Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-05 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
CVE-2026-23131 | Linux Kernel up to 6.6.121/6.12.67/6.18.7 lib/kobject.c hp_init_bios_buffer_attribute buffer overflow (Nessus ID 299321 / WID-SEC-2026-0421)
A vulnerability described as critical has been identified in Linux Kernel up to 6.6.121/6.12.67/6.18.7. Affected by this issue is the function hp_init_bios_buffer_attribute in the library lib/kobject.c. The manipulation results in buffer ov
CVE-2026-23132 | Linux Kernel up to 6.18.7 dw_dp_bind privilege escalation (Nessus ID 299318 / WID-SEC-2026-0421)
A vulnerability, which was classified as problematic, was found in Linux Kernel up to 6.18.7. This issue affects the function dw_dp_bind. Such manipulation leads to privilege escalation. This vulnerability is listed as CVE-2026-23132. The a
CVE-2026-23130 | Linux Kernel up to 6.18.7 wifi ath12k_mac_op_flush race condition (Nessus ID 299231 / WID-SEC-2026-0421)
A vulnerability was found in Linux Kernel up to 6.18.7. It has been rated as critical. This affects the function ath12k_mac_op_flush of the component wifi. Performing a manipulation results in race condition. This vulnerability is identifie
CVE-2026-23129 | Linux Kernel up to 6.12.67/6.18.7 dpll _add reference count (Nessus ID 299219 / WID-SEC-2026-0421)
A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.12.67/6.18.7. Affected by this vulnerability is the function _add of the component dpll. Executing a manipulation can lead to improper update of reference c
CVE-2026-23127 | Linux Kernel up to 6.18.7 lib/refcount.c perf_mmap_rb use after free (Nessus ID 299181 / WID-SEC-2026-0421)
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.18.7. This vulnerability affects the function perf_mmap_rb in the library lib/refcount.c. Executing a manipulation can lead to use after free. This vulnera
CVE-2026-23128 | Linux Kernel up to 6.18.7 swsusp_arch_resume buffer overflow (Nessus ID 299069 / WID-SEC-2026-0421)
A vulnerability identified as critical has been detected in Linux Kernel up to 5.15.198/6.1.161/6.6.121/6.12.67/6.18.7. Affected by this issue is the function swsusp_arch_resume. The manipulation leads to buffer overflow. This vulnerability
CVE-2026-23126 | Linux Kernel up to 6.1.161/6.6.121/6.12.67/6.18.7 Netdevsim Driver nsim_bpf_create_prog protection mechanism (Nessus ID 299071 / WID-SEC-2026-0421)
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.1.161/6.6.121/6.12.67/6.18.7. This affects the function nsim_bpf_create_prog of the component Netdevsim Driver. Such manipulation leads to protection mecha
CVE-2026-67276 | Mikrotik RouterOS up to 6.49.20/7.23.3/7.24.1 signature verification (EUVD-2026-72024)
A vulnerability classified as very critical was found in Mikrotik RouterOS up to 6.49.20/7.23.3/7.24.1. This impacts an unknown function. Executing a manipulation can lead to improper verification of cryptographic signature. The identificat
CVE-2026-86206 | N-able N-central prior 2026.3 HF3/2026.4 access control (EUVD-2026-72023)
A vulnerability marked as very critical has been reported in N-able N-central. The affected element is an unknown function. This manipulation causes improper access controls. This vulnerability is handled as CVE-2026-86206. The attack can b
CVE-2026-67277 | Mikrotik RouterOS up to 6.49.20/7.23.3/7.24.1 integer underflow (EUVD-2026-72025)
A vulnerability described as very critical has been identified in Mikrotik RouterOS up to 6.49.20/7.23.3/7.24.1. The impacted element is an unknown function. Such manipulation leads to integer underflow. This vulnerability is uniquely ident
CVE-2026-67279 | Mikrotik RouterOS up to 6.49.20/7.23.3/7.24.1 SSH Connection Protocol improper authentication (EUVD-2026-72027)
A vulnerability, which was classified as very critical, was found in Mikrotik RouterOS up to 6.49.20/7.23.3/7.24.1. Affected by this vulnerability is an unknown functionality of the component SSH Connection Protocol. The manipulation result
CVE-2026-67278 | MikroTik RouterOS up to 6.49.20/7.23.3/7.24.1 certificate validation (EUVD-2026-72026)
A vulnerability, which was classified as problematic, has been found in MikroTik RouterOS up to 6.49.20/7.23.3/7.24.1. Affected is an unknown function. The manipulation leads to improper certificate validation. This vulnerability is referen
CVE-2026-86060 | Mikrotik RouterOS up to 6.49.20/7.23.3/7.24.1 SSH Login privileges management (EUVD-2026-72029)
A vulnerability has been found in Mikrotik RouterOS up to 6.49.20/7.23.3/7.24.1 and classified as very critical. Affected by this issue is some unknown functionality of the component SSH Login. This manipulation causes improper privilege ma
CVE-2026-67281 | Mikrotik RouterOS up to 6.49.20/7.23.3/7.24.1 WebFig information disclosure (EUVD-2026-72028)
A vulnerability classified as problematic has been found in Mikrotik RouterOS up to 6.49.20/7.23.3/7.24.1. This affects an unknown function of the component WebFig. Performing a manipulation results in information disclosure. This vulnerabi
CVE-2026-86148 | Tenda CP3 27.5.57.101 Kylin Apis/system.c SystemAsh AlarmVoiceURL os command injection (EUVD-2026-72030)
A vulnerability was found in Tenda CP3 27.5.57.101 and classified as very critical. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results i
CVE-2026-86150 | Tenda CP3 27.5.57.101 custom-x/softap/hostapd wpa_passphrase hard-coded credentials (EUVD-2026-72032)
A vulnerability was found in Tenda CP3 27.5.57.101. It has been declared as problematic. Impacted is an unknown function of the file custom-x/softap/hostapd. Such manipulation of the argument wpa_passphrase leads to hard-coded credentials.
