vulnerability Multiples vulnérabilités dans Microsoft Edge (17 août 2026) Multiple vulnerabilities have been discovered in Microsoft Edge, allowing for remote code execution and a security issue not specified by the vendor. Users of Edge versions prior to 151.0.4129.86 are at risk. CERT-FR · Aug 17, 2026 High CVE-2026-19556CVE-2026-19557CVE-2026-19558vulnerabilityremote code executionmicrosoft edge
vulnerability Multiples vulnérabilités dans les produits Netgate (14 août 2026) Multiple vulnerabilities have been discovered in Netgate products, including pfSense. These vulnerabilities allow for data integrity compromise, data confidentiality breaches, and remote code execution. Several CVEs have… CERT-FR · Aug 14, 2026 High CVE-2026-56126CVE-2026-56127CVE-2026-56128vulnerabilitypfsenseremote code execution
vulnerability Multiples vulnérabilités dans Elastic Kibana (14 août 2026) Multiple vulnerabilities have been discovered in Elastic Kibana. Some of these vulnerabilities allow for privilege escalation, remote denial-of-service, and data confidentiality compromise. Elastic has released several s… CERT-FR · Aug 14, 2026 High CVE-2015-8131CVE-2026-49089CVE-2026-72629kibanaelasticvulnerability
vulnerability Hitachi Energy APM Edge Product Hitachi Energy is issuing a security advisory regarding critical vulnerabilities in its APM Edge product, specifically versions 6.10 and earlier. These vulnerabilities, including a write-what-where condition and an out-o… CISA Advisories · Aug 13, 2026 Critical CVE-2026-43284CVE-2026-43500SWvulnerabilitycvelinux
vulnerability Attackers Exploit SharePoint Authentication Bypass After Public PoC Release Threat actors are actively exploiting a critical Microsoft SharePoint vulnerability (CVE-2026-55040) due to a bypass in the authentication feature. Following the release of a proof-of-concept by Rapid7, attackers are lev… The Hacker News · Aug 13, 2026 Critical CVE-2026-55040HOJANEjwtauthenticationsharepoint
vulnerability Multiples vulnérabilités dans les produits Fortinet (13 août 2026) Multiple vulnerabilities have been discovered in Fortinet products, including several that could allow for remote code execution, privilege escalation, and denial-of-service attacks. These vulnerabilities affect various… CERT-FR · Aug 13, 2026 High CVE-2026-26035CVE-2026-49975CVE-2026-70465vulnerabilitypatchremote code execution
vulnerability Multiples vulnérabilités dans Progress MOVEit WAF (13 août 2026) Multiple vulnerabilities have been discovered in Progress MOVEit WAF, allowing attackers to execute arbitrary code remotely, escalate privileges, and bypass security policies. These vulnerabilities affect versions prior… CERT-FR · Aug 13, 2026 Critical CVE-2026-59686CVE-2026-59687CVE-2026-59688vulnerabilityprogressmoveit
vulnerability SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code SAP has released patches to address a critical security flaw in its Commerce Cloud (Data Hub Adapter) that could allow unauthenticated attackers to execute arbitrary code. This vulnerability stems from insufficient autho… The Hacker News · Aug 12, 2026 Critical CVE-2026-58231CVE-2026-44772CVE-2026-34265securitypatcharbitrary code execution
vulnerability Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS A critical vulnerability (CVE-2026-20349, CVSS: 8.6) in Cisco ASA and FTD software has been actively exploited in the wild. This flaw, triggered by a crafted HTTP request, can lead to a denial-of-service condition and is… The Hacker News · Aug 12, 2026 Critical CVE-2026-20349cveasaftd
vulnerability Multiples vulnérabilités dans les produits SonicWall (12 août 2026) SonicWall products are experiencing multiple vulnerabilities, including remote code execution and privilege escalation, allowing attackers to compromise data confidentiality and integrity. These vulnerabilities have been… CERT-FR · Aug 12, 2026 High CVE-2026-18634CVE-2026-66145CVE-2026-66146sonicwallvulnerabilityremote code execution
