Technology intelligence

Clearer
signals.
Brighter
decisions.

NEXUS TECH WIRE

Technology.
Ideas.
People.
A more connected
tomorrow.

Vulnerabilities intelligence

Publisher updates

A useful brief, clear publisher credit, and a direct link to every full article.

Conceptual illustration of a repaired computing layer with an illuminated seam and connected circuitry.
AI-generated illustration Conceptual artwork
Vulnerabilities

Multiples vulnérabilités dans Zabbix Agent (24 septembre 2026)

The brief

CERT-FR has flagged multiple security issues affecting Zabbix Agent2 releases earlier than 7.0.31. Its September 24 notice references the vendor's ZBX-28059 bulletin for fixes but does not describe the vulnerabilities' impact. The affected-product scope is specifically Agent2; the advisory does not identify a separate Zabbix Server version range.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Source material adapted into an original NexusTechWire brief. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities

Multiples vulnérabilités dans Wireshark (24 septembre 2026)

The brief

CERT-FR identifies remote code execution and denial of service risks in Wireshark's 4.4 and 4.6 release branches. Its September 24 advisory lists versions before 4.4.19 and 4.6.9 respectively as affected. It links the corresponding Wireshark security bulletins and CVE records so operators can match their installed branch with the vendor's corrections.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Source material adapted into an original NexusTechWire brief. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities

Multiples vulnérabilités dans Papercut (24 septembre 2026)

From the publisher

De multiples vulnérabilités ont été découvertes dans Papercut. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une atteinte à la confidentialité des données et une injection de code indirecte à distance (XSS).

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities

Multiples vulnérabilités dans SolarWinds Observability Self-Hosted (23 septembre 2026)

The brief

CERT-FR warns of remote code execution vulnerabilities in SolarWinds Observability Self-Hosted releases before 2026.2.3. The September 23 notice names CVE-2026-28324 and CVE-2026-28325 and links separate SolarWinds advisories for the two flaws. It directs administrators to those vendor bulletins for corrections; its affected-version statement applies specifically to the self-hosted product.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Source material adapted into an original NexusTechWire brief. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities

Multiples vulnérabilités dans les produits HPE Aruba Networking (23 septembre 2026)

From the publisher

De multiples vulnérabilités ont été découvertes dans les produits HPE Aruba Networking. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities

Multiples vulnérabilités dans Apache Tomcat (23 septembre 2026)

From the publisher

De multiples vulnérabilités ont été découvertes dans Apache Tomcat. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à l'intégrité des données et un contournement de la politique de sécurité.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities
Conceptual illustration of a repaired computing layer with an illuminated seam and connected circuitry.
AI-generated illustration Conceptual artwork

Multiples vulnérabilités dans Mattermost Server (23 septembre 2026)

The brief

CERT-FR has grouped several Mattermost Server flaws that can disrupt service remotely or expose confidential data. The affected branches are 11.7 before 11.7.11, 11.8 before 11.8.6, 11.9 before 11.9.2 and 11.10 before 11.10.2. Its September 23 advisory links Mattermost's security-update notices for the corresponding fixes and identifies three associated CVEs.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Source material adapted into an original NexusTechWire brief. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities

Vulnérabilité dans WordPress (23 septembre 2026)

The brief

CERT-FR reports that WordPress versions earlier than 7.1.2 are affected by CVE-2026-87902, a vulnerability it describes as permitting remote code execution. The September 23 notice points to WordPress's 7.1.2 release announcement and the project's GitHub security advisory for correction details. Its affected-version statement concerns WordPress itself, without naming a separate plugin or theme.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Source material adapted into an original NexusTechWire brief. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities

Vulnérabilité dans Check Point Security Management Server (23 septembre 2026)

From the publisher

Une vulnérabilité a été découverte dans Check Point Security Management Server. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance et une atteinte à l'intégrité des données. L'éditeur indique que la vulnérabilité CVE-2026-93616 est activement exploitée.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities

Multiples vulnérabilités dans Google Chrome (23 septembre 2026)

The brief

CERT-FR's September 23 Chrome notice lists Windows and Linux builds before 154.0.8037.57 and macOS builds before 154.0.8037.58 as affected by multiple vulnerabilities. It links Google's September 22 stable-channel update and the associated CVE records. The notice leaves the security impact unspecified and refers readers to Google's bulletin for the relevant fixes.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Source material adapted into an original NexusTechWire brief. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities

Vulnérabilité dans F5 BIG-IP (23 septembre 2026)

From the publisher

Une vulnérabilité a été découverte dans F5 BIG-IP. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance. L'éditeur indique que la vulnérabilité CVE-2026-94127 est activement exploitée. Des indicateurs de compromission sont disponibles dans l'avis de l'éditeur.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities

Multiples vulnérabilités dans les produits FoxIT (23 septembre 2026)

From the publisher

De multiples vulnérabilités ont été découvertes dans les produits FoxIT. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, une élévation de privilèges et une atteinte à la confidentialité des données.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities
Conceptual illustration of a repaired computing layer with an illuminated seam and connected circuitry.
AI-generated illustration Conceptual artwork

2026-013: Critical Vulnerability in F5 BIG-IP APM

From the publisher

On 22 September 2026, F5 published an advisory addressing a critical vulnerability affecting its BIG-IP APM product. The vendor confirmed active exploitation in the wild. CERT-EU recommends taking appropriate actions as soon as possible.

