🎯 CVE-2026-86115 MEDIUM 5.0 🔥 EPSS 3%
📄 .md Alle CVEs anzeigen ✕

CVE-2026-86115: Schwachstellen-Eintrag (NVD)

Sim before 0.8.14 classifies tool requests as internal based on URL prefix matching without scheme normalization, skipping SSRF validation and minting internal authentication tokens. Authenticated workflow authors can bypass external URL validation by supplying paths starting with /api/ in HTTP blocks to reach internal-only endpoints like POST /api/function/execute.

Improper Control of Generation of Code ('Code Injection') 🎯 Medium

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

🛡️ Empfohlene Mitigation: Refactor your program so that you do not have to dynamically generate code.
Vollständige Definition bei MITRE ➔
📰 Eigene Berichterstattung: ➔ CVE-2026-86115 | simstudioai Sim up to 0.8.13 URL Prefix Matching /api/function/
📚 Referenzen & Quellen:
Ausnutzungs-Zeitleiste:
CVSS-Vektor-Analyse: 5.0
AV · Angriffsvektor Netzwerk
AC · Komplexität Gering
PR · Privilegien Gering
UI · Interaktion Keine
S · Scope Verändert
C · Vertraulichkeit Gering
I · Integrität Keine
A · Verfügbarkeit Keine
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Veröffentlicht:05.09.2026
Aktualisiert:05.09.2026 10:16
Assigner (CNA):NVD
Quellen: 🇪🇺 EUVD-Datenbank (ENISA) + 🇺🇸 NVD-Anreicherung · 24-h-Cache
CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

354k+ 🇪🇺 EUVD-Datenbank
15 🔴 Critical im Radar
10 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
0 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-09: 256 2025-10: 316 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 418 2026-03: 652 2026-04: 574 2026-05: 683 2026-06: 942 2026-07: 1333 2026-08: 1329 7.617 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-08-292026-09-05
≥90 %40
≥50 %40
≥10 %30
<10 %304300
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Generic Security 38
WordPress 7
Google 5
Microsoft 4
Linux 2
Apple 2
Schweregrad & Status:
Hersteller (Datenbank-weit, 90.597 Einträge):
Quelle:
🔍
7.5 HIGH
EPSS 23.8%
CVE-2026-86174 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-86174 | Makeplane Plane up to 1.4.2 Public Comment Endpoint issue_id authorization (EUVD-2026-71973)

A vulnerability marked as problematic has been reported in Makeplane Plane up to 1.4.2. This affects an unknown function of the component Public Comment Endpoint. This manipulation of the argument issue_id causes missing authorization. The

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.6%
CVE-2026-86177 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-86177 | Pterodactyl Panel up to 1.14.0 Scheduled Task privileges management (EUVD-2026-71976)

A vulnerability described as critical has been identified in Pterodactyl Panel up to 1.14.0. This impacts an unknown function of the component Scheduled Task. Such manipulation leads to improper privilege management. This vulnerability is r

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.2%
CVE-2026-86176 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-86176 | netbox-community NetBox up to 4.7.0 API Endpoints permission (EUVD-2026-71975)

A vulnerability identified as problematic has been detected in netbox-community NetBox up to 4.7.0. The affected element is an unknown function of the component API Endpoints. The manipulation leads to permission issues. This vulnerability

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.4%
CVE-2026-86175 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-86175 | netbox-community NetBox up to 4.7.0 Data Source Backend missing encryption (EUVD-2026-71974)

A vulnerability categorized as problematic has been discovered in netbox-community NetBox up to 4.7.0. Impacted is an unknown function of the component Data Source Backend. Executing a manipulation can lead to missing encryption of sensitiv

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.9%
CVE-2026-12843 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-12843 | StellarWP LearnDash LMS Plugin up to 5.1.6 on WordPress authorization (EUVD-2026-71990)

A vulnerability, which was classified as critical, was found in StellarWP LearnDash LMS Plugin up to 5.1.6 on WordPress. This affects an unknown part. The manipulation results in authorization bypass. This vulnerability is cataloged as CVE-

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
5.8 MEDIUM
EPSS 4.5%
CVE-2026-86178 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-86178 | Pixelfed up to 0.12.9 StoryComposeController information disclosure (EUVD-2026-71977)

