vulnerability OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests A memory-exhaustion denial-of-service vulnerability, dubbed HollowByte, exists in OpenSSL versions 3.6.3, 3.5.7, 3.4.6, 3.0.21, 4.0.1, 3.6.2, and 3.6.3. The vulnerability stems from a flawed memory allocation process dur… The Hacker News · Jul 17, 2026 High CVE-2025-66199CVE-2026-34183memory-exhaustiondostls
vulnerability Fresh SharePoint Vulnerability Exploited Soon After Disclosure A critical remote code execution vulnerability in Microsoft SharePoint has been actively exploited by threat actors shortly after its disclosure. Microsoft has released patches to address the issue, but CISA has added it… SecurityWeek · Jul 17, 2026 Critical CVE-2026-58644CVE-2026-56164CVE-2026-55040rcesharepointvulnerability
vulnerability CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV CISA has added a critical, actively exploited vulnerability in Microsoft SharePoint Server to its KEV list, forcing federal agencies to address it immediately. This zero-day flaw, CVE-2026-58644, allows for remote code e… The Hacker News · Jul 17, 2026 Critical CVE-2026-58644sharepointvulnerabilitydeserialization
vulnerability ISC Stormcast For Friday, July 17th, 2026 https://isc.sans.edu/podcastdetail/10012, (Fri, Jul 17th) The ISC Stormcast highlighted a significant vulnerability in the latest version of Apache Log4j, potentially allowing attackers to execute arbitrary code through a specially crafted log message. This vulnerability, along… SANS Internet Storm Center · Jul 17, 2026 Critical log4jjndivulnerability
vulnerability Multiples vulnérabilités dans Microsoft Windows (17 juillet 2026) Microsoft has announced multiple vulnerabilities across various versions of Windows, including Windows 10 and 11. These vulnerabilities could allow attackers to execute arbitrary code remotely, elevate privileges, and co… CERT-FR · Jul 17, 2026 High CVE-2026-56171CVE-2026-58598CVE-2026-58643windowsvulnerabilitypatch
vulnerability Multiples vulnérabilités dans les produits Microsoft (17 juillet 2026) Multiple vulnerabilities have been discovered in Microsoft products, primarily within SharePoint, allowing attackers to compromise data confidentiality and bypass security policies. Microsoft has released security bullet… CERT-FR · Jul 17, 2026 Medium CVE-2026-56171CVE-2026-62826sharepointvulnerabilitymicrosoft
vulnerability Multiples vulnérabilités dans le noyau Linux de Red Hat (17 juillet 2026) Multiple vulnerabilities have been discovered in Red Hat's Linux kernel. These vulnerabilities can lead to arbitrary code execution, privilege escalation, and a denial-of-service attack. Red Hat has released security adv… CERT-FR · Jul 17, 2026 High CVE-2025-38653CVE-2025-68183CVE-2025-68724linuxkernelvulnerability
vulnerability Multiples vulnérabilités dans Google Chrome (17 juillet 2026) Multiple vulnerabilities have been discovered in Google Chrome, impacting older versions of the browser. The exact nature of the security issue is not specified by the publisher, but users are advised to update to the la… CERT-FR · Jul 17, 2026 Medium CVE-2026-15899CVE-2026-15900CVE-2026-15901vulnerabilitychromesecurity
vulnerability n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer A vulnerability in n8n’s Enterprise token exchange feature allows attackers to log in as users from another issuer if the platform trusts more than one external token issuer. The flaw stems from a mismatch between the is… The Hacker News · Jul 16, 2026 High CVE-2026-59208CVE-2026-54305jwttokenidentity-binding
vulnerability Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix Several vulnerabilities exist in Rockwell Automation's CompactLogix, ControlLogix, Compact GuardLogix, and GuardLogix controllers. Successful exploitation could lead to a denial-of-service condition due to an invalid pro… CISA Advisories · Jul 16, 2026 High CVE-2025-12011CVE-2025-12012CVE-2025-11698firmwarecontrol-systemdenial-of-service
