threat-intel SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits SonicWall has issued an urgent patch warning due to two newly exploited zero-day vulnerabilities in its SMA1000 secure remote access appliances. Threat actors are actively leveraging these flaws, and CISA has added them… SecurityWeek · Jul 15, 2026 Critical CVE-2026-15409CVE-2026-15410zero-dayssrfcode_injection
vulnerability Multiples vulnérabilités dans Mozilla Firefox (15 juillet 2026) Mozilla has announced multiple security vulnerabilities in Firefox, allowing attackers to bypass security policies and potentially cause unspecified security problems. These vulnerabilities require immediate patching to… CERT-FR · Jul 15, 2026 Medium CVE-2026-14906CVE-2026-15718CVE-2026-15719firefoxvulnerabilitysecurity
vulnerability Vulnérabilité dans Xen XAPI (15 juillet 2026) A security vulnerability has been identified in Xen XAPI, allowing attackers to bypass security policies. This could lead to unauthorized access and potential system compromise. The vulnerability is being addressed throu… CERT-FR · Jul 15, 2026 Medium CVE-2026-42491xenxapivulnerability
vulnerability Vulnérabilité dans Tenable Nessus Agent (15 juillet 2026) A critical vulnerability has been identified in Tenable Nessus Agent, allowing attackers to execute arbitrary code remotely and bypass security policies. This flaw, CVE-2026-15265, affects older versions of the agent and… CERT-FR · Jul 15, 2026 Critical CVE-2026-15265vulnerabilityremote code executionsecurity policy
vulnerability Adobe Patches Critical ColdFusion Vulnerabilities Adobe released a substantial security update addressing 88 vulnerabilities across its Creative Cloud suite, including several critical flaws in ColdFusion, Commerce, Experience Manager, and Illustrator. The update focuse… SecurityWeek · Jul 14, 2026 High CVE-2026-48318CVE-2026-48322CVE-2026-48284securitypatchvulnerability
vulnerability 7 Severe Vulnerabilities Patched in VMware Avi Load Balancer Broadcom has released updates to patch seven critical and high-severity vulnerabilities in VMware Avi Load Balancer. These flaws could allow attackers to bypass authentication, execute code, and escalate privileges, posi… SecurityWeek · Jul 14, 2026 High CVE-2026-47865CVE-2026-47866CVE-2026-47867vulnerabilityload balancingauthentication
vulnerability SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud SAP released 19 security patches on July 26th, 2026, addressing critical vulnerabilities across several of its flagship products, including NetWeaver, Approuter, and Commerce Cloud. The most severe vulnerability, CVE-202… SecurityWeek · Jul 14, 2026 Critical CVE-2026-44747CVE-2026-27690CVE-2026-44761sapvulnerabilitypatch
vulnerability Zimbra Patches Critical Code Execution Vulnerability A critical cross-site scripting (XSS) vulnerability in Zimbra’s Classic Web Client could allow attackers to execute code on a victim’s system simply by opening a specially crafted email. Zimbra has released version 10.1.… SecurityWeek · Jul 13, 2026 Critical xssvulnerabilityzimbra
vulnerability Organizations Warned of Exploited Joomla Extension Vulnerabilities Two critical vulnerabilities in Joomla extensions – Balbooa Forms and iCagenda – have been actively exploited by threat actors, allowing for remote code execution without authentication. Both vulnerabilities have been ad… SecurityWeek · Jul 13, 2026 Critical CVE-2026-56291CVE-2026-48939joomlavulnerabilityremote code execution
vulnerability Microsoft Reins in RoguePlanet Zero-Day Threat A disgruntled security researcher, known as "Nightmare-Eclipse," published a proof-of-concept exploit (RoguePlanet) for a Windows Defender vulnerability, leading Microsoft to issue an out-of-band patch. The vulnerability… Dark Reading · Jul 9, 2026 High CVE-2026-50656CVE-2026-33825zero-dayprivilege-escalationmicrosoft
