🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

354k+ 🇪🇺 EUVD-Datenbank
15 🔴 Critical im Radar
11 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
0 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-09: 237 2025-10: 316 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 418 2026-03: 652 2026-04: 574 2026-05: 683 2026-06: 942 2026-07: 1333 2026-08: 1329 7.598 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-08-292026-09-06
≥90 %40
≥50 %40
≥10 %30
<10 %304300
📈 EPSS-Riser (7 Tage) CVE-2023-29073 ↑ 0.1 %
Frühindikator · FIRST.org
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Generic Security 25
Linux 21
Adobe 4
Microsoft 3
Google 3
WordPress 2
Schweregrad & Status:
Hersteller (Datenbank-weit, 90.597 Einträge):
Quelle:
🔍
7.5 HIGH
EPSS 30.2%
CVE-2026-74647 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-74647 | Linux Kernel up to 6.6.151/6.12.103/6.18.44/7.1.8 Fastrpc fastrpc_req_munmap_impl race condition (Nessus ID 343049)

A vulnerability, which was classified as very critical, has been found in Linux Kernel up to 6.6.151/6.12.103/6.18.44/7.1.8. The impacted element is the function fastrpc_req_munmap_impl of the component Fastrpc. This manipulation causes rac

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 30.5%
CVE-2026-74648 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-74648 | Linux Kernel up to 7.1.8 rtl8723bs rtw_cfg80211_monitor_if_xmit_entry out-of-bounds (Nessus ID 343049)

A vulnerability was found in Linux Kernel up to 7.1.8. It has been rated as very critical. This affects the function rtw_cfg80211_monitor_if_xmit_entry of the component rtl8723bs. This manipulation causes out-of-bounds read. The identificat

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 25.8%
CVE-2026-74646 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-74646 | Linux Kernel up to 6.6.151/6.12.103/6.18.44/7.1.8 fastrpc fastrpc_internal_invoke race condition (Nessus ID 343049)

A vulnerability was found in Linux Kernel up to 6.6.151/6.12.103/6.18.44/7.1.8. It has been classified as very critical. Affected by this vulnerability is the function fastrpc_internal_invoke of the component fastrpc. The manipulation leads

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 22.5%
CVE-2026-74642 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-74642 | Linux Kernel up to 6.6.151/6.12.103/6.18.44/7.1.8 ALSA ump_to_endpoint use after free (Nessus ID 343049 / WID-SEC-2026-2970)

A vulnerability classified as very critical was found in Linux Kernel up to 6.6.151/6.12.103/6.18.44/7.1.8. The affected element is the function ump_to_endpoint of the component ALSA. The manipulation results in use after free. This vulnera

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 26.7%
CVE-2026-74636 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-74636 | Linux Kernel up to 7.1.8 tracing trace_event_update_all locking (Nessus ID 343049 / WID-SEC-2026-2970)

A vulnerability described as very critical has been identified in Linux Kernel up to 7.1.8. This issue affects the function trace_event_update_all of the component tracing. Executing a manipulation can lead to improper locking. This vulnera

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 29.1%
CVE-2026-74634 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-74634 | Linux Kernel up to 6.12.103/6.18.44/7.1.8 ring-buffer ring_buffer_subbuf_order_set use after free (Nessus ID 343049 / WID-SEC-2026-2970)

A vulnerability marked as very critical has been reported in Linux Kernel up to 6.12.103/6.18.44/7.1.8. This vulnerability affects the function ring_buffer_subbuf_order_set of the component ring-buffer. Performing a manipulation results in

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 18.7%
CVE-2026-74635 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-74635 | Linux Kernel up to 7.1.8 fbdev bitblit.c bit_cursor out-of-bounds (Nessus ID 343049 / WID-SEC-2026-2970)

A vulnerability, which was classified as problematic, has been found in Linux Kernel up to 7.1.8. This issue affects the function bit_cursor of the file drivers/video/fbdev/core/bitblit.c of the component fbdev. The manipulation leads to ou

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 26.8%
CVE-2026-74631 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-74631 | Linux Kernel up to 7.1.8 smc smc_rx_splice use after free (Nessus ID 343049 / WID-SEC-2026-2970)

A vulnerability identified as very critical has been detected in Linux Kernel up to 6.1.182/6.6.151/6.12.103/6.18.44/7.1.8. Affected by this issue is the function smc_rx_splice of the component smc. This manipulation causes use after free.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
9.0 CRITICAL
EPSS 62.5%
CVE-2026-20212 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Cisco