A vulnerability labeled as problematic has been found in Pixelfed up to 0.12.9. The impacted element is an unknown function of the component StoryComposeController. The manipulation results in information disclosure. This vulnerability was

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.7%
CVE-2026-10196 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-10196 | getwpfunnels Mail Mint Plugin up to 1.31.0 on WordPress handle_form_submission deserialization (EUVD-2026-71991)

A vulnerability classified as critical was found in getwpfunnels Mail Mint Plugin up to 1.31.0 on WordPress. Affected by this vulnerability is the function handle_form_submission. Executing a manipulation can lead to deserialization. This v

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
7.5 HIGH
EPSS 22.8%
CVE-2026-15550 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-15550 | Saturday Drive Ninja Forms Plugin up to 3.0.30 on WordPress bulk_actions missing authentication (EUVD-2026-71992)

A vulnerability has been found in Saturday Drive Ninja Forms Plugin up to 3.0.30 on WordPress and classified as problematic. This vulnerability affects the function bulk_actions. This manipulation causes missing authentication. This vulnera

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
7.5 HIGH
EPSS 20.7%
CVE-2026-86184 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-86184 | Lara Dashboard up to 1.2.x Screenshot Login email improper authentication (EUVD-2026-71993)

A vulnerability was found in Lara Dashboard up to 1.2.x. It has been classified as critical. Impacted is an unknown function of the component Screenshot Login. Performing a manipulation of the argument email results in improper authenticati

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.7%
CVE-2026-86185 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-86185 | Bilibili Desktop up to 1.18.0 TLS Certificate Verification certificate validation (EUVD-2026-71994)

A vulnerability was found in Bilibili Desktop up to 1.18.0 and classified as problematic. This issue affects some unknown processing of the component TLS Certificate Verification. Such manipulation leads to improper certificate validation.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.3%
CVE-2023-49105 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CISA Flags Old ownCloud Flaw After Reported Philippine Nuclear Data Theft

CISA added CVE-2023-49105 to its exploited-flaws catalog after researchers tied the old ownCloud bug to reported Philippine nuclear data theft. This article has been indexed from Security Archives – TechRepublic Read the original article: C

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.5%
CVE-2026-32475 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites

Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions. This article has been indexed from SecurityWeek Read the original article: Elementor Pro WordP

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
7.5 HIGH
EPSS 18.5%
CVE-2026-32475 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites

Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions. The post Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites appeared first o

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
7.5 HIGH
EPSS 30.4%
CVE-2026-81578 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

PaperCut-Schwachstellen: Angreifer stehlen Anmeldedaten an Schulen und Universitäten

LONDON (IT BOLTWISE) – Angreifer nutzen neu gemeldete PaperCut-Schwachstellen, um an Schulen und Universitäten in den USA und Europa Zugangsdaten auszuspähen. In den Beobachtungen wurden CVE-2026-81578 und CVE-2026-82078 für Authentifizieru

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.4%
CVE-2026-6471 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers

A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged replication accounts to execute attacker-controlled code, escalate to database superuser, and establish persistent backdoors on affected servers. Tracked as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.5 CRITICAL
EPSS 62.4%
CVE-2026-81578 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting C

CWE-287: Improper Authentication ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.4%
CVE-2026-6471 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers

A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged replication accounts to execute attacker-controlled code, escalate to database superuser, and establish persistent backdoors on affected servers. Tracked as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.4%
CVE-2026-6471 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers

A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged replication accounts to execute attacker-controlled code, escalate to database superuser, and establish persistent backdoors on affected servers. Tracked as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.4%
CVE-2026-6471 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

12-Year-Old PostgreSQL Flaw Lets Backup Accounts Execute Code and Take Over Databases

A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged backup and replication accounts to execute arbitrary code, escalate to database superuser privileges, and establish persistent access on vulnerable servers.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.8%
CVE-2026-85046 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

U.S. CISA adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Google Chromium V8 flaw, trac

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 82.8%
CVE-2026-85046 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

Google’s Chrome Update Patches Sixth Zero-Day Exploited in 2026

Chrome users have another actively exploited zero-day to worry about, and this one sits inside the engine that powers much of the modern web. Google has patched CVE-2026-85046, a high-severity type confusion vulnerability in Chrome’s V8 Jav

