🎯 CVE-2026-89059
📄 .md Alle CVEs anzeigen ✕

CVE-2026-89059: Schwachstellen-Eintrag (NVD)

A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count. A remote, unauthenticated attacker can send a small crafted image declaring enormous dimensions to trigger a very large memory allocation, exhausting the JVM heap and resulting in a denial of service.

Improper Control of Generation of Code ('Code Injection') 🎯 Medium

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

🛡️ Empfohlene Mitigation: Refactor your program so that you do not have to dynamically generate code.
Vollständige Definition bei MITRE ➔
📰 Eigene Berichterstattung: ➔ CVE-2026-89059 | Red Hat RESTEasy IIOImageProvider resource consumption (EUVD-20
📚 Referenzen & Quellen:
Ausnutzungs-Zeitleiste:
CVSS-Vektor-Analyse: 7.5
AV · Angriffsvektor Netzwerk
AC · Komplexität Gering
PR · Privilegien Keine
UI · Interaktion Keine
S · Scope Unverändert
C · Vertraulichkeit Keine
I · Integrität Keine
A · Verfügbarkeit Hoch
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Veröffentlicht:18.09.2026
Aktualisiert:18.09.2026 13:18
Assigner (CNA):NVD
Quellen: 🇪🇺 EUVD-Datenbank (ENISA) + 🇺🇸 NVD-Anreicherung · 24-h-Cache
CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

366k+ 🇪🇺 EUVD-Datenbank
0 🔴 Critical im Radar
0 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
0 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-09: 94 2025-10: 317 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 417 2026-03: 649 2026-04: 574 2026-05: 683 2026-06: 941 2026-07: 1327 2026-08: 1828 2026-09: 913 8.857 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-08-302026-09-18
≥90 %00
≥50 %00
≥10 %00
<10 %300300
📈 EPSS-Riser (7 Tage) CVE-2022-2900 ↑ 0.2 %
Frühindikator · FIRST.org
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Schweregrad & Status:
Hersteller (Datenbank-weit, 96.170 Einträge):
Quelle:
🔍
EPSS 27.5%
CVE-2026-65348 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-65348 | Apple iOS/iPadOS/macOS prior 26.7/27/15.8 permission

A vulnerability labeled as critical has been found in Apple iOS, iPadOS and macOS. This affects an unknown function. Executing a manipulation can lead to permission issues. This vulnerability is registered as CVE-2026-65348. The attack need

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 29.1%
CVE-2026-65354 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-65354 | Apple iOS/iPadOS/macOS up to 26 sandbox

A vulnerability described as very critical has been identified in Apple iOS, iPadOS and macOS up to 26. Affected is an unknown function. The manipulation results in sandbox issue. This vulnerability is reported as CVE-2026-65354. The attack

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 20%
CVE-2026-43785 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-43785 | Apple iOS/iPadOS/macOS/tvOS/visionOS prior 27 privileges management

A vulnerability was found in Apple iOS, iPadOS, macOS, tvOS and visionOS and classified as critical. The impacted element is an unknown function. The manipulation results in improper privilege management. This vulnerability is identified as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 32.4%
CVE-2026-43790 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-43790 | Apple macOS up to 15.7/26/26.6 Kernel memory corruption

A vulnerability categorized as very critical has been discovered in Apple macOS up to 15.7/26/26.6. Affected by this vulnerability is an unknown functionality of the component Kernel. Executing a manipulation can lead to memory corruption.

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 26.2%
CVE-2026-65345 💻 Lokal 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-65345 | Apple iOS/iPadOS/macOS prior 26.7/27/15.8 permission

A vulnerability identified as problematic has been detected in Apple iOS, iPadOS and macOS. The impacted element is an unknown function. Performing a manipulation results in permission issues. This vulnerability is cataloged as CVE-2026-653

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 25.2%
CVE-2026-65344 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-65344 | Apple iOS/iPadOS/macOS/tvOS/visionOS prior 26.7/27/15.8 out-of-bounds write

A vulnerability categorized as very critical has been discovered in Apple iOS, iPadOS, macOS, tvOS and visionOS. The affected element is an unknown function. Such manipulation leads to out-of-bounds write. This vulnerability is listed as CV

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 32.9%
CVE-2026-65342 💻 Lokal 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-65342 | Apple macOS up to 15.7/26/26.6 permission

A vulnerability was found in Apple macOS up to 15.7/26/26.6. It has been rated as problematic. Impacted is an unknown function. This manipulation causes permission issues. This vulnerability is tracked as CVE-2026-65342. The attack is restr

