CVE-2026-90777: Schwachstellen-Eintrag (NVD)
ESPnet before 202609 deserializes pretrained model checkpoints using torch.load with weights_only=False, allowing arbitrary code execution from attacker-supplied files. Attackers can craft malicious checkpoint files that execute code during deserialization when loaded through the initialization or fine-tuning path.
- 🔗 github.com/espnet/espnet
- 🔗 github.com/espnet/espnet/blob/v.202511/espnet2/torch…
- 🔗 github.com/espnet/espnet/commit/91ca045fc179f29bc7b7…
- 🔗 github.com/espnet/espnet/releases/tag/v.202609
- 🔗 github.com/espnet/espnet/security/advisories/GHSA-64…
- 🔗 www.vulncheck.com/advisories/espnet-before-202609-remote-co…
Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-13 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
CISA warnt: GitLab-Schlagloch CVE-2026-85706 aktiv ausgenutzt
USA / LONDON (IT BOLTWISE) – Die US-Cybersicherheitsbehörde CISA meldet, dass Angreifer eine GitLab-Sicherheitslücke maximaler Schwere (CVE-2026-85706) bereits ausnutzen. Betroffen ist ein DevSecOps-Feature, bei dem fehlende Authentifizieru
CVE-2026-47887 | Spring Framework up to 7.0.8 UrlFileNameViewController redirect (WID-SEC-2026-2955)
A vulnerability was found in Spring Framework up to 7.0.8. It has been classified as problematic. Impacted is an unknown function of the component UrlFileNameViewController. Performing a manipulation results in open redirect. This vulnerabi
CVE-2026-85092 | jtsylve LiME up to 1.12.0 path link following (EUVD-2026-70302)
A vulnerability has been found in jtsylve LiME up to 1.12.0 and classified as problematic. This issue affects some unknown processing. The manipulation of the argument path leads to link following. This vulnerability is listed as CVE-2026-8
CVE-2026-53683 | FreeIPA Web UI reset_password.html redirect
A vulnerability was found in FreeIPA and classified as problematic. The affected element is an unknown function of the file reset_password.html of the component Web UI. The manipulation results in open redirect. This vulnerability is report
CVE-2026-78071 | Digital Peak DP Calendar Extension up to 10.11.2 Location Location title cross site scripting (EUVD-2026-67653)
A vulnerability was found in Digital Peak DP Calendar Extension up to 10.11.2. It has been classified as problematic. This affects an unknown part of the component Location. The manipulation of the argument Location title leads to cross sit
CVE-2026-47888 | VMware Spring Framework up to 7.0.8 RSocket Setup Frame memory leak (Nessus ID 341186 / WID-SEC-2026-2955)
A vulnerability was found in VMware Spring Framework up to 7.0.8. It has been declared as problematic. The affected element is an unknown function of the component RSocket Setup Frame. Executing a manipulation can lead to memory leak. The i
CVE-2026-89578 | Linux Kernel up to 6.18.49/7.2.3 dm-io dm-io.c do_region race condition (Nessus ID 345346)
A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.18.49/7.2.3. This issue affects the function do_region of the file dm-io.c of the component dm-io. The manipulation results in race condition. This vulnerab
CVE-2026-83530 | Google Cel-Go up to 0.28.x Parser ParserExpressionSizeLimit allocation of resources (Nessus ID 345347)
A vulnerability labeled as problematic has been found in Google Cel-Go up to 0.28.x. The impacted element is the function ParserExpressionSizeLimit of the component Parser. Executing a manipulation can lead to allocation of resources. This
CVE-2026-89669 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 nfsd nfsd4_copy_notify use after free (Nessus ID 345349)
A vulnerability, which was classified as very critical, was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. The impacted element is the function nfsd4_copy_notify of the component nfsd. Such manipulation leads to use after free. This vu
CVE-2026-89453 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 iommu iommu_call_iopf_notifier memory leak (Nessus ID 345348)
A vulnerability was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. It has been declared as critical. Affected is the function iommu_call_iopf_notifier of the component iommu. The manipulation results in memory leak. This vulnerability
CVE-2026-89489 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 OpenRISC sys_or1k_atomic v1/v2 out-of-bounds write (Nessus ID 345351)
A vulnerability was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. It has been declared as very critical. This vulnerability affects the function sys_or1k_atomic of the component OpenRISC. The manipulation of the argument v1/v2 results
CVE-2026-89738 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 at91_udc at91_udc_shutdown_vbus_timer use after free (Nessus ID 345350)
