vulnerability Zoom Patches Critical Windows Flaw That Could Enable Account Takeover Zoom has released critical security patches to address a series of vulnerabilities in its Windows-based products, including Zoom Workplace, Zoom VDI Client, and Zoom Rooms. These flaws could allow attackers to gain unaut… The Hacker News · Jul 16, 2026 High CVE-2026-53412CVE-2026-53411CVE-2026-53410windowsvulnerabilityaccount_takeover
vulnerability Nightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day Nightmare Eclipse, a security researcher, has released another unpatched Windows zero-day vulnerability, LegacyHive, which allows local privilege escalation. This exploit targets the Windows User Profile Service and requ… SecurityWeek · Jul 16, 2026 High zero-dayprivilege-escalationwindows
vulnerability Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities Several cybersecurity firms, including Trend Micro, Tenable, ESET, and Palo Alto Networks, have released patches to address critical vulnerabilities in their products. These vulnerabilities range from local privilege esc… SecurityWeek · Jul 16, 2026 High CVE-2026-15265vulnerabilitypatchsecurity
vulnerability Vulnérabilité dans les produits ESET (16 juillet 2026) A denial-of-service vulnerability has been identified in ESET’s endpoint and server security products. Specifically, versions 12.0.x through 12.0.14.0, 12.1.x through 12.1.2.0, 12.2.x through 12.2.9.0, 13.0.x through 13.… CERT-FR · Jul 16, 2026 Medium CVE-2026-6424denial-of-servicevulnerabilityeset
vulnerability Multiples vulnérabilités dans les produits Splunk (16 juillet 2026) Multiple vulnerabilities have been discovered in Splunk products, including Splunk Cloud Platform and Enterprise versions. These vulnerabilities allow for data confidentiality and integrity breaches, as well as the poten… CERT-FR · Jul 16, 2026 High CVE-2025-30204CVE-2025-47913CVE-2025-61726vulnerabilitypatchsecurity
vulnerability Vulnérabilité dans Ruby on Rails (16 juillet 2026) A vulnerability in Ruby on Rails versions prior to 1.7.1 allows for remote code injection via XSS. This means attackers could potentially execute malicious code on vulnerable systems, requiring immediate patching to prev… CERT-FR · Jul 16, 2026 Medium rubyrailsxss
vulnerability Multiples vulnérabilités dans Drupal (16 juillet 2026) Multiple vulnerabilities have been discovered in Drupal, allowing attackers to compromise data confidentiality and inject malicious code remotely. These vulnerabilities affect older versions of the CMS, requiring immedia… CERT-FR · Jul 16, 2026 Medium CVE-2026-15916CVE-2026-15917CVE-2026-55805drupalvulnerabilitycve
vulnerability Vulnérabilité dans Traefik (16 juillet 2026) A security vulnerability has been identified in Traefik versions 3.7.x, allowing attackers to bypass security policies. Users are advised to apply the latest security patch released by Traefik to mitigate this risk. CERT-FR · Jul 16, 2026 Medium traefikvulnerabilitysecurity
vulnerability Multiples vulnérabilités dans les produits F5 (16 juillet 2026) Multiple vulnerabilities have been discovered in F5 products, including BIG-IP, WAF, and NGINX. These vulnerabilities could allow an attacker to achieve remote code execution, denial of service, and data confidentiality… CERT-FR · Jul 16, 2026 High CVE-2026-42533CVE-2026-46333CVE-2026-52865securityvulnerabilitypatch
vulnerability Multiples vulnérabilités dans Cisco RoomOS (16 juillet 2026) Multiple vulnerabilities have been discovered in Cisco RoomOS, potentially allowing attackers to compromise data confidentiality and bypass security policies. These vulnerabilities affect older versions of the operating… CERT-FR · Jul 16, 2026 Medium CVE-2026-20150CVE-2026-20153CVE-2026-20156ciscoroomosvulnerability
vulnerability Unpatched Cursor Vulnerability Exposes Users to Code Execution A critical, unpatched vulnerability in Cursor, a popular AI-assisted development environment, allows for code execution simply by opening a project containing a malicious git.exe binary. Despite being reported to Cursor… SecurityWeek · Jul 15, 2026 Critical cursorgitcode execution
vulnerability CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities The CISA is urging immediate patching of Microsoft SharePoint servers due to several recently disclosed zero-day vulnerabilities. These flaws could allow remote code execution and enable attackers to steal sensitive info… SecurityWeek · Jul 15, 2026 High CVE-2026-56164CVE-2026-55040CVE-2026-58644zero-dayremote code executioniis
vulnerability Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws Multiple security flaws have been patched across Firefox, Chrome, Adobe products (including ColdFusion, Commerce, Experience Manager, and Illustrator), and VMware. Mozilla addressed two critical vulnerabilities in Firefo… The Hacker News · Jul 15, 2026 High CVE-2026-15718CVE-2026-15719CVE-2026-15764UNsecurity updatevulnerabilitypatch
vulnerability 2-Click Cursor Exploit Enables Dev Environment Takeover A vulnerability in Cursor AI, an AI coding tool used by over 50,000 enterprises including 64% of the Fortune 500, allows attackers to install malicious code through a cleverly disguised pull request link. Researchers at… Dark Reading · Jul 15, 2026 High aisecuritypull request
vulnerability Microsoft smashes Patch Tuesday record for second successive month Microsoft released a massive Patch Tuesday update, exceeding 600 security vulnerabilities – the largest in the program's history. This surge in vulnerabilities, driven in part by AI-assisted discovery, has led to a signi… The Record · Jul 15, 2026 High CVE-2026-56164CVE-2026-56155CVE-2026-55040UNpatch tuesdayvulnerabilityexploit
vulnerability Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday Security researcher Chaotic Eclipse has released a proof-of-concept (PoC) exploit, LegacyHive, targeting a Windows User Profile Service vulnerability that allows arbitrary hive loading and privilege escalation. This expl… The Hacker News · Jul 15, 2026 High CVE-2026-56164CVE-2026-56155CVE-2026-32201vulnerabilityprivilege escalationsharepoint
vulnerability Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow Fortinet, Ivanti, and ServiceNow have released patches to address 15 vulnerabilities across their products. The most critical issue involves a remote code execution flaw in ServiceNow's AI platform, while Fortinet addres… SecurityWeek · Jul 15, 2026 High CVE-2026-6875CVE-2026-14902CVE-2026-14903vulnerabilitypatchremote code execution
vulnerability Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution A vulnerability in Cursor, a Git repository hosting platform for Windows, allows malicious cloned repositories to execute arbitrary code on the user's system. The flaw stems from Cursor's tendency to run a `git.exe` file… The Hacker News · Jul 15, 2026 High CVE-2026-26268CVE-2026-10591CVE-2020-26233gitwindowscode execution
vulnerability Progress Confirms Zero-Day Vulnerability Behind ShareFile Disruption Progress Software has confirmed a zero-day vulnerability in its ShareFile Storage Zones Controller, leading to a service disruption and prompting customers to shut down their servers. While access is now being restored w… SecurityWeek · Jul 15, 2026 High zero-dayvulnerabilitypath traversal
vulnerability Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates Google and Mozilla have released security updates for Chrome and Firefox, addressing several critical vulnerabilities. These updates include patches for zero-day exploits and prevent potential attacks. While exploit code… SecurityWeek · Jul 15, 2026 High CVE-2026-15718CVE-2026-15719CVE-2026-15764vulnerabilityzero-daypatch