Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-05 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advi
CVE-2026-86141 | xmlsoft libxml2 up to 2.15.3 xmlregexp xmlRegNewParserCtxt null pointer dereference (Nessus ID 343096)
A vulnerability has been found in xmlsoft libxml2 up to 2.15.3 and classified as critical. Affected by this issue is the function xmlRegNewParserCtxt of the component xmlregexp. Performing a manipulation results in null pointer dereference.
CVE-2026-86145 | PCRE PCRE2 up to 10.47 Recursive DFA Matching Workspace pcre2_dfa_match out-of-bounds write (Nessus ID 343097)
A vulnerability was found in PCRE PCRE2 up to 10.47. It has been classified as critical. This vulnerability affects the function pcre2_dfa_match of the component Recursive DFA Matching Workspace. The manipulation leads to out-of-bounds writ
CVE-2026-85522 | valkey-io valkey up to 9.5.4/9.1.0 Slot Migration cluster_migrateslots.c createSlotImportJob job_name out-of-bounds (Issue 4207 / Nessus ID 343098)
A vulnerability classified as problematic was found in valkey-io valkey up to 9.5.4/9.1.0. Affected by this vulnerability is the function createSlotImportJob of the file src/cluster_migrateslots.c of the component Slot Migration. The manipu
CVE-2026-86137 | xmlsoft libxml2 up to 2.15.3 NXT macro xmlFAParsePosCharGroup out-of-bounds (Nessus ID 343099)
A vulnerability marked as critical has been reported in xmlsoft libxml2 up to 2.15.3. The affected element is the function xmlFAParsePosCharGroup of the component NXT macro. Performing a manipulation results in out-of-bounds read. This vuln
CVE-2026-86142 | xmlsoft libxml2 up to 2.15.3 xmlXPtrEvalXPtrPart buffer overflow (Nessus ID 343102)
A vulnerability was found in xmlsoft libxml2 up to 2.15.3 and classified as problematic. This affects the function xmlXPtrEvalXPtrPart. Executing a manipulation can lead to buffer overflow. The identification of this vulnerability is CVE-20
CVE-2026-86144 | xmlsoft libxml2 up to 2.15.3 xinclude xmlXIncludeProcess parseFlags xml external entity reference (Nessus ID 343103)
A vulnerability classified as critical has been found in xmlsoft libxml2 up to 2.15.3. This affects the function xmlXIncludeProcess of the component xinclude. The manipulation of the argument parseFlags leads to xml external entity referenc
CVE-2026-18540 | Node.js Undici up to 6.28.0/7.29.1/8.10.2 Retry Interceptor response splitting (Nessus ID 343100)
A vulnerability was found in Node.js Undici up to 6.28.0/7.29.1/8.10.2. It has been rated as problematic. This vulnerability affects unknown code of the component Retry Interceptor. Performing a manipulation results in http response splitti
CVE-2026-86140 | xmlsoft libxml2 up to 2.15.3 valid.c xmlSnprintfElements stack-based overflow (Nessus ID 343107)
A vulnerability, which was classified as problematic, was found in xmlsoft libxml2 up to 2.15.3. Affected by this vulnerability is the function xmlSnprintfElements of the file valid.c. Such manipulation leads to stack-based buffer overflow.
