Voici la liste des derniers avis du CERT-Renater en 2026 :


13 Feb 2026VULN167Traefik : TCP readTimeout bypass via STARTTLS on PostgresSystems running Traefik versions prior to 2.6.1, 3.0.0-beta.3.
13 Feb 2026VULN166SPIP : Mise =?UTF-8?Q?=C3=A0?= jour de =?UTF-8?Q?s=C3=A9curit=C3=A9?= sortie de SPIP 4.4.8Systems running SPIP versions prior to 4.4.8.
13 Feb 2026VULN165SurrealDB : Denial of Service through scripting function memory edge caseSystems running SurrealDB (Rust) versions prior to 2.6.1, 3.0.0-beta.3.
13 Feb 2026VULN164Fortinet : Multiple vulnerabilities fixed in FortiOSFortiOS versions prior to 7.6.5, 7.4.10.
13 Feb 2026VULN163Fortinet : Missing authorization on CSV user importSystems running FortiAuthenticator versions prior to 6.6.7.
13 Feb 2026VULN162PostgreSQL : PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 Released!Systems running PostgreSQL versions prior to 18.2, 17.8, 16.12, 15.16, 14.21.
13 Feb 2026VULN161Apache : CVE-2025-33042 Apache Avro Java SDK Code injection on Java generated codeSystems running Apache Avro Java SDK versions prior to 1.12.1, 1.11.5.
12 Feb 2026VULN160Pillow : Out-of-bounds write when loading PSD imagesSystems running Pillow versions prior to 12.1.1.
12 Feb 2026VULN159APPLE : APPLE-SA-02-11-2026-7 watchOS 26.3watchOS versions prior to 26.3.
12 Feb 2026VULN158APPLE : APPLE-SA-02-11-2026-6 tvOS 26.3tvOS versions prior to 26.3.
12 Feb 2026VULN157APPLE : iOS 26.3, 18.7.5 and iPadOS 26.3, 18.7.5iOS, iPadOS versions prior to 26.3, 18.7.5.
12 Feb 2026VULN156APPLE : macOS Tahoe 26.3, Sequoia 15.7.4 and Sonoma 14.8.4macOS versions prior to Tahoe 26.3, Sequoia 15.7.4, Sonoma 14.8.4.
12 Feb 2026VULN155BeyondTrust : RCE in Remote Support (RS) and Privileged Remote Access (PRA)Systems running BeyondTrust Remote Support versions prior to Patch BT26-02-RS (v21.3 - 25.3.1), BeyondTrust Privileged Remote Access versions prior to Patch BT26-02-PRA (v22.1 - 24.X).
11 Feb 2026VULN154Ivanti : Security Advisory EPM February 2026 for EPM 2024Systems running Ivanti Endpoint Manager versions prior to 2024 SU5.
11 Feb 2026VULN153GitLab : GitLab Patch Release: 18.8.4, 18.7.4, 18.6.6Systems running GitLab versions prior to 18.8.4, 18.7.4, 18.6.6.
11 Feb 2026VULN152Adobe : Security Updates Available for Adobe Bridge APSB26-21Systems running Adobe Bridge versions prior to 15.1.4 (LTS), 16.0.2.
11 Feb 2026VULN151Adobe : Security Update Available for Adobe InDesign APSB26-17Systems running Adobe InDesign versions prior to ID21.2, ID20.5.2.
11 Feb 2026VULN149munge : Buffer overflow in message unpacking allows key leakage and credential forgerySystems running munge versions prior to 0.5.18.
11 Feb 2026VULN148Adobe : Security Updates Available for Adobe After Effects APSB26-15Systems running Adobe After Effects versions prior to 25.6.4, 26.0.
11 Feb 2026VULN147Keycloak : Keycloak 26.5.3 fix multiple security vulnerabilitiesSystems running Keycloak versions prior to 26.5.3.
11 Feb 2026VULN146Cryptography : PyCA cryptography 46.0.5 releasedSystems running PyCA cryptography versions prior to 46.0.0.
