| | CVE-2026-65945 | Apache | medium | 6.5 | 0.3%
| | Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0
Users are recommended to upgra… | Aug 10, 2026 | Aug 17, 2026 |
| | CVE-2026-65948 | Apache | high | 7.3 | 0.3%
| | UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8.0.
Note: UnixAuth is NOT a … | Aug 10, 2026 | Aug 17, 2026 |
| | CVE-2026-66801 | Red Hat | critical | 9.9 | — | ✓ Fix | A flaw was found in multicluster-global-hub. An attacker who compromises a managed hub can leverage … | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-71577 | Red Hat | medium | 6.3 | — | | A flaw was found in multicluster-global-hub. During a ManagedClusterMigration, the system incorrectl… | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-71576 | Red Hat | high | 8.5 | — | | A flaw was found in multicluster-global-hub. The manager component improperly validates the source i… | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-68870 | Microsoft | medium | — | 0.1%
| | The Azure Key Vault secrets backend in Apache Airflow's Microsoft Azure provider resolved a team-sco… | Aug 10, 2026 | Aug 11, 2026 |
| | CVE-2026-13717 | Red Hat | high | 8.8 | — | | A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway. Improper configuration of the Gat… | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-14450 | Red Hat | high | 9.9 | — | | A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to bypass the… | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-15467 | Red Hat | high | 8.1 | — | | A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user with… | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-15581 | Red Hat | high | 8.0 | — | | A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the … | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-16456 | Red Hat | high | 6.5 | — | | A flaw was found in the `odh-model-controller`. An authenticated user with permissions to create cus… | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-18608 | Red Hat | high | 8.7 | — | | A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which de… | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-18611 | Red Hat | medium | 7.5 | — | | A flaw was found in the Data Science Pipelines Operator. This vulnerability allows an unauthenticate… | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-18617 | Red Hat | high | 8.8 | — | | A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a vul… | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-18618 | Red Hat | medium | 7.5 | — | | A flaw was found in ml-metadata. The statically-linked gRPC stack in ml-metadata is outdated, making… | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-18620 | Red Hat | medium | 7.1 | — | | A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper au… | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-18621 | Red Hat | high | 7.6 | — | | A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can b… | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-18941 | Red Hat | high | 7.7 | — | | A flaw was found in Feast and feast-operator. The default configuration for both the Feast SDK and t… | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-18942 | Red Hat | high | 5.5 | — | | A flaw was found in the Feast operator. A malicious tenant could inject arbitrary code into their fe… | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-18948 | Red Hat | critical | 9.9 | — | | A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored i… | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-18949 | Red Hat | critical | 8.8 | — | | A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the da… | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-18950 | Red Hat | critical | 8.8 | — | | A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerabilit… | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-18951 | Red Hat | critical | 8.8 | — | | A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI ov… | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-18982 | Red Hat | critical | 8.8 | — | | A flaw was found in the RHOAI training-operator. This vulnerability allows a user with standard edit… | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-68871 | Apache | medium | 6.5 | 0.2%
| | The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connec… | Aug 10, 2026 | Aug 17, 2026 |
| | CVE-2026-68872 | Apache | medium | 6.5 | 0.2%
| | The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon prov… | Aug 10, 2026 | Aug 17, 2026 |
| | CVE-2026-18947 | Red Hat | high | 8.5 | — | | A flaw was found in Feast. An authorization bypass vulnerability exists in the /materialize and /mat… | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2025-32736 | ForgeRock | medium | — | 0.2%
| | Cross-Site Request Forgery weaknesses in the Administrative Console of PingFederate versions before … | Aug 10, 2026 | Sep 9, 2026 |
| | CVE-2026-66799 | Red Hat | high | 7.1 | — | | A flaw was found in the cluster-backup-operator. A privileged user with administrative access to a s… | Aug 11, 2026 | Aug 11, 2026 |
| | CVE-2026-19516 | Grafana | critical | 9.1 | 0.2%
| | A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound re… | Aug 11, 2026 | Aug 12, 2026 |
| | CVE-2026-5304 | Red Hