Ausgenutzte Cisco-ISE-Schwachstelle löst Angriffswelle auf vertrauenswürdige Softwarekanäle aus
CVE-2026-76460 in Cisco ISE wird aktiv ausgenutzt. Der Artikel erläutert Risiken, weitere RCE-Lücken und wichtige Schutzmaßnahmen.
Illustration mit KI erzeugt
Am 21. September 2026 festgestellte Sicherheitsaktivitäten zeigen, dass Angreifer vertrauenswürdige Infrastrukturen wiederholt als Mechanismus für den Erstzugriff missbrauchen. Management-APIs, Plugins für KI-Agenten, Browser-Erweiterungen, eingebettete Website-Skripte und legitime Cloud-Dienste spielen in den jüngsten Kampagnen allesamt eine Rolle.
Das dringendste Problem ist CVE-2026-76460, eine Authentifizierungsumgehung mit einem CVSS-Wert von 10,0, die Cisco Identity Services Engine betrifft. Cisco hat die aktive Ausnutzung bestätigt. Zudem hat die Cybersecurity and Infrastructure Security Agency die Schwachstelle in ihren Katalog der bekannten, aktiv ausgenutzten Schwachstellen aufgenommen.
Zu den weiteren unmittelbaren Risiken zählen die nicht authentifizierte Ausführung von Code in Orkes Conductor, eine Schwachstelle durch fehlerhaft formatierte Bilder in libheif und Discourse sowie eine Supply-Chain-Technik für KI-Plugins, mit der sich fest verankerter Code unbemerkt ersetzen lässt.
Cisco-ISE-API-Schwachstelle wird bereits ausgenutzt
CVE-2026-76460 betrifft zwei Produkte in Version 3.1.0:
- Cisco Identity Services Engine 3.1.0
- Cisco Identity Services Engine Passive Identity Connector 3.1.0
Die Schwachstelle entsteht durch unzureichende Authentifizierungskontrollen an einem API-Endpunkt. Ein Angreifer aus der Ferne kann ohne Zugangsdaten eine speziell präparierte Anfrage senden, die Authentifizierung umgehen und sich über die webbasierte Management-Oberfläche unbefugten Zugriff verschaffen.
Der CVSS-3.1-Vektor lautet CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. Die Bewertung beschreibt einen über das Netzwerk erreichbaren Angriff mit geringer Komplexität, für den weder Berechtigungen noch eine Benutzerinteraktion erforderlich sind und der potenziell schwerwiegende Auswirkungen auf Vertraulichkeit, Integrität und Verfügbarkeit hat. Die Schwachstelle ist als CWE-648 klassifiziert.
Die CISA nahm die Schwachstelle am 16. September 2026 in den KEV-Katalog auf und setzte für US-Bundesbehörden den 19. September 2026 als Frist für die Behebung fest. Zu den erforderlichen Maßnahmen gehören die Umsetzung der Cisco-Mitigationsanweisungen, der risikobasierten Patch-Vorgaben aus BOD 26-04 sowie der Anforderungen der CISA zur forensischen Triage. Organisationen müssen die Nutzung einstellen, falls keine wirksame Mitigation verfügbar ist.
Die betroffenen Versionen sind bekannt, eine konkrete behobene Cisco-Version geht aus den verfügbaren Informationen jedoch nicht hervor. Administratoren sollten sich daher an den aktuellen Anweisungen des Herstellers orientieren, statt daraus eine sichere Versionsgrenze abzuleiten.
Da die Ausnutzung bestätigt wurde, sollte die Reaktion über das Einspielen von Patches hinausgehen. Sicherheitsteams sollten die ISE-API-Aktivitäten, die Erreichbarkeit der Management-Oberfläche und Authentifizierungsprotokolle auf unerwartete Zugriffe untersuchen. Internetexponierte oder weitreichend erreichbare Management-Dienste genießen dabei höchste Priorität.
Dies ist bei den beteiligten Herstellern keine isolierte KEV-Entwicklung. In den vergangenen 90 Tagen wurden auch CVE-2025-39682, CVE-2025-39964, CVE-2026-53266, CVE-2026-87886, CVE-2026-76461 und CVE-2026-87491 für Produkte von Linux, Google und Cisco in den Katalog aufgenommen. CVE-2026-76461, eine weitere Cisco-Kennung, wurde am 14. September 2026 hinzugefügt.