10 Feb 2026VULN145Fortinet : SQLi in administrative interfaceSystems running FortiClientEMS versions prior to 7.4.5.
10 Feb 2026VULN144SAP : SAP Security Patch Day - February 2026Systems running SAP products.
10 Feb 2026VULN143libpng : Heap buffer overflow in png_set_quantizeSystems running libpng versions prior to 1.6.55.
10 Feb 2026VULN142PowerDNS : PowerDNS Security Advisory 2026-01 Crafted zones can lead to increased resource usage in RecursorSystems running PowerDNS Recursor versions prior to 5.1.10, 5.2.8, 5.3.5.
10 Feb 2026VULN141GNUTLS : gnutls 3.8.12 fix DoS and Stack write buffer overflow vulnerabilitiesSystems running GNUTLS versions prior to 3.8.12.
10 Feb 2026VULN140Apache : CVE-2026-23906 Apache Druid Authentication Bypass via LDAP Anonymous BindSystems running Apache Druid versions prior to 36.0.0.
9 Feb 2026VULN139Broadcom : VMware Tanzu Greenplum 6.32.0Systems running VMware Tanzu Greenplum versions prior to 6.32.0.
9 Feb 2026VULN138Apache : CVE-2026-24343 Apache HertzBeat Uncontrolled Resource Consumption via Crafted XPath ExpressionsSystems running Apache HertzBeat versions prior to 1.8.0.
9 Feb 2026VULN137Apache : Permission Bypass and permission leak vulnerabilities fixed in Apache AirflowSystems running Apache Airflow versions prior to 3.1.7.
9 Feb 2026VULN136Gitlab : GitLab AI Gateway Critical Patch Release: 18.6.2, 18.7.1, and 18.8.1Systems running GitLab AI Gateway versions prior to 18.6.2, 18.7.1, 18.8.1.
9 Feb 2026VULN135Roundcube : Security updates 1.6.13 and 1.5.13 releasedSystems running Roundcube Webmail prior to 1.6.13, 1.5.13.
6 Feb 2026VULN134Broadcom : Isolation Segmentation for VMware Tanzu Platform 10.2.7+LTS-T, 10.3.4Systems running VMware Tanzu Platform versions prior to 10.2.7+LTS-T.
6 Feb 2026VULN133ESET : Local privilege escalation vulnerability in ESET Management Agent for Windows fixedSystems running ESET Management Agent for Windows versions prior to 13.0.1400.0.
6 Feb 2026VULN132web2py : web2py has an Open Redirect VulnerabilitySystems running web2py versions prior to 3.1.7.
6 Feb 2026VULN131pgAdmin : 2026-02-05 - pgAdmin 4 v9.12 ReleasedSystems running pgAdmin 4 versions prior to 9.12.
6 Feb 2026VULN130vim : buffer overflow in helpfile option handling affects Vim < 9.1.2132Systems running Vim versions prior to 9.1.2132.
5 Feb 2026VULN129Broadcom : Foundation Core for VMware Tanzu Platform 3.1.7Systems running Foundation Core for VMware Tanzu Platform versions prior to 3.1.7.
5 Feb 2026VULN128Splunk : Third-Party Package Updates in Splunk SOAR - February 2026Systems running Splunk SOAR versions prior to 7.1.0.
5 Feb 2026VULN127Cisco : Cisco Security Advisories Published on February 04, 2026Systems running Cisco Meeting Management, Cisco TelePresence Collaboration Endpoint Software and RoomOS Software, Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure, Cisco Secure Web Appliance.
5 Feb 2026VULN126Drupal : Login Disable - Less critical - Access bypass - SA-CONTRIB-2026-008Systems running Login Disable for Drupal versions prior to 2.1.3.
5 Feb 2026VULN125NGINX : CVE-2026-1642 SSL upstream injection Vulnerability fixedSystems running NGINX versions prior to 1.29.5+, 1.28.2+.
5 Feb 2026VULN124modelcontextprotocol.io : Sharing server/transport instances can leak cross-client response dataSystems running @modelcontextprotocol/sdk (npm) versions prior to 1.26.0.