vulnerability WolfSSL, GeoVision, VTK vulnerabilities Cisco Talos has disclosed a significant number of vulnerabilities across WolfSSL, GeoVision, and VTK-DICOM. These vulnerabilities range from buffer overflows and command injection to session cookie issues and heap overfl… Cisco Talos · Jul 9, 2026 Medium CVE-2026-28739CVE-2026-25106CVE-2026-33091buffer_overflowcommand_injectioncve
vulnerability Palo Alto Networks Patches 13 Vulnerabilities Palo Alto Networks has released advisories detailing 13 vulnerabilities across its products, including a critical buffer overflow that could lead to arbitrary code execution. While the company reports no active exploitat… SecurityWeek · Jul 9, 2026 High CVE-2026-0288vulnerabilitypatchbuffer overflow
vulnerability Schneider Electric PowerChute Serial Shutdown Schneider Electric PowerChute Serial Shutdown versions 1.4 and earlier contain multiple vulnerabilities that could allow attackers to overwrite critical files, inject malicious data, gain unauthorized access, or trigger… CISA Advisories · Jul 9, 2026 High CVE-2026-2399CVE-2026-2404CVE-2026-2405vulnerabilitypatchsecurity advisory
vulnerability Microsoft Patches Defender ‘RoguePlanet’ Vulnerability Microsoft has released a patch to address a Defender vulnerability, dubbed RoguePlanet, which could allow an attacker to escalate privileges. The vulnerability was initially identified by Nightmare Eclipse (Chaotic Eclip… SecurityWeek · Jul 9, 2026 High CVE-2026-50656CVE-2026-41091CVE-2026-45498vulnerabilitypatchdefender
vulnerability Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges Microsoft has patched a critical vulnerability, RoguePlanet, within its Defender antivirus software that could allow attackers to gain SYSTEM-level privileges. This flaw, discovered by Chaotic Eclipse, allows for arbitra… The Hacker News · Jul 9, 2026 Critical CVE-2026-50656CVE-2026-33825CVE-2026-45498vulnerabilityprivilege escalationantivirus
vulnerability Chrome 150 Update Patches 27 Vulnerabilities Google released Chrome 150, addressing 27 security vulnerabilities, including two critical flaws related to use-after-free bugs. The update represents a significant effort to remediate a substantial number of memory safe… SecurityWeek · Jul 9, 2026 Medium memory-safetyvulnerabilitychrome
vulnerability Multiples vulnérabilités dans Traefik (09 juillet 2026) Multiple vulnerabilities have been discovered in Traefik, allowing an attacker to bypass security policies. These vulnerabilities affect older versions of the popular reverse proxy and load balancer, requiring immediate… CERT-FR · Jul 9, 2026 Medium CVE-2026-65601CVE-2026-65602traefikvulnerabilitysecurity
threat-intel CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws The CISA has issued an urgent warning to federal agencies and all organizations regarding several actively exploited vulnerabilities in Adobe ColdFusion, Langflow, Joomla extensions, and CitrixBleed. These flaws, includi… SecurityWeek · Jul 8, 2026 Critical CVE-2026-48282CVE-2026-55255CVE-2026-33017vulnerabilityexploitationpatch
threat-intel BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA BeyondTrust has released patches to address critical security vulnerabilities in its Remote Support and Privileged Remote Access products. These flaws, if exploited, could allow unauthenticated attackers to gain unauthor… The Hacker News · Jul 7, 2026 Critical CVE-2026-40138CVE-2026-40139CVE-2026-40140vulnerabilityauthenticationremote access
vulnerability Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign Classic Adobe has released critical security patches for vulnerabilities in both ColdFusion and Adobe Campaign Classic, addressing flaws with CVSS scores of up to 10.0. These vulnerabilities could allow for remote code execution… The Hacker News · Jul 1, 2026 Critical CVE-2026-48276CVE-2026-48283CVE-2026-48277adobevulnerabilitycode execution