🎯 CVE-2026-87776 HIGH 7.5 🔥 EPSS 24.1%
📄 .md Alle CVEs anzeigen ✕

CVE-2026-87776: Schwachstellen-Eintrag (NVD)

compression is a Node.js and Express compression middleware. In versions before 1.8.2, when a client aborts the connection while a compressed response is still being sent, the zlib stream created to compress that response is never destroyed, so each aborted compressed response leaks its native zlib memory. A remote unauthenticated attacker can repeatedly open requests and disconnect early, exhausting the available memory and crashing the server. All applications using compression are affected. The issue is fixed in compression 1.8.2, and users should upgrade to 1.8.2 or later.

Improper Control of Generation of Code ('Code Injection') 🎯 Medium

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

🛡️ Empfohlene Mitigation: Refactor your program so that you do not have to dynamically generate code.
Vollständige Definition bei MITRE ➔
🩹 Patch verfügbar (OSV):
🩹 0f9707417bd53d41a319fce8bdb80dfa08b435c8 (Commit)
📰 Eigene Berichterstattung: ➔ CVE-2026-87776 | compression up to 1.8.1 resource consumption (Nessus ID 344814)
📚 Referenzen & Quellen:
Ausnutzungs-Zeitleiste:
CVSS-Vektor-Analyse: 7.5
AV · Angriffsvektor Netzwerk
AC · Komplexität Gering
PR · Privilegien Keine
UI · Interaktion Keine
S · Scope Unverändert
C · Vertraulichkeit Keine
I · Integrität Keine
A · Verfügbarkeit Hoch
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Veröffentlicht:11.09.2026
Aktualisiert:11.09.2026 14:17
Assigner (CNA):NVD
Quellen: 🇪🇺 EUVD-Datenbank (ENISA) + 🇺🇸 NVD-Anreicherung · 24-h-Cache
CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

354k+ 🇪🇺 EUVD-Datenbank
8 🔴 Critical im Radar
7 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
0 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-09: 164 2025-10: 316 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 418 2026-03: 652 2026-04: 574 2026-05: 683 2026-06: 942 2026-07: 1333 2026-08: 1329 7.525 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-08-292026-09-12
≥90 %40
≥50 %40
≥10 %30
<10 %304300
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Generic Security 46
Linux 8
Microsoft 3
Fortinet 1
Google 1
Cisco 1
Schweregrad & Status:
Hersteller (Datenbank-weit, 90.597 Einträge):
Quelle:
🔍
7.5 HIGH
EPSS 28.2%
CVE-2026-73289 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73289 | RustFS up to 1.0.0-beta.11 Condition string.rs eval_like privileges management

A vulnerability classified as critical was found in RustFS up to 1.0.0-beta.11. This impacts the function eval_like of the file crates/policy/src/policy/function/string.rs of the component Condition. The manipulation results in improper pri

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.4%
CVE-2026-73288 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73288 | RustFS up to 1.0.0-beta.12 Object Lock objectlock_sys.rs check_object_lock_for_deletion privileges management

A vulnerability classified as problematic has been found in RustFS. This affects the function check_object_lock_for_deletion of the file crates/ecstore/src/bucket/object_lock/objectlock_sys.rs of the component Object Lock. The manipulation

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20%
CVE-2026-73263 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73263 | Prowler-Cloud Prowler up to 5.35.x Kubernetes Provider kubernetes_provider.py config.load_kube_config_from_dict deserialization

A vulnerability was found in Prowler-Cloud Prowler up to 5.35.x and classified as critical. Affected is the function config.load_kube_config_from_dict of the file prowler/providers/kubernetes/kubernetes_provider.py of the component Kubernet

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.5%
CVE-2026-73287 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73287 | RustFS up to 1.0.0-beta.11 FtpsDriver driver.rs FtpsDriver::mkd improper authorization

A vulnerability described as problematic has been identified in RustFS up to 1.0.0-beta.11. The impacted element is the function FtpsDriver::mkd of the file crates/protocols/src/ftps/driver.rs of the component FtpsDriver. Executing a manipu

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.7%
CVE-2026-73285 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73285 | RustFS up to 1.0.0-beta.12 IAM crates/iam/src/sys.rs maybe_merge_object_tag_conditions improper authorization

A vulnerability marked as critical has been reported in RustFS. The affected element is the function maybe_merge_object_tag_conditions of the file crates/iam/src/sys.rs of the component IAM. Performing a manipulation results in improper aut

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.9%
CVE-2026-73286 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73286 | RustFS up to 1.0.0-beta.11 Condition Keys get_condition_values access control