Orkes und Discourse sind von separaten Pfaden zur Remote-Code-Ausführung betroffen
Die neu offengelegte CVE-2026-58138 betrifft Orkes Conductor ab Version 3.21.21 bis einschließlich vor 3.30.2. Sie weist einen CVSS-Wert von 9,8 auf und ermöglicht es nicht authentifizierten Angreifern, über die Workflow-API Betriebssystembefehle auszuführen.
Das Problem betrifft nicht in einer Sandbox ausgeführte GraalVM-Evaluatoren, die mit HostAccess.ALL oder allowAllAccess(true) konfiguriert sind. Noch vor der Authentifizierung kann ein Angreifer Inline-Workflow-Definitionen mit schädlichen JavaScript- oder Python-Ausdrücken übermitteln.
Zu den betroffenen Ausführungspfaden gehören die Aufgabentypen INLINE, LAMBDA, DO_WHILE und SWITCH. Schädliche Ausdrücke können auf Java-Reflection zugreifen oder direkt Subprozesse aufrufen und so die Workflow-Auswertung in eine beliebige Befehlsausführung verwandeln.
Bereitstellungen von Orkes Conductor sollten auf Version 3.30.2 oder höher aktualisiert werden. Betreiber sollten den nicht authentifizierten Zugriff auf Workflow-APIs zusätzlich einschränken und eingereichte Definitionen auf unerwartete Skripte, Reflection, Evaluator- oder Subprozessaktivitäten prüfen.
Eine andere Angriffsfläche zeigt sich bei CVE-2026-32882, einem Heap-Buffer-Over-Read in libheif, der durch fehlerhaft formatierte HEIF-Bilder ausgelöst wird. Betroffen sind Upstream-Versionen von libheif bis einschließlich 1.21.2; libheif 1.22.0 gilt als korrigierte Upstream-Version.
Der Fehler tritt in HeifPixelImage::overlay() auf. Verwendet ein untergeordnetes Overlay-Bild unterschiedliche Bit-Tiefen für Alpha- und Farbkanäle, indiziert die Funktion die Alpha-Ebene anhand des Strides des Farbkanals statt anhand von alpha_stride. Bei einer dokumentierten Bildkonfiguration mit 100 × 50 Pixeln kann der daraus resultierende Out-of-Bounds-Read 3.123 Bytes über den Alpha-Puffer hinausgehen.
Die Upstream-Bewertung liegt bei CVSS 7,1. Die Discourse-Sicherheitsmitteilung bewertet die Auswirkungen auf Produktebene jedoch mit 8,8 und beschreibt eine Remote-Code-Ausführung über Bild-Uploads. Die unterschiedlichen Werte ergeben sich daraus, dass jeweils ein anderer Ausnutzungskontext bewertet wird.
Korrigierte Discourse-Versionen sind 2026.7.0, 2026.6.1, 2026.5.2 und 2026.1.6. Installationen auf Docker-Basis können wie gewohnt neu erstellt werden:
./launcher rebuild app
Unterstützte Discourse-Core-Versionen verarbeiten Bilder außerdem in einer Sandbox, sofern der zugrunde liegende Kernel dies unterstützt.
Hacktron berichtete unabhängig davon, die libheif-Schwachstelle mit einer falsch konfigurierten SSO-Umgebung verkettet zu haben, um auf ChatGPT-Konten von OpenAI-Mitarbeitern und interne Repositories zuzugreifen. Die gemeldeten Probleme wurden 14 Stunden nach der verantwortungsvollen Offenlegung behoben.
Plugin4Shell untergräbt das Vertrauen in fest verankerte Erweiterungen für KI-Agenten
Plugin4Shell ist eine Zero-Click-Supply-Chain-Technik, von der vier Umgebungen für KI-Programmierung betroffen sind:
- Claude Code
- OpenAI Codex
- GitHub Copilot
- Google Gemini CLI
Der Angriff hebelt den Schutz aus, den das Festpinnen von Plugin-SHA-Werten bieten soll. Ein Agent prüft zwar die von einem Marktplatz bereitgestellte Commit-Referenz, stellt jedoch nicht unabhängig fest, ob tatsächlich der erwartete Commit aus dem Repository bezogen wurde.
Ein Angreifer, der dieses Repository kontrolliert, kann den Checkout daher auf schädliche Inhalte verweisen lassen, während der aufgezeichnete SHA weiterhin legitim erscheint. Das Ersatz-Plugin wird anschließend installiert und ausgeführt, ohne dass ein Benutzer klicken muss.
