ENISA EUVD · EUVD-2026-17610Official EUVD mappingImpact:
The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink.
When an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time.
Additionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function().
Patches:
Users should upgrade to version 4.18.0.
Workarounds:
Do not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.
Official EUVD record ↗BSI · German · WID-SEC-2026-3376Atlassian Bamboo, Bitbucket, Confluence, Fisheye/Crucible, Jira Software und Jira Service Management: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Bitbucket, Confluence, Fisheye/Crucible, Jira Software und Jira Service Management ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, serverseitige Request-Forgery-Angriffe (SSRF) durchzuführen, Cross-Site-Scripting-Angriffe zu starten, sensible Informationen offenzulegen, Daten zu manipulieren oder Denial-of-Service-Zustände herbeizuführen.
Official advisory ↗BSI · German · WID-SEC-2026-3046IBM Concert: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in IBM Concert ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen, um einen SQL-Injection Angriff durchzuführen und um Sicherheitsvorkehrungen zu umgehen.
Official advisory ↗BSI · German · WID-SEC-2026-2933Splunk SOAR: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Splunk SOAR ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen SQL-Injection Angriff durchzuführen, um einen Cross-Site Scripting Angriff durchzuführen, und um beliebigen Programmcode auszuführen.
Official advisory ↗BSI · German · WID-SEC-2026-2887Oracle Communications: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Communications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2026-2923Atlassian Produkte (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, und Jira): Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Atlassian Bitbucket, Atlassian Confluence, Atlassian Crucible, Atlassian Fisheye und Atlassian Jira ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen, um einen SQL-Injection Angriff durchzuführen, und um Sicherheitsvorkehrungen zu umgehen.
Official advisory ↗BSI · German · WID-SEC-2026-2437Oracle Communications: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Communications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2026-2448Oracle Utilities Applications: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Utilities Applications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2026-2445Oracle Financial Services Applications: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Financial Services Applications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2026-2436Oracle Construction and Engineering: Mehrere SchwachstellenEin entfernter, anonymer Angreifer kann mehrere Schwachstellen in Oracle Construction and Engineering ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2026-2460Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management ausnutzen, um beliebigen Code auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand auszulösen.
Official advisory ↗BSI · German · WID-SEC-2026-2260IBM Operational Decision Manager: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in IBM Operational Decision Manager ausnutzen, um beliebigen Programmcode auszuführen, um seine Privilegien zu erhöhen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, und um Sicherheitsvorkehrungen zu umgehen.
Official advisory ↗BSI · German · WID-SEC-2026-1654IBM App Connect Enterprise: Mehrere SchwachstellenEin entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um beliebigen Programmcode auszuführen, Daten zu manipulieren, Cross-Site-Scripting-Angriffe durchzuführen, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand auszulösen.
Official advisory ↗BSI · German · WID-SEC-2026-1160Red Hat Enterprise Linux und Satellite (satellite/iop-remediations-rhel9 container image): Mehrere SchwachstellenEin entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux und Red Hat Satellite ausnutzen, um Informationen offenzulegen oder beliebigen Code auszuführen.
Official advisory ↗Cyber Security Agency of Singapore · English · CSA-SB-20260401Security Bulletin 01 Apr 2026The Cyber Security Agency of Singapore included this CVE in its official Security Bulletin 01 Apr 2026, published on 1 April 2026. Open the linked bulletin for the product, severity and reference information published in that issue.
Official advisory ↗INCIBE-CERT · Spanish · boletin-de-seguridad-de-atlassian-septiembre-de-2026Boletín de seguridad de Atlassian: septiembre de 2026an:
CVE-2026-54512 : DoS (Denial of Service) en tools.jackson.core:jackson-databind.
CVE-2026-54513 : RCE (Remote Code Execution) en jackson-databind.
CVE-2026-45623 : Divulgación de información en postcss.
CVE-2026-73507 : DoS (Denial of Service) en io.netty:netty-codec.
CVE-2026-68763 : DoS (Denial of Service) en org.apache.tomcat:tomcat-coyote.
CVE-2026-73646 : File Inclusion en postcss.
CVE-2026-53404 : BASM (Broken Authentication & Session Management) en Apache Tomcat.
CVE-2026-55153 : DoS (Denial of Service) en com.mchange:mchange-commons-java.
CVE-2026-21582 : BASM (Broken Authentication & Session Management) en Bitbucket Data Center.
CVE-2026-4800 : RCE (Remote Code Execution) en lodash.
