vulnerability Attackers Exploit N-able Patch Bypass Flaw on RMM Servers N-able disclosed a patch bypass vulnerability (CVE-2026-18577) that allowed attackers to gain administrative access to N-central servers, its remote monitoring and management (RMM) platform. Threat actors exploited this… Dark Reading · Aug 3, 2026 High CVE-2026-18577CVE-2026-18556patch-bypassremote-managementrmm
threat-intel N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete N-able has revealed that attackers exploited a vulnerability in its N-central remote monitoring and management platform to gain remote administrative access to customer systems. Despite a patch release, attackers continu… The Hacker News · Aug 3, 2026 High CVE-2026-18577CVE-2026-18556FIauthenticationremote accessvulnerability
vulnerability Multiples vulnérabilités dans Papercut (03 août 2026) A series of vulnerabilities have been discovered in PaperCut NG/MF, allowing attackers to compromise data confidentiality and bypass security policies. The vulnerabilities are centered around versions prior to 26.0.3 and… CERT-FR · Aug 3, 2026 Medium CVE-2026-8793CVE-2026-8794vulnerabilitypatchsecurity
vulnerability Multiples vulnérabilités dans le noyau Linux de SUSE (31 juillet 2026) Multiple vulnerabilities have been discovered in the SUSE Linux kernel. Several of these vulnerabilities can lead to data confidentiality and integrity breaches, as well as the circumvention of security policies and deni… CERT-FR · Jul 31, 2026 High CVE-2023-20585CVE-2025-10263CVE-2025-39894kernelpatchsecurity
threat-intel DataBahn Raises $40 Million for Agentic Data Pipeline Management DataBahn, a Texas-based company specializing in data pipeline management, has secured $40 million in Series B funding to bolster its agentic data control plane and expand its capabilities. This investment will allow them… SecurityWeek · Jul 30, 2026 Info data-managementdata-governanceai
threat-intel North Korea’s Lazarus Group sharing tools with ransomware hackers, South Korean agencies warn North Korea's Lazarus Group is sharing its cyber tools and infrastructure with ransomware hackers, specifically the Gunra group, targeting South Korean organizations. The agencies warn that even visiting compromised legi… The Record · Jul 30, 2026 High SONOnorth korearansomwarelazarus group
vulnerability Critical VM Escape Vulnerability Patched in VMware ESXi VMware has released patches to address several critical vulnerabilities in its ESXi, vCenter, Workstation, and Fusion products. These flaws could allow attackers to execute code on the host, bypass authentication, or cau… SecurityWeek · Jul 29, 2026 Critical CVE-2026-47876CVE-2026-59309CVE-2026-59310vulnerabilitypatchsecurity
vulnerability Multiples vulnérabilités dans le noyau Linux de Red Hat (24 juillet 2026) Multiple vulnerabilities have been discovered in the Red Hat Linux kernel. Some of these vulnerabilities allow an attacker to cause remote code execution, privilege escalation, and a denial-of-service attack. These vulne… CERT-FR · Jul 24, 2026 High CVE-2024-46738CVE-2024-50076CVE-2025-39982linuxkernelvulnerability
vulnerability Multiples vulnérabilités dans les produits Mitel (23 juillet 2026) Multiple vulnerabilities have been discovered in Mitel products, allowing attackers to execute arbitrary code remotely and inject malicious code via XSS. These vulnerabilities affect various versions of MiCollab and Open… CERT-FR · Jul 23, 2026 High vulnerabilityremote code executionxss
vulnerability Multiples vulnérabilités dans Oracle Systems (23 juillet 2026) Multiple vulnerabilities have been discovered within Oracle Systems, potentially allowing attackers to compromise data confidentiality, integrity, and cause denial of service. These vulnerabilities affect various Oracle… CERT-FR · Jul 23, 2026 High CVE-2026-60659CVE-2026-60661CVE-2026-60833oraclevulnerabilitypatch
threat-intel Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Oracle released a massive quarterly security update addressing over 1,400 vulnerabilities, primarily identified through the use of AI. The update includes fixes for a wide range of products and services, highlighting the… SecurityWeek · Jul 22, 2026 High patchvulnerabilityai
vulnerability Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities Zimbra has released patches to address nine security vulnerabilities, including a critical SNMP command injection flaw and several XSS vulnerabilities. These fixes are vital to mitigate potential code execution and email… The Hacker News · Jul 21, 2026 Medium CVE-2026-50055snmpxsscommand-injection
vulnerability Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution A critical security vulnerability in ServiceNow's AI Platform is being actively exploited, allowing unauthenticated code execution and potentially a complete compromise of ServiceNow instances. ServiceNow has released p… The Hacker News · Jul 21, 2026 Critical CVE-2026-6875vulnerabilitycode executionsandbox
vulnerability SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data SAP has released security updates to address a critical vulnerability (CVSS 9.9) in its NetWeaver ABAP system, allowing attackers to potentially access or modify data. Two other critical vulnerabilities related to Appro… The Hacker News · Jul 14, 2026 Critical CVE-2026-44747CVE-2026-27690CVE-2026-44761sapabapoauth
vulnerability 7 Severe Vulnerabilities Patched in VMware Avi Load Balancer Broadcom has released updates to patch seven critical and high-severity vulnerabilities in VMware Avi Load Balancer. These flaws could allow attackers to bypass authentication, execute code, and escalate privileges, posi… SecurityWeek · Jul 14, 2026 High CVE-2026-47865CVE-2026-47866CVE-2026-47867vulnerabilityload balancingauthentication
threat-intel 11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot Researchers have discovered 11 outdated, Microsoft-signed UEFI shim bootloaders that could be exploited to bypass Secure Boot on systems relying on these shims. These bootloaders, primarily from versions 0.7 and earlier,… The Hacker News · Jul 14, 2026 High CVE-2026-8863CVE-2026-10797FIuefisecure bootvulnerability
vulnerability New CitrixBleed Vulnerability Exploited Immediately After Public Disclosure A newly discovered CitrixBleed-like vulnerability (CVE-2026-8451) in NetScaler ADC and Gateways was exploited within 24 hours of its public disclosure. The flaw, stemming from an out-of-bounds read issue in the XML parse… SecurityWeek · Jul 2, 2026 Critical CVE-2026-8451DEHKcitrixbleedsamlmemory disclosure
vulnerability Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation Attempts A critical remote code execution (RCE) vulnerability, CVE-2026-8037, in Progress Kemp LoadMaster is currently being actively exploited. The flaw allows unauthenticated attackers to execute arbitrary commands on vulnerabl… The Hacker News · Jul 1, 2026 Critical CVE-2026-8037CVE-2024-1212rcecommand injectionload balancer
vulnerability Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-Service This article details six newly discovered vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway software, potentially allowing for denial-of-service attacks and arbitrary file reads. The vulnerabilities, ranging… The Hacker News · Jul 1, 2026 High CVE-2026-8451CVE-2026-8452CVE-2026-8655samlhttp2memory
vulnerability Critical SimpleHelp Vulnerability Exploited for Malware Delivery A critical vulnerability (CVE-2026-48558) in SimpleHelp RMM software allowed unauthorized access and subsequent malware deployment. The flaw, related to OpenID Connect authentication, enabled attackers to gain full techn… SecurityWeek · Jun 30, 2026 Critical CVE-2026-48558USoidcauthenticationmalware