vulnerability Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius A zero-day SQL-injection vulnerability in Metabase Cloud is actively being exploited, potentially impacting a wide range of organizations beyond Metabase customers. The vulnerability allows remote attackers to gain admin… Dark Reading · Aug 10, 2026 High sql-injectionzero-dayvulnerability
vulnerability Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC Cisco has warned of seven high-severity vulnerabilities in its Secure Endpoint Connector software, stemming from flaws within the ClamAV antivirus engine. These vulnerabilities could lead to denial-of-service conditions… SecurityWeek · Aug 10, 2026 High CVE-2026-20337CVE-2026-20339CVE-2026-20345clamavvulnerabilitypatch
vulnerability Framework loses customer data in Metabase zero-day attack A zero-day vulnerability in Metabase has been exploited, leading to the exposure of customer data. Attackers are leveraging this flaw to gain unauthorized access to sensitive information stored within the Metabase platfo… The Register · Aug 10, 2026 High CHRUzero-dayvulnerabilityphishing
vulnerability Metabase Patches Vulnerability Exploited as Zero-Day Metabase has released critical patches to address a zero-day SQL injection vulnerability that was actively exploited in the wild. Attackers gained unauthorized access to Metabase Cloud instances, potentially stealing dat… SecurityWeek · Aug 10, 2026 Critical sql injectionzero-daypatch
vulnerability CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning to federal agencies to patch a critical vulnerability (CVE-2026-8037) in Progress LoadMaster and related products. This vulnerab… SecurityWeek · Aug 10, 2026 Critical CVE-2026-8037CVE-2026-33691command-injectionremote-code-executionpatch
vulnerability Critical Flaws Discovered in Belgian eID Software Used by 2 Million People A critical vulnerability in Nitro Software Belgium’s Connective digital identity system, used by over two million people in Belgium, allowed attackers to steal sensitive data and forge electronic signatures. The flaw was… SecurityWeek · Aug 10, 2026 High BEdigital identityeidbrowser extension
vulnerability ISC Stormcast For Monday, August 10th, 2026 https://isc.sans.edu/podcastdetail/10044, (Mon, Aug 10th) The ISC Stormcast highlighted a significant vulnerability in the latest version of Apache Log4j, potentially allowing attackers to execute arbitrary code remotely. This exploit could lead to widespread data breaches and… SANS Internet Storm Center · Aug 10, 2026 Critical log4jrcevulnerability
vulnerability Multiples vulnérabilités dans Roundcube (10 août 2026) Multiple vulnerabilities have been discovered in Roundcube Webmail, allowing attackers to execute arbitrary code remotely, compromise data confidentiality, and forge server-side requests. These flaws exist in versions 1.… CERT-FR · Aug 10, 2026 High vulnerabilitywebmailsecurity
vulnerability Multiples vulnérabilités dans VMware Tanzu Greenplum (10 août 2026) Multiple vulnerabilities have been discovered in VMware Tanzu Greenplum. These vulnerabilities allow an attacker to cause a security issue, though the specific nature of the issue is not detailed. Users are advised to co… CERT-FR · Aug 10, 2026 Medium CVE-2018-11798CVE-2019-0205CVE-2020-13949vulnerabilitycvepatch
vulnerability Multiples vulnérabilités dans HPE Aruba Networking Private 5G Core (10 août 2026) Multiple vulnerabilities have been discovered in HPE Aruba Networking Private 5G Core, allowing attackers to elevate privileges and bypass security policies. These vulnerabilities are present in older versions of the sof… CERT-FR · Aug 10, 2026 Medium CVE-2026-33377CVE-2026-54763vulnerabilitysecurityaruba
vulnerability Vulnérabilité dans Synology Assistant (10 août 2026) A vulnerability has been identified in Synology Assistant, allowing an attacker to compromise data confidentiality, data integrity, and cause a denial of service. Users of versions prior to 7.0.7-50095 are strongly advis… CERT-FR · Aug 10, 2026 Medium CVE-2026-4793synologyvulnerabilitysecurity
vulnerability Multiples vulnérabilités dans ClamAV (10 août 2026) Multiple vulnerabilities have been discovered in ClamAV, potentially allowing attackers to compromise data confidentiality, cause denial of service, and introduce an unspecified security issue. These vulnerabilities affe… CERT-FR · Aug 10, 2026 Medium CVE-2025-8088CVE-2026-20337CVE-2026-20338vulnerabilityantivirusclamav
vulnerability Vulnérabilité dans SonicWall Global VPN Client (10 août 2026) A vulnerability in SonicWall Global VPN Client allows an attacker to cause a denial-of-service. SonicWall has released a security bulletin and a corresponding CVE to address this issue. CERT-FR · Aug 10, 2026 Medium CVE-2026-66151vpnvulnerabilitydenial-of-service
vulnerability Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data A critical one-click vulnerability, dubbed RovoBlast, has been discovered in Atlassian’s Rovo AI assistant, allowing attackers to inject malicious prompts and exfiltrate sensitive data from various Atlassian products and… SecurityWeek · Aug 8, 2026 Critical aiprompt injectiondata exfiltration
vulnerability Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers Atlassian’s Rovo assistant has two vulnerabilities that could allow attackers to exfiltrate data. The first, a one-click link flaw, has been patched by Atlassian. The second, a content-borne prompt injection attack, allo… The Hacker News · Aug 8, 2026 High prompt-injectiondata-exfiltrationatlassian
vulnerability Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication A zero-day vulnerability in Metabase has been exploited in the wild, allowing unauthenticated attackers to gain administrator access to the application and steal data. The vulnerability affects versions 1.58 and above, a… The Hacker News · Aug 8, 2026 Critical CVE-2023-38646zero-daysql injectiondata breach
vulnerability N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist N-able has released a second hotfix (Hotfix 2) to address a critical zero-day vulnerability (CVE-2026-18577) in its N-central RMM product, which was being actively exploited by threat actors. The vulnerability allows for… The Hacker News · Aug 8, 2026 Critical CVE-2026-18577CVE-2026-18556zero-dayremote accesscloudflare
vulnerability Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts A critical command injection vulnerability in Progress Kemp LoadMaster has been added to CISA's KEV catalog, following reports of widespread exploitation attempts. The vulnerability allows unauthenticated attackers to ex… The Hacker News · Aug 8, 2026 Critical CVE-2026-8037AUCHINcommand injectionload balancerpatching
vulnerability MIT boffins' TONTOU attack slips through Spectre defenses on Intel and AMD CPUs This article discusses a vulnerability related to Spectre defenses on Intel and AMD CPUs, where an AI-powered attack, dubbed TONTOU, successfully bypassed existing security measures. The vulnerability stems from AI's str… The Register · Aug 7, 2026 Medium CHIRspectrevulnerabilityai
vulnerability New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP A high-severity cross-site scripting (XSS) vulnerability in WordPress's login screen allows attackers to execute PHP code on a server, potentially leading to database compromise and full system control. The vulnerability… The Hacker News · Aug 7, 2026 High CVE-2026-64638xsswordpresscve-2026-64638