CVE-2026-86143 | xmlsoft libxml2 up to 2.15.3 xmlIO xmlOutputWriteCallback integer overflow (Nessus ID 343104)
A vulnerability classified as problematic was found in xmlsoft libxml2 up to 2.15.3. This impacts the function xmlOutputWriteCallback of the component xmlIO. The manipulation results in integer overflow. This vulnerability is known as CVE-2
CVE-2026-86138 | xmlsoft libxml2 up to 2.15.3 dict.c xmlDictAddQString integer overflow (Nessus ID 343105)
A vulnerability described as problematic has been identified in xmlsoft libxml2 up to 2.15.3. The impacted element is the function xmlDictAddQString of the file dict.c. Executing a manipulation can lead to integer overflow. This vulnerabili
CVE-2026-85008 | undici up to 7.29.0/8.10.1 Cache Interceptor input validation (Nessus ID 343106)
A vulnerability classified as problematic has been found in undici up to 7.29.0/8.10.1. This affects an unknown part of the component Cache Interceptor. Performing a manipulation results in improper input validation. This vulnerability is r
CVE-2026-86139 | xmlsoft libxml2 up to 2.15.3 URI Escape uri.c xmlURIEscapeStr integer overflow (Nessus ID 343108)
A vulnerability, which was classified as critical, has been found in xmlsoft libxml2 up to 2.15.3. Affected is the function xmlURIEscapeStr of the file uri.c of the component URI Escape. This manipulation causes integer overflow. This vulne
CVE-2026-85148 | Lightstar SmartIT Desktop Manager up to 10 hard-coded credentials (CNNVD-2026-92390283)
A vulnerability has been found in Lightstar SmartIT Desktop Manager up to 10 and classified as critical. Impacted is an unknown function. Performing a manipulation results in hard-coded credentials. This vulnerability is reported as CVE-202
CVE-2026-85397 | code-projects Hospital Information System 1.0 addReq.php findBySearch sql injection (EUVD-2026-70859 / CNNVD-2026-99637767)
A vulnerability, which was classified as critical, has been found in code-projects Hospital Information System 1.0. This impacts the function findBySearch of the file addReq.php. This manipulation of the argument Search causes sql injection
CVE-2026-85382 | light0011 cms Chapter Content Output oneChapter.tpl htmlspecialchars_decode content cross site scripting (CNNVD-2026-95247126)
A vulnerability marked as problematic has been reported in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. Impacted is the function htmlspecialchars_decode of the file App/Home/View/Default/C
CVE-2026-67567 | Red Hat Advanced Cluster Management for Kubernetes multicloud-operators-subscription privileges management (EUVD-2026-63589)
A vulnerability marked as very critical has been reported in Red Hat Advanced Cluster Management for Kubernetes. This issue affects some unknown processing of the component multicloud-operators-subscription. This manipulation causes imprope
CVE-2026-70398 | Red Hat Advanced Cluster Management for Kubernetes multicloud-integrations privileges management (EUVD-2026-57058)
A vulnerability labeled as very critical has been found in Red Hat Advanced Cluster Management for Kubernetes. This affects an unknown function of the component multicloud-integrations. The manipulation results in improper privilege managem
CVE-2026-66878 | Red Hat Advanced Cluster Management for Kubernetes multicloud-operators-subscription Channel.Spec.SecretRef.Namespace information disclosure (EUVD-2026-57059)
A vulnerability identified as problematic has been detected in Red Hat Advanced Cluster Management for Kubernetes. The impacted element is an unknown function of the component multicloud-operators-subscription. The manipulation of the argum
CVE-2026-70495 | Red Hat Advanced Cluster Management for Kubernetes search-v2-operator permission (EUVD-2026-60361)
A vulnerability marked as very critical has been reported in Red Hat Advanced Cluster Management for Kubernetes. This issue affects some unknown processing of the component search-v2-operator. Performing a manipulation results in permission
CVE-2026-0799 | Tcpdump Group libpcap up to 1.10.6 BPF Interpreter out-of-bounds (EUVD-2026-72015)
A vulnerability, which was classified as problematic, was found in Tcpdump Group libpcap up to 1.10.6. This affects an unknown function of the component BPF Interpreter. Executing a manipulation can lead to out-of-bounds read. This vulnerab
CVE-2026-31912 | Tcpdump Group libpcap up to 1.10.6 BPF Interpreter buffer overflow (EUVD-2026-72016)
A vulnerability categorized as problematic has been discovered in Tcpdump Group libpcap up to 1.10.6. This vulnerability affects unknown code of the component BPF Interpreter. Executing a manipulation can lead to buffer overflow. This vulne
CVE-2026-31911 | Tcpdump Group libpcap up to 1.10.6 BPF Interpreter abort input validation (EUVD-2026-72017)
A vulnerability was found in Tcpdump Group libpcap up to 1.10.6. It has been rated as critical. This affects the function abort of the component BPF Interpreter. Performing a manipulation results in improper input validation. This vulnerabi
CVE-2026-6244 | Tcpdump Group libpcap up to 1.10.6 BPF Interpreter divide by zero (EUVD-2026-72018)
