vulnerability Vulnérabilité dans les produits Cisco (12 août 2026) A vulnerability in Cisco’s Adaptive Security Appliance (ASA) allows attackers to trigger a denial-of-service attack. Cisco has confirmed that this vulnerability is actively being exploited, and users are urged to apply t… CERT-FR · Aug 12, 2026 High CVE-2026-20349ciscoasavulnerability
vulnerability Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities Microsoft released its August 2026 security update, containing 421 vulnerabilities across a wide range of products, with 62 marked as critical. Several vulnerabilities, including those affecting Windows, SharePoint, Azur… Cisco Talos · Aug 11, 2026 High CVE-2026-68820CVE-2026-62893CVE-2026-65665vulnerabilityremote code executionprivilege escalation
vulnerability 421 bugs in Microsoft's Patch Tuesday release, and the Norks have already attacked one Microsoft released a Patch Tuesday update containing 421 bugs, and a group known as ‘The Norks’ has already exploited one of these vulnerabilities to launch an attack. This highlights a continuing issue with Microsoft’s… The Register · Aug 11, 2026 High CVE-2026-68820CVE-2026-62832CVE-2026-62893microsoftpatch tuesdayvulnerability
vulnerability Microsoft Plugs Nearly 400 Security Holes Microsoft released a massive update bundle addressing 398 security vulnerabilities, including one actively exploited and two previously disclosed flaws. Despite the sheer volume of fixes, only one of these vulnerabilitie… Krebs on Security · Aug 11, 2026 High CVE-2026-68820CVE-2026-62832CVE-2026-72971patch tuesdayvulnerabilityai
vulnerability Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack Microsoft released a security update containing 398 new vulnerabilities, with one zero-day flaw actively being exploited by Check Point Research's Lazarus group as part of Operation Dream Job. This zero-day (CVE-2026-688… The Hacker News · Aug 11, 2026 High CVE-2026-68820CVE-2026-62878CVE-2026-62893zero-dayrceexploit
vulnerability Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client A Security, an Israeli offensive-security startup, discovered three Zoom vulnerabilities that could allow a meeting participant to hijack another attendee’s computer. The flaws, including a buffer over-write and a use-af… The Hacker News · Aug 11, 2026 High CVE-2026-53413CVE-2026-53414CVE-2026-53415ISzoomvulnerabilitybuffer overflow
vulnerability August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day Microsoft released a substantial update addressing 421 vulnerabilities, including a critical zero-day exploit in a kernel-mode driver (afd.sys). Threat actors, potentially including nation-state actors like those linked… SecurityWeek · Aug 11, 2026 High CVE-2026-68820CVE-2025-32709CVE-2025-21418zero-daykernel-modeprivilege escalation
vulnerability Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws Adobe has released critical patches to address over 50 vulnerabilities across its products, including significant flaws in ColdFusion and Campaign Classic. These vulnerabilities could lead to code execution and denial-of… SecurityWeek · Aug 11, 2026 High CVE-2026-48362CVE-2026-48273CVE-2026-71384vulnerabilitypatchsecurity
vulnerability Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE Researchers at Rapid7 discovered a chain of vulnerabilities in Microsoft SharePoint, allowing unauthenticated attackers to impersonate users, including administrators, through a complex AI-assisted process. The initial b… The Hacker News · Aug 11, 2026 High CVE-2026-55040CVE-2026-63520jwtsharepointrce
vulnerability Zoom Patches Zero-Click Code Execution Vulnerability Zoom has released patches to address four critical vulnerabilities, including a zero-click remote code execution flaw that could allow an attacker to take control of any participant’s machine without any user interaction… SecurityWeek · Aug 11, 2026 Critical CVE-2026-53413CVE-2026-53414CVE-2026-53415vulnerabilityremote code executionzero-click
vulnerability SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities SAP released 28 security notes on August 2026 Patch Day to address a range of critical vulnerabilities across its products, including SAP Commerce Cloud, NetWeaver Application Server ABAP, and ABAP Platform. These flaws… SecurityWeek · Aug 11, 2026 Critical CVE-2026-58231CVE-2026-44772CVE-2026-44758vulnerabilitypatchcode injection
vulnerability Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo Mozilla has revoked a cryptographic key used to sign Firefox and Thunderbird downloads for Linux after an unencrypted copy was accidentally committed to a private repository. This affects older downloads and requires man… The Hacker News · Aug 11, 2026 High gpgkey revocationgithub breach
vulnerability Pulsetto Vagus Nerve Stimulator A critical vulnerability (CVE-2026-18844) exists in Pulsetto Vagus Nerve Stimulator devices, allowing attackers to bypass security measures and manipulate device settings via Bluetooth Low Energy (BLE). The vulnerability… CISA Advisories · Aug 11, 2026 Critical CVE-2026-18844LIbluetoothcvecontrol systems
vulnerability Mira Hormone Monitor, Mira Android App Multiple vulnerabilities in the Mira Hormone Monitor and Mira Android App allow an attacker to access unauthorized health profile information, make changes to health data, cause denial-of-service conditions, and potentia… CISA Advisories · Aug 11, 2026 High CVE-2026-66875CVE-2026-66098CVE-2026-67558bleauthenticationwebview
vulnerability ISC Stormcast For Tuesday, August 11th, 2026 https://isc.sans.edu/podcastdetail/10046, (Tue, Aug 11th) The ISC Stormcast highlighted a significant vulnerability in the latest version of Apache Log4j 2, potentially allowing attackers to execute arbitrary code through a malicious log message. This vulnerability, alongside r… SANS Internet Storm Center · Aug 11, 2026 Critical log4jrcevulnerability
vulnerability Multiples vulnérabilités dans Postfix (11 août 2026) Multiple vulnerabilities have been discovered in Postfix, potentially allowing attackers to cause a denial-of-service, bypass security policies, and create an unspecified security issue. Users of Postfix versions prior t… CERT-FR · Aug 11, 2026 Medium vulnerabilitymail serversecurity
vulnerability Vulnérabilité dans CPython (11 août 2026) A denial-of-service vulnerability has been identified in CPython, allowing an attacker to disrupt remote systems. The vulnerability stems from a lack of recent security updates and requires immediate patching to prevent… CERT-FR · Aug 11, 2026 Medium CVE-2026-18503pythondenial-of-servicevulnerability
vulnerability Vulnérabilité dans Docker (11 août 2026) A vulnerability has been identified in Docker Desktop, allowing an attacker to compromise data integrity. Users of versions prior to 4.86.0 should immediately update to mitigate the risk. CERT-FR · Aug 11, 2026 Medium CVE-2026-17106dockervulnerabilitysecurity
vulnerability Multiples vulnérabilités dans OpenSSH (11 août 2026) Multiple vulnerabilities have been discovered in OpenSSH, impacting versions prior to 10.5. The exact nature of the security issue is not specified by the publisher, but users are advised to consult the vendor's security… CERT-FR · Aug 11, 2026 Medium sshvulnerabilitysecurity
vulnerability Multiples vulnérabilités dans SPIP (11 août 2026) A series of vulnerabilities have been discovered in SPIP, a popular French content management system. These include remote code execution, SQL injection, and server-side request forgery, impacting versions prior to 4.4.1… CERT-FR · Aug 11, 2026 Medium vulnerabilitysql-injectionssrf