vulnerability Multiples vulnérabilités dans les produits Splunk (16 juillet 2026) Multiple vulnerabilities have been discovered in Splunk products, including Splunk Cloud Platform and Enterprise versions. These vulnerabilities allow for data confidentiality and integrity breaches, as well as the poten… CERT-FR · Jul 16, 2026 High CVE-2025-30204CVE-2025-47913CVE-2025-61726vulnerabilitypatchsecurity
vulnerability Vulnérabilité dans Ruby on Rails (16 juillet 2026) A vulnerability in Ruby on Rails versions prior to 1.7.1 allows for remote code injection via XSS. This means attackers could potentially execute malicious code on vulnerable systems, requiring immediate patching to prev… CERT-FR · Jul 16, 2026 Medium rubyrailsxss
vulnerability Vulnérabilité dans les produits ESET (16 juillet 2026) A denial-of-service vulnerability has been identified in ESET’s endpoint and server security products. Specifically, versions 12.0.x through 12.0.14.0, 12.1.x through 12.1.2.0, 12.2.x through 12.2.9.0, 13.0.x through 13.… CERT-FR · Jul 16, 2026 Medium CVE-2026-6424denial-of-servicevulnerabilityeset
vulnerability Multiples vulnérabilités dans Drupal (16 juillet 2026) Multiple vulnerabilities have been discovered in Drupal, allowing attackers to compromise data confidentiality and inject malicious code remotely. These vulnerabilities affect older versions of the CMS, requiring immedia… CERT-FR · Jul 16, 2026 Medium CVE-2026-15916CVE-2026-15917CVE-2026-55805drupalvulnerabilitycve
vulnerability Multiples vulnérabilités dans les produits F5 (16 juillet 2026) Multiple vulnerabilities have been discovered in F5 products, including BIG-IP, WAF, and NGINX. These vulnerabilities could allow an attacker to achieve remote code execution, denial of service, and data confidentiality… CERT-FR · Jul 16, 2026 High CVE-2026-42533CVE-2026-46333CVE-2026-52865securityvulnerabilitypatch
vulnerability Multiples vulnérabilités dans Cisco RoomOS (16 juillet 2026) Multiple vulnerabilities have been discovered in Cisco RoomOS, potentially allowing attackers to compromise data confidentiality and bypass security policies. These vulnerabilities affect older versions of the operating… CERT-FR · Jul 16, 2026 Medium CVE-2026-20150CVE-2026-20153CVE-2026-20156ciscoroomosvulnerability
threat-intel Forgotten Bootloaders Expose Secure Boot Blind Spot Researchers discovered 11 vulnerable, but still trusted, UEFI shim bootloaders that could have been used to bypass Secure Boot on systems relying on Microsoft's third-party UEFI signing certificate. Despite being outdate… Dark Reading · Jul 15, 2026 High secure bootfirmwareuefi
threat-intel Claude Flaw Automatically Sends Malicious Prompts to AI Agents A vulnerability, dubbed ‘PromptFiction,’ has been discovered in Anthropic’s Claude Desktop application, allowing attackers to automatically submit malicious prompts to the AI assistant with a single click, bypassing the… Dark Reading · Jul 15, 2026 High prompt-injectionai-securityuri-scheme
vulnerability Unpatched Cursor Vulnerability Exposes Users to Code Execution A critical, unpatched vulnerability in Cursor, a popular AI-assisted development environment, allows for code execution simply by opening a project containing a malicious git.exe binary. Despite being reported to Cursor… SecurityWeek · Jul 15, 2026 Critical cursorgitcode execution
vulnerability CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities The CISA is urging immediate patching of Microsoft SharePoint servers due to several recently disclosed zero-day vulnerabilities. These flaws could allow remote code execution and enable attackers to steal sensitive info… SecurityWeek · Jul 15, 2026 High CVE-2026-56164CVE-2026-55040CVE-2026-58644zero-dayremote code executioniis
vulnerability Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws Multiple security flaws have been patched across Firefox, Chrome, Adobe products (including ColdFusion, Commerce, Experience Manager, and Illustrator), and VMware. Mozilla addressed two critical vulnerabilities in Firefo… The Hacker News · Jul 15, 2026 High CVE-2026-15718CVE-2026-15719CVE-2026-15764UNsecurity updatevulnerabilitypatch
vulnerability Microsoft smashes Patch Tuesday record for second successive month Microsoft released a massive Patch Tuesday update, exceeding 600 security vulnerabilities – the largest in the program's history. This surge in vulnerabilities, driven in part by AI-assisted discovery, has led to a signi… The Record · Jul 15, 2026 High CVE-2026-56164CVE-2026-56155CVE-2026-55040UNpatch tuesdayvulnerabilityexploit
threat-intel Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers The CISA, NSA, and international partners have jointly released guidance to help software companies and online services establish effective Coordinated Vulnerability Disclosure (CVD) programs. This program focuses on col… CISA Advisories · Jul 15, 2026 Info vulnerabilitycvdsecurity
vulnerability Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday Security researcher Chaotic Eclipse has released a proof-of-concept (PoC) exploit, LegacyHive, targeting a Windows User Profile Service vulnerability that allows arbitrary hive loading and privilege escalation. This expl… The Hacker News · Jul 15, 2026 High CVE-2026-56164CVE-2026-56155CVE-2026-32201vulnerabilityprivilege escalationsharepoint
vulnerability Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow Fortinet, Ivanti, and ServiceNow have released patches to address 15 vulnerabilities across their products. The most critical issue involves a remote code execution flaw in ServiceNow's AI platform, while Fortinet addres… SecurityWeek · Jul 15, 2026 High CVE-2026-6875CVE-2026-14902CVE-2026-14903vulnerabilitypatchremote code execution
vulnerability Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution A vulnerability in Cursor, a Git repository hosting platform for Windows, allows malicious cloned repositories to execute arbitrary code on the user's system. The flaw stems from Cursor's tendency to run a `git.exe` file… The Hacker News · Jul 15, 2026 High CVE-2026-26268CVE-2026-10591CVE-2020-26233gitwindowscode execution
threat-intel White House Launches AI-Driven ‘Gold Eagle’ Vulnerability Coordination Initiative The White House has launched Gold Eagle, a new initiative designed to streamline vulnerability detection and remediation across government and industry. This program leverages AI, specifically Anthropic's Mythos, to proa… SecurityWeek · Jul 15, 2026 Medium vulnerabilityaicybersecurity
vulnerability Progress Confirms Zero-Day Vulnerability Behind ShareFile Disruption Progress Software has confirmed a zero-day vulnerability in its ShareFile Storage Zones Controller, leading to a service disruption and prompting customers to shut down their servers. While access is now being restored w… SecurityWeek · Jul 15, 2026 High zero-dayvulnerabilitypath traversal
threat-intel ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Rockwell This Patch Tuesday saw significant security updates released by Siemens, Schneider Electric, Rockwell Automation, ABB, and Mitsubishi Electric to address a range of vulnerabilities in their industrial control systems (IC… SecurityWeek · Jul 15, 2026 High GEicspatch tuesdayvulnerability
vulnerability Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates Google and Mozilla have released security updates for Chrome and Firefox, addressing several critical vulnerabilities. These updates include patches for zero-day exploits and prevent potential attacks. While exploit code… SecurityWeek · Jul 15, 2026 High CVE-2026-15718CVE-2026-15719CVE-2026-15764vulnerabilityzero-daypatch