A vulnerability, which was classified as very critical, was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. This affects the function at91_udc_shutdown_vbus_timer of the component at91_udc. Executing a manipulation can lead to use after
CVE-2026-89527 | Linux Kernel up to 7.2.3 svcrdma svc_rdma_create use after free (Nessus ID 345352)
A vulnerability classified as very critical has been found in Linux Kernel up to 7.2.3. This issue affects the function svc_rdma_create of the component svcrdma. This manipulation causes use after free. This vulnerability is registered as C
GitHub Pays $100,000 Bounty for Critical RCE Flaw in Git Push Pipeline
GitHub has awarded security researcher Saif Ghani a $100,000 bug bounty after the disclosure of CVE-2026-3854, a critical remote code execution vulnerability affecting GitHub’s Git push processing pipeline. The reward is reportedly the larg
CVE-2026-82763 | Contec FX3000 Series/FX4000 Series/FX5000 Series cross site scripting (EUVD-2026-77242)
A vulnerability categorized as problematic has been discovered in Contec FX3000 Series, FX4000 Series and FX5000 Series. The impacted element is an unknown function. Executing a manipulation can lead to cross site scripting. This vulnerabil
CVE-2026-82789 | Contec CONPROSYS HMI System up to 3.7.x injection (EUVD-2026-77243)
A vulnerability, which was classified as critical, has been found in Contec CONPROSYS HMI System up to 3.7.x. The affected element is an unknown function. This manipulation causes injection. This vulnerability appears as CVE-2026-82789. The
CVE-2026-25832 | TrustedFirmware Mbed TLS up to 3.6.6/4.1.1 input validation (EUVD-2026-77305)
A vulnerability described as problematic has been identified in TrustedFirmware Mbed TLS up to 3.6.6/4.1.1. Affected by this vulnerability is an unknown functionality. Such manipulation leads to improper input validation. This vulnerability
CVE-2026-90691 | 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04 API Files Endpoint hexstrike_server.py FileOperationsManager filename path traversal (135/225 / EUVD-2026-77244)
A vulnerability identified as critical has been detected in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The impacted element is the function FileOperationsManager of the file hexstrike_server.py of the component API F
CVE-2026-82792 | Contec CAN-2-WF/CAN-2-USB up to 2.19 cross site scripting (EUVD-2026-77247)
A vulnerability was found in Contec CAN-2-WF and CAN-2-USB up to 2.19. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation results in cross site scripting. This vulnerability was
CVE-2026-82790 | Contec PC-HELPER Wireless I/O DIO-0404RY-LWF up to 1.0.x cross site scripting (EUVD-2026-77245)
A vulnerability was found in Contec PC-HELPER Wireless IO DIO-0404RY-LWF and DIO-0404RY-LWF-US up to 1.0.x. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross site scripting. This vulnera
CVE-2026-82791 | Contec CAN-2-WF/CAN-2-USB up to 2.19 os command injection (EUVD-2026-77246)
A vulnerability, which was classified as very critical, was found in Contec CAN-2-WF and CAN-2-USB up to 2.19. The impacted element is an unknown function. Such manipulation leads to os command injection. This vulnerability is traded as CVE
CVE-2026-82793 | Contec CAN-2-WF/CAN-2-USB up to 2.19 unrestricted upload (EUVD-2026-77249)
A vulnerability has been found in Contec CAN-2-WF and CAN-2-USB up to 2.19 and classified as problematic. This affects an unknown function. Performing a manipulation results in unrestricted upload. This vulnerability is known as CVE-2026-82
CVE-2026-82765 | Contec FX5000/FX4000/FX3000 path traversal (EUVD-2026-77248)
A vulnerability classified as critical was found in Contec FX5000, FX4000 and FX3000. Affected is an unknown function. Such manipulation leads to path traversal. This vulnerability is traded as CVE-2026-82765. The attack may be launched rem
CVE-2026-82794 | Contec SolarView Compact up to 8.x Schedule Settings os command injection (EUVD-2026-77250)
A vulnerability was found in Contec SolarView Compact up to 8.x and classified as very critical. This impacts an unknown function of the component Schedule Settings. Executing a manipulation can lead to os command injection. This vulnerabil
CVE-2026-85125 | YAMAP up to 17.1.0 WebView access control (EUVD-2026-77253)
A vulnerability described as critical has been identified in YAMAP up to 17.1.0. The affected element is an unknown function of the component WebView. The manipulation results in improper access controls. This vulnerability is cataloged as
CVE-2026-82796 | Contec SV-CPT-MC310/SV-CPT-MC310F up to 8.x Image Management cross site scripting (EUVD-2026-77252)
A vulnerability was found in Contec SV-CPT-MC310 and SV-CPT-MC310F up to 8.x. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Image Management. This manipulation causes cross site scri
