vulnerability Siemens Desigo DXR and PXC Controllers A denial-of-service vulnerability exists in Siemens Desigo DXR and PXC controllers, exploitable by sending malformed BACnet packets. This can cause the devices to stop responding to queries, requiring a device reset or r… CISA Advisories · Aug 13, 2026 High CVE-2026-59693industrial control systemsbacnetdenial of service
vulnerability Haiwell IoT Cloud HMI Gateway A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway, version 3.40.1.12. Exploitation could allow an attacker to execute arbitrary OS commands with root privileges, posin… CISA Advisories · Aug 13, 2026 Critical CVE-2026-19188cwe-78iotcommand injection
vulnerability Siemens Simcenter Femap Siemens Simcenter Femap contains two file parsing vulnerabilities that could be triggered when the application reads BMP files. An attacker could exploit these flaws to execute code within the current process, potentiall… CISA Advisories · Aug 13, 2026 High CVE-2026-59700CVE-2026-59701vulnerabilitycontrol-systemfile-parsing
vulnerability Johnson Controls Metasys A vulnerability in Johnson Controls Metasys allows a low-privilege user to inject malicious code via a crafted URL, potentially leading to session hijacking and unauthorized access across multiple versions. The vulnerabi… CISA Advisories · Aug 13, 2026 Critical CVE-2026-34491cve-2026-34491xsscisa
vulnerability AWS key exposed in JavaScript may have lit way to Beacon's charity data A vulnerability in Joomla extensions, specifically iCagenda and Balbooa Forms, has been exploited by attackers to gain unauthorized access to vulnerable websites. This allows attackers to inject malicious code and potent… The Register · Aug 13, 2026 Medium joomlavulnerabilityextension
vulnerability Fortinet Patches Authentication Flaws in FortiWeb and FortiManager Fortinet has released patches for eight security vulnerabilities across its products, including critical authentication flaws in FortiWeb and FortiManager. These vulnerabilities could allow attackers to gain unauthorized… SecurityWeek · Aug 13, 2026 Critical CVE-2026-26035CVE-2026-70468CVE-2026-70465vulnerabilityauthenticationpatch
vulnerability Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’ A disgruntled security researcher, Nightmare Eclipse, released a new zero-day exploit called ShieldBreak targeting Microsoft Defender, allowing users to escalate privileges on Windows 11 and Server 2025. This exploit lev… SecurityWeek · Aug 13, 2026 High CVE-2026-50656zero-daydefenderprivilege escalation
vulnerability Belgium's eID Authentication Opens Citizen Accounts to RCE A critical vulnerability was discovered in Belgium's eID authentication system due to a severely flawed browser extension, "Connective." This vulnerability allowed attackers to steal Belgian citizens' identities, payment… Dark Reading · Aug 13, 2026 Critical BEbrowser extensionsrceidentity theft
vulnerability Attackers Exploit SharePoint Authentication Bypass After Public PoC Release Threat actors are actively exploiting a critical Microsoft SharePoint vulnerability (CVE-2026-55040) due to a bypass in the authentication feature. Following the release of a proof-of-concept by Rapid7, attackers are lev… The Hacker News · Aug 13, 2026 Critical CVE-2026-55040HOJANEjwtauthenticationsharepoint
vulnerability Multiples vulnérabilités dans GitLab (13 août 2026) Multiple vulnerabilities have been discovered in GitLab, including remote code injection, denial of service, and privilege escalation. These issues affect versions 19.1.x through 19.1.4, 19.2.x through 19.2.2, and all ve… CERT-FR · Aug 13, 2026 High CVE-2025-9486CVE-2026-15216CVE-2026-15217gitlabvulnerabilityremote code injection
vulnerability Vulnérabilité dans WordPress (13 août 2026) A remote code execution vulnerability has been identified in older versions of WordPress, allowing attackers to execute arbitrary code. This affects WordPress versions prior to 7.0.4, and requires immediate patching to p… CERT-FR · Aug 13, 2026 Critical CVE-2026-65640wordpressrcevulnerability
vulnerability Multiples vulnérabilités dans les produits Fortinet (13 août 2026) Multiple vulnerabilities have been discovered in Fortinet products, including several that could allow for remote code execution, privilege escalation, and denial-of-service attacks. These vulnerabilities affect various… CERT-FR · Aug 13, 2026 High CVE-2026-26035CVE-2026-49975CVE-2026-70465vulnerabilitypatchremote code execution
vulnerability Multiples vulnérabilités dans Wireshark (13 août 2026) Multiple vulnerabilities have been discovered in Wireshark, allowing an attacker to cause a denial-of-service. These vulnerabilities affect Wireshark versions 4.4.x prior to 4.4.18 and 4.6.x prior to 4.6.8. Users are adv… CERT-FR · Aug 13, 2026 Medium vulnerabilitydenial-of-servicenetwork analysis
vulnerability Multiples vulnérabilités dans Progress MOVEit WAF (13 août 2026) Multiple vulnerabilities have been discovered in Progress MOVEit WAF, allowing attackers to execute arbitrary code remotely, escalate privileges, and bypass security policies. These vulnerabilities affect versions prior… CERT-FR · Aug 13, 2026 Critical CVE-2026-59686CVE-2026-59687CVE-2026-59688vulnerabilityprogressmoveit
vulnerability Vulnérabilité dans les produits Foxit (13 août 2026) A vulnerability has been identified in Foxit PDF Editor and Reader software, allowing an attacker to compromise data integrity. Users of older versions of these products are at risk of exploitation. The vendor has releas… CERT-FR · Aug 13, 2026 Medium CVE-2026-18622pdfvulnerabilitydata integrity
vulnerability Multiples vulnérabilités dans les produits Adobe (13 août 2026) Multiple vulnerabilities have been discovered in Adobe products, including Adobe Commerce and ColdFusion. These vulnerabilities allow for remote code execution, privilege escalation, denial of service, and circumvention… CERT-FR · Aug 13, 2026 High CVE-2026-21273CVE-2026-21279CVE-2026-25652vulnerabilitypatchadobe
vulnerability Spectre rears its ugly head again as researchers show some RISC-V chips are susceptible Researchers have discovered that some RISC-V chips are vulnerable to Spectre, a hardware-level security flaw that can be exploited to steal sensitive data. This represents a resurgence of Spectre concerns, highlighting t… The Register · Aug 12, 2026 Medium spectrerisc-vhardware
vulnerability Microsoft-vendetta hacker has a new zero day that gives system privileges on fully patched Windows A Microsoft-based hacker has developed a new zero-day vulnerability in on-prem SharePoint, allowing them to gain system privileges on fully patched Windows systems. This represents a significant security risk, as it bypa… The Register · Aug 12, 2026 High CVE-2026-50656CVE-2026-33825CVE-2026-41091zero-daysharepointvulnerability
vulnerability SharePoint Vulnerability Exploited Shortly After PoC Release A SharePoint vulnerability, patched last month, is now being actively exploited in the wild, with attackers leveraging a publicly released proof-of-concept. This follows a series of similar vulnerabilities discovered thi… SecurityWeek · Aug 12, 2026 High CVE-2026-55040CVE-2026-63520CVE-2026-50522sharepointvulnerabilityexploitation
vulnerability Exposed: Woeful security at UK criminal records office that led to sensitive data leak A security vulnerability in Joomla extensions has been exploited to compromise numerous websites, highlighting a broader issue of security weaknesses within open-source CMS platforms. This incident underscores the ongoin… The Register · Aug 12, 2026 Medium joomlavulnerabilityopen-source