Retour aux CVE tendances

Semaine du 20 avril 2026

CVE tendances* des 7 derniers jours (du 13 avril 2026 au 20 avril 2026)

1
CVE-2026-33032Nginxui / Nginx Web Server
Score SYRN95
CVSS9.8
Activité53
Publié30/03/2026
StatutTrès actif

Nginx UI is a web user interface for the Nginx web server. In versions 2.3.5 and prior, the nginx-ui MCP (Model Context Protocol) integration exposes two HTTP endpoints: /mcp and /mcp_message. While /mcp requires both IP whitelisting and authentication (AuthRequired() middleware), the /mcp_message endpoint only applies IP whitelisting - and the default IP whitelist is empty, which the middleware treats as "allow all". This means any network attacker can invoke all MCP tools without authentication, including restarting nginx, creating/modifying/deleting nginx configuration files, and triggering automatic config reloads - achieving complete nginx service takeover. At time of publication, there are no publicly available patches.

2
CVE-2026-32201Microsoft / Microsoft SharePoint
NouveauKEV
Score SYRN92
CVSS6.5
Activité51
Publié14/04/2026
StatutTrès actif

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

3
CVE-2026-34197Apache Software Foundation / Activemq
KEV
Score SYRN96
CVSS8.8
Activité42
Publié07/04/2026
StatutTrès actif

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including BrokerService.addNetworkConnector(String) and BrokerService.addConnector(String). An authenticated attacker can invoke these operations with a crafted discovery URI that triggers the VM transport's brokerConfig parameter to load a remote Spring XML application context using ResourceXmlApplicationContext. Because Spring's ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates the configuration, arbitrary code execution occurs on the broker's JVM through bean factory methods such as Runtime.exec(). This issue affects Apache ActiveMQ Broker: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ All: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ: before 5.19.4, from 6.0.0 before 6.2.3. Users are recommended to upgrade to version 5.19.4 or 6.2.3, which fixes the issue

4
CVE-2026-33825Microsoft / Microsoft Defender
Nouveau
Score SYRN55
CVSS7.8
Activité40
Publié14/04/2026
StatutTrès actif

Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.

5
CVE-2026-33824Microsoft / Microsoft Windows
Nouveau
Score SYRN69
CVSS9.8
Activité24
Publié14/04/2026
StatutActif

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

6
CVE-2026-34621Adobe / Acrobat
KEV
Score SYRN94
CVSS8.6
Activité23
Publié11/04/2026
StatutActif

Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

7
CVE-2025-0520Showdoc / Showdoc
Score SYRN73
CVSS9.4
Activité23
Publié29/04/2025
StatutActif

An unrestricted file upload vulnerability in ShowDoc caused by improper validation of file extension allows execution of arbitrary PHP, leading to remote code execution.This issue affects ShowDoc: before 2.8.7.

8
CVE-2026-39808Fortinet / Fortisandbox
Nouveau
Score SYRN80
CVSS9.1
Activité19
Publié14/04/2026
StatutActif

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here>

9
CVE-2024-3721Tbk / Dvr-4104
Score SYRN95
CVSS6.3
Activité16
Publié13/04/2024
StatutActif

A vulnerability was found in TBK DVR-4104 and DVR-4216 up to 20240412 and classified as critical. This issue affects some unknown processing of the file /device.rsp?opt=sys&cmd=___S_O_S_T_R_E_A_MAX___. The manipulation of the argument mdb/mdc leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-260573 was assigned to this vulnerability.

10
CVE-2026-20184Cisco Systems / Cisco Webex Meetings
Nouveau
Score SYRN53
CVSS9.8
Activité15
Publié15/04/2026
StatutActif

A vulnerability in the integration of single sign-on (SSO) with Control Hub in Cisco Webex Services could have allowed an unauthenticated, remote attacker to impersonate any user within the service. This vulnerability existed because of improper certificate validation. Prior to this vulnerability being addressed, an attacker could have exploited this vulnerability by connecting to a service endpoint and supplying a crafted token. A successful exploit could have allowed the attacker to gain unauthorized access to legitimate Cisco Webex services.

* Le classement tendance est basé sur le nombre de signalements collectés par les sources de threat intelligence de SYRN sur la période donnée.

Surveillez ces vulnérabilités et soyez alerté lorsque de nouvelles menaces ciblent votre stack.

Commencer gratuitement