Retour aux CVE tendances

Semaine du 14 septembre 2026

CVE tendances* des 7 derniers jours (du 7 septembre 2026 au 14 septembre 2026)

1
CVE-2026-85706Gitlab / Gitlab
NouveauKEV
Score SYRN95
CVSS10.0
Activité162
Publié12/09/2026
StatutTrès actif

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.

2
CVE-2026-20079Cisco Systems / Secure Firewall Management Center
KEV
Score SYRN95
CVSS10.0
Activité99
Publié04/03/2026
StatutTrès actif

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.  This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device. 

3
CVE-2026-75650Adobe / Commerce
NouveauKEV
Score SYRN93
CVSS10.0
Activité89
Publié07/09/2026
StatutTrès actif

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

4
CVE-2026-86218N-able / N-Central
KEV
Score SYRN92
CVSS10.0
Activité71
Publié06/09/2026
StatutTrès actif

N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.

5
CVE-2026-85880Microsoft / Microsoft Windows
NouveauKEV
Score SYRN80
CVSS7.8
Activité66
Publié08/09/2026
StatutTrès actif

Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.

6
CVE-2026-87491Google / Google Chrome
NouveauKEV
Score SYRN89
CVSS8.8
Activité54
Publié09/09/2026
StatutTrès actif

Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

7
CVE-2026-85102Checkpoint / Quantum Security Gateway
Nouveau
Score SYRN53
CVSS9.8
Activité52
Publié09/09/2026
StatutTrès actif

Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

8
CVE-2026-85103Checkpoint / Quantum Security Gateway
Nouveau
Score SYRN53
CVSS9.8
Activité51
Publié09/09/2026
StatutTrès actif

A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.

9
CVE-2026-85046Google / Google Chrome
KEV
Score SYRN88
CVSS8.8
Activité48
Publié03/09/2026
StatutTrès actif

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

10
CVE-2026-44756Sap_se / Sap Extended Passport (Epp) Processing
Nouveau
Score SYRN61
CVSS10.0
Activité44
Publié08/09/2026
StatutTrès actif

A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availability of the application.

* Le classement tendance est basé sur le nombre de signalements collectés par les sources de threat intelligence de SYRN sur la période donnée.

Surveillez ces vulnérabilités et soyez alerté lorsque de nouvelles menaces ciblent votre stack.

Commencer gratuitement