| | CVE-2026-50528 | Microsoft | high | 8.2 | 0.4%
| | Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a … | Jul 14, 2026 | Jul 22, 2026 |
| | CVE-2026-50646 | Microsoft | high | 7.8 | 1.0%
| | Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code local… | Jul 14, 2026 | Jul 24, 2026 |
| | CVE-2026-50648 | Microsoft | high | 7.5 | 0.9%
| | Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attack… | Jul 14, 2026 | Jul 24, 2026 |
| | CVE-2026-50649 | Microsoft | high | 7.8 | 0.9%
| | Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally. | Jul 14, 2026 | Jul 24, 2026 |
| | CVE-2026-50650 | Microsoft | high | 7.8 | 0.3%
| | Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized a… | Jul 14, 2026 | Jul 24, 2026 |
| | CVE-2026-50651 | Microsoft | high | 7.5 | 0.6%
| | Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny… | Jul 14, 2026 | Jul 22, 2026 |
| | CVE-2026-50659 | Microsoft | medium | 6.5 | 0.5%
| | Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing ov… | Jul 14, 2026 | Jul 24, 2026 |
| | CVE-2026-15583 | Grafana | high | 8.6 | 0.5%
| | A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate… | Jul 15, 2026 | Aug 12, 2026 |
| | CVE-2026-35152 | Apache | medium | — | 2.3%
| | A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint)… | Jul 15, 2026 | Aug 6, 2026 |
| | CVE-2026-56287 | Apache | high | 8.1 | 0.3%
| | A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/… | Jul 15, 2026 | Jul 15, 2026 |
| | CVE-2026-57821 | Apache | high | 8.1 | 0.3%
| | A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in… | Jul 15, 2026 | Jul 15, 2026 |
| | CVE-2026-15809 | Red Hat | high | 7.8 | — | | A flaw was found in CRI-O. The fix for a previous vulnerability (CVE-2022-4318) was incorrect, allow… | Jul 15, 2026 | Jul 15, 2026 |
| | CVE-2026-59838 | Fortinet | medium | 5.9 | — | | A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in For… | Jul 15, 2026 | Jul 15, 2026 |
| | CVE-2026-42533 | F5 | high | 8.1 | 3.6%
| | A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching … | Jul 15, 2026 | Aug 10, 2026 |
| | CVE-2026-52865 | F5 | medium | 6.5 | 0.3%
| | When NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remo… | Jul 15, 2026 | Jul 16, 2026 |
| | CVE-2026-55723 | F5 | high | 8.3 | 0.3%
| | When NGINX Ingress Controller is configured with Custom Resource Definitions (CRDs) or Ingress annot… | Jul 15, 2026 | Jul 16, 2026 |
| | CVE-2026-56434 | F5 | medium | 6.5 | 0.4%
| | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulner… | Jul 15, 2026 | Aug 10, 2026 |
| | CVE-2026-59762 | F5 | high | 7.5 | 0.5%
| | When an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause an increase… | Jul 15, 2026 | Aug 6, 2026 |
| | CVE-2026-60062 | F5 | medium | 6.4 | 0.2%
| | The NGINX Agent config_dirs directive allows a low-privileged attacker to gain limited read and writ… | Jul 15, 2026 | Aug 6, 2026 |
| | CVE-2026-60065 | F5 | low | 3.7 | 0.3%
| | When NGINX Plus is configured to use the Message Queuing Telemetry Transport (MQTT) filter module (n… | Jul 15, 2026 | Aug 10, 2026 |
| | CVE-2026-60005 | F5 | high | 8.2 | 0.7%
| | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the … | Jul 15, 2026 | Aug 11, 2026 |
| | CVE-2026-12382 | Red Hat | high | 8.2 | — | | A flaw was found in the AAP Gateway Envoy proxy configuration. The non-mTLS route to EDA event strea… | Jul 15, 2026 | Jul 15, 2026 |
| | CVE-2026-20146 | Cisco | medium | 5.5 | 0.5%
| | A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (IS… | Jul 15, 2026 | Jul 16, 2026 |
| | CVE-2026-20150 | Cisco | high | 8.8 | 0.2%
| | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS en… | Jul 15, 2026 | Aug 14, 2026 |
| | CVE-2026-20153 | Cisco | high | 7.5 | 0.3%
| | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS en… | Jul 15, 2026 | Aug 14, 2026 |
| | CVE-2026-20156 | Cisco | high | 8.1 | 0.3%
| | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS en… | Jul 15, 2026 | Aug 14, 2026 |
