Retour aux CVE tendances

Semaine du 23 mars 2026

CVE tendances* des 7 derniers jours (du 16 mars 2026 au 23 mars 2026)

1
CVE-2026-3888Canonical / Ubuntu 16.04 Lts
Nouveau
Score SYRN49
CVSS7.8
Activité93
Publié17/03/2026
StatutTrès actif

Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automatically clean up this directory. This issue affects Ubuntu 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, and 24.04 LTS.

2
CVE-2026-20131Cisco Systems / Secure Firewall Management Center
KEVRansomware
Score SYRN97
CVSS10.0
Activité75
Publié04/03/2026
StatutTrès actif

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vulnerability by sending a crafted serialized Java object to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root. Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.

3
CVE-2026-32746Gnu / Inetutils
Score SYRN69
CVSS9.8
Activité64
Publié13/03/2026
StatutTrès actif

telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because add_slc does not check whether the buffer is full.

4
CVE-2026-21992Oracle Corporation / Identity Manager
Nouveau
Score SYRN77
CVSS9.8
Activité44
Publié20/03/2026
StatutTrès actif

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager and Oracle Web Services Manager. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager and Oracle Web Services Manager. Note: Oracle Web Services Manager is installed with an Oracle Fusion Middleware Infrastructure. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

5
CVE-2026-20643Apple / Ipados
Nouveau
Score SYRN38
CVSS5.4
Activité33
Publié17/03/2026
StatutTrès actif

A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Background Security Improvements for iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1, and macOS 26.3.2. Processing maliciously crafted web content may bypass Same Origin Policy.

6
CVE-2026-20963Microsoft / Microsoft SharePoint
KEV
Score SYRN93
CVSS8.8
Activité30
Publié13/01/2026
StatutTrès actif

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

7
CVE-2026-33017Langflow-ai / Langflow
Nouveau
Score SYRN82
CVSS9.3
Activité28
Publié20/03/2026
StatutTrès actif

Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building public flows without requiring authentication. When the optional data parameter is supplied, the endpoint uses attacker-controlled flow data (containing arbitrary Python code in node definitions) instead of the stored flow data from the database. This code is passed to exec() with zero sandboxing, resulting in unauthenticated remote code execution. This is distinct from CVE-2025-3248, which fixed /api/v1/validate/code by adding authentication. The build_public_tmp endpoint is designed to be unauthenticated (for public flows) but incorrectly accepts attacker-supplied flow data containing arbitrary executable code. This issue has been fixed in version 1.9.0.

8
CVE-2025-47813Wftpserver / Wing Ftp Server
KEV
Score SYRN92
CVSS4.3
Activité24
Publié10/07/2025
StatutActif

loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie.

9
CVE-2026-21385Qualcomm / 5G Fixed Wireless Access Platform
KEV
Score SYRN92
CVSS7.8
Activité23
Publié02/03/2026
StatutActif

Memory corruption while using alignments for memory allocation.

10
CVE-2025-66376Synacor / Zimbra Collaboration Suite
KEV
Score SYRN91
CVSS7.2
Activité22
Publié05/01/2026
StatutActif

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.

* Le classement tendance est basé sur le nombre de signalements collectés par les sources de threat intelligence de SYRN sur la période donnée.

Surveillez ces vulnérabilités et soyez alerté lorsque de nouvelles menaces ciblent votre stack.

Commencer gratuitement