vulnerability Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT Rockwell Automation has released a vulnerability in its 1756-EN2, 1756-EN3, and 1756-ENBT communication modules. Exploitation could lead to a denial-of-service condition. Users are advised to update to the latest version… CISA Advisories · Jul 16, 2026 High CVE-2026-9653vulnerabilitycontrol systemscisa
vulnerability Rockwell Automation Arena Rockwell Automation has released an advisory regarding critical vulnerabilities in its Arena simulation software. Specifically, versions up to V17.00.00 are affected by memory corruption flaws that could allow an attacke… CISA Advisories · Jul 16, 2026 High CVE-2026-8085CVE-2026-8312CVE-2026-8313vulnerabilitycontrol-systemmemory-corruption
vulnerability SALTO ProAccess Space A critical vulnerability (CVE-2026-11889) exists in SALTO ProAccess Space versions prior to 6.13, allowing an authenticated attacker to escalate privileges and gain unauthorized access to spaces beyond their assigned par… CISA Advisories · Jul 16, 2026 Critical CVE-2026-11889WOvulnerabilityprivilege escalationcve-2026-11889
vulnerability AutomationDirect Productivity Suite AutomationDirect Productivity Suite versions 4.6.2.2 and earlier are vulnerable to multiple out-of-bounds read and write vulnerabilities, potentially leading to kernel memory corruption, privilege escalation, system inst… CISA Advisories · Jul 16, 2026 High CVE-2026-60063CVE-2026-61389CVE-2026-60140cvevulnerabilityioctl
vulnerability Rockwell Automation Flex 5000 Adapter Rockwell Automation has released a security advisory regarding a denial-of-service vulnerability in its Flex 5000 Adapter software. Exploitation could lead to a denial-of-service condition, and Rockwell recommends upgrad… CISA Advisories · Jul 16, 2026 High CVE-2026-12659vulnerabilitydenial-of-servicecontrol systems
vulnerability NASA Core Flight System (cFS) Health & Safety (HS) Application NASA has issued an advisory regarding a vulnerability in its Core Flight System (cFS) Health & Safety (HS) Application, potentially leading to denial-of-service conditions. The vulnerability, identified as a segmentation… CISA Advisories · Jul 16, 2026 Medium CVE-2026-15352vulnerabilitysegmentation faultcisa
vulnerability Rockwell Automation FactoryTalk DataMosaix Rockwell Automation has issued a security advisory regarding a critical vulnerability (CVE-2026-9292) in its FactoryTalk DataMosaix Private Cloud software. An authenticated attacker can inject malicious scripts that are… CISA Advisories · Jul 16, 2026 Critical CVE-2026-9292cve-2026-9292xsscwe-79
vulnerability Splunk, Zoom Patch Critical Vulnerabilities Splunk and Zoom have released patches to address several critical and high-severity vulnerabilities in their respective products. These flaws could allow attackers to steal credentials, access sensitive data, and potenti… SecurityWeek · Jul 16, 2026 High CVE-2026-20296CVE-2026-20297CVE-2026-20298vulnerabilitypatchsecurity
vulnerability Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide A researcher discovered a critical vulnerability in Shark robot vacuums due to a flawed certificate policy on Amazon's AWS cloud platform. Attackers can exploit this to gain remote control of vacuums across an entire AWS… The Hacker News · Jul 16, 2026 Critical awsiotcertificate
vulnerability F5 Patches Multiple NGINX, BIG-IP Vulnerabilities F5 has released out-of-band security patches to address eight critical vulnerabilities affecting NGINX and BIG-IP. These flaws could lead to denial-of-service attacks, memory leaks, and potentially allow remote code exec… SecurityWeek · Jul 16, 2026 High CVE-2026-42533nginxbig-ipvulnerability