Source CERT-EUCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

Vulnérabilité dans SolarWinds Access Rights Manager (22 septembre 2026)

The brief

CERT-FR identifies a remote code execution flaw in SolarWinds Access Rights Manager releases before 2026.2.1. The issue is tracked as CVE-2026-28326 and is covered by a SolarWinds security advisory dated September 17. The French agency's September 22 notice directs administrators to that vendor guidance for the required correction details.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Source material adapted into an original NexusTechWire brief. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities

Multiples vulnérabilités dans Moodle (22 septembre 2026)

The brief

CERT-FR warns of SQL injection and security-policy bypass vulnerabilities in Moodle. Its September 22 advisory covers releases earlier than 4.5.14, plus the 5.0, 5.1 and 5.2 branches before 5.0.10, 5.1.7 and 5.2.3 respectively. It links two Moodle security notices published that day and directs site administrators to them for the corresponding fixes.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Source material adapted into an original NexusTechWire brief. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities

Multiples vulnérabilités dans Synology DSM (21 septembre 2026)

From the publisher

De multiples vulnérabilités ont été découvertes dans Synology DSM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities

2026-012: Critical Vulnerabilities in Check Point Products

From the publisher

On 9 September 2026, Check Point released emergency security updates addressing two critical vulnerabilities affecting Check Point Security Gateway, Security Management Server, and Spark Firewall deployments configured to use Remote Access VPN or Site-to-Site VPN. Both vulnerabilities carry a CVSS score of 9.8 and could allow an unauthenticated, remote attacker to execute arbitrary code on affected appliances. CERT-EU strongly recommends applying the available hotfixes as soon as possible, prioritising internet-facing and perimeter appliances.

Source CERT-EUCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

Vulnérabilité dans Metabase (10 septembre 2026)

From the publisher

Le 06 août 2026, Metabase a publié un avis de sécurité concernant une vulnérabilité critique permettant à un attaquant non authentifié de provoquer une injection SQL (SQLi) dans la base de donnée de l'application Metabase.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities
Conceptual illustration of a repaired computing layer with an illuminated seam and connected circuitry.
AI-generated illustration Conceptual artwork

2026-011: Critical Vulnerabilities in SAP Kernel and NetWeaver Message Server

From the publisher

On 8 September 2026, as part of its September Security Patch Day, SAP released Security Notes addressing two critical vulnerabilities affecting a broad range of SAP products[3]. The most severe, CVE-2026-44756 (CVSS 10.0), is a memory corruption vulnerability in SAP Extended Passport (EPP) processing, nicknamed "OVERPASS" by the Onapsis Research Labs (ORL), which discovered and responsibly disclosed it[3]. The second, CVE-2026-58240 (CVSS 9.8), nicknamed "S4GET", is a missing authentication check in the SAP NetWeaver Message Server[6]. Both are remotely exploitable without authentication. According to the reporting researchers, successful exploitation of either can result in arbitrary operating system command execution under the account that owns the SAP installation, leading to full compromise of the affected system and the business data it holds[6].

Source CERT-EUCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

Multiples vulnérabilités dans SonicWall Secure Mobile Access (02 septembre 2026)

From the publisher

Le 01 septembre 2026, SonicWall a publié un avis de sécurité concernant deux vulnérabilités affectant les Secure Mobile Access (SMA) 1000. La vulnérabilité critique CVE-2026-83548 permet une falsification de requêtes côté serveur (SSRF) de la part d'un attaquant non authentifié.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Vulnerabilities

2026-010: Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway

From the publisher

On 19 August 2026, Citrix published a security advisory addressing multiple critical vulnerabilities in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway). CERT-EU recommends updating affected devices as soon as possible.

Source CERT-EUCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

CVE-2026-19444

The brief

Kubernetes has disclosed CVE-2026-19444, a medium-severity vulnerability in kubectl's Windows file-copy function. Copying data from a container an operator does not control can allow unauthorized writes on their computer within their existing permissions. The advisory lists fixes in releases 1.34.12, 1.35.9 and 1.36.5, and recommends avoiding copies from untrusted containers before upgrading. Only Windows clients are affected.

Source KubernetesCC BY 4.0 · Source material adapted into an original NexusTechWire brief. Original source license applies.

Read full article
Vulnerabilities

2026-009: Critical Vulnerabilities in Microsoft SharePoint

From the publisher

[UPDATED] On 14 July 2026, Microsoft released security updates addressing critical remote code execution (RCE) vulnerabilities in Microsoft SharePoint Server. On 20 July 2026, WatchTowr identified a proof-of-concept exploit code and subsequently observed active exploitation of CVE-2026-50522, a vulnerability part of an ongoing series of actively exploited flaws affecting on-premise SharePoint Server instances, including CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644. CERT-EU strongly recommends updating affected servers immediately, rotating credentials for any assets that may have been exposed to the internet, and conducting a compromise assessment.

Source CERT-EUCC BY 4.0 · Publisher excerpt shortened and converted to plain text. Original source license applies.

Read full article
Vulnerabilities

Multiples vulnérabilités dans Sonicwall Secure Mobile Access (15 juillet 2026)

From the publisher

Le 14 juillet 2026, Sonicwall a publié un avis de sécurité concernant deux vulnérabilités affectant les Secure Mobile Access (SMA) 1000. La vulnérabilité critique CVE-2026-15409 permet une falsification de requêtes côté serveur (SSRF) de la part d'un attaquant non authentifié.

Source CERT-FR / ANSSIEtalab Open Licence v2.0 · Publisher excerpt shortened and converted to plain text. Original source license applies. See the attributed original source for its latest revision date. Reuse does not imply publisher endorsement.

Read full article
Latest collection

Original briefs are AI-assisted and checked against the linked source. Publisher excerpts are labeled separately; each story keeps its original date and article link.