5 Feb 2026VULN123openclaw : Local File Inclusion via MEDIA: Path ExtractionSystems running openclaw (npm) versions prior to 2026.1.30.
5 Feb 2026VULN122n8n : Multiple Critical Vulnerabilities fixed in n8nSystems running n8n (npm) versions prior to 2.5.2, 1.123.17.
5 Feb 2026VULN121rancher : Vulnerable to path traversal via parameters.pathPatternSystems running rancher/local-path-provisioner versions prior to 0.0.34.
4 Feb 2026VULN120Tenable : Tenable Identity Exposure Version 3.77.16 Fixes Multiple VulnerabilitiesSystems running Tenable Identity Exposure versions prior to 3.77.16.
4 Feb 2026VULN119Google : Chrome 144.0.7559.132/.133 fixes high-severity security vulnerabilitySystems running Google Chrome versions prior to 144.0.7559.132/.133.
4 Feb 2026VULN118glpi : Multiple security vulnerabilities fixed in glpiSystems running glpi versions prior to 10.0.23, 11.0.5.
4 Feb 2026VULN117wagtail : Improper permission handling on admin preview endpointsSystems running wagtail versions prior to 6.3.6, 7.0.4, 7.1.3, 7.2.2, 7.3.
4 Feb 2026VULN116Claude Code : Multiple security vulnerabilities fixed in ClaudeSystems running Claude Code versions prior to 2.0.74.
4 Feb 2026VULN115Django : Django security releases issued 6.0.2, 5.2.11, and 4.2.28Systems running Django versions prior to 6.0.2, 5.2.11, 4.2.28.
3 Feb 2026VULN114Broadcom : Platform Automation Toolkit 5.4.0Systems running Platform Automation Toolkit versions prior to 5.4.0.
3 Feb 2026VULN113Broadcom : Telemetry for VMware Tanzu Platform 2.4.0Systems running Tanzu Telemetry for VMware Tanzu versions prior to 2.4.0.
3 Feb 2026VULN112Broadcom : Tanzu Kubernetes Grid Integrated Edition (TKGi) VulnerabilitiesSystems running anzu Kubernetes Grid Integrated Edition (TKGi).
3 Feb 2026VULN111Node.js : OpenSSL Security Advisory Assessment, January 2026Systems running Node.js and OpenSSL versions 3.0, 3.5.
3 Feb 2026VULN110Plone : Plone Security Advisory 20260116 - Attempted code insertions into Github pull requestsSystems running plone ecosystem software.
3 Feb 2026VULN109clawdbot : command injection and 1-Click RCE vulnerabilities fixedSystems running clawdbot (npm) versions prior to 2026.1.29.
3 Feb 2026VULN108kubernetes : Multiple issues in ingress-nginxSystems running ingress-nginx versions prior to 1.13.7, 1.14.3.
2 Feb 2026VULN107Grafana : Unauthenticated DoS and Cross-dashboard privilege escalationSystems running Grafana versions prior to 12.3.1+security-01, 12.2.3+security-01, 12.1.5+security-01, 12.0.8+security-01, 11.6.9+security-01.
2 Feb 2026VULN106geopandas : geopandas SQL Injection Vulnerability in to_postgis() Allows Information DisclosureSystems running geopandas (pip) versions prior to 1.1.2.
2 Feb 2026VULN105PsySH : Local Privilege Escalation via CWD .psysh.php auto-loadSystems running PsySH versions prior to 0.12.19, 0.11.23.
2 Feb 2026VULN104Rancher : Rancher CLI skips TLS verification on Rancher CLI login commandSystems running Rancher versions prior to 2.13.2, 2.12.6, 2.11.10, 2.10.11.
2 Feb 2026VULN103Apache : Apache Syncope Console XXE and Reflected XSS vulnerabilitiesSystems running Apache Syncope versions prior to 3.0.16, 4.0.4.
