Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-08-31 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
HardBreacher PoC Claims Kaspersky Endpoint 0-Day Privilege Escalation on Windows 11
HardBreacher’s newly published PoC claims a local privilege-escalation flaw in Kaspersky Endpoint Security on fully patched Windows 11 systems, but the issue remains unverified and has not been publicly confirmed or assigned a CVE by Kasper
Microsoft Exchange: 85% der deutschen <b>Server</b> ungepatcht und anfällig - BornCity
Das BSI meldet eine hohe Gefährdung deutscher Exchange-Server durch CVE-2026-62911 und empfiehlt sofortige Updates sowie Zugriffsschutz. Weiterlesen
CVE-2026-83492 | Extend mes Kubio AI Website Builder up to 2.9.0 input validation (EUVD-2026-68616)
A vulnerability was found in Extend mes Kubio AI Website Builder up to 2.9.0. It has been rated as critical. This affects an unknown function. Performing a manipulation results in improper input validation. This vulnerability was named CVE-
CVE-2026-51713 | TOTOLINK T6 4.1.5cu.748 WAN Dial State Management /cgi-bin/cstecgi.cgi setManualDialCfg access control (EUVD-2026-68636)
A vulnerability has been found in TOTOLINK T6 4.1.5cu.748 and classified as critical. This issue affects the function setManualDialCfg of the file /cgi-bin/cstecgi.cgi of the component WAN Dial State Management. The manipulation leads to im
CVE-2026-51712 | TOTOLINK T6 4.1.5cu.748_B20211015 /cgi-bin/cstecgi.cgi setApWiFiSchCfg access control (EUVD-2026-68637)
A vulnerability classified as critical has been found in TOTOLINK T6 4.1.5cu.748_B20211015. Affected by this vulnerability is the function setApWiFiSchCfg of the file /cgi-bin/cstecgi.cgi. This manipulation causes improper access controls.
CVE-2026-82724 | ash-project ash_phoenix up to 2.3.24 SubdomainHook AshPhoenix.LiveView.SubdomainHook.on_mount improper authorization (EUVD-2026-68336)
A vulnerability marked as problematic has been reported in ash-project ash_phoenix up to 2.3.24. This impacts the function AshPhoenix.LiveView.SubdomainHook.on_mount of the component SubdomainHook. This manipulation causes improper authoriz
CVE-2026-51715 | TOTOLINK T6 4.1.5cu.748_B20211015 Mac Filter Rules /cgi-bin/cstecgi.cgi delMacFilterRules access control (EUVD-2026-68634)
A vulnerability was found in TOTOLINK T6 4.1.5cu.748_B20211015. It has been classified as very critical. The affected element is the function delMacFilterRules of the file /cgi-bin/cstecgi.cgi of the component Mac Filter Rules. This manipul
CVE-2026-81664 | OpenFaaS up to 0.27.13 Authentication gateway/main.go auth.DecorateWithBasicAuth improper authorization (EUVD-2026-67033)
A vulnerability marked as problematic has been reported in OpenFaaS up to 0.27.13. This vulnerability affects the function auth.DecorateWithBasicAuth of the file gateway/main.go of the component Authentication Handler. Performing a manipula
CVE-2026-81682 | jahlives openssl_encrypt up to 1.4.8 Desktop GUI permission (EUVD-2026-67038)
A vulnerability was found in jahlives openssl_encrypt up to 1.4.8. It has been declared as problematic. The affected element is an unknown function of the component Desktop GUI. Such manipulation leads to permission issues. This vulnerabili
CVE-2026-51714 | TOTOLINK T6 4.1.5cu.748 /cgi-bin/cstecgi.cgi setRoamingCfg access control (EUVD-2026-68635)
A vulnerability was found in TOTOLINK T6 4.1.5cu.748 and classified as very critical. Impacted is the function setRoamingCfg of the file /cgi-bin/cstecgi.cgi. The manipulation results in improper access controls. This vulnerability is known
CVE-2026-51716 | TOTOLINK T6 4.1.5cu.748_B20211015 Port Forwarding /cgi-bin/cstecgi.cgi delPortForwardRules access control (EUVD-2026-68633)
A vulnerability was found in TOTOLINK T6 4.1.5cu.748_B20211015. It has been declared as very critical. The impacted element is the function delPortForwardRules of the file /cgi-bin/cstecgi.cgi of the component Port Forwarding. Such manipula