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 32.7%
CVE-2026-19949 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-19949 Leaves Millions of WordPress Sites Running Vulnerable Plugin Versions

A WordPress backup tool designed to help sites recover from trouble can instead become the trigger for an attack. Researchers disclosed a high-severity SQL injection vulnerability in the All-in-One WP Migration and Backup plugin that affect

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
7.5 HIGH
EPSS 18.4%
CVE-2026-6471 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

PostgreSQL stoppt Codeausführung via Logical Decoding: neuer Whitelist-Parameter

LONDON (IT BOLTWISE) – PostgreSQL schließt eine seit 2014 bekannte Schwachstelle (CVE-2026-6471), die mit dem REPLICATION-Attribut beliebigen Code im Backend-Prozess ausführen konnte. Die Absicherung erfolgt über einen neuen Parameter outpu

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.4%
CVE-2026-6471 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

PostgreSQL fixiert CVE-2026-6471: REPLICATION-Benutzer können Code als DB-User ausführen

LONDON (IT BOLTWISE) – PostgreSQL hat ein Sicherheitsproblem mit der logischen Replikation geschlossen, das einem Konto mit REPLICATION-Attribut die Ausführung beliebigen Codes als OS-User des Datenbankservers ermöglicht. Betroffen sind Ver

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.5 CRITICAL
EPSS 64.3%
CVE-2026-73749 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

HPE Patches Critical RCE Vulnerabilities in AOS-CX

Nearly two dozen issues, tracked collectively as CVE-2026-73749 (CVSS score of 9.8), were addressed with the updates. The post HPE Patches Critical RCE Vulnerabilities in AOS-CX appeared first on SecurityWeek. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Nightmare Eclipse drops a CrowdStrike zero-day.

Extortion group leaks alleged Manchester Airports Group data. France&#039;s CNIL fines hospital over 2025 data breach. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.4%
CVE-2026-6471 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

PostgreSQL Hit by 12-Year-Old Vulnerability Allowing Server Takeover

PostGREShell (CVE-2026-6471) is a 12-year-old PostgreSQL flaw that lets low-privileged attackers execute code and take over servers. Cyera researchers found a severe PostgreSQL vulnerability, dubbed PostGREShell and tracked as CVE-2026-6471

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.4%
CVE-2026-6471 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

PostgreSQL Hit by 12-Year-Old Vulnerability Allowing Server Takeover

PostGREShell (CVE-2026-6471) is a 12-year-old PostgreSQL flaw that lets low-privileged attackers execute code and take over servers. Cyera researchers found a severe PostgreSQL vulnerability, dubbed PostGREShell and tracked as CVE-2026-6471

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 89.1%
CVE-2026-9586 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Sangoma Switchvox Vulnerabilities Exploited in the Wild

Tracked as CVE-2026-9586, the unauthenticated SQL injection flaw can be exploited remotely for arbitrary code execution. The post Sangoma Switchvox Vulnerabilities Exploited in the Wild appeared first on SecurityWeek. Weiterlesen

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 2.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

[NEU] [niedrig] Checkmk: Schwachstelle ermöglicht Denial of Service

Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Checkmk Agent Receiver ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.5%
CVE-2026-18167 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

Multiple TP-Link Archer Vulnerabilities Allow Attackers to Execute Remote Code

TP-Link has disclosed two security vulnerabilities in its Archer AX55 v4 router that could let attackers on the local network crash a service, steal administrator credentials, and potentially execute remote code on affected devices. The fla

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.5%
CVE-2026-18167 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

Multiple TP-Link Archer Vulnerabilities Allow Attackers to Execute Remote Code

TP-Link has disclosed two security vulnerabilities in its Archer AX55 v4 router that could let attackers on the local network crash a service, steal administrator credentials, and potentially execute remote code on affected devices. The fla

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 2.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

[NEU] [UNGEPATCHT] [mittel] xpdf: Schwachstelle ermöglicht Denial of Service

Ein entfernter, anonymer Angreifer kann eine Schwachstelle in xpdf ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

[NEU] [mittel] Dell integrated Dell Remote Access Controller: Schwachstelle ermöglicht Codeausführung

Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Dell integrated Dell Remote Access Controller ausnutzen, um beliebigen Programmcode auszuführen. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

[NEU] [mittel] Ollama: Schwachstelle ermöglicht Offenlegung von Informationen

Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Ollama ausnutzen, um Informationen offenzulegen. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Linux

[NEU] [hoch] util-linux: Schwachstelle ermöglicht Privilegieneskalation

Ein lokaler Angreifer kann eine Schwachstelle in util-linux ausnutzen, um seine Privilegien zu erhöhen. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 28.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

[NEU] [hoch] GeoNetwork: Schwachstelle ermöglicht Manipulation von Dateien

Ein entfernter, anonymer Angreifer kann eine Schwachstelle in GeoNetwork ausnutzen, um Dateien zu manipulieren. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

[NEU] [UNGEPATCHT] [mittel] bluez: Schwachstelle ermöglicht Codeausführung

Ein Angreifer in Bluetooth-Reichweite kann eine Schwachstelle in bluez ausnutzen, um beliebigen Programmcode auszuführen. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 82.8%
CVE-2026-85046 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

Google patches actively exploited Chrome zero-day (CVE-2026-85046)

Google has patched 12 vulnerabilities affecting its popular Chrome browser, among them CVE-2026-85046, which has been exploited in the wild. “Google is aware that an exploit for CVE-2026-85046 exists in the wild,” the company said in a Thur

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 18.4%
CVE-2026-6471 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover

Dubbed PostGREShell, CVE-2026-6471 turns low-level replication access into code execution, permanent superuser privileges and a persistent database backdoor. The post 12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover ap

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 2.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

[UPDATE] [hoch] Dell BSAFE: Schwachstelle ermöglicht Denial of Service

Ein Angreifer kann eine Schwachstelle in Dell BSAFE ausnutzen, um einen Denial of Service zu verursachen Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

Google Patches 6th Chrome Zero-Day of 2026

Google’s Chrome 152 security update resolves 12 vulnerabilities, including a high-severity type confusion flaw in the V8 engine. The post Google Patches 6th Chrome Zero-Day of 2026 appeared first on SecurityWeek. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.5 CRITICAL
EPSS 55.5%
CVE-2026-14894 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

WordPress: Super Forms und Elementor Pro von RCE-Angriffen betroffen

LONDON (IT BOLTWISE) – Angreifer nutzen zwei kritische Lücken in WordPress-Plugins, um ohne Anmeldung Dateien mit PHP-Inhalt hochzuladen und anschließend Remote Code Execution auszuführen. Laut Wordfence wurden bereits über 250.000 bzw. 190

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
5.8 MEDIUM
EPSS 2.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Linux

[UPDATE] [mittel] Red Hat Enterprise Linux (iperf3): Schwachstelle ermöglicht Denial of Service

Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

Google fixes actively exploited Chrome V8 zero-day vulnerability

Google has released a Chrome security update addressing 12 vulnerabilities, including a high-severity V8 flaw that is being actively exploited in attacks. The fixes are included in Chrome 152.0.7977.82/.83 for Windows and macOS and version

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
9.8 CRITICAL
⚠️ KEV
EPSS 82.8%
CVE-2026-85046 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

Google fixes the sixth actively exploited Chrome zero-day of 2026

Google patched 12 Chrome flaws, including an actively exploited V8 zero-day that could enable remote code execution through a crafted webpage. Google released a Chrome security update fixing 12 vulnerabilities, including CVE-2026-85046 (CVS

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 82.8%
CVE-2026-85046 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

Google fixes the sixth actively exploited Chrome zero-day of 2026

Google patched 12 Chrome flaws, including an actively exploited V8 zero-day that could enable remote code execution through a crafted webpage. Google released a Chrome security update fixing 12 vulnerabilities, including CVE-2026-85046 (CVS

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.0 HIGH
⚠️ KEV
EPSS 82.8%
CVE-2026-85046 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

Chrome-Update schließt V8-Zero-Day: CVE-2026-85046 aktiv ausgenutzt

LONDON (IT BOLTWISE) – Google hat ein Chrome-Update veröffentlicht, das zwölf Sicherheitslücken schließt. Im Fokus steht CVE-2026-85046, eine V8-Type-Confusion-Fehlerspur (CVSS: 8,8), die nach Angaben der Beschreibung bereits aktiv in freie