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 2.6%
CVE-2026-43791 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-43791 | Apple macOS up to 15.7/26/26.6 information disclosure

A vulnerability was found in Apple macOS up to 15.7/26/26.6. It has been declared as problematic. Affected by this issue is some unknown functionality. Executing a manipulation can lead to information disclosure. This vulnerability is track

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 27%
CVE-2026-43808 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-43808 | Apple iPadOS/iOS/macOS/tvOS/watchOS up to 26.5 use after free

A vulnerability was found in Apple iPadOS, iOS, macOS, tvOS and watchOS up to 26.5. It has been rated as very critical. This affects an unknown part. The manipulation leads to use after free. This vulnerability is listed as CVE-2026-43808.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 6%
CVE-2026-43787 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-43787 | Apple macOS up to 15.7/26/26.6 information disclosure

A vulnerability classified as problematic was found in Apple macOS up to 15.7/26/26.6. The affected element is an unknown function. Executing a manipulation can lead to information disclosure. This vulnerability is handled as CVE-2026-43787

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 26.9%
CVE-2026-43789 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-43789 | Apple macOS up to 15.7/26/26.6 Sandbox privileges management

A vulnerability was found in Apple macOS up to 15.7/26/26.6. It has been classified as critical. Affected by this vulnerability is an unknown functionality of the component Sandbox. Performing a manipulation results in improper privilege ma

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 31.4%
CVE-2026-43696 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-43696 | Apple macOS up to 26 improper authorization

A vulnerability marked as problematic has been reported in Apple macOS up to 26. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper authorization. This vulnerability is traded as CVE-2026-43696. A

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 28.2%
CVE-2026-43674 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-43674 | Apple iOS/iPadOS up to 26 improper authentication

A vulnerability was found in Apple iOS and iPadOS up to 26. It has been classified as problematic. Affected is an unknown function. This manipulation causes improper authentication. This vulnerability is registered as CVE-2026-43674. The at

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 2.5%
CVE-2026-43762 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-43762 | Apple iOS/iPadOS/macOS/visionOS up to 26.5 information disclosure

A vulnerability was found in Apple iOS, iPadOS, macOS and visionOS up to 26.5. It has been declared as problematic. This impacts an unknown function. Such manipulation leads to information disclosure. This vulnerability is listed as CVE-202

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 32.7%
CVE-2026-43737 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-43737 | Apple iOS/iPadOS/macOS/tvOS/watchOS prior 26.7/27/15.8 improper authorization

A vulnerability, which was classified as problematic, was found in Apple iOS, iPadOS, macOS, tvOS and watchOS. Impacted is an unknown function. Executing a manipulation can lead to improper authorization. The identification of this vulnerab

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 20.7%
CVE-2026-43702 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-43702 | Apple iPadOS/iOS/macOS/tvOS/watchOS Video File memory corruption

A vulnerability, which was classified as very critical, has been found in Apple iPadOS, iOS, macOS, tvOS and watchOS. This issue affects some unknown processing of the component Video File Handler. Performing a manipulation results in memor

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 18.8%
CVE-2026-43719 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-43719 | Apple macOS up to 15.7/26/26.6 SMB use after free

A vulnerability classified as very critical has been found in Apple macOS up to 15.7/26/26.6. This affects an unknown part of the component SMB Handler. This manipulation causes use after free. This vulnerability is handled as CVE-2026-4371

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 19.6%
CVE-2026-43695 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-43695 | Apple iPadOS/iOS/macOS/tvOS/visionOS/watchOS prior prior iOS 27 improper authorization

A vulnerability labeled as problematic has been found in Apple iPadOS, iOS, macOS, tvOS, visionOS and watchOS. Affected is an unknown function. Executing a manipulation can lead to improper authorization. This vulnerability appears as CVE-2

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 22.2%
CVE-2026-43697 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-43697 | Apple macOS up to 15.7/26/26.6 out-of-bounds

A vulnerability was found in Apple macOS up to 15.7/26/26.6. It has been rated as problematic. The impacted element is an unknown function. This manipulation causes out-of-bounds read. This vulnerability is registered as CVE-2026-43697. Rem

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 29.5%
CVE-2026-43690 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-43690 | Apple macOS up to 15.7/26/26.6 race condition

A vulnerability, which was classified as problematic, has been found in Apple macOS up to 15.7/26/26.6. Affected by this issue is some unknown functionality. This manipulation causes race condition. The identification of this vulnerability

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 23.6%
CVE-2026-43688 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-43688 | Apple iOS/iPadOS/macOS up to 26 memory corruption

