vulnerability Multiples vulnérabilités dans GLPI (27 juillet 2026) Multiple vulnerabilities have been discovered in GLPI, including potential for privilege escalation, data integrity compromise, and SQL injection. These vulnerabilities affect GLPI versions prior to 11.0.8 and 10.0.26. U… CERT-FR · Jul 27, 2026 High CVE-2026-47678CVE-2026-47679CVE-2026-52848glpivulnerabilitysql injection
vulnerability Vulnérabilité dans Traefik (27 juillet 2026) A security vulnerability has been identified in Traefik, allowing attackers to bypass security policies. This affects older versions of the popular reverse proxy and load balancer, requiring immediate patching to prevent… CERT-FR · Jul 27, 2026 Medium traefikvulnerabilitysecurity
vulnerability Multiples vulnérabilités dans les produits Atlassian (27 juillet 2026) Multiple vulnerabilities have been discovered in Atlassian products, including Confluence Data Center and Jira Service Management. These vulnerabilities allow for remote code execution, privilege escalation, denial of se… CERT-FR · Jul 27, 2026 High CVE-2022-37599CVE-2022-37601CVE-2022-37603vulnerabilitysupply-chaindata-breach
vulnerability Multiples vulnérabilités dans Microsoft Edge (27 juillet 2026) Multiple vulnerabilities have been discovered in Microsoft Edge, potentially allowing attackers to compromise data confidentiality and bypass security policies. These vulnerabilities are detailed in a series of security… CERT-FR · Jul 27, 2026 Medium CVE-2026-57978CVE-2026-57989CVE-2026-57990vulnerabilitymicrosoftedge
vulnerability Scans for ESAFENET CDG 3 Document Management System Weak Logins, (Sun, Jul 26th) A scan targeting ESAFENET CDG, a Chinese-focused document management system, revealed weak default passwords and vulnerabilities, including SQL injection and XSS. Threat actors are leveraging existing exploit scripts to… SANS Internet Storm Center · Jul 26, 2026 Medium CNdefault passwordsql injectionxss
vulnerability Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available A critical Remote Code Execution (RCE) vulnerability in Fastjson 1.x, a Java JSON library by Alibaba, is being actively exploited. Attackers are leveraging a type-resolution path to execute arbitrary code in Spring Boot… The Hacker News · Jul 25, 2026 High CVE-2026-16723USSGCArcejsonjava
vulnerability Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git A researcher, depthfirst, has published a proof-of-concept exploit targeting GitLab 18.11.3 and earlier, allowing authenticated users to execute arbitrary commands as the ‘git’ user. The vulnerability stems from flaws wi… The Hacker News · Jul 25, 2026 High rcejupyterjson
vulnerability Rockwell Patches Code Execution Flaws in Arena Simulation Software Rockwell Automation has released a patch to address four critical vulnerabilities in its Arena Simulation software, preventing attackers from executing arbitrary code on affected systems. These flaws stem from improper d… SecurityWeek · Jul 25, 2026 Critical CVE-2026-8085CVE-2026-8312CVE-2026-8313otsimulationmemory corruption
vulnerability Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller Researchers discovered a vulnerability, dubbed ‘Certighost,’ allowing low-privilege Active Directory users to impersonate Domain Controllers by obtaining certificates. The flaw leverages a chase mechanism within Active D… The Hacker News · Jul 24, 2026 High CVE-2026-54121active directorycertificate authoritykerberos
vulnerability Vatican's Official Prayer App Leaks 700K+ Global Users' PII The Vatican's official prayer app, Click to Pray, is leaking the personal information of over 700,000 users due to an unsecured API endpoint. The vulnerability allows anyone to access names, email addresses, locations, a… Dark Reading · Jul 24, 2026 High ESidorsvulnerabilitydata breach
vulnerability Default Azure Automation Setting Enables Cross-Tenant Identity Takeover A critical vulnerability in Microsoft's Azure Automation service, stemming from a default public configuration for automation account identities, could have allowed attackers to take over another tenant's identity and ac… Dark Reading · Jul 24, 2026 Critical CVE-2025-29827identitycloudautomation
vulnerability Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers Bing Image Search had two critical vulnerabilities allowing attackers to execute commands as SYSTEM on Microsoft's servers by submitting crafted SVGs. The issue stemmed from a helper component that treated SVG files as c… The Hacker News · Jul 24, 2026 High CVE-2026-32194CVE-2026-32191CVE-2016-3714svgcommand-injectionimagemagick
vulnerability NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats NodeBB has patched eight security flaws, including vulnerabilities allowing unauthorized admin access and the ability to read private chats, discovered by AI penetration testing. The flaws, some of which stem from the fo… The Hacker News · Jul 24, 2026 High CVE-2026-58593securityvulnerabilityadmin access
vulnerability Multiples vulnérabilités dans le noyau Linux de SUSE (24 juillet 2026) Multiple vulnerabilities have been discovered in the SUSE Linux kernel. Some of these vulnerabilities allow for data confidentiality and integrity breaches, as well as bypassing security policies and causing denial of se… CERT-FR · Jul 24, 2026 High CVE-2023-20585CVE-2025-10263CVE-2025-39894linuxkernelsecurity
vulnerability Vulnérabilité dans les produits Moxa (24 juillet 2026) A critical vulnerability has been identified in Moxa products, allowing attackers to elevate their privileges. This security issue stems from a flaw within the Linux kernel and requires immediate attention to prevent pot… CERT-FR · Jul 24, 2026 Critical CVE-2026-46333linuxsshprivilege-escalation
vulnerability Multiples vulnérabilités dans MongoDB (24 juillet 2026) Multiple vulnerabilities have been discovered in MongoDB, allowing an attacker to cause a denial of service and potentially exploit a security policy bypass. These vulnerabilities affect various versions of MongoDB Compa… CERT-FR · Jul 24, 2026 High CVE-2026-13055CVE-2026-13056CVE-2026-13057mongodbvulnerabilitysecurity
vulnerability Multiples vulnérabilités dans le noyau Linux de Debian (24 juillet 2026) Multiple vulnerabilities have been discovered in the Linux kernel of Debian, potentially allowing attackers to elevate privileges, compromise data confidentiality, and cause denial of service. These vulnerabilities affec… CERT-FR · Jul 24, 2026 High CVE-2025-21807CVE-2026-46093CVE-2026-53027linuxkerneldebian
vulnerability Multiples vulnérabilités dans Google Chrome (24 juillet 2026) Google Chrome has been found to have multiple vulnerabilities, requiring users to update to a secure version to prevent potential security issues. The CERT-FR report details several CVEs associated with these flaws, urgi… CERT-FR · Jul 24, 2026 Medium CVE-2026-16804CVE-2026-16805CVE-2026-16806chromevulnerabilitysecurity
vulnerability Multiples vulnérabilités dans le noyau Linux de Debian LTS (24 juillet 2026) Multiple vulnerabilities have been discovered within the Linux kernel of Debian LTS. These vulnerabilities allow an attacker to cause privilege escalation, data confidentiality breaches, and data integrity issues. Affect… CERT-FR · Jul 24, 2026 High CVE-2025-23131CVE-2026-23272CVE-2026-23278linuxkerneldebian
vulnerability Multiples vulnérabilités dans les produits ESET (24 juillet 2026) Multiple vulnerabilities have been discovered in ESET’s security products, primarily for macOS, allowing attackers to potentially elevate their privileges. These vulnerabilities require immediate patching to prevent expl… CERT-FR · Jul 24, 2026 Medium CVE-2026-10610CVE-2026-7483macosvulnerabilitypatch