Searching in Data Privacy & Cybersecurity · Search everything
679 changes Data Privacy & Cybersecurity
Advisory on Risks Associated with Frontier AI Models
The Cyber Security Agency of Singapore (CSA) has published an advisory warning organisations about cybersecurity risks associated with frontier AI models. These advanced AI systems can reportedly reduce the time to identify vulnerabilities and engineer exploits from months to hours. While no misuse has been observed, CSA outlines immediate and long-term mitigation measures for organisations to strengthen their security posture.
Multiple Windows Vulnerabilities Enable Code Execution, Privilege Escalation
CERT-FR issued advisory CERTFR-2026-AVI-0442 alerting to 51 vulnerabilities in Microsoft Windows. Affected CVEs include CVE-2023-20585, CVE-2026-0390, and multiple others from CVE-2026-26151 through CVE-2026-27914. The vulnerabilities enable remote code execution and privilege escalation. Microsoft released security bulletins on April 14, 2026. Organizations running affected Windows systems are advised to apply patches immediately.
Adobe Product Vulnerabilities Allow Remote Code Execution, DoS, Security Bypass
CERT-FR issued advisory CERTFR-2026-AVI-0438 warning of multiple critical vulnerabilities in Adobe products. Affected products include Acrobat 2024, Acrobat DC, Acrobat Reader DC, ColdFusion 2023, and ColdFusion 2025 on Windows and macOS. The vulnerabilities allow remote code execution, remote denial of service, and security policy bypass. ANSSI references Adobe security bulletins APSB26-38 and APSB26-44.
Python CPython Remote Denial of Service Vulnerability
CERT-FR issued a security advisory regarding a remote denial of service vulnerability in Python CPython. The vulnerability (CVE-2026-5713) affects CPython versions without the latest security patch. Organizations using affected Python installations are at risk of remote denial of service attacks.
Multiples vulnérabilités dans Ivanti Neurons (XSS et contournement de sécurité)
CERT-FR a publié un avis de sécurité concernant deux vulnérabilités (CVE-2026-4913 et CVE-2026-4914) dans Ivanti Neurons for ITSM versions antérieures à 2025.4. Les failles permettent une injection de code indirecte à distance (XSS) et un contournement de la politique de sécurité. Les organisations utilisant ce logiciel doivent vérifier leur version et appliquer les correctifs disponibles via le bulletin de sécurité Ivanti du 14 avril 2026.
Multiple Fortinet Vulnerabilities Allow Code Execution
CERT-FR published advisory CERTFR-2026-AVI-0440 covering 29 vulnerabilities across multiple Fortinet product lines, including FortiOS, FortiAnalyzer, FortiManager, FortiProxy, FortiSandbox, FortiClientEMS, and others. Affected products span versions 7.x through 7.6.x and earlier, exposing systems to risks including remote code execution, data confidentiality and integrity breaches, SSRF, XSS, SQL injection, denial of service, and privilege escalation. Fortinet published corresponding security bulletins FG-IR-26-100 through FG-IR-26-127 between April 14-15, 2026.
Multiple Microsoft Office Vulnerabilities Allow Remote Code Execution, Data Breach
CERT-FR published security advisory CERTFR-2026-AVI-0441 alerting organizations to 12 critical vulnerabilities in Microsoft Office products including Excel, PowerPoint, Office 2016/2019/LTSC 2021/2024, and Office Online Server. The vulnerabilities allow remote code execution and data confidentiality breaches. Users are advised to apply Microsoft's security patches immediately.
Multiples vulnérabilités dans Tenable Identity Exposure versions antérieures à 3.77.17
CERT-FR has published a security advisory regarding 18 vulnerabilities discovered in Tenable Identity Exposure, affecting versions prior to 3.77.17. The vulnerabilities include privilege escalation, remote denial of service, data confidentiality breaches, data integrity compromise, and security policy bypass. Affected organizations are advised to consult the vendor security bulletin and apply available patches.
Multiple .NET Vulnerabilities Allow DoS and Security Bypass
CERT-FR issued advisory CERTFR-2026-AVI-0443 alerting that six vulnerabilities (CVE-2026-23666, CVE-2026-26171, CVE-2026-32178, CVE-2026-32203, CVE-2026-32226, CVE-2026-33116) were discovered in Microsoft .NET affecting versions 8.0, 9.0, and 10.0 on Linux, Mac OS, and Windows, as well as multiple .NET Framework versions. These vulnerabilities allow remote attackers to cause denial of service and bypass security policies. Affected organizations should apply patches per Microsoft security bulletins.
Multiple Microsoft CVEs Allow Code Execution, Elevation
CERT-FR issued advisory CERTFR-2026-AVI-0445 notifying of 22 Microsoft security vulnerabilities affecting products including Microsoft Defender, Microsoft Dynamics 365, Microsoft HPC Pack, Microsoft Power Apps, Microsoft SharePoint (multiple versions), Microsoft SQL Server (2016-2025), and Microsoft Visual Studio. Affected systems risk data confidentiality breaches, security policy bypass, remote code execution, denial of service, and privilege elevation. Microsoft has released patches and updates to address these vulnerabilities.