🎯 CVE-2026-86060 LOW 3.1 🔥 EPSS 5.3%
📄 .md Alle CVEs anzeigen ✕

CVE-2026-86060: Schwachstellen-Eintrag (NVD)

RouterOS contains an argument-handling flaw in the SSH login
path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)

Improper Privilege Management 🎯 Medium

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

🛡️ Empfohlene Mitigation: Very carefully manage the setting, management, and handling of privileges. Explicitly manage trust zones in the software.
Vollständige Definition bei MITRE ➔
🎯 ATT&CK-Techniken (Kill-Chain-Verhalten):
📰 Eigene Berichterstattung: ➔ CVE-2026-86060 | Mikrotik RouterOS up to 6.49.20/7.23.3/7.24.1 SSH Login privile
📚 Referenzen & Quellen:
Ausnutzungs-Zeitleiste:
Veröffentlicht:05.09.2026
Aktualisiert:05.09.2026 21:16
Assigner (CNA):NVD
Quellen: 🇪🇺 EUVD-Datenbank (ENISA) + 🇺🇸 NVD-Anreicherung · 24-h-Cache
CWE-269: Privilege Management ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

354k+ 🇪🇺 EUVD-Datenbank
11 🔴 Critical im Radar
8 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
0 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-09: 240 2025-10: 316 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 418 2026-03: 652 2026-04: 574 2026-05: 683 2026-06: 942 2026-07: 1333 2026-08: 1329 7.601 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-08-292026-09-05
≥90 %40
≥50 %40
≥10 %30
<10 %304300
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Generic Security 37
Linux 9
Adobe 5
WordPress 4
VMware 2
Google 2
Schweregrad & Status:
Hersteller (Datenbank-weit, 90.597 Einträge):
Quelle:
🔍
7.5 HIGH
EPSS 18%
CVE-2026-18309 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18309 | GIMP APNG File Parser integer overflow

A vulnerability classified as critical was found in GIMP. Affected is an unknown function of the component APNG File Parser. Such manipulation leads to integer overflow. This vulnerability is documented as CVE-2026-18309. The attack can be

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.4%
CVE-2026-18299 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18299 | GStreamer rtpsbcdepay use after free (Nessus ID 339182)

A vulnerability identified as critical has been detected in GStreamer. Affected is an unknown function of the component rtpsbcdepay. The manipulation leads to use after free. This vulnerability is listed as CVE-2026-18299. The attack may be

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27%
CVE-2026-18300 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18300 | GIMP HDR File Parser integer overflow (Nessus ID 342395)

A vulnerability categorized as critical has been discovered in GIMP. Affected by this issue is some unknown functionality of the component HDR File Parser. The manipulation results in integer overflow. This vulnerability is identified as CV

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.4%
CVE-2026-18301 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18301 | GIMP PSD File Parser integer overflow (Nessus ID 342026)

A vulnerability was found in GIMP. It has been rated as critical. Affected by this vulnerability is an unknown functionality of the component PSD File Parser. The manipulation leads to integer overflow. This vulnerability is referenced as C

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31%
CVE-2026-18302 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18302 | GIMP TIF File Parser buffer overflow (Nessus ID 342026)

A vulnerability was found in GIMP. It has been declared as critical. Affected is an unknown function of the component TIF File Parser. Executing a manipulation can lead to buffer overflow. The identification of this vulnerability is CVE-202

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.6%
CVE-2026-18303 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18303 | GIMP TIF File Parser buffer overflow (Nessus ID 342026)

A vulnerability was found in GIMP. It has been classified as critical. This impacts an unknown function of the component TIF File Parser. Performing a manipulation results in buffer overflow. This vulnerability was named CVE-2026-18303. The

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.3%
CVE-2026-18305 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18305 | GIMP TIF File Parser integer overflow (Nessus ID 342026)

A vulnerability has been found in GIMP and classified as critical. The impacted element is an unknown function of the component TIF File Parser. This manipulation causes integer overflow. This vulnerability is handled as CVE-2026-18305. The

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.7%
CVE-2026-18304 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18304 | GIMP TIF File Parser integer overflow (Nessus ID 342026)

