2026.3 Hotfix 4 to fix CVE-2026-86218. This critical vulnerability could allow an unauthenticated attacker to execute code remotely on an exposed N-central server. The update, identified as build 2026.3.1.14, w
N-able Released Hotfix for RCE Vulnerability Affecting Platform
N-able has released N-central 2026.3 Hotfix 4 to fix CVE-2026-86218. This critical vulnerability could allow an unauthenticated attacker to execute code remotely on an exposed N-central server. The update, identified as build 2026.3.1.14, w
Critical N-able N-central Flaw Enables Pre-Auth Remote Code Execution
N-able has released a security update to address CVE-2026-86218, a critical-severity vulnerability in its N-central remote monitoring and management platform. This vulnerability could enable pre-authenticated remote code execution on an aff
Critical N-able N-central Flaw Enables Pre-Auth Remote Code Execution
N-able has released a security update to address CVE-2026-86218, a critical-severity vulnerability in its N-central remote monitoring and management platform. This vulnerability could enable pre-authenticated remote code execution on an aff
Hackers Exploit PaperCut NG/MF Flaws to Steal Credentials and Deploy Meterpreter
Threat actors are actively exploiting two critical vulnerabilities in PaperCut NG/MF, identified as CVE-2026-81578 and CVE-2026-82078. These exploits allow attackers to take control of print management servers, steal credentials, and deploy
Hackers Exploit PaperCut NG/MF Flaws to Steal Credentials and Deploy Meterpreter
Threat actors are actively exploiting two critical vulnerabilities in PaperCut NG/MF, identified as CVE-2026-81578 and CVE-2026-82078. These exploits allow attackers to take control of print management servers, steal credentials, and deploy
Critical N-able N-central Flaw Enables Unauthenticated Pre-Auth Remote Code Execution
N-able has issued an urgent security update for a critical vulnerability in its N-central remote monitoring and management (RMM) platform that could let an unauthenticated attacker execute code on a vulnerable server before logging in. Trac
[UPDATE] [mittel] Grafana: Schwachstelle ermöglicht Denial of Service
Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Grafana Plugins für SQL Datenquellen ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen
[UPDATE] [mittel] Grafana: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen und Manipulation von Dateien
Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Grafana ausnutzen, um Sicherheitsvorkehrungen zu umgehen, und um Dateien zu manipulieren. Weiterlesen
Magento and Adobe Commerce StyleSmuggler 0-Day RCE Actively Exploited in Attacks
Security researchers have discovered an actively exploited, unauthenticated remote code execution vulnerability affecting installations of Magento Open Source and Adobe Commerce. This vulnerability, known as StyleSmuggler, allows attackers
Magento and Adobe Commerce StyleSmuggler 0-Day RCE Actively Exploited in Attacks
Security researchers have discovered an actively exploited, unauthenticated remote code execution vulnerability affecting installations of Magento Open Source and Adobe Commerce. This vulnerability, known as StyleSmuggler, allows attackers
CVE-2026-20212: Nexus-9000-Switches per S1HAL per root über TCP 43210/43211 angreifbar
LONDON (IT BOLTWISE) – Eine als kritisch eingestufte Schwachstelle (CVE-2026-20212, CVSS 9,8) betrifft Cisco Nexus 9000 Switches mit Silicon-One-ASICs. Unauthentifizierte Angreifer können per TCP 43210 und 43211 im Default-Layer-3-VRF belie
0patch liefert drei Jahre Support für Microsoft Office 2021 - BornCity
Windows 7/Server 2008 R2: 0Patch-Support bis Januar 2027 · Windows 10 ... 0patch Fix für Windows Server Telephony Schwachstelle CVE-2026-20931 Weiterlesen
Docker CVE-2026-34040: AuthZ-Bypass erlaubt Root-Container nach Größen-Check
LONDON (IT BOLTWISE) – Eine lang zurückliegende Schwachstelle im Docker Engine AuthZ-Middleware-Pfad ermöglicht nach aktueller Analyse einen Authentifizierungs-Umgehungsweg. Ein übergroßer API-Request wird vor dem Policy-Plugin abgeschnitte
PaperCut Flaws Exploited in Attacks on U.S. and European Schools
Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-20
PaperCut Flaws Exploited in Attacks on U.S. and European Schools
Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-20
Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions. The post Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites appeared first o
Google’s Chrome Update Patches Sixth Zero-Day Exploited in 2026
Chrome users have another actively exploited zero-day to worry about, and this one sits inside the engine that powers much of the modern web. Google has patched CVE-2026-85046, a high-severity type confusion vulnerability in Chrome’s V8 Jav
CVE-2026-19949 Leaves Millions of WordPress Sites Running Vulnerable Plugin Versions
A WordPress backup tool designed to help sites recover from trouble can instead become the trigger for an attack. Researchers disclosed a high-severity SQL injection vulnerability in the All-in-One WP Migration and Backup plugin that affect
HPE Patches Critical RCE Vulnerabilities in AOS-CX
Nearly two dozen issues, tracked collectively as CVE-2026-73749 (CVSS score of 9.8), were addressed with the updates. The post HPE Patches Critical RCE Vulnerabilities in AOS-CX appeared first on SecurityWeek. Weiterlesen
Nightmare Eclipse drops a CrowdStrike zero-day.