CVE-2026-81692 | jahlives openssl_encrypt up to 1.4.8 FLAC file allocation of resources (EUVD-2026-67048)
A vulnerability marked as problematic has been reported in jahlives openssl_encrypt up to 1.4.8. Impacted is an unknown function of the component FLAC file Handler. Performing a manipulation results in allocation of resources. This vulnerab
CVE-2026-81687 | jahlives openssl_encrypt up to 1.4.8 resource consumption (EUVD-2026-67043)
A vulnerability classified as problematic has been found in jahlives openssl_encrypt up to 1.4.8. This issue affects the function openssl_encrypt. Performing a manipulation results in resource consumption. This vulnerability was named CVE-2
CVE-2026-52491 | LibTIFF Thumbnail thumbnail.c main code injection (EUVD-2026-66177)
A vulnerability was found in LibTIFF. It has been declared as critical. The affected element is the function main of the file libtiff/tools/thumbnail.c of the component Thumbnail. Such manipulation leads to code injection. This vulnerabilit
CVE-2026-20887 | Intel Vision Software access control (intel-sa-01457)
A vulnerability marked as critical has been reported in Intel Vision Software. Affected is an unknown function. Performing a manipulation results in improper access controls. This vulnerability is reported as CVE-2026-20887. The attack is p
CVE-2026-24874 | themrdemonized xray-monolith up to 2025.12.29 type confusion
A vulnerability identified as critical has been detected in themrdemonized xray-monolith up to 2025.12.29. This affects an unknown part. The manipulation leads to type confusion. This vulnerability is uniquely identified as CVE-2026-24874.
CVE-2025-53811 | Mosh-Pro 1.3.2 on macOS default permission
A vulnerability described as critical has been identified in Mosh-Pro 1.3.2 on macOS. Affected by this issue is some unknown functionality. Such manipulation leads to incorrect default permissions. This vulnerability is referenced as CVE-20
CVE-2024-6387 | OpenSSH up to 9.8 on Linux Signal grace_alarm_handler regreSSHion race condition (EDB-52269 / Nessus ID 209711)
A vulnerability categorized as critical has been discovered in OpenSSH up to 9.8 on Linux. Affected by this issue is the function grace_alarm_handler of the component Signal Handler. Executing a manipulation can lead to race condition. This
CVE-2026-0826 | HP Poly Trio 8300/Poly Trio 8500/Poly Trio 8800 up to 8.1.6 on Linux stack-based overflow
A vulnerability marked as critical has been reported in HP Poly Trio 8300, Poly Trio 8500 and Poly Trio 8800 up to 8.1.6 on Linux. This impacts an unknown function. This manipulation causes stack-based buffer overflow. This vulnerability is
CVE-2026-13753 | HP Deskjet 2800 Series prior TBP1CN2612AR Webserver authorization
A vulnerability, which was classified as problematic, was found in HP Deskjet 2800 Series. This issue affects some unknown processing of the component Webserver. Such manipulation leads to missing authorization. This vulnerability is refere
CVE-2024-52011 | vitejs launch-editor up to 2.8.x on Windows Special Character launchEditor File command injection
A vulnerability classified as critical was found in vitejs launch-editor up to 2.8.x on Windows. This affects the function launchEditor of the component Special Character Handler. The manipulation of the argument File results in command inj
CVE-2026-15044 | Red Hat OpenShift AI TrustyAI Service Operator improper authorization
A vulnerability was found in Red Hat OpenShift AI. It has been rated as critical. This affects an unknown part of the component TrustyAI Service Operator. This manipulation causes improper authorization. This vulnerability appears as CVE-20
HardBreacher PoC Claims Kaspersky Endpoint 0-Day Privilege Escalation on Windows 11