CVE-2026-20212: Nexus-9000-Switches per S1HAL per root über TCP 43210/43211 angreifbar

LONDON (IT BOLTWISE) – Eine als kritisch eingestufte Schwachstelle (CVE-2026-20212, CVSS 9,8) betrifft Cisco Nexus 9000 Switches mit Silicon-One-ASICs. Unauthentifizierte Angreifer können per TCP 43210 und 43211 im Default-Layer-3-VRF belie

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Management-Interface vom Internet trennen und ACLs auf vertrauenswürdige IPs beschränken.
7.5 HIGH
EPSS 28.6%
CVE-2026-74625 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-74625 | Linux Kernel up to 7.1.8 Bridge nf_ct_bridge_pre _nfct memory leak (Nessus ID 343049 / WID-SEC-2026-2970)

A vulnerability was found in Linux Kernel up to 7.1.8. It has been classified as critical. This affects the function nf_ct_bridge_pre of the component Bridge. Performing a manipulation of the argument _nfct results in memory leak. This vuln

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 28.8%
CVE-2026-74630 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-74630 | Linux Kernel up to 7.1.8 ipv6 in6_dev_get ip6_ptr use after free (Nessus ID 343049 / WID-SEC-2026-2970)

A vulnerability labeled as very critical has been found in Linux Kernel up to 7.1.8. Affected is the function in6_dev_get of the component ipv6. The manipulation of the argument ip6_ptr results in use after free. This vulnerability is catal

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 24.4%
CVE-2026-74624 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-74624 | Linux Kernel up to 6.6.151/6.12.103/6.18.44/7.1.8 Netfilter Conntrack nf_ct_l4proto_log_invalid deadlock (Nessus ID 343049 / WID-SEC-2026-2970)

A vulnerability classified as critical has been found in Linux Kernel up to 6.6.151/6.12.103/6.18.44/7.1.8. This affects the function nf_ct_l4proto_log_invalid of the component Netfilter Conntrack. Performing a manipulation results in deadl

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 25.7%
CVE-2026-74623 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-74623 | Linux Kernel up to 7.1.8 atlantic aq_vec_deinit memory leak (Nessus ID 343049 / WID-SEC-2026-2970)

A vulnerability categorized as problematic has been discovered in Linux Kernel up to 6.1.182/6.6.151/6.12.103/6.18.44/7.1.8. This affects the function aq_vec_deinit of the component atlantic. Executing a manipulation can lead to memory leak

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 20.5%
CVE-2026-74621 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-74621 | Linux Kernel up to 6.6.151/6.12.103/6.18.44/7.1.8 act_ct net/sched/act_ct.c tcf_ct_handle_fragments memory leak (Nessus ID 343049 / WID-SEC-2026-2970)

A vulnerability classified as critical has been found in Linux Kernel up to 6.6.151/6.12.103/6.18.44/7.1.8. Affected is the function tcf_ct_handle_fragments of the file net/sched/act_ct.c of the component act_ct. This manipulation causes me

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 25.9%
CVE-2026-74620 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-74620 | Linux Kernel up to 7.1.8 act_gact/act_police net/sched tcf_action_check_ctrlact TCA_GACT_PROB.paction/TCA_POLICE_RESULT input validation (Nessus ID 343049 / WID-SEC-2026-2970)

A vulnerability was found in Linux Kernel up to 7.1.8 and classified as problematic. Affected by this issue is the function tcf_action_check_ctrlact of the file net/sched of the component act_gact/act_police. Executing a manipulation of the

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 30.6%
CVE-2026-74619 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-74619 | Linux Kernel up to 6.6.151/6.12.103/6.18.44/7.1.8 overlayfs fs/overlayfs/super.c ovl_fill_super user_ns improper authorization (Nessus ID 343049 / WID-SEC-2026-2970)

A vulnerability was found in Linux Kernel up to 6.6.151/6.12.103/6.18.44/7.1.8. It has been declared as very critical. The affected element is the function ovl_fill_super of the file fs/overlayfs/super.c of the component overlayfs. Such man

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 32%
CVE-2026-74618 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-74618 | Linux Kernel up to 6.12.103/6.18.44/7.1.8 binfmt_misc fs/binfmt_misc.c bm_fill_super user_ns improper authorization (Nessus ID 343049 / WID-SEC-2026-2970)

