Retour aux CVE tendances

Semaine du 27 juillet 2026

CVE tendances* des 7 derniers jours (du 20 juillet 2026 au 27 juillet 2026)

1
CVE-2026-63030Wordpress / Wordpress
KEV
Score SYRN98
CVSS9.8
Activité109
Publié17/07/2026
StatutTrès actif

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.

2
CVE-2026-50522Microsoft / Microsoft SharePoint
KEV
Score SYRN98
CVSS9.8
Activité108
Publié14/07/2026
StatutTrès actif

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

3
CVE-2026-60137Wordpress / Wordpress
KEV
Score SYRN97
CVSS5.9
Activité83
Publié17/07/2026
StatutTrès actif

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.

4
CVE-2026-16232Checkpoint / Multi-Domain Security Management
NouveauKEV
Score SYRN96
CVSS9.1
Activité64
Publié22/07/2026
StatutTrès actif

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.

5
CVE-2026-6875Servicenow / Servicenow Ai Platform
Score SYRN96
CVSS9.5
Activité54
Publié13/07/2026
StatutTrès actif

ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow platform. ServiceNow addressed this vulnerability by deploying a security update to hosted instances. Relevant security updates have also been provided to ServiceNow self-hosted customers and partners. Further, the vulnerability is addressed in the listed patches and family releases, which have been made available to hosted and self-hosted customers, as well as partners. We are not currently aware of exploitation against ServiceNow instances. We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.

6
CVE-2026-64600Linux / Linux Kernel
Nouveau
Score SYRN46
CVSS7.8
Activité54
Publié23/07/2026
StatutTrès actif

In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode, a data fork mapping, and a cow fork mapping. Unfortunately, these two helpers cycle the ILOCK to grab a transaction, which means that the mappings are stale as soon as we reacquire the ILOCK. Currently we refresh the cow fork mapping by re-calling xfs_find_trim_cow_extent, but we don't refresh the data fork mapping beforehand, which means that the xfs_bmap_trim_cow in that function queries the refcount btree about the wrong physical blocks and returns an inaccurate value in *shared. If *shared is now false, the directio write proceeds with a stale data fork mapping. Fix this by querying the data fork mapping if the sequence counter changes across the ILOCK cycle.

7
CVE-2026-0257Paloaltonetworks / Pan-Os
KEV
Score SYRN96
CVSS7.8
Activité52
Publié13/05/2026
StatutTrès actif

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.

8
CVE-2026-8933Canonical / Ubuntu 22.04 Lts
Nouveau
Score SYRN30
CVSS7.8
Activité48
Publié21/07/2026
StatutTrès actif

A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution environment for snap applications. This vulnerability uniquely affects versions of snap-confine configured with set-capabilities (rather than standard set-uid-root installations). Due to a flaw in how privilege boundaries or security sandboxes are initialized when the binary runs under limited ambient capabilities, a local, unprivileged attacker can exploit this behavior to bypass intended restrictions and execute arbitrary code. Successful exploitation allows the local user to elevate their privileges to full root authority.

9
CVE-2026-54121Microsoft / Microsoft Windows
Score SYRN64
CVSS8.8
Activité40
Publié14/07/2026
StatutTrès actif

Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.

10
CVE-2025-55182Vercel / Next.Js
KEVRansomware
Score SYRN100
CVSS10.0
Activité34
Publié03/12/2025
StatutTrès actif

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.

* Le classement tendance est basé sur le nombre de signalements collectés par les sources de threat intelligence de SYRN sur la période donnée.

Surveillez ces vulnérabilités et soyez alerté lorsque de nouvelles menaces ciblent votre stack.

Commencer gratuitement