CVE-2026-44249 : Improper Authorization en io.netty:netty-handler.
CVE-2026-76172 : SSRF (Server-Side Request Forgery) en fast-uri.
CVE-2026-75975 : SSRF (Server-Side Request Forgery) en fast-uri.
CVE-2026-75899 : SSRF (Server-Side Request Forgery) en fast-uri.
CVE-2026-50010 : BASM (Broken Authentication & Session Management) en Netty.
CVE-2026-45416 : DoS (Denial of Service) en io.netty:netty-handler.
CVE-2026-42583 : DoS (Denial of Service) en io.netty:netty-codec.
CVE-2026-73086 : CSRF (Cross-Site Request Forgery) en nanoid.
CVE
Identificador CVE
Severidad
Explotación
Fabricante
CVE-2026-75595
Crí
Official advisory ↗INCIBE-CERT · Spanish · boletin-de-seguridad-de-atlassian-agosto-de-2026Boletín de seguridad de Atlassian: agosto de 2026rta.
CVE-2026-67320: Divulgación de información en axios.
CVE-2026-54291: MITM (Man-in-the-Middle) en org.postgresql:postgresql.
CVE-2026-41907: RCE (Remote Code Execution) en uuid.
CVE-2026-41851: DoS (Denial of Service) en org.springframework:spring-expression.
CVE-2026-55831: DoS (Denial of Service) en io.netty:netty-codec-http.
CVE-2026-41850: DoS (Denial of Service) en org.springframework:spring-expression.
CVE
Identificador CVE
Severidad
Explotación
Fabricante
CVE-2021-44906
Crítica
No
ATLASSIAN
CVE-2025-14813
Crítica
No
ATLASSIAN
CVE-2026-59873
Crítica
No
ATLASSIAN
CVE-2026-53434
Crítica
No
ATLASSIAN
CVE-2026-2332
Crítica
No
ATLASSIAN
CVE-2026-4800
Crítica
No
ATLASSIAN
CVE-2023-45133
Crítica
No
ATLASSIAN
CVE-2026-59873
Crítica
No
ATLASSIAN
CVE-2026-4800
Crítica
No
ATLASSIAN
CVE-2026-59873
Crítica
No
ATLASSIAN
Listado de referencias
Security Bulletin - August 18 2026
Etiquetas
Actualización
Aviso
Criptografía
Denegación de servicio - DoS - DDoS
+
Inyección
RCE
Vulnerabilidad
-
Suscripción boletines
Nipo : 094-20-022-9
Síguenos en:
Contacto
Valora nuestros servicios
Empleo
Política de Privacidad
Aviso Legal
Accesibilidad
Configuración de cookies
Política de cookies
Mapa web
Transparencia
Perfil de contratante
Canal de denuncias
Nipo : 094-20-027-6
×
Ir arriba
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-1256Multiples vulnérabilités dans les produits IBMd?id=CVE-2026-44631
Référence CVE CVE-2026-44690
https://www.cve.org/CVERecord?id=CVE-2026-44690
Référence CVE CVE-2026-44990
https://www.cve.org/CVERecord?id=CVE-2026-44990
Référence CVE CVE-2026-45623
https://www.cve.org/CVERecord?id=CVE-2026-45623
Référence CVE CVE-2026-45819
https://www.cve.org/CVERecord?id=CVE-2026-45819
Référence CVE CVE-2026-45822
https://www.cve.org/CVERecord?id=CVE-2026-45822
Référence CVE CVE-2026-45970
https://www.cve.org/CVERecord?id=CVE-2026-45970
Référence CVE CVE-2026-45991
https://www.cve.org/CVERecord?id=CVE-2026-45991
Référence CVE CVE-2026-46120
https://www.cve.org/CVERecord?id=CVE-2026-46120
Référence CVE CVE-2026-4800
https://www.cve.org/CVERecord?id=CVE-2026-4800
Référence CVE CVE-2026-48586
https://www.cve.org/CVERecord?id=CVE-2026-48586
Référence CVE CVE-2026-4867
https://www.cve.org/CVERecord?id=CVE-2026-4867
Référence CVE CVE-2026-48801
https://www.cve.org/CVERecord?id=CVE-2026-48801
Référence CVE CVE-2026-48913
https://www.cve.org/CVERecord?id=CVE-2026-48913
Référence CVE CVE-2026-48988
https://www.cve.org/CVERecord?id=CVE-2026-48988
Référence CVE CVE-2026-49268
https://www.cve.org/CVERecord?id=CVE-2026-49268
Référence CVE CVE-2026-49356