| | CVE-2026-20157 | Cisco | high | 7.5 | 0.1%
| | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS en… | Jul 15, 2026 | Aug 14, 2026 |
| | CVE-2026-20158 | Cisco | high | 7.5 | 0.3%
| | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS en… | Jul 15, 2026 | Aug 14, 2026 |
| | CVE-2026-20187 | Cisco | high | 7.5 | 0.3%
| | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS en… | Jul 15, 2026 | Aug 14, 2026 |
| | CVE-2026-20296 | Splunk | high | 8.3 | 0.2%
| | In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform ve… | Jul 15, 2026 | Jul 24, 2026 |
| | CVE-2026-20297 | Splunk | high | 7.2 | 0.5%
| | In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, 9.4.13, and 9.3.14, and Splunk Cloud Pla… | Jul 15, 2026 | Jul 24, 2026 |
| | CVE-2026-20298 | Splunk | medium | 5.3 | 0.2%
| | In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform ve… | Jul 15, 2026 | Jul 24, 2026 |
| | CVE-2026-26032 | Apache | medium | 5.4 | — | | The PackagerResolver of Apache Ivy is able to download online
artifacts and to (re)package them in a… | Jul 15, 2026 | Jul 16, 2026 |
| | CVE-2026-21729 | Grafana | high | 7.5 | 0.3%
| | Loki queries with large limits can cause large memory allocations which can impact the availability … | Jul 16, 2026 | Aug 12, 2026 |
| | CVE-2026-15925 | Red Hat | high | 7.4 | 0.2%
| | A flaw was found in Snowflake Connector for Python. A network-positioned attacker could exploit impr… | Jul 16, 2026 | Jul 16, 2026 |
| | CVE-2026-59860 | Microsoft | high | 8.7 | — | | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.3, Kiota is affected by a code-g… | Jul 16, 2026 | Jul 17, 2026 |
| | CVE-2026-59861 | Microsoft | high | 7.5 | — | | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.0, Kiota's Ruby generator embedd… | Jul 16, 2026 | Jul 17, 2026 |
| | CVE-2026-59862 | Microsoft | high | 7.5 | — | | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.0, Kiota's Python generator let … | Jul 16, 2026 | Jul 17, 2026 |
| | CVE-2026-59859 | Microsoft | high | 8.7 | — | | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.4, Kiota's PHP generator embedde… | Jul 16, 2026 | Jul 17, 2026 |
| | CVE-2026-59865 | Microsoft | critical | 9.3 | — | | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota info` read x-ms-kiota-… | Jul 16, 2026 | Jul 17, 2026 |
| | CVE-2026-59864 | Microsoft | critical | 9.3 | — | | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota plugin add` and `kiota… | Jul 16, 2026 | Jul 17, 2026 |
| | CVE-2026-59866 | Microsoft | critical | 9.3 | — | | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, Kiota emitted x-ms-kiota-info… | Jul 16, 2026 | Jul 17, 2026 |
| | CVE-2026-58643 | Microsoft | medium | 6.1 | 0.2%
| | Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admi… | Jul 16, 2026 | Aug 14, 2026 |
| | CVE-2026-59117 | Microsoft | high | 7.5 | 0.4%
| | Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code o… | Jul 16, 2026 | Jul 30, 2026 |
| | CVE-2026-62826 | Microsoft | medium | 4.6 | 0.2%
| | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of… | Jul 16, 2026 | Jul 22, 2026 |
| | CVE-2026-21770 | Microsoft | medium | 6.5 | 0.1%
| | HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which coul… | Jul 17, 2026 | Jul 17, 2026 |
| | CVE-2026-62764 | Apache | medium | 6.5 | 0.3%
| | Improper Handling of Insufficient Privileges vulnerability in Apache Accumulo.
An authenticated, but… | Jul 17, 2026 | Aug 11, 2026 |
| | CVE-2026-16089 | Red Hat | medium | 5.4 | 0.2%
| | A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs b… | Jul 17, 2026 | Jul 17, 2026 |
| | CVE-2026-56171 | Microsoft | high | 7.1 | 0.6%
| | Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthori… | Jul 17, 2026 | Jul 22, 2026 |
| | CVE-2026-57980 | Microsoft | medium | 5.4 | 0.2%
| | Authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows a… | Jul 17, 2026 | Jul 21, 2026 |