250
Exploits actifs en 2026
Source CISA KEV
1734
Total exploits CISA
Depuis le début
10
Alertes CERT-FR 2026
Récupérées ce mois
10
Critiques aujourd'hui
Toutes sources

Veille Cybersécurité

Mis à jour le : 08/10/2026 20:00 — Sources : CERT-FR, CISA, NVD NIST

Critique Haute Moyenne Basse
BleepingComputer HAUTE Actualité sécurité
Cisco released security advisories for five critical vulnerabilities in its NX-OS data center network operating system that could be exploited to run arbitrary code with root privileges on Nexus switc...
2026-10-08
BleepingComputer HAUTE Actualité sécurité
OAuth grants create data highways between SaaS apps, AI agents, and other tools. And, they are multiplying faster than any security team can review them. As the recent Klue breach showed, attackers ar...
2026-10-08
BleepingComputer HAUTE Actualité sécurité
A Maryland man was found guilty of stealing more than $53 million after hacking the decentralized crypto exchange Uranium Finance twice in April 2021. [...]
2026-10-08
BleepingComputer HAUTE Actualité sécurité
ASOS is sending updates to affected customers about the cybersecurity incident it suffered earlier this week, confirming that hackers accessed some personal data. [...]
2026-10-08
BleepingComputer HAUTE Actualité sécurité
​​​On the second day of Pwn2Own Ireland 2026, security researchers collected $232,500 in cash awards after exploiting 45 unique zero-day vulnerabilities. [...]
2026-10-08
The Hacker News HAUTE Actualité sécurité
The Russia-aligned threat actor known as UAC-0099 has been attributed to a previously undocumented .NET infostealer and remote access trojan (RAT) codenamed ASHVEIN. According to TrendAI, the malware...
2026-10-08
The Hacker News HAUTE Actualité sécurité
Cybersecurity researchers have disclosed details of a targeted campaign aimed at South Korean financial organizations that used an artificial intelligence (AI) pen testing tool named ARTEX to carry ou...
2026-10-08
The Hacker News HAUTE Actualité sécurité
Phishing kits are no longer limited to copying a familiar login page and waiting for a victim to enter credentials. Attackers are increasingly building filtering, session management, and traffic contr...
2026-10-08
The Hacker News HAUTE Actualité sécurité
Cybersecurity researchers have discovered a cluster of 16 malicious Mozilla Firefox extensions that are capable of stealing cryptocurrency wallet recovery phrases and private keys. "The extensions ma...
2026-10-08
The Hacker News HAUTE Actualité sécurité
The U.S. State Department is offering up to $10 million for information leading to the identification or location of Zhang Yu, a Chinese national charged in the United States in connection with the 20...
2026-10-08
CISA KEV CRITIQUE Exploit actif
Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for a denial of service.
Citrix NetScaler
2026-10-04
CERT-FR HAUTE Alerte française
2026-10-02
CISA KEV CRITIQUE Exploit actif
Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489.
Zammad GmbH Zammad
2026-10-02
CISA KEV CRITIQUE Exploit actif
Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490.
Zammad GmbH Zammad
2026-10-02
CERT-FR HAUTE Alerte française
2026-10-01
CISA KEV CRITIQUE Exploit actif
Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
Fortinet FortiMail
2026-10-01
CISA KEV CRITIQUE Exploit actif
Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request.
Cisco Catalyst SD-WAN Manager
2026-09-30
CISA KEV CRITIQUE Exploit actif
Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution.
Apple Multiple Products
2026-09-29
CISA KEV CRITIQUE Exploit actif
Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service
Citrix NetScaler
2026-09-27
CISA KEV CRITIQUE Exploit actif
Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands.
Citrix NetScaler
2026-09-27
CISA KEV CRITIQUE Exploit actif
Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060.
MikroTik RouterOS
2026-09-25
CISA KEV CRITIQUE Exploit actif
Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network.
Microsoft SharePoint
2026-09-25