CVE-2026-85638: Schwachstellen-Eintrag (NVD)
A weakness has been identified in jofpin trape 2.0. This affects an unknown part of the file core/user.py. This manipulation of the argument vId/id causes authorization bypass. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-15 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
CVE-2026-64294 | Linux Kernel up to 7.2-rc2 mm file_owner_or_capable/owner_or_capable permission (Nessus ID 345814)
A vulnerability described as very critical has been identified in Linux Kernel up to 6.6.144/6.12.95/6.18.38/7.1.3/7.2-rc2. Impacted is the function file_owner_or_capable/owner_or_capable of the component mm. Executing a manipulation can le
CVE-2026-68363 | Linux Kernel up to 7.2-rc4 ath9k hif_usb.c ath9k_hif_request_firmware use after free (Nessus ID 345819)
A vulnerability was found in Linux Kernel up to 6.6.147/6.12.100/6.18.41/7.1.5/7.2-rc4 and classified as critical. The affected element is the function ath9k_hif_request_firmware of the file drivers/net/wireless/ath/ath9k/hif_usb.c of the c
Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
Threat actors are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture plugin that lets unauthenticated attackers upload malicious PHP files and potentially seize full control of vulnerable WordPress sites.
Red Heron Hackers Exploit Critical Gitea RCE to Steal Source Code and Deploy Linux Malware
A Chinese-speaking threat actor tracked as Red Heron has exploited a remote-code-execution vulnerability in Gitea to steal source code, establish persistence, and deploy a previously undocumented Linux rootkit. The campaign weaponized CVE-2
CVE-2026-86739 | grokability Snipe-IT up to 8.6.3 Acceptance Controller store return value
A vulnerability categorized as problematic has been discovered in grokability Snipe-IT up to 8.6.3. The impacted element is the function Account\AcceptanceController::store of the component Acceptance Controller. Such manipulation leads to
CVE-2026-86751 | Grokability Snipe-IT up to 8.6.x Markdown Image Parsing file_get_contents notes file inclusion
A vulnerability was found in Grokability Snipe-IT up to 8.6.x. It has been classified as critical. The impacted element is the function file_get_contents of the component Markdown Image Parsing. This manipulation of the argument notes cause
CVE-2026-87627 | Google Chrome up to 152.0.7977.82 Safebrowsing access control (Nessus ID 344274)
A vulnerability, which was classified as critical, was found in Google Chrome. The impacted element is an unknown function of the component Safebrowsing. Executing a manipulation can lead to improper access controls. This vulnerability is t
CVE-2026-86748 | Grokability Snipe-IT up to 8.6.x Restore Endpoint cleanup
A vulnerability was found in Grokability Snipe-IT up to 8.6.x. It has been rated as problematic. The affected element is an unknown function of the component Restore Endpoint. This manipulation causes improper cleanup on thrown exception. T
CVE-2026-56711 | VideoLAN VLC Media Player up to 3.0.23 Picture Buffer Allocation src/misc/picture.c AllocatePicture integer overflow
A vulnerability was found in VideoLAN VLC Media Player up to 3.0.23 and classified as critical. This affects the function AllocatePicture of the file src/misc/picture.c of the component Picture Buffer Allocation. The manipulation results in
CVE-2026-73324 | VideoLAN VLC Media Player up to 3.0.23 RTSP Access access.c RtspReadLine heap-based overflow
A vulnerability classified as problematic was found in VideoLAN VLC Media Player up to 3.0.23. This issue affects the function RtspReadLine of the file modules/access/rtsp/access.c of the component RTSP Access. Such manipulation leads to he
CVE-2026-79969 | Dell Secure Connect Gateway race condition (EUVD-2026-74893)
A vulnerability was found in Dell Secure Connect Gateway. It has been classified as critical. The affected element is an unknown function. The manipulation leads to race condition. This vulnerability is listed as CVE-2026-79969. The attack
CVE-2026-79968 | Dell Secure Connect Gateway toctou
A vulnerability labeled as very critical has been found in Dell Secure Connect Gateway. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to time-of-check time-of-use. This vulnerability appears a
CVE-2026-87656 | Google Chrome up to 152.0.7977.82 Safebrowsing access control (CNNVD-2026-98296902)
A vulnerability classified as critical has been found in Google Chrome. Affected by this vulnerability is an unknown functionality of the component Safebrowsing. This manipulation causes improper access controls. This vulnerability appears
Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Attackers are actively exploiting a critical flaw in a WooCommerce extension to seize control of WordPress sites without a username or password. The issue affects Wholesale Lead Capture and turns a routine file-upload feature into a direct
CVE-2026-63889 | Linux Kernel up to 7.0.11 Scsi Transport Fc pname_count integer overflow (Nessus ID 345819)
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 7.0.11. Affected by this issue is some unknown functionality of the component Scsi Transport Fc. The manipulation of the argument pname_count leads to i
CVE-2026-15789 | moby BuildKit up to 0.31.1 BuildKit control API path traversal (Nessus ID 345821)
A vulnerability, which was classified as problematic, has been found in moby BuildKit up to 0.31.1. The affected element is an unknown function of the component BuildKit control API. The manipulation leads to path traversal. This vulnerabil
CVE-2026-90852 | luben zstd-jni up to 1.5.7-13 Dictionary Sharing ZstdCompressCtx.java ZstdCompressCtx.loadDict use after free (Issue 404 / Nessus ID 345822)
A vulnerability labeled as critical has been found in luben zstd-jni up to 1.5.7-13. This vulnerability affects the function ZstdCompressCtx.loadDict of the file ZstdCompressCtx.java of the component Dictionary Sharing. Such manipulation le
CVE-2026-91846 | CIRCL MISP up to 2.5.45 Collection __assertCanUseElements improper authorization (334d53709 / EUVD-2026-78328)
A vulnerability identified as problematic has been detected in CIRCL MISP up to 2.5.45. This vulnerability affects the function __assertCanUseElements of the component Collection. This manipulation causes improper authorization. This vulner
CVE-2026-76159 | Duplicati 2.3.0.1 Configuration Loader preload.json permission (EUVD-2026-78330)
A vulnerability, which was classified as problematic, has been found in Duplicati 2.3.0.1. This impacts an unknown function of the file preload.json of the component Configuration Loader. This manipulation causes permission issues. This vul
CVE-2026-77853 | LITE-ON FF-RFI079I4/FF-RFI078I4 up to 02.01.14 NETCONF os command injection (EUVD-2026-78332)
A vulnerability marked as very critical has been reported in LITE-ON FF-RFI079I4 and FF-RFI078I4 up to 02.01.14. Impacted is an unknown function of the component NETCONF. Performing a manipulation results in os command injection. This vulne
CVE-2026-91781 | GNU Binutils 2.47 ELF Section bfd/elf64-x86-64.c elf_x86_64_common_section_index null pointer dereference (Bug 34449 / EUVD-2026-78329)
A vulnerability marked as problematic has been reported in GNU Binutils 2.47. Affected is the function elf_x86_64_common_section_index of the file bfd/elf64-x86-64.c of the component ELF Section Handler. The manipulation leads to null point
CVE-2026-91851 | CIRCL MISP up to 2.5.45 Dashboard Template Filtering listTemplates restrict_to_permission_flag privileges management (245b8d63a / EUVD-2026-78333)
A vulnerability classified as problematic was found in CIRCL MISP up to 2.5.45. This affects the function DashboardsController::listTemplates of the component Dashboard Template Filtering. The manipulation of the argument restrict_to_permis
CVE-2026-80217 | LITE-ON FF-RFI079I4/FF-RFI078I4 up to 02.01.14 os command injection (EUVD-2026-78334)
