| | CVE-2026-62145 | Check Point | high | 7.5 | 0.4%
| | A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Port… | Jul 22, 2026 | Jul 24, 2026 |
| | CVE-2026-16232 | Check Point | critical | 9.8 | 71.4%
| ⚠ KEV | An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unaut… | Jul 22, 2026 | Aug 10, 2026 |
| | CVE-2026-21723 | Grafana | medium | 5.3 | 0.2%
| | The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) ca… | Jul 23, 2026 | Aug 12, 2026 |
| | CVE-2026-17039 | Red Hat | low | 3.1 | 0.2%
| | A flaw was found in pki-core. The certificate authority (CA) renewal request path does not perform t… | Jul 24, 2026 | Jul 24, 2026 |
| | CVE-2026-35425 | Microsoft | high | 8.0 | 0.5%
| | Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code… | Jul 24, 2026 | Aug 17, 2026 |
| | CVE-2026-49159 | Microsoft | medium | 6.5 | 0.6%
| | Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized a… | Jul 24, 2026 | Jul 29, 2026 |
| | CVE-2026-50517 | Microsoft | critical | 9.9 | 1.3%
| | Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over… | Jul 24, 2026 | Jul 29, 2026 |
| | CVE-2026-54120 | Microsoft | critical | 9.9 | 0.7%
| | Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a … | Jul 24, 2026 | Aug 6, 2026 |
| | CVE-2026-56160 | Microsoft | critical | 9.1 | 0.6%
| | Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate pri… | Jul 24, 2026 | Aug 7, 2026 |
| | CVE-2026-56165 | Microsoft | critical | 9.8 | 0.7%
| | Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over… | Jul 24, 2026 | Jul 30, 2026 |
| | CVE-2026-56167 | Microsoft | high | 8.5 | 0.4%
| | Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privi… | Jul 24, 2026 | Jul 29, 2026 |
| | CVE-2026-56191 | Microsoft | critical | 10.0 | 0.7%
| | Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tamp… | Jul 24, 2026 | Jul 29, 2026 |
| | CVE-2026-58275 | Microsoft | critical | 10.0 | 0.7%
| | Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a netw… | Jul 24, 2026 | Aug 7, 2026 |
| | CVE-2026-62825 | Microsoft | critical | 10.0 | 0.7%
| | Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges ove… | Jul 24, 2026 | Aug 7, 2026 |
| | CVE-2026-56392 | Red Hat | medium | 4.4 | 0.1%
| | A flaw was found in GNU coreutils, specifically in the `unexpand` utility. This vulnerability, a hea… | Jul 24, 2026 | Jul 24, 2026 |
| | CVE-2026-63317 | Apache | medium | 5.6 | 0.3%
| | Arbitrary Class Instantiation via XML Feature Generator Descriptor and Format Name in Apache OpenNLP… | Jul 24, 2026 | Aug 6, 2026 |
| | CVE-2026-66010 | Red Hat | medium | 6.1 | 0.2%
| | A flaw was found in DOMPurify. This vulnerability allows attackers to bypass application security po… | Jul 24, 2026 | Jul 24, 2026 |
| | CVE-2026-9765 | Grafana | high | 7.1 | — | | Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue.
… | Jul 24, 2026 | Jul 24, 2026 |
| | CVE-2026-45811 | Apache | high | 7.5 | 0.3%
| | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBL… | Jul 24, 2026 | Jul 27, 2026 |
| | CVE-2026-45812 | Apache | medium | 6.5 | 0.3%
| | Incorrect Calculation of Buffer Size vulnerability in Apache NimBLE when processing Legacy Advertisi… | Jul 24, 2026 | Jul 27, 2026 |
| | CVE-2026-45813 | Apache | high | 8.8 | 0.3%
| | Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS serv… | Jul 24, 2026 | Jul 27, 2026 |
| | CVE-2026-45815 | Apache | high | 7.5 | 0.4%
| | Reachable Assertion vulnerability in Apache NimBLE.
A specially crafted ATT Read Multiple Variable R… | Jul 24, 2026 | Jul 27, 2026 |
| | CVE-2026-45816 | Apache | high | 7.5 | 0.4%
| | NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event.
