Retour aux CVE tendances

Semaine du 10 août 2026

CVE tendances* des 7 derniers jours (du 3 août 2026 au 10 août 2026)

1
CVE-2026-18577N-able / N-Central
NouveauKEV
Score SYRN95
CVSS8.2
Activité63
Publié02/08/2026
StatutTrès actif

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

2
CVE-2026-63077Jetbrains / Teamcity
KEV
Score SYRN97
CVSS9.8
Activité50
Publié27/07/2026
StatutTrès actif

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

3
CVE-2026-64561Linux / Linux Kernel
Nouveau
Score SYRN51
CVSS8.8
Activité47
Publié04/08/2026
StatutTrès actif

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available Check for a "stale" page fault, i.e. for an invalid and/or obsolete root, after making MMU pages available for the shadow MMU. If reclaiming shadow pages zaps an in-use root, i.e. marks it invalid, then KVM will attempt to map memory into an invalid root. On its own, populating an invalid root is "fine", but because child shadow pages inherit their parent's role, any children created during the map/fetch will be created as invalid pages, thus violating KVM's invariant that invalid pages are never on the list of active MMU pages. Note, the underlying flaw has existed since KVM first started tracking invalid roots in 2008 (commit 2e53d63acba7, "KVM: MMU: ignore zapped root pagetables"), but the true badness only came along in 2020 (Linux 5.9) with the invariant that invalid shadow pages can't be on the list of active pages. Note #2, inheriting role.invalid when creating child shadow pages is also far from ideal; that flaw will be addressed separately.

4
CVE-2026-58048Webpros / Cpanel
Score SYRN93
CVSS9.4
Activité36
Publié31/07/2026
StatutTrès actif

Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.

5
CVE-2026-64638Wordpress / Wordpress
Nouveau
Score SYRN95
CVSS8.9
Activité29
Publié07/08/2026
StatutTrès actif

WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim. This issue affects all versions of WordPress. Version 7.0.3 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7. Discovered and responsibly disclosed by [the team at pwn.ai](https://pwn.ai/).

6
CVE-2026-18556N-able / N-Central
KEV
Score SYRN94
CVSS8.2
Activité26
Publié01/08/2026
StatutTrès actif

Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.

7
CVE-2026-9198Langflow / Langflow
KEV
Score SYRN96
CVSS9.8
Activité23
Publié17/07/2026
StatutActif

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments

8
CVE-2026-66066Rails / Rails
Score SYRN94
CVSS9.5
Activité20
Publié30/07/2026
StatutActif

Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured to use libvips and accept image uploads from untrusted users. An unauthenticated attacker may exploit this behavior to read arbitrary files accessible to the Rails process, including environment variables and application secrets. Exposure of credentials such as secret_key_base or external-service tokens may enable remote code execution or lateral movement. This issue has been fixed in versions 7.2.3.2, 8.0.5.1 and 8.1.3.1.

9
CVE-2025-55182Vercel / Next.Js
KEVRansomware
Score SYRN100
CVSS10.0
Activité17
Publié03/12/2025
StatutActif

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.

10
CVE-2026-8037Progress / Connection Manager For Objectscale
KEV
Score SYRN98
CVSS9.6
Activité17
Publié04/06/2026
StatutActif

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints

* Le classement tendance est basé sur le nombre de signalements collectés par les sources de threat intelligence de SYRN sur la période donnée.

Surveillez ces vulnérabilités et soyez alerté lorsque de nouvelles menaces ciblent votre stack.

Commencer gratuitement