🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

354k+ 🇪🇺 EUVD-Datenbank
6 🔴 Critical im Radar
4 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
0 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-09: 240 2025-10: 316 2025-11: 257 2025-12: 426 2026-01: 431 2026-02: 418 2026-03: 652 2026-04: 574 2026-05: 683 2026-06: 942 2026-07: 1333 2026-08: 1329 7.601 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Adobe Apple Google Linux Microsoft Oracle Corporation
● Adobe ● Apple ● Google ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
Tier2026-08-292026-09-05
≥90 %40
≥50 %40
≥10 %30
<10 %304300
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Generic Security 44
WordPress 4
Linux 3
VMware 3
Adobe 2
Google 2
Schweregrad & Status:
Hersteller (Datenbank-weit, 90.597 Einträge):
Quelle:
🔍
● 2 Filter aktiv Alles zurücksetzen ✕
7.5 HIGH
EPSS 22.2%
CVE-2026-72323 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-72323 | Linux Kernel up to 7.2-rc2 IGMP igmp_gq_start_timer use after free

A vulnerability was found in Linux Kernel up to 6.6.144/6.12.96/6.18.39/7.1.4/7.2-rc2. It has been rated as critical. Affected by this vulnerability is the function igmp_gq_start_timer of the component IGMP. The manipulation leads to use af

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 32.7%
CVE-2026-19478 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-19478 | GitLab up to 18.11.10/19.0.7/19.1.5/19.2.3 GraphQL Directive authorization (WID-SEC-2026-2882)

A vulnerability was found in GitLab up to 18.11.10/19.0.7/19.1.5/19.2.3. It has been declared as critical. This affects an unknown part of the component GraphQL Directive. The manipulation results in missing authorization. This vulnerabilit

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.8%
CVE-2026-34884 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Apache

CVE-2026-34884 | Apache SkyWalking MCP up to 0.1.0 set_skywalking_url injection (EUVD-2026-60572)

A vulnerability was found in Apache SkyWalking MCP up to 0.1.0. It has been classified as critical. Impacted is the function set_skywalking_url. The manipulation leads to injection. This vulnerability is documented as CVE-2026-34884. The at

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: ModSecurity WAF-Regeln aktivieren und HTTP/2-Konfiguration überprüfen.
7.5 HIGH
EPSS 21.4%
CVE-2026-72667 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-72667 | Elastic Kibana up to 8.19.19/9.4.4 Observability log analysis feature allocation of resources

A vulnerability, which was classified as problematic, has been found in Elastic Kibana up to 8.19.19/9.4.4. Affected is an unknown function of the component Observability log analysis feature. Performing a manipulation results in allocation

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.5%
CVE-2026-68476 💻 Lokal 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-68476 | Linux Kernel up to 7.2-rc3 ipvs __ip_vs_get_out_rt allocation of resources (WID-SEC-2026-2852)

A vulnerability, which was classified as very critical, was found in Linux Kernel up to 6.6.144/6.12.96/6.18.39/7.1.4/7.2-rc3. Impacted is the function __ip_vs_get_out_rt of the component ipvs. Executing a manipulation can lead to allocatio

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 29%
CVE-2026-73841 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73841 | OpenChoreo up to 1.1.x API Handlers exec.go project improper authorization (EUVD-2026-58507)

A vulnerability described as critical has been identified in OpenChoreo up to 1.1.x. Affected by this issue is some unknown functionality of the file internal/openchoreo-api/api/handlers/exec.go of the component API Handlers. The manipulati

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.7%
CVE-2026-47837 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-47837 | Spring Cloud Config up to 3.1.14/4.2.8/4.3.4/5.0.4 Monitor Endpoint missing authentication (WID-SEC-2026-2952)

A vulnerability classified as problematic has been found in Spring Cloud Config up to 3.1.14/4.2.8/4.3.4/5.0.4. The impacted element is an unknown function of the component Monitor Endpoint. Performing a manipulation results in missing auth

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.9%
CVE-2026-47836 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
VMware

CVE-2026-47836 | VMware Spring Cloud Config up to 3.1.14/4.2.8/4.3.4/5.0.4 SVN Cloning toctou (WID-SEC-2026-2952)

A vulnerability described as problematic has been identified in VMware Spring Cloud Config up to 3.1.14/4.2.8/4.3.4/5.0.4. The affected element is an unknown function of the component SVN Cloning. Such manipulation leads to time-of-check ti

