← Retour aux CVE tendances

Semaine du 28 septembre 2026

CVE tendances* des 7 derniers jours (du 21 septembre 2026 au 28 septembre 2026)

1
CVE-2026-87902Wordpress / Wordpress
NouveauKEV
Score SYRN92
CVSS8.1
Activité150
Publié22/09/2026
StatutTrès actif

An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.

2
CVE-2026-94127F5 / Big-Ip Access Policy Manager
NouveauKEV
Score SYRN91
CVSS9.3
Activité133
Publié22/09/2026
StatutTrès actif

When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability. Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

3
CVE-2026-88771Citrix / Netscaler
NouveauKEV
Score SYRN92
CVSS9.5
Activité98
Publié27/09/2026
StatutTrès actif

Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.

4
CVE-2026-93616Checkpoint / Multi-Domain Security Management
NouveauKEV
Score SYRN92
CVSS9.8
Activité70
Publié22/09/2026
StatutTrès actif

A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.

5
CVE-2026-88772Citrix / Netscaler
NouveauKEV
Score SYRN92
CVSS9.5
Activité69
Publié27/09/2026
StatutTrès actif

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service

6
CVE-2026-65660Microsoft / Microsoft SharePoint
KEV
Score SYRN91
CVSS8.8
Activité62
Publié11/08/2026
StatutTrès actif

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

7
CVE-2026-48842Roundcube / Webmail
Score SYRN90
CVSS8.1
Activité41
Publié25/05/2026
StatutTrès actif

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.

8
CVE-2026-93952Arista / Velocloud Orchestrator
NouveauKEV
Score SYRN87
CVSS9.5
Activité38
Publié22/09/2026
StatutTrès actif

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Hosted, including Dedicated, versions of VCO were impacted and have already been patched.

9
CVE-2026-35273Oracle / Peoplesoft
KEVRansomware
Score SYRN95
CVSS9.8
Activité35
Publié11/06/2026
StatutTrès actif

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

10
CVE-2026-85102Checkpoint / Gaia Embedded
KEV
Score SYRN89
CVSS9.8
Activité35
Publié09/09/2026
StatutTrès actif

Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

* Le classement tendance est basé sur le nombre de signalements collectés par les sources de threat intelligence de SYRN sur la période donnée.

Surveillez ces vulnérabilités et soyez alerté lorsque de nouvelles menaces ciblent votre stack.

Commencer gratuitement