A vulnerability labeled as critical has been found in RustFS up to 1.0.0-beta.11. Impacted is the function get_condition_values of the component Condition Keys. Such manipulation leads to improper access controls. This vulnerability is uniq

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.3%
CVE-2026-73284 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Generic Security

CVE-2026-73284 | RustFS up to 1.0.0-beta.10 Service Account service_account.rs AddServiceAccount target_user privileges management

A vulnerability categorized as critical has been discovered in RustFS up to 1.0.0-beta.10. This vulnerability affects the function AddServiceAccount of the file rustfs/src/admin/handlers/service_account.rs of the component Service Account.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.9%
CVE-2026-73264 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73264 | prowler-cloud Prowler up to 5.33.0 Lighthouse Providers lighthouse_providers.py base_url improper authorization

A vulnerability identified as problematic has been detected in prowler-cloud Prowler up to 5.33.0. This issue affects some unknown processing of the file api/src/backend/tasks/jobs/lighthouse_providers.py of the component Lighthouse Provide

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.7%
CVE-2026-73290 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73290 | RustFS up to 1.0.0-beta.11 Policy Evaluation access.rs access control

A vulnerability was found in RustFS up to 1.0.0-beta.11. It has been classified as problematic. Affected by this vulnerability is an unknown functionality of the file rustfs/src/storage/access.rs of the component Policy Evaluation. Performi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.9%
CVE-2026-73265 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73265 | RustFS up to 1.0.0-beta.10 GetObject/CopyObject/UploadPartCopy improper authorization

A vulnerability was found in RustFS up to 1.0.0-beta.10. It has been declared as problematic. Affected by this issue is the function GetObject/CopyObject/UploadPartCopy. Executing a manipulation can lead to improper authorization. This vuln

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.1%
CVE-2026-90558 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90558 | irontec sngrep up to 1.8.4 stack-based overflow (EUVD-2026-76903 / Nessus ID 345447)

A vulnerability classified as critical has been found in irontec sngrep up to 1.8.4. Affected is an unknown function. This manipulation causes stack-based buffer overflow. This vulnerability is handled as CVE-2026-90558. The attack can be i

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.8%
CVE-2026-90557 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90557 | Freeciv up to 3.2.5 Savegame sg_load_player_unit out-of-bounds (EUVD-2026-76902 / Nessus ID 345448)

A vulnerability described as problematic has been identified in Freeciv up to 3.2.5. This impacts the function sg_load_player_unit of the component Savegame. The manipulation results in out-of-bounds read. This vulnerability is known as CVE

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24%
CVE-2026-90556 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90556 | Freeciv up to 3.2.5 Worklist worklist_load heap-based overflow (EUVD-2026-76901 / Nessus ID 345451)

A vulnerability marked as problematic has been reported in Freeciv up to 3.2.5. This affects the function worklist_load of the component Worklist. The manipulation leads to heap-based buffer overflow. This vulnerability is traded as CVE-202

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.3%
CVE-2026-90559 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90559 | Xerial snappy-java up to 1.1.10.8 Snappy.uncompress out-of-bounds write (EUVD-2026-76904)

A vulnerability classified as problematic was found in Xerial snappy-java up to 1.1.10.8. Affected by this vulnerability is the function Snappy.uncompress. Such manipulation leads to out-of-bounds write. This vulnerability is uniquely ident

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.6%
CVE-2026-90560 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90560 | luben zstd-jni up to 1.5.7-13 Dictionary Decompression ZstdDictDecompress constructor offset/length out-of-bounds (EUVD-2026-76905 / Nessus ID 345449)

A vulnerability, which was classified as critical, has been found in luben zstd-jni up to 1.5.7-13. Affected by this issue is the function ZstdDictDecompress constructor of the component Dictionary Decompression. Performing a manipulation o

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.7%
CVE-2026-90616 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90616 | Flatpak up to 1.18.0 Sandbox Directory Binding link following (EUVD-2026-76911)

A vulnerability classified as problematic was found in Flatpak up to 1.18.0. The affected element is an unknown function of the component Sandbox Directory Binding. The manipulation results in link following. This vulnerability is known as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.8%
CVE-2026-90485 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90485 | IOBit Uninstaller 15.5.0.11 IOCTL Dispatch IURegistryFilter.sys sub_11838 null pointer dereference (EUVD-2026-76913)

A vulnerability has been found in IOBit Uninstaller 15.5.0.11 and classified as problematic. Affected by this issue is the function sub_11838 of the file IURegistryFilter.sys of the component IOCTL Dispatch Handler. This manipulation causes

