Nicolas Marty
Thème d'affichage

Veille technologique

Ce que je surveille

Les mises à jour Microsoft, les failles de sécurité signalées par le CERT-FR, l'écosystème SCCM et les postes de travail. Les articles sont relevés automatiquement par un script qui interroge les flux RSS et les stocke en base, dédoublonnés.

Septembre 2026

  • 18 sept. 2026
    Reddit r/SCCM
    MECM/WSUS: Clients failing software update scan after re-enabling deployment – “Sources are current but invalid. TTL is also invalid

    Hi everyone, I’m facing a strange issue in my MECM (Configuration Manager) + WSUS environment and would really appreciate some help from anyone who has experienced something similar. A few days ago, I disabled a Security Updates deployment from my MECM server. After around 4–5 days, I enabled the deployment again. Since then, all MECM clients are failing to perform software update scans. On the affected clients, ScanAgent.log shows: Sources are current but invalid. TTL is also invalid. Th…

    Lire l'article sur Reddit r/SCCM
  • 17 sept. 2026
    Reddit r/SCCM
    IPU TS - Run Actions on Failure Condition

    We have the condition "TS Variable _SMSTSLastActionSucceeded is not equals true" and the whole IPU is a in the "25H2" Group, so it works great an a real failure. But we the 25H2 Group it self, have the WMI Query condition "select * from Win32_OperatingSystem where BuildNumber < "26200"" My "issue" is, that if the 25H2 group is skipped, as a device is already on 25H2, it also runs into the Failing group. What whould be a better solution for this? And I know, that typically the TS won't run a se…

    Lire l'article sur Reddit r/SCCM
  • 17 sept. 2026
    Reddit r/SCCM
    Configuration Manager 2603 Hotfix (KB39398030)

    Anyone installed? Any problem or all OK? Thanks for any feedback submitted by /u/santimandu [link] [comments]

    Lire l'article sur Reddit r/SCCM
  • 17 sept. 2026
    Reddit r/SCCM
    HP Z4 G4 ca2023

    After updating HP z4 g4 to the current 3.00 bios version , the rollout for the 2023 secure boot keys is not fully complete. There are Three checks boxes not checked in the secure boot configurations . Therefore the update is not able to completed. Sometimes windows is fighting with the firmware triggering a bitlockerscreen. The settings are exposed to the wmi . The bios password is needed, if set . Short script , to change the BIOS settings $HPBIOSPassword = "" + "Pass“ $bios = Get-WmiOb…

    Lire l'article sur Reddit r/SCCM
  • 17 sept. 2026
    Reddit r/SCCM
    Security update for scripts, the SMS Provider, the Message Processing Engine, and DDR processing

    Hello ConfigMgr admins, Microsoft has released KB 39398030 security update for version Implementing this update enhances the security and functionality of Configuration Manager by resolving critical issues related to scripts, the SMS Provider, the Message Processing Engine, and Discovery Data Record processing. The update is available in the Updates and Servicing node for Configuration Manager version 2603, and for versions 2509 and 2503 with specific update rollups. Hotfix Documentation: htt…

    Lire l'article sur Reddit r/SCCM
  • 17 sept. 2026
    Reddit r/SCCM
    Driver Automation Tool for HP? Worth it?

    We've been using the DAT for a few years and I love it; it makes the task sequence so smooth and tidy but the huge issue is that it seems to build packages from HP's CSML enterprise catalogue which appear to be woefully out of date. While the script that comes with it is great, it looks like we're going to have to build our own driver packs to work with the automation steps. Anything I'm missing? submitted by /u/Blanzeros [link] [comments]

    Lire l'article sur Reddit r/SCCM
  • 16 sept. 2026
    Reddit r/SCCM
    RMM Comparison Sheet – Request for Updates

    submitted by /u/TechEnthusiast212 [link] [comments]

    Lire l'article sur Reddit r/SCCM
  • 16 sept. 2026
    Reddit r/SCCM
    Windows Server 2019 Domain Controllers BSOD After August/September 2026 Cumulative Updates (KB5120238 / KB5122876)

    submitted by /u/Flowmate [link] [comments]

    Lire l'article sur Reddit r/SCCM
  • 15 sept. 2026
    Reddit r/SCCM
    Found a task sequence step added three years ago that exists purely to work around a bug nobody ever actually fixed

    Task sequence step, added 2023: "Run PowerShell script to manually clear WMI repository corruption flag before proceeding to app install." Ran on every single deployment since, no exceptions, because leaving it out caused the install to fail on a meaningful chunk of machines. Finally got investigated properly last month when someone new to the team asked why this wasn't just handled by ensuring WMI was healthy earlier in the build process instead of patching around corruption after the fact. Tu…

    Lire l'article sur Reddit r/SCCM
  • 14 sept. 2026
    Reddit r/SCCM
    MS Releases all sorts of OOB updates for Sept 2026 Patches

    I think the catalog is still kind of a mess because of typos in the update names + Win11 23h2 wasn't included as of yet (1:30 pm central time sync): https://support.microsoft.com/en-us/servicing/os/windows-11/2026/09/kb5129195-windows-11-24h2-25h2-security-update https://support.microsoft.com/en-us/servicing/os/windows-11/2026/09/kb5129242-windows-11-23h2-update https://support.microsoft.com/en-us/servicing/os/windows-server/2026/09/kb5129237-windows-server-2022-update https://support.micros…

    Lire l'article sur Reddit r/SCCM
  • 14 sept. 2026
    Reddit r/SCCM
    Windows 11 25H2 September Patch Broke All My PWA Apps — Anyone Else?