A vulnerability was found in GIMP and classified as critical. This affects an unknown function of the component TIF File Parser. Such manipulation leads to integer overflow. This vulnerability is uniquely identified as CVE-2026-18304. The a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.3%
CVE-2026-18307 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18307 | GIMP TIF File Parser buffer overflow (Nessus ID 342026)

A vulnerability, which was classified as critical, has been found in GIMP. Impacted is an unknown function of the component TIF File Parser. The manipulation leads to buffer overflow. This vulnerability is traded as CVE-2026-18307. It is po

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.3%
CVE-2026-18306 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18306 | GIMP SGI File Parser integer overflow (Nessus ID 342026)

A vulnerability, which was classified as critical, was found in GIMP. The affected element is an unknown function of the component SGI File Parser. The manipulation results in integer overflow. This vulnerability is known as CVE-2026-18306.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.5%
CVE-2026-18297 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18297 | GStreamer OGG File Parser stack-based overflow

A vulnerability marked as critical has been reported in GStreamer. Affected by this issue is some unknown functionality of the component OGG File Parser. This manipulation causes stack-based buffer overflow. This vulnerability is registered

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.4%
CVE-2026-18308 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18308 | GIMP TIF File Parser integer overflow (Nessus ID 342026)

A vulnerability classified as critical was found in GIMP. This issue affects some unknown processing of the component TIF File Parser. Executing a manipulation can lead to integer overflow. This vulnerability appears as CVE-2026-18308. The

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.8%
CVE-2026-18298 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18298 | GStreamer PNG File Parser heap-based overflow (Nessus ID 339182)

A vulnerability labeled as critical has been found in GStreamer. Affected by this vulnerability is an unknown functionality of the component PNG File Parser. The manipulation results in heap-based buffer overflow. This vulnerability is cata

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 26.2%
CVE-2026-76848 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-76848 | TypeORM up to 1.1.0 SelectQueryBuilder SelectQueryBuilder.ts createSelectDistinctExpression distinctOn sql injection

This issue is likely a false positive. Please verify the cited sources and consider not including this entry. Weiterlesen

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.3%
CVE-2026-39909 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-39909 | ggml-org llama.cpp up to b9060 RPC server GRAPH_RECOMPUTE handler use after free (EUVD-2026-64001)

This appears to be a false positive. Please validate the mentioned sources and consider excluding this entry altogether. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.8%
CVE-2026-45201 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-45201 | Imagination Graphics DDK up to 26.1 RTM1 out-of-bounds

A vulnerability classified as very critical was found in Imagination Graphics DDK up to 1.18 RTM1/23.2 RTM1/24.2 RTM2/25.3 RTM/26.1 RTM1. Affected is an unknown function. Executing a manipulation can lead to out-of-bounds read. This vulnera

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.8%
CVE-2026-45202 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-45202 | Imagination Graphics DDK up to 26.1 RTM1 Memory Free Paths double free

A vulnerability classified as very critical has been found in Imagination Graphics DDK up to 1.18 RTM2/23.2 RTM2/24.2 RTM2/25.3 RTM/26.1 RTM1. This impacts an unknown function of the component Memory Free Paths. Performing a manipulation re

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18%
CVE-2026-45199 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-45199 | Imagination Graphics DDK up to 26.1 RTM1 GPU Firmware memory corruption

A vulnerability described as very critical has been identified in Imagination Graphics DDK up to 26.1 RTM1. This affects an unknown function of the component GPU Firmware. Such manipulation leads to memory corruption. This vulnerability is

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.2%
CVE-2026-43798 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-43798 | Apple swift-nio-ssh up to 0.14.0 memory corruption

A vulnerability identified as critical has been detected in Apple swift-nio-ssh up to 0.14.0. This affects an unknown function. Performing a manipulation results in memory corruption. This vulnerability is known as CVE-2026-43798. Remote ex

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 3.3%
CVE-2026-52021 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-52021 | code100x CMS 1.0 Middleware src/middleware.ts information disclosure

A vulnerability described as problematic has been identified in code100x CMS 1.0. Affected by this vulnerability is an unknown functionality of the file src/middleware.ts of the component Middleware. The manipulation results in information

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.2%
CVE-2026-66785 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-66785 | Red Hat Advanced Cluster Management for Kubernetes Submariner redirect (EUVD-2026-63572)

