CVE-2026-89258: Schwachstellen-Eintrag (NVD)
Hugo is a static site generator. In versions after v0.123.0 and before v0.165.0, symlinks in parent directories were not dropped during direct resource lookups, allowing path confinement to be bypassed. An attacker who can place — or who convinces a site author to place — a symlink inside a mounted directory (for example, in a locally vendored theme under themes/) can cause functions that perform direct lookups, such as resources.Get and os.ReadFile, to follow that symlink and read files outside the intended project boundaries, disclosing their contents in the built site. Themes mounted as Go modules fetched from GitHub have symlinks stripped on download and are not affected, and multi-directory walks (e.g. content/asset walking) are not affected. This issue is an incomplete-fix follow-up to GHSA-c3wq-j5vh-68rc and GHSA-fw87-fv5r-9fpw; it is fixed in v0.165.0.
Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-12 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
CVE-2026-89682 | Linux Kernel up to 6.18.50/7.2.3 nfsd nfsd_file_dispose_list_delayed use after free (Nessus ID 345435)
A vulnerability categorized as very critical has been discovered in Linux Kernel up to 6.18.50/7.2.3. This affects the function nfsd_file_dispose_list_delayed of the component nfsd. Such manipulation leads to use after free. This vulnerabil
CVE-2026-89724 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 FWHT encoder vidioc_s_fmt_vid_out out-of-bounds write (Nessus ID 345436)
A vulnerability has been found in Linux Kernel up to 6.12.108/6.18.49/7.2.3 and classified as very critical. This vulnerability affects the function vidioc_s_fmt_vid_out of the component FWHT encoder. This manipulation causes out-of-bounds
CVE-2026-80990 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 Thunderbolt tbnet_connected_work allocation of resources (Nessus ID 345437)
A vulnerability marked as critical has been reported in Linux Kernel up to 6.12.108/6.18.49/7.2.3. This impacts the function tbnet_connected_work of the component Thunderbolt. This manipulation causes allocation of resources. This vulnerabi
CVE-2026-89706 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 nfsd _nfsd_copy_file_range race condition (Nessus ID 345438)
A vulnerability identified as problematic has been detected in Linux Kernel up to 6.12.108/6.18.49/7.2.3. This vulnerability affects the function _nfsd_copy_file_range of the component nfsd. Performing a manipulation results in race conditi
CVE-2026-89508 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 ucma ucma_set_ib_path use after free (Nessus ID 345439)
A vulnerability described as very critical has been identified in Linux Kernel up to 6.12.108/6.18.49/7.2.3. The impacted element is the function ucma_set_ib_path of the component ucma. Executing a manipulation can lead to use after free. T
CVE-2026-89550 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 SUNRPC svcauth_gss_unwrap_priv len divide by zero (Nessus ID 345441)
A vulnerability classified as critical was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. This impacts the function svcauth_gss_unwrap_priv of the component SUNRPC. Such manipulation of the argument len leads to divide by zero. This vu
CVE-2026-89731 | Linux Kernel up to 6.18.50/7.2.3 cxl_ras cxl_rch_get_aer_info out-of-bounds (Nessus ID 345440)
A vulnerability classified as critical has been found in Linux Kernel up to 6.18.50/7.2.3. This affects the function cxl_rch_get_aer_info of the component cxl_ras. The manipulation leads to out-of-bounds read. This vulnerability is traded a
CVE-2026-89668 | Linux Kernel up to 6.18.49/7.2.3 Nfsd Debugfs init_nfsd use after free (Nessus ID 345443)
A vulnerability, which was classified as very critical, has been found in Linux Kernel up to 6.18.49/7.2.3. The affected element is the function init_nfsd of the component Nfsd Debugfs. This manipulation causes use after free. This vulnerab
CVE-2026-89643 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 Audit audit_del_rule use after free (Nessus ID 345442)
A vulnerability was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. It has been rated as very critical. This impacts the function audit_del_rule of the component Audit. The manipulation leads to use after free. This vulnerability is lis
CVE-2026-89560 | Linux Kernel up to 6.18.49/7.2.3 landlock permission (Nessus ID 345444)