    So… I updated to Windows 11 25H2 with the September cumulative patch and now literally every single PWA-App I had pinned to Start or the Taskbar is dead. Click the icon → Nothing happens: No error, no window, no splash screen → Just dead shortcuts. Is anyone else seeing this on Windows 11 or 25H2? Did Microsoft acknowledge this yet? submitted by /u/shaktirathore [link] [comments]

    Lire l'article sur Reddit r/SCCM
  • 12 sept. 2026
    Reddit r/SCCM
    Built a PowerShell/SCCM tool to help track down hundreds of missing devices

    I've been working on a project at work where we needed to physically locate a few hundred devices, but the reporting we had wasn't giving us enough useful information to actually hand the list off to technicians and say "go find these." I started with basically just a list of computer names and ended up building a PowerShell audit around SCCM and AD. Right now it takes the device list and pulls/checks things like: SCCM device information Online/offline status Last active time Last known/…

    Lire l'article sur Reddit r/SCCM
  • 11 sept. 2026
    Reddit r/SCCM
    SCCM or SQL for finding Adobe Standard vs Pro?

    I get Standard from this query but the counts are way off. I know Adobe has been going more towards a single installer. SELECT DISTINCT SYS.Netbios_Name0 AS [Machine Name], SYS.User_Name0 AS [Username], CASE WHEN SOFT.ProductName0 LIKE '%Reader%' THEN 'Adobe Reader' WHEN SOFT.ProductName0 LIKE '%Acrobat%Pro%' OR SOFT.ProductName0 LIKE '%Acrobat%Professional%' THEN 'Adobe Acrobat Pro' ELSE 'Adobe Acrobat Standard' END AS [Adobe Product] FROM v_R_System SYS JOIN v_GS_INSTALLED_SOFTWARE SOFT ON SYS…

    Lire l'article sur Reddit r/SCCM
  • 11 sept. 2026
    Reddit r/SCCM
    Office ADR best practices

    ADR for win servers preview returns about 31 updates this month, including m365 and office 2016. so, Any lessons learned around deployment package size or keeping content manageable? interested in whether there are architectural or operational improvements I'm missing Should I be re-evaluating the entire Office management strategy? https://preview.redd.it/wzst5xxu2xoh1.jpg?width=603&format=pjpg&auto=webp&s=bae51fa9d2318062a761ba8b789b5b8c97bf8f95 https://preview.redd.it/o6scn36w2xoh1.j…

    Lire l'article sur Reddit r/SCCM
  • 11 sept. 2026
    Reddit r/SCCM
    Dell Inventory agent

    Does anyone who uses Dell third party updates seem to have a high failure rate for the newest 15.0.1.190 build of the agent? Normally I get high install percent jsut a couple days after the mandatory updates applies but now I only have like 25 out of over 350 agents. submitted by /u/whirlwind87 [link] [comments]

    Lire l'article sur Reddit r/SCCM
  • 11 sept. 2026
    Reddit r/SCCM
    Issue with ODBC Driver for SQL Server 18.7.1.1

    Our SCCM servers updated to this last night via PMP and it caused them to not be able to connect to the SCCM DB server. We have rolled back to 18.6.2.1 submitted by /u/steve-work [link] [comments]

    Lire l'article sur Reddit r/SCCM
  • 11 sept. 2026
    Reddit r/SCCM
    Introducing TSDude : A new Task Sequence UI

    While we always recommended UI++, its aging VBS dependencies, XML files that some struggled to maintain and the fact that it’s no longer maintained by the developer pushed us to bridge the gap and work on a solution that would check all the boxes. Features : Based on PowerShell Inspired by the great UI++ (because you don’t change a winning formula) Comes with a configurator helping you build and maintain your XML config files Custom colors and logo Has all the same features that UI++ had…

    Lire l'article sur Reddit r/SCCM
  • 11 sept. 2026
    Reddit r/SCCM
    Patching - Task Sequence - External request reboot

    Hi all, Over the last couple of months we've been running into a recurring issue during patching with MECM. Our Task Sequence is randomly failing due to an "External Request Reboot", and it's now impacting hundreds of servers every month. Has anyone else experienced this? If so, were you able to identify the root cause or find a workaround? So far, it's been pretty difficult to troubleshoot since the failures seem somewhat inconsistent, but the volume is becoming a real problem. Any ideas, t…

    Lire l'article sur Reddit r/SCCM
  • 11 sept. 2026
    Reddit r/SCCM
    Anyone have these laptops? Lenovo ThinkPad L14 Gen 6. I can't find the right WinPE driver.

