vulnerability Multiples vulnérabilités dans les produits Mattermost (15 juin 2026) Multiple vulnerabilities have been discovered in Mattermost Server, potentially allowing an attacker to cause a security issue not specified by the vendor. These vulnerabilities could lead to data integrity and confident… CERT-FR · Jun 15, 2026 Medium CVE-2026-10085CVE-2026-10103CVE-2026-10106vulnerabilitymattermostsecurity
vulnerability Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication A critical vulnerability (CVE-2026-20253) has been identified in Splunk Enterprise versions below 10.2.4 and 10.0.7, allowing unauthenticated users to execute arbitrary code and potentially gain remote access. The flaw s… The Hacker News · Jun 13, 2026 Critical CVE-2026-20253USremote code executionauthenticationpostgresql
vulnerability phpBB forum fixes auth bypass bug lurking for a decade A 10-year-old authentication bypass vulnerability discovered in the phpBB forum software allows an attacker to log in as any user, including administrators. BleepingComputer · Jun 12, 2026 Medium
vulnerability Ivanti Sentry Exploitation Attempts Hitting Honeypots A recently patched vulnerability in Ivanti Sentry, CVE-2026-10520, has been observed attempting exploitation on honeypots, according to Ivanti and CISA. The flaw allows for remote code execution with root privileges via… SecurityWeek · Jun 12, 2026 High CVE-2026-10520USvulnerabilitycommand injectionroot privilege
vulnerability Chrome 149 Update Patches 28 Vulnerabilities The browser refresh resolved critical and high-severity security defects, including a dozen use-after-free bugs. The post Chrome 149 Update Patches 28 Vulnerabilities appeared first on SecurityWeek . SecurityWeek · Jun 12, 2026 High
vulnerability CISA orders feds to patch actively exploited Ivanti flaw by Sunday CISA has issued a Binding Operational Directive (BOD) 26-04, mandating that federal agencies patch an actively exploited vulnerability (CVE-2026-10520) in Ivanti Sentry security gateways within three days. This vulnerabi… BleepingComputer · Jun 12, 2026 Critical CVE-2026-10520patchingcisavulnerability
vulnerability Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters Oracle has mitigated CVE-2026-35273, but it has not publicly confirmed the vulnerability’s in-the-wild exploitation. The post Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters appeared first on S… SecurityWeek · Jun 12, 2026 Critical CVE-2026-35273
vulnerability ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities The ShinyHunters extortion group exploited a zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft to gain unauthorized access to university systems, resulting in data theft and a demand for payment. Mandiant iden… The Hacker News · Jun 11, 2026 High CVE-2026-35273GBUSzero-dayexploitationuniversity
vulnerability Oracle mitigates PeopleSoft zero-day exploited in data theft attacks A critical zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft PeopleTools has been exploited by the ShinyHunters ransomware gang to steal data from numerous organizations. Oracle has released mitigations, but t… BleepingComputer · Jun 11, 2026 Critical CVE-2026-35273zero-daydata theftpeoplesoft
vulnerability Max-Severity Ivanti Flaw Exploited 24 Hours After Disclosure A critical vulnerability (CVE-2026-10520) in Ivanti Sentry was exploited within 24 hours of its disclosure, highlighting the speed at which attackers can react to newly released vulnerabilities. The flaw, an OS command i… Dark Reading · Jun 11, 2026 Critical CVE-2026-10520CVE-2026-10523CVE-2026-1340vulnerabilitycommand injectionroot access
vulnerability Oracle Addresses PeopleSoft Vulnerability Amid Reports of Zero-Day Attacks Oracle has released a patch for CVE-2026-35273, but it has not said whether it’s a zero-day exploited in ShinyHunters attacks. The post Oracle Addresses PeopleSoft Vulnerability Amid Reports of Zero-Day Attacks appeared… SecurityWeek · Jun 11, 2026 Critical CVE-2026-35273
vulnerability Brickcom Cameras This CISA advisory details a critical vulnerability in Brickcom cameras (Cube, Dome, Bullet, and Box models, version 3.2.3.5.6) that allows unauthenticated remote attackers to access live video feeds and retrieve sensiti… CISA Advisories · Jun 11, 2026 Critical CVE-2026-50245CVE-2026-50005default credentialsonvifremote access
vulnerability Hackers Exploit Langflow Vulnerability for Remote Code Execution Disclosed in March, the security defect enables unauthenticated attackers to write files to arbitrary locations on the system. The post Hackers Exploit Langflow Vulnerability for Remote Code Execution appeared first on S… SecurityWeek · Jun 11, 2026 High CVE-2026-5027
vulnerability Splunk, Palo Alto Networks Patch Severe Vulnerabilities The security defects could allow attackers to create or modify arbitrary files and access and modify protected resources. The post Splunk, Palo Alto Networks Patch Severe Vulnerabilities appeared first on SecurityWeek . SecurityWeek · Jun 11, 2026 High CVE-2026-0274CVE-2026-20253
vulnerability ‘GreatXML’ Zero-Day Exploit Bypasses BitLocker The PoC exploits Microsoft Defender’s offline scan to spawn a SYSTEM shell when rebooting in Recovery Mode. The post ‘GreatXML’ Zero-Day Exploit Bypasses BitLocker appeared first on SecurityWeek . SecurityWeek · Jun 11, 2026 Critical
vulnerability Microsoft fixes BitLocker recovery bug on Windows Server 2025 Microsoft released updates (KB5094125 and KB5093998) to address a bug in Windows Server 2025 and Windows 11 that caused BitLocker recovery prompts after installing security updates. The issue stemmed from specific Group… BleepingComputer · Jun 11, 2026 Medium bitlockertpmgroup policy
vulnerability Microsoft Patches Exploited Exchange Server Vulnerability The company warned about zero-day attacks exploiting the Exchange Server vulnerability CVE-2026-42897 on May 14. The post Microsoft Patches Exploited Exchange Server Vulnerability appeared first on SecurityWeek . SecurityWeek · Jun 11, 2026 Critical CVE-2026-42897
vulnerability Max severity Ivanti Sentry vulnerability now exploited in attacks Attackers are now targeting a recently patched maximum-severity flaw in Ivanti Sentry, enabling them to execute code with root privileges on Internet-exposed secure mobile gateways. BleepingComputer · Jun 11, 2026 Medium CVE-2026-10520
vulnerability Vulnérabilité dans Traefik (11 juin 2026) A security vulnerability has been identified in Traefik, allowing attackers to bypass security policies. This issue affects older versions of the popular reverse proxy and load balancer, requiring immediate patching to p… CERT-FR · Jun 11, 2026 Medium CVE-2026-54761traefikvulnerabilitysecurity
vulnerability Vulnérabilité dans LibreNMS (11 juin 2026) A critical vulnerability has been identified in LibreNMS, allowing attackers to execute arbitrary code remotely. This affects versions 21.6.x through 26.x, and requires immediate patching to prevent exploitation. CERT-FR · Jun 11, 2026 Critical CVE-2026-55182librenmsremote code executionvulnerability