Betroffene Versionen und Grenzen der korrigierten Versionen wurden nicht offengelegt. Benutzer müssen die Agent-Software gemäß den Anweisungen des jeweiligen Anbieters aktualisieren. Eine Validierung ausschließlich auf Marktplatzseite kann einen Verifizierungsfehler innerhalb des Clients nicht beheben.
Unternehmen sollten Plugins wie ausführbare Softwareabhängigkeiten behandeln. Eigentümerschaft an Repositories, Schreibberechtigungen und die Herkunft von Plugins erfordern dieselben Kontrollen wie interne Pakete. Die Überwachung sollte außerdem Prozesse und ausgehende Netzwerkverbindungen erfassen, die von Coding-Agenten erstellt werden, insbesondere nach der Installation oder Aktualisierung von Plugins.
ClickFix-Kampagnen verlagern sich über Cloud-Dienste und eingebettete Skripte
Ein Supply-Chain-Kompromiss bei Brevo zeigt, wie ein einzelner Cloud-Schlüssel sowohl einen Anbieter als auch dessen Kunden gefährden kann. Am 14. September 2026 nutzte ein Angreifer einen kompromittierten Brevo-Cloudflare-API-Schlüssel, um einen Worker im Konto des Unternehmens bereitzustellen.
Etwa fünf Stunden und 30 Minuten lang veränderte der Worker Seiten auf brevo.com, Seiten auf sibforms.com sowie drei von Kunden eingebettete JavaScript-Dateien. Mehr als 100.000 Websites waren dem eingeschleusten Code ausgesetzt.
Ausgewählten Besuchern wurde ein gefälschtes Cloudflare-CAPTCHA angezeigt, das sie aufforderte, einen schädlichen Befehl einzufügen und auszuführen. Website-Administratoren konnten beim Besuch ihrer eigenen Websites außerdem ein schädliches WordPress-Plugin erhalten.
Dieser Vorfall steht getrennt von Brevos früherem SAML-SSO-Kompromiss. Davon waren 138 Konten betroffen; sechs Konten wurden für Phishing missbraucht und aus 43 Konten wurden Kontakte exportiert.
Bei einer weiteren ClickFix-Aktivität wurde ein legitimes Google Doc genutzt, um einen Sicherheitsforscher anzugreifen. Ein gebundenes Google Apps Script zeigte eine benutzerdefinierte Seitenleiste mit einem vorgetäuschten Entschlüsselungsfehler und Anweisungen zum Einfügen von Befehlen in Terminal. Die Payload unterschied sich je nach Plattform: AMOS-Infostealer für macOS und eine PowerShell-Loader-Kette für Windows.
Eine Kampagne zum Diebstahl von Kryptowährungen nutzte eine weitere Variante. Sie rief verschleiertes JavaScript über die Google Visualization API ab und versuchte, Opfer dazu zu bewegen, Code in Chrome einzufügen oder ihn über Tampermonkey zu installieren, das ebenfalls für Persistenz sorgte.
Diese Angriffe sind nicht auf einen herkömmlichen Browser-Exploit angewiesen. Ihr gemeinsamer Kontrollpunkt ist die Benutzeranweisung. Legitime CAPTCHA-, Dokumentenreparatur- und Software-Update-Prozesse verlangen von Benutzern nicht, beliebigen Code in PowerShell, Terminal, eine Adressleiste oder eine Erweiterungskonsole einzufügen.
Browserzugriff und angrenzende Angriffe vergrößern die Angriffsfläche
Das Banking-Malware-Toolkit KREMLIN installiert schädliche Erweiterungen in Google Chrome und Microsoft Edge. Die seit mindestens Mai 2025 aktive und als REF9334 erfasste Operation gibt sich als etwa ein Dutzend brasilianischer Banken aus.
Die mehrstufigen JavaScript-Loader und benutzerdefinierten C++-Installer installieren Erweiterungen, die Zugangsdaten, Sitzungstoken und andere im Browser gespeicherte Daten stehlen können. Bei Verdacht auf eine Betroffenheit sollten nicht autorisierte Erweiterungen entfernt, Browsersitzungen ungültig gemacht und Token ausgetauscht werden.
