| | CVE-2026-58075 | Veeam | medium | — | 0.3%
| | A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which ca… | Aug 4, 2026 | Sep 3, 2026 |
| | CVE-2026-64630 | Veeam | medium | — | 0.2%
| | A vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared… | Aug 4, 2026 | Sep 3, 2026 |
| | CVE-2026-64631 | Veeam | medium | — | 0.3%
| | A vulnerability allowing a low-privileged user to inject SQL and extract database contents. | Aug 4, 2026 | Sep 3, 2026 |
| | CVE-2026-64633 | Veeam | medium | — | 0.5%
| | A vulnerability allowing remote unauthenticated code execution on the agent host. | Aug 4, 2026 | Sep 3, 2026 |
| | CVE-2026-64634 | Veeam | medium | — | 0.1%
| | A vulnerability allowing local privilege escalation to the Reporter service context. | Aug 4, 2026 | Sep 3, 2026 |
| | CVE-2026-16442 | Red Hat | high | 7.4 | — | ✓ Fix | A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federati… | Aug 5, 2026 | Aug 5, 2026 |
| | CVE-2026-16102 | Red Hat | high | 8.1 | — | ✓ Fix | A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and acc… | Aug 5, 2026 | Aug 5, 2026 |
| | CVE-2026-16100 | Red Hat | medium | 6.5 | — | ✓ Fix | A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the syst… | Aug 5, 2026 | Aug 5, 2026 |
| | CVE-2026-16071 | Red Hat | medium | 5.4 | — | ✓ Fix | A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities… | Aug 5, 2026 | Aug 5, 2026 |
| | CVE-2026-15573 | Red Hat | high | 8.1 | — | ✓ Fix | A flaw was found in Keycloak's Authorization Services. The component responsible for matching reques… | Aug 5, 2026 | Aug 5, 2026 |
| | CVE-2026-15572 | Red Hat | high | 8.8 | — | ✓ Fix | A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Al… | Aug 5, 2026 | Aug 5, 2026 |
| | CVE-2026-66257 | Apache | high | 7.5 | 0.3%
| | A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaus… | Aug 5, 2026 | Aug 7, 2026 |
| | CVE-2026-66273 | Apache | high | 7.5 | 0.3%
| | A pre-authentication attacker could leverage type size/count handling to cause excessive allocation … | Aug 5, 2026 | Aug 7, 2026 |
| | CVE-2026-67465 | Apache | high | 7.5 | 0.4%
| | A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaus… | Aug 5, 2026 | Aug 7, 2026 |
| | CVE-2026-67551 | Apache | high | 7.5 | 0.5%
| | pre-authentication attacker could leverage type size/count handling to cause excessive allocation le… | Aug 5, 2026 | Aug 7, 2026 |
| | CVE-2026-67588 | Apache | high | 7.5 | 0.5%
| | A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaus… | Aug 5, 2026 | Aug 7, 2026 |
| | CVE-2026-67589 | Apache | high | 7.5 | 0.5%
| | A pre-authentication attacker could leverage type size/count handling to cause excessive allocation … | Aug 5, 2026 | Aug 7, 2026 |
| | CVE-2026-68060 | Apache | high | 7.5 | 0.5%
| | A pre-authentication attacker could leverage type size/count handling to cause excessive allocation … | Aug 5, 2026 | Aug 7, 2026 |
| | CVE-2026-68074 | Apache | high | 7.5 | 0.4%
| | A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaus… | Aug 5, 2026 | Aug 7, 2026 |
| | CVE-2026-71202 | Red Hat | high | 7.5 | — | | A flaw was found in the `raster` Rust crate. A remote attacker could exploit an integer underflow vu… | Aug 5, 2026 | Aug 5, 2026 |
| | CVE-2026-66274 | Apache | high | 7.5 | 0.5%
| | A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially … | Aug 5, 2026 | Aug 7, 2026 |
| | CVE-2026-66275 | Apache | medium | 6.5 | 0.4%
| | An authenticated attacker could exceed the session flow control incoming window potentially leading … | Aug 5, 2026 | Aug 7, 2026 |
| | CVE-2026-66276 | Apache | medium | 6.5 | 0.3%
| | An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessi… | Aug 5, 2026 | Aug 7, 2026 |
| | CVE-2026-66277 | Apache | medium | 6.5 | 0.3%
| | It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling … | Aug 5, 2026 | Aug 7, 2026 |
| | CVE-2026-67552 | Apache | high | 7.5 | 0.4%
| | A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially … | Aug 5, 2026 | Aug 7, 2026 |
