vulnerability 18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers A 18-year-old vulnerability in Linux's SCTP networking code allows local users to gain root access on a host, potentially escaping containers. Tencent researchers discovered and demonstrated this flaw, which has existed… The Hacker News · Aug 7, 2026 High CVE-2026-64564CHlinuxsctpuse-after-free
vulnerability Microsoft, Apple Release Fresh Security Updates Microsoft and Apple released a combined set of security updates addressing dozens of vulnerabilities across their products, including critical remote code execution flaws. These updates target a wide range of products, i… SecurityWeek · Aug 7, 2026 Critical CVE-2026-63508CVE-2026-56162CVE-2026-65667vulnerabilityremote code executionpatch
vulnerability Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets Two vulnerabilities – one in Gemini CLI and another in Claude Code – have been discovered that allowed unprivileged attackers to execute code on CI runners, potentially exposing sensitive information. Gemini CLI allowed… The Hacker News · Aug 7, 2026 High CVE-2026-12537CVE-2026-54316ci/cdinput validationcommand injection
vulnerability Critical Vulnerabilities Patched With Chrome 151 Update Google released Chrome 151 to address 370 security vulnerabilities, primarily memory safety bugs, with 41 classified as critical. The update aims to prevent data corruption, crashes, and potential code execution exploits… SecurityWeek · Aug 7, 2026 High memory-safetychromevulnerability
vulnerability ISC Stormcast For Friday, August 7th, 2026 https://isc.sans.edu/podcastdetail/10042, (Fri, Aug 7th) The ISC Stormcast highlighted a significant vulnerability in Apache ActiveMQ, potentially allowing attackers to execute arbitrary code. This could lead to widespread disruption and data compromise across various industri… SANS Internet Storm Center · Aug 7, 2026 Critical activemqvulnerabilityremote code execution
vulnerability Multiples vulnérabilités dans le noyau Linux de Red Hat (07 août 2026) Multiple vulnerabilities have been discovered in Red Hat's Linux kernel. Some of these vulnerabilities allow an attacker to cause arbitrary code execution, privilege escalation, and a denial-of-service attack. These vuln… CERT-FR · Aug 7, 2026 High CVE-2025-10263CVE-2025-40026CVE-2025-54518linuxkernelsecurity
vulnerability Multiples vulnérabilités dans le noyau Linux de SUSE (07 août 2026) Multiple vulnerabilities have been discovered in the Linux kernel of SUSE. These vulnerabilities allow an attacker to bypass security policies and create an unspecified security issue. The affected system is SUSE Linux M… CERT-FR · Aug 7, 2026 High CVE-2026-23240CVE-2026-31738CVE-2026-43038linuxkernelsecurity
vulnerability Multiples vulnérabilités dans Google Chrome (07 août 2026) Multiple vulnerabilities have been discovered in Google Chrome, potentially allowing an attacker to trigger a security issue. These vulnerabilities affect Chrome versions prior to 151.0.7922.108 on Windows and Linux, and… CERT-FR · Aug 7, 2026 High CVE-2026-19137CVE-2026-19138CVE-2026-19139chromevulnerabilitysecurity
vulnerability Multiples vulnérabilités dans le noyau Linux d'Ubuntu (07 août 2026) Multiple vulnerabilities have been discovered in the Linux kernel of Ubuntu. Several of these vulnerabilities allow for privilege escalation, data confidentiality breaches, and a security issue not specified by the publi… CERT-FR · Aug 7, 2026 High CVE-2022-49803CVE-2022-49961CVE-2022-50073linuxvulnerabilitysecurity
vulnerability Multiples vulnérabilités dans WordPress (07 août 2026) Multiple vulnerabilities have been discovered in WordPress, including remote code execution and privilege escalation, potentially leading to data compromise. These flaws are primarily affecting older versions of the plat… CERT-FR · Aug 7, 2026 High CVE-2026-64638wordpressvulnerabilityssrf
vulnerability Multiples vulnérabilités dans Progress Telerik (07 août 2026) A security advisory from CERT-FR details multiple vulnerabilities within Progress Telerik's ASP.NET AJAX product. These vulnerabilities include remote code execution, denial of service, and data breaches, allowing attack… CERT-FR · Aug 7, 2026 High CVE-2026-14932CVE-2026-13181CVE-2026-13182vulnerabilitydeserializationssrf
vulnerability Multiples vulnérabilités dans le noyau Linux de Debian (07 août 2026) Multiple vulnerabilities have been discovered in the Linux kernel of Debian. These vulnerabilities allow an attacker to cause privilege escalation, data corruption, and denial of service. The affected Debian versions are… CERT-FR · Aug 7, 2026 High CVE-2026-45944CVE-2026-53005CVE-2026-53260vulnerabilitylinuxdebian
vulnerability Vulnérabilité dans Apple macOS (07 août 2026) Apple has disclosed a security vulnerability in macOS that allows attackers to bypass security policies. This vulnerability could lead to unauthorized access and potential compromise of user systems. Users of affected ma… CERT-FR · Aug 7, 2026 Medium CVE-2026-65400macossecurityvulnerability
vulnerability New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts A vulnerability (CVE-2026-64561) in the KVM virtualization software allows a privileged guest user to potentially escape the virtualization environment and execute code on the host system. This stems from a stale-root ch… The Hacker News · Aug 6, 2026 High CVE-2026-64561CVE-2026-53359CVE-2026-46316kvmshadow-mmunested virtualization
vulnerability Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugs Cisco has released patches to address multiple critical security vulnerabilities affecting its SD-WAN and IOS XE software. These flaws, including several with a CVSS score of 9.8 and 9.9, cover issues like improper input… The Hacker News · Aug 6, 2026 High CVE-2026-20303CVE-2026-20304CVE-2026-20310sd-wanios xevulnerability
vulnerability New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs Researchers at MIT have discovered a new vulnerability, dubbed INTERRUPT INJECTION, that allows an unprivileged Linux program to bypass Spectre v2 defenses on Intel and AMD CPUs. By precisely timing a hardware interrupt,… The Hacker News · Aug 6, 2026 High CVE-2023-20569spectreinterruptkernel
vulnerability ABB Ability Zenon ABB has issued a security advisory regarding multiple vulnerabilities in its Ability Zenon industrial automation platform. These vulnerabilities, primarily related to MongoDB, could allow attackers to bypass security, cr… CISA Advisories · Aug 6, 2026 High CVE-2025-14847CVE-2020-7928CVE-2020-7921WOvulnerabilitydata-breachmalware
vulnerability Johnson Controls Inc. TL280 A critical vulnerability (CWE-327) exists in Johnson Controls Inc.'s TL280 firmware, allowing attackers to access sensitive information on the device. The vulnerability stems from hardcoded credentials embedded directly… CISA Advisories · Aug 6, 2026 Critical CVE-2026-27871cwe-327firmwareics
vulnerability Medixant RadiAnt DICOM A vulnerability in Medixant RadiAnt DICOM versions older than 2025.2 allows an attacker to crash the application by opening a maliciously crafted DICOM file, potentially leading to remote code execution. CISA recommends… CISA Advisories · Aug 6, 2026 High CVE-2026-17264PLdicomcwe-787heap overflow
vulnerability Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses Researchers have discovered a vulnerability in Apple's iCloud Private Relay tool that allows users' real IP addresses to be exposed, even when the tool is active. The issue stems from three WebKit features – DNS prefetch… The Hacker News · Aug 6, 2026 High webkitprivacyip leak