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.1%
CVE-2026-79300 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-79300 | SEP sesam prior 5.2.0.24 improper authorization (EUVD-2026-76915)

A vulnerability was found in SEP sesam. It has been declared as problematic. Affected by this issue is some unknown functionality. The manipulation results in improper authorization. This vulnerability is identified as CVE-2026-79300. The a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.9%
CVE-2026-90494 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90494 | restify node-restify up to 12.0.0 /lib/plugins/static.js serveStatic path traversal (EUVD-2026-76941)

A vulnerability was found in restify node-restify up to 12.0.0. It has been rated as problematic. This affects the function serveStatic in the library /lib/plugins/static.js. This manipulation causes path traversal. This vulnerability is ha

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 23.4%
CVE-2026-90678 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90678 | HAProxy up to 3.3.14/3.4.4/3.5-dev5 HTTP/3 Multiplexer request smuggling (EUVD-2026-76943)

A vulnerability labeled as problematic has been found in HAProxy up to 3.3.14/3.4.4/3.5-dev5. Impacted is an unknown function of the component HTTP/3 Multiplexer. Executing a manipulation can lead to http request smuggling. This vulnerabili

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 32.1%
CVE-2026-90495 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-90495 | Fengoffice Feng Office up to 3.11.13.11 Legacy API CompanyWebsite.class.php instance-&gt;findAll auth sql injection (EUVD-2026-76942)

A vulnerability categorized as critical has been discovered in Fengoffice Feng Office up to 3.11.13.11. This impacts the function Contacts::instance-&amp;gt;findAll of the file application/models/CompanyWebsite.class.php of the component Le

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 19.6%
CVE-2026-90679 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90679 | Forgejo up to 16.0.4 ActivityPub reqsignature.go signature verification (EUVD-2026-76944)

A vulnerability marked as problematic has been reported in Forgejo up to 16.0.4. The affected element is an unknown function of the file routers/api/v1/activitypub/reqsignature.go of the component ActivityPub. The manipulation leads to impr

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32%
CVE-2025-25252 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Fortinet

CVE-2025-25252 | Fortinet FortiOS up to 7.6.2 SSL VPN session expiration (FG-IR-24-487 / EUVD-2025-34237)

A vulnerability was found in Fortinet FortiOS up to 6.4.16/7.0.16/7.2.10/7.4.6/7.6.2. It has been rated as problematic. This impacts an unknown function of the component SSL VPN. Performing a manipulation results in session expiration. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.3%
CVE-2026-68488 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Linux

Plesk Backup Manager Flaw Lets Low-Privileged Users Gain Root Access to Servers

A newly disclosed vulnerability in Plesk Backup Manager could allow low-privileged users to escalate privileges and gain full root access on affected Linux servers. Tracked as CVE-2026-68488, the flaw stems from a symlink race condition dur

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 19.1%
CVE-2022-43713 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-43713 | GX XperienCentral up to 10.35.0 Interactive Forms input validation (EUVD-2022-46695)

A vulnerability labeled as critical has been found in GX XperienCentral up to 10.35.0. This affects an unknown part of the component Interactive Forms. Such manipulation leads to improper input validation. This vulnerability is referenced a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.4%
CVE-2022-43722 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-43722 | Siemens SICAM PAS/SICAM PQS up to 6.x uncontrolled search path (ssa-849072 / EUVD-2022-46699)

A vulnerability classified as very critical was found in Siemens SICAM PAS and SICAM PQS up to 6.x. Affected is an unknown function. The manipulation results in uncontrolled search path. This vulnerability is cataloged as CVE-2022-43722. Th

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.1%
CVE-2022-43711 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-43711 | GX XperienCentral up to 10.33.0 Interactive Forms eval cross site scripting (EUVD-2022-46693)

A vulnerability marked as problematic has been reported in GX XperienCentral up to 10.33.0. This vulnerability affects the function eval of the component Interactive Forms. Performing a manipulation results in cross site scripting. This vul

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.7%
CVE-2022-43712 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-43712 | GX XperienCentral up to 10.36.0 POST Request /web/mvc access control (EUVD-2022-46694)

A vulnerability, which was classified as critical, has been found in GX XperienCentral up to 10.36.0. This issue affects some unknown processing of the file /web/mvc of the component POST Request Handler. The manipulation leads to improper

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.1%
CVE-2022-43710 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-43710 | GX XperienCentral up to 10.33.0 Interactive Forms cross-site request forgery (EUVD-2022-46692)