Zwei weitere KEV- und Plattformprobleme erfordern Aufmerksamkeit. CVE-2026-58704 mit einem CVSS-Wert von 8,8 ist eine Berechtigungsumgehung im Google Android Cellular Modem. Sie erfordert Zugriff aus einem benachbarten Netzwerk, jedoch weder Berechtigungen noch eine Benutzerinteraktion. Die CISA nahm die Schwachstelle am 16. September 2026 in den KEV-Katalog auf und setzte den 19. September als Frist für die Behebung fest.
CVE-2026-82079 betrifft Nintendo-Switch-Versionen vor 23.0.0. Ein Angreifer in Funkreichweite kann speziell präparierten Datenverkehr an das lokale Funksubsystem senden und einen Stack-Buffer-Overflow ausnutzen, um mithilfe von Return-Oriented Programming Code auszuführen. Eine Aktualisierung auf Version 23.0.0 oder höher behebt den dokumentierten betroffenen Versionsbereich.
Schließlich ermöglicht CVE-2026-90894, auch als ParaShells bekannt, eine lokale Rechteausweitung über den Root-Dienst prl_disp_service von Parallels Desktop. Bis eine Behebung durch den Hersteller verfügbar ist, sollten Organisationen den Zugriff durch nicht vertrauenswürdige lokale Benutzer einschränken und auf ungewöhnliche Appliance-Installationen, die Ausführung von tar oder Root-Kinderprozesse achten.
Die operative Priorität ist eindeutig: Zuerst müssen die im KEV-Katalog aufgeführten Cisco- und Android-Schwachstellen behoben werden. Anschließend sollten die nicht authentifizierte Workflow-Ausführung, die Gefährdung durch die Bildverarbeitung und kompromittierte Software-Vertriebskanäle adressiert werden. Vertrauenswürdige Schnittstellen nehmen den Angreifern einen Großteil der Arbeit ab.
Quellen
Dieser Artikel ist eine eigenständige Aufbereitung auf Basis der folgenden Quellen.
- PrimärquelleGitHub Security Advisory
- The Hacker News
In diesem Artikel behandelte CVEs
- CVE-2026-85061Kritisch10.0MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.4.1, DOM.sanitize() in src/util/dom.ts iterates elem.attributes as a live NamedNodeMap while removeAttributes() removes attributes from the same collection, shifting indexes and skipping an adjacent dangerous attri
- CVE-2026-76460Kritisch10.0A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted reques
- CVE-2026-70416Kritisch10.0Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
- CVE-2026-68488Kritisch9.9A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover.
- CVE-2026-89049Kritisch9.9A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agent) before 3.3.4851.0 on all platforms might allow an authenticated remote user to bypass the remote d
- CVE-2026-91998Kritisch9.9Casdoor through 4.4.0 contains an authorization bypass vulnerability in the /api/mcp endpoint that allows attackers with any application's clientId and clientSecret to gain unrestricted access to user administration across all organizations. Attackers can enumerate user records including password sa
- CVE-2026-76672Kritisch9.9A vulnerability exists in the SD-WAN Orchestrator that may lead to the exposure of sensitive configuration information. An authenticated remote attacker with read-only privileges could exploit this vulnerability by sending a specially crafted request to the cache synchronization endpoint. Successful
- CVE-2026-76669Kritisch9.9Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. Successful exploitation could allow a remote low-privileged authenticated user to escalate their privileges to those of an administrative user, leading to complete system compromise.
- CVE-2026-76670Kritisch9.9Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. Successful exploitation could allow a remote low-privileged authenticated user to escalate their privileges to those of an administrative user, leading to complete system compromise.
- CVE-2025-39682Kritisch9.8In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process either - only contiguous DATA records (any number of them) - one non-DATA record If the next record has different type than what has alrea
- CVE-2026-28323Kritisch9.8SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled.
- CVE-2026-65400Kritisch9.8An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1, macOS Tahoe 26.7. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.