A vulnerability classified as very critical was found in Apple iOS, iPadOS and macOS up to 26. Affected by this vulnerability is an unknown functionality. The manipulation results in memory corruption. This vulnerability was named CVE-2026-

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 22%
CVE-2026-43683 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-43683 | Apple macOS up to 15.7/26.6/26.x out-of-bounds

A vulnerability marked as problematic has been reported in Apple macOS up to 15.7/26.6/26.x. This affects an unknown function. Performing a manipulation results in out-of-bounds read. This vulnerability is known as CVE-2026-43683. Attacking

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 5.5%
CVE-2026-71641 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-71641 | ZJU-FAST-Lab EGO-Planner-v2 EGOReplanFSM denial of service

A vulnerability was found in ZJU-FAST-Lab EGO-Planner-v2 and classified as problematic. Affected is an unknown function of the component EGOReplanFSM. Such manipulation leads to denial of service. This vulnerability is traded as CVE-2026-71

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 5.3%
CVE-2026-89060 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-89060 | Red Hat Advanced Cluster Management for Kubernetes multicluster-observability-addon information disclosure

A vulnerability, which was classified as problematic, was found in Red Hat Advanced Cluster Management for Kubernetes. Affected by this issue is some unknown functionality of the component multicluster-observability-addon. The manipulation

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 24.3%
CVE-2026-82100 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-82100 | IBM DataStage on Cloud Pak for Data 5.4.0.0 path traversal

A vulnerability was found in IBM DataStage on Cloud Pak for Data 5.4.0.0. It has been classified as problematic. This vulnerability affects unknown code. This manipulation causes path traversal. This vulnerability is registered as CVE-2026-

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 20%
CVE-2026-78135 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-78135 | strongSwan up to 6.0.7 libcharon improper authentication

A vulnerability was found in strongSwan up to 6.0.7. It has been declared as very critical. Affected is an unknown function of the component libcharon. The manipulation results in improper authentication. This vulnerability is cataloged as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 27.5%
CVE-2026-14276 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-14276 | IBM i Access Family up to 1.1.9.15 Emulator Macro RunProgram os command injection

A vulnerability classified as critical was found in IBM i Access Family up to 1.1.9.15. This affects the function RunProgram of the component Emulator Macro. Executing a manipulation can lead to os command injection. The identification of t

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 28.3%
CVE-2026-19542 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-19542 | GNU glibc tdelete memory corruption (WID-SEC-2026-3014)

A vulnerability identified as very critical has been detected in GNU glibc. Impacted is the function tdelete. The manipulation leads to memory corruption. This vulnerability is traded as CVE-2026-19542. It is possible to initiate the attack

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 30.9%
CVE-2026-13285 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-13285 | IBM MQ up to 10.0.0.0 xml external entity reference

A vulnerability was found in IBM MQ up to 10.0.0.0 and classified as critical. Affected by this issue is some unknown functionality. Such manipulation leads to xml external entity reference. This vulnerability is listed as CVE-2026-13285. T

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 27.1%
CVE-2026-18119 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18119 | Concrete CMS up to 9.5.2 Block Design Dialog cross site scripting

A vulnerability classified as problematic was found in Concrete CMS up to 9.5.2. Affected is an unknown function of the component Block Design Dialog. Executing a manipulation can lead to cross site scripting. This vulnerability is tracked

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 19.3%
CVE-2026-28836 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-28836 | Apple macOS up to 14.8.7 privileges management

A vulnerability was found in Apple macOS up to 14.8.7. It has been classified as problematic. The impacted element is an unknown function. The manipulation leads to improper privilege management. This vulnerability is documented as CVE-2026

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 29.3%
CVE-2026-14275 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-14275 | IBM i Access Family up to 1.1.9.15 os command injection

A vulnerability classified as critical has been found in IBM i Access Family up to 1.1.9.15. The impacted element is an unknown function. Performing a manipulation results in os command injection. This vulnerability was named CVE-2026-14275

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 2.1%
CVE-2026-28938 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-28938 | Apple iOS/iPadOS up to 26.5 information disclosure

A vulnerability labeled as problematic has been found in Apple iOS and iPadOS up to 26.5. This issue affects some unknown processing. The manipulation results in information disclosure. This vulnerability is known as CVE-2026-28938. Attacki

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 2.6%
CVE-2026-28937 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-28937 | Apple macOS up to 26 information disclosure

A vulnerability identified as problematic has been detected in Apple macOS up to 26. This vulnerability affects unknown code. The manipulation leads to information disclosure. This vulnerability is traded as CVE-2026-28937. It is possible t