2 Feb 2026VULN102Notepad++ : Notepad++ Hijacked by State-Sponsored HackersSystems running Notepad++ versions prior to 8.9.2.
2 Feb 2026VULN101CISA : Critical Vulnerability in KiloView Encoder SeriesSystems running KiloView Encoder Series.
30 Jan 2026VULN100Withsecure : Multiple security vulnerabilities fixed in Withsecure productsSystems running Withsecure products.
30 Jan 2026VULN099Ivanti : Security Advisory Ivanti Endpoint Manager Mobile (EPMM) (CVE-2026-1281 & CVE-2026-1340)Systems running Ivanti Endpoint Manager Mobile versions prior to RPM 12.x.0.x, RPM 12.x.1.x.
30 Jan 2026VULN098Qnap : Vulnerability in legacy QTS with NFS service enabledSystems running qnap QTS versions prior to 5.2.x.
29 Jan 2026VULN097HPE Aruba Networking : HPE Aruba Networking Fabric Composer Multiple VulnerabilitiesSystems running HPE Aruba Networking Fabric Composer versions prior to 7.3.0.
29 Jan 2026VULN096Tenable : Tenable Network Monitor Version 6.5.3 Fixes Multiple VulnerabilitiesSystems running Nessus Network Monitor versions prior to 6.5.3.
29 Jan 2026VULN095Google : Chrome 144.0.7559.109/.110 fixes high-severity security vulnerabilitySystems running Google Chrome versions prior to 144.0.7559.109/.110.
29 Jan 2026VULN094SolarWinds : Multiple security vulnerabilities fixed in SolarWinds Web Help DeskSystems running SolarWinds Web Help Desk versions prior to 2026.1.
29 Jan 2026VULN093AutoGPT : RCE via Disabled Block ExecutionSystems running AutoGPT Platform versions prio to autogpt-platform-beta-v0.6.44.
28 Jan 2026VULN092Fortinet : Administrative FortiCloud SSO authentication bypassSystems running FortiOS versions prior to 7.6.6, 7.4.11, 7.2.13, 7.0.19, FortiManager versions prior to 7.6.6, 7.4.10, 7.2.13, 7.0.16, FortiAnalyzer versions prior to 7.6.6, 7.4.10, 7.2.12, 7.0.16, FortiProxy versions prior to 7.6.6, 7.4.13, FortiWeb versions prior to 8.0.4, 7.6.7, 7.4.12.
28 Jan 2026VULN091Vllm : Server-Side Request Forgery (SSRF) in `MediaConnector`Systems running vllm (pip) versions prior to 0.14.1.
28 Jan 2026VULN090Symfony : Incorrect argument escaping under MSYS2/Git Bash on Windows can lead to destructive file operationsSystems running symfony/process (Composer), symfony/symfony (Composer) versions prior to 5.4.51, 6.4.33, 7.3.11, 7.4.5, 8.0.5.
28 Jan 2026VULN089Suricata : Multiple Vulnerabilities fixed in suricataSystems running Suricata versions prior to 7.0.14, 8.0.3.
28 Jan 2026VULN088node-tar : Multiple vulnerabilities fixed in node-tarSystems running node-tar (npm) versions prior to 7.5.7.
28 Jan 2026VULN087Citrix : XenServer Security Update for CVE-2025-58151 and CVE-2026-23553Systems running XenServer versions 8.4.
28 Jan 2026VULN086GnuPG : GnuPG and Gpg4win Security Advisory (T8044)Systems running GnuPG versions prior to 2.5.17.
28 Jan 2026VULN085OpenSSL : OpenSSL Security Advisory [27th January 2026]Systems running OpenSSL versions prior to 3.6.1, 3.5.5, 3.4.4, 3.3.6, 3.0.19, 1.1.1ze, 1.0.2zn.
28 Jan 2026VULN084Kyverno : Kyverno Cross-Namespace Privilege Escalation and Denial of Service VulnerabilitiesSystems running kyverno (Go) versions prior to 1.16.3, 1.15.3.