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.5%
CVE-2026-80428 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-80428 | ILIAS-eLearning ILIAS up to 9.21/10.9/11.2 Shibboleth Logout shib_logout.php unserialize deserialization (EUVD-2026-66602)

A vulnerability described as critical has been identified in ILIAS-eLearning ILIAS up to 9.21/10.9/11.2. This affects the function unserialize of the file components/ILIAS/AuthShibboleth/resources/shib_logout.php of the component Shibboleth

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.1%
CVE-2026-78367 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Linux

CVE-2026-78367 | Red Hat Enterprise Linux Tarball Mode injection

A vulnerability categorized as very critical has been discovered in Red Hat Enterprise Linux, Hardened Images and OpenShift Container Platform. This affects an unknown part of the component Tarball Mode. Such manipulation leads to injection

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
7.5 HIGH
EPSS 22.5%
CVE-2026-65644 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-65644 | Rocket.Chat up to 7.10.14/8.7.0 Omnichannel Queue InquireSidePanelItem.tsx dangerouslySetInnerHTML Name injection (EUVD-2026-63806)

A vulnerability labeled as critical has been found in Rocket.Chat up to 7.10.14/8.7.0. The affected element is the function dangerouslySetInnerHTML of the file InquireSidePanelItem.tsx of the component Omnichannel Queue. The manipulation of

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.1%
CVE-2026-65645 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-65645 | Rocket.Chat up to 8.7.x Meteor DDP getThreadsList/getThreadMessages rid/tmid improper authorization (EUVD-2026-63805)

A vulnerability identified as problematic has been detected in Rocket.Chat up to 8.7.x. Impacted is the function getThreadsList/getThreadMessages of the component Meteor DDP. The manipulation of the argument rid/tmid leads to improper autho

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.5%
CVE-2026-69419 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Microsoft

CVE-2026-69419 | Microsoft Azure Data Manager for Energy integer overflow (EUVD-2026-63625)

A vulnerability was found in Microsoft Azure Data Manager for Energy and classified as critical. This affects an unknown function. Executing a manipulation can lead to integer overflow. This vulnerability is handled as CVE-2026-69419. The a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
7.5 HIGH
EPSS 27.9%
CVE-2026-75618 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-75618 | TP-Link Tapo C100/Tapo C101 RTSP service null pointer dereference

A vulnerability identified as critical has been detected in TP-Link Tapo C100 and Tapo C101. This vulnerability affects unknown code of the component RTSP service. Performing a manipulation results in null pointer dereference. This vulnerab

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.6%
CVE-2026-18824 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-18824 | IBM AIX/PowerVM VIOS os command injection

A vulnerability categorized as very critical has been discovered in IBM AIX and PowerVM VIOS. This affects an unknown function. Executing a manipulation can lead to os command injection. This vulnerability is registered as CVE-2026-18824. I

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 26.7%
CVE-2026-14978 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-14978 | HashiCorp go-slug up to 0.18.2 Unicode Normalization privileges management (WID-SEC-2026-2978)

A vulnerability categorized as problematic has been discovered in HashiCorp go-slug up to 0.18.2. This affects an unknown part of the component Unicode Normalization. The manipulation results in improper privilege management. This vulnerabi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.6%
CVE-2026-14514 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-14514 | IBM Reliable Scalable Cluster Technology 3.0 allocation of resources

A vulnerability was found in IBM Reliable Scalable Cluster Technology 3.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to allocation of resources. This vuln

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.9%
CVE-2026-75619 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-75619 | TP-Link Tapo C100/Tapo C101 RTSP Service heap-based overflow

A vulnerability labeled as critical has been found in TP-Link Tapo C100 and Tapo C101. This issue affects some unknown processing of the component RTSP Service. Executing a manipulation can lead to heap-based buffer overflow. This vulnerabi

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.7%
CVE-2026-19582 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-19582 | GNU Binutils PE File rsrc_print_name stack-based overflow (EUVD-2026-63197)

This issue seems to be a false positive. Please check the referenced sources and consider omitting this entry entirely. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.9%
CVE-2026-15316 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-15316 | TP-Link Tapo C200 Configuration Service input validation

A vulnerability marked as critical has been reported in TP-Link Tapo C200. Impacted is an unknown function of the component Configuration Service. Performing a manipulation results in improper input validation. This vulnerability is reporte

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.7%
CVE-2026-71106 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-71106 | Oracle Hospitality OPERA Property Services up to 5.6.28.1 Opera Servlet access control