CVE-2026-86149 | Tenda CP3 27.5.57.101 Net/NetCheckPing.cpp interface_name/host os command injection (EUVD-2026-72031)
A vulnerability was found in Tenda CP3 27.5.57.101. It has been classified as very critical. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os comman
CVE-2026-86151 | Tenda CP3 27.5.57.101 Network Configuration Management Apis/system.c sub_2F77E8 os command injection (EUVD-2026-72036)
A vulnerability was found in Tenda CP3 27.5.57.101. It has been rated as very critical. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Management. Performing a manipulation r
CVE-2026-59304 | VMware Spring Cloud Stream up to 4.2.6/4.3.3/5.0.2 type confusion (EUVD-2026-67190)
A vulnerability was found in VMware Spring Cloud Stream up to 4.2.6/4.3.3/5.0.2. It has been classified as problematic. This affects an unknown part. Performing a manipulation results in type confusion. This vulnerability is reported as CVE
CVE-2026-13732 | Red Hat Enterprise Linux STABS debug format parser gdb/stabsread.c read_member_functions out-of-bounds write
A vulnerability was found in Red Hat Enterprise Linux. It has been declared as problematic. Impacted is the function read_member_functions of the file gdb/stabsread.c of the component STABS debug format parser. Such manipulation leads to ou
CVE-2026-82877 | ILIAS up to 9.21/10.9/11.2 SOAP Import addFile path traversal
A vulnerability, which was classified as problematic, was found in ILIAS up to 9.21/10.9/11.2. The impacted element is the function addFile of the component SOAP Import. Executing a manipulation can lead to path traversal. The identificatio
CVE-2026-59306 | VMware Spring Cloud Stream up to 4.2.6/4.3.3/5.0.2 deserialization
A vulnerability was found in VMware Spring Cloud Stream up to 4.2.6/4.3.3/5.0.2. It has been declared as problematic. This vulnerability affects unknown code. Executing a manipulation can lead to deserialization. This vulnerability appears
CVE-2026-47844 | Spring Reactor Netty up to 1.0.52/1.2.18/1.3.6 exposure of resource
A vulnerability categorized as critical has been discovered in Spring Reactor Netty up to 1.0.52/1.2.18/1.3.6. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to exposure of resource. This vulne
CVE-2026-59303 | VMware Spring Cloud Stream up to 4.2.6/4.3.3/5.0.2 allocation of resources (EUVD-2026-67189)
A vulnerability was found in VMware Spring Cloud Stream up to 4.2.6/4.3.3/5.0.2 and classified as problematic. Affected by this issue is some unknown functionality. Such manipulation leads to allocation of resources. This vulnerability is d
CVE-2026-59305 | VMware Spring Cloud Stream up to 4.2.6/4.3.3/5.0.2 Partition Interceptor incorrect behavior order
A vulnerability, which was classified as problematic, was found in VMware Spring Cloud Stream up to 4.2.6/4.3.3/5.0.2. Affected is an unknown function of the component Partition Interceptor. The manipulation results in incorrect behavior or
CVE-2026-59301 | VMware Spring Cloud Function up to 4.2.7/4.3.4/5.0.3 log file (EUVD-2026-67187)
A vulnerability was found in VMware Spring Cloud Function up to 4.2.7/4.3.4/5.0.3. It has been classified as problematic. Affected is an unknown function. This manipulation causes sensitive information in log files. This vulnerability appea