28 Jan 2026VULN083vm2 : Sandbox EscapeSystems running vm2 versions prior to 3.10.2.
27 Jan 2026VULN082Microsoft : =?UTF-8?Q?Vuln=C3=A9rabilit=C3=A9?= de contournement de la =?UTF-8?Q?fonctionnalit=C3=A9?= de =?UTF-8?Q?s?= =?UTF-8?Q?=C3=A9curit=C3=A9?= dans Microsoft OfficeSystems running Microsoft Office 2016, Microsoft Office LTSC 2024, Microsoft Office LTSC 2021, Microsoft 365 Apps for Enterprise, Microsoft Office 2019.
27 Jan 2026VULN081React : Denial of Service Vulnerabilities in React Server ComponentsSystems running react-server-dom-parcel (npm), react-server-dom-turbopack (npm), react-server-dom-webpack (npm) versions prior to 19.0.4, 19.1.5, 19.2.4.
27 Jan 2026VULN080next.js : Denial of Service Vulnerabilities fixed in next.jsSystems running next(npm) versions prior to 15.0.8, 15.1.12, 15.2.9, 15.3.9, 15.4.11, 15.5.10, 15.6.0-canary.61, 16.0.11, 16.1.5.
27 Jan 2026VULN079pytorch : Loading a malicious PyTorch checkpoint with weights_only=True can result in arbitrary code executionSystems running PyTorch versions prior to 2.10.0.
27 Jan 2026VULN078Xen : Multiple vulnerabilities fixed in XenSystems running Xen.
26 Jan 2026VULN077CPython : email BytesGenerator header injection due to unquoted newlinesSystems running CPython.
26 Jan 2026VULN076protobuf : A potential Denial of Service issue in protobuf-pythonSystems running protobuf (pip) versions prior to 4.25.8, 5.29.5, 6.31.1.
26 Jan 2026VULN075Apache : Apache Continuum Command injection leading to RCESystems running Apache Continuum.
26 Jan 2026VULN074Apache : Apache Karaf Decanter log-socket collector has deserialization vulnerabilitySystems running Apache Karaf versions prior to 2.12.0.
26 Jan 2026VULN073Apache : HDFS native client Out of bounds write in URI parser of native HDFS clientSystems running Apache Hadoop HDFS native client versions prior to 3.4.2.
23 Jan 2026VULN072Broadcom : Web Security Services Agent Security UpdateSystems running Cloud Secure Web Gateway versions prior to 9.8.5.
23 Jan 2026VULN071Python : CVE-2025-12781 base64.b64decode() always accepts \"+/\" characters, despite setting altcharsSystems running CPython.
23 Jan 2026VULN070Symantec : Symantec Endpoint Protection Security UpdateSystems running Symantec Endpoint Protection versions prior to 14.3 RU10 (14.3.12167.10000), 14.3 RU9 (14.3.11237.9000), 14.3 RU8 (14.3.10178.8000).
23 Jan 2026VULN069Apache : Vulnerabilities fixed in Apache SolrSystems running Apache Solr versions prior to 9.10.1.
23 Jan 2026VULN068TYPO3 : Insecure Deserialization in extension \"Mailqueue\" (mailqueue)Systems running TYPO3 extension manager versions prior to 0.5.1, 0.4.3.
23 Jan 2026VULN067surrealdb : Confused Deputy Privilege Escalation through Future Fields and FunctionsSystems running surrealdb (Rust) versions prior to 2.5.0, 3.0.0-beta.3.
23 Jan 2026VULN066GNU InetUtils : GNU InetUtils Security Advisory remote authentication by-pass in telnetdSystems running GNU InetUtils telnetd.
23 Jan 2026VULN065incus : Arbitrary command execution vulnerabilities fixed in incusSystems running incusd (Go) versions prior to 6.21.0, 6.0.6.
22 Jan 2026VULN064vllm : RCE via auto_map dynamic module loading during model initializationSystems running vllm versions prior to 0.14.0.
22 Jan 2026VULN063Argo Workflows : Stored XSS in the artifact directory listingSystems running argo-workflows (Go) versions prior to 3.6.17, 3.7.8.