A vulnerability categorized as critical has been discovered in Oracle Hospitality OPERA Property Services up to 5.6.28.1. Affected by this vulnerability is an unknown functionality of the component Opera Servlet. Executing a manipulation ca

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.4%
CVE-2026-70724 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-70724 | Oracle MySQL Cluster up to 8.0.48/8.4.11/9.7.2 Cluster General access control (WID-SEC-2026-2903)

A vulnerability marked as critical has been reported in Oracle MySQL Cluster up to 8.0.48/8.4.11/9.7.2. This affects an unknown part of the component Cluster General. The manipulation leads to improper access controls. This vulnerability is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.5%
CVE-2026-15315 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-15315 | TP-Link Tapo C200 improper authentication

A vulnerability, which was classified as very critical, was found in TP-Link Tapo C200. Affected is an unknown function. Such manipulation leads to improper authentication. This vulnerability is uniquely identified as CVE-2026-15315. The at

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Adobe

Magento-Backdoor „StyleSmuggler“: Ungepatchte Zero-Day trifft Adobe Commerce

LONDON (IT BOLTWISE) – Eine ungesicherte Zero-Day-Lücke in Magento Open Source und Adobe Commerce wird offenbar aktiv ausgenutzt. Die Sicherheitsfirma Sansec nennt die Schwachstelle „StyleSmuggler“ und beschreibt eine Kette, die ohne Login

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 28.9%
CVE-2026-66782 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-66782 | Red Hat Advanced Cluster Management for Kubernetes Submariner Operator improper authorization (EUVD-2026-61066)

A vulnerability classified as very critical was found in Red Hat Advanced Cluster Management for Kubernetes. This issue affects some unknown processing of the component Submariner Operator. Executing a manipulation can lead to improper auth

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.2%
CVE-2026-17084 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-17084 | Python up to 3.15.x stringprep in_table_b2 interpretation conflict (WID-SEC-2026-2924)

A vulnerability labeled as critical has been found in Python up to 3.15.x. This affects the function in_table_b2 of the component stringprep. Such manipulation leads to interpretation conflict. This vulnerability is documented as CVE-2026-1

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.5%
CVE-2026-74234 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-74234 | Legora prior 2026-08-14 Front-Matter Parser eval cross site scripting

This issue was flagged as a false-positive. Please consult the sources mentioned and consider not using this entry at all. Weiterlesen

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.7%
CVE-2026-66783 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-66783 | Red Hat Advanced Cluster Management for Kubernetes submariner-operator permission (EUVD-2026-61067)

A vulnerability categorized as very critical has been discovered in Red Hat Advanced Cluster Management for Kubernetes. This impacts an unknown function of the component submariner-operator. Executing a manipulation can lead to permission i

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.3%
CVE-2026-72532 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-72532 | Joomla! Project Joomla Extension up to 4.0.0/5.4.7/6.0.0/6.1.2 Category improper authorization (WID-SEC-2026-2926)

A vulnerability classified as problematic was found in Joomla! Project Joomla Extension up to 4.0.0/5.4.7/6.0.0/6.1.2. This impacts an unknown function of the component Category. The manipulation results in improper authorization. This vuln

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 29.3%
CVE-2026-73337 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73337 | Joomla Extension up to 4.0.0/5.4.6/6.0.0/6.1.2 state issue (WID-SEC-2026-2926)

A vulnerability was found in Joomla Extension up to 4.0.0/5.4.6/6.0.0/6.1.2. It has been classified as critical. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in state issue. This vulnerabilit

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 25.6%
CVE-2026-73373 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73373 | Joomla! Project Joomla! CMS/Joomla! Framework Filesystem package up to 5.4.7/6.1.2 SHTML file unrestricted upload (WID-SEC-2026-2926)

A vulnerability, which was classified as critical, was found in Joomla! Project Joomla! CMS and Joomla! Framework Filesystem package up to 5.4.7/6.1.2. This affects an unknown function of the component SHTML file Handler. The manipulation r

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 27.2%
CVE-2026-71574 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-71574 | Joomla! Project Joomla! CMS Extension up to 5.4.6/6.1.2 Webservice Endpoint improper authorization (WID-SEC-2026-2926)

A vulnerability has been found in Joomla! Project Joomla! CMS Extension up to 5.4.6/6.1.2 and classified as problematic. This impacts an unknown function of the component Webservice Endpoint. This manipulation causes improper authorization.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.5%
CVE-2026-19500 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-19500 | Brainstorm Force SureForms Plugin up to 2.1.2 Entries resource consumption