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 20%
CVE-2026-28899 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-28899 | Apple macOS up to 15.7/26/26.5/26.6 Gatekeeper privileges management

A vulnerability, which was classified as very critical, has been found in Apple macOS up to 15.7/26/26.5/26.6. The affected element is an unknown function of the component Gatekeeper. Performing a manipulation results in improper privilege

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 30.1%
CVE-2026-28966 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-28966 | Apple iOS/iPadOS/macOS/tvOS/visionOS prior 26.7/27/15.8 out-of-bounds write

A vulnerability has been found in Apple iOS, iPadOS, macOS, tvOS and visionOS and classified as critical. This affects an unknown function. The manipulation leads to out-of-bounds write. This vulnerability is listed as CVE-2026-28966. The a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 24.8%
CVE-2026-28935 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-28935 | Apple iPadOS/iOS/macOS/tvOS/visionOS/watchOS prior 27 memory corruption

A vulnerability classified as critical has been found in Apple iPadOS, iOS, macOS, tvOS, visionOS and watchOS. This issue affects some unknown processing. This manipulation causes memory corruption. The identification of this vulnerability

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 32%
CVE-2026-28968 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-28968 | Apple iOS/iPadOS/macOS/tvOS/visionOS/watchOS prior 26.7/27 out-of-bounds write

A vulnerability classified as very critical was found in Apple iOS, iPadOS, macOS, tvOS, visionOS and watchOS. Impacted is an unknown function. Such manipulation leads to out-of-bounds write. This vulnerability is referenced as CVE-2026-289

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 32%
CVE-2026-20683 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apple

CVE-2026-20683 | Apple iOS/iPadOS/macOS/visionOS prior 27/15.8/26.7 improper authentication

A vulnerability was found in Apple iOS, iPadOS, macOS and visionOS. It has been declared as critical. This affects an unknown function. The manipulation results in improper authentication. This vulnerability is reported as CVE-2026-20683. T

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 22.5%
CVE-2026-80434 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-80434 | IBM DataStage on Cloud Pak for Data 5.4.0.0 resource injection

A vulnerability identified as critical has been detected in IBM DataStage on Cloud Pak for Data 5.4.0.0. The affected element is an unknown function. Performing a manipulation results in improper control of resource identifiers. This vulner

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 26.1%
CVE-2026-88011 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-88011 | Traefik up to 2.11.55/3.7.11 Header Normalization improper authentication

A vulnerability described as critical has been identified in Traefik up to 2.11.55/3.7.11. This issue affects some unknown processing of the component Header Normalization. The manipulation results in improper authentication. This vulnerabi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 26.9%
CVE-2026-82092 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-82092 | IBM DataStage on Cloud Pak for Data 5.4.0.0 path traversal

A vulnerability was found in IBM DataStage on Cloud Pak for Data 5.4.0.0 and classified as critical. This affects an unknown part. The manipulation results in path traversal. This vulnerability is cataloged as CVE-2026-82092. The attack may

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 27.1%
CVE-2026-81554 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-81554 | IBM DataStage 5.4.0.0 path traversal

A vulnerability, which was classified as very critical, was found in IBM DataStage 5.4.0.0. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to path traversal. This vulnerability is tracked as CV

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 30%
CVE-2026-81551 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-81551 | IBM DataStage on Cloud Pak for Data 5.4.0.0 path traversal

A vulnerability, which was classified as very critical, has been found in IBM DataStage on Cloud Pak for Data 5.4.0.0. Affected is an unknown function. Performing a manipulation results in path traversal. This vulnerability is identified as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 20.1%
CVE-2026-80378 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-80378 | IBM DataStage on Cloud Pak for Data 5.4.0.0 improper authorization

A vulnerability was found in IBM DataStage on Cloud Pak for Data 5.4.0.0 and classified as critical. This issue affects some unknown processing. The manipulation results in improper authorization. This vulnerability is reported as CVE-2026-

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 21.5%
CVE-2026-9327 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-9327 | IBM WebSphere Application Server 8.5/9.0 privileges management (WID-SEC-2026-3255)

A vulnerability, which was classified as critical, was found in IBM WebSphere Application Server 8.5/9.0. The impacted element is an unknown function. The manipulation results in improper privilege management. This vulnerability is reported

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 27%
CVE-2026-52098 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-52098 | FlowiseAI Flowise 3.1.2 /api/v1/prediction code injection

A vulnerability, which was classified as critical, was found in FlowiseAI Flowise 3.1.2. This vulnerability affects unknown code of the file /api/v1/prediction. Such manipulation leads to code injection. This vulnerability is uniquely ident