A vulnerability, which was classified as problematic, was found in Red Hat Advanced Cluster Management for Kubernetes. Affected by this vulnerability is an unknown functionality of the component Submariner. The manipulation results in open

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30%
CVE-2026-19586 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-19586 | TP-Link ER7212PC OpenVPN Server os command injection (WID-SEC-2026-2964)

A vulnerability was found in TP-Link ER7212PC, ER605, ER7206, ER7406, ER707-M2, ER7412-M2, ER8411, ER706W, ER706W-4G, ER706WP-4G, ER703WP-4G-Outdoor, DR3220v-4G, DR3650v, DR3650v-4G, ER603WP-4G-Outdoor, DR3150, ER701-5G-Outdoor and ER605W.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.8%
CVE-2026-66787 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-66787 | Red Hat Advanced Cluster Management for Kubernetes lighthouse debug code (EUVD-2026-63533)

A vulnerability labeled as problematic has been found in Red Hat Advanced Cluster Management for Kubernetes. Impacted is an unknown function of the component lighthouse. The manipulation results in active debug code. This vulnerability is i

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.9%
CVE-2026-66788 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-66788 | Red Hat Advanced Cluster Management for Kubernetes Resource Injection privileges management (EUVD-2026-63535)

A vulnerability classified as very critical has been found in Red Hat Advanced Cluster Management for Kubernetes. This affects an unknown function of the component Resource Injection. Performing a manipulation results in improper privilege

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Adobe

Hackers Actively Exploiting Magento and Adobe Commerce 0-Day RCE Vulnerability

A newly discovered zero-day vulnerability in Magento Open Source and Adobe Commerce is being actively exploited by attackers to seize full control of online stores, and there is still no official patch available. Dutch e-commerce security f

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.7%
CVE-2026-80746 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-80746 | Linux Kernel up to 7.1.9 disp_cc_mdss_mdp_clk_src RCG clk-rcg2.c update_config behavioral workflow (Nessus ID 343069)

A vulnerability, which was classified as critical, has been found in Linux Kernel up to 7.1.9. Affected by this vulnerability is the function update_config of the file drivers/clk/qcom/clk-rcg2.c of the component disp_cc_mdss_mdp_clk_src RC

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 23.3%
CVE-2026-80745 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-80745 | Linux Kernel up to 7.1.9 fp9931 out-of-bounds (Nessus ID 343070)

A vulnerability categorized as critical has been discovered in Linux Kernel up to 7.1.9. The impacted element is an unknown function of the component fp9931. Executing a manipulation can lead to out-of-bounds read. This vulnerability is reg

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 32.2%
CVE-2026-80741 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-80741 | Linux Kernel up to 6.18.45/7.1.9 DRM Log drm_log.c drm_log_draw_kmsg_record len out-of-bounds (Nessus ID 343072)

A vulnerability was found in Linux Kernel up to 6.18.45/7.1.9. It has been declared as very critical. Impacted is the function drm_log_draw_kmsg_record of the file drivers/gpu/drm/drm_log.c of the component DRM Log. Such manipulation of the

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 24.2%
CVE-2026-80735 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-80735 | Linux Kernel up to 6.18.44/7.1.8 ovpn out-of-bounds (Nessus ID 343071)

A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.18.44/7.1.8. This impacts an unknown function of the component ovpn. Such manipulation leads to out-of-bounds read. This vulnerability is referenced as CVE

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 27.6%
CVE-2026-85458 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-85458 | Xpdf up to 4.06 divide by zero (Nessus ID 343074 / WID-SEC-2026-3185)

A vulnerability classified as problematic has been found in Xpdf up to 4.06. This affects an unknown function. This manipulation causes divide by zero. This vulnerability appears as CVE-2026-85458. The attack may be initiated remotely. Ther

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.7%
CVE-2026-80753 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-80753 | Linux Kernel up to 7.1.9 ovpn use after free (Nessus ID 343073)

A vulnerability described as very critical has been identified in Linux Kernel up to 7.1.9. Affected by this vulnerability is an unknown functionality of the component ovpn. Such manipulation leads to use after free. This vulnerability is t

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 32.8%
CVE-2026-80734 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-80734 | Linux Kernel up to 7.1.8 btrfs extent_io.c btrfs_read_locked_inode initialization (Nessus ID 343076)