    I even downloaded Lenovo's Winpe drivers from here. https://support.lenovo.com/us/en/downloads/ds576081-sccm-package-for-windows-pe-11-thinkpad-l14-gen-6-type-21s8-21s9-l16-gen-2-type-21sc-21sd Imported then into the Boot image, pxe booted and 169. ip address. I then booted into Lenovo's OEM windows on the device to see what driver windows 11 is actually using it's a Intel Ethernet Connection (18) 1219-V I am really hoping someone else has this model because we just bought 120 of these and can…

    Lire l'article sur Reddit r/SCCM
  • 10 sept. 2026
    Reddit r/SCCM
    Windows 11 25H2 Multilingual Task Sequence – Language Pack Installation

    Hello, I am currently working on a multilingual Windows 11 25H2 task sequence. In the past, I have created several images where, after installing the OS, I would use DISM to install the required Language Pack (LP) CAB files and Features on Demand (FOD) CAB files. I would then install the latest cumulative update to complete the localization. However, with Windows 11 25H2, I am facing an issue because the cumulative update size has increased by approximately 4.6 GB, mainly due to the UUP-based…

    Lire l'article sur Reddit r/SCCM
  • 10 sept. 2026
    Reddit r/SCCM
    Initiating Install of Pending Software Center installs via Powershell

    Morning Everyone and happy patch week /s This week, our leadership has informed us that our patching timeline has shrunk from Thursday - Sunday, to Thursday - Friday. Unfortunately we have an unresolved issue in our environment that means about 40 servers fail per environment (Were not sure why yet, weve been investigating for a while and trying a bunch of fixes but no dice yet). Where as before the schedule change that would mean our team of 5 dudes would come in the morning after and divide…

    Lire l'article sur Reddit r/SCCM
  • 10 sept. 2026
    Reddit r/SCCM
    Office 2024 LTSC - September patches

    Anyone else had these not appear in WSUS / sync to Config Manager? M365 / 2021 LTSC patches all synced ok and deployed etc. but 2024 missing. No errors in sync logs etc. and product obviously ticked on the SUP settings given the others have synced. Never been an issue with these up to now. Checked and there's definitely been a September patch released too. Update from u/Mahava86 Reply from support There was an issue on the Office side with the update, but the patch is now published …

    Lire l'article sur Reddit r/SCCM
  • 10 sept. 2026
    CERT-FR — Alertes
    Vulnérabilité dans Metabase (10 septembre 2026)

    Le 06 août 2026, Metabase a publié un avis de sécurité concernant une vulnérabilité critique permettant à un attaquant non authentifié de provoquer une injection SQL (SQLi) dans la base de donnée de l'application Metabase. Cette injection SQL permet d’obtenir les droits administrateur de...

    Lire l'article sur CERT-FR — Alertes
  • 9 sept. 2026
    Reddit r/SCCM
    MECM Extension Feed For Windows Admin Center

    I currently have the SCCM extension installed for WAC, but there is a notification when you navigate to this tab, advising to install the MECM extension. Does anyone know where I can get the extension from or which feed has this? Thanks. submitted by /u/FahidShaheen [link] [comments]

    Lire l'article sur Reddit r/SCCM
  • 9 sept. 2026
    Reddit r/SCCM
    Windows 11 24H2 / 25H2 Patches

    I am sitting here after 1pm with these two beasts of patches still downloading. Is this everyone’s experience or just something else? Once I begin my downloads these almost always fail and need to be retried a few times. It is 8:07pm and still downloading. While mostly all server patches, .net , exchange have completed and distributed. submitted by /u/xxiijm [link] [comments]

    Lire l'article sur Reddit r/SCCM
  • 5 sept. 2026
    MSEndpointMgr
    1PhoneMirror Levels Up: Webcam, Stats, Better Screenshots, and Signed

    It’s been a few months since I first wrote about my 1PhoneMirror tool, and it has kept moving – mostly driven by my own needs and, honestly, a fair bit of curiosity-driven tinkering. I use it regularly myself, both for writing documentation and for live demos, and both of those use cases have quietly pushed […] The post 1PhoneMirror Levels Up: Webcam, Stats, Better Screenshots, and Signed appeared first on MSEndpointMgr.

    Lire l'article sur MSEndpointMgr
  • 2 sept. 2026
    CERT-FR — Alertes
    Multiples vulnérabilités dans SonicWall Secure Mobile Access (02 septembre 2026)

    Le 01 septembre 2026, SonicWall a publié un avis de sécurité concernant deux vulnérabilités affectant les Secure Mobile Access (SMA) 1000. La vulnérabilité critique CVE-2026-83548 permet une falsification de requêtes côté serveur (SSRF) de la part d'un attaquant non authentifié. La vulnérabilité...

    Lire l'article sur CERT-FR — Alertes

Août 2026

  • 31 août 2026
    Reddit r/SCCM
    KB38982839 Security update for ConfigMgr 2603, 2509, and 2503.

    Hello ConfigMgr admins, Microsoft has released KB38982839 security update addressing the issues with SMS Provider and administration service applicable for ConfigMgr versions 2603, 2509, and 2503. Installing this hotfix enhances the security of Configuration Manager by resolving vulnerabilities related to the SMS Provider and administration service, thereby improving overall system integrity. Hotfix Documentation - https://learn.microsoft.com/en-us/intune/configmgr/hotfix/2603/38982839 Hotfi…

    Lire l'article sur Reddit r/SCCM
  • 16 août 2026
    MSEndpointMgr
    Creating a Win32 App in Intune with PowerShell and Microsoft Graph: The Ultimate Guide

    If you’re starting to, or already, dabble with Intune automation, one of the first questions you eventually hit is…how do I create a Win32 app without using the Intune admin center? In the portal, you upload an .intunewin, fill in the app details, configure install commands, detection and requirements, then click through a few screens […] The post Creating a Win32 App in Intune with PowerShell and Microsoft Graph: The Ultimate Guide appeared first on MSEndpointMgr.