HardBreacher’s newly published PoC claims a local privilege-escalation flaw in Kaspersky Endpoint Security on fully patched Windows 11 systems, but the issue remains unverified and has not been publicly confirmed or assigned a CVE by Kasper
HardBreacher PoC Claims Kaspersky Endpoint 0-Day Privilege Escalation on Windows 11
HardBreacher’s newly published PoC claims a local privilege-escalation flaw in Kaspersky Endpoint Security on fully patched Windows 11 systems, but the issue remains unverified and has not been publicly confirmed or assigned a CVE by Kasper
Microsoft Exchange mit kritischer Schwachstelle: Neue Lücke, alte Fehler
... Hacker über eine Schwachstelle in anfällige Exchange-Systeme eindringen können. Wie das Bundesamt für Sicherheit in der Informationstechnik (BSI) ... Weiterlesen
HardBreacher Exploit Targets Kaspersky Endpoint Security Zero-Day for Windows 11 Privilege Escalation
A proof of concept called HardBreacher allegedly exploits an unpatched local privilege escalation flaw in Kaspersky Antivirus for Endpoint. This vulnerability allows a local user to control a privileged component. The code was published by
HardBreacher Exploit Targets Kaspersky Endpoint Security Zero-Day for Windows 11 Privilege Escalation
A proof of concept called HardBreacher allegedly exploits an unpatched local privilege escalation flaw in Kaspersky Antivirus for Endpoint. This vulnerability allows a local user to control a privileged component. The code was published by
HardBreacher PoC Targets Kaspersky Endpoint Security Zero-Day for Windows 11 Privilege Escalation
A publicly available proof-of-concept (PoC) named HardBreacher claims to exploit an unpatched elevation-of-privilege issue in Kaspersky Endpoint Security for Windows, potentially allowing a local user to gain high-level access on affected W
Metasploit Exploit Targets Actively Exploited PaperCut NG/MF Zero-Day RCE Chain
A new Metasploit Framework module is poised to make a recently disclosed, actively exploited PaperCut NG and MF zero-day chain more accessible. Rapid7 contributor Stephen Fewer submitted pull request #21842 for CVE-2026-81578 and CVE-2026-8
Metasploit Adds Exploit for PaperCut MF/NG Zero-Day RCE Vulnerabilities
Rapid7’s Metasploit Framework is set to add an exploit module targeting the actively exploited chain of vulnerabilities affecting PaperCut MF and PaperCut NG. This addition will provide public offensive tooling for a security emergency invo
Metasploit Adds Exploit for PaperCut MF/NG Zero-Day RCE Vulnerabilities
Rapid7’s Metasploit Framework is set to add an exploit module targeting the actively exploited chain of vulnerabilities affecting PaperCut MF and PaperCut NG. This addition will provide public offensive tooling for a security emergency invo
[NEU] [mittel] PJSIP: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in PJSIP ausnutzen, um Sicherheitsvorkehrungen zu umgehen. Weiterlesen
[NEU] [mittel] HP Computer: Schwachstelle ermöglicht Privilegieneskalation
Ein lokaler Angreifer kann eine Schwachstelle in HP Computer ausnutzen, um seine Privilegien zu erhöhen. Weiterlesen
[NEU] [hoch] JFrog Artifactory: Schwachstelle ermöglicht Erlangen von Administratorrechten
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in JFrog Artifactory ausnutzen, um Administratorrechte zu erlangen. Weiterlesen
[NEU] [mittel] sudo: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
Ein lokaler Angreifer kann eine Schwachstelle in sudo ausnutzen, um Sicherheitsvorkehrungen zu umgehen. Weiterlesen
[UPDATE] [mittel] Red Hat Enterprise Linux (NetworkManager): Schwachstelle ermöglicht Privilegieneskalation
Ein lokaler Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux (NetworkManager) ausnutzen, um seine Privilegien zu erhöhen. Weiterlesen
PaperCut Issues Second Emergency Patch as Researchers Break Fix for Exploited Zero-Days
PaperCut released a second emergency patch last Friday, for two vulnerabilities in its NG and MF print management servers that attackers are already exploiting, after security researchers demonstrated that the vendor's first fix could