https://www.cve.org/CVERecord?id=CVE-2026-49356
Référence CVE CVE-2026-49458
https://www.cve.org/CVERecord?id=CVE
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-1206Multiples vulnérabilités dans les produits IBMd?id=CVE-2026-47021
Référence CVE CVE-2026-47027
https://www.cve.org/CVERecord?id=CVE-2026-47027
Référence CVE CVE-2026-47057
https://www.cve.org/CVERecord?id=CVE-2026-47057
Référence CVE CVE-2026-47058
https://www.cve.org/CVERecord?id=CVE-2026-47058
Référence CVE CVE-2026-47059
https://www.cve.org/CVERecord?id=CVE-2026-47059
Référence CVE CVE-2026-47063
https://www.cve.org/CVERecord?id=CVE-2026-47063
Référence CVE CVE-2026-47065
https://www.cve.org/CVERecord?id=CVE-2026-47065
Référence CVE CVE-2026-47244
https://www.cve.org/CVERecord?id=CVE-2026-47244
Référence CVE CVE-2026-47838
https://www.cve.org/CVERecord?id=CVE-2026-47838
Référence CVE CVE-2026-4800
https://www.cve.org/CVERecord?id=CVE-2026-4800
Référence CVE CVE-2026-48006
https://www.cve.org/CVERecord?id=CVE-2026-48006
Référence CVE CVE-2026-48043
https://www.cve.org/CVERecord?id=CVE-2026-48043
Référence CVE CVE-2026-48059
https://www.cve.org/CVERecord?id=CVE-2026-48059
Référence CVE CVE-2026-48155
https://www.cve.org/CVERecord?id=CVE-2026-48155
Référence CVE CVE-2026-48156
https://www.cve.org/CVERecord?id=CVE-2026-48156
Référence CVE CVE-2026-4867
https://www.cve.org/CVERecord?id=CVE-2026-4867
Référence CVE CVE-2026-48710
https://www.cve.org/CVERecord?id=CVE-2026-48710
Référence CVE CVE-2026-48735
https://www.cve.org/CVERecord?id=CVE
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-1165Multiples vulnérabilités dans les produits IBMd?id=CVE-2026-47842
Référence CVE CVE-2026-47877
https://www.cve.org/CVERecord?id=CVE-2026-47877
Référence CVE CVE-2026-47883
https://www.cve.org/CVERecord?id=CVE-2026-47883
Référence CVE CVE-2026-47884
https://www.cve.org/CVERecord?id=CVE-2026-47884
Référence CVE CVE-2026-47885
https://www.cve.org/CVERecord?id=CVE-2026-47885
Référence CVE CVE-2026-47887
https://www.cve.org/CVERecord?id=CVE-2026-47887
Référence CVE CVE-2026-47889
https://www.cve.org/CVERecord?id=CVE-2026-47889
Référence CVE CVE-2026-47890
https://www.cve.org/CVERecord?id=CVE-2026-47890
Référence CVE CVE-2026-47891
https://www.cve.org/CVERecord?id=CVE-2026-47891
Référence CVE CVE-2026-4800
https://www.cve.org/CVERecord?id=CVE-2026-4800
Référence CVE CVE-2026-48043
https://www.cve.org/CVERecord?id=CVE-2026-48043
Référence CVE CVE-2026-48589
https://www.cve.org/CVERecord?id=CVE-2026-48589
Référence CVE CVE-2026-48978
https://www.cve.org/CVERecord?id=CVE-2026-48978
Référence CVE CVE-2026-49268
https://www.cve.org/CVERecord?id=CVE-2026-49268
Référence CVE CVE-2026-49458
https://www.cve.org/CVERecord?id=CVE-2026-49458
Référence CVE CVE-2026-49459
https://www.cve.org/CVERecord?id=CVE-2026-49459
Référence CVE CVE-2026-49844
https://www.cve.org/CVERecord?id=CVE-2026-49844
Référence CVE CVE-2026-49978
https://www.cve.org/CVERecord?id=C
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-1056Multiples vulnérabilités dans les produits Splunkd?id=CVE-2026-42284
Référence CVE CVE-2026-42766
https://www.cve.org/CVERecord?id=CVE-2026-42766
Référence CVE CVE-2026-42934
https://www.cve.org/CVERecord?id=CVE-2026-42934
Référence CVE CVE-2026-42945
https://www.cve.org/CVERecord?id=CVE-2026-42945