A vulnerability described as problematic has been identified in Brainstorm Force SureForms Plugin up to 2.1.2. This impacts an unknown function of the component Entries. Executing a manipulation can lead to resource consumption. The identif

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19%
CVE-2026-73371 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-73371 | Joomla! Project Joomla Extension up to 5.4.7/6.1.2 Batch Copy improper authorization (WID-SEC-2026-2926)

A vulnerability, which was classified as critical, has been found in Joomla! Project Joomla Extension up to 5.4.7/6.1.2. The impacted element is an unknown function of the component Batch Copy. The manipulation leads to improper authorizati

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.5%
CVE-2026-66795 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-66795 | Red Hat Multicluster Engine for Kubernetes managedcluster-import-controller certificate validation

A vulnerability was found in Red Hat Multicluster Engine for Kubernetes. It has been rated as problematic. Affected by this issue is some unknown functionality of the component managedcluster-import-controller. This manipulation causes impr

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.8 MEDIUM
EPSS 3.1%
CVE-2026-66781 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-66781 | Red Hat Advanced Cluster Management for Kubernetes Submariner Operator information disclosure (EUVD-2026-61065)

A vulnerability described as problematic has been identified in Red Hat Advanced Cluster Management for Kubernetes. This affects an unknown part of the component Submariner Operator. Such manipulation leads to information disclosure. This v

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 20.8%
CVE-2022-43250 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-43250 | Libde265 1.0.8 Video File fallback-motion.cc put_qpel_0_0_fallback_16 heap-based overflow (Issue 346 / EUVD-2022-46294)

A vulnerability, which was classified as critical, has been found in Libde265 1.0.8. This issue affects the function put_qpel_0_0_fallback_16 of the file fallback-motion.cc of the component Video File Handler. The manipulation leads to heap

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 32.3%
CVE-2022-43249 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-43249 | Libde265 1.0.8 Video File fallback-motion.cc put_epel_hv_fallback heap-based overflow (Issue 345 / EUVD-2022-46293)

A vulnerability classified as critical was found in Libde265 1.0.8. This vulnerability affects the function put_epel_hv_fallback of the file fallback-motion.cc of the component Video File Handler. Executing a manipulation can lead to heap-b

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 31.1%
CVE-2022-43248 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-43248 | Libde265 1.0.8 Video File fallback-motion.cc put_weighted_pred_avg_16_fallback heap-based overflow (Issue 349 / EUVD-2022-46292)

A vulnerability classified as critical has been found in Libde265 1.0.8. This affects the function put_weighted_pred_avg_16_fallback of the file fallback-motion.cc of the component Video File Handler. Performing a manipulation results in he

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19%
CVE-2022-43245 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-43245 | Libde265 1.0.8 Video File sao.cc apply_sao_internal memory corruption (Issue 352 / EUVD-2022-46289)

A vulnerability described as critical has been identified in Libde265 1.0.8. Affected by this issue is the function apply_sao_internal of the file sao.cc of the component Video File Handler. Such manipulation leads to memory corruption. Thi

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 19.8%
CVE-2022-43244 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-43244 | Libde265 1.0.8 Video File fallback-motion.cc put_qpel_fallback heap-based overflow (Issue 342 / EUVD-2022-46288)

A vulnerability marked as critical has been reported in Libde265 1.0.8. Affected by this vulnerability is the function put_qpel_fallback of the file fallback-motion.cc of the component Video File Handler. This manipulation causes heap-based

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 21.9%
CVE-2022-43243 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-43243 | Libde265 1.0.8 Video File sse-motion.cc ff_hevc_put_weighted_pred_avg_8_sse heap-based overflow (Issue 339 / EUVD-2022-46287)

A vulnerability labeled as critical has been found in Libde265 1.0.8. Affected is the function ff_hevc_put_weighted_pred_avg_8_sse of the file sse-motion.cc of the component Video File Handler. The manipulation results in heap-based buffer

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 24.1%
CVE-2022-43242 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2022-43242 | Libde265 1.0.8 Video File motion.cc mc_luma heap-based overflow (Issue 340 / EUVD-2022-46286)

A vulnerability identified as critical has been detected in Libde265 1.0.8. This impacts the function mc_luma of the file motion.cc of the component Video File Handler. The manipulation leads to heap-based buffer overflow. This vulnerabilit