    Lire l'article sur MSEndpointMgr
  • 14 août 2026
    MSEndpointMgr
    Intune Remote Help – The Deep Dive Now That It’s Included In Your E5

    Microsoft Intune Remote Help is not a brand-new tool. It has been around for a few years as a standalone add-on and as part of the Intune Suite. What is new is that Microsoft is adding the advanced Intune Suite capabilities to Microsoft 365 E3 and E5, and the rollout started in July 2026. That means a large […] The post Intune Remote Help – The Deep Dive Now That It’s Included In Your E5 appeared first on MSEndpointMgr.

    Lire l'article sur MSEndpointMgr
  • 9 août 2026
    MSEndpointMgr
    WAM Bam, Thank You Ma’am. What Changed in the Microsoft Graph SDK

    If you are sometimes slow updating your lab modules, like me, you may have noticed that when you ran Connect-MgGraph to do your Intune magic, you didn’t get a browser prompt for that interactive login. That’s because WAM in the Microsoft Graph SDK is now doing the heavy lifting on Windows. What is this sourcery? […] The post WAM Bam, Thank You Ma’am. What Changed in the Microsoft Graph SDK appeared first on MSEndpointMgr.

    Lire l'article sur MSEndpointMgr
  • 1 août 2026
    MSEndpointMgr
    Intune assignment filters for every in-support Windows build

    Table of Contents Overview Filters Limitations Platform Naming Windows Build Numbers Catalog Windows 11 26H1 is a Problem Child Generating Filters The Script LTSC Feature Updates Which Filters Should You Actually Create? Creating Filters Gotchas Summary Overview Assignment filters get created the way most Intune objects get created. Adhoc, one at a time, in a […] The post Intune assignment filters for every in-support Windows build appeared first on MSEndpointMgr.

    Lire l'article sur MSEndpointMgr

Juillet 2026

  • 30 juil. 2026
    MSEndpointMgr
    Is WinGet Enterprise Ready? A Deep Dive Into the Evidence

    A deep-dive look at the Windows Package Manager Community Repository. Its manifests, submission pipeline, validation model, and a clear-eyed comparison against curated enterprise catalogs maintained by dedicated commercial teams. Table of Contents Why this post exists Before we deep dive Where this post goes Part 1: The anatomy of a WinGet package It’s metadata all […] The post Is WinGet Enterprise Ready? A Deep Dive Into the Evidence appeared first on MSEndpointMgr.

    Lire l'article sur MSEndpointMgr
  • 22 juil. 2026
    CERT-FR — Alertes
    Multiples vulnérabilités dans Microsoft Sharepoint (22 juillet 2026)

    Le 14 juillet 2026, à l'occasion de sa mise à jour mensuelle, Microsoft a publié, entre autres, des correctifs pour deux vulnérabilités critiques affectant SharePoint. Les vulnérabilités CVE-2026-50522 et CVE-2026-58644 permettent à un attaquant non authentifié d'exécuter du code arbitraire à...

    Lire l'article sur CERT-FR — Alertes
  • 20 juil. 2026
    CERT-FR — Alertes
    Multiples vulnérabilités dans WordPress (20 juillet 2026)

    Le 17 juillet 2026, WordPress a publié un correctif pour deux vulnérabilités : CVE-2026-60137 : une injection SQL (SQLi) ; CVE-2026-63030 : celle-ci permet un contournement de la politique de sécurité. Un attaquant peut exploiter ces deux vulnérabilités, de manière combinée, pour obtenir une...

    Lire l'article sur CERT-FR — Alertes
  • 15 juil. 2026
    CERT-FR — Alertes
    Multiples vulnérabilités dans Sonicwall Secure Mobile Access (15 juillet 2026)

    Le 14 juillet 2026, Sonicwall a publié un avis de sécurité concernant deux vulnérabilités affectant les Secure Mobile Access (SMA) 1000. La vulnérabilité critique CVE-2026-15409 permet une falsification de requêtes côté serveur (SSRF) de la part d'un attaquant non authentifié. La vulnérabilité...

