Security & Threat Intelligence · 26.08.2026, 12:02 UTC
Exploits and vulnerabilities in Q2 2026
| Schweregrad | critical aktiv ausgenutzt (KEV) |
|---|---|
| CVSS | 9.0 |
| CVE | ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ ↗ |
| Kategorie | Security & Threat Intelligence |
| Quelle | Securelist (Kaspersky) ↗ |
| Veröffentlicht | 26.08.2026 UTC |
Sicherheitsmeldung mit Schweregrad kritisch (CVSS 9.0). Sie wird laut CISA-KEV aktiv ausgenutzt und sollte priorisiert behandelt werden. Betroffene Kennungen: CVE-2017-0199, CVE-2017-11882, CVE-2018-0802, CVE-2019-13272, CVE-2021-22555. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
The vulnerability landscape shifted significantly in Q2 2026. First, the number of registered CVEs reached an unprecedented level. This is driven primarily by the widespread adoption of AI, both for application development and search for security flaws. This resulted in entire new classes of vulnerabilities emerging, particularly in the Linux networking subsystem. Second, security researchers have been publishing exploits for unpatched vulnerabilities more frequently. Publications like these can generate significant fallout, since they potentially open the door for attackers to target unprotected systems. Statistics on registered vulnerabilities This section provides statistical data on registered vulnerabilities. The data comes from Kaspersky’s vulnerability knowledge base, which draws on the CVE database as well as the Russian BDU database and GitHub Advisory (GHSA). As a result, the figures for previous reporting periods may differ from those published in earlier reports. We examine the number of registered vulnerabilities for each month over the last five years. As the chart below shows, this number continues to surge, a trend reflected across all the databases we track. It’s driven primarily by the widespread adoption of AI tools: as we predicted in our previous report, these tools have played a major role in the discovery of vulnerabilities in third-party software. Meanwhile, these tools often contain security issues of their own. For example, OpenClaw, a popular AI project, ranked 12th among those with the highest number of vulnerabilities discovered and published …
Maßnahmen
⬇ Als MarkdownVerwandte Beiträge
- high Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeter
- info USN-8678-2: OpenSSL, OpenSSL 1.0 vulnerabilities
- info USN-8681-1: OpenJDK 25 vulnerabilities
- info Choose your fighter: Balancing competing requirements to select models for your AI SOC