A vulnerability marked as very critical has been reported in Linux Kernel up to 7.1.8. This issue affects the function btrfs_read_locked_inode of the file extent_io.c of the component btrfs. Performing a manipulation results in improper ini

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 22.6%
CVE-2026-80748 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-80748 | Linux Kernel up to 6.18.45/7.1.9 mmc out-of-bounds (Nessus ID 343078)

A vulnerability identified as critical has been detected in Linux Kernel up to 6.18.45/7.1.9. This affects the function ls2k0500_mmc_reorder_cmd_data/ls2k2000_mmc_reorder_cmd_data of the component mmc. The manipulation leads to out-of-bound

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 29.7%
CVE-2026-80727 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-80727 | Linux Kernel up to 6.12.104/6.18.44/7.1.8 x86 MCE lib/debugobjects.c timer_setup race condition (Nessus ID 343079)

A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.12.104/6.18.44/7.1.8. Affected by this issue is the function timer_setup of the file lib/debugobjects.c of the component x86 MCE. The manipulation results i

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 22.6%
CVE-2026-80740 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-80740 | Linux Kernel up to 6.18.45/7.1.9 DRM Log drm_log_setup_modeset columns infinite loop (Nessus ID 343080)

A vulnerability was found in Linux Kernel up to 6.18.45/7.1.9. It has been rated as problematic. This vulnerability affects the function drm_log_setup_modeset of the component DRM Log. This manipulation of the argument columns causes infini

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Adobe

Hackers Actively Exploiting Magento and Adobe Commerce 0-Day RCE Vulnerability

A newly discovered zero-day vulnerability in Magento Open Source and Adobe Commerce is being actively exploited by attackers to seize full control of online stores, and there is still no official patch available. Dutch e-commerce security f

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Adobe

Hackers Actively Exploiting Magento and Adobe Commerce 0-Day RCE Vulnerability

A newly discovered zero-day vulnerability in Magento Open Source and Adobe Commerce is being actively exploited by attackers to seize full control of online stores, and there is still no official patch available. Dutch e-commerce security f

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Adobe

Magento-Backdoor „StyleSmuggler“: Ungepatchte Zero-Day trifft Adobe Commerce

LONDON (IT BOLTWISE) – Eine ungesicherte Zero-Day-Lücke in Magento Open Source und Adobe Commerce wird offenbar aktiv ausgenutzt. Die Sicherheitsfirma Sansec nennt die Schwachstelle „StyleSmuggler“ und beschreibt eine Kette, die ohne Login

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Adobe

Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store&#039;s server without logging in, Dutch e-commerce security company Sansec said in an advi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.4%
CVE-2026-81578 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

PaperCut Flaws Exploited in Attacks on U.S. and European Schools

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-20

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.4%
CVE-2026-81578 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

PaperCut Flaws Exploited in Attacks on U.S. and European Schools

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-20

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.4%
CVE-2026-81578 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

PaperCut Flaws Exploited in Attacks on U.S. and European Schools

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-20

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.0 CRITICAL
EPSS 64.4%
CVE-2026-59346 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
VMware

Broadcom schließt kritische Lücke in VMware Workstation und Fusion (CVE-2026-59346)

LONDON (IT BOLTWISE) – Broadcom hat Sicherheitsupdates für VMware Workstation und VMware Fusion veröffentlicht und schließt dabei zwei Lücken, darunter einen kritischen Integer-Overflow mit CVSS 9,3. Unter bestimmten Bedingungen kann ein An

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 82.5%
CVE-2026-32475 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

Elementor Pro WordPress Flaw Exploited to Upload Webshells and Execute Commands

  A critical vulnerability in the Elementor Pro WordPress plugin is being actively exploited to upload malicious PHP files and execute commands remotely on the affected websites. The vulnerability, tracked as CVE-2026-32475, affects the Ele

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
7.5 HIGH
EPSS 22.4%
CVE-2026-59346 💻 Lokal 🔓 Keine Authentifizierung nötig
VMware

Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.5 CRITICAL
EPSS 72.1%
CVE-2026-9586 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Switchvox Vulnerability Triggers Active Exploitation Risk

