Aller au contenu
BNTIC News Numérique · Innovation · Énergie
CyberAlert · BNTIC

Bulletin hebdomadaire · mercredi 9 septembre 2026

Les failles de la semaine

Trois vulnérabilités, pas trente. Celles qui sont réellement exploitées, expliquées en français, avec ce qu'il faut faire.

Exploité par des attaquants

Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability

Concerne Adobe Commerce and Magento.

Signalé le
08/09/2026
Gravité CVSS
Non renseignée par la source
Échéance CISA
11/09/2026
À faire

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Exploité par des attaquants

Microsoft Windows Link Following Vulnerability

Concerne Microsoft Windows.

Signalé le
08/09/2026
Gravité CVSS
Non renseignée par la source
Échéance CISA
22/09/2026
À faire

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Exploité par des attaquants

N-able N-central Static Code Injection Vulnerability

Concerne N-able N-central.

Signalé le
08/09/2026
Gravité CVSS
Non renseignée par la source
Échéance CISA
11/09/2026
À faire

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Recevoir ce bulletin par e-mail

Le bulletin est envoyé chaque semaine aux abonnés CyberAlert. Inscrivez-vous depuis l'accueil ; votre demande est validée par notre équipe avant activation, et la désinscription est immédiate.

Sélection établie à partir du catalogue CISA KEV, enrichie FIRST EPSS et NVD. Généré le 09/09/2026 à 08:40.