Référence CVE CVE-2026-42946
https://www.cve.org/CVERecord?id=CVE-2026-42946
Référence CVE CVE-2026-44243
https://www.cve.org/CVERecord?id=CVE-2026-44243
Référence CVE CVE-2026-44244
https://www.cve.org/CVERecord?id=CVE-2026-44244
Référence CVE CVE-2026-45409
https://www.cve.org/CVERecord?id=CVE-2026-45409
Référence CVE CVE-2026-45447
https://www.cve.org/CVERecord?id=CVE-2026-45447
Référence CVE CVE-2026-4800
https://www.cve.org/CVERecord?id=CVE-2026-4800
Référence CVE CVE-2026-6276
https://www.cve.org/CVERecord?id=CVE-2026-6276
Référence CVE CVE-2026-6429
https://www.cve.org/CVERecord?id=CVE-2026-6429
Référence CVE CVE-2026-6472
https://www.cve.org/CVERecord?id=CVE-2026-6472
Référence CVE CVE-2026-6473
https://www.cve.org/CVERecord?id=CVE-2026-6473
Référence CVE CVE-2026-6474
https://www.cve.org/CVERecord?id=CVE-2026-6474
Référence CVE CVE-2026-6475
https://www.cve.org/CVERecord?id=CVE-2026-6475
Référence CVE CVE-2026-6477
https://www.cve.org/CVERecord?id=CVE-2026-6477
Référence CVE CVE-2026-6478
https://www.cve.org/CVERecord?id=CVE-2026-6478
Ré
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-1032Multiples vulnérabilités dans les produits IBMd?id=CVE-2026-46968
Référence CVE CVE-2026-47010
https://www.cve.org/CVERecord?id=CVE-2026-47010
Référence CVE CVE-2026-47021
https://www.cve.org/CVERecord?id=CVE-2026-47021
Référence CVE CVE-2026-47027
https://www.cve.org/CVERecord?id=CVE-2026-47027
Référence CVE CVE-2026-47057
https://www.cve.org/CVERecord?id=CVE-2026-47057
Référence CVE CVE-2026-47058
https://www.cve.org/CVERecord?id=CVE-2026-47058
Référence CVE CVE-2026-47059
https://www.cve.org/CVERecord?id=CVE-2026-47059
Référence CVE CVE-2026-47063
https://www.cve.org/CVERecord?id=CVE-2026-47063
Référence CVE CVE-2026-47244
https://www.cve.org/CVERecord?id=CVE-2026-47244
Référence CVE CVE-2026-4800
https://www.cve.org/CVERecord?id=CVE-2026-4800
Référence CVE CVE-2026-48043
https://www.cve.org/CVERecord?id=CVE-2026-48043
Référence CVE CVE-2026-50020
https://www.cve.org/CVERecord?id=CVE-2026-50020
Référence CVE CVE-2026-50560
https://www.cve.org/CVERecord?id=CVE-2026-50560
Référence CVE CVE-2026-50645
https://www.cve.org/CVERecord?id=CVE-2026-50645
Référence CVE CVE-2026-54225
https://www.cve.org/CVERecord?id=CVE-2026-54225
Référence CVE CVE-2026-5516
https://www.cve.org/CVERecord?id=CVE-2026-5516
Référence CVE CVE-2026-5588
https://www.cve.org/CVERecord?id=CVE-2026-5588
Référence CVE CVE-2026-5598
https://www.cve.org/CVERecord?id=CVE-20
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0958Multiples vulnérabilités dans les produits IBMecord?id=CVE-2026-44930
Référence CVE CVE-2026-4519
https://www.cve.org/CVERecord?id=CVE-2026-4519
Référence CVE CVE-2026-45292
https://www.cve.org/CVERecord?id=CVE-2026-45292
Référence CVE CVE-2026-45505
https://www.cve.org/CVERecord?id=CVE-2026-45505
Référence CVE CVE-2026-46595
https://www.cve.org/CVERecord?id=CVE-2026-46595
Référence CVE CVE-2026-46597
https://www.cve.org/CVERecord?id=CVE-2026-46597
Référence CVE CVE-2026-46598
https://www.cve.org/CVERecord?id=CVE-2026-46598
Référence CVE CVE-2026-46605
https://www.cve.org/CVERecord?id=CVE-2026-46605
Référence CVE CVE-2026-4786
https://www.cve.org/CVERecord?id=CVE-2026-4786
Référence CVE CVE-2026-4800
https://www.cve.org/CVERecord?id=CVE-2026-4800
Référence CVE CVE-2026-4867