Extortion group leaks alleged Manchester Airports Group data. France's CNIL fines hospital over 2025 data breach. Weiterlesen
Sangoma Switchvox Vulnerabilities Exploited in the Wild
Tracked as CVE-2026-9586, the unauthenticated SQL injection flaw can be exploited remotely for arbitrary code execution. The post Sangoma Switchvox Vulnerabilities Exploited in the Wild appeared first on SecurityWeek. Weiterlesen
[NEU] [niedrig] Checkmk: Schwachstelle ermöglicht Denial of Service
Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Checkmk Agent Receiver ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen
[NEU] [UNGEPATCHT] [mittel] xpdf: Schwachstelle ermöglicht Denial of Service
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in xpdf ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen
[NEU] [mittel] Dell integrated Dell Remote Access Controller: Schwachstelle ermöglicht Codeausführung
Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Dell integrated Dell Remote Access Controller ausnutzen, um beliebigen Programmcode auszuführen. Weiterlesen
[NEU] [mittel] Ollama: Schwachstelle ermöglicht Offenlegung von Informationen
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Ollama ausnutzen, um Informationen offenzulegen. Weiterlesen
[NEU] [hoch] util-linux: Schwachstelle ermöglicht Privilegieneskalation
Ein lokaler Angreifer kann eine Schwachstelle in util-linux ausnutzen, um seine Privilegien zu erhöhen. Weiterlesen
[NEU] [UNGEPATCHT] [mittel] bluez: Schwachstelle ermöglicht Codeausführung
Ein Angreifer in Bluetooth-Reichweite kann eine Schwachstelle in bluez ausnutzen, um beliebigen Programmcode auszuführen. Weiterlesen
[NEU] [hoch] GeoNetwork: Schwachstelle ermöglicht Manipulation von Dateien
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in GeoNetwork ausnutzen, um Dateien zu manipulieren. Weiterlesen
12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover
Dubbed PostGREShell, CVE-2026-6471 turns low-level replication access into code execution, permanent superuser privileges and a persistent database backdoor. The post 12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover ap
[UPDATE] [hoch] Dell BSAFE: Schwachstelle ermöglicht Denial of Service
Ein Angreifer kann eine Schwachstelle in Dell BSAFE ausnutzen, um einen Denial of Service zu verursachen Weiterlesen
Google Patches 6th Chrome Zero-Day of 2026
Google’s Chrome 152 security update resolves 12 vulnerabilities, including a high-severity type confusion flaw in the V8 engine. The post Google Patches 6th Chrome Zero-Day of 2026 appeared first on SecurityWeek. Weiterlesen
Google fixes actively exploited Chrome V8 zero-day vulnerability
Google has released a Chrome security update addressing 12 vulnerabilities, including a high-severity V8 flaw that is being actively exploited in attacks. The fixes are included in Chrome 152.0.7977.82/.83 for Windows and macOS and version
CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers’ crosshairs. The vulnerabilities are as follows – C
HP Easy Start for macOS: CVE-2026-12554 / CVE-2026-12555 / CVE-2026-12556
Posted by Nir Yehoshua on Sep 03Hello Full Disclosure list, Cipher Security Labs has published technical details for three High-severity vulnerabilities affecting HP Easy Start for macOS. The issues were coordinated with HP and are addresse
Attackers exploit zero-days in consistently besieged SonicWall product
SonicWall customers are grappling with yet another pair of actively exploited zero-day vulnerabilities in SonicWall SMA 1000 appliances, a product that’s been besieged with recurring defects and attacks over the past nine months. The vendo
Serious vulnerability threatens tens of thousands of Exchange servers
A serious vulnerability was recently discovered in Exchange Server 2016, Exchange Server 2016, and Exchange Server Subscription Edition (SE). The vulnerability is designated CVE-2026-62911 and can be exploited by hackers to gain full access
Tycon Systems TPDIN-Monitor-WEB3
View CSAF Summary Successful exploitation of these vulnerabilities could allow for an attacker to perform a man-in-the-middle (MitM) attack, cause a factory reset, wipe credentials, or retrieve sensitive information. The following versions
Rockwell Automation 1756-ENBT Module
View CSAF Summary Successful exploitation of this vulnerability could crash the module. The device requires a restart to recover. The following versions of Rockwell Automation 1756-ENBT Module are affected: 1756-ENBT module vers:all/* (CVE-
OPCFoundation OPC UA LocalDiscoveryServer (LDS)
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to take control of a high-privilege terminal during installation and run arbitrary commands. The following versions of OPCFoundation OPC UA LocalDiscove
IXON VPN Client
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to perform remote code execution on the computer running the client with elevated privileges. The following versions of IXON VPN Client are affected: VP