A vulnerability described as critical has been identified in Linux Kernel up to 6.12.103/6.18.44/7.1.8. This impacts the function bm_fill_super of the file fs/binfmt_misc.c of the component binfmt_misc. The manipulation of the argument user

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 24.4%
CVE-2026-80728 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-80728 | Linux Kernel up to 6.6.151/6.12.103/6.18.44/7.1.8 amdgpu drm/amdgpu vcn_v4_0_sw_fini memory corruption (Nessus ID 343049)

A vulnerability identified as critical has been detected in Linux Kernel up to 6.6.151/6.12.103/6.18.44/7.1.8. This affects the function vcn_v4_0_sw_fini of the file drm/amdgpu of the component amdgpu. This manipulation causes memory corrup

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 21.7%
CVE-2026-74616 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-74616 | Linux Kernel up to 7.1.8 XDP xdpf_clone buffer overflow (Nessus ID 343049 / WID-SEC-2026-2970)

A vulnerability marked as very critical has been reported in Linux Kernel up to 7.1.8. This affects the function xdpf_clone of the component XDP. The manipulation leads to buffer overflow. This vulnerability is documented as CVE-2026-74616.

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 24.5%
CVE-2026-74615 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-74615 | Linux Kernel up to 7.1.8 VXLAN vxlan_changelink use after free (Nessus ID 343049 / WID-SEC-2026-2970)

A vulnerability has been found in Linux Kernel up to 7.1.8 and classified as very critical. Affected by this vulnerability is the function vxlan_changelink of the component VXLAN. Performing a manipulation results in use after free. This vu

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

IDScan sued over 153 million licence breach, FalconFlank zero-day hijacks CrowdStrike, Magento stores backdoored with no patch

Identity verification firm IDScan faces multiple lawsuits and investigations after hackers allegedly breached it. The criminals offered over 153 million U.S. and Canadian driver&#039;s license scans for sale. Nightmare Eclipse releases Falc

CWE-269: Privilege Management ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.5%
CVE-2024-11114 💻 Lokal 🔓 Keine Authentifizierung nötig
Microsoft

DEF CON SG1 - CSIT Village - Ernest Ang - From Chrome Renderer, To Mouse To System

YouTube VideoYou click on a link. A download prompt appears. Your mouse suddenly seems to take on a life of its own and clicks the pop-up. Before you know it, your Windows machine belongs to me. This session breaks down an amusing and far-

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 18.5%
CVE-2025-52691 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

DEF CON SG1 - CSIT Village - Chua Meng Han - From CTF To CVE 202552691 Lessons Hidden In Plain Sight

YouTube VideoCritical vulnerabilities like CVE-2025-52691 remind us that “low-hanging fruit” still exists today. This session deconstructs how simple, overlooked design flaws can be weaponised for catastrophic impact. We will also share pra

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 85.9%
CVE-2025-52692 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

DEF CON SG1 - CSIT Village - Jun Rong And Javier Koh - Cve 2025 52692 Rogue Request Roots Router

YouTube VideoThis talk breaks down the discovery of CVE-2025-52692, a zero-day vulnerability in the widely used Linksys E9450 SG router. We will show how a simple string comparison flaw allowed a complete authentication bypass, eventually

CWE-287: Improper Authentication ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32%
CVE-2026-20931 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

0patch liefert drei Jahre Support für Microsoft Office 2021 - BornCity

Windows 7/Server 2008 R2: 0Patch-Support bis Januar 2027 · Windows 10 ... 0patch Fix für Windows Server Telephony Schwachstelle CVE-2026-20931 Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
9.5 CRITICAL
EPSS 76.5%
CVE-2026-42167 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

ProFTPD mod_sql post-authentication SQLi RCE

Topic: ProFTPD mod_sql post-authentication SQLi RCE Risk: Medium Text:#!/usr/bin/env python3 &quot;&quot;&quot; CVE-2026-42167 — ProFTPD mod_sql post-authentication SQL injection -&amp;gt; RCE postauth_stor_r... Weiterlesen

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Adobe

A New Magento Zero-Day Is Breaking Into Online Stores Right Now

  Online stores running Magento Open Source and Adobe Commerce are being broken into through a security flaw that has no patch, no CVE number and, as of Saturday, no acknowledgment from Adobe. The company that found it says it went public b