- CVE-2026-58138Kritisch9.8Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS commands by submitting inline workflow definitions containing malicious JavaScript or Python expressions to the workflow API endpoint prior to au
- CVE-2026-80172Kritisch9.8Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insufficient Verification of Data Authenticity vulnerability. An unauthenticated attacker with remote access could exploit this, leading to unauthorized access. This vulnerabili
- CVE-2026-82232Kritisch9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging unsanitized sort clauses for Task search. This issue affects Ap
- CVE-2026-76461Kritisch9.8A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email pa
- CVE-2026-65414Kritisch9.8An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. A remote attacker may be able to cause unexpected app termina
- CVE-2026-89026Kritisch9.8The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote attackers to forge valid bearer tokens. Attackers can
- CVE-2026-81642Kritisch9.8In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC validator that enables denial of service and possible remote code execution as a result of digesting DNSKEYs. A DNSKEY with an owner compression pointer to its own RDATA can overflow the digest buffer. Remote c
- CVE-2026-39919Kritisch9.8Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG 2000 output adapter (base/sjpx_openjpeg.c) that allows attackers to cause memory corruption by supplying a crafted PDF containing a JPEG 2000 image with mismatched component subsampling factors. When image com
- CVE-2026-91843Kritisch9.8A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.
- CVE-2026-90999Kritisch9.8Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled telemetry to become code that is executed by an agent in a privileged automation environment. An external attacker can submit fabricated Sentry events without having access to the vict
- CVE-2026-76673Kritisch9.8Vulnerabilities have been identified in the API of EdgeConnect SD-WAN Orchestrator that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compro
- CVE-2026-76674Kritisch9.8Buffer overflow vulnerabilities exist in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated remote attacker to execute arbitrary code. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operat
- CVE-2026-91749Kritisch9.6Use after free in Workers in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
- CVE-2026-93372Kritisch9.6Buffer overflow in WebGL in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
- CVE-2026-93374Kritisch9.6Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
- CVE-2026-61410Kritisch9.4Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authorization vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution. This vulnerability
- CVE-2026-80238Kritisch9.3Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Execution with Unnecessary Privileges vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Protection mechanism
- CVE-2026-43790Kritisch9.1The issue was addressed with improved memory handling. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.
- CVE-2026-92034Kritisch9.1Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
- CVE-2026-92038Kritisch9.1Mitigation bypass in the Remote Settings Client component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
- CVE-2026-28309Kritisch9.1SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. The impact is lower in Windows deployments.
- CVE-2026-28306Kritisch9.1SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system administrator. The impact is lower in Windows deployments.
- CVE-2026-28308Kritisch9.1SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrator access is required. The impact is lower in Windows deployments.
- CVE-2026-28310Kritisch9.1SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate their user type to that of a system administrator. The impact is lower in Windows deployments.
- CVE-2026-28314Kritisch9.1SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. User authentication is required. The impact is lower in Windows deployments.
- CVE-2026-28313Kritisch9.1SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary account takeover. The impact is lower in Windows deployments.
- CVE-2026-28307Kritisch9.1SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator group. The impact is lower in Windows deployments.
- CVE-2026-28305Kritisch9.1SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution as root. A domain account with admin privileges and read and write access to the home directory is required. The impact is lower in Windows deployments.
- CVE-2026-28317Kritisch9.1SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires domain administrator access. The impact is lower in Windows deployments.
- CVE-2026-28304Kritisch9.1SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary execution of code remotely as root. The impact is lower in Windows deployments.
- CVE-2026-28312Kritisch9.1SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system administrator and allow code execution as root. The impact is lower in Windows deployments.
- CVE-2026-28316Kritisch9.1SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability to execute commands as the root user. This issue requires a domain account with administrator access. The impact is lower in Wind
- CVE-2026-28302Kritisch9.1SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root. This issue requires group administrator access. The impact is lower in Windows deployments.
- CVE-2026-28321Kritisch9.1SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate privileges and execute code as root. A domain administrator access is required, and the impact is lower in Windows installations.
- CVE-2026-85982Kritisch9.0The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) issues due to improper HTML encoding of data in search results and updater log content displayed in the admin panel. An authenticated user with privileges to modify directory attributes, or a low-privileged local user on
- CVE-2026-74469Hoch8.8In the Linux kernel, the following vulnerability has been resolved: sctp: prevent peer transport count overflow sctp_assoc_add_peer() increments the association's 16-bit transport_count for every new unique peer. Adding the 65,536th transport wraps the count to zero. SCTP sock_diag uses transport
- CVE-2026-65346Hoch8.8An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing an image may lead to arbitrary code execution.
- CVE-2026-15315Hoch8.8Tapo C120 v1 and C200 v5 contain an improper authentication vulnerability within the login authentication verification module. An attacker on the local network can exploit weaknesses in challenge parameter validation to bypass normal authentication controls and obtain administrative session tokens.
