Retour aux CVE tendances

Semaine du 21 septembre 2026

CVE tendances* des 7 derniers jours (du 14 septembre 2026 au 21 septembre 2026)

1
CVE-2026-76460Cisco Systems / Cisco Identity Services Engine
NouveauKEV
Score SYRN92
CVSS10.0
Activité105
Publié16/09/2026
StatutTrès actif

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.

2
CVE-2026-76461Cisco Systems / Asyncos
NouveauKEV
Score SYRN93
CVSS9.8
Activité101
Publié14/09/2026
StatutTrès actif

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.

3
CVE-2026-58704Google / Android
NouveauKEV
Score SYRN80
CVSS8.0
Activité70
Publié15/09/2026
StatutTrès actif

In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

4
CVE-2026-85706Gitlab / Gitlab
KEV
Score SYRN96
CVSS10.0
Activité49
Publié12/09/2026
StatutTrès actif

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.

5
CVE-2026-91843Checkpoint / Quantum Security Management
Nouveau
Score SYRN67
CVSS9.8
Activité48
Publié16/09/2026
StatutTrès actif

A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.

6
CVE-2026-87886Acronis / Acronis Backup
NouveauKEV
Score SYRN80
CVSS7.8
Activité35
Publié17/09/2026
StatutTrès actif

Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.3.238.

7
CVE-2026-58138Netflix / Conductor
Score SYRN92
CVSS9.3
Activité24
Publié30/06/2026
StatutActif

Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS commands by submitting inline workflow definitions containing malicious JavaScript or Python expressions to the workflow API endpoint prior to authentication. Attackers can exploit unsandboxed GraalVM evaluators configured with HostAccess.ALL or allowAllAccess(true) through INLINE, LAMBDA, DO_WHILE, and SWITCH task types to invoke arbitrary system commands via Java reflection or direct subprocess calls.

8
CVE-2026-53266Linux / Linux Kernel
KEV
Score SYRN86
CVSS8.8
Activité24
Publié25/06/2026
StatutActif

In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0). This is intentional: at the bridge ebtables hooks the Ethernet header is addressed through skb_mac_header()/eth_hdr(), while skb->data points at the Ethernet payload. Asking skb_ensure_writable() for ETH_HLEN bytes would check the payload, not the Ethernet header, and would reintroduce the small packet regression fixed by commit 63137bc5882a. However, the optional ARP sender hardware address rewrite is different. It writes through skb_store_bits() at an offset relative to skb->data: skb_store_bits(skb, sizeof(struct arphdr), info->mac, ETH_ALEN) skb_header_pointer() only safely reads the ARP header; it does not make the later sender hardware address range writable. If that range is still held in a nonlinear skb fragment backed by a splice-imported file page, skb_store_bits() maps the frag page and copies the new MAC address directly into it. Ensure the ARP SHA range is writable before reading the ARP header and before calling skb_store_bits().

9
CVE-2025-39964Linux / Linux Kernel
KEV
Score SYRN80
CVSS7.8
Activité23
Publié13/10/2025
StatutActif

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal socket state. Disallow this by adding a new ctx->write field that indiciates exclusive ownership for writing.

10
CVE-2026-41940Cpanel / Cpanel
KEVRansomware
Score SYRN99
CVSS9.3
Activité22
Publié29/04/2026
StatutActif

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

* Le classement tendance est basé sur le nombre de signalements collectés par les sources de threat intelligence de SYRN sur la période donnée.

Surveillez ces vulnérabilités et soyez alerté lorsque de nouvelles menaces ciblent votre stack.

Commencer gratuitement