[NEU] [niedrig] NetApp StorageGRID: Schwachstelle ermöglicht Denial of Service
Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in NetApp StorageGRID ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen
[NEU] [mittel] ffmpeg: Schwachstelle ermöglicht Codeausführung und DoS
Ein Angreifer aus einem angrenzenden Netzwerk kann eine Schwachstelle in ffmpeg ausnutzen, um möglicherweise beliebigen Code auszuführen oder einen Denial-of-Service-Zustand zu verursachen. Weiterlesen
[NEU] [mittel] Red Hat Enterprise Linux (iperf3): Schwachstelle ermöglicht Denial of Service
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um einen Denial of Service Angriff durchzuführen. Weiterlesen
[NEU] [mittel] Red Hat Enterprise Linux (xmlrpc-c): Schwachstelle ermöglicht Cross-Site Scripting
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen. Weiterlesen
Elon Musk warnt vor KI-<b>Hacking</b> auf Superniveau bis Ende 2027 - klamm.de
Die Schwachstelle, die die KI-Hacking-Debatte neu entfachte. JFrog veröffentlichte am 28. August die Schwachstelle CVE-2026-82329. Diese erhielt auf ... Weiterlesen
Root-Sicherheitslücke bedroht cPanel/WHM
In aktuellen Versionen haben die Entwickler der Webhosting-Control-Panel-Software cPanel/WHM eine Schwachstelle geschlossen. Weiterlesen
Root-Sicherheitslücke bedroht cPanel/WHM
In aktuellen Versionen haben die Entwickler der Webhosting-Control-Panel-Software cPanel/WHM eine Schwachstelle geschlossen. Weiterlesen
Composer Path Traversal Flaw Lets Malicious Packages Expose Sensitive Files
A newly disclosed vulnerability in Composer could allow malicious or compromised PHP packages to alter permissions on files located outside their intended installation directory, potentially exposing sensitive data on shared and multi-tenan
[UPDATE] [mittel] GNU Emacs TRAMP: Schwachstelle ermöglicht Codeausführung
Ein lokaler Angreifer kann eine Schwachstelle in GNU Emacs TRAMP ausnutzen, um beliebigen Programmcode auszuführen. Weiterlesen
[UPDATE] [mittel] PAM: Schwachstelle ermöglicht Offenlegung von Informationen
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in PAM ausnutzen, um Informationen offenzulegen. Weiterlesen
Exchange-Sicherheitslücke: 85 Prozent der On-Prem-Server in Deutschland anfällig
Ein Proof-of-Concept-Exploit für eine hochriskante Exchange-Lücke ist öffentlich. 85 Prozent der On-Premises-Server sind anfällig. Weiterlesen
Exchange-Sicherheitslücke: 85 Prozent der On-Prem-Server in Deutschland anfällig
Ein Proof-of-Concept-Exploit für eine hochriskante Exchange-Lücke ist öffentlich. 85 Prozent der On-Premises-Server sind anfällig. Weiterlesen
GitLab-Lücke CVE-2026-19478: CVSS 9,4 sofort ausgenutzt - Tech Insider
... Cybersicherheit betont – ein Hinweis darauf, dass die langfristige Marktbewertung stärker von der Produktstrategie als von einzelnen CVE-Meldungen ... Weiterlesen
CVE-2026-75757 | Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an attacker who controls a sibling subdomain rebind an admin's session to a different actor, tenant, or authorization mode. AshAdmin's client JavaScript read its state cookies (tenant, actor_resource, actor_primary_key, actor_action, actor_domain, actor_authorizing, actor_paused) by matching the cookie name with an unanchored regular expression (new RegE
Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an attacker who controls a sibling subdomain rebind an admin's session to a different actor, tenant, or authorization mode. AshAdmin'
CVE-2026-82605 | A vulnerability has been found in BareBones BBEdit up to 15.5.5. The affected element is an unknown function of the component Lasso Language Tokenizer. Such manipulation leads to infinite loop. The attack can be executed remotely. Upgrading to version 16.0 is sufficient to fix this issue. The affected component should be upgraded.
