Tendências de vulnerabilidades — CVEs mais exploradas e zero-days | dbugs

#1 · PT-2026-87686 · Microsoft · Windows

CVE-2026-69730

·

Publicado

2026-09-08

·

Atualizado

2026-09-11

9.8

Crítica

Base

AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

🚨Critical - Windows DNS Server Remote Code Execution via Use-After-Free (CVE-2026-69730)
A use-after-free in the Windows DNS Server service (DNS.exe) can be triggered remotely by sending crafted DNS requests over the network, corrupting memory and leading to arbitrary code execution as SYSTEM. Clients/resolvers not running the DNS Server role are not impacted.
👉Affected: Microsoft Windows DNS Server (multiple Windows/Windows Server...
Mais

Correção

RCE

Use After Free

20 Publicações
203Republicações
223.6 K Audiência
Graph

#2 · PT-2025-48817 · Meta · React-Server-Dom-Webpack

CVE-2025-55182

·

Publicado

2025-12-03

·

Atualizado

2026-09-11

10

Crítica

Base

AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Nome do Software Vulnerável e Versões Afetadas React Server Components versões 19.0.0 a 19.2.0
Descrição Um problema de execução remota de código pré-autenticação existe nos pacotes react-server-dom-parcel, react-server-dom-turbopack e react-server-dom-webpack. O problema decorre da desserialização insegura de payloads na função requireModule() ao processar o parâmetro hasOwnProperty em requisições HTTP enviadas para...
Mais

Exploit

Correção

RCE

DoS

LPE

Deserialization of Untrusted Data

2.0 K Publicações
8.9 KRepublicações
10.1 M Audiência
Graph

#3 · PT-2026-89811 · Gitlab · Gitlab

CVE-2026-85706

·

Publicado

2026-09-11

·

Atualizado

2026-09-12

10

Crítica

Base

AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Breaking: GitLab has released patches for multiple vulnerabilities, including CVE-2026-85706 — a path-traversal flaw in the repository commits API rated CVSS 10.0. Public disclosure saw in-the-wild probes within hours, confirming active exploitation attempts that can let an unauthenticated attacker read arbitrary files on affected servers.
Expert take: treat this as critical. The attack vector targets repository API paths and can expos...
Mais

Exploit

Correção

Path traversal

39 Publicações
101Republicações
93.2 K Audiência
Graph

#4 · PT-2026-88591 · Google · Google Chrome

CVE-2026-87491

·

Publicado

2026-08-06

·

Atualizado

2026-09-12

8.8

Alta

Base

AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Google has released emergency Chrome updates addressing 230 vulnerabilities — including an actively exploited V8 out-of-bounds write tracked as CVE-2026-87491. The bug, described as a medium-severity out-of-bounds write in the V8 JavaScript/WebAssembly engine, has been used in the wild to achieve code execution inside Chrome’s renderer sandbox.
Key points:
  • Active exploit: attackers have weaponized the V8 flaw in live attacks, making...
Mais

Correção

RCE

LPE

Memory Corruption

51 Publicações
164Republicações
91.1 K Audiência
Graph

#5 · PT-2026-34274 · Linux · Linux Kernel

·

CVE-2026-31431

·

Publicado

2026-03-23

·

Atualizado

2026-09-11

7.8

Alta

Base

AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Nome do Software Vulnerável e Versões Afetadas Linux kernel versões anteriores a 7.0 Linux kernel versões anteriores a 6.19.12
Descrição Uma falha existe na interface de algoritmo criptográfico algif aead do kernel do Linux. O problema decorre de uma operação in-place incorreta durante o processamento criptográfico, onde os mapeamentos de dados de origem e destino diferem. Um invasor local com baixos privilégios pode explorar...
Mais

Exploit

Correção

RCE

DoS

LPE

Use After Free

861 Publicações
6.7 KRepublicações
5.4 M Audiência
Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph