vulnerability Multiples vulnérabilités dans les produits Mattermost (14 août 2026) Multiple vulnerabilities have been discovered in Mattermost Server versions 10.11.x through 11.9.x. The CERT-FR bulletin details several security updates addressing these issues, urging users to apply the provided patche… CERT-FR · Aug 14, 2026 Medium mattermostvulnerabilitysecurity update
vulnerability Vulnérabilité dans les produits Sophos (14 août 2026) A critical vulnerability has been identified in Sophos products, allowing attackers to escalate privileges on macOS systems. This affects older versions of Intercept X Endpoint and Sophos Home, requiring immediate patchi… CERT-FR · Aug 14, 2026 Critical CVE-2026-18367macosvulnerabilityprivilege escalation
vulnerability Multiples vulnérabilités dans PostgreSQL (14 août 2026) Multiple vulnerabilities have been discovered in PostgreSQL, impacting versions 15.x through 18.x and prior to 14.24. These vulnerabilities include potential for data confidentiality breaches, policy bypasses, denial of… CERT-FR · Aug 14, 2026 High CVE-2026-14662CVE-2026-14663CVE-2026-14664postgresqlvulnerabilitysecurity
vulnerability Multiples vulnérabilités dans les produits IBM (14 août 2026) Multiple vulnerabilities have been discovered in IBM products, including remote code execution, privilege escalation, and denial-of-service attacks. These vulnerabilities affect a wide range of IBM products, including Db… CERT-FR · Aug 14, 2026 High CVE-2021-23337CVE-2023-44487CVE-2024-3651vulnerabilitysecuritypatch
vulnerability Multiples vulnérabilités dans Tenable Security Center (14 août 2026) Multiple vulnerabilities have been discovered in Tenable Security Center, including remote code execution, privilege escalation, and SQL injection. These vulnerabilities affect versions of Security Center prior to 6.9.0.… CERT-FR · Aug 14, 2026 High CVE-2026-11564CVE-2026-11586CVE-2026-11856vulnerabilityremote code executionsql injection
vulnerability GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE A newly discovered zero-day SQL injection vulnerability in GeoServer is currently being actively exploited. The vulnerability, which has been assigned a GitHub security advisory identifier (GHSA-mqjf-5f49-2fjh), allows f… The Hacker News · Aug 13, 2026 Critical CVE-2024-36401CVE-2023-25158CVE-2023-25157sql injectionzero-dayremote code execution
vulnerability Magento visé quelques heures après la divulgation d’un correctif A critical vulnerability (CVE-2026-71362) in Adobe Commerce, Commerce B2B, and Magento Open Source has been actively exploited shortly after its patch release. While no confirmed customer breaches have been publicly repo… ZATAZ · Aug 13, 2026 Critical CVE-2026-71362session hijackingpatchecommerce
vulnerability VMware vCenter : des serveurs français compromis A critical vulnerability, CVE-2026-59310, affecting VMware vCenter has been actively exploited since August 3rd, with over 360 compromised IP addresses across 47 countries, including a significant number in France. The v… ZATAZ · Aug 13, 2026 High CVE-2026-59310CVE-2026-47876CVE-2026-59309DEUSTRvulnerabilityexploitreverse shell
vulnerability Adobe Commerce Bug Targeted Immediately After Disclosure A critical vulnerability in Adobe Commerce and Magento allowed unauthenticated attackers to gain access to other customer accounts immediately after its disclosure. Adobe swiftly released a patch, but threat actors were… SecurityWeek · Aug 13, 2026 Critical CVE-2026-71362vulnerabilityecommerceadobe
vulnerability WordPress 7.0.4 Patches Remote Code Execution Vulnerability WordPress has released version 7.0.4 to address a high-severity remote code execution vulnerability. This flaw, tracked as CVE-2026-65640, allows authenticated attackers to execute code by uploading malicious PostScript… SecurityWeek · Aug 13, 2026 High CVE-2026-65640wordpressvulnerabilityremote code execution
vulnerability Siemens Siveillance Video Siemens has released security advisories addressing a Remote Code Execution (RCE) vulnerability in its Siveillance Video Management Servers. Versions V2023 R3 through V2025 are affected, allowing users with edit permissi… CISA Advisories · Aug 13, 2026 High CVE-2026-3014rcecve-2026-3014industrial control systems
vulnerability Siemens Parasolid Siemens Parasolid versions V38.0 and V38.1 are vulnerable to an out-of-bounds read vulnerability when parsing X_T files, potentially allowing an attacker to execute arbitrary code. Siemens has released updates to address… CISA Advisories · Aug 13, 2026 High CVE-2026-64629vulnerabilitysupply-chainindustrial-control-systems
vulnerability Siemens LOGO! Soft Comfort Siemens LOGO! Soft Comfort contains multiple vulnerabilities in its project-file encryption and password handling, allowing a local attacker to extract the master key and decrypt project data or remove passwords. These v… CISA Advisories · Aug 13, 2026 High CVE-2026-57262CVE-2026-57263GEencryptionpasswordhardcoded
vulnerability AVEVA Enterprise SCADA A critical vulnerability (CVE-2025-7639) has been identified in AVEVA Enterprise SCADA, allowing an authenticated attacker with specific privileges to tamper with serialized data and potentially execute code. This vulner… CISA Advisories · Aug 13, 2026 High CVE-2025-7639cve-2025-7639deserializationcode execution
vulnerability Hitachi Energy APM Edge Product Hitachi Energy is issuing a security advisory regarding critical vulnerabilities in its APM Edge product, specifically versions 6.10 and earlier. These vulnerabilities, including a write-what-where condition and an out-o… CISA Advisories · Aug 13, 2026 Critical CVE-2026-43284CVE-2026-43500SWvulnerabilitycvelinux
vulnerability Flow Neuroscience FL-100 A critical vulnerability has been identified in Flow Neuroscience devices (FL-100 and Halo Neuroscience FL-100) due to a hard-coded credential that allows an attacker within Bluetooth range to manipulate brain stimulatio… CISA Advisories · Aug 13, 2026 Critical CVE-2026-18164bluetoothvulnerabilityhardcoded
vulnerability Johnson Controls Inc. Airwall Johnson Controls Inc.'s Airwall software versions 4.0.4 and earlier contain critical vulnerabilities. A hardcoded cryptographic key allows attackers to decrypt sensitive data, bypass authentication, and access arbitrary… CISA Advisories · Aug 13, 2026 High CVE-2026-64887CVE-2026-34492vulnerabilityhardcoded keypath traversal
vulnerability ANDRITZ HIPASE-250 and 250 SCALA ANDRITZ HIPASE-250 and 250 SCALA devices, versions <=7.20, are vulnerable to several security flaws that could allow an attacker to read stored passwords, access configuration endpoints without authentication, and gain V… CISA Advisories · Aug 13, 2026 High CVE-2026-65309CVE-2026-65310CVE-2026-65311vulnerabilitypasswordauthentication
vulnerability Siemens License Server (SLS) Siemens License Server (SLS) versions prior to 5.3 are vulnerable to two separate attacks: a local privilege escalation due to an insecure sudoers policy, allowing an attacker to execute arbitrary commands and plant mali… CISA Advisories · Aug 13, 2026 Critical CVE-2026-69108CVE-2026-69109vulnerabilitysudopath traversal
vulnerability Siemens Solid Edge Siemens Solid Edge versions 2025 and 2026 are vulnerable to multiple file parsing vulnerabilities, including out-of-bounds reads and writes, and use-after-free errors, when processing PAR, PSM, and DFT files. These vulne… CISA Advisories · Aug 13, 2026 High CVE-2026-50058CVE-2026-50059CVE-2026-50060vulnerabilityfile-parsingcad