https://www.cve.org/CVERecord?id=CVE-2026-4867
Référence CVE CVE-2026-49157
https://www.cve.org/CVERecord?id=CVE-2026-49157
Référence CVE CVE-2026-49270
https://www.cve.org/CVERecord?id=CVE-2026-49270
Référence CVE CVE-2026-49844
https://www.cve.org/CVERecord?id=CVE-2026-49844
Référence CVE CVE-2026-5038
https://www.cve.org/CVERecord?id=CVE-2026-5038
Référence CVE CVE-2026-5079
https://www.cve.org/CVERecord?id=CVE-2026-5079
Référence CVE CVE-2026-53550
https://www.cve.org/CVERecord?id=CVE-2026-53550
Référence CVE CVE-2026-53655
https://www.cve.org/CVERecord?id=CVE-202
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0934Multiples vulnérabilités dans les produits Atlassiand?id=CVE-2026-44488
Référence CVE CVE-2026-44490
https://www.cve.org/CVERecord?id=CVE-2026-44490
Référence CVE CVE-2026-44492
https://www.cve.org/CVERecord?id=CVE-2026-44492
Référence CVE CVE-2026-44494
https://www.cve.org/CVERecord?id=CVE-2026-44494
Référence CVE CVE-2026-44495
https://www.cve.org/CVERecord?id=CVE-2026-44495
Référence CVE CVE-2026-44496
https://www.cve.org/CVERecord?id=CVE-2026-44496
Référence CVE CVE-2026-44705
https://www.cve.org/CVERecord?id=CVE-2026-44705
Référence CVE CVE-2026-46625
https://www.cve.org/CVERecord?id=CVE-2026-46625
Référence CVE CVE-2026-47838
https://www.cve.org/CVERecord?id=CVE-2026-47838
Référence CVE CVE-2026-4800
https://www.cve.org/CVERecord?id=CVE-2026-4800
Référence CVE CVE-2026-48779
https://www.cve.org/CVERecord?id=CVE-2026-48779
Référence CVE CVE-2026-6321
https://www.cve.org/CVERecord?id=CVE-2026-6321
Référence CVE CVE-2026-6322
https://www.cve.org/CVERecord?id=CVE-2026-6322
Gestion détaillée du document
le 27 juillet 2026
Version initiale
Alertes
Avis
Bulletins d’actualités
Mentions légales
Conditions générales
À propos
Contact
cyber.gouv.fr
service-public.fr
legifrance.gouv.fr
info.gouv.fr
france.fr
info.gouv.fr/risques
Premier Ministre / Secrétariat Général de la Défense et de la Sécurité Nationale / Agence nationale de la
sécurité des syst
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0901Multiples vulnérabilités dans les produits IBMord?id=CVE-2026-44582
Référence CVE CVE-2026-45109
https://www.cve.org/CVERecord?id=CVE-2026-45109
Référence CVE CVE-2026-45149
https://www.cve.org/CVERecord?id=CVE-2026-45149
Référence CVE CVE-2026-45249
https://www.cve.org/CVERecord?id=CVE-2026-45249
Référence CVE CVE-2026-4539
https://www.cve.org/CVERecord?id=CVE-2026-4539
Référence CVE CVE-2026-45409
https://www.cve.org/CVERecord?id=CVE-2026-45409
Référence CVE CVE-2026-46595
https://www.cve.org/CVERecord?id=CVE-2026-46595
Référence CVE CVE-2026-46597
https://www.cve.org/CVERecord?id=CVE-2026-46597
Référence CVE CVE-2026-46598
https://www.cve.org/CVERecord?id=CVE-2026-46598
Référence CVE CVE-2026-4800
https://www.cve.org/CVERecord?id=CVE-2026-4800
Référence CVE CVE-2026-4867
https://www.cve.org/CVERecord?id=CVE-2026-4867
Référence CVE CVE-2026-50645
https://www.cve.org/CVERecord?id=CVE-2026-50645
Référence CVE CVE-2026-53663
https://www.cve.org/CVERecord?id=CVE-2026-53663
Référence CVE CVE-2026-54269
https://www.cve.org/CVERecord?id=CVE-2026-54269
Référence CVE CVE-2026-54270
https://www.cve.org/CVERecord?id=CVE-2026-54270
Référence CVE CVE-2026-54285
https://www.cve.org/CVERecord?id=CVE-2026-54285
Référence CVE CVE-2026-5795
https://www.cve.org/CVERecord?id=CVE-2026-5795
