VULNERABILITY / HIGH / 2026-09-28
Citrix NetScaler ADC/Gateway — active exploitation before patches
Audit impact: Adds a pre-patch exposure-window concept and separates two states: current vulnerability remediation and historical compromise assessment. When an authoritative source documents exploitation before patches, an asset exposed during that period should be flagged for compromise assessment without claiming that compromise occurred.
Boundary: The external scan may only report a technology or version when genuinely observable. No PoC, RCE, authentication bypass or active CVE validation. Reconstructing the exposure window and reviewing logs/IOCs requires client authorisation and internal evidence.
Official source: CERT-FR — CERTFR-2026-ALE-011 ↗
TECHNOLOGY-DEBTEXTERNAL-SURFACEPRE-PATCH-EXPOSURE-WINDOWCOMPROMISE-ASSESSMENTREMOTE-CODE-EXECUTIONDETECTION-GAP
INCIDENT / HIGH / 2026-09-03
Hôpital Privé de la Loire — compromised account, excessive privileges and late detection
Audit impact: Strengthens paid controls for MFA, authorisation scope, least privilege, abnormal-access detection and bulk consultation/extraction detection. Blast Radius should measure how much data one compromised account can reach.
Boundary: MFA, authorisation scope, SIEM and internal blast radius are not inferred from a public scan: authorised internal evidence is required.
Official source: CNIL ↗
IDENTITYMFALEAST-PRIVILEGEDETECTION-GAPBULK-ACCESSBLAST-RADIUS
VULNERABILITY / HIGH / 2026-09-03
SPIP — critical vulnerabilities before 4.4.23
Audit impact: Adds passive SPIP fingerprinting. If a reliable version below 4.4.23 is observed, the detailed audit should correlate it with the CERT-FR advisory. Without reliable version evidence: detect the technology but do not claim vulnerability.
Boundary: No administration-console probing, brute force or exploitation attempt.
Official source: CERT-FR — CERTFR-2026-AVI-1109 ↗
TECHNOLOGY-DEBTSPIPVERSION-EXPOSUREREMOTE-CODE-EXECUTIONPRIVILEGE-ESCALATION
REGULATION / HIGH / 2026-08-01
Cyber Resilience Act — reporting obligations from 11 September 2026
Audit impact: Adds a paid Vulnerability & Incident Reporting Readiness module for applicable manufacturers: product owner, reporting channel, 24h/72h workflow, affected versions, corrective measure and notification evidence.
Boundary: An Internet scan must never claim CRA compliance. The module is enabled only after confirming that the client is in scope.
Official source: Commission européenne ↗
CRAVULNERABILITY-REPORTINGINCIDENT-REPORTING24H72HPRODUCT-SECURITY
STRATEGIC / MEDIUM / 2026-09-03
ANSSI / G7 — prepare the transition to post-quantum cryptography
Audit impact: Adds a progressive crypto inventory: TLS, signature algorithms, key type/size, certificate chain and observable dependencies. Show “Crypto agility: review recommended” without score penalty at this stage.
Boundary: Standard pre-quantum cryptography is not presented as a current vulnerability. This is a readiness and crypto-agility indicator.
Official source: ANSSI ↗
CRYPTOGRAPHYCRYPTO-AGILITYPQCTLSCERTIFICATE-INVENTORY
INCIDENT / HIGH / 2026-08-14
DGFiP — stolen credentials, authorised third-party account and data extraction
Audit impact: Strengthens review of trust paths associated with authorised third-party accounts, the access scope of a compromised identity and the ability to revoke external access quickly. The subsequent suspension of external SPDC access illustrates the importance of an operational containment mechanism.
Boundary: The external scan may identify a publicly observable portal or identity provider, but cannot infer third-party privileges, MFA coverage or actual revocation capability. No credential testing, MFA bypass or partner-access testing is performed without explicit authorisation.
Official source: Ministère de l’Économie et des Finances ↗
IDENTITYCREDENTIAL-ABUSETHIRD-PARTY-TRUSTEXTERNAL-ACCESSDATA-EXPOSUREACCESS-REVOCATIONBLAST-RADIUS
INCIDENT / HIGH / 2026-02-18
FICOBA — compromised authorised account and banking-data access
Audit impact: Reinforces measurement of the authorisation scope associated with one compromised account in the authorised internal audit.
Boundary: Actual authorisation scope requires authorised internal access.
Official source: Ministère de l’Économie et des Finances ↗
IDENTITYPRIVILEGED-ACCESSDATA-EXPOSUREBLAST-RADIUS
INCIDENT / MEDIUM / 2026-07-13
ANSSI — Turla targeting and compromise of French entities
Audit impact: Strengthens external-surface inventory and technology-debt assessment without turning the public audit into an intrusive penetration test.
Boundary: No exploitation, persistence or intrusive action is reproduced.
Official source: ANSSI ↗
RECONNAISSANCEEXTERNAL-SURFACETECHNOLOGY-DEBTPERSISTENCE