  Sangoma Switchvox CVE-2026-9586 is a serious unauthenticated SQL injection flaw that can lead to remote code execution, and Horizon3 says it has already seen real-world exploitation attempts. The issue was patched in Switchvox 8.4.0.2, ma

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.3%
CVE-2023-49105 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CISA Flags Old ownCloud Flaw After Reported Philippine Nuclear Data Theft

CISA added CVE-2023-49105 to its exploited-flaws catalog after researchers tied the old ownCloud bug to reported Philippine nuclear data theft. This article has been indexed from Security Archives – TechRepublic Read the original article: C

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.5%
CVE-2026-32475 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites

Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions. This article has been indexed from SecurityWeek Read the original article: Elementor Pro WordP

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
7.5 HIGH
EPSS 18.5%
CVE-2026-32475 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites

Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions. The post Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites appeared first o

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
7.5 HIGH
EPSS 30.4%
CVE-2026-81578 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

PaperCut-Schwachstellen: Angreifer stehlen Anmeldedaten an Schulen und Universitäten

LONDON (IT BOLTWISE) – Angreifer nutzen neu gemeldete PaperCut-Schwachstellen, um an Schulen und Universitäten in den USA und Europa Zugangsdaten auszuspähen. In den Beobachtungen wurden CVE-2026-81578 und CVE-2026-82078 für Authentifizieru

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.4%
CVE-2026-6471 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers

A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged replication accounts to execute attacker-controlled code, escalate to database superuser, and establish persistent backdoors on affected servers. Tracked as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.4%
CVE-2026-6471 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers

A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged replication accounts to execute attacker-controlled code, escalate to database superuser, and establish persistent backdoors on affected servers. Tracked as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.4%
CVE-2026-6471 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

12-Year-Old PostgreSQL Flaw Lets Backup Accounts Execute Code and Take Over Databases

A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged backup and replication accounts to execute arbitrary code, escalate to database superuser privileges, and establish persistent access on vulnerable servers.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.8%
CVE-2026-85046 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

U.S. CISA adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Google Chromium V8 flaw, trac

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 82.8%
CVE-2026-85046 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

Google’s Chrome Update Patches Sixth Zero-Day Exploited in 2026

Chrome users have another actively exploited zero-day to worry about, and this one sits inside the engine that powers much of the modern web. Google has patched CVE-2026-85046, a high-severity type confusion vulnerability in Chrome’s V8 Jav

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 32.7%
CVE-2026-19949 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-19949 Leaves Millions of WordPress Sites Running Vulnerable Plugin Versions

A WordPress backup tool designed to help sites recover from trouble can instead become the trigger for an attack. Researchers disclosed a high-severity SQL injection vulnerability in the All-in-One WP Migration and Backup plugin that affect

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
7.5 HIGH
EPSS 18.4%
CVE-2026-6471 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

PostgreSQL stoppt Codeausführung via Logical Decoding: neuer Whitelist-Parameter

LONDON (IT BOLTWISE) – PostgreSQL schließt eine seit 2014 bekannte Schwachstelle (CVE-2026-6471), die mit dem REPLICATION-Attribut beliebigen Code im Backend-Prozess ausführen konnte. Die Absicherung erfolgt über einen neuen Parameter outpu

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.4%
CVE-2026-6471 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

PostgreSQL fixiert CVE-2026-6471: REPLICATION-Benutzer können Code als DB-User ausführen

LONDON (IT BOLTWISE) – PostgreSQL hat ein Sicherheitsproblem mit der logischen Replikation geschlossen, das einem Konto mit REPLICATION-Attribut die Ausführung beliebigen Codes als OS-User des Datenbankservers ermöglicht. Betroffen sind Ver

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.5 CRITICAL
EPSS 64.3%
CVE-2026-73749 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

HPE Patches Critical RCE Vulnerabilities in AOS-CX

Nearly two dozen issues, tracked collectively as CVE-2026-73749 (CVSS score of 9.8), were addressed with the updates. The post HPE Patches Critical RCE Vulnerabilities in AOS-CX appeared first on SecurityWeek. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Nightmare Eclipse drops a CrowdStrike zero-day.

Extortion group leaks alleged Manchester Airports Group data. France&#039;s CNIL fines hospital over 2025 data breach. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.