vulnerability Multiples vulnérabilités dans Microsoft Edge (24 juillet 2026) Multiple vulnerabilities have been discovered in Microsoft Edge, impacting versions prior to 150.0.4078.96. The exact nature of the vulnerabilities and the resulting security issue are not specified by the publisher. Use… CERT-FR · Jul 24, 2026 Medium CVE-2026-16413CVE-2026-16414CVE-2026-16415vulnerabilitypatchsecurity
vulnerability Vulnérabilité dans NetApp ONTAP 9 (24 juillet 2026) A critical vulnerability has been identified in NetApp ONTAP 9, potentially allowing attackers to cause denial of service, compromise data confidentiality, and damage data integrity. Affected versions require immediate p… CERT-FR · Jul 24, 2026 Critical CVE-2026-42511vulnerabilityremotedata
vulnerability Multiples vulnérabilités dans le noyau Linux de Red Hat (24 juillet 2026) Multiple vulnerabilities have been discovered in the Red Hat Linux kernel. Some of these vulnerabilities allow an attacker to cause remote code execution, privilege escalation, and a denial-of-service attack. These vulne… CERT-FR · Jul 24, 2026 High CVE-2024-46738CVE-2024-50076CVE-2025-39982linuxkernelvulnerability
vulnerability Millions of California-bought cars can be hijacked via Bluetooth A vulnerability in Joomla extensions, specifically iCagenda and Balbooa Forms, is being exploited to compromise websites running the CMS. Attackers are leveraging these flaws to gain unauthorized access to vulnerable sit… The Register · Jul 23, 2026 Medium joomlavulnerabilityextension
vulnerability Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files Researchers at Accomplish AI discovered a sandbox escape vulnerability in Anthropic's Claude Cowork for macOS, allowing the AI agent to access and modify files on the host Mac. Approximately 500,000 macOS users running l… The Hacker News · Jul 23, 2026 High CVE-2026-46331sandboxmacoslinux
vulnerability MZ Automation lib60870 A vulnerability in MZ Automation lib60870, version 2.4.0 and earlier, allows for a denial-of-service attack through an out-of-bounds read. This affects critical infrastructure sectors like chemical, energy, and water/was… CISA Advisories · Jul 23, 2026 Medium CVE-2026-16002GEout-of-boundsdenial of servicecisa
vulnerability Panduit IntraVUE Pronetiqs has identified and reported several vulnerabilities in Panduit IntraVUE software versions 3.2.1a14 and earlier, posing significant risks to industrial control systems. These vulnerabilities include plaintext st… CISA Advisories · Jul 23, 2026 High CVE-2026-40430CVE-2026-42933CVE-2026-44955industrial control systemsot securitypassword vulnerability
vulnerability Johnson Controls XAAP Android A vulnerability exists in the Johnson Controls XAAP Android application, version 1.53 and earlier. Attackers with physical access to a device could potentially read sensitive data stored locally without encryption. This… CISA Advisories · Jul 23, 2026 High CVE-2026-34490vulnerabilityandroidcleartext storage
vulnerability Weintek cMT3092X Weintek’s cMT3092X HMI and EasyWeb software versions are vulnerable to privilege escalation and credential exposure. A non-privileged user can modify cookies to gain elevated privileges, and user passwords are stored in… CISA Advisories · Jul 23, 2026 High CVE-2026-60134CVE-2026-61892CVE-2026-61886patchplaintextprivilege escalation
vulnerability Johnson Controls C-CURE 9000 and Victor application server Johnson Controls has issued security advisories regarding critical vulnerabilities in its C-CURE 9000 and Victor application servers, as well as the victor Web application. Exploitation could allow an unauthenticated att… CISA Advisories · Jul 23, 2026 High CVE-2026-21655CVE-2026-21653CVE-2026-34496cve-2026-21653cve-2026-21655cve-2026-34496
