vulnerability Multiples vulnérabilités dans Microsoft Edge (21 août 2026) Microsoft Edge is experiencing multiple vulnerabilities, as detailed in security advisories released by CERT-FR. These vulnerabilities could allow an attacker to trigger an unspecified security issue. Users of Microsoft… CERT-FR · Aug 21, 2026 Medium CVE-2026-76033CVE-2026-76034CVE-2026-76035vulnerabilitymicrosoftedge
vulnerability Vulnérabilité dans Microsoft Entra ID (21 août 2026) A critical vulnerability (CVE-2026-69836) has been identified in Microsoft Entra ID, allowing for remote code execution. While initially reported as actively exploited, Microsoft has clarified that it is currently not be… CERT-FR · Aug 21, 2026 Critical CVE-2026-69836entria idremote code executioncve
vulnerability Multiples vulnérabilités dans Google Chrome (21 août 2026) Multiple vulnerabilities have been discovered in Google Chrome, impacting older versions of the browser on Linux, Windows, and macOS. The exact nature of the vulnerabilities is not specified, but users are advised to upd… CERT-FR · Aug 21, 2026 Medium CVE-2026-76017CVE-2026-76018CVE-2026-76019chromevulnerabilitysecurity
vulnerability Vulnérabilité dans SPIP (21 août 2026) A remote code execution vulnerability has been discovered in SPIP, allowing attackers to execute arbitrary code from a remote location. The vulnerability is currently being actively exploited, and users of SPIP versions… CERT-FR · Aug 21, 2026 High CVE-2026-77806remote-code-executionvulnerabilitysecurity
vulnerability Multiples vulnérabilités dans les produits Microsoft (21 août 2026) Multiple vulnerabilities have been discovered in Microsoft products, allowing attackers to bypass security policies and cause denial-of-service conditions. Microsoft has released security bulletins detailing the issues a… CERT-FR · Aug 21, 2026 Medium CVE-2026-55013CVE-2026-55015microsoftvulnerabilitysecurity
vulnerability Vulnérabilité dans Microsoft Office (21 août 2026) A vulnerability has been discovered in Microsoft Office that could allow an attacker to compromise data confidentiality. Affected versions of Office, including Office 365 and Office 2019, require immediate patching to pr… CERT-FR · Aug 21, 2026 Medium CVE-2026-70105vulnerabilitymicrosoftpatch
vulnerability Vulnérabilité dans Python (21 août 2026) A security vulnerability has been identified in Python, allowing attackers to bypass security policies. This stems from a flaw in the Python interpreter, requiring users to apply security updates to mitigate the risk. CERT-FR · Aug 21, 2026 Medium CVE-2026-19672pythonvulnerabilitysecurity
vulnerability Multiples vulnérabilités dans le noyau Linux d'Ubuntu (21 août 2026) Multiple vulnerabilities have been discovered in the Linux kernel of Ubuntu. Some of these vulnerabilities allow for privilege escalation, data confidentiality compromise, and data integrity compromise. These vulnerabili… CERT-FR · Aug 21, 2026 CVE-2021-47354CVE-2021-47378CVE-2024-38612
vulnerability Multiples vulnérabilités dans le noyau Linux de Debian (21 août 2026) Multiple vulnerabilities have been discovered in the Linux kernel of Debian, allowing an attacker to potentially elevate their privileges. These vulnerabilities are present in older Debian versions and require immediate… CERT-FR · Aug 21, 2026 Medium CVE-2026-13595CVE-2026-27456CVE-2026-53612linuxkerneldebian
vulnerability N-able Bug Exposes Password Vault Master Keys N-able Passportal, a popular password manager used by MSPs and SMBs, has a significant security vulnerability allowing malicious websites to steal users' vault credentials. The browser extension blindly trusts all incomi… Dark Reading · Aug 20, 2026 High password managerbrowser extensioncloud security
vulnerability Researcher tricks Apple’s Find My into sharing location data with Linux A security researcher successfully tricked Apple’s Find My feature into revealing their location data by exploiting a flaw in the system. This demonstrates a vulnerability that could be used to track users, highlighting… The Register · Aug 20, 2026 Medium locationprivacysecurity
vulnerability Hackers Target Zimbra Servers in Active Exploitation Campaign A recently patched Zimbra vulnerability (CVE-2026-73570) is currently being actively exploited by threat actors, primarily linked to Russian and Chinese state-sponsored hackers. Attackers are leveraging this flaw to gain… SecurityWeek · Aug 20, 2026 Critical CVE-2026-73570PLzimbravulnerabilitysnmp
vulnerability Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE A critical vulnerability in isolated-vm, a popular JavaScript sandbox library, allows attackers to escape the sandbox environment and potentially execute code on the host system. The flaw stems from a type confusion issu… The Hacker News · Aug 20, 2026 Critical vulnerabilitysandboxjavascript
vulnerability Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers Citrix has released security updates to address two critical vulnerabilities in NetScaler ADC and NetScaler Gateway, including a high-severity authentication bypass. These flaws primarily affect deployments where specifi… The Hacker News · Aug 20, 2026 High CVE-2026-19489CVE-2026-19490CVE-2026-8451authenticationvpnsaml
vulnerability Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution A critical security flaw in Zimbra Collaboration (ZCS) has been actively exploited in the wild, allowing attackers to execute arbitrary commands without authentication. The vulnerability, CVE-2026-73570, stems from impro… The Hacker News · Aug 20, 2026 Critical CVE-2026-73570CVE-2025-66376PLsnmpcommand injectionremote code execution
vulnerability Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities Atlassian and Splunk have released patches to address over 250 vulnerabilities across their products, including numerous critical and high-severity flaws in third-party dependencies. These updates aim to mitigate risks s… SecurityWeek · Aug 20, 2026 High vulnerabilitypatchthird-party
vulnerability MLflow Vulnerability Exploited for Cloud Credential Theft A vulnerability in MLflow, a popular AI engineering platform, has been exploited by threat actors to steal cloud credentials and secrets. The flaw, tracked as CVE-2026-64849, allows unauthenticated SSRF attacks, leading… SecurityWeek · Aug 20, 2026 Critical CVE-2026-64849ssrfcloudmlflow
vulnerability Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments Researchers at the University of Massachusetts Amherst have demonstrated a method to revive expired Visa credit cards for contactless payments by rewriting the expiration date on a POS terminal, bypassing standard crypto… The Hacker News · Aug 20, 2026 High UScontactlessnfcexpiry
vulnerability Johnson Controls Simplex Incident Manager A critical vulnerability in Johnson Controls Simplex Incident Manager allows a local attacker with low privileges to extract user credentials (passwords and authentication tokens) from system memory, potentially leading… CISA Advisories · Aug 20, 2026 Critical CVE-2026-27875memory-dumpingcredential theftbuilding automation
vulnerability Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities Cisco has released patches to address 15 critical and high-severity vulnerabilities across its products, including Crosswork and BroadWorks. These flaws could lead to remote code execution, authentication bypasses, and d… SecurityWeek · Aug 20, 2026 High CVE-2026-20030CVE-2026-20357CVE-2026-20358vulnerabilitypatchsecurity