A vulnerability was found in Linux Kernel up to 6.18.49/7.2.3. It has been rated as very critical. This vulnerability affects unknown code of the component landlock. The manipulation leads to permission issues. This vulnerability is uniquel
CVE-2026-89511 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 qede qede_fill_frag_skb null pointer dereference (Nessus ID 345445)
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. Affected is the function qede_fill_frag_skb of the component qede. This manipulation causes null pointer dereference. This vulne
CVE-2026-84651 | Jenkins Project up to 2.567.x REST API permission
A vulnerability labeled as problematic has been found in Jenkins Project Jenkins up to 2.567.x. This impacts an unknown function of the component REST API. Such manipulation leads to permission issues. This vulnerability is listed as CVE-20
CVE-2026-84648 | Jenkins Project Jenkins Plugin up to 2.567.x Log Viewer cross site scripting
A vulnerability was found in Jenkins Project Jenkins Plugin up to 2.567.x and classified as problematic. The affected element is an unknown function of the component Log Viewer. Executing a manipulation can lead to cross site scripting. Thi
CVE-2026-84652 | Jenkins Project up to 2.567.x session fixiation
A vulnerability classified as very critical was found in Jenkins Project Jenkins up to 2.567.x. This affects an unknown part. The manipulation results in session fixiation. This vulnerability is reported as CVE-2026-84652. The attack can be
CVE-2026-65646 | WebPros Plesk prior 18.0.79.8/18.0.80.4 DNS zone management neutralization
A vulnerability was found in WebPros Plesk. It has been declared as critical. This affects the function DNS zone management. The manipulation results in improper neutralization. This vulnerability is cataloged as CVE-2026-65646. The attack
CVE-2026-84646 | Jenkins Project Jenkins Plugin up to 2.567.x permission
A vulnerability categorized as critical has been discovered in Jenkins Project Jenkins Plugin up to 2.567.x. The impacted element is an unknown function. The manipulation results in permission issues. This vulnerability is identified as CVE
CVE-2026-84650 | Jenkins Project up to 2.567.x Transient Field deserialization
A vulnerability identified as problematic has been detected in Jenkins Project Jenkins up to 2.567.x. This affects an unknown function of the component Transient Field. This manipulation causes deserialization. This vulnerability is tracked
CVE-2026-84645 | Jenkins Project up to 2.567.x Stapler config.xml deserialization
A vulnerability, which was classified as critical, has been found in Jenkins Project Jenkins up to 2.567.x. Affected by this vulnerability is an unknown functionality of the file config.xml of the component Stapler. The manipulation leads t
CVE-2026-58616 | Microsoft Edge up to 151.0.4129.86 Copilot Chat race condition
A vulnerability described as problematic has been identified in Microsoft Edge. This impacts an unknown function of the component Copilot Chat. Executing a manipulation can lead to race condition. This vulnerability is handled as CVE-2026-5
CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following rep
Nintendo Switch Security Flaw Lets Nearby Attackers Exploit QR Codes Used to Share Screenshots
Nintendo has issued an urgent security advisory for owners of the original Switch console, warning of a flaw that could allow an attacker in close physical proximity to run unauthorized code on the device or pull data stored on it, simply
Multiple VLC Media Player Vulnerabilities Allow Attackers to Corrupt or Read Heap Memory
Two security vulnerabilities in VLC Media Player could allow attackers to corrupt heap memory or disclose sensitive data from a victim’s memory. The flaws, tracked as CVE-2026-56711 and CVE-2026-73324, affect VLC Media Player versions 3.0.0
Multiple VLC Media Player Vulnerabilities Allow Attackers to Corrupt or Read Heap Memory
Two security vulnerabilities in VLC Media Player could allow attackers to corrupt heap memory or disclose sensitive data from a victim’s memory. The flaws, tracked as CVE-2026-56711 and CVE-2026-73324, affect VLC Media Player versions 3.0.0
Multiple VLC Media Player Vulnerabilities Allow Attackers to Corrupt or Read Heap Memory
Two security vulnerabilities in VLC Media Player could allow attackers to corrupt heap memory or disclose sensitive data from a victim’s memory. The flaws, tracked as CVE-2026-56711 and CVE-2026-73324, affect VLC Media Player versions 3.0.0