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 31.8%
CVE-2026-83548 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers’ crosshairs. The vulnerabilities are as follows – C

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.8%
CVE-2026-12554 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

HP Easy Start for macOS: CVE-2026-12554 / CVE-2026-12555 / CVE-2026-12556

Posted by Nir Yehoshua on Sep 03Hello Full Disclosure list, Cipher Security Labs has published technical details for three High-severity vulnerabilities affecting HP Easy Start for macOS. The issues were coordinated with HP and are addresse

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 95.8%
CVE-2026-83548 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Attackers exploit zero-days in consistently besieged SonicWall product

SonicWall customers are grappling with yet another pair of actively exploited zero-day vulnerabilities in SonicWall SMA 1000 appliances, a product that’s been besieged with recurring defects and attacks over the past nine months.  The vendo

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.5 CRITICAL
EPSS 62.5%
CVE-2026-20212 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Cisco

Cisco Fixed Critical RCE in Nexus 9000 Series Switches

Cisco patched a critical Nexus 9000 vulnerability, CVE-2026-20212, allowing unauthenticated remote root code execution. Cisco has released patches for a critical flaw, tracked as tracked as CVE-2026-20212 (CVSS score of 9.8) in 10 Silicon O

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Management-Interface vom Internet trennen und ACLs auf vertrauenswürdige IPs beschränken.
9.5 CRITICAL
EPSS 62.5%
CVE-2026-20212 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Cisco

Cisco Fixed Critical RCE in Nexus 9000 Series Switches

Cisco patched a critical Nexus 9000 vulnerability, CVE-2026-20212, allowing unauthenticated remote root code execution. Cisco has released patches for a critical flaw, tracked as tracked as CVE-2026-20212 (CVSS score of 9.8) in 10 Silicon O

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Management-Interface vom Internet trennen und ACLs auf vertrauenswürdige IPs beschränken.
7.5 HIGH
EPSS 28.5%
CVE-2026-62911 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

Serious vulnerability threatens tens of thousands of Exchange servers

A serious vulnerability was recently discovered in Exchange Server 2016, Exchange Server 2016, and Exchange Server Subscription Edition (SE). The vulnerability is designated CVE-2026-62911 and can be exploited by hackers to gain full access

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 20.5%
CVE-2026-20212 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

Cisco warnt vor kritischer Nexus-9000-Schwachstelle und liefert IOS-XR-Hardening

LONDON (IT BOLTWISE) – Cisco schließt eine kritische Schwachstelle in Nexus 9000 mit der CVE-2026-20212, die unauthentifizierten Angreifern die Ausführung von Code mit Root-Rechten ermöglichen kann. Betroffen sind unter anderem bestimmte Ne

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.4%
CVE-2026-77847 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Tycon Systems TPDIN-Monitor-WEB3

View CSAF Summary Successful exploitation of these vulnerabilities could allow for an attacker to perform a man-in-the-middle (MitM) attack, cause a factory reset, wipe credentials, or retrieve sensitive information. The following versions

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29%
CVE-2025-10478 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Rockwell Automation 1756-ENBT Module

View CSAF Summary Successful exploitation of this vulnerability could crash the module. The device requires a restart to recover. The following versions of Rockwell Automation 1756-ENBT Module are affected: 1756-ENBT module vers:all/* (CVE-

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.3%
CVE-2026-77477 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

OPCFoundation OPC UA LocalDiscoveryServer (LDS)

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to take control of a high-privilege terminal during installation and run arbitrary commands. The following versions of OPCFoundation OPC UA LocalDiscove

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.5 CRITICAL
EPSS 62%
CVE-2026-75925 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

IXON VPN Client

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to perform remote code execution on the computer running the client with elevated privileges. The following versions of IXON VPN Client are affected: VP

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.3%
CVE-2026-12663 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Rockwell Automation ControlFLASH

View CSAF Summary Successful exploitation of this vulnerability could give an attacker the ability to run any commands or code of the attacker&#039;s choice on a target machine at the logged-in user&#039;s permission level. The following ve

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.