A vulnerability described as very critical has been identified in LITE-ON FF-RFI079I4 and FF-RFI078I4 up to 02.01.14. The affected element is an unknown function. Executing a manipulation can lead to os command injection. This vulnerability
CVE-2026-91826 | Samsung rLottie stack-based overflow (EUVD-2026-78331)
A vulnerability labeled as problematic has been found in Samsung rLottie. This issue affects some unknown processing. Such manipulation leads to stack-based buffer overflow. This vulnerability is listed as CVE-2026-91826. The attack must be
CVE-2026-91782 | GNU Binutils 2.47 Dynamic Relocation Allocation bfd/elfxx-x86.c elf_x86_allocate_dynrelocs null pointer dereference (Bug 34448 / EUVD-2026-78335)
A vulnerability described as problematic has been identified in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_allocate_dynrelocs of the file bfd/elfxx-x86.c of the component Dynamic Relocation Allocation. The man
CVE-2022-44002 | BACKCLICK Professional 5.9.63 cross site scripting (syss-2022-026 / EUVD-2022-46965)
A vulnerability labeled as problematic has been found in BACKCLICK Professional 5.9.63. This vulnerability affects unknown code. Executing a manipulation can lead to cross site scripting. This vulnerability is tracked as CVE-2022-44002. The
CVE-2022-44001 | BACKCLICK Professional 5.9.63 CORBA Back-End Services improper authentication (SYSS-2022-035 / EUVD-2022-46964)
A vulnerability has been found in BACKCLICK Professional 5.9.63 and classified as critical. Affected by this vulnerability is an unknown functionality of the component CORBA Back-End Services. This manipulation causes improper authenticatio
CVE-2022-44000 | BACKCLICK Professional 5.9.63 Internal Communications Interface missing authentication (SYSS-2022-032 / EUVD-2022-46963)
A vulnerability identified as problematic has been detected in BACKCLICK Professional 5.9.63. This affects an unknown part of the component Internal Communications Interface. Performing a manipulation results in missing authentication. This
CVE-2022-43999 | BACKCLICK Professional 5.9.63 CORBA Management Services missing authentication (SYSS-2022-034 / EUVD-2022-46962)
A vulnerability categorized as problematic has been discovered in BACKCLICK Professional 5.9.63. Affected by this issue is some unknown functionality of the component CORBA Management Services. Such manipulation leads to missing authenticat
Hackers Actively Exploiting Gitea n-day RCE Vulnerability in the Wild to Hijack Instances
Hackers are actively exploiting a critical Gitea remote code execution vulnerability, tracked as CVE-2026-60004, to compromise internet-facing source-code management servers. Researchers found that a Chinese-speaking threat actor, named Red
Marimo RCE Flaw Lets Hackers Steal AWS Credentials and Pivot to Bastion Host in 8 Seconds
A threat actor exploited a critical pre-authentication remote code execution vulnerability in marimo to harvest AWS credentials, retrieve an SSH private key from AWS Secrets Manager, and authenticate to a bastion host in just eight seconds,
Marimo RCE Flaw Lets Hackers Steal AWS Credentials and Pivot to Bastion Host in 8 Seconds
A threat actor exploited a critical pre-authentication remote code execution vulnerability in marimo to harvest AWS credentials, retrieve an SSH private key from AWS Secrets Manager, and authenticate to a bastion host in just eight seconds,
WooCommerce Plugin Bug Lets Remote Attackers Create Admin Accounts and Take Over Sites
A critical security flaw in the WooCommerce Wholesale Lead Capture plugin is being actively exploited, allowing remote attackers to upload malicious files and potentially take full control of vulnerable WordPress sites. The vulnerability, t
Hackers Exploit Marimo RCE to Steal AWS Credentials and Reach Bastion Host in 8 Seconds
Threat actors have been observed exploiting a critical remote code execution vulnerability in the Marimo notebook platform to steal AWS credentials and authenticate to an SSH bastion host within eight seconds. The attack, documented by the
Marimo RCE Flaw Lets Hackers Steal AWS Credentials and Pivot to Bastion Host in 8 Seconds
A threat actor exploited a pre-authentication remote code execution flaw in marimo to harvest AWS credentials, retrieve an SSH private key from AWS Secrets Manager, and authenticate to a bastion host in eight seconds. Tracked as CVE-2026-39
Schwachstelle in LiteSpeed Enterprise: Root-Zugriff für Shared-Hosting-Accounts möglich
LONDON (IT BOLTWISE) – Eine kritische Sicherheitslücke in LiteSpeed Web Server Enterprise könnte es Nutzern mit niedrigem Privileg auf Shared-Hosting-Servern ermöglichen, Root-Zugriff zu erlangen. Betroffen sind Versionen vor 6.3.7; cPanel
Cisco AsyncOS: CVE-2026-76461 wird aktiv ausgenutzt – Patch bis 17. September 2026
LONDON (IT BOLTWISE) – Cisco warnt, dass die Lücke in AsyncOS für den Secure Email Gateway bereits aktiv ausgenutzt wird. Die Schwachstelle CVE-2026-76461 (CVSS 9,8/10) kann laut Hersteller einem unauthentifizierten Angreifer das Ausführen
Linux Kernel ZcopyReaper Vulnerability Lets Local Attackers Gain Root Privileges
Security researchers have disclosed a local privilege escalation vulnerability in the Linux kernel related to the Reliable Datagram Sockets (RDS) zero-copy send path. This vulnerability could let an unprivileged local attacker gain root pri
Linux Kernel ZcopyReaper Vulnerability Lets Local Attackers Gain Root Privileges
Security researchers have disclosed a local privilege escalation vulnerability in the Linux kernel related to the Reliable Datagram Sockets (RDS) zero-copy send path. This vulnerability could let an unprivileged local attacker gain root pri
Non-Zero-Day VPN Flaw Left Japan ‘s Government Shared Network Platform Exposed: 246,000 Records at Risk
Japan ‘s Digital Agency disclosed a VPN breach exposing 246,000 government employee records across 23 ministries. Detected June 25, publicly disclosed September 11. Japan ‘s Digital Agency disclosed that attackers exploited a vulnerability
GRIMWEDGE nutzt Chrome-Windows Patch-Gap: Mehrstufige Zero-Day Kette im Fokus
LONDON (IT BOLTWISE) – Ein von Volexity beobachteter chinesisch zugeordneter Angriffscluster nutzt eine Spear-Phishing-Kampagne, um eine mehrstufige Zero-Day-Chain aus Chrome- und Windows-Schwächen auszulösen. Der Einstieg erfolgt über eine
Nintendo Switch Vulnerability Lets Nearby Attackers Run Unauthorized Code via QR Codes
Nintendo has patched a high-severity vulnerability in the Nintendo Switch that could allow nearby attackers to execute unauthorized code or access information stored on affected consoles by abusing QR-code-based local wireless connections.
GRIMWEDGE & BlueMoon: Chrome-Windows-Zero-Day-Kette über reflektiertes XSS
LONDON (IT BOLTWISE) – Forschende ordnen einen Spear-Phishing-Angriff zu, der eine reflektierte XSS-Schwachstelle auf einer U.S.-Uni-Webseite missbraucht. Die Angreifer kombinieren drei zuvor gepatchte Lücken in Google Chrome und Windows, u
Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation
An unauthenticated attacker can exploit CVE-2026-76461 to execute arbitrary commands on the underlying OS with root privileges. The post Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation appeared first on SecurityWee
A maximum severity GitLab flaw could turn your CI/CD server into an attacker’s treasure trove
Yet another security vulnerability has been discovered in GitLab infrastructure, this one a perfect 10 in severity. CVE-2026-85706, the second flaw GitLab has disclosed in just a month, is a maximum-severity vulnerability that allows attack
A maximum severity GitLab flaw could turn your CI/CD server into an attacker’s treasure trove
Yet another security vulnerability has been discovered in GitLab infrastructure, this one a perfect 10 in severity. CVE-2026-85706, the second flaw GitLab has disclosed in just a month, is a maximum-severity vulnerability that allows attack
Angriffe auf öffentlich erreichbare Vite-Dev-Server: Hacker suchen AWS- und Azure-Geheimnisse
LONDON (IT BOLTWISE) – Eine groß angelegte Scanning-Kampagne zielt auf öffentlich erreichbare Vite-Entwicklungsserver. Laut F5 missbrauchen Angreifer eine Schwachstelle CVE-2026-39364, um Datei- und Zugriffsbeschränkungen zu umgehen und sen