Référence CVE CVE-2026-6321
https://www.cve.org/CVERecord?id=CVE-20
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0834Multiples vulnérabilités dans les produits IBMd?id=CVE-2026-42039
Référence CVE CVE-2026-42040
https://www.cve.org/CVERecord?id=CVE-2026-42040
Référence CVE CVE-2026-42041
https://www.cve.org/CVERecord?id=CVE-2026-42041
Référence CVE CVE-2026-42042
https://www.cve.org/CVERecord?id=CVE-2026-42042
Référence CVE CVE-2026-42043
https://www.cve.org/CVERecord?id=CVE-2026-42043
Référence CVE CVE-2026-42044
https://www.cve.org/CVERecord?id=CVE-2026-42044
Référence CVE CVE-2026-42264
https://www.cve.org/CVERecord?id=CVE-2026-42264
Référence CVE CVE-2026-44431
https://www.cve.org/CVERecord?id=CVE-2026-44431
Référence CVE CVE-2026-44432
https://www.cve.org/CVERecord?id=CVE-2026-44432
Référence CVE CVE-2026-4800
https://www.cve.org/CVERecord?id=CVE-2026-4800
Référence CVE CVE-2026-4923
https://www.cve.org/CVERecord?id=CVE-2026-4923
Référence CVE CVE-2026-4926
https://www.cve.org/CVERecord?id=CVE-2026-4926
Référence CVE CVE-2026-50645
https://www.cve.org/CVERecord?id=CVE-2026-50645
Référence CVE CVE-2026-6051
https://www.cve.org/CVERecord?id=CVE-2026-6051
Référence CVE CVE-2026-6052
https://www.cve.org/CVERecord?id=CVE-2026-6052
Référence CVE CVE-2026-6053
https://www.cve.org/CVERecord?id=CVE-2026-6053
Référence CVE CVE-2026-6938
https://www.cve.org/CVERecord?id=CVE-2026-6938
Référence CVE CVE-2026-7246
https://www.cve.org/CVERecord?id=CVE-2026-7246
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0698Multiples vulnérabilités dans les produits IBMd?id=CVE-2026-42039
Référence CVE CVE-2026-42040
https://www.cve.org/CVERecord?id=CVE-2026-42040
Référence CVE CVE-2026-42041
https://www.cve.org/CVERecord?id=CVE-2026-42041
Référence CVE CVE-2026-42042
https://www.cve.org/CVERecord?id=CVE-2026-42042
Référence CVE CVE-2026-42043
https://www.cve.org/CVERecord?id=CVE-2026-42043
Référence CVE CVE-2026-42044
https://www.cve.org/CVERecord?id=CVE-2026-42044
Référence CVE CVE-2026-42198
https://www.cve.org/CVERecord?id=CVE-2026-42198
Référence CVE CVE-2026-44431
https://www.cve.org/CVERecord?id=CVE-2026-44431
Référence CVE CVE-2026-44432
https://www.cve.org/CVERecord?id=CVE-2026-44432
Référence CVE CVE-2026-4800
https://www.cve.org/CVERecord?id=CVE-2026-4800
Référence CVE CVE-2026-4923
https://www.cve.org/CVERecord?id=CVE-2026-4923
Référence CVE CVE-2026-4926
https://www.cve.org/CVERecord?id=CVE-2026-4926
Référence CVE CVE-2026-8620
https://www.cve.org/CVERecord?id=CVE-2026-8620
Référence CVE CVE-2026-8633
https://www.cve.org/CVERecord?id=CVE-2026-8633
Référence CVE CVE-2026-8644
https://www.cve.org/CVERecord?id=CVE-2026-8644
Référence CVE CVE-2026-9311
https://www.cve.org/CVERecord?id=CVE-2026-9311
Référence CVE CVE-2026-9319
https://www.cve.org/CVERecord?id=CVE-2026-9319
Référence CVE CVE-2026-9330
https://www.cve.org/CVERecord?id=CVE-2026-9330
Ge
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0667Multiples vulnérabilités dans les produits IBMERecord?id=CVE-2026-40973
Référence CVE CVE-2026-40974
https://www.cve.org/CVERecord?id=CVE-2026-40974
Référence CVE CVE-2026-40975
https://www.cve.org/CVERecord?id=CVE-2026-40975
Référence CVE CVE-2026-40977
https://www.cve.org/CVERecord?id=CVE-2026-40977
Référence CVE CVE-2026-41044