vulnerability MZ Automation libIEC61850 MZ Automation libIEC61850 versions 1.0.0 through 1.6.1 are vulnerable to several stack and heap-based buffer overflows, potentially allowing an unauthenticated attacker to crash critical IEC 61850 services or execute arb… CISA Advisories · Jul 23, 2026 High CVE-2026-50039CVE-2026-49035CVE-2026-50103iec61850buffer overflowindustrial control systems
vulnerability New Check Point Zero-Day Vulnerability Exploited in the Wild A critical zero-day vulnerability in Check Point’s Security Management and Multi-Domain Management products has been actively exploited in the wild. The flaw allows attackers to gain administrator-level access, and Check… SecurityWeek · Jul 23, 2026 Critical CVE-2026-16232CVE-2026-50751CVE-2024-24919zero-dayauthenticationprivilege escalation
vulnerability Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs A nine-year-old vulnerability (CVE-2026-64600) in the Linux kernel's XFS filesystem allows unprivileged local users to gain root access on default Red Hat Enterprise Linux, CentOS Stream, and Amazon Linux installations.… The Hacker News · Jul 23, 2026 High CVE-2026-64600CVE-2026-8933linuxxfskernel
vulnerability Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access Check Point has released security updates to address a critical vulnerability (CVE-2026-16232) in its SmartConsole login process, which allows unauthenticated remote attackers to gain full administrative access. This fla… The Hacker News · Jul 23, 2026 Critical CVE-2026-16232CVE-2026-62144CVE-2026-62145vulnerabilityauthenticationremote access
vulnerability Multiples vulnérabilités dans les produits Mitel (23 juillet 2026) Multiple vulnerabilities have been discovered in Mitel products, allowing attackers to execute arbitrary code remotely and inject malicious code via XSS. These vulnerabilities affect various versions of MiCollab and Open… CERT-FR · Jul 23, 2026 High vulnerabilityremote code executionxss
vulnerability Vulnérabilité dans Moodle (23 juillet 2026) A vulnerability in Moodle versions prior to 5.2.1 allows an attacker to compromise user data confidentiality. The CERT-FR has issued a security bulletin detailing the issue and recommending immediate patching. CERT-FR · Jul 23, 2026 Medium moodlevulnerabilitydata breach
vulnerability Multiples vulnérabilités dans Oracle Database Server (23 juillet 2026) Multiple vulnerabilities have been discovered in Oracle Database Server, potentially leading to data integrity compromise, data confidentiality breaches, and remote denial-of-service attacks. These vulnerabilities affect… CERT-FR · Jul 23, 2026 High CVE-2025-7962CVE-2026-28387CVE-2026-28388oracledatabasevulnerability
vulnerability Multiples vulnérabilités dans les produits Check Point (23 juillet 2026) Multiple vulnerabilities have been discovered in Check Point products, allowing attackers to elevate privileges and bypass security policies. Check Point reports that CVE-2026-16232 is actively being exploited. Users are… CERT-FR · Jul 23, 2026 High CVE-2026-16232CVE-2026-62144CVE-2026-62145vulnerabilitycheck pointsecurity
vulnerability Multiples vulnérabilités dans Oracle PeopleSoft (23 juillet 2026) Multiple vulnerabilities have been discovered in Oracle PeopleSoft, allowing an attacker to cause a denial-of-service, lead to data confidentiality breaches, and compromise data integrity. These vulnerabilities are part… CERT-FR · Jul 23, 2026 High CVE-2025-55130CVE-2025-55131CVE-2025-55132oraclepeoplesoftvulnerability
vulnerability Multiples vulnérabilités dans Oracle Systems (23 juillet 2026) Multiple vulnerabilities have been discovered within Oracle Systems, potentially allowing attackers to compromise data confidentiality, integrity, and cause denial of service. These vulnerabilities affect various Oracle… CERT-FR · Jul 23, 2026 High CVE-2026-60659CVE-2026-60661CVE-2026-60833oraclevulnerabilitypatch