China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks
China-linked threat actors UTA0560 and JungleBamboo chained a Google Chrome zero-day with a Windows kernel privilege-escalation flaw in phishing campaigns targeting NGOs and other victims. Volexity documented the operations, detected on Sep
China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks
China-linked threat actors UTA0560 and JungleBamboo chained a Google Chrome zero-day with a Windows kernel privilege-escalation flaw in phishing campaigns targeting NGOs and other victims. Volexity documented the operations, detected on Sep
CISA Warns of Critical GitLab Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab flaw, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog after confirming it was exploited in attacks. The issue affects bot
CISA Warns of Critical GitLab Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab flaw, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog after confirming it was exploited in attacks. The issue affects bot
CISA Warns of Critical GitLab Path Traversal Flaw Exploited to Read Arbitrary Server Files
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab path traversal vulnerability, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog after evidence that the flaw is being activ
CISA Warns of GitLab Path Traversal Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab vulnerability, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog, warning that attackers are actively exploiting the flaw.
CISA Warns of GitLab Path Traversal Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab vulnerability, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog, warning that attackers are actively exploiting the flaw.
Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
Ravie LakshmananSep 11, 2026Vulnerability / Malware Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC)
GitLab schließt CVE-2026-85706 mit CVSS 10, aktive In-the-Wild-Probes
LONDON (IT BOLTWISE) – GitLab hat mehrere Sicherheitslücken gepatcht, darunter eine Schwachstelle mit CVSS 10,0 (CVE-2026-85706), die bereits innerhalb von Stunden nach der Veröffentlichung von Angreifern abgefragt wurde. Betroffen sind bes
VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data
Two security vulnerabilities in VLC Media Player could enable attackers to corrupt memory or extract sensitive data from affected systems by persuading users to open a specially crafted image file or media playlist. The flaws, tracked as CV
CISA Warns MikroTik RouterOS Flaw Is Exploited to Escalate Privileges
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical MikroTik RouterOS privilege-escalation vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, warning that the flaw is being actively exploit
VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data
Two security vulnerabilities in VLC media player versions 3.0.0 through 3.0.23 could allow attackers to exploit heap memory issues. These vulnerabilities can be triggered by processing a malicious PNG file or connecting to attacker-controll
VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data
Two security vulnerabilities in VLC media player versions 3.0.0 through 3.0.23 could allow attackers to exploit heap memory issues. These vulnerabilities can be triggered by processing a malicious PNG file or connecting to attacker-controll
CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, warning that these flaws are actively being exploited in the wild. On
CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, warning that these flaws are actively being exploited in the wild. On
[UPDATE] [hoch] Red Hat Enterprise Linux (lxml): Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um Sicherheitsvorkehrungen zu umgehen. Weiterlesen
cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw
A recently disclosed vulnerability in ConfigServer Security &amp; Firewall (CSF) could allow unauthenticated remote attackers to execute arbitrary commands through the product’s MESSENGER service. This vulnerability, tracked as CVE-2026
cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw
A recently disclosed vulnerability in ConfigServer Security &amp; Firewall (CSF) could allow unauthenticated remote attackers to execute arbitrary commands through the product’s MESSENGER service. This vulnerability, tracked as CVE-2026