https://www.cve.org/CVERecord?id=CVE-2026-41044
Référence CVE CVE-2026-41324
https://www.cve.org/CVERecord?id=CVE-2026-41324
Référence CVE CVE-2026-4424
https://www.cve.org/CVERecord?id=CVE-2026-4424
Référence CVE CVE-2026-4519
https://www.cve.org/CVERecord?id=CVE-2026-4519
Référence CVE CVE-2026-4786
https://www.cve.org/CVERecord?id=CVE-2026-4786
Référence CVE CVE-2026-4800
https://www.cve.org/CVERecord?id=CVE-2026-4800
Référence CVE CVE-2026-4867
https://www.cve.org/CVERecord?id=CVE-2026-4867
Référence CVE CVE-2026-4923
https://www.cve.org/CVERecord?id=CVE-2026-4923
Référence CVE CVE-2026-4926
https://www.cve.org/CVERecord?id=CVE-2026-4926
Référence CVE CVE-2026-5121
https://www.cve.org/CVERecord?id=CVE-2026-5121
Référence CVE CVE-2026-5598
https://www.cve.org/CVERecord?id=CVE-2026-5598
Référence CVE CVE-2026-5795
https://www.cve.org/CVERecord?id=CVE-2026-5795
Référence CVE CVE-2026-6100
https://www.cve.org/CVERecord?id=CVE-2026-6100
Référence CVE CVE-2026-6918
https://www.cve.org/CVERecord?id=CVE-2026-6918
Ré
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0550Multiples vulnérabilités dans les produits IBMord?id=CVE-2026-34517
Référence CVE CVE-2026-34518
https://www.cve.org/CVERecord?id=CVE-2026-34518
Référence CVE CVE-2026-34519
https://www.cve.org/CVERecord?id=CVE-2026-34519
Référence CVE CVE-2026-34520
https://www.cve.org/CVERecord?id=CVE-2026-34520
Référence CVE CVE-2026-34525
https://www.cve.org/CVERecord?id=CVE-2026-34525
Référence CVE CVE-2026-39892
https://www.cve.org/CVERecord?id=CVE-2026-39892
Référence CVE CVE-2026-40087
https://www.cve.org/CVERecord?id=CVE-2026-40087
Référence CVE CVE-2026-40175
https://www.cve.org/CVERecord?id=CVE-2026-40175
Référence CVE CVE-2026-4539
https://www.cve.org/CVERecord?id=CVE-2026-4539
Référence CVE CVE-2026-4800
https://www.cve.org/CVERecord?id=CVE-2026-4800
Gestion détaillée du document
le 07 mai 2026
Version initiale
Alertes
Avis
Bulletins d’actualités
Mentions légales
Conditions générales
À propos
Contact
cyber.gouv.fr
service-public.fr
legifrance.gouv.fr
info.gouv.fr
france.fr
info.gouv.fr/risques
Premier Ministre / Secrétariat Général de la Défense et de la Sécurité Nationale / Agence nationale de la
sécurité des systèmes d'information
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0523Multiples vulnérabilités dans les produits IBMecord?id=CVE-2026-26278
Référence CVE CVE-2026-27601
https://www.cve.org/CVERecord?id=CVE-2026-27601
Référence CVE CVE-2026-27970
https://www.cve.org/CVERecord?id=CVE-2026-27970
Référence CVE CVE-2026-2950
https://www.cve.org/CVERecord?id=CVE-2026-2950
Référence CVE CVE-2026-32141
https://www.cve.org/CVERecord?id=CVE-2026-32141
Référence CVE CVE-2026-33186
https://www.cve.org/CVERecord?id=CVE-2026-33186
Référence CVE CVE-2026-33228
https://www.cve.org/CVERecord?id=CVE-2026-33228
Référence CVE CVE-2026-33532
https://www.cve.org/CVERecord?id=CVE-2026-33532
Référence CVE CVE-2026-3621
https://www.cve.org/CVERecord?id=CVE-2026-3621
Référence CVE CVE-2026-4800
https://www.cve.org/CVERecord?id=CVE-2026-4800
Gestion détaillée du document
le 30 avril 2026
Version initiale
Alertes
Avis
Bulletins d’actualités
Mentions légales
Conditions générales
À propos
Contact
cyber.gouv.fr
service-public.fr
legifrance.gouv.fr
info.gouv.fr
france.fr
info.gouv.fr/risques