| | CVE-2026-67553 | Apache | medium | 6.5 | 0.3%
| | An authenticated attacker could exceed the session flow control incoming window potentially leading … | Aug 5, 2026 | Aug 7, 2026 |
| | CVE-2026-67554 | Apache | medium | 6.5 | 0.3%
| | An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessi… | Aug 5, 2026 | Aug 7, 2026 |
| | CVE-2026-67555 | Apache | medium | 6.5 | 0.3%
| | It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling … | Aug 5, 2026 | Aug 7, 2026 |
| | CVE-2026-67590 | Apache | high | 7.5 | 0.5%
| | A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially … | Aug 5, 2026 | Aug 7, 2026 |
| | CVE-2026-67591 | Apache | medium | 6.5 | 0.4%
| | An authenticated attacker could exceed the session flow control incoming window potentially leading … | Aug 5, 2026 | Aug 7, 2026 |
| | CVE-2026-67592 | Apache | high | 7.5 | 0.5%
| | It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling … | Aug 5, 2026 | Aug 7, 2026 |
| | CVE-2026-68073 | Apache | high | 7.5 | 0.2%
| | A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially … | Aug 5, 2026 | Aug 6, 2026 |
| | CVE-2026-68075 | Apache | medium | 6.5 | 0.2%
| | An authenticated attacker could exceed the session flow control incoming window potentially leading … | Aug 5, 2026 | Aug 6, 2026 |
| | CVE-2026-68077 | Apache | medium | 6.5 | 0.2%
| | An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessi… | Aug 5, 2026 | Aug 6, 2026 |
| | CVE-2026-68078 | Apache | medium | 6.5 | 0.3%
| | It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling … | Aug 5, 2026 | Aug 6, 2026 |
| | CVE-2026-68080 | Apache | medium | 6.5 | 0.3%
| | It was not possible to govern the rate at which the broker would respond to an echo flow, enabling a… | Aug 5, 2026 | Aug 6, 2026 |
| | CVE-2026-61483 | Apache | high | 7.5 | 0.8%
| | ** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy.
This issue a… | Aug 5, 2026 | Sep 4, 2026 |
| | CVE-2026-61484 | Apache | critical | 9.8 | 0.6%
| | ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy.
T… | Aug 5, 2026 | Sep 4, 2026 |
| | CVE-2026-61485 | Apache | high | 7.5 | 0.3%
| | ** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size Value vulnerability in Apache … | Aug 5, 2026 | Aug 6, 2026 |
| | CVE-2026-61486 | Apache | critical | 9.8 | 0.6%
| | ** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy.
This is… | Aug 5, 2026 | Sep 4, 2026 |
| | CVE-2026-10090 | Red Hat | high | 9.9 | — | | A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of… | Aug 5, 2026 | Aug 5, 2026 |
| | CVE-2026-10059 | Red Hat | high | 9.1 | — | | A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant admin… | Aug 5, 2026 | Aug 5, 2026 |
| | CVE-2026-71235 | Red Hat | high | 8.8 | — | | A flaw was found in Magistrala's Rules Engine. An authenticated low-privileged user can exploit this… | Aug 5, 2026 | Aug 5, 2026 |
| | CVE-2026-71225 | Red Hat | medium | 6.5 | — | | A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (… | Aug 5, 2026 | Aug 5, 2026 |
| | CVE-2026-71226 | Red Hat | medium | 7.3 | — | | Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an e… | Aug 5, 2026 | Aug 5, 2026 |
| | CVE-2026-71281 | Red Hat | high | 8.8 | — | | A flaw was found in peft. The LoRA-GA and CorDA initialization modules within Hugging Face peft impr… | Aug 5, 2026 | Aug 5, 2026 |
| | CVE-2026-71227 | Red Hat | medium | 5.1 | — | | A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchrono… | Aug 5, 2026 | Aug 5, 2026 |
| | CVE-2026-16443 | Red Hat | high | 7.4 | — | ✓ Fix | A flaw was found in the SAML metadata import functionality of the keycloak-services component, which… | Aug 5, 2026 | Aug 5, 2026 |
| | CVE-2026-49331 | Red Hat | medium | 6.5 | — | | A flaw was found in openshift/oauth-proxy. On paths configured to bypass authentication (skip-auth-r… | Aug 5, 2026 | Aug 5, 2026 |
| | CVE-2026-48834 | Apache | high | 7.5 | 0.2%
| | Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer.
This issue affe… | Aug 5, 2026 | Aug 6, 2026 |