vulnerability Vulnérabilité dans SPIP (21 août 2026) A remote code execution vulnerability has been discovered in SPIP, allowing attackers to execute arbitrary code from a remote location. The vulnerability is currently being actively exploited, and users of SPIP versions prior to 4.4.21 are strongly advised to apply the latest security update immediately. CERT-FR · Aug 21, 2026 High CVE-2026-77806remote-code-executionvulnerabilitysecurity
vulnerability Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code A critical vulnerability (CVE-2026-32475) in the Elementor Pro WordPress plugin allows unauthenticated attackers to upload PHP files and execute code, potentially leading to remote code execution. The flaw stems from a d… The Hacker News · Aug 20, 2026 High CVE-2026-32475CVE-2026-65640wordpressvulnerabilityremote-code-execution
vulnerability Siemens Simcenter Nastran A stack overflow vulnerability exists in Siemens Simcenter Nastran and Femap versions prior to V2606, potentially allowing remote code execution. Siemens has released updates to address the issue. Organizations are advis… CISA Advisories · Aug 18, 2026 High CVE-2026-59086stack-overflowremote-code-executionindustrial-control-systems
threat-intel Cl0p industrialise ses attaques via PTC Windchill A critical vulnerability in PTC Windchill and FlexPLM has been exploited by the Cl0p group, leading to a widespread campaign targeting nearly 50 international companies, including Philips, Shell, Fiserv, and GE. The vuln… ZATAZ · Aug 13, 2026 High CVE-2026-12569vulnerabilitysupply-chainremote-code-execution
vulnerability Multiples vulnérabilités dans SPIP (11 août 2026) A series of vulnerabilities have been discovered in SPIP, a popular French content management system. These include remote code execution, SQL injection, and server-side request forgery, impacting versions prior to 4.4.1… CERT-FR · Aug 11, 2026 Medium vulnerabilitysql-injectionssrf
vulnerability CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning to federal agencies to patch a critical vulnerability (CVE-2026-8037) in Progress LoadMaster and related products. This vulnerab… SecurityWeek · Aug 10, 2026 Critical CVE-2026-8037CVE-2026-33691command-injectionremote-code-executionpatch
threat-intel Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix A 2024 safety recall for Bendix’s EC80 heavy-truck brake controller, initially issued to address memory corruption issues, has been revealed to contain a significant set of vulnerabilities, including a remotely accessibl… SecurityWeek · Aug 7, 2026 High USCAvulnerabilityremote-code-executiondenial-of-service
vulnerability Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug HashiCorp, Veeam, and Django have released critical patches to address several vulnerabilities, including a cross-tenant credential reuse flaw in Terraform MCP Server, a multi-tenant console credential impersonation issu… The Hacker News · Aug 5, 2026 High CVE-2026-58073CVE-2026-58072CVE-2026-58067credential-reuseremote-code-executionspatial-data
vulnerability Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw A public exploit for a remote code execution vulnerability in vBulletin has been released, targeting versions 6.2.1 and earlier, and 6.1.6 and earlier. The vulnerability allows unauthenticated code execution, but the exp… The Hacker News · Jul 27, 2026 High CVE-2026-61511CVE-2025-48827CVE-2025-48828rcevbulletinremote-code-execution
vulnerability Multiples vulnérabilités dans les produits Atlassian (27 juillet 2026) Multiple vulnerabilities have been discovered in Atlassian products, including Confluence Data Center and Jira Service Management. These vulnerabilities allow for remote code execution, privilege escalation, denial of se… CERT-FR · Jul 27, 2026 High CVE-2022-37599CVE-2022-37601CVE-2022-37603vulnerabilitysupply-chaindata-breach
threat-intel Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE Threat actors linked to the Cl0p ransomware group are exploiting internet-exposed PTC Windchill and FlexPLM deployments to gain unauthenticated remote code execution and steal sensitive data for extortion. The campaign l… The Hacker News · Jul 25, 2026 Critical CVE-2026-12569vulnerabilityransomwaredata-breach
vulnerability Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution A critical vulnerability (CVE-2026-42533) in NGINX allows unauthenticated remote code execution, potentially due to a heap buffer overflow triggered by a specific configuration involving regex-based maps. The vulnerabili… The Hacker News · Jul 19, 2026 High CVE-2026-42533CVE-2026-42945CVE-2026-9256heap-overflowregexremote-code-execution
vulnerability CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV CISA has added a critical, actively exploited vulnerability in Microsoft SharePoint Server to its KEV list, forcing federal agencies to address it immediately. This zero-day flaw, CVE-2026-58644, allows for remote code e… The Hacker News · Jul 17, 2026 Critical CVE-2026-58644sharepointvulnerabilitydeserialization
threat-intel Multiples vulnérabilités dans les produits IBM (17 juillet 2026) Multiple vulnerabilities have been discovered in IBM products, including remote code execution, privilege escalation, and denial-of-service vulnerabilities. Several CVEs have been assigned, covering a wide range of IBM p… CERT-FR · Jul 17, 2026 High CVE-2020-28500CVE-2020-7760CVE-2020-8203vulnerabilitysupply-chainremote-code-execution
threat-intel FFmpeg fixes PixelSmash flaw in widely used video decoder A vulnerability, dubbed ‘PixelSmash’ (CVE-2026-8461), has been identified in FFmpeg’s MagicYUV decoder, allowing for remote code execution (RCE) on vulnerable systems. The flaw stems from an out-of-bounds write in the de… BleepingComputer · Jun 22, 2026 High CVE-2026-8461USsupply-chainremote-code-executionheap-overflow
vulnerability Gogs patches critical zero-day enabling remote code execution A critical zero-day vulnerability in Gogs, a remote collaboration platform, has been identified, allowing authenticated attackers to execute remote code and access private repositories. The flaw, present in versions up t… BleepingComputer · Jun 8, 2026 High CVE-2024-39933CVE-2024-39932CVE-2026-26194USCNJPremote-code-executionzero-dayauthentication
supply-chain Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware A coordinated supply chain attack targeting the Packagist repository has compromised eight PHP packages, inserting malicious code into their package.json files. The attack leveraged GitHub Releases URLs to deploy a Linux… The Hacker News · May 23, 2026 High supply-chainphpcomposer
vulnerability Google accidentally exposed details of unfixed Chromium flaw Google inadvertently exposed details of a persistent vulnerability in Chromium, allowing for remote code execution on devices. The flaw, initially reported in December 2022, remained unfixed for over two years, leading t… BleepingComputer · May 21, 2026 High remote-code-executionbrowservulnerability
vulnerability Siemens Simcenter Femap A heap-based buffer overflow vulnerability has been identified in Siemens Simcenter Femap, specifically within the Datakit library. The vulnerability, reported by TrendAI Zero Day Initiative, allows for remote code execu… CISA Advisories · May 14, 2026 High CVE-2025-12659GEheap-overflowremote-code-executionipt