22 Jan 2026VULN062GLIBC : DoS and stack contents leak vulnerabilitiesSystems running GNU C Library versions 2.30 up to and including 2.42.
22 Jan 2026VULN061Ceph : Incorrect usage of certificate checking via Pybind useSystems running pybind (ceph) versions prior to 20.2.1, 19.2.4, 18.2.9.
21 Jan 2026VULN060CPython : CPython Multiple vulnerabilitiesSystems running CPython.
21 Jan 2026VULN059Bind : CVE-2025-13878 Malformed BRID/HHIT records can cause named to terminate unexpectedlySystems running BIND versions prior to 9.18.44, 9.20.18, 9.21.17.
21 Jan 2026VULN058Oracle : January 2026 Critical Patch Update ReleasedSystems running Oracle products.
21 Jan 2026VULN057GitLab : GitLab Patch Release 18.8.2, 18.7.2, 18.6.4Systems running GitLab versions prior to 18.8.2, 18.7.2, 18.6.4.
21 Jan 2026VULN056Cisco : Cisco Security Advisories Published on January 21, 2026Cisco Unified Communications Products, Cisco Intersight Virtual Appliance, Cisco IEC6400 Wireless Backhaul Edge Compute Software, Cisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise.
20 Jan 2026VULN055urllib3 : Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)Systems running urllib3 versions prior to 2.6.3.
20 Jan 2026VULN054Wireshark : Wireshark file parser and dissector crashesSystems running Wireshark versions prior to 4.6.3, 4.4.13.
20 Jan 2026VULN053Traefik : ACME TLS-ALPN fast path lacks timeouts and close on handshake stallSystems running traefik versions prior to 2.11.35, 3.6.7.
19 Jan 2026VULN052Svelte : XSS with textarea bind:valueSystems running svelte (npm) versions prior to 3.59.2.
19 Jan 2026VULN051Mattermost : Multiple security vulnerabilities fixed in MattermostSystems running Mattermost.
19 Jan 2026VULN050Deno : fix for `node:crypto` vulnerability and Incomplete fix for command-injection prevention on WindowsSystems running Deno versions prior to 2.6.0.
19 Jan 2026VULN049GLIBC : Integer overflow in memalign leads to heap corruptionSystems running GNU C Library versions 2.30 up to and including 2.42.
16 Jan 2026VULN048Centreon : CVE-2025-43865, CVE-2025-43864 - Centreon 25.10 IT & Business EditionsSystems running Centreon 25.10 IT & Business Editions.
16 Jan 2026VULN047GLPI : Unauthorized access to documents and Unauthenticated SQL injection fixedSystems running glpi versions prior to 10.0.21, 11.0.3.
16 Jan 2026VULN046Pimcore : Multiple vulnerabilities fixed in PimcoreSystems running pimcore (Composer) versions prior to 12.3.1 11.5.14.
16 Jan 2026VULN045Go : Go 1.25.6 and Go 1.24.12 include 6 security fixesSystems running Go versions prior to 1.25.6, 1.24.12.
16 Jan 2026VULN044Apache : Apache Airflow sensitive data exposure vulnerabilities fixedSystems running Apache Airflow versions prior to 3.1.6.
16 Jan 2026VULN043Apache : CVE-2025-60021 Apache bRPC Remote command injection vulnerability in heap builtin serviceSystems running Apache bRPC versions prior to 1.15.0.
15 Jan 2026VULN042Adobe : =?UTF-8?Q?Se?= =?UTF-8?Q?curity=E2=80=AFupdate_available=E2=80=AFfor?= Adobe Dreamweaver APSB26-01Systems running Adobe Dreamweaver versions prior to 21.7.
15 Jan 2026VULN041Cisco : Cisco Security Advisories Published on January 15, 2026Systems running Cisco Secure Email Gateway And Cisco Secure Email and Web Manager, Cisco Identity Services Engine, Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure.
