vulnerability NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands A security vulnerability in NASA/JPL's AMMOS Instrument Toolkit's AIT-GUI browser-based operator console allows unauthenticated attackers to issue arbitrary commands to spacecraft and instruments. Researchers at Cycode d… The Hacker News · Aug 20, 2026 High CVE-2026-60112CVE-2026-47731CVE-2026-71214browserauthenticationcommand-injection
vulnerability Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler Citrix has announced patches for a critical authentication bypass vulnerability in its NetScaler ADC and NetScaler Gateway products. This flaw, with a CVSS score of 9.3, allows unauthenticated remote attackers to gain ac… SecurityWeek · Aug 20, 2026 Critical CVE-2026-19490CVE-2026-19489patchauthenticationvulnerability
vulnerability Critical GitLab Flaw Exploited Shortly After Disclosure A critical vulnerability in GitLab (CVE-2026-19478) was quickly exploited by threat actors shortly after its disclosure. The code injection flaw allowed unauthenticated users to delete public projects and modify user dat… SecurityWeek · Aug 20, 2026 Critical CVE-2026-19478gitlabvulnerabilitygraphql
vulnerability Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code A critical vulnerability (CVE-2026-32475) in the Elementor Pro WordPress plugin allows unauthenticated attackers to upload PHP files and execute code, potentially leading to remote code execution. The flaw stems from a d… The Hacker News · Aug 20, 2026 High CVE-2026-32475CVE-2026-65640wordpressvulnerabilityremote-code-execution
vulnerability Multiples vulnérabilités dans les produits Splunk (20 août 2026) Multiple vulnerabilities have been discovered in Splunk products, including remote code execution, privilege escalation, and data confidentiality breaches. Several of these vulnerabilities can be exploited to achieve rem… CERT-FR · Aug 20, 2026 CVE-2024-35255CVE-2025-13465CVE-2025-13473vulnerabilitydata breachsupply chain
vulnerability Multiples vulnérabilités dans les produits Cisco (20 août 2026) Multiple vulnerabilities have been discovered in Cisco products, including BroadWorks Application Delivery Platform, BroadWorks Application Server, and BroadWorks Profile Server. These vulnerabilities allow for remote co… CERT-FR · Aug 20, 2026 High CVE-2026-20030CVE-2026-20231CVE-2026-20315ciscovulnerabilityremote code execution
vulnerability Multiples vulnérabilités dans Ceph (20 août 2026) Multiple vulnerabilities have been discovered in Ceph, allowing an attacker to elevate privileges, compromise data confidentiality, and bypass security policies. These vulnerabilities affect older versions of the distrib… CERT-FR · Aug 20, 2026 High CVE-2025-30156CVE-2026-39944CVE-2026-50152cephvulnerabilitysecurity
vulnerability Multiples vulnérabilités dans les produits Citrix (20 août 2026) Multiple vulnerabilities have been discovered in Citrix products, including NetScaler ADC and NetScaler Gateway. These flaws could allow attackers to cause a denial-of-service, bypass security policies, and create an uns… CERT-FR · Aug 20, 2026 Medium CVE-2026-19489CVE-2026-19490citrixvulnerabilitysecurity
vulnerability Multiples vulnérabilités dans Microsoft Windows (20 août 2026) Multiple vulnerabilities have been discovered in Microsoft Windows, allowing an attacker to elevate privileges and compromise data confidentiality. These vulnerabilities affect a wide range of Windows versions and server… CERT-FR · Aug 20, 2026 High CVE-2026-62727CVE-2026-69550securitypatchvulnerability
vulnerability Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second Researchers have demonstrated a significant vulnerability in Cloudflare Workers, allowing a remote Spectre attack to leak JWTs from co-located Workers at a rate up to 12 bits per second. Despite previous mitigations like… The Hacker News · Aug 19, 2026 High spectredyprisjwt