    Lire l'article sur CERT-FR — Alertes
  • 3 juil. 2026
    MSEndpointMgr
    EPM Part 3: Writing Intune Endpoint Privilege Management rules for the real world: File hash, certificate, and when each one is the wrong choice

    This is the third post in a series on Microsoft Intune Endpoint Privilege Management. In Post 1, we covered the architecture and the strategic case for EPM. In Post 2, we walked through audit mode, deploying the agent in two policies, collecting elevation data, and turning that data into a prioritized rule backlog and a […] The post EPM Part 3: Writing Intune Endpoint Privilege Management rules for the real world: File hash, certificate, and when each one is the wrong choice appeared first on MS…

    Lire l'article sur MSEndpointMgr

Juin 2026

  • 22 juin 2026
    MSEndpointMgr
    EPM Part 2: Before you remove local admin: How to use Intune Endpoint Privilege Management audit mode to understand your environment

    This is the second post in a series on Microsoft Intune Endpoint Privilege Management (EPM). If you haven’t read the first post, “The End of Local Admin“, we recommend starting there. It covers what Intune Endpoint Privilege Management is, why it matters architecturally, and how the elevation model works under the hood. This post picks up […] The post EPM Part 2: Before you remove local admin: How to use Intune Endpoint Privilege Management audit mode to understand your environment appeared firs…

    Lire l'article sur MSEndpointMgr
  • 15 juin 2026
    MSEndpointMgr
    EPM Part 1: The End of Local Admin: How Intune Endpoint Privilege Management solves a problem IT has lived with for decades

    This blog post is the first in a series on Microsoft Intune Endpoint Privilege Management. This is not a Microsoft doc, but a series about how EPM will work in real life. The Scenario Every IT Pro Recognizes It’s a Tuesday afternoon. A developer sends a message in Teams: “Hey, I need to install a […] The post EPM Part 1: The End of Local Admin: How Intune Endpoint Privilege Management solves a problem IT has lived with for decades appeared first on MSEndpointMgr.

    Lire l'article sur MSEndpointMgr
  • 4 juin 2026
    MSEndpointMgr
    Your Apps Are Running on Borrowed Time: The Hidden Risk of Out-of-Support Runtime Dependencies

    Introduction: A Security Blind Spot Hiding in Plain Sight Enterprise IT teams diligently track application versions and apply security patches to operating systems and applications. Yet one critical blind spot remains: the underlying runtime libraries many applications silently depend on. These can be old, end-of-life software components no longer receiving security fixes, turning seemingly up-to-date […] The post Your Apps Are Running on Borrowed Time: The Hidden Risk of Out-of-Support Runtime …

    Lire l'article sur MSEndpointMgr

Mai 2026

  • 15 mai 2026
    CERT-FR — Alertes
    [Màj] Vulnérabilité dans Microsoft Exchange Server (15 mai 2026)

    [Mise à jour du 11 juin 2026] Le 9 juin 2026, Microsoft a publié des versions correctives. [Publication initiale] Le 14 mai 2026, Microsoft a publié un avis de sécurité concernant la vulnérabilité CVE-2026-42897 affectant Exchange Server. Elle permet à un attaquant non authentifié de provoquer...

    Lire l'article sur CERT-FR — Alertes

Mars 2026

  • 31 mars 2026
    CERT-FR — Alertes
    Vulnérabilité dans F5 BIG-IP Access Policy Manager (31 mars 2026)

    Le 15 octobre 2025, F5 a publié un avis de sécurité concernant entre autres la vulnérabilité CVE-2025-53521. Celle-ci affecte BIG-IP APM et permet à un attaquant non authentifié d'exécuter du code à distance. Le 29 mars 2026, l'éditeur indique que cette vulnérabilité est exploitée activement. Le...

    Lire l'article sur CERT-FR — Alertes
  • 20 mars 2026
    CERT-FR — Alertes
    Note d’alerte – Ciblage des messageries instantanées (20 mars 2026)

    Le CERT-FR observe une recrudescence de campagnes d’attaques ciblant les comptes de messagerie instantanées. Ces campagnes ciblent particulièrement les secteurs régaliens (personnalités politiques, cadres de l’administration) mais aussi les personnels de la société civile exerçant des fonctions...

    Lire l'article sur CERT-FR — Alertes

Février 2026

  • 25 févr. 2026
    CERT-FR — Alertes
    [MàJ] Vulnérabilité dans Cisco Catalyst SD-WAN (25 février 2026)

    Une vulnérabilité a été découverte dans Cisco Catalyst SD-WAN. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité. Cisco indique que la vulnérabilité CVE-2026-20127 est activement exploitée.

    Lire l'article sur CERT-FR — Alertes

Janvier 2026

  • 30 janv. 2026
    CERT-FR — Alertes
    [MàJ] Multiples vulnérabilités dans Ivanti Endpoint Manager Mobile (30 janvier 2026)

    [Mise à jour du 09 février 2026] Le 6 février 2026, Ivanti a mis à disposition des scripts RPM de détection d'indicateurs de compromission, à utiliser en fonction de la version d'EPMM installée. L'éditeur a également mis son guide d'analyse à jour (cf. section Documentation). [Mise à jour du 02...

    Lire l'article sur CERT-FR — Alertes

Décembre 2025

  • 5 déc. 2025
    CERT-FR — Alertes
    [MàJ] Vulnérabilité dans React Server Components (05 décembre 2025)

    **[Mise à jour du 11 décembre 2025]** Le CERT-FR a connaissance de multiples exploitations de la vulnérabilité CVE-2025-55182. Les serveurs avec une version vulnérable exposés après la publication des preuves de concept publiques du 5 décembre 2025 doivent être considérés comme compromis....