15 Jan 2026VULN040Adobe : Security Updates Available for Adobe Illustrator APSB26-03Systems running Adobe Illustrator versions prior to 2025 29.8.4, 2026 30.1.
15 Jan 2026VULN039Adobe : Security updates available for Adobe ColdFusion APSB26-12Systems running Adobe ColdFusion versions prior to 2025 Update 6, 2023 Update 18.
15 Jan 2026VULN038Mozilla : Security Vulnerabilities fixed in Thunderbird 147, 140.7Systems running Thunderbird versions prior to 147, 140.7.
15 Jan 2026VULN037Mozilla : Security Vulnerabilities fixed in Firefox 147, ESR 115.32, ESR 140.7Systems running Firefox versions prior to 147, ESR 115.32, ESR 140.7.
15 Jan 2026VULN036Google: Chrome 144.0.7559.59/60 fixes high-severity security vulnerabilitySystems running Google Chrome versions prior to 144.0.7559.59/60.
14 Jan 2026VULN035Misp : Stored/Reflected XSS via Unsanitized Parameters in URL Generation and JavaScript ContextSystems running misp versions prior to 2.5.31.
14 Jan 2026VULN034Spring : CVE-2026-22718 Command injection on user machine using VSCode extension for Spring CLISystems running Spring CLI VSCode Extension.
14 Jan 2026VULN033Fortinet : Heap-based buffer overflow in cw_acd daemonSystems running FortiOS versions prior to 7.6.4, 7.4.9, 7.2.12, 7.0.18, 6.4.17, FortiSASE versions prior to 25.2.c, FortiSwitchManager versions prior to 7.2.7, 7.0.6.
14 Jan 2026VULN032Fortinet : Unauthenticated remote command injection in FortiSIEMSystems running FortiSIEM versions prior to 7.4.1, 7.3.5, 7.2.7, 7.1.9.
14 Jan 2026VULN031Fortinet : Unauthenticated access to local configurationSystems running FortiFone versions prior to 7.0.2, 3.0.24.
14 Jan 2026VULN030TYPO3 : Broken Access Control and Insecure Deserialization Vulnerabilities fixed in TYPO3Systems running TYPO3 CMS versions prior to 10.4.55 ELTS, 11.5.49 ELTS, 12.4.41 LTS, 13.4.23 LTS, 14.0.2.
14 Jan 2026VULN029AdonisJS : Mass Assignment in AdonisJS Lucid Allows Overwriting Internal ORMSystems running @adonisjs/lucid versions prior to 21.8.2, 22.0.0-next.6.
14 Jan 2026VULN028opencode : Malicious website can execute commands on the local system through XSS in the OpenCode web UISystems running opencode versions prior to 1.1.10.
14 Jan 2026VULN027Apache : Apache Camel security advisory CVE-2025-66169Systems running Apache Camel versions prior to 4.10.8, 4.14.3, 4.17.0.
14 Jan 2026VULN026Node.js : Tuesday, January 13, 2026 Security ReleasesSystems running Node.js versions prior to 20.20.0, 22.22.0, 24.13.0, 25.3.0.
13 Jan 2026VULN025VMware : Vulnerabilities fixed in VMware Tanzu GemFire 10.1.6 and 10.2.1Systems running VMware Tanzu Data Intelligence, VMware Tanzu Data Services Pack, VMware Tanzu Data Suite, VMware Tanzu Gemfire.
13 Jan 2026VULN024SAP : SAP Security Patch Day - January 2026Systems running SAP products.
13 Jan 2026VULN023react-router : Multiple vulnerabilities fixed in react-router ecosystemSystems running @react-router/node (npm) versions prior to 7.9.4, react-router (npm) versions prior to 7.12.0, @remix-run/react (npm) versions prior to 2.17.1, @remix-run/router (npm) versions prior to 1.23.2, @remix-run/deno (npm), @remix-run/node (npm), @remix-run/server-runtime (npm) versions prior to 2.17.3.
13 Jan 2026VULN022Libpng : Heap buffer over-read vulnerabilities fixed in libpngSystems running Libpng versions prior to 1.6.54.