Check Point Patches Critical VPN Vulnerabilities
Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution. The post Check Point Patches Critical VPN Vulnerabilities appeared first on SecurityWeek. Weiterlesen
[UPDATE] [mittel] Red Hat OpenShift: Schwachstelle ermöglicht Manipulation von Dateien
Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Red Hat OpenShift ausnutzen, um Dateien zu manipulieren. Weiterlesen
[NEU] [niedrig] Red Hat Enterprise Linux (GNU coreutils unexpand): Schwachstelle ermöglicht DoS und Manipulation von Dateien
Ein lokaler Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um einen Denial of Service Angriff durchzuführen oder möglicherweise den Speicher zu manipulieren. Weiterlesen
[NEU] [UNGEPATCHT] [niedrig] GNU libc: Schwachstelle ermöglicht Denial of Service
Ein Angreifer aus einem angrenzenden Netzwerk kann eine Schwachstelle in GNU libc ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen
[NEU] [hoch] libvirt: Schwachstelle ermöglicht Privilegieneskalation
Ein lokaler Angreifer kann eine Schwachstelle in libvirt ausnutzen, um seine Privilegien zu erhöhen. Weiterlesen
[NEU] [mittel] QT (NFC-Modul): Schwachstelle ermöglicht DoS and die Offenlegung von Informationen
Ein Angreifer aus einem angrenzenden Netzwerk kann eine Schwachstelle in QT ausnutzen, um angrenzenden Speicher offenzulegen oder einen Denial-of-Service-Zustand zu verursachen. Weiterlesen
Attackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware
Three threat groups are exploiting two Cisco FMC flaws to steal credentials, gain root access and deploy Qilin ransomware. Cisco Talos says three separate threat groups are exploiting two recently patched Secure Firewall Management Center (
Critical ConfigServer Security & Firewall Flaw Lets Remote Attackers Execute Arbitrary Commands
A critical vulnerability in ConfigServer Security &amp; Firewall (CSF) could allow unauthenticated remote attackers to execute arbitrary commands on vulnerable servers. Tracked as CVE-2026-65638, the flaw affects CSF versions 14.00 thro
[UPDATE] [mittel] Snipe-IT: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Snipe-IT ausnutzen, um Sicherheitsvorkehrungen zu umgehen. Weiterlesen
[UPDATE] [mittel] CyberPanel: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in CyberPanel ausnutzen, um Sicherheitsvorkehrungen zu umgehen. Weiterlesen
Cisco warnt: Ausnutzung von FMC-Sicherheitslücken ermöglicht Qilin-Ransomware
LONDON (IT BOLTWISE) – Cisco meldet, dass Angreifende zwei kürzlich gepatchte Schwachstellen im Secure Firewall Management Center (FMC) nutzen, um erst Credentials zu stehlen und anschließend Qilin-Ransomware auszurollen. Besonders kritisch
Imperva Customers Protected Against StyleSmuggler (CVE-2026-75650) in Adobe Commerce and Magento Open Source
TL;DR: CVE-2026-75650, dubbed StyleSmuggler, is a critical vulnerability affecting Adobe Commerce and Magento Open Source. The vulnerability allows an unauthenticated attacker to inject malicious PHP code into Magento’s template system and
[UPDATE] [mittel] Golang Go "FIPS OpenSSL": Schwachstelle ermöglicht nicht spezifizierten Angriff
Ein lokaler Angreifer kann eine Schwachstelle in der Golang Go Komponente "FIPS OpenSSL" ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen. Weiterlesen
[NEU] [mittel] Fortra GoAnywhere MFT: Schwachstelle ermöglicht Offenlegung von Informationen
Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Fortra GoAnywhere MFT ausnutzen, um Informationen offenzulegen. Weiterlesen
[NEU] [hoch] GeoNetwork: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in GeoNetwork ausnutzen, um Sicherheitsvorkehrungen zu umgehen und so Daten offenzulegen oder zu manipulieren. Weiterlesen
[NEU] [hoch] Palo Alto Networks Cortex XDR Broker VM: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit Administratorrechten
Ein Angreifer aus einem angrenzenden Netzwerk kann eine Schwachstelle in Palo Alto Networks Cortex XDR Broker VM ausnutzen, um beliebigen Programmcode mit Administratorrechten auszuführen. Weiterlesen
[NEU] [niedrig] Laravel: Schwachstelle ermöglicht Cross-Site Scripting
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Laravel ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen. Weiterlesen
U.S. CISA adds Microsoft Windows, N-able N-central, and Adobe flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft Windows, N-able N-central, and Adobe flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added th