    Lire l'article sur CERT-FR — Alertes

Septembre 2025

  • 25 sept. 2025
    CERT-FR — Alertes
    [MàJ] Multiples vulnérabilités dans Cisco ASA et FTD (25 septembre 2025)

    **[Mise à jour du 07 novembre 2025]** Le 5 novembre 2025, Cisco a mis a jour son billet de blogue initialement publié le 25 septembre 2025 (cf. section Documentation). L'éditeur déclare avoir connaissance d'une nouvelle attaque, affectant les équipements ASA et FTD vulnérables, qui cause un déni...

    Lire l'article sur CERT-FR — Alertes

Août 2025

  • 26 août 2025
    CERT-FR — Alertes
    Vulnérabilité dans Citrix NetScaler ADC et NetScaler Gateway (26 août 2025)

    Le 26 août 2025, Citrix a publié un bulletin de sécurité (cf. section Documentation) concernant, entre autres, la vulnérabilité CVE-2025-7775. Celle-ci permet une exécution de code arbitraire à distance et affecte toutes les versions de Citrix NetScaler ADC et NetScaler Gateway, dans certaines...

    Lire l'article sur CERT-FR — Alertes
  • 5 août 2025
    CERT-FR — Alertes
    Incidents de sécurité dans les pare-feux SonicWall (05 août 2025)

    [Mise à jour du 7 août 2025] Le 6 août 2025, SonicWall a remplacé une partie de son communiqué initial pour indiquer que les incidents de sécurité évoqués étaient vraisemblablement corrélés à la vulnérabilité CVE-2024-40766. Celle-ci a fait l'objet d'un bulletin de sécurité, SNWLID-2024-0015 (cf....

    Lire l'article sur CERT-FR — Alertes

Juillet 2025

  • 21 juil. 2025
    CERT-FR — Alertes
    [MàJ] Multiples vulnérabilités dans Microsoft SharePoint (21 juillet 2025)

    **[Mise à jour du 23 juillet 2025]** Le 20 juillet 2025, Microsoft a publié des correctifs pour une vulnérabilité de type limitation insuffisante d'un chemin d'accès à un répertoire restreint, aussi appelé *path traversal*, affectant SharePoint Enterprise Server 2016, SharePoint Server 2019 et...

    Lire l'article sur CERT-FR — Alertes
  • 1 juil. 2025
    CERT-FR — Alertes
    Multiples vulnérabilités dans Citrix NetScaler ADC et NetScaler Gateway (01 juillet 2025)

    **[Mise à jour du 17 juillet 2025]** L'éditeur a publié un lien contenant une méthode d'évaluation permettant d'identifier des tentatives d'exploitation dans les journaux applicatifs et systèmes [12]. **[Mise à jour du 7 juillet 2025]** Le 17 juin 2025, Citrix a publié un bulletin de sécurité...

    Lire l'article sur CERT-FR — Alertes

Juin 2025

  • 5 juin 2025
    CERT-FR — Alertes
    [MàJ] Vulnérabilité dans Roundcube (05 juin 2025)

    [Mise à jour du 06 juin 2025] Une preuve de concept est publiquement disponible. [Publication initiale] Le 01 juin 2025, Roundcube a publié des correctifs concernant une vulnérabilité critique affectant son portail de messagerie ainsi que tous les produits l'incluant (par exemple cPanel et...

    Lire l'article sur CERT-FR — Alertes

Mai 2025

  • 14 mai 2025
    CERT-FR — Alertes
    Multiples vulnérabilités dans Ivanti Endpoint Manager Mobile (EPMM) (14 mai 2025)

    [Mise à jour du 15 mai 2025] Une preuve de concept est publiquement disponible sur Internet. [Publication initiale] Le 13 mai 2025, Ivanti a publié deux avis de sécurité concernant les vulnérabilités CVE-2025-4427 et CVE-2025-4428. L'utilisation combinée de ces deux vulnérabilités permet...

    Lire l'article sur CERT-FR — Alertes
  • 13 mai 2025
    CERT-FR — Alertes
    Vulnérabilité dans les produits Fortinet (13 mai 2025)

    Le 13 mai 2025, Fortinet a publié un avis de sécurité concernant la vulnérabilité CVE-2025-32756. Celle-ci permet à un attaquant non authentifié d'exécuter du code arbitraire à distance. L'éditeur indique que cette vulnérabilité est activement exploitée. Les exploitations constatées jusqu'ici...

    Lire l'article sur CERT-FR — Alertes

Avril 2025

  • 28 avr. 2025
    CERT-FR — Alertes
    Vulnérabilité dans SAP NetWeaver (28 avril 2025)

    Le 24 avril 2025, SAP a publié un bulletin de sécurité relatif à la vulnérabilité CVE-2025-31324 qui permet l'exécution de code arbitraire à distance pour un utilisateur non authentifié. Cette vulnérabilité est provoquée par un contournement de la politique de sécurité qui permet de télécharger...

    Lire l'article sur CERT-FR — Alertes
  • 11 avr. 2025
    CERT-FR — Alertes
    Activités de post-exploitation dans Fortinet FortiGate (11 avril 2025)

    Fortinet a publié le 10 avril 2025 un billet de blogue [1] indiquant l'utilisation d'une technique de post-exploitation qui permet une atteinte à la confidentialité des données de l'ensemble du système des équipements Fortigate affectés. Cette technique repose sur l'utilisation d'un lien...

