vulnerability Multiples vulnérabilités dans Oracle Virtualization (23 juillet 2026) Multiple vulnerabilities have been discovered in Oracle Virtualization, allowing an attacker to compromise data confidentiality, data integrity, and cause a denial of service. These vulnerabilities affect Oracle VM Virtu… CERT-FR · Jul 23, 2026 Medium CVE-2026-47041CVE-2026-47043CVE-2026-47044oraclevirtualizationvulnerabilities
vulnerability Multiples vulnérabilités dans Oracle Java SE (23 juillet 2026) Multiple vulnerabilities have been discovered in Oracle Java SE, potentially allowing an attacker to cause a denial of service, compromise data confidentiality, and damage data integrity. These vulnerabilities affect var… CERT-FR · Jul 23, 2026 High CVE-2026-41254CVE-2026-46917CVE-2026-46968javavulnerabilitysecurity
vulnerability Multiples vulnérabilités dans Oracle MySQL (23 juillet 2026) Multiple vulnerabilities have been discovered in Oracle MySQL, allowing an attacker to cause a denial-of-service, compromise data confidentiality, and damage data integrity. These vulnerabilities are present across vario… CERT-FR · Jul 23, 2026 High CVE-2025-68161CVE-2026-46936CVE-2026-47008mysqloraclevulnerability
vulnerability Multiples vulnérabilités dans Mozilla Thunderbird (23 juillet 2026) Mozilla Thunderbird contains multiple vulnerabilities that could lead to data compromise, security policy bypass, denial of service, remote code execution, and privilege escalation. These vulnerabilities are present in v… CERT-FR · Jul 23, 2026 High CVE-2026-14899CVE-2026-15718CVE-2026-15719vulnerabilitysecurityfirefox
vulnerability Multiples vulnérabilités dans Oracle Weblogic (23 juillet 2026) Multiple vulnerabilities have been discovered in Oracle WebLogic, allowing an attacker to compromise data confidentiality and integrity. These vulnerabilities affect various WebLogic Server Proxy Plug-ins and the WebLogi… CERT-FR · Jul 23, 2026 High CVE-2025-68161CVE-2026-34477CVE-2026-34478oracleweblogicvulnerability
vulnerability Flaws in Passkey Implementation Show Old Attacks Still Work Researchers at SpecterOps discovered several exploitable flaws in Microsoft's passkey implementation, particularly within Microsoft Entra ID, that could allow attackers to impersonate privileged users and bypass MFA. Des… Dark Reading · Jul 22, 2026 High CVE-2026-34348passkeyswebauthnmicrosoft
vulnerability Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs A critical vulnerability (CVE-2026-8933, CVSS 7.8) has been discovered in snap-confine within Ubuntu Desktop installations. An unprivileged user can exploit a race condition to gain root access and full control of the sy… The Hacker News · Jul 22, 2026 High CVE-2026-8933CVE-2021-44731CVE-2022-3328local privilege escalationrace conditionubuntu
vulnerability Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data A vulnerability in the Adobe Acrobat Chrome extension (HermeticReader, CVE-2026-48294) allows attackers to silently steal WhatsApp Web data by tricking users into visiting a malicious website. The flaw requires only user… The Hacker News · Jul 22, 2026 High CVE-2026-48294chromeextensionwhatsapp
vulnerability Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft A widely-used Adobe Chrome extension was exploited to steal WhatsApp data by tricking users into visiting a malicious webpage. The vulnerability, dubbed HermeticReader, allowed attackers to silently access users' private… SecurityWeek · Jul 22, 2026 High CVE-2026-48294uxsschromedata-breach
vulnerability Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication A critical vulnerability in Windmill, a popular open-source developer platform, is being actively exploited to allow attackers to read arbitrary server files without needing any credentials. This unauthenticated path tra… The Hacker News · Jul 22, 2026 High CVE-2026-29059path traversalunauthenticatedserver files
vulnerability Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks A fourth SharePoint vulnerability, CVE-2026-50522, is being actively exploited in the wild, allowing attackers to execute arbitrary code on SharePoint servers. Threat actors are specifically targeting SharePoint machine… SecurityWeek · Jul 22, 2026 High CVE-2026-50522CVE-2026-58644CVE-2026-56164sharepointvulnerabilityremote code execution
vulnerability Multiples vulnérabilités dans GLPI (22 juillet 2026) Multiple vulnerabilities have been discovered in GLPI, allowing an attacker to compromise data confidentiality, data integrity, and bypass security policies. These vulnerabilities affect older versions of the system and… CERT-FR · Jul 22, 2026 Medium CVE-2026-45801CVE-2026-53627CVE-2026-53628glpivulnerabilitysecurity
vulnerability Multiples vulnérabilités dans Google Chrome (22 juillet 2026) Multiple vulnerabilities have been discovered in Google Chrome, impacting older versions of the browser on Windows, Linux, and macOS. Users are advised to consult the official Chrome security update bulletin for availabl… CERT-FR · Jul 22, 2026 Medium CVE-2026-16413CVE-2026-16414CVE-2026-16415chromevulnerabilitysecurity
vulnerability Multiples vulnérabilités dans les produits HPE Aruba Networking (22 juillet 2026) Multiple vulnerabilities have been discovered in HPE Aruba Networking products, allowing an attacker to execute arbitrary code, compromise data confidentiality, and bypass security policies. These vulnerabilities affect… CERT-FR · Jul 22, 2026 High CVE-2026-35387CVE-2026-44878CVE-2026-44879vulnerabilitypatchsecurity
vulnerability Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC A critical SharePoint vulnerability (CVE-2026-50522) is currently being actively exploited, allowing attackers to execute code remotely and steal machine keys. Microsoft released a patch last month, but attackers are lev… The Hacker News · Jul 21, 2026 Critical CVE-2026-50522CVE-2026-56164CVE-2026-58644sharepointvulnerabilityrce
vulnerability Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities Zimbra has released patches to address nine security vulnerabilities, including a critical SNMP command injection flaw and several XSS vulnerabilities. These fixes are vital to mitigate potential code execution and email… The Hacker News · Jul 21, 2026 Medium CVE-2026-50055snmpxsscommand-injection
vulnerability Rockwell Automation FactoryTalk Services Platform Rockwell Automation has issued a security advisory regarding a vulnerability in its FactoryTalk Services Platform (FTSP) version 6.60. An attacker could impersonate an authorized user by bypassing JWT signature validatio… CISA Advisories · Jul 21, 2026 High CVE-2026-10714vulnerabilityftpcisa
vulnerability Siemens IAM Client Siemens has identified a critical unquoted search path vulnerability in its IAM Client SDK, potentially allowing an authenticated local attacker to escalate privileges. Multiple Siemens products, including COMOS, Designc… CISA Advisories · Jul 21, 2026 Critical CVE-2025-40945cwe-426unquoted search pathiam client
vulnerability Tycon Systems TPDIN-Monitor-WEB2 Tycon Systems TPDIN-Monitor-WEB2 versions 2.3.9 are vulnerable to a critical authentication bypass flaw, allowing unauthenticated remote attackers to gain full administrative access to the device. This could lead to disr… CISA Advisories · Jul 21, 2026 Critical CVE-2026-61884CVE-2026-55985authentication bypasscwe-288cwe-312
vulnerability Rockwell Automation ThinManager Rockwell Automation has issued a security advisory regarding a path traversal vulnerability in its ThinManager software. This vulnerability allows an authenticated attacker to write arbitrary files to restricted system d… CISA Advisories · Jul 21, 2026 Critical CVE-2026-11917path traversalicsindustrial control systems