CVE-2026-47859 | Spring Integration up to 7.1.0 RFC6587SyslogDeserializer allocation of resources (EUVD-2026-66825)
A vulnerability, which was classified as critical, was found in Spring Integration up to 5.5.21/6.4.12/6.5.10/7.0.5/7.1.0. This issue affects some unknown processing of the component RFC6587SyslogDeserializer. The manipulation results in al
CVE-2026-18482 | Klarso Neo.mjs FileSystemService FileSystemService.mjs checkSyntax/runPlaywrightTest absolutePath os command injection (88c77fc4 / EUVD-2026-63326)
A vulnerability was found in Klarso Neo.mjs and classified as problematic. Affected by this vulnerability is the function checkSyntax/runPlaywrightTest of the file FileSystemService.mjs of the component FileSystemService. Executing a manipu
CVE-2026-18296 | GStreamer MRF File Parser heap-based overflow (Nessus ID 339182)
A vulnerability described as critical has been identified in GStreamer. This affects an unknown part of the component MRF File Parser. Such manipulation leads to heap-based buffer overflow. This vulnerability is documented as CVE-2026-18296
CVE-2026-76956 | libexpat project Libexpat up to 2.8.3 denial of service (WID-SEC-2026-2944)
A vulnerability classified as problematic was found in libexpat project Libexpat up to 2.8.3. Impacted is an unknown function. Such manipulation leads to denial of service. This vulnerability is documented as CVE-2026-76956. The attack can
CVE-2026-8619 | TP-Link Archer MR600/TL-MR100/TL-MR150/TL-MR6400 2/3.2/8.0 HTTP service null pointer dereference
A vulnerability described as critical has been identified in TP-Link Archer MR600, TL-MR100, TL-MR150 and TL-MR6400 2/3.2/8.0. This vulnerability affects unknown code of the component HTTP service. The manipulation results in null pointer d
CVE-2026-19507 | RDK RDK-B WebUI rdkb-2025q4-kirkstone.04.10.26 check.jst resource consumption
A vulnerability has been found in RDK RDK-B WebUI rdkb-2025q4-kirkstone.04.10.26 and classified as problematic. This issue affects some unknown processing of the file check.jst of the component WebUI. Performing a manipulation results in re
CVE-2026-19509 | RDK RDK-B WebUI rdkb-2025q4-kirkstone ajaxSet_wireless_network_configuration.jst ssid_number input validation
A vulnerability has been found in RDK RDK-B WebUI rdkb-2025q4-kirkstone and classified as problematic. The affected element is an unknown function of the file ajaxSet_wireless_network_configuration.jst of the component WebUI. Performing a m
CVE-2026-19506 | RDK WebUI rdkb-2025q4-kirkstone.04.10.26 check.jst race condition
A vulnerability identified as critical has been detected in RDK WebUI rdkb-2025q4-kirkstone.04.10.26. This impacts an unknown function of the file check.jst. This manipulation causes race condition. This vulnerability is registered as CVE-2
CVE-2026-19508 | RDK B WebUI rdkb-2025q4-kirkstone Multipart Form-Data Parser jst_post.c memory corruption
A vulnerability labeled as very critical has been found in RDK B WebUI rdkb-2025q4-kirkstone. Affected is an unknown function of the file jst_post.c of the component Multipart Form-Data Parser. Such manipulation leads to memory corruption.
