vulnerability Critical Paperclip Flaw Allowed Admin Access, Code Execution A critical vulnerability (CVE-2026-41679) in Paperclip, an AI management platform, allowed remote attackers to gain administrative access and execute code on the server, potentially exposing sensitive data and internal s… SecurityWeek · Aug 6, 2026 Critical CVE-2026-41679aivulnerabilitycode-execution
vulnerability AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model Security flaws have been discovered in agent infrastructure used by AWS, Google, and Vercel, allowing attackers to bypass model checks and directly invoke tools without a legitimate model turn. These vulnerabilities stem… The Hacker News · Aug 6, 2026 High CVE-2026-18830CVE-2026-18236CVE-2026-64650agentmodelauthorization
vulnerability Cisco Patches Critical SD-WAN, IOS XE, FMC Vulnerabilities Cisco has released patches for a significant number of vulnerabilities across its SD-WAN, IOS XE, and FMC products. These include critical flaws that could allow remote code execution and unauthorized access, with some v… SecurityWeek · Aug 6, 2026 High CVE-2026-20303CVE-2026-20304CVE-2026-20310vulnerabilitypatchsecurity
vulnerability CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild A critical vulnerability (CVE-2026-63077) in JetBrains TeamCity, allowing unauthenticated remote code execution, is currently being actively exploited in the wild. CISA has issued a Binding Operational Directive requirin… The Hacker News · Aug 6, 2026 Critical CVE-2026-63077cveremote code executiondeserialization
vulnerability Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability JetBrains TeamCity, a popular CI/CD platform, is experiencing a critical vulnerability (CVE-2026-63077) that allows unauthenticated attackers to execute commands on the server. CISA has added the vulnerability to its lis… SecurityWeek · Aug 6, 2026 Critical CVE-2026-63077vulnerabilityrcedeserialization
vulnerability Multiples vulnérabilités dans les produits Wallix (06 août 2026) Wallix has disclosed multiple vulnerabilities in its Access Manager and Bastion products, potentially allowing attackers to escalate privileges and bypass security policies. These flaws could be exploited to gain unautho… CERT-FR · Aug 6, 2026 Medium vulnerabilitysamlprivilege escalation
vulnerability Multiples vulnérabilités dans les produits Cisco (06 août 2026) Multiple vulnerabilities have been discovered in Cisco products, including SD-WAN and networking equipment. These vulnerabilities can lead to remote code execution, denial-of-service attacks, and data confidentiality bre… CERT-FR · Aug 6, 2026 High CVE-2026-20124CVE-2026-20200CVE-2026-20263ciscosd-wanvulnerability
vulnerability Multiples vulnérabilités dans les produits Nextcloud (06 août 2026) Multiple vulnerabilities have been discovered in Nextcloud products, allowing an attacker to compromise data confidentiality and bypass security policies. These vulnerabilities affect various versions of Mail and Server,… CERT-FR · Aug 6, 2026 Medium CVE-2026-61527CVE-2026-61545vulnerabilitypatchsecurity
vulnerability Multiples vulnérabilités dans KeyCloak (06 août 2026) Multiple vulnerabilities have been discovered in Keycloak, potentially allowing for privilege escalation, denial of service attacks, and data compromise. These vulnerabilities affect versions 26.6.x through 26.6.5, 26.7.… CERT-FR · Aug 6, 2026 High CVE-2026-15572CVE-2026-15573CVE-2026-16071keycloakvulnerabilitysecurity
vulnerability Vulnérabilité dans Sonicwall SonicOS (06 août 2026) SonicWall has announced a vulnerability in its SonicOS firmware that allows attackers to bypass security policies. This affects a range of firewalls, including models from the Gen6, Gen7, and Gen8 series. The vulnerabili… CERT-FR · Aug 6, 2026 High CVE-2026-0516securityfirmwarepatch
vulnerability How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones Two security researchers, Dimitrios Valsamaras and Ken Gannon, demonstrated a complex exploit chain targeting Samsung phones, leveraging vulnerabilities in the Samsung Members and Samsung Account apps to gain remote code… SecurityWeek · Aug 5, 2026 High CVE-2025-21079CVE-2025-58486CVE-2025-58487androidbixbyexploit
vulnerability Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports Two critical vulnerabilities in Paperclip, an AI agent control plane, allow attackers to execute commands on a server or a developer's computer. The first vulnerability (CVE-2026-41679) requires no prior account or inter… The Hacker News · Aug 5, 2026 Critical CVE-2026-41679agentauthenticationdns
vulnerability Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug HashiCorp, Veeam, and Django have released critical patches to address several vulnerabilities, including a cross-tenant credential reuse flaw in Terraform MCP Server, a multi-tenant console credential impersonation issu… The Hacker News · Aug 5, 2026 High CVE-2026-58073CVE-2026-58072CVE-2026-58067credential-reuseremote-code-executionspatial-data
vulnerability New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch A critical memory corruption vulnerability (CVE-2026-64531) in the Linux kernel's Open vSwitch datapath allows local users to gain root access on a wide range of distributions. The vulnerability stems from a 16-bit lengt… The Hacker News · Aug 5, 2026 Critical CVE-2026-64531linuxkernelopen vswitch
vulnerability Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup A critical vulnerability (CVE-2026-59774) in Gitea versions 1.22.1 through 1.27.0 allows unauthenticated attackers to read files accessible to the service account. While a direct remote code execution exploit hasn't been… The Hacker News · Aug 5, 2026 Critical CVE-2026-59774CVE-2026-60004CVE-2026-20896vulnerabilityorg-moderemote code execution
vulnerability CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities The CISA has issued a warning about three actively exploited vulnerabilities affecting IBM Langflow OSS, N-able N-central, and Apache Tomcat. These vulnerabilities – CVE-2026-9198, CVE-2026-18556, and CVE-2026-34486 – ar… SecurityWeek · Aug 5, 2026 High CVE-2026-9198CVE-2026-18556CVE-2026-18577CHcvepatchremote code execution
vulnerability Vulnerabilities in Car Anti-Theft Device A security flaw in a popular aftermarket car alarm system, the KARR Security System, allows hackers to remotely control vehicles via Bluetooth. This vulnerability affects over two million cars in the US and could lead to… Schneier on Security · Aug 5, 2026 Critical bluetoothvehiclesecurity
vulnerability Multiples vulnérabilités dans Google Pixel (05 août 2026) Google has discovered and addressed multiple vulnerabilities within its Pixel devices. These vulnerabilities could allow an attacker to gain elevated privileges, though specific details remain undisclosed. Users are advi… CERT-FR · Aug 5, 2026 Medium CVE-2026-0163androidsecurityvulnerability
vulnerability Vulnérabilité dans Mozilla Firefox pour Android (05 août 2026) Mozilla has announced a vulnerability in Firefox for Android that could allow an attacker to compromise user data confidentiality. Users running versions of Firefox for Android prior to 153.0.3 are at risk and should upd… CERT-FR · Aug 5, 2026 Medium CVE-2026-18809firefoxandroidvulnerability
vulnerability Multiples vulnérabilités dans HPE Aruba Networking EdgeConnect SD-WAN Orchestrator (05 août 2026) Multiple vulnerabilities have been discovered in HPE Aruba Networking EdgeConnect SD-WAN Orchestrator, allowing attackers to compromise data confidentiality, integrity, and bypass security policies. HPE has released a se… CERT-FR · Aug 5, 2026 Medium CVE-2026-63455CVE-2026-63456sd-wanvulnerabilityhpe