- CVE-2026-87491Hoch8.8Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-73693Hoch8.8FileRun before 2026.3.0 contains an OS command injection vulnerability in the PhotoProofSheet handler that allows authenticated users with upload permission to execute arbitrary commands by uploading files with shell metacharacters in their names. Attackers can upload a file containing command subst
- CVE-2026-78175Hoch8.8The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.0.7 via the `withdraw_method_field` parameter of the `tutor_save_withdraw_account` AJAX handler. This is due to the handler lacking any capability o
- CVE-2026-58704Hoch8.8In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2026-53266Hoch8.8In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0). This is intentional: at the bridge ebtables hooks the Ethernet header is
- CVE-2026-92013Hoch8.8Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
- CVE-2026-92015Hoch8.8Privilege escalation in the WebExtensions component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
- CVE-2026-92020Hoch8.8Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
- CVE-2026-92022Hoch8.8Use-after-free in the DOM: HTML Parser component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
- CVE-2026-92029Hoch8.8Use-after-free in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
- CVE-2026-92033Hoch8.8Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 156.
- CVE-2026-91721Hoch8.8Use after free in Internals in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
- CVE-2026-28326Hoch8.8SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The issue stems from a hardcoded static key.
- CVE-2026-18851Hoch8.8Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2, and 12.8.0.4 allows a remote authenticated attacker to escalate their privileges to admin.
- CVE-2026-91931Hoch8.5Flowise before 3.1.4 contains a remote code execution vulnerability in the Custom MCP node that allows authenticated attackers to execute arbitrary code by supplying npx package names in the mcpServerConfig parameter. Attackers can invoke npx with attacker-controlled npm packages to execute code on
- CVE-2026-91932Hoch8.5Flowise before 3.1.4 contains a validation bypass vulnerability in MCP server configuration allowing authenticated attackers remote code execution through an unvalidated cwd parameter. Attackers can bypass path validation using clean filenames in the args array while controlling the working director
- CVE-2026-82079Hoch8.4A stack-based buffer overflow vulnerability in the Nintendo Switch local wireless networking functionality may allow an attacker within wireless range to execute arbitrary code using return-oriented programming (ROP) through crafted network traffic. This issue affects Nintendo Switch: before 23.0.0.
- CVE-2026-78626Hoch8.1The Okta Access Gateway improperly handles input sanitization and regular expression evaluation within its Protected Rule authorization check, resulting in an authorization bypass when an administrator has explicitly configured a Protected Rule policy on one or more application resources.
- CVE-2025-43936Hoch8.1Dell ObjectScale, versions prior to ObjectScale 4.4.0.0, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
- CVE-2025-39964Hoch7.8In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsiste
- CVE-2026-68121Hoch7.8In the Linux kernel, the following vulnerability has been resolved: pppoe: reload header pointer after dev_hard_header() pppoe_sendmsg() saves a pointer to the PPPoE header before calling dev_hard_header(). Device header callbacks are allowed to reallocate the skb head, invalidating pointers into
- CVE-2026-81000Hoch7.8In the Linux kernel, the following vulnerability has been resolved: net: tun: bound receive headroom tun_get_user() uses tun->align both as skb headroom and when choosing how much packet data to keep linear. OVS can propagate an oversized headroom request from another port to TUN or TAP. When ali
- CVE-2026-90894Hoch7.8Parallels Desktop runs prl_disp_service as root. Local clients reach it on the world-writable socket /var/run/prl_disp_service.socket. PrlSrv_LoginLocal accepts peer credentials. No Parallels signature. No admin group. After login, PrlSrv_InstallAppliance lets you pick the appliance folder (sVmPa
- CVE-2026-43502Hoch7.8In the Linux kernel, the following vulnerability has been resolved: net/rds: handle zerocopy send cleanup before the message is queued A zerocopy send can fail after user pages have been pinned but before the message is attached to the sending socket. The purge path currently infers zerocopy stat
- CVE-2026-84607Hoch7.8A race condition was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. A sandboxed app may be able to execute arbitrary code with kernel privil
- CVE-2026-87886Hoch7.8Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2
- CVE-2026-78623Hoch7.7The Okta Access Gateway does not sanitize SAML assertion values before interpolating them into database queries in the advanced mode datastore configuration. The unsanitized values are substituted directly into the query string prior to preparation, resulting in unintended SQL execution against the
- CVE-2026-73178Hoch7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Syncope. An administrator with adequate entitlements can get access via REST to the list of existing Access Tokens, including their signed JWT body. These values can be then used to perform further REST requests, imp
- CVE-2026-19667Hoch7.5If an attacker-controlled authoritative server can produce a negative answer that is exactly 65536 bytes, then a flaw in `named` results in a negative cache entry of 0 bytes. When this entry is subsequently read, `named` aborts. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 throu
- CVE-2026-77692Hoch7.5An attacker can cause `named` to abort by sending a crafted DNS-over-HTTPS request with a cryptographically invalid SIG(0) record, and then closing the transport connection prematurely. This issue affects BIND 9 versions 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, and 9.20.9-S1 through 9.20.27-S
- CVE-2026-19666Hoch7.5On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the resolver `named` process will exit unexpectedly. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 t
- CVE-2026-76163Hoch7.5If BIND is loaded with a "`named.conf`" file that contains no global "`options`" block, an attacker can send a query of QTYPE TKEY which may cause an assertion failure and subsequent unexpected program exit. This issue affects BIND 9 versions 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, and 9.20.