CVE-2026-82795 | Contec SolarView Compact up to 8.x Schedule Settings/Mail Send Setting cross site scripting (EUVD-2026-77251)
A vulnerability categorized as problematic has been discovered in Contec SolarView Compact up to 8.x. This affects an unknown part of the component Schedule Settings/Mail Send Setting. Such manipulation leads to cross site scripting. This v
China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor
China-linked threat actors tracked as UNC3569 have exploited a critical one-click remote code execution vulnerability in Tencent’s Sogou Input Method for Windows to deploy the GRAYRABBIT backdoor on targeted systems. Tracked as CVE-2026-519
China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor
China-linked threat actors tracked as UNC3569 have exploited a critical one-click remote code execution vulnerability in Tencent’s Sogou Input Method for Windows to deploy the GRAYRABBIT backdoor on targeted systems. Tracked as CVE-2026-519
China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor
China-linked threat actors tracked as UNC3569 have exploited a critical one-click remote code execution vulnerability in Tencent’s Sogou Input Method for Windows to deploy the GRAYRABBIT backdoor on targeted systems. Tracked as CVE-2026-519
Critical AWS Flaw Lets Attackers Bypass Port Forwarding Restrictions and Steal IAM Credentials
A critical vulnerability in the AWS Systems Manager (SSM) Agent could allow authorized attackers to bypass Session Manager port-forwarding restrictions, access link-local services, and steal temporary IAM credentials assigned to Amazon EC2
GitHub Pays $100,000 Bounty for Critical RCE Flaw Triggered by a Single Git Push
GitHub has reportedly awarded a $100,000 bug bounty to security researcher Saif Ghani for identifying a critical remote code execution vulnerability that could be triggered through a specially crafted Git repository operation. The flaw, tra
Critical Check Point VPN Flaws Could Face Large-Scale Exploitation, NCSC Warns
The Netherlands’ National Cyber Security Center (NCSC) has warned organizations to urgently patch two critical vulnerabilities in Check Point VPN products, saying widespread exploitation attempts are likely to begin soon. Tracked as CVE-202
Weekly Cybersecurity Newsletter Bulletin – Microsoft 0-day, FortiOS, PAN-OS Flaw, Revolut Data Breach, and 20+ Stories
This week’s roundup covers a massive Microsoft Patch Tuesday with two exploited zero-days, active FortiGate exploitation, a critical PAN-OS root-level RCE flaw, the Revolut KYC data breach, and more than 20 other stories spanning AI-driven
Weekly Cybersecurity Newsletter Bulletin – Microsoft 0-day, FortiOS, PAN-OS Flaw, Revolut Data Breach, and 20+ Stories
This week’s roundup covers a massive Microsoft Patch Tuesday with two exploited zero-days, active FortiGate exploitation, a critical PAN-OS root-level RCE flaw, the Revolut KYC data breach, and more than 20 other stories spanning AI-driven
GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read – Exploited Within 24 Hours
CVE-2026-85706, a CVSS 10.0 GitLab path traversal, was under active exploitation within 24 hours of disclosure. GitLab disclosed CVE-2026-85706 (CVSS score of 10.0) on September 10, 2026, a path traversal vulnerability in its repository com
Plesk Backup Manager Flaw Lets Low-Privileged Users Gain Root Access to Servers
A newly disclosed vulnerability in Plesk Backup Manager could allow low-privileged users to escalate privileges and gain full root access on affected Linux servers. Tracked as CVE-2026-68488, the flaw stems from a symlink race condition dur
Plesk Backup Manager Flaw Lets Low-Privileged Users Gain Root Access to Servers
A newly disclosed vulnerability in Plesk Backup Manager could allow low-privileged users to escalate privileges and gain full root access on affected Linux servers. Tracked as CVE-2026-68488, the flaw stems from a symlink race condition dur
Microsoft-Patchday: 966 Schwachstellen, davon 105 kritisch - BornCity
... Windows 10, Windows 11 und Windows Server zu erlangen. Dabei werde eine frühere Korrektur für die Lücke CVE-2026-69414 umgangen. Microsoft ... Weiterlesen
Multiple VLC Media Player Vulnerabilities Allow Attackers to Corrupt or Read Heap Memory
Two security vulnerabilities in VLC Media Player could allow attackers to corrupt heap memory or disclose sensitive data from a victim’s memory. The flaws, tracked as CVE-2026-56711 and CVE-2026-73324, affect VLC Media Player versions 3.0.0
Multiple VLC Media Player Vulnerabilities Allow Attackers to Corrupt or Read Heap Memory