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 92.7%
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Adobe

Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store&#039;s server without logging in, Dutch e-commerce security company Sansec said in an advi

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.4%
CVE-2026-81578 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

PaperCut Flaws Exploited in Attacks on U.S. and European Schools

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-20

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 30.4%
CVE-2026-81578 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

PaperCut Flaws Exploited in Attacks on U.S. and European Schools

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-20

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.0 CRITICAL
EPSS 64.4%
CVE-2026-59346 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
VMware

Broadcom schließt kritische Lücke in VMware Workstation und Fusion (CVE-2026-59346)

LONDON (IT BOLTWISE) – Broadcom hat Sicherheitsupdates für VMware Workstation und VMware Fusion veröffentlicht und schließt dabei zwei Lücken, darunter einen kritischen Integer-Overflow mit CVSS 9,3. Unter bestimmten Bedingungen kann ein An

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 82.5%
CVE-2026-32475 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

Elementor Pro WordPress Flaw Exploited to Upload Webshells and Execute Commands

  A critical vulnerability in the Elementor Pro WordPress plugin is being actively exploited to upload malicious PHP files and execute commands remotely on the affected websites. The vulnerability, tracked as CVE-2026-32475, affects the Ele

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
7.5 HIGH
EPSS 22.4%
CVE-2026-59346 💻 Lokal 🔓 Keine Authentifizierung nötig
VMware

Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.5 CRITICAL
EPSS 72.1%
CVE-2026-9586 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Switchvox Vulnerability Triggers Active Exploitation Risk

  Sangoma Switchvox CVE-2026-9586 is a serious unauthenticated SQL injection flaw that can lead to remote code execution, and Horizon3 says it has already seen real-world exploitation attempts. The issue was patched in Switchvox 8.4.0.2, ma

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 22.3%
CVE-2023-49105 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CISA Flags Old ownCloud Flaw After Reported Philippine Nuclear Data Theft

CISA added CVE-2023-49105 to its exploited-flaws catalog after researchers tied the old ownCloud bug to reported Philippine nuclear data theft. This article has been indexed from Security Archives – TechRepublic Read the original article: C

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.5%
CVE-2026-32475 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites

Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions. This article has been indexed from SecurityWeek Read the original article: Elementor Pro WordP

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
7.5 HIGH
EPSS 18.5%
CVE-2026-32475 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites

Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions. The post Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites appeared first o

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
7.5 HIGH
EPSS 30.4%
CVE-2026-81578 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

PaperCut-Schwachstellen: Angreifer stehlen Anmeldedaten an Schulen und Universitäten

LONDON (IT BOLTWISE) – Angreifer nutzen neu gemeldete PaperCut-Schwachstellen, um an Schulen und Universitäten in den USA und Europa Zugangsdaten auszuspähen. In den Beobachtungen wurden CVE-2026-81578 und CVE-2026-82078 für Authentifizieru

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.4%
CVE-2026-6471 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers

A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged replication accounts to execute attacker-controlled code, escalate to database superuser, and establish persistent backdoors on affected servers. Tracked as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.4%
CVE-2026-6471 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers

A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged replication accounts to execute attacker-controlled code, escalate to database superuser, and establish persistent backdoors on affected servers. Tracked as

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.4%
CVE-2026-6471 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

12-Year-Old PostgreSQL Flaw Lets Backup Accounts Execute Code and Take Over Databases

A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged backup and replication accounts to execute arbitrary code, escalate to database superuser privileges, and establish persistent access on vulnerable servers.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS 18.8%
CVE-2026-85046 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

U.S. CISA adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Google Chromium V8 flaw, trac

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
⚠️ KEV
EPSS 82.8%
CVE-2026-85046 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Google

Google’s Chrome Update Patches Sixth Zero-Day Exploited in 2026

Chrome users have another actively exploited zero-day to worry about, and this one sits inside the engine that powers much of the modern web. Google has patched CVE-2026-85046, a high-severity type confusion vulnerability in Chrome’s V8 Jav

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.2 HIGH
EPSS 32.7%
CVE-2026-19949 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-19949 Leaves Millions of WordPress Sites Running Vulnerable Plugin Versions

A WordPress backup tool designed to help sites recover from trouble can instead become the trigger for an attack. Researchers disclosed a high-severity SQL injection vulnerability in the All-in-One WP Migration and Backup plugin that affect

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.