Retour aux CVE tendances

Semaine du 9 mars 2026

CVE tendances* des 7 derniers jours (du 2 mars 2026 au 9 mars 2026)

1
CVE-2026-21385Qualcomm / 5G Fixed Wireless Access Platform
NouveauKEV
Score SYRN90
CVSS7.8
Activité53
Publié02/03/2026
StatutTrès actif

Memory corruption while using alignments for memory allocation.

2
CVE-2026-22719Vmware / Aria Operations
KEV
Score SYRN88
CVSS8.1
Activité44
Publié25/02/2026
StatutTrès actif

VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress.  To remediate CVE-2026-22719, apply the patches listed in the 'Fixed Version' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001  Workarounds for CVE-2026-22719 are documented in the 'Workarounds' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001

3
CVE-2026-20127Cisco Systems / Catalyst Sd-Wan Manager
KEV
Score SYRN97
CVSS10.0
Activité33
Publié25/02/2026
StatutTrès actif

A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric. 

4
CVE-2026-21902Juniper Networks / Junos Os Evolved
Score SYRN70
CVSS9.8
Activité19
Publié25/02/2026
StatutActif

An Incorrect Permission Assignment for Critical Resource vulnerability in the On-Box Anomaly detection framework of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated, network-based attacker to execute code as root. The On-Box Anomaly detection framework should only be reachable by other internal processes over the internal routing instance, but not over an externally exposed port. With the ability to access and manipulate the service to execute code as root a remote attacker can take complete control of the device. Please note that this service is enabled by default as no specific configuration is required. This issue affects Junos OS Evolved on PTX Series: * 25.4 versions before 25.4R1-S1-EVO, 25.4R2-EVO. This issue does not affect Junos OS Evolved versions before 25.4R1-EVO. This issue does not affect Junos OS.

5
CVE-2026-20122Cisco Systems / Catalyst Sd-Wan Manager
Score SYRN19
CVSS5.4
Activité18
Publié25/02/2026
StatutActif

A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. To exploit this vulnerability, the attacker must have valid read-only credentials with API access on the affected system. This vulnerability is due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmanage user privileges.

6
CVE-2026-20079Cisco Systems / Cisco Secure Firewall Management Center (Fmc)
Nouveau
Score SYRN75
CVSS10.0
Activité17
Publié04/03/2026
StatutActif

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device.

7
CVE-2026-0628Google / Google Chrome
Score SYRN65
CVSS8.8
Activité16
Publié06/01/2026
StatutActif

Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: High)

8
CVE-2026-20128Cisco Systems / Catalyst Sd-Wan Manager
Score SYRN26
CVSS7.5
Activité15
Publié25/02/2026
StatutActif

A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an authenticated, local attacker to gain DCA user privileges on an affected system. To exploit this vulnerability, the attacker must have valid vmanage credentials on the affected system. This vulnerability is due to the presence of a credential file for the DCA user on an affected system. An attacker could exploit this vulnerability by accessing the filesystem as a low-privileged user and reading the file that contains the DCA password from that affected system. A successful exploit could allow the attacker to access another affected system and gain DCA user privileges. Note: Cisco Catalyst SD-WAN Manager releases 20.18 and later are not affected by this vulnerability.

9
CVE-2026-21513Microsoft / Microsoft Windows
KEV
Score SYRN91
CVSS8.8
Activité15
Publié10/02/2026
StatutActif

Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.

10
CVE-2026-20131Cisco Systems / Cisco Secure Firewall Management Center (Fmc)
Nouveau
Score SYRN84
CVSS10.0
Activité14
Publié04/03/2026
StatutActif

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vulnerability by sending a crafted serialized Java object to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root. Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.

* Le classement tendance est basé sur le nombre de signalements collectés par les sources de threat intelligence de SYRN sur la période donnée.

Surveillez ces vulnérabilités et soyez alerté lorsque de nouvelles menaces ciblent votre stack.

Commencer gratuitement