A vulnerability identified as problematic has been detected in GX XperienCentral up to 10.33.0. Affected by this issue is some unknown functionality of the component Interactive Forms. This manipulation causes cross-site request forgery. Th

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 32.6%
CVE-2022-43709 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-43709 | MyBB 1.8.31 Users sql injection (GHSA-ggp5-454p-867v / EUVD-2022-46691)

A vulnerability described as critical has been identified in MyBB 1.8.31. This affects an unknown part of the component Users Module. The manipulation results in sql injection. This vulnerability was named CVE-2022-43709. The attack may be

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.3%
CVE-2026-68488 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Linux

Plesk Backup Manager Flaw Lets Low-Privileged Users Gain Root Access to Servers

A newly disclosed vulnerability in Plesk Backup Manager could allow low-privileged users to escalate privileges and gain full root access on affected Linux servers. Tracked as CVE-2026-68488, the flaw stems from a symlink race condition dur

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 25.3%
CVE-2026-68488 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Linux

Plesk Backup Manager Flaw Lets Low-Privileged Users Gain Root Access to Servers

A newly disclosed vulnerability in Plesk Backup Manager could allow low-privileged users to escalate privileges and gain full root access on affected Linux servers. Tracked as CVE-2026-68488, the flaw stems from a symlink race condition dur

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 24.7%
CVE-2026-89696 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89696 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 nfsd nfsd4_putfh null pointer dereference (Nessus ID 345430)

A vulnerability was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3 and classified as critical. This affects the function nfsd4_putfh of the component nfsd. Such manipulation leads to null pointer dereference. This vulnerability is liste

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 20.8%
CVE-2026-80996 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-80996 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 L2TP exceptional condition (Nessus ID 345431)

A vulnerability classified as problematic was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. This affects an unknown function of the component L2TP. The manipulation results in handling of exceptional conditions. This vulnerability is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
5.8 MEDIUM
EPSS 6.1%
CVE-2026-89481 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89481 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 nvme-tcp nvme_tcp_handle_r2t information disclosure (Nessus ID 345433)

A vulnerability, which was classified as problematic, was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. Affected by this issue is the function nvme_tcp_handle_r2t of the component nvme-tcp. The manipulation results in information disc

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 28.1%
CVE-2026-89739 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89739 | Linux Kernel up to 6.18.49/7.2.3 dwc3 dwc3_gadget_free_endpoints use after free (Nessus ID 345432)

A vulnerability identified as very critical has been detected in Linux Kernel up to 6.18.49/7.2.3. Affected by this issue is the function dwc3_gadget_free_endpoints of the component dwc3. Performing a manipulation results in use after free.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 21.1%
CVE-2026-89584 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-89584 | Linux Kernel up to 7.2.3 block stack-based overflow (Nessus ID 345434)

A vulnerability was found in Linux Kernel up to 7.2.3. It has been declared as very critical. This issue affects some unknown processing of the component block. Such manipulation leads to stack-based buffer overflow. This vulnerability is l

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 24.8%
CVE-2026-90473 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90473 | msgpack msgpack-java up to 0.9.12 MessageUnpacker MessageUnpacker.skipValue integer overflow (Nessus ID 345452)

A vulnerability was found in msgpack msgpack-java up to 0.9.12. It has been classified as problematic. This issue affects the function MessageUnpacker.skipValue of the component MessageUnpacker. The manipulation leads to integer overflow. T

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.4%
CVE-2026-90472 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90472 | msgpack msgpack-java up to 0.9.12 MessageUnpacker.unpackValue stack-based overflow (Nessus ID 345450)

A vulnerability has been found in msgpack msgpack-java up to 0.9.12 and classified as problematic. This affects the function MessageUnpacker.unpackValue. Performing a manipulation results in stack-based buffer overflow. This vulnerability i

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.3%
CVE-2026-51990 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

Sogou Input Method: Chinesische <b>Hacker</b> nutzen CVE-2026-51990 - Börse Express

UNC3569 nutzte CVE-2026-51990 gegen Sogou-Nutzer. Tencent schloss die kritische Lücke im April mit Version 16.3.0.3498. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 89.1%
CVE-2026-42016 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following rep

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.1%
CVE-2026-82079 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Nintendo Switch Security Flaw Lets Nearby Attackers Exploit QR Codes Used to Share Screenshots

  Nintendo has issued an urgent security advisory for owners of the original Switch console, warning of a flaw that could allow an attacker in close physical proximity to run unauthorized code on the device or pull data stored on it, simply