vulnerability Chrome, Firefox Updates Patch Dozens of Vulnerabilities Google and Mozilla have released security updates for Chrome and Firefox, addressing a significant number of vulnerabilities, including critical and high-severity flaws. These updates aim to prevent exploitation of issue… SecurityWeek · Aug 19, 2026 High vulnerabilitypatchsecurity
vulnerability Multiples vulnérabilités dans les produits Axis (19 août 2026) Multiple vulnerabilities have been discovered in Axis products, including remote code execution, privilege escalation, and denial-of-service attacks. These vulnerabilities affect various Axis products, requiring immediat… CERT-FR · Aug 19, 2026 High CVE-2026-4757CVE-2026-5303CVE-2026-5304vulnerabilityremote code executionprivilege escalation
vulnerability Multiples vulnérabilités dans Synacor Zimbra Collaboration (19 août 2026) Multiple vulnerabilities have been discovered in Synacor Zimbra Collaboration, allowing attackers to execute arbitrary code remotely, perform server-side request forgery (SSRF), and inject remote code via XSS. The ENISA… CERT-FR · Aug 19, 2026 High CVE-2026-73570CVE-2026-10631CVE-2026-50054zimbravulnerabilityssrf
vulnerability Multiples vulnérabilités dans Oracle Virtualization (19 août 2026) Multiple vulnerabilities have been discovered in Oracle Virtualization, primarily affecting Oracle VM VirtualBox version 7.2.14. These vulnerabilities allow for denial of service, data confidentiality breaches, and data… CERT-FR · Aug 19, 2026 High CVE-2026-71113CVE-2026-71114CVE-2026-71115vulnerabilityvirtualizationoracle
vulnerability Multiples vulnérabilités dans Oracle PeopleSoft (19 août 2026) A French security advisory from CERT-FR details multiple vulnerabilities within Oracle PeopleSoft versions 9.2 and 8.61-8.63. These flaws could lead to data breaches, data integrity issues, denial of service attacks, and… CERT-FR · Aug 19, 2026 High CVE-2026-60742CVE-2026-60821CVE-2026-60831oraclepeoplesoftvulnerability
vulnerability Multiples vulnérabilités dans Oracle Systems (19 août 2026) Multiple vulnerabilities have been discovered within Oracle Systems, potentially allowing attackers to compromise data confidentiality and integrity. These vulnerabilities affect several Oracle products and require immed… CERT-FR · Aug 19, 2026 High CVE-2026-60822CVE-2026-70737CVE-2026-70829oraclevulnerabilitypatch
vulnerability Multiples vulnérabilités dans Joomla! (19 août 2026) Multiple vulnerabilities have been discovered in Joomla!, including those allowing for remote code execution, data integrity compromise, and cross-site scripting (XSS). These vulnerabilities are present in Joomla! versio… CERT-FR · Aug 19, 2026 High CVE-2026-71572CVE-2026-71573CVE-2026-71574joomlavulnerabilitycve
vulnerability Multiples vulnérabilités dans Oracle Database Server (19 août 2026) Multiple vulnerabilities have been discovered in Oracle Database Server, allowing attackers to potentially execute code remotely, cause denial of service, and compromise data confidentiality. These vulnerabilities affect… CERT-FR · Aug 19, 2026 High CVE-2026-59889CVE-2026-71062CVE-2026-71063oracledatabasevulnerability
vulnerability Multiples vulnérabilités dans Oracle Weblogic (19 août 2026) Multiple vulnerabilities have been discovered in Oracle WebLogic Server, allowing attackers to cause denial of service, compromise data confidentiality, and potentially execute arbitrary code remotely. These vulnerabilit… CERT-FR · Aug 19, 2026 High CVE-2023-21839CVE-2024-20931CVE-2026-60415oracleweblogicvulnerability
vulnerability Vulnérabilité dans les produits Moxa (19 août 2026) A vulnerability has been identified in Moxa products, allowing an attacker to trigger a denial-of-service attack remotely. This affects several Moxa devices and requires immediate attention to mitigate the risk. CERT-FR · Aug 19, 2026 Medium CVE-2011-1473moxavulnerabilitydenial-of-service