A vulnerability identified as problematic has been detected in Tcpdump Group libpcap up to 1.10.6. This issue affects some unknown processing of the component BPF Interpreter. The manipulation leads to divide by zero. This vulnerability is
CVE-2026-18313 | Tcpdump Group libpcap up to 1.9.x/1.10.6 memory leak (EUVD-2026-72020)
A vulnerability was found in Tcpdump Group libpcap up to 1.9.x/1.10.6. It has been declared as critical. Affected by this issue is some unknown functionality. Such manipulation leads to memory leak. This vulnerability is documented as CVE-2
CVE-2026-6554 | Tcpdump Group libpcap up to 1.10.6 BPF Interpreter infinite loop (EUVD-2026-72019)
A vulnerability, which was classified as problematic, has been found in Tcpdump Group libpcap up to 1.10.6. The impacted element is an unknown function of the component BPF Interpreter. Performing a manipulation results in infinite loop. Th
CVE-2026-18238 | Tcpdump Group libpcap up to 1.8.x/1.9.x/1.10.6 Packet Message out-of-bounds (EUVD-2026-72021)
A vulnerability was found in Tcpdump Group libpcap up to 1.8.x/1.9.x/1.10.6. It has been classified as problematic. Affected by this vulnerability is an unknown functionality of the component Packet Message Handler. This manipulation causes
CVE-2026-86207 | N-able N-central up to 2026.3.1.7 improper authentication (EUVD-2026-72022)
A vulnerability labeled as very critical has been found in N-able N-central up to 2026.3.1.7. Impacted is an unknown function. The manipulation results in improper authentication. This vulnerability is known as CVE-2026-86207. Attacking loc
CVE-2026-70496 | Red Hat Advanced Cluster Management for Kubernetes ClusterRole privileges management (EUVD-2026-62678)
A vulnerability classified as very critical was found in Red Hat Advanced Cluster Management for Kubernetes. Impacted is an unknown function of the component ClusterRole. The manipulation results in improper privilege management. This vulne
CVE-2026-71470 | Red Hat Advanced Cluster Management for Kubernetes search-v2-operator permission (EUVD-2026-62590)
A vulnerability was found in Red Hat Advanced Cluster Management for Kubernetes. It has been declared as very critical. Affected is an unknown function of the component search-v2-operator. Executing a manipulation can lead to permission iss
CVE-2026-71469 | Red Hat Advanced Cluster Management for Kubernetes search-v2-api memory allocation (EUVD-2026-57687)
A vulnerability categorized as critical has been discovered in Red Hat Advanced Cluster Management for Kubernetes. Impacted is an unknown function of the component search-v2-api. Such manipulation leads to uncontrolled memory allocation. Th
CVE-2026-71471 | Red Hat Advanced Cluster Management for Kubernetes Search Collector.ImageOverride os command injection (EUVD-2026-57686)
A vulnerability was found in Red Hat Advanced Cluster Management for Kubernetes. It has been rated as very critical. This issue affects some unknown processing of the component Search. This manipulation of the argument Collector.ImageOverri
CVE-2026-71472 | Red Hat Advanced Cluster Management for Kubernetes Search WORK_MEM os command injection (EUVD-2026-60362)
A vulnerability labeled as very critical has been found in Red Hat Advanced Cluster Management for Kubernetes. This vulnerability affects unknown code of the component Search. Such manipulation of the argument WORK_MEM leads to os command i
CVE-2026-71473 | Red Hat Advanced Cluster Management for Kubernetes search-v2-operator privileges management (EUVD-2026-57685)
A vulnerability was found in Red Hat Advanced Cluster Management for Kubernetes. It has been declared as problematic. This vulnerability affects unknown code of the component search-v2-operator. The manipulation results in improper privileg
CVE-2026-72508 | Red Hat Advanced Cluster Management for Kubernetes multicloud-operators-subscription privileges management (EUVD-2026-57529)
A vulnerability has been found in Red Hat Advanced Cluster Management for Kubernetes and classified as very critical. The impacted element is an unknown function of the component multicloud-operators-subscription. The manipulation leads to
CVE-2026-73137 | Red Hat Advanced Cluster Management for Kubernetes multicloud-operators-subscription GetSecret secretRef.Namespace information disclosure (EUVD-2026-63590)
A vulnerability identified as problematic has been detected in Red Hat Advanced Cluster Management for Kubernetes. This affects the function GetSecret of the component multicloud-operators-subscription. The manipulation of the argument secr
CVE-2026-72526 | Red Hat Advanced Cluster Management for Kubernetes multicloud-integrations privileges management (EUVD-2026-57057)
A vulnerability marked as very critical has been reported in Red Hat Advanced Cluster Management for Kubernetes. This impacts an unknown function of the component multicloud-integrations. This manipulation causes improper privilege manageme
CVE-2026-73122 | Red Hat Advanced Cluster Management for Kubernetes multicloud-operators-channel improper authorization (EUVD-2026-57060)
A vulnerability categorized as problematic has been discovered in Red Hat Advanced Cluster Management for Kubernetes. The affected element is an unknown function of the component multicloud-operators-channel. Executing a manipulation can le
PaperCut Flaws Exploited in Attacks on U.S. and European Schools
Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-20
PaperCut Flaws Exploited in Attacks on U.S. and European Schools
Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-20
PaperCut Flaws Exploited in Attacks on U.S. and European Schools
Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-20
Broadcom schließt kritische Lücke in VMware Workstation und Fusion (CVE-2026-59346)
LONDON (IT BOLTWISE) – Broadcom hat Sicherheitsupdates für VMware Workstation und VMware Fusion veröffentlicht und schließt dabei zwei Lücken, darunter einen kritischen Integer-Overflow mit CVSS 9,3. Unter bestimmten Bedingungen kann ein An
Elementor Pro WordPress Flaw Exploited to Upload Webshells and Execute Commands
A critical vulnerability in the Elementor Pro WordPress plugin is being actively exploited to upload malicious PHP files and execute commands remotely on the affected websites. The vulnerability, tracked as CVE-2026-32475, affects the Ele
Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026
Switchvox Vulnerability Triggers Active Exploitation Risk
Sangoma Switchvox CVE-2026-9586 is a serious unauthenticated SQL injection flaw that can lead to remote code execution, and Horizon3 says it has already seen real-world exploitation attempts. The issue was patched in Switchvox 8.4.0.2, ma
CISA Flags Old ownCloud Flaw After Reported Philippine Nuclear Data Theft
CISA added CVE-2023-49105 to its exploited-flaws catalog after researchers tied the old ownCloud bug to reported Philippine nuclear data theft. This article has been indexed from Security Archives – TechRepublic Read the original article: C
Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions. This article has been indexed from SecurityWeek Read the original article: Elementor Pro WordP
Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions. The post Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites appeared first o
PaperCut-Schwachstellen: Angreifer stehlen Anmeldedaten an Schulen und Universitäten
LONDON (IT BOLTWISE) – Angreifer nutzen neu gemeldete PaperCut-Schwachstellen, um an Schulen und Universitäten in den USA und Europa Zugangsdaten auszuspähen. In den Beobachtungen wurden CVE-2026-81578 und CVE-2026-82078 für Authentifizieru
12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers
A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged replication accounts to execute attacker-controlled code, escalate to database superuser, and establish persistent backdoors on affected servers. Tracked as
12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers
A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged replication accounts to execute attacker-controlled code, escalate to database superuser, and establish persistent backdoors on affected servers. Tracked as
12-Year-Old PostgreSQL Flaw Lets Backup Accounts Execute Code and Take Over Databases
A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged backup and replication accounts to execute arbitrary code, escalate to database superuser privileges, and establish persistent access on vulnerable servers.
U.S. CISA adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Google Chromium V8 flaw, trac
Google’s Chrome Update Patches Sixth Zero-Day Exploited in 2026
Chrome users have another actively exploited zero-day to worry about, and this one sits inside the engine that powers much of the modern web. Google has patched CVE-2026-85046, a high-severity type confusion vulnerability in Chrome’s V8 Jav
CVE-2026-19949 Leaves Millions of WordPress Sites Running Vulnerable Plugin Versions
A WordPress backup tool designed to help sites recover from trouble can instead become the trigger for an attack. Researchers disclosed a high-severity SQL injection vulnerability in the All-in-One WP Migration and Backup plugin that affect
PostgreSQL stoppt Codeausführung via Logical Decoding: neuer Whitelist-Parameter
LONDON (IT BOLTWISE) – PostgreSQL schließt eine seit 2014 bekannte Schwachstelle (CVE-2026-6471), die mit dem REPLICATION-Attribut beliebigen Code im Backend-Prozess ausführen konnte. Die Absicherung erfolgt über einen neuen Parameter outpu
PostgreSQL fixiert CVE-2026-6471: REPLICATION-Benutzer können Code als DB-User ausführen
LONDON (IT BOLTWISE) – PostgreSQL hat ein Sicherheitsproblem mit der logischen Replikation geschlossen, das einem Konto mit REPLICATION-Attribut die Ausführung beliebigen Codes als OS-User des Datenbankservers ermöglicht. Betroffen sind Ver
HPE Patches Critical RCE Vulnerabilities in AOS-CX
Nearly two dozen issues, tracked collectively as CVE-2026-73749 (CVSS score of 9.8), were addressed with the updates. The post HPE Patches Critical RCE Vulnerabilities in AOS-CX appeared first on SecurityWeek. Weiterlesen
Nightmare Eclipse drops a CrowdStrike zero-day.
Extortion group leaks alleged Manchester Airports Group data. France's CNIL fines hospital over 2025 data breach. Weiterlesen
PostgreSQL Hit by 12-Year-Old Vulnerability Allowing Server Takeover
PostGREShell (CVE-2026-6471) is a 12-year-old PostgreSQL flaw that lets low-privileged attackers execute code and take over servers. Cyera researchers found a severe PostgreSQL vulnerability, dubbed PostGREShell and tracked as CVE-2026-6471