CVE-2026-18289 | OriginLab OriginPro OPJ File Parser out-of-bounds write
A vulnerability labeled as critical has been found in OriginLab OriginPro. Affected by this vulnerability is an unknown functionality of the component OPJ File Parser. Such manipulation leads to out-of-bounds write. This vulnerability is do
CVE-2026-19505 | RDK WebUI rdkb-2025q4-kirkstone.04.10.26 jst_functions.c signature verification
A vulnerability categorized as very critical has been discovered in RDK WebUI rdkb-2025q4-kirkstone.04.10.26. This affects an unknown function of the file jst_functions.c. The manipulation results in improper verification of cryptographic s
CVE-2026-18295 | GStreamer MRF File Parser out-of-bounds write (Nessus ID 339182)
A vulnerability classified as critical has been found in GStreamer. This vulnerability affects unknown code of the component MRF File Parser. Performing a manipulation results in out-of-bounds write. This vulnerability is reported as CVE-20
Magento-Backdoor „StyleSmuggler“: Ungepatchte Zero-Day trifft Adobe Commerce
LONDON (IT BOLTWISE) – Eine ungesicherte Zero-Day-Lücke in Magento Open Source und Adobe Commerce wird offenbar aktiv ausgenutzt. Die Sicherheitsfirma Sansec nennt die Schwachstelle „StyleSmuggler“ und beschreibt eine Kette, die ohne Login
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advi
PaperCut Flaws Exploited in Attacks on U.S. and European Schools
Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-20
PaperCut Flaws Exploited in Attacks on U.S. and European Schools
Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-20
PaperCut Flaws Exploited in Attacks on U.S. and European Schools
Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-20
Broadcom schließt kritische Lücke in VMware Workstation und Fusion (CVE-2026-59346)
LONDON (IT BOLTWISE) – Broadcom hat Sicherheitsupdates für VMware Workstation und VMware Fusion veröffentlicht und schließt dabei zwei Lücken, darunter einen kritischen Integer-Overflow mit CVSS 9,3. Unter bestimmten Bedingungen kann ein An
Elementor Pro WordPress Flaw Exploited to Upload Webshells and Execute Commands
A critical vulnerability in the Elementor Pro WordPress plugin is being actively exploited to upload malicious PHP files and execute commands remotely on the affected websites. The vulnerability, tracked as CVE-2026-32475, affects the Ele
Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026
Switchvox Vulnerability Triggers Active Exploitation Risk
Sangoma Switchvox CVE-2026-9586 is a serious unauthenticated SQL injection flaw that can lead to remote code execution, and Horizon3 says it has already seen real-world exploitation attempts. The issue was patched in Switchvox 8.4.0.2, ma
CISA Flags Old ownCloud Flaw After Reported Philippine Nuclear Data Theft
CISA added CVE-2023-49105 to its exploited-flaws catalog after researchers tied the old ownCloud bug to reported Philippine nuclear data theft. This article has been indexed from Security Archives – TechRepublic Read the original article: C
Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions. This article has been indexed from SecurityWeek Read the original article: Elementor Pro WordP
Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions. The post Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites appeared first o
PaperCut-Schwachstellen: Angreifer stehlen Anmeldedaten an Schulen und Universitäten
LONDON (IT BOLTWISE) – Angreifer nutzen neu gemeldete PaperCut-Schwachstellen, um an Schulen und Universitäten in den USA und Europa Zugangsdaten auszuspähen. In den Beobachtungen wurden CVE-2026-81578 und CVE-2026-82078 für Authentifizieru
12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers
A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged replication accounts to execute attacker-controlled code, escalate to database superuser, and establish persistent backdoors on affected servers. Tracked as
12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers
A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged replication accounts to execute attacker-controlled code, escalate to database superuser, and establish persistent backdoors on affected servers. Tracked as
12-Year-Old PostgreSQL Flaw Lets Backup Accounts Execute Code and Take Over Databases
A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged backup and replication accounts to execute arbitrary code, escalate to database superuser privileges, and establish persistent access on vulnerable servers.
U.S. CISA adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Google Chromium V8 flaw, trac
Google’s Chrome Update Patches Sixth Zero-Day Exploited in 2026
Chrome users have another actively exploited zero-day to worry about, and this one sits inside the engine that powers much of the modern web. Google has patched CVE-2026-85046, a high-severity type confusion vulnerability in Chrome’s V8 Jav
CVE-2026-19949 Leaves Millions of WordPress Sites Running Vulnerable Plugin Versions
A WordPress backup tool designed to help sites recover from trouble can instead become the trigger for an attack. Researchers disclosed a high-severity SQL injection vulnerability in the All-in-One WP Migration and Backup plugin that affect
PostgreSQL stoppt Codeausführung via Logical Decoding: neuer Whitelist-Parameter
LONDON (IT BOLTWISE) – PostgreSQL schließt eine seit 2014 bekannte Schwachstelle (CVE-2026-6471), die mit dem REPLICATION-Attribut beliebigen Code im Backend-Prozess ausführen konnte. Die Absicherung erfolgt über einen neuen Parameter outpu
PostgreSQL fixiert CVE-2026-6471: REPLICATION-Benutzer können Code als DB-User ausführen
LONDON (IT BOLTWISE) – PostgreSQL hat ein Sicherheitsproblem mit der logischen Replikation geschlossen, das einem Konto mit REPLICATION-Attribut die Ausführung beliebigen Codes als OS-User des Datenbankservers ermöglicht. Betroffen sind Ver
HPE Patches Critical RCE Vulnerabilities in AOS-CX
Nearly two dozen issues, tracked collectively as CVE-2026-73749 (CVSS score of 9.8), were addressed with the updates. The post HPE Patches Critical RCE Vulnerabilities in AOS-CX appeared first on SecurityWeek. Weiterlesen