threat-intel 943 Patches Rolled Out With Oracle’s August 2026 Security Update Oracle released a massive update – 943 security patches – as part of its August 2026 Critical Security Patch Update, addressing over 1,000 unique vulnerabilities across numerous products. Many of these flaws, particularly those affecting Fusion Middleware and Hyperion, can be exploited remotely without requiring authen… SecurityWeek · Aug 19, 2026 High patchingvulnerabilitiessecurity
vulnerability Vulnérabilité dans SPIP (17 août 2026) A critical vulnerability has been identified in SPIP, allowing attackers to execute arbitrary code remotely. This affects older versions of the content management system, requiring immediate patching to prevent exploitat… CERT-FR · Aug 17, 2026 High spipremotecode
vulnerability Ivanti EPM Update Patches Remotely Exploitable Flaws Ivanti has released patches to address four vulnerabilities in its Endpoint Manager (EPM) and Neurons for MDM products. Two of the EPM flaws are remotely exploitable, allowing attackers to steal credentials and gain cont… SecurityWeek · Aug 12, 2026 High CVE-2026-18129CVE-2026-18125CVE-2026-18127vulnerabilitypatchremote
supply-chain Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11 Researchers have discovered a method to leverage Windows Plug and Play to achieve SYSTEM-level access on Windows 11 machines. By emulating USB devices and exploiting a vulnerability in the driver installation process, an… The Hacker News · Aug 11, 2026 High usbremotedriver
vulnerability Multiples vulnérabilités dans WordPress (07 août 2026) Multiple vulnerabilities have been discovered in WordPress, including remote code execution and privilege escalation, potentially leading to data compromise. These flaws are primarily affecting older versions of the plat… CERT-FR · Aug 7, 2026 High CVE-2026-64638wordpressvulnerabilityssrf
vulnerability Vulnérabilité dans Microsoft Office (03 août 2026) A remote code execution vulnerability has been identified in Microsoft Office, allowing attackers to execute arbitrary code. This affects various versions of Office 365, Excel, and Office LTSC, requiring immediate patchi… CERT-FR · Aug 3, 2026 High CVE-2026-62870remotecodeexecution
vulnerability Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data A zero-day vulnerability in Cisco Secure Firewall Management Center (FMC) software is actively being exploited, allowing unauthenticated remote attackers to gain access to sensitive data. The vulnerability stems from sta… The Hacker News · Jul 30, 2026 High CVE-2026-20316CVE-2026-20079zero-dayauthenticationremote
vulnerability Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day Arista Networks has released patches for a critical zero-day vulnerability in its VeloCloud Orchestrator, which has been actively exploited in the wild. The flaw allows remote access to privileged functionality, and no s… SecurityWeek · Jul 28, 2026 Critical CVE-2026-16812CVE-2025-68686CVE-2022-42475zero-daypatchvulnerability
vulnerability Vulnérabilité dans NetApp ONTAP 9 (24 juillet 2026) A critical vulnerability has been identified in NetApp ONTAP 9, potentially allowing attackers to cause denial of service, compromise data confidentiality, and damage data integrity. Affected versions require immediate p… CERT-FR · Jul 24, 2026 Critical CVE-2026-42511vulnerabilityremotedata
vulnerability CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability, CVE-2026-45247, affecting the Mirasvit Cache Warmer Magento extension to its KEV catalog. This flaw allows for remote c… The Hacker News · Jun 4, 2026 Critical CVE-2026-45247USUKFRphpobjectdeserialization
vulnerability Vulnérabilité dans LibreNMS (12 mai 2026) A vulnerability in LibreNMS allows for remote code injection via cross-site scripting (XSS). This affects versions prior to 26.3.0, potentially enabling attackers to execute malicious code on vulnerable systems. Users ar… CERT-FR · May 12, 2026 Medium CVE-2026-2728xssvulnerabilityremote