Two security vulnerabilities in VLC Media Player could allow attackers to corrupt heap memory or disclose sensitive data from a victim’s memory. The flaws, tracked as CVE-2026-56711 and CVE-2026-73324, affect VLC Media Player versions 3.0.0
China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks
China-linked threat actors UTA0560 and JungleBamboo chained a Google Chrome zero-day with a Windows kernel privilege-escalation flaw in phishing campaigns targeting NGOs and other victims. Volexity documented the operations, detected on Sep
China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks
China-linked threat actors UTA0560 and JungleBamboo chained a Google Chrome zero-day with a Windows kernel privilege-escalation flaw in phishing campaigns targeting NGOs and other victims. Volexity documented the operations, detected on Sep
CISA Warns of Critical GitLab Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab flaw, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog after confirming it was exploited in attacks. The issue affects bot
CISA Warns of Critical GitLab Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab flaw, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog after confirming it was exploited in attacks. The issue affects bot
CISA Warns of Critical GitLab Path Traversal Flaw Exploited to Read Arbitrary Server Files
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab path traversal vulnerability, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog after evidence that the flaw is being activ
CISA Warns of GitLab Path Traversal Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab vulnerability, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog, warning that attackers are actively exploiting the flaw.
Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
Ravie LakshmananSep 11, 2026Vulnerability / Malware Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC)
GitLab schließt CVE-2026-85706 mit CVSS 10, aktive In-the-Wild-Probes
LONDON (IT BOLTWISE) – GitLab hat mehrere Sicherheitslücken gepatcht, darunter eine Schwachstelle mit CVSS 10,0 (CVE-2026-85706), die bereits innerhalb von Stunden nach der Veröffentlichung von Angreifern abgefragt wurde. Betroffen sind bes
VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data
Two security vulnerabilities in VLC media player versions 3.0.0 through 3.0.23 could allow attackers to exploit heap memory issues. These vulnerabilities can be triggered by processing a malicious PNG file or connecting to attacker-controll
Attackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware
Three threat groups are exploiting two Cisco FMC flaws to steal credentials, gain root access and deploy Qilin ransomware. Cisco Talos says three separate threat groups are exploiting two recently patched Secure Firewall Management Center (
[UPDATE] [mittel] Snipe-IT: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Snipe-IT ausnutzen, um Sicherheitsvorkehrungen zu umgehen. Weiterlesen
[UPDATE] [mittel] CyberPanel: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in CyberPanel ausnutzen, um Sicherheitsvorkehrungen zu umgehen. Weiterlesen
Imperva Customers Protected Against StyleSmuggler (CVE-2026-75650) in Adobe Commerce and Magento Open Source
TL;DR: CVE-2026-75650, dubbed StyleSmuggler, is a critical vulnerability affecting Adobe Commerce and Magento Open Source. The vulnerability allows an unauthenticated attacker to inject malicious PHP code into Magento’s template system and
[UPDATE] [mittel] Golang Go "FIPS OpenSSL": Schwachstelle ermöglicht nicht spezifizierten Angriff
Ein lokaler Angreifer kann eine Schwachstelle in der Golang Go Komponente "FIPS OpenSSL" ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen. Weiterlesen
[NEU] [mittel] Fortra GoAnywhere MFT: Schwachstelle ermöglicht Offenlegung von Informationen
Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Fortra GoAnywhere MFT ausnutzen, um Informationen offenzulegen. Weiterlesen
[NEU] [hoch] GeoNetwork: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in GeoNetwork ausnutzen, um Sicherheitsvorkehrungen zu umgehen und so Daten offenzulegen oder zu manipulieren. Weiterlesen
Active exploitation of Cisco Secure Firewall Management Center vulnerabilities
Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software. First, CVE-2026-20079 is an authentication bypass vulnerability in unpatched instances of Cisco’s Secure F
Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."Microsoft notes that 2 of the vulnerabiliti
Attackers Exploit Unpatched Magento Zero-Day to Backdoor Online Stores
Attackers are exploiting an unpatched remote code execution flaw in Adobe Commerce and Magento Open Source to install persistent backdoors on e-commerce sites, Dutch security firm Sansec reported, with the first intrusions observed Sept. 4