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.9%
CVE-2026-34040 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Docker CVE-2026-34040: AuthZ-Bypass erlaubt Root-Container nach Größen-Check

LONDON (IT BOLTWISE) – Eine lang zurückliegende Schwachstelle im Docker Engine AuthZ-Middleware-Pfad ermöglicht nach aktueller Analyse einen Authentifizierungs-Umgehungsweg. Ein übergroßer API-Request wird vor dem Policy-Plugin abgeschnitte

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.3%
CVE-2026-75754 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

ASUS Control Center Flaw Allows Attackers to Gain Full Admin Control of the System

ASUS has issued an urgent security update for ASUS Control Center Enterprise (ACC) after researchers uncovered a maximum-severity vulnerability that lets remote attackers seize complete administrative control over the platform and every dev

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.3%
CVE-2026-75754 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

ASUS Control Center Flaw Allows Attackers to Gain Full Admin Control of the System

ASUS has issued an urgent security update for ASUS Control Center Enterprise (ACC) after researchers uncovered a maximum-severity vulnerability that lets remote attackers seize complete administrative control over the platform and every dev

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.3%
CVE-2026-75754 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

ASUS Control Center Flaw Allows Attackers to Gain Full Admin Control of the System

ASUS has issued an urgent security update for ASUS Control Center Enterprise (ACC) after researchers uncovered a maximum-severity vulnerability that lets remote attackers seize complete administrative control over the platform and every dev

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Adobe

Hackers Actively Exploiting Magento and Adobe Commerce 0-Day RCE Vulnerability

A newly discovered zero-day vulnerability in Magento Open Source and Adobe Commerce is being actively exploited by attackers to seize full control of online stores, and there is still no official patch available. Dutch e-commerce security f

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Adobe

Hackers Actively Exploiting Magento and Adobe Commerce 0-Day RCE Vulnerability

A newly discovered zero-day vulnerability in Magento Open Source and Adobe Commerce is being actively exploited by attackers to seize full control of online stores, and there is still no official patch available. Dutch e-commerce security f

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Adobe

Magento-Backdoor „StyleSmuggler“: Ungepatchte Zero-Day trifft Adobe Commerce

LONDON (IT BOLTWISE) – Eine ungesicherte Zero-Day-Lücke in Magento Open Source und Adobe Commerce wird offenbar aktiv ausgenutzt. Die Sicherheitsfirma Sansec nennt die Schwachstelle „StyleSmuggler“ und beschreibt eine Kette, die ohne Login

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.4%
CVE-2026-81578 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

PaperCut Flaws Exploited in Attacks on U.S. and European Schools

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-20

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.0 CRITICAL
EPSS 64.4%
CVE-2026-59346 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
VMware

Broadcom schließt kritische Lücke in VMware Workstation und Fusion (CVE-2026-59346)

LONDON (IT BOLTWISE) – Broadcom hat Sicherheitsupdates für VMware Workstation und VMware Fusion veröffentlicht und schließt dabei zwei Lücken, darunter einen kritischen Integer-Overflow mit CVSS 9,3. Unter bestimmten Bedingungen kann ein An

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.5%
CVE-2026-32475 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites

Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions. The post Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites appeared first o

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
7.5 HIGH
EPSS 18.4%
CVE-2026-6471 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers

A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged replication accounts to execute attacker-controlled code, escalate to database superuser, and establish persistent backdoors on affected servers. Tracked as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.4%
CVE-2026-6471 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers

A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged replication accounts to execute attacker-controlled code, escalate to database superuser, and establish persistent backdoors on affected servers. Tracked as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.4%
CVE-2026-6471 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

12-Year-Old PostgreSQL Flaw Lets Backup Accounts Execute Code and Take Over Databases

A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged backup and replication accounts to execute arbitrary code, escalate to database superuser privileges, and establish persistent access on vulnerable servers.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.8%
CVE-2026-85046 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

U.S. CISA adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Google Chromium V8 flaw, trac

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 82.8%
CVE-2026-85046 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

Google’s Chrome Update Patches Sixth Zero-Day Exploited in 2026

Chrome users have another actively exploited zero-day to worry about, and this one sits inside the engine that powers much of the modern web. Google has patched CVE-2026-85046, a high-severity type confusion vulnerability in Chrome’s V8 Jav

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 32.7%
CVE-2026-19949 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-19949 Leaves Millions of WordPress Sites Running Vulnerable Plugin Versions