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 30.3%
CVE-2026-90803 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90803 | GNU Binutils 2.47 ld bfd/elf64-x86-64.c elf_x86_64_relocate_section roff buffer overflow (Bug 34444)

A vulnerability was found in GNU Binutils 2.47. It has been declared as problematic. Affected by this vulnerability is the function elf_x86_64_relocate_section of the file bfd/elf64-x86-64.c of the component ld. Such manipulation of the arg

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 26.8%
CVE-2026-89013 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-89013 | Dolibarr up to 23.0.4 Document Storage Endpoints htdocs/document.php hashp authorization

A vulnerability was found in Dolibarr up to 23.0.4. It has been rated as problematic. This affects an unknown function of the file htdocs/document.php of the component Document Storage Endpoints. Performing a manipulation of the argument ha

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 27.5%
CVE-2026-90802 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90802 | GNU Binutils 2.47 ld bfd/libbfd.c bfd_putl64 null pointer dereference (Bug 34443)

A vulnerability was found in GNU Binutils 2.47. It has been classified as problematic. Affected is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. This manipulation causes null pointer dereference. This vulnerability a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 21.5%
CVE-2026-90801 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-90801 | GNU Binutils 2.47 ld bfd/cache.c cache_bwrite nbytes buffer overflow (Bug 34442)

A vulnerability was found in GNU Binutils 2.47 and classified as problematic. This impacts the function cache_bwrite of the file bfd/cache.c of the component ld. The manipulation of the argument nbytes results in buffer overflow. This vulne

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 27.7%
CVE-2026-81917 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-81917 | Concrete CMS up to 9.5.2 Document Library block cross site scripting

A vulnerability categorized as problematic has been discovered in Concrete CMS up to 9.5.2. This vulnerability affects unknown code of the component Document Library block. Executing a manipulation can lead to cross site scripting. This vul

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 18%
CVE-2026-81918 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-81918 | Concrete CMS up to 9.5.2 Page Attribute Display Block cross site scripting

A vulnerability identified as problematic has been detected in Concrete CMS up to 9.5.2. This issue affects some unknown processing of the component Page Attribute Display Block. The manipulation leads to cross site scripting. This vulnerab

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 21.4%
CVE-2026-81911 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-81911 | Concrete CMS up to 9.5.2 Boards canEditBoardContents collection cross site scripting

A vulnerability marked as problematic has been reported in Concrete CMS up to 9.5.2. This affects the function canEditBoardContents of the component Boards. Performing a manipulation of the argument collection results in cross site scriptin

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 29.3%
CVE-2026-81916 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-81916 | Concrete CMS up to 9.5.2 Express Entry Authorization privileges management

A vulnerability, which was classified as problematic, was found in Concrete CMS up to 9.5.2. Impacted is an unknown function of the component Express Entry Authorization. Such manipulation leads to improper privilege management. This vulner

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
EPSS 22.6%
CVE-2026-74761 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-74761 | Apache ActiveMQ improper authentication

A vulnerability classified as critical was found in Apache ActiveMQ. The impacted element is an unknown function. Executing a manipulation can lead to improper authentication. This vulnerability appears as CVE-2026-74761. The attack may be

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
EPSS 20.4%
CVE-2026-75035 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-75035 | SUSE Rancher up to 2.15.0 Token store privileges management

A vulnerability was found in SUSE Rancher up to 2.15.0. It has been rated as problematic. This affects an unknown function of the component Token store. This manipulation causes improper privilege management. This vulnerability is handled a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
EPSS 18.9%
CVE-2026-67593 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-67593 | Apache ActiveMQ Artemis Openwire Protocol authorization

A vulnerability categorized as critical has been discovered in Apache ActiveMQ Artemis. This affects an unknown part of the component Openwire Protocol. Executing a manipulation can lead to missing authorization. This vulnerability is regis

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
EPSS 23.9%
CVE-2026-57967 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-57967 | Apache ActiveMQ Artemis missing authentication

A vulnerability was found in Apache ActiveMQ Artemis. It has been rated as very critical. Affected by this issue is some unknown functionality. Performing a manipulation results in missing authentication. This vulnerability is cataloged as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
EPSS 19.8%
CVE-2026-87544 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

CVE-2026-87544 | Google Chrome up to 152.0.7977.82 Extensions improper authorization

A vulnerability was found in Google Chrome. It has been classified as critical. This impacts an unknown function of the component Extensions. This manipulation causes improper authorization. This vulnerability is registered as CVE-2026-8754

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.