Red Heron nutzt Gitea-RCE und Rootkit SIXZUT für 13 kompromittierte Ziele
LONDON (IT BOLTWISE) – Ein mutmaßlich China-gebundenes Akteurscluster soll eine neu offengelegte Schwachstelle in Gitea (CVE-2026-60004) schnell zu einem automatisierten Angriffsframework ausgebaut haben. Dabei wird von 1.386 gescannten Git
GitLab warnt nach „In-the-wild“-Hinweisen vor Path-Traversal (CVE-2026-85706)
LONDON (IT BOLTWISE) – Hinweise auf „In-the-wild“-Ausnutzung rücken eine GitLab-Schwachstelle mit maximaler Kritikalität in den Fokus. Betroffen ist CVE-2026-85706, das Angreifern unter bestimmten Bedingungen den Zugriff auf beliebige Datei
Logitech Options+ flaw lets attackers gain Windows SYSTEM privileges
A vulnerability in Logitech Options+ allows a standard Windows user to gain SYSTEM-level privileges by exploiting a weakness in the software’s updater service. Tracked as CVE-2026-12518, the issue requires no administrator rights, network a
Nintendo warns of Switch code execution flaw via on-screen QR codes
Nintendo has patched a high-severity Nintendo Switch vulnerability that could allow a nearby attacker to execute unauthorized code or access information stored on the console. The flaw, tracked as CVE-2026-82079, affects Switch systems runn
CISA warnt: GitLab-Schlagloch CVE-2026-85706 aktiv ausgenutzt
USA / LONDON (IT BOLTWISE) – Die US-Cybersicherheitsbehörde CISA meldet, dass Angreifer eine GitLab-Sicherheitslücke maximaler Schwere (CVE-2026-85706) bereits ausnutzen. Betroffen ist ein DevSecOps-Feature, bei dem fehlende Authentifizieru
Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
Ravie LakshmananSep 11, 2026Vulnerability / Malware Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC)
Imperva Customers Protected Against StyleSmuggler (CVE-2026-75650) in Adobe Commerce and Magento Open Source
TL;DR: CVE-2026-75650, dubbed StyleSmuggler, is a critical vulnerability affecting Adobe Commerce and Magento Open Source. The vulnerability allows an unauthenticated attacker to inject malicious PHP code into Magento’s template system and
Active exploitation of Cisco Secure Firewall Management Center vulnerabilities
Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software. First, CVE-2026-20079 is an authentication bypass vulnerability in unpatched instances of Cisco’s Secure F
Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."Microsoft notes that 2 of the vulnerabiliti
Nightmare Eclipse drops a CrowdStrike zero-day.
Extortion group leaks alleged Manchester Airports Group data. France's CNIL fines hospital over 2025 data breach. Weiterlesen
CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers’ crosshairs. The vulnerabilities are as follows – C
CVE-2026-75757 | Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an attacker who controls a sibling subdomain rebind an admin's session to a different actor, tenant, or authorization mode. AshAdmin's client JavaScript read its state cookies (tenant, actor_resource, actor_primary_key, actor_action, actor_domain, actor_authorizing, actor_paused) by matching the cookie name with an unanchored regular expression (new RegE
Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an attacker who controls a sibling subdomain rebind an admin's session to a different actor, tenant, or authorization mode. AshAdmin'
CVE-2026-82605 | A vulnerability has been found in BareBones BBEdit up to 15.5.5. The affected element is an unknown function of the component Lasso Language Tokenizer. Such manipulation leads to infinite loop. The attack can be executed remotely. Upgrading to version 16.0 is sufficient to fix this issue. The affected component should be upgraded.
A vulnerability has been found in BareBones BBEdit up to 15.5.5. The affected element is an unknown function of the component Lasso Language Tokenizer. Such manipulation leads to infinite loop. The attack can be executed remotely. Upgrading