vulnerability CISA Warns of Exploited Oracle WebLogic Vulnerability The CISA has issued a critical warning to federal agencies about a widely exploited vulnerability in Oracle WebLogic servers (CVE-2026-21962). This flaw allows attackers to execute code remotely without authentication, a… SecurityWeek · 5d ago Critical CVE-2026-21962CNoracleweblogicvulnerability
vulnerability Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data A critical, actively exploited vulnerability in Oracle WebLogic Server allows unauthenticated attackers to access sensitive data. Despite patches being released in January, threat actors are still leveraging this flaw, p… The Hacker News · 5d ago Critical CVE-2026-21962CVE-2020-14882CVE-2020-2551rceweblogiccve-2026-21962
vulnerability ISC Stormcast For Tuesday, August 25th, 2026 https://isc.sans.edu/podcastdetail/10066, (Tue, Aug 25th) The ISC Stormcast highlighted a significant vulnerability in the latest version of Apache Log4j, potentially allowing attackers to execute arbitrary code through a specially crafted log message. This exploit could lead t… SANS Internet Storm Center · 6d ago Critical log4jlog4shellremote code execution
vulnerability Multiples vulnérabilités dans Keycloak (25 août 2026) Multiple vulnerabilities have been discovered in Keycloak, allowing an attacker to bypass security policies and potentially take control of an account if they know its identifier. The CERT-FR has a proof of concept for C… CERT-FR · 6d ago Medium CVE-2026-18963CVE-2026-14613CVE-2026-15571keycloakvulnerabilityauthentication
vulnerability Multiples vulnérabilités dans Cisco IOS XE (25 août 2026) Cisco has announced multiple vulnerabilities in its IOS XE software, allowing attackers to bypass security policies and potentially cause unspecified security issues. These vulnerabilities affect several versions of the… CERT-FR · 6d ago High CVE-2026-20267CVE-2026-20268CVE-2026-20269ciscoios xevulnerability
vulnerability Exploited Zimbra Flaw Highlights Shrinking Window to Patch A critical vulnerability in Zimbra Unified Communications Suite (ZCS) is being aggressively exploited, prompting CISA to issue a three-day deadline for federal agencies to patch. The flaw, CVE-2026-73570, allows unauthen… Dark Reading · 6d ago High CVE-2026-73570CVE-2026-73750CVE-2025-66376PORULIpatchingvulnerabilityremote code execution
vulnerability Browser fingerprint tool shows how easy you are to track using the latest sneaky tricks A vulnerability in Joomla extensions, specifically iCagenda and Balbooa Forms, is being exploited by attackers to compromise websites running on vulnerable CMS platforms. This allows attackers to gain unauthorized access… The Register · 6d ago Medium joomlaextensionvulnerability
vulnerability 91 Vulnerabilities Patched in Spring Application Framework Broadcom released a massive update addressing 91 vulnerabilities within the Spring application framework. Many of these flaws, including a critical Remote Code Execution (RCE) vulnerability, could be exploited for variou… SecurityWeek · 6d ago High CVE-2026-59270CVE-2026-59285CVE-2026-59318springvulnerabilityrce
vulnerability Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account A critical vulnerability (CVE-2026-18963) in Keycloak allows unauthenticated attackers to force a password reset and take over any user account, including administrative accounts. Red Hat and Keycloak have released patch… The Hacker News · 6d ago Critical CVE-2026-18963CVE-2026-15571password-resetauthenticationkeycloak
vulnerability ISC Stormcast For Monday, August 24th, 2026 https://isc.sans.edu/podcastdetail/10064, (Mon, Aug 24th) The ISC Stormcast highlighted a significant vulnerability in the latest version of Apache Log4j, potentially allowing attackers to execute arbitrary code through a specially crafted log message. This vulnerability is act… SANS Internet Storm Center · Aug 24, 2026 Critical log4jremote code executionapache
vulnerability Multiples vulnérabilités dans LibreNMS (24 août 2026) Multiple vulnerabilities have been discovered in LibreNMS, allowing an attacker to compromise data confidentiality and bypass security policies. Users of LibreNMS versions prior to 26.8.0 are strongly advised to apply th… CERT-FR · Aug 24, 2026 Medium librenmsvulnerabilitynetwork monitoring
vulnerability Multiples vulnérabilités dans Metabase (24 août 2026) Multiple vulnerabilities have been discovered in Metabase, allowing attackers to potentially compromise data confidentiality through SQL injection and an unspecified security issue. These vulnerabilities affect older ver… CERT-FR · Aug 24, 2026 Medium CVE-2026-72898CVE-2026-72899CVE-2026-72900sql injectionvulnerabilitymetabase
vulnerability Critical Isolated-vm Vulnerability Leads to RCE on Host A critical type confusion vulnerability in the isolated-vm Node.js library is being exploited to achieve remote code execution (RCE) on the host system. The vulnerability stems from a flawed data transfer mechanism withi… SecurityWeek · Aug 21, 2026 Critical rcetype-confusionnode.js
vulnerability Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0 Cisco has released security updates to address nine vulnerabilities affecting its Crosswork and Secure Workload platforms. These flaws, discovered during internal testing, range in severity from critical to medium and co… The Hacker News · Aug 21, 2026 High CVE-2026-20030CVE-2026-20357CVE-2026-20358securitypatchvulnerability
vulnerability Microsoft Rolls Out 22 Fresh Security Patches Microsoft released 22 security patches addressing critical and high-severity vulnerabilities across its Azure, Entra ID, Exchange, Fabric, and Defender products. Several of these flaws, including a zero-day exploit dubbe… SecurityWeek · Aug 21, 2026 Critical CVE-2026-69502CVE-2026-69555CVE-2026-65816vulnerabilitypatchzero-day
vulnerability CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning to federal agencies regarding two critical vulnerabilities in TrueConf, a secure video conferencing platform. Threat actors, spe… SecurityWeek · Aug 21, 2026 High CVE-2026-72529CVE-2026-72530RUBYvulnerabilitypatchtrueconf
vulnerability GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure A critical vulnerability (CVE-2026-19478) in GitLab, allowing unauthenticated code injection and data manipulation, has been actively exploited shortly after its disclosure. This poses a significant risk to organizations… The Hacker News · Aug 21, 2026 Critical CVE-2026-19478vulnerabilitycode-injectiongraphql
vulnerability Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution Microsoft has patched a critical vulnerability in Entra ID, which has been exploited in the wild. The flaw allows remote code execution, and while Microsoft has addressed it, it highlights the ongoing need for vigilance… The Hacker News · Aug 21, 2026 Critical CVE-2026-69836CVE-2026-68820entria idazure adremote code execution
vulnerability Vulnérabilité dans Microsoft Entra ID (21 août 2026) A critical vulnerability (CVE-2026-69836) has been identified in Microsoft Entra ID, allowing for remote code execution. While initially reported as actively exploited, Microsoft has clarified that it is currently not be… CERT-FR · Aug 21, 2026 Critical CVE-2026-69836entria idremote code executioncve
vulnerability Multiples vulnérabilités dans Traefik (21 août 2026) Multiple vulnerabilities have been discovered in Traefik, allowing attackers to bypass security policies. These vulnerabilities affect older versions of the popular reverse proxy and load balancer, requiring immediate pa… CERT-FR · Aug 21, 2026 Medium vulnerabilitysecuritytraefik