    Lire l'article sur CERT-FR — Alertes
  • 3 avr. 2025
    CERT-FR — Alertes
    [MàJ] Vulnérabilité dans les produits Ivanti (03 avril 2025)

    **\[Mise à jour du 11 avril 2025\]** Le CERT-FR a connaissance d'une preuve de concept publique permettant de provoquer une exécution de code arbitraire à distance. **[Mise à jour du 04 avril 2025]** Le CERT-FR a connaissance d'une preuve de concept publique permettant de provoquer un arrêt du...

    Lire l'article sur CERT-FR — Alertes

Janvier 2025

  • 14 janv. 2025
    CERT-FR — Alertes
    [MàJ] Vulnérabilité dans les produits Fortinet (14 janvier 2025)

    \[Mise à jour du 28 janvier 2025\] Une preuve de concept permettant l'exploitation de cette vulnérabilité est disponible publiquement. Le 14 janvier 2025, Fortinet a publié un avis de sécurité concernant la vulnérabilité critique CVE-2024-55591 affectant FortiOS et FortiProxy. Elle permet à un...

    Lire l'article sur CERT-FR — Alertes
  • 9 janv. 2025
    CERT-FR — Alertes
    [MàJ] Vulnérabilité dans les produits Ivanti (09 janvier 2025)

    Une vulnérabilité jour-zéro de type débordement de pile a été découverte dans Ivanti Connect Secure (ICS), Policy Secure (IPS), Neurons for Zero Trust Access (ZTA) gateways. Cette vulnérabilité, d'identifiant CVE-2025-0282, permet à un attaquant non authentifié de provoquer une exécution de code...

    Lire l'article sur CERT-FR — Alertes

Novembre 2024

  • 15 nov. 2024
    CERT-FR — Alertes
    [MàJ] Multiples vulnérabilités sur l'interface d'administration des équipements Palo Alto Networks (15 novembre 2024)

    Le 8 novembre 2024, Palo Alto Networks a publié un avis de sécurité relatif à une vulnérabilité critique dans certains pare-feux Palo Alto Networks. Elle permet à un attaquant non authentifié d'exécuter du code arbitraire à distance sur l'interface d'administration des équipements. L'éditeur...

    Lire l'article sur CERT-FR — Alertes

Octobre 2024

  • 23 oct. 2024
    CERT-FR — Alertes
    [MàJ] Multiples vulnérabilités dans Fortinet FortiManager (23 octobre 2024)

    **[Mise à jour du 14 janvier 2025]** **Publication des correctifs** Le 14 janvier 2025, Fortinet a publié un avis de sécurité relatif à la vulnérabilité CVE-2024-50566 qui correspond à la vulnérabilité de type jour-zéro pour laquelle une preuve de concept a été publiée en novembre 2024. Des...

    Lire l'article sur CERT-FR — Alertes
  • 22 oct. 2024
    CERT-FR — Alertes
    Exploitations de vulnérabilités dans Ivanti Cloud Services Appliance (CSA) (22 octobre 2024)

    Ivanti a publié plusieurs avis de sécurité sur des vulnérabilités affectant CSA qui sont activement exploitées : * le 10 septembre 2024, Ivanti a publié un avis de sécurité concernant la vulnérabilité CVE-2024-8190 qui permet à un attaquant, authentifié en tant qu'administrateur, d'exécuter du...

    Lire l'article sur CERT-FR — Alertes

Septembre 2024

  • 27 sept. 2024
    CERT-FR — Alertes
    [MàJ] Vulnérabilités affectant OpenPrinting CUPS (27 septembre 2024)

    **[Mise à jour du 10 octobre 2024]** Le 28 septembre 2024, Elastic Security Labs a publié des règles de détection au format propriétaire de l'éditeur (cf. section Documentation), qui sont confirmées par les analyses du CERT-FR pour la détection des attaques connues. **[Publication initiale]** De...

    Lire l'article sur CERT-FR — Alertes
  • 10 sept. 2024
    CERT-FR — Alertes
    Vulnérabilité dans SonicWall (10 septembre 2024)

    Le 22 août 2024, Sonicwall a publié un correctif concernant la vulnérabilité critique CVE-2024-40766 affectant les pare-feux Sonicwall génération 5, 6 et 7. Cette vulnérabilité, de type contrôle d'accès défaillant, permet à un attaquant de provoquer un déni de service à distance, une atteinte à...

    Lire l'article sur CERT-FR — Alertes

Août 2024

  • 9 août 2024
    CERT-FR — Alertes
    Multiples vulnérabilités dans Roundcube (09 août 2024)

    Le 4 août 2024, Roundcube a publié des correctifs concernant les vulnérabilités critiques CVE-2024-42008 et CVE-2024-42009 affectant son serveur de courriel. Ces vulnérabilités permettent des injections de code indirectes à distance (XSS) qui peuvent, par exemple, conduire à la récupération du...

    Lire l'article sur CERT-FR — Alertes

Juillet 2024

  • 1 juil. 2024
    CERT-FR — Alertes
    Vulnérabilité dans OpenSSH (01 juillet 2024)

    Le 1 juillet 2024, OpenSSH a publié un avis de sécurité concernant la vulnérabilité critique CVE-2024-6387. Cette vulnérabilité permet à un attaquant non authentifié d'exécuter du code arbitraire à distance avec les privilèges *root*. L'éditeur précise que les versions 8.5p1 à 9.7p1 sont...

