threat-intel China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access A Chinese-made router manufacturer, Zhibotong Electronics (ZBT) through its brand Zbtlink, ships routers with two factory-installed implants – SPEAKINGSTONE and DARKLANTERN – that provide unauthenticated remote access to the devices. These implants allow an attacker to execute commands as root, exfiltrate data, and est… The Hacker News · 2d ago High CVE-2026-74232CVE-2026-74233CVE-2026-66747CHc2routerfirmware
vulnerability Rockwell Automation OTTO Fleet Manager Rockwell Automation’s OTTO Fleet Manager is vulnerable to a brute-force attack due to a weak password hashing implementation. This allows attackers to potentially compromise stored password hashes, especially if they gai… CISA Advisories · 3d ago High CVE-2026-75112passwordbrute-forcecve
vulnerability Multiples vulnérabilités dans OpenSSL (26 août 2026) Multiple vulnerabilities have been discovered in OpenSSL, allowing for denial of service attacks and policy bypasses. These vulnerabilities affect various OpenSSL versions and could be exploited by attackers. Users are a… CERT-FR · 4d ago Medium CVE-2026-14457CVE-2026-18798CVE-2026-54874vulnerabilityopensslsecurity
vulnerability CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning to federal agencies regarding two critical vulnerabilities in TrueConf, a secure video conferencing platform. Threat actors, spe… SecurityWeek · Aug 21, 2026 High CVE-2026-72529CVE-2026-72530RUBYvulnerabilitypatchtrueconf
vulnerability Vulnérabilité dans SPIP (21 août 2026) A remote code execution vulnerability has been discovered in SPIP, allowing attackers to execute arbitrary code from a remote location. The vulnerability is currently being actively exploited, and users of SPIP versions… CERT-FR · Aug 21, 2026 High CVE-2026-77806remote-code-executionvulnerabilitysecurity
vulnerability Vulnérabilité dans Microsoft Entra ID (21 août 2026) A critical vulnerability (CVE-2026-69836) has been identified in Microsoft Entra ID, allowing for remote code execution. While initially reported as actively exploited, Microsoft has clarified that it is currently not be… CERT-FR · Aug 21, 2026 Critical CVE-2026-69836entria idremote code executioncve
vulnerability Multiples vulnérabilités dans Joomla! (19 août 2026) Multiple vulnerabilities have been discovered in Joomla!, including those allowing for remote code execution, data integrity compromise, and cross-site scripting (XSS). These vulnerabilities are present in Joomla! versio… CERT-FR · Aug 19, 2026 High CVE-2026-71572CVE-2026-71573CVE-2026-71574joomlavulnerabilitycve
vulnerability Multiples vulnérabilités dans Oracle Systems (19 août 2026) Multiple vulnerabilities have been discovered within Oracle Systems, potentially allowing attackers to compromise data confidentiality and integrity. These vulnerabilities affect several Oracle products and require immed… CERT-FR · Aug 19, 2026 High CVE-2026-60822CVE-2026-70737CVE-2026-70829oraclevulnerabilitypatch
threat-intel Multiples vulnérabilités dans les produits Mozilla (19 août 2026) Mozilla has disclosed multiple vulnerabilities across its Firefox and Thunderbird products. These vulnerabilities include potential for remote code execution, denial of service, and information disclosure. Affected versi… CERT-FR · Aug 19, 2026 High CVE-2026-74934CVE-2026-74935CVE-2026-74936vulnerabilityfirefoxthunderbird
vulnerability Multiples vulnérabilités dans Oracle Database Server (19 août 2026) Multiple vulnerabilities have been discovered in Oracle Database Server, allowing attackers to potentially execute code remotely, cause denial of service, and compromise data confidentiality. These vulnerabilities affect… CERT-FR · Aug 19, 2026 High CVE-2026-59889CVE-2026-71062CVE-2026-71063oracledatabasevulnerability