12 Jan 2026VULN021Angular : XSS Vulnerability via Unsanitized SVG Script AttributesSystems running @angular/compiler (npm), @angular/core (npm) versions prior to 21.1.0-rc.0, 21.0.7, 20.3.16, 19.2.18.
12 Jan 2026VULN020Apache : CVE-2025-68493 Apache Struts XXE vulnerability in outdated XWork componentSystems running Apache Struts versions prior to 25.10.2, 24.10.3, 24.04.3.
12 Jan 2026VULN019Centreon : Centreon Open Tickets - Vulnerabilities, one High Severity Systems running Centreon Open Tickets versions prior to 25.10.0, 24.10.5, 24.04.5, 23.10.4.
12 Jan 2026VULN018Joomla! : Core - XSS vectors in Joomla! CMSSystems running Joomla! CMS versions prior to 5.4.2, 6.0.2.
9 Jan 2026VULN017Centreon : Centreon AWIE - Critical Severity VulnerabilitiesSystems running Centreon AWIE versions prior to 25.10.2, 24.10.3, 24.04.3.
9 Jan 2026VULN016Apache : Multiple Vulnerabilities fixed in Apache NimBLE 1.9.0Systems Apache NimBLE versions prior to 1.9.0.
9 Jan 2026VULN015Tenable : Nessus Agent Versions 11.0.3 and 10.9.3 Fix One VulnerabilitySystems running Nessus Agent versions prior to 11.0.3, 10.9.3.
9 Jan 2026VULN014Trend Micro : Trend Micro Apex Central (on-premise) January 2026 Multiple VulnerabilitiesSystems Apex Central (on-premise) versions prior to Critical Patch Build 7190.
9 Jan 2026VULN013Cisco : Cisco Security Advisories Published on January 07, 2026Systems running Cisco Products running Snort, Cisco Identity Services Engine.
9 Jan 2026VULN012RustFS : Multiple Vulnerabilities Resolved in RustFS, one CriticalSystems running RustFS versions prior to alpha.79.
8 Jan 2026VULN011Veeam : Vulnerabilities Resolved in Veeam Backup & Replication, one CriticalSystems running Veeam Backup & Replication versions prior to 13.0.1.1071.
8 Jan 2026VULN010Vega : Vega Cross-Site Scripting (XSS) vulnerabilitiesSystems running vega-selections (npm) versions prior to 6.1.2, 5.6.3, vega-functions (npm) versions prior to 6.1.1.
8 Jan 2026VULN009Google : Chrome 143.0.7499.192/.193 fixes high-severity security vulnerabilitySystems running Google Chrome versions prior to 143.0.7499.192/.193.
8 Jan 2026VULN008GitLab : GitLab Patch Release 18.7.1, 18.6.3, 18.5.5Systems running GitLab versions prior to 18.7.1, 18.6.3, 18.5.5.
7 Jan 2026VULN007Opencti : GraphQL IDOR allows authenticated user to delete workspace content of other usersSystems running OpenCTI versions prior to 6.8.1.
7 Jan 2026VULN006Apache : CVE-2025-68280 Apache SIS XML External Entity (XXE) vulnerabilitySystems running Apache SIS versions prior to 1.6.
7 Jan 2026VULN005AIOHTTP : Multiple Security Vulnerabilities fixed in AIOHTTPSystems running AIOHTTP versions prior to 3.13.3.
7 Jan 2026VULN004curl : Multiple vulnerabilities fixed in curl 8.18.0Systems running curl versions prior to 8.18.0.
7 Jan 2026VULN003GNU Wget : Critical file overwrite issue with metalink in GNU Wget2 CVE-2025-69194Systems running GNU Wget2 versions prior to 2.2.1.
7 Jan 2026VULN002Langflow : Missing Authentication on Critical API EndpointsSystems running Langflow versions prior to 1.7.1.
7 Jan 2026VULN001n8n : Critical RCE via Arbitrary File WriteSystems running n8n versions prior to 1.121.3.