Premier Ministre / Secrétariat Général de la Défense et de la Sécurité Nationale / Agence nationale de la
sécurité des systèmes d'information
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0500Multiples vulnérabilités dans VMware Tanzuord?id=CVE-2026-34480
Référence CVE CVE-2026-34483
https://www.cve.org/CVERecord?id=CVE-2026-34483
Référence CVE CVE-2026-34486
https://www.cve.org/CVERecord?id=CVE-2026-34486
Référence CVE CVE-2026-34487
https://www.cve.org/CVERecord?id=CVE-2026-34487
Référence CVE CVE-2026-3449
https://www.cve.org/CVERecord?id=CVE-2026-3449
Référence CVE CVE-2026-34500
https://www.cve.org/CVERecord?id=CVE-2026-34500
Référence CVE CVE-2026-40175
https://www.cve.org/CVERecord?id=CVE-2026-40175
Référence CVE CVE-2026-41239
https://www.cve.org/CVERecord?id=CVE-2026-41239
Référence CVE CVE-2026-41240
https://www.cve.org/CVERecord?id=CVE-2026-41240
Référence CVE CVE-2026-4800
https://www.cve.org/CVERecord?id=CVE-2026-4800
Gestion détaillée du document
le 27 avril 2026
Version initiale
Alertes
Avis
Bulletins d’actualités
Mentions légales
Conditions générales
À propos
Contact
cyber.gouv.fr
service-public.fr
legifrance.gouv.fr
info.gouv.fr
france.fr
info.gouv.fr/risques
Premier Ministre / Secrétariat Général de la Défense et de la Sécurité Nationale / Agence nationale de la
sécurité des systèmes d'information
Official advisory ↗JVN iPedia · Japanese · JVNDB-2026-010458lodashのlodash-es等の複数製品におけるコードインジェクションの脆弱性この脆弱性では、_.templateのvariableオプションと同様の検証がoptions.importsのキー名に適用されておらず、不正なキー名を渡すとテンプレートのコンパイル時に任意のコードが実行される恐れがあります。さらに、assignInWithの使用により継承されたプロパティもマージされるため、Object.prototypeが汚染されている場合は悪用される可能性があります。対策としては、バージョン4.18.0へのアップグレードを行い、options.importsに信頼できないキー名を渡さないことを推奨します。
Official advisory ↗JVN iPedia · Japanese · JVNDB-2026-021427HCL Technologies LimitedのHCL iControlにおけるセッション期限に関する脆弱性HCL iControlは、不十分なセッションタイムアウトの脆弱性の影響を受けました。この脆弱性は、ウェブアプリケーションが一定期間の非アクティブ状態の後にユーザーセッションを自動的に終了しないという問題を引き起こします。
Official advisory ↗NCSC-NL · Dutch · NCSC-2026-0325Kwetsbaarheden verholpen in Atlassian productenMultiple lodash vulnerabilities, including CVE-2021-23337 and command injection in _.template, affect various versions and Oracle products, enabling code injection and remote takeover with severity up to CVSS 9.8, fixed in lodash 4.18.0 and later.
Official advisory ↗NCSC-NL · Dutch · NCSC-2026-0309Kwetsbaarheden verholpen in Oracle CommunicationsMultiple lodash vulnerabilities, including CVE-2021-23337, involve unvalidated options.imports key names in _.template leading to arbitrary code execution, affecting versions prior to 4.18.0 and impacting products like Oracle Banking Corporate Lending with critical severity.
Official advisory ↗NCSC-NL · Dutch · NCSC-2026-0258Kwetsbaarheden verholpen in Oracle Financial ServicesLodash versions prior to 4.18.0 contain a critical vulnerability (CVE-2021-23337) in the _.template function allowing code injection via unvalidated options.imports keys, alongside other issues including prototype pollution and denial of service.
Official advisory ↗NCSC-NL · Dutch · NCSC-2026-0256Kwetsbaarheden verholpen in Oracle CommunicationsLodash versions prior to 4.18.0 contain a critical vulnerability (CVE-2021-23337) in the _.template function allowing code injection via unvalidated options.imports keys, alongside other issues including prototype pollution and denial of service.
Official advisory ↗