vulnerability Multiples vulnérabilités dans Oracle Weblogic (19 août 2026) Multiple vulnerabilities have been discovered in Oracle WebLogic Server, allowing attackers to cause denial of service, compromise data confidentiality, and potentially execute arbitrary code remotely. These vulnerabilit… CERT-FR · Aug 19, 2026 High CVE-2023-21839CVE-2024-20931CVE-2026-60415oracleweblogicvulnerability
vulnerability Multiples vulnérabilités dans Oracle Java SE (19 août 2026) Multiple vulnerabilities have been discovered in Oracle Java SE, including those allowing for remote code execution, denial of service, and data confidentiality breaches. These vulnerabilities affect various Java SE vers… CERT-FR · Aug 19, 2026 High CVE-2026-60589CVE-2026-61308CVE-2026-62574javavulnerabilityoracle
vulnerability Multiples vulnérabilités dans Python (19 août 2026) Multiple vulnerabilities have been discovered in Python, potentially allowing attackers to compromise data confidentiality and bypass security policies. These vulnerabilities are linked to specific CVEs and require updat… CERT-FR · Aug 19, 2026 Medium CVE-2026-15806CVE-2026-17084pythonvulnerabilitysecurity
vulnerability Multiples vulnérabilités dans Google Chrome (19 août 2026) Multiple vulnerabilities have been discovered in Google Chrome, impacting older versions. The exact nature of the vulnerabilities is not specified, but users are advised to consult the Chrome security bulletin for availa… CERT-FR · Aug 19, 2026 Medium CVE-2026-76033CVE-2026-76034CVE-2026-76035chromevulnerabilitysecurity
vulnerability Critical GitLab Zero-Click Flaw Poses Mitigation Challenges GitLab has released an out-of-band security update addressing two critical vulnerabilities, CVE-2026-19478 and CVE-2062-19650, that could allow unauthenticated attackers to manipulate or delete data. The vulnerabilities… Dark Reading · Aug 18, 2026 Critical CVE-2026-19478CVE-2026-19650graphqlcvezero-click
vulnerability GitLab Patches Critical Code Injection Vulnerability GitLab has released patches to address two critical vulnerabilities, including a code injection flaw that could allow unauthorized data modification and deletion. These vulnerabilities affected multiple versions of GitLa… SecurityWeek · Aug 18, 2026 Critical CVE-2026-19478CVE-2026-19650vulnerabilitygraphqlcve
vulnerability Multiples vulnérabilités dans Typo3 (18 août 2026) Multiple vulnerabilities have been discovered in Typo3, allowing attackers to bypass security policies. These flaws require immediate patching to prevent exploitation and potential security breaches. The French CERT has… CERT-FR · Aug 18, 2026 Medium CVE-2026-15305CVE-2026-19418typo3vulnerabilitysecurity
vulnerability Multiples vulnérabilités dans Zabbix (18 août 2026) Multiple vulnerabilities have been discovered in Zabbix, potentially allowing attackers to cause a denial of service, compromise data confidentiality, and damage data integrity. These vulnerabilities affect various Zabbi… CERT-FR · Aug 18, 2026 High CVE-2026-1199CVE-2026-23922CVE-2026-23929zabbixvulnerabilitypatch
vulnerability Multiples vulnérabilités dans GitLab (18 août 2026) Multiple vulnerabilities have been discovered in GitLab, including one that could allow attackers to compromise data integrity and another through Cross-Site Request Forgery (CSRF). GitLab versions 19.0.x through 19.0.8,… CERT-FR · Aug 18, 2026 Medium CVE-2026-19478CVE-2026-19650gitlabvulnerabilitysecurity
vulnerability Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects GitLab has released a critical security update to address a vulnerability (CVE-2026-19478) that could allow unauthenticated attackers to delete public projects and user data. The flaw, which was discovered outside of Git… The Hacker News · Aug 17, 2026 Critical CVE-2026-19478CVE-2026-19650vulnerabilitygraphqlcve