Retour aux CVE tendances

Semaine du 17 août 2026

CVE tendances* des 7 derniers jours (du 10 août 2026 au 17 août 2026)

1
CVE-2026-68820Microsoft / Microsoft Windows
NouveauKEV
Score SYRN94
CVSS7.0
Activité119
Publié11/08/2026
StatutTrès actif

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

2
CVE-2026-20349Cisco Systems / Adaptive Security Appliance Software
NouveauKEV
Score SYRN94
CVSS8.6
Activité80
Publié11/08/2026
StatutTrès actif

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.  This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.

3
CVE-2026-55040Microsoft / Microsoft SharePoint
Score SYRN94
CVSS9.1
Activité69
Publié14/07/2026
StatutTrès actif

Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.

4
CVE-2026-59310Vmware / Cloud Foundation
KEV
Score SYRN95
CVSS9.8
Activité60
Publié30/07/2026
StatutTrès actif

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

5
CVE-2026-58231Sap_se / Sap Commerce Cloud Data Hub Adapter
Nouveau
Score SYRN96
CVSS10.0
Activité37
Publié11/08/2026
StatutTrès actif

SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.

6
CVE-2026-65400Apple / Macos
Score SYRN86
CVSS7.1
Activité29
Publié06/08/2026
StatutTrès actif

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.

7
CVE-2026-71362Adobe / Adobe Commerce
Nouveau
Score SYRN94
CVSS9.1
Activité28
Publié11/08/2026
StatutTrès actif

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.

8
CVE-2026-50656Microsoft / Cisco Identity Services Engine
Score SYRN66
CVSS7.8
Activité27
Publié16/06/2026
StatutTrès actif

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ".

9
CVE-2026-72898Metabase / Metabase
NouveauKEV
Score SYRN97
CVSS10.0
Activité27
Publié10/08/2026
StatutTrès actif

Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.

10
CVE-2026-63077Jetbrains / Teamcity
KEV
Score SYRN98
CVSS9.8
Activité26
Publié27/07/2026
StatutTrès actif

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

* Le classement tendance est basé sur le nombre de signalements collectés par les sources de threat intelligence de SYRN sur la période donnée.

Surveillez ces vulnérabilités et soyez alerté lorsque de nouvelles menaces ciblent votre stack.

Commencer gratuitement