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.2%
CVE-2026-56711 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Multiple VLC Media Player Vulnerabilities Allow Attackers to Corrupt or Read Heap Memory

Two security vulnerabilities in VLC Media Player could allow attackers to corrupt heap memory or disclose sensitive data from a victim’s memory. The flaws, tracked as CVE-2026-56711 and CVE-2026-73324, affect VLC Media Player versions 3.0.0

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.2%
CVE-2026-56711 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Multiple VLC Media Player Vulnerabilities Allow Attackers to Corrupt or Read Heap Memory

Two security vulnerabilities in VLC Media Player could allow attackers to corrupt heap memory or disclose sensitive data from a victim’s memory. The flaws, tracked as CVE-2026-56711 and CVE-2026-73324, affect VLC Media Player versions 3.0.0

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.2%
CVE-2026-56711 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Multiple VLC Media Player Vulnerabilities Allow Attackers to Corrupt or Read Heap Memory

Two security vulnerabilities in VLC Media Player could allow attackers to corrupt heap memory or disclose sensitive data from a victim’s memory. The flaws, tracked as CVE-2026-56711 and CVE-2026-73324, affect VLC Media Player versions 3.0.0

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 💻 Lokal 🔓 Keine Authentifizierung nötig
Microsoft

China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks

China-linked threat actors UTA0560 and JungleBamboo chained a Google Chrome zero-day with a Windows kernel privilege-escalation flaw in phishing campaigns targeting NGOs and other victims. Volexity documented the operations, detected on Sep

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 💻 Lokal 🔓 Keine Authentifizierung nötig
Microsoft

China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks

China-linked threat actors UTA0560 and JungleBamboo chained a Google Chrome zero-day with a Windows kernel privilege-escalation flaw in phishing campaigns targeting NGOs and other victims. Volexity documented the operations, detected on Sep

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 32.1%
CVE-2026-85706 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CISA Warns of Critical GitLab Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab flaw, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog after confirming it was exploited in attacks. The issue affects bot

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.1%
CVE-2026-85706 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CISA Warns of Critical GitLab Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab flaw, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog after confirming it was exploited in attacks. The issue affects bot

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 96.1%
CVE-2026-85706 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CISA Warns of Critical GitLab Path Traversal Flaw Exploited to Read Arbitrary Server Files

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab path traversal vulnerability, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog after evidence that the flaw is being activ

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.1%
CVE-2026-85706 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CISA Warns of GitLab Path Traversal Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab vulnerability, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog, warning that attackers are actively exploiting the flaw.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.1%
CVE-2026-85706 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CISA Warns of GitLab Path Traversal Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab vulnerability, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog, warning that attackers are actively exploiting the flaw.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 25.9%
CVE-2026-20079 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Cisco

Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

Ravie LakshmananSep 11, 2026Vulnerability / Malware Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC)

CWE-287: Improper Authentication ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Management-Interface vom Internet trennen und ACLs auf vertrauenswürdige IPs beschränken.
10.0 CRITICAL
EPSS 79.1%
CVE-2026-85706 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

GitLab schließt CVE-2026-85706 mit CVSS 10, aktive In-the-Wild-Probes

LONDON (IT BOLTWISE) – GitLab hat mehrere Sicherheitslücken gepatcht, darunter eine Schwachstelle mit CVSS 10,0 (CVE-2026-85706), die bereits innerhalb von Stunden nach der Veröffentlichung von Angreifern abgefragt wurde. Betroffen sind bes

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.2%
CVE-2026-56711 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC Media Player could enable attackers to corrupt memory or extract sensitive data from affected systems by persuading users to open a specially crafted image file or media playlist. The flaws, tracked as CV

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 90.3%
CVE-2026-86060 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CISA Warns MikroTik RouterOS Flaw Is Exploited to Escalate Privileges

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical MikroTik RouterOS privilege-escalation vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, warning that the flaw is being actively exploit

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.2%
CVE-2026-56711 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0 through 3.0.23 could allow attackers to exploit heap memory issues. These vulnerabilities can be triggered by processing a malicious PNG file or connecting to attacker-controll

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.2%
CVE-2026-56711 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0 through 3.0.23 could allow attackers to exploit heap memory issues. These vulnerabilities can be triggered by processing a malicious PNG file or connecting to attacker-controll

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 89.7%
CVE-2026-67277 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, warning that these flaws are actively being exploited in the wild. On

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 89.7%
CVE-2026-67277 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, warning that these flaws are actively being exploited in the wild. On

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.