This req… | Jul 24, 2026 | Jul 27, 2026 |
| | CVE-2026-46452 | Apache | medium | 5.3 | 0.3%
| | Improper Input Validation vulnerability in Apache NimBLE in Mesh Proxy SAR reassembly could result i… | Jul 24, 2026 | Jul 27, 2026 |
| | CVE-2026-66142 | Apache | high | 7.5 | 0.3%
| | Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or … | Jul 24, 2026 | Jul 27, 2026 |
| | CVE-2026-66143 | Apache | high | 7.5 | 0.3%
| | It is possible to bypass the maximum number of normalized policy alternatives that was introduced in… | Jul 24, 2026 | Jul 27, 2026 |
| | CVE-2026-66144 | Apache | high | 7.5 | 0.3%
| | Although remote policy references are not retrieved during policy normalization, if they are manuall… | Jul 24, 2026 | Jul 27, 2026 |
| | CVE-2026-17059 | Red Hat | medium | 6.5 | 0.2%
| | A flaw was found in the role-users endpoint of the keycloak-services library, which is the core comp… | Jul 24, 2026 | Jul 24, 2026 |
| | CVE-2026-49326 | Apache | medium | 6.5 | 0.2%
| | Missing Authorization vulnerability in Apache HBase thrift and rest delegation service.
A scan oper… | Jul 24, 2026 | Aug 6, 2026 |
| | CVE-2026-56163 | Microsoft | critical | 10.0 | 0.9%
| | Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unautho… | Jul 24, 2026 | Jul 29, 2026 |
| | CVE-2026-57106 | Microsoft | critical | 10.0 | 0.9%
| | Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privil… | Jul 24, 2026 | Jul 29, 2026 |
| | CVE-2026-58630 | Microsoft | critical | 10.0 | 0.8%
| | Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges o… | Jul 24, 2026 | Aug 6, 2026 |
| | CVE-2026-17107 | Red Hat | high | 8.5 | 0.2%
| | A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Manag… | Jul 24, 2026 | Jul 24, 2026 |
| | CVE-2026-62835 | Microsoft | critical | 9.3 | 1.0%
| | Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over … | Jul 24, 2026 | Jul 29, 2026 |
| | CVE-2026-57978 | Microsoft | medium | 5.4 | 0.2%
| | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perfor… | Jul 26, 2026 | Aug 3, 2026 |
| | CVE-2026-57989 | Microsoft | high | 7.4 | 0.4%
| | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclo… | Jul 26, 2026 | Aug 3, 2026 |
| | CVE-2026-57990 | Microsoft | high | 7.4 | 0.9%
| | Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an una… | Jul 26, 2026 | Aug 3, 2026 |
| | CVE-2026-17527 | Red Hat | high | 7.7 | — | | In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to p… | Jul 27, 2026 | Jul 27, 2026 |
| | CVE-2026-17501 | Red Hat | medium | 5.3 | — | | A flaw was found in llama.cpp. A remote attacker could exploit a vulnerability in the JSON-Schema-to… | Jul 27, 2026 | Jul 27, 2026 |
| | CVE-2026-64535 | Red Hat | medium | 6.5 | — | | A use-after-free flaw was found in the Linux kernel's NVMe-over-Fabrics TCP target (nvmet-tcp) drive… | Jul 27, 2026 | Jul 27, 2026 |
| | CVE-2026-16554 | Red Hat | medium | 6.8 | — | | A flaw was found in the cJSON library. On 32-bit platforms, a specially crafted JSON string can caus… | Jul 27, 2026 | Jul 27, 2026 |
| | CVE-2026-41608 | Apache | high | 7.5 | 1.1%
| | Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Pyth… | Jul 27, 2026 | Jul 28, 2026 |
| | CVE-2026-43871 | Apache | high | 7.5 | — | | Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PH… | Jul 27, 2026 | Jul 27, 2026 |
| | CVE-2026-45112 | Apache | high | 7.5 | — | | Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings.
… | Jul 27, 2026 | Jul 27, 2026 |
| | CVE-2026-48144 | Apache | critical | 9.1 | — | | Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings… | Jul 27, 2026 | Jul 28, 2026 |
| | CVE-2026-48145 | Apache | high | 7.5 | — | | Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings.
… | Jul 27, 2026 | Jul 27, 2026 |
| | CVE-2026-48586 | Apache | high | 7.5 | — | | Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++,… | Jul 27, 2026 | Jul 27, 2026 |
| | CVE-2026-49158 | Apache | high | 7.5 | — | | Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby… | Jul 27, 2026 | Jul 27, 2026 |
| | CVE-2026-55968 | Apache | high | 7.5 | — | | Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerabili… | Jul 27, 2026 | Jul 27, 2026 |
| | CVE-2026-55969 | Apache | high | 7.5 | — | | Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Ha… | Jul 27, 2026 | Jul 27, 2026 |