vulnerability Vulnérabilité dans les produits Cisco (12 août 2026) A vulnerability in Cisco’s Adaptive Security Appliance (ASA) allows attackers to trigger a denial-of-service attack. Cisco has confirmed that this vulnerability is actively being exploited, and users are urged to apply t… CERT-FR · Aug 12, 2026 High CVE-2026-20349ciscoasavulnerability
vulnerability Pulsetto Vagus Nerve Stimulator A critical vulnerability (CVE-2026-18844) exists in Pulsetto Vagus Nerve Stimulator devices, allowing attackers to bypass security measures and manipulate device settings via Bluetooth Low Energy (BLE). The vulnerability… CISA Advisories · Aug 11, 2026 Critical CVE-2026-18844LIbluetoothcvecontrol systems
threat-intel Multiples vulnérabilités dans les produits SAP (11 août 2026) Multiple vulnerabilities have been discovered in SAP products, including remote code execution, privilege escalation, and data confidentiality breaches. These vulnerabilities can be exploited to cause significant damage.… CERT-FR · Aug 11, 2026 High CVE-2025-42947CVE-2025-58057CVE-2026-33871vulnerabilitysapsecurity
vulnerability Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC Cisco has warned of seven high-severity vulnerabilities in its Secure Endpoint Connector software, stemming from flaws within the ClamAV antivirus engine. These vulnerabilities could lead to denial-of-service conditions… SecurityWeek · Aug 10, 2026 High CVE-2026-20337CVE-2026-20339CVE-2026-20345clamavvulnerabilitypatch
vulnerability Multiples vulnérabilités dans VMware Tanzu Greenplum (10 août 2026) Multiple vulnerabilities have been discovered in VMware Tanzu Greenplum. These vulnerabilities allow an attacker to cause a security issue, though the specific nature of the issue is not detailed. Users are advised to co… CERT-FR · Aug 10, 2026 Medium CVE-2018-11798CVE-2019-0205CVE-2020-13949vulnerabilitycvepatch
threat-intel AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day An AI-powered research tool, HTTP Terminator, developed by PortSwigger, autonomously discovered several novel HTTP desynchronization techniques, including a zero-day vulnerability in Apache Traffic Server. The tool, usin… The Hacker News · Aug 7, 2026 High CVE-2026-63078UShttpdesyncrqt
vulnerability Multiples vulnérabilités dans le noyau Linux de SUSE (07 août 2026) Multiple vulnerabilities have been discovered in the Linux kernel of SUSE. These vulnerabilities allow an attacker to bypass security policies and create an unspecified security issue. The affected system is SUSE Linux M… CERT-FR · Aug 7, 2026 High CVE-2026-23240CVE-2026-31738CVE-2026-43038linuxkernelsecurity
vulnerability Multiples vulnérabilités dans Google Chrome (07 août 2026) Multiple vulnerabilities have been discovered in Google Chrome, potentially allowing an attacker to trigger a security issue. These vulnerabilities affect Chrome versions prior to 151.0.7922.108 on Windows and Linux, and… CERT-FR · Aug 7, 2026 High CVE-2026-19137CVE-2026-19138CVE-2026-19139chromevulnerabilitysecurity
vulnerability Vulnérabilité dans Apple macOS (07 août 2026) Apple has disclosed a security vulnerability in macOS that allows attackers to bypass security policies. This vulnerability could lead to unauthorized access and potential compromise of user systems. Users of affected ma… CERT-FR · Aug 7, 2026 Medium CVE-2026-65400macossecurityvulnerability
vulnerability Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugs Cisco has released patches to address multiple critical security vulnerabilities affecting its SD-WAN and IOS XE software. These flaws, including several with a CVSS score of 9.8 and 9.9, cover issues like improper input… The Hacker News · Aug 6, 2026 High CVE-2026-20303CVE-2026-20304CVE-2026-20310sd-wanios xevulnerability