← Retour aux CVE tendances

Semaine du 5 octobre 2026

CVE tendances* des 7 derniers jours (du 28 septembre 2026 au 5 octobre 2026)

1
CVE-2026-88771Citrix / Netscaler
KEV
Score SYRN94
CVSS9.5
Activité130
Publié27/09/2026
StatutTrès actif

Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.

2
CVE-2026-88772Citrix / Netscaler
KEV
Score SYRN93
CVSS9.5
Activité118
Publié27/09/2026
StatutTrès actif

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service

3
CVE-2026-86950Apple / Ipados
NouveauKEV
Score SYRN89
CVSS8.8
Activité113
Publié28/09/2026
StatutTrès actif

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.

4
CVE-2026-104286Fortinet / Fortimail
NouveauKEV
Score SYRN93
CVSS9.8
Activité110
Publié01/10/2026
StatutTrès actif

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

5
CVE-2026-76504Cisco Systems / Catalyst Sd-Wan Manager
NouveauKEV
Score SYRN93
CVSS9.8
Activité104
Publié30/09/2026
StatutTrès actif

A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user.

6
CVE-2026-88779Citrix / Netscaler
NouveauKEV
Score SYRN88
CVSS8.7
Activité79
Publié04/10/2026
StatutTrès actif

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.

7
CVE-2026-90970Gitlab / Gitlab Ai Gateway
Nouveau
Score SYRN60
CVSS9.9
Activité41
Publié02/10/2026
StatutTrès actif

GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 that, under certain conditions, could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template sandbox via a specially crafted flow configuration, resulting in arbitrary command execution on the AI Gateway.

8
CVE-2026-73570Synacor / Zimbra Collaboration Suite
KEV
Score SYRN92
CVSS8.9
Activité41
Publié13/08/2026
StatutTrès actif

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

9
CVE-2026-102489Docker / Docker Container Platform
NouveauKEV
Score SYRN86
CVSS8.7
Activité31
Publié30/09/2026
StatutTrès actif

Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.

10
CVE-2026-102490Docker / Docker Container Platform
NouveauKEV
Score SYRN80
CVSS8.5
Activité26
Publié30/09/2026
StatutTrès actif

All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.

* Le classement tendance est basé sur le nombre de signalements collectés par les sources de threat intelligence de SYRN sur la période donnée.

Surveillez ces vulnérabilités et soyez alerté lorsque de nouvelles menaces ciblent votre stack.

Commencer gratuitement