- CVE-2026-80274Hoch7.5If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a valid wildcard answer and signed NSEC3 proof, followed by an unsigned NSEC at the same owner name, it will trigger an unexpected program exit. This issue affects BIND 9 versions 9.11.
- CVE-2026-73694Hoch7.2FileRun before 2026.3.0 contains an OS command injection vulnerability caused by a no-op redefinition of escapeshellcmd() in CLI.php that strips shell-metacharacter escaping, allowing attacker-controlled input to reach an exec() sink unsanitized. Attackers can exploit this through an interactive pat
- CVE-2026-73698Hoch7.2FileRun before 2026.3.0 contains a SQL injection vulnerability that allows delegated or simple administrators to execute arbitrary SQL by submitting the description parameter as an array, causing the getValuesString() method in DB/DP.php to interpolate raw array values directly into an INSERT statem
- CVE-2026-73699Hoch7.2FileRun before 2026.3.0 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary code by exploiting incorrect options passed to unserialize() in the Perms::getPerms() method, where a positional array is used instead of the required named-key array to dis
- CVE-2026-32882Hoch7.1libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap buffer over-read in HeifPixelImage::overlay() in libheif/pixelimage.cc. When compositing an overlay image (iovl) whose child image has a different bit depth for the alpha channel than for the color c
- CVE-2026-56711Hoch7.0VLC media player versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing crafted media. Exploitation requires user interaction and may result in application termination or code execution with the privileges of the VLC process.
- CVE-2026-65812Mittel6.8Insertion of sensitive information into sent data in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
- CVE-2026-15316Mittel6.5An improper input validation vulnerability in the configuration service for processing encrypted credential data has been identified in Tapo C200 v5. An attacker can send oversized crypted ciphertext values that may trigger exception handling failures, due to insufficient validation, causing the af
- CVE-2026-77147Mittel6.5Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy Command class containing untrusted code in their CommandArgs static implementation, bypassing the Groovy security
- CVE-2026-28315Mittel6.2SolarWinds Serv-U was found to be affected by a stored cross-site scripting vulnerability that could lead to session hijacking or information disclosure from an administrator account.
- CVE-2026-92005Mittel5.3Use-after-free in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
- CVE-2026-91726Mittel4.7Out of bounds read in WebGL in Google Chrome on on Android prior to 153.0.8010.47 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
- CVE-2026-73324Mittel4.3Certain VLC media player builds in versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing media from an attacker-controlled network source. Exploitation requires user interaction and may disclose a limited, layout-dependent amount of VLC process memory. Exposur
- CVE-2026-80844In the Linux kernel, the following vulnerability has been resolved: xfrm: ah6: validate routing header segments_left AH6 rearranges routing-header addresses before computing or verifying the ICV. ipv6_rearrange_rthdr() assumes that segments_left is not larger than the number of addresses described
- CVE-2026-0310A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service (DoS) condition on VM-Series firewalls or execute arbitrary cod
- CVE-2026-65638Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to execute arbitrary commands as the CSF service account via shell command injection. The vulnerability affects versions of the software originally distributed by ConfigServer, as well
- CVE-2026-82717In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in that can progressively corrupt heap memory and under certain systems and compilation options could lead to remote code execution. The vulnerability starts when CNAME synthesis during an upstream response needs to enforce(
- CVE-2026-77179On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a symlink, escape the shared workspace, and read or modify arbitrary host files as the VMM user, potentia