A WordPress backup tool designed to help sites recover from trouble can instead become the trigger for an attack. Researchers disclosed a high-severity SQL injection vulnerability in the All-in-One WP Migration and Backup plugin that affect

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
9.5 CRITICAL
EPSS 64.3%
CVE-2026-73749 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

HPE Patches Critical RCE Vulnerabilities in AOS-CX

Nearly two dozen issues, tracked collectively as CVE-2026-73749 (CVSS score of 9.8), were addressed with the updates. The post HPE Patches Critical RCE Vulnerabilities in AOS-CX appeared first on SecurityWeek. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Nightmare Eclipse drops a CrowdStrike zero-day.

Extortion group leaks alleged Manchester Airports Group data. France&#039;s CNIL fines hospital over 2025 data breach. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.4%
CVE-2026-6471 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

PostgreSQL Hit by 12-Year-Old Vulnerability Allowing Server Takeover

PostGREShell (CVE-2026-6471) is a 12-year-old PostgreSQL flaw that lets low-privileged attackers execute code and take over servers. Cyera researchers found a severe PostgreSQL vulnerability, dubbed PostGREShell and tracked as CVE-2026-6471

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 89.1%
CVE-2026-9586 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Sangoma Switchvox Vulnerabilities Exploited in the Wild

Tracked as CVE-2026-9586, the unauthenticated SQL injection flaw can be exploited remotely for arbitrary code execution. The post Sangoma Switchvox Vulnerabilities Exploited in the Wild appeared first on SecurityWeek. Weiterlesen

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 2.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

[NEU] [niedrig] Checkmk: Schwachstelle ermöglicht Denial of Service

Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Checkmk Agent Receiver ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 2.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

[NEU] [UNGEPATCHT] [mittel] xpdf: Schwachstelle ermöglicht Denial of Service

Ein entfernter, anonymer Angreifer kann eine Schwachstelle in xpdf ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

[NEU] [mittel] Dell integrated Dell Remote Access Controller: Schwachstelle ermöglicht Codeausführung

Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Dell integrated Dell Remote Access Controller ausnutzen, um beliebigen Programmcode auszuführen. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

[NEU] [mittel] Ollama: Schwachstelle ermöglicht Offenlegung von Informationen

Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Ollama ausnutzen, um Informationen offenzulegen. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Linux

[NEU] [hoch] util-linux: Schwachstelle ermöglicht Privilegieneskalation

Ein lokaler Angreifer kann eine Schwachstelle in util-linux ausnutzen, um seine Privilegien zu erhöhen. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 28.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

[NEU] [hoch] GeoNetwork: Schwachstelle ermöglicht Manipulation von Dateien

Ein entfernter, anonymer Angreifer kann eine Schwachstelle in GeoNetwork ausnutzen, um Dateien zu manipulieren. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

[NEU] [UNGEPATCHT] [mittel] bluez: Schwachstelle ermöglicht Codeausführung

Ein Angreifer in Bluetooth-Reichweite kann eine Schwachstelle in bluez ausnutzen, um beliebigen Programmcode auszuführen. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.4%
CVE-2026-6471 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover

Dubbed PostGREShell, CVE-2026-6471 turns low-level replication access into code execution, permanent superuser privileges and a persistent database backdoor. The post 12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover ap

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 2.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

[UPDATE] [hoch] Dell BSAFE: Schwachstelle ermöglicht Denial of Service

Ein Angreifer kann eine Schwachstelle in Dell BSAFE ausnutzen, um einen Denial of Service zu verursachen Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

Google Patches 6th Chrome Zero-Day of 2026

Google’s Chrome 152 security update resolves 12 vulnerabilities, including a high-severity type confusion flaw in the V8 engine. The post Google Patches 6th Chrome Zero-Day of 2026 appeared first on SecurityWeek. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 2.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Linux

[UPDATE] [mittel] Red Hat Enterprise Linux (iperf3): Schwachstelle ermöglicht Denial of Service

Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

Google fixes actively exploited Chrome V8 zero-day vulnerability

Google has released a Chrome security update addressing 12 vulnerabilities, including a high-severity V8 flaw that is being actively exploited in attacks. The fixes are included in Chrome 152.0.7977.82/.83 for Windows and macOS and version

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 31.8%
CVE-2026-83548 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers’ crosshairs. The vulnerabilities are as follows – C

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.