vulnerability Apple Patches iOS and macOS, (Mon, Aug 17th) Apple released security updates for iOS, iPadOS, and macOS to address 108 vulnerabilities, primarily targeting the WebKit component. This update follows a smaller macOS patch and represents a significant effort to bolste… SANS Internet Storm Center · Aug 17, 2026 Medium CVE-2026-28958CVE-2026-28973CVE-2026-28984webkitsecuritypatch
vulnerability Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection Researchers at Wiz discovered a GitHub Actions workflow injection vulnerability in Snowflake's snowflakedb/snowflake-connector-net repository. An attacker could craft a GitHub issue to inject malicious code into a workfl… The Hacker News · Aug 17, 2026 Medium github actionsworkflow injectionjira
vulnerability Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads A critical security flaw in Forminator Forms (WordPress plugin) and User Profile Builder (WordPress plugin) allows unauthenticated attackers to execute arbitrary code on vulnerable sites. The Forminator vulnerability (CV… The Hacker News · Aug 17, 2026 Critical CVE-2026-15748CVE-2026-15826wordpressvulnerabilityremote code execution
vulnerability Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access Security researchers at SSD Secure Disclosure have discovered a two-stage exploit chain that allows attackers to gain full Android kernel access on devices using Unisoc modem firmware. The vulnerability stems from a shar… The Hacker News · Aug 17, 2026 High CVE-2025-31718CVE-2022-20210CHandroidmodemkernel
vulnerability Recent macOS Screen Sharing Vulnerability Exploited in Attacks A recently patched macOS Screen Sharing vulnerability is being actively exploited in the wild by threat actors to gain root access and deploy cryptominers. The flaw allows attackers to authenticate without credentials si… SecurityWeek · Aug 17, 2026 High CVE-2026-65400macosscreen sharingroot access
vulnerability Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure A critical vulnerability in SAP Commerce Cloud was rapidly exploited by hackers just days after its public announcement. The flaw, tracked as CVE-2026-58231, allows for arbitrary code execution and poses a significant ri… SecurityWeek · Aug 17, 2026 Critical CVE-2026-58231CVE-2019-0344sapcommercevulnerability
vulnerability ISC Stormcast For Monday, August 17th, 2026 https://isc.sans.edu/podcastdetail/10054, (Mon, Aug 17th) The ISC Stormcast highlighted a significant vulnerability in the latest version of Apache Struts, potentially allowing for remote code execution via a deserialization attack. This vulnerability is actively being exploite… SANS Internet Storm Center · Aug 17, 2026 Critical strutsvulnerabilitydeserialization
vulnerability Multiples vulnérabilités dans Microsoft Edge (17 août 2026) Multiple vulnerabilities have been discovered in Microsoft Edge, allowing for remote code execution and a security issue not specified by the vendor. Users of Edge versions prior to 151.0.4129.86 are at risk. CERT-FR · Aug 17, 2026 High CVE-2026-19556CVE-2026-19557CVE-2026-19558vulnerabilityremote code executionmicrosoft edge
vulnerability Multiples vulnérabilités dans les produits Microsoft (17 août 2026) Multiple vulnerabilities have been discovered in Microsoft products, allowing attackers to execute arbitrary code remotely and elevate privileges. These issues primarily affect PowerShell versions, requiring immediate pa… CERT-FR · Aug 17, 2026 High CVE-2026-50523CVE-2026-69414microsoftpowershellvulnerability
vulnerability Vulnérabilité dans SPIP (17 août 2026) A critical vulnerability has been identified in SPIP, allowing attackers to execute arbitrary code remotely. This affects older versions of the content management system, requiring immediate patching to prevent exploitat… CERT-FR · Aug 17, 2026 High spipremotecode
vulnerability Wireshark 4.6.8 Released, (Sun, Aug 16th) Wireshark, a widely used network protocol analyzer, released version 4.6.8, addressing 28 vulnerabilities and 25 bugs. This update significantly improves the security posture of the tool, mitigating potential risks assoc… SANS Internet Storm Center · Aug 16, 2026 Medium wiresharkvulnerabilitynetwork analysis
vulnerability SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch A critical security vulnerability (CVE-2026-58231) in SAP Commerce Cloud is being actively exploited, despite a patch being available for days. The flaw stems from inadequate input validation, potentially leading to code… The Hacker News · Aug 15, 2026 Critical CVE-2026-58231CVE-2025-31324USsapvulnerabilitypatch
vulnerability Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner A critical vulnerability in Apple's macOS Screen Sharing component has been actively exploited in the wild to install a cryptocurrency miner. Researchers have discovered a pre-authentication vulnerability (CVE-2026-65400… The Hacker News · Aug 15, 2026 Critical CVE-2026-65400CVE-2026-43779CVE-2026-43777USmacosscreen sharingvulnerability
vulnerability Hackers Exploiting Unpatched GeoServer Zero-Day A zero-day vulnerability in GeoServer is being actively exploited by threat actors shortly after its public disclosure. The flaw, a SQL injection, allows remote code execution and has prompted immediate action from secur… SecurityWeek · Aug 14, 2026 High sql injectionzero-dayremote code execution
vulnerability Multiples vulnérabilités dans Stormshield Network Security (14 août 2026) Multiple vulnerabilities have been discovered in Stormshield Network Security, potentially allowing for remote code execution, denial of service, and data compromise. These vulnerabilities affect various versions of the… CERT-FR · Aug 14, 2026 Medium CVE-2026-25075CVE-2026-34180CVE-2026-35058vulnerabilityremote code executiondenial of service
vulnerability Multiples vulnérabilités dans le noyau Linux de Red Hat (14 août 2026) Multiple vulnerabilities have been discovered in Red Hat's Linux kernel. These vulnerabilities allow for data integrity compromise, data confidentiality breaches, and bypassing security policies, potentially leading to c… CERT-FR · Aug 14, 2026 High CVE-2024-53143CVE-2025-10263CVE-2025-54518linuxkernelvulnerability
vulnerability Multiples vulnérabilités dans le noyau Linux de Debian (14 août 2026) Multiple vulnerabilities have been discovered in the Linux kernel of Debian. These vulnerabilities allow for privilege escalation, data compromise, and denial of service. Affected Debian versions are those prior to 6.12.… CERT-FR · Aug 14, 2026 High CVE-2025-40098CVE-2026-45897CVE-2026-45901linuxkerneldebian
vulnerability Multiples vulnérabilités dans Elastic Kibana (14 août 2026) Multiple vulnerabilities have been discovered in Elastic Kibana. Some of these vulnerabilities allow for privilege escalation, remote denial-of-service, and data confidentiality compromise. Elastic has released several s… CERT-FR · Aug 14, 2026 High CVE-2015-8131CVE-2026-49089CVE-2026-72629kibanaelasticvulnerability
vulnerability Multiples vulnérabilités dans les produits Netgate (14 août 2026) Multiple vulnerabilities have been discovered in Netgate products, including pfSense. These vulnerabilities allow for data integrity compromise, data confidentiality breaches, and remote code execution. Several CVEs have… CERT-FR · Aug 14, 2026 High CVE-2026-56126CVE-2026-56127CVE-2026-56128vulnerabilitypfsenseremote code execution
vulnerability Multiples vulnérabilités dans les produits Mattermost (14 août 2026) Multiple vulnerabilities have been discovered in Mattermost Server versions 10.11.x through 11.9.x. The CERT-FR bulletin details several security updates addressing these issues, urging users to apply the provided patche… CERT-FR · Aug 14, 2026 Medium mattermostvulnerabilitysecurity update