A vulnerability has been found in BareBones BBEdit up to 15.5.5. The affected element is an unknown function of the component Lasso Language Tokenizer. Such manipulation leads to infinite loop. The attack can be executed remotely. Upgrading
CVE-2026-82604 | A flaw has been found in BareBones BBEdit up to 15.5.5. Impacted is an unknown function of the component Java Language Module. This manipulation causes uncontrolled recursion. Remote exploitation of the attack is possible. Upgrading to version 16.0 is recommended to address this issue. You should upgrade the affected component.
A flaw has been found in BareBones BBEdit up to 15.5.5. Impacted is an unknown function of the component Java Language Module. This manipulation causes uncontrolled recursion. Remote exploitation of the attack is possible. Upgrading to vers
CVE-2026-82603 | A vulnerability was detected in SeaCMS up to 13.6. This issue affects some unknown processing of the file /member.php?action=del_pl of the component Comment Cache. The manipulation of the argument itype/vid results in path traversal. The attack may be launched remotely. The exploit is now public and may be used.
A vulnerability was detected in SeaCMS up to 13.6. This issue affects some unknown processing of the file /member.php?action=del_pl of the component Comment Cache. The manipulation of the argument itype/vid results in path traversal. The at
CVE-2026-82602 | A security vulnerability has been detected in SeaCMS up to 13.6. This vulnerability affects unknown code of the file /ass.php. The manipulation leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
A security vulnerability has been detected in SeaCMS up to 13.6. This vulnerability affects unknown code of the file /ass.php. The manipulation leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclo
CVE-2026-82601 | A weakness has been identified in SeaCMS up to 13.6. This affects an unknown part of the file /err.php. Executing a manipulation of the argument errtxt can lead to cross site scripting. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.
A weakness has been identified in SeaCMS up to 13.6. This affects an unknown part of the file /err.php. Executing a manipulation of the argument errtxt can lead to cross site scripting. The attack can be launched remotely. The exploit has b
CVE-2026-75760 | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In AshAi.Changes.Vectorize, when the embedding provider call fails the change added a changeset error whose message inspected the raw error term (An error occurred while generating embeddings: #{inspect(error)}). A plain-string add_error produces an Ash.Error.Changes.InvalidChange
Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In AshAi.Changes.Vectorize, when the embedding provider ca
CVE-2026-82580 | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses internal error text to chat users. In AshAi.ToolLoop and AshAi.Tools, an exception raised while executing a tool was serialized verbatim with Exception.message/1 into the tool-result content. That content is appended to the conversation, emitted as a {:tool_result, ...} stream event, and sent back to the model, which typically relays it to the user. No
Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses internal error text to chat users. In AshAi.ToolLoop and AshAi.Tools, an exception raised while executing a tool was serialized verb
CVE-2026-82579 | Loop with Unreachable Exit Condition (Infinite Loop) vulnerability in ash-project ash_ai allows an attacker who can influence a model's output to hang the tool loop and drive unbounded, repeated model requests. AshAi.ToolLoop classifies a model response of :tool_calls, then filters the calls through normalize_tool_calls/2 and unprocessed_tool_calls/2. Both can empty the list: a call missing a valid name, or one reusing a tool_call_id that already has a resul
Loop with Unreachable Exit Condition (Infinite Loop) vulnerability in ash-project ash_ai allows an attacker who can influence a model's output to hang the tool loop and drive unbounded, repeated model requests. AshAi.ToolLoop classifies a
CVE-2026-82564 | Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_ai allows a caller of an identity-configured tool to update or destroy records it never identified, including every row in the table. In AshAi.Tool.Execution, identity_filter/3 built the update/destroy filter directly from the raw tool arguments as [{key, Map.get(arguments, to_string(key))}] and passed it to Ash.Query.do_filter/2. A map value is parsed as a predicate expression
Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_ai allows a caller of an identity-configured tool to update or destroy records it never identified, including every row in the table. In AshAi.Tool.Execution