    Lire l'article sur CERT-FR — Alertes

Mai 2024

  • 30 mai 2024
    CERT-FR — Alertes
    [MàJ] Vulnérabilité dans les produits Check Point (30 mai 2024)

    [Mise à jour du 31 mai 2024] Des preuves de concept sont désormais disponibles publiquement sur Internet. De plus, l'éditeur indique avoir détecté des tentatives de compromission à partir du 7 avril 2024. **[Publication Initiale]** Une vulnérabilité a été découverte dans les produits Check Point....

    Lire l'article sur CERT-FR — Alertes

Avril 2024

  • 25 avr. 2024
    CERT-FR — Alertes
    Multiples vulnérabilités dans les produits Cisco (25 avril 2024)

    Le 24 avril 2024, Cisco a publié trois avis de sécurité concernant des vulnérabilités affectant les équipements de sécurité ASA et FTD. Deux d'entre eux concernent les vulnérabilités CVE-2024-20353 et CVE-2024-20359 qui sont activement exploitées dans le cadre d'attaques ciblées. La vulnérabilité...

    Lire l'article sur CERT-FR — Alertes
  • 12 avr. 2024
    CERT-FR — Alertes
    [MàJ] Vulnérabilité dans Palo Alto Networks GlobalProtect (12 avril 2024)

    \[Mise à jour du 10 mai 2024\] Le CERT-FR est intervenu pour le traitement d'une compromission par rançongiciel au sein d'une entité française. Dans le cadre de cette attaque, la vulnérabilité a été exploitée pour ensuite réaliser une latéralisation dans le système d'information de la victime et...

    Lire l'article sur CERT-FR — Alertes

Février 2024

  • 15 févr. 2024
    CERT-FR — Alertes
    [MàJ] Vulnérabilité dans Microsoft Outlook (15 février 2024)

    \[Mise à jour du 15 mars 2024\] Ajout de précision concernant les défi-réponses NTLM \[Mise à jour du 22 février 2024\] Ajout de recommandations et de précisions sur le fonctionnement de la vulnérabilité. La vulnérabilité CVE-2024-21413 permet à un attaquant de contourner les mesures de sécurité...

    Lire l'article sur CERT-FR — Alertes
  • 9 févr. 2024
    CERT-FR — Alertes
    [MàJ] Vulnérabilité dans Fortinet FortiOS (09 février 2024)

    \[Mise à jour du 19 mars 2024\] Le CERT-FR a connaissance de codes d'exploitation publics et de nouvelles tentatives d'exploitation. Le 8 février 2024, Fortinet a publié l'avis de sécurité concernant la vulnérabilité critique CVE-2024-21762 affectant le VPN SSL de FortiOS. Cette vulnérabilité...

    Lire l'article sur CERT-FR — Alertes
  • 5 févr. 2024
    CERT-FR — Alertes
    [MàJ] Incident affectant les solutions AnyDesk (05 février 2024)

    \[Mise à jour du 27 février 2024\] Le 29 janvier 2024 l'ANSSI a été alertée par le BSI que l'éditeur AnyDesk Software GmbH a été victime d'une fuite de données. Le code source des applications développées par l'éditeur ainsi que des certificats et clés privées pourraient avoir été dérobés. De...

    Lire l'article sur CERT-FR — Alertes

Janvier 2024

  • 12 janv. 2024
    CERT-FR — Alertes
    [MàJ] Multiples Vulnérabilités dans GitLab (12 janvier 2024)

    \[Mise à jour du 29 janvier 2024\] Le 25 janvier 2024, l'éditeur a publié un avis de sécurité concernant plusieurs vulnérabilités affectant GitLab CE et EE. La vulnérabilité CVE-2024-0402 est considérée critique avec un score CVSSv3 de 9,9. Elle permet à un attaquant authentifié d'écrire des...

    Lire l'article sur CERT-FR — Alertes
  • 11 janv. 2024
    CERT-FR — Alertes
    [MàJ] Multiples vulnérabilités dans Ivanti Connect Secure et Policy Secure Gateways (11 janvier 2024)

    [Mise à jour du 4 mars 2024] Ivanti a publié le 29 février des recommandations de résolution pour les Ivanti Connect Secure ou Policy Secure en machine virtuelle [16]. [Mise à jour du 15 février 2024] l'éditeur a publié le 15 février des correctifs pour les versions suivantes, qui n'en...

    Lire l'article sur CERT-FR — Alertes

Octobre 2023

  • 23 oct. 2023
    CERT-FR — Alertes
    [MàJ] Vulnérabilité dans Citrix NetScaler ADC et NetScaler Gateway (23 octobre 2023)

    \[Mise à jour du 22 novembre 2023\] L'éditeur a publié un document \[3\] le 20 novembre 2023 listant les différents journaux à analyser ainsi que les éléments à rechercher pour identifier une activité pouvant être liée à une compromission. Par ailleurs, la CISA a publié un avis de sécurité le 21...

    Lire l'article sur CERT-FR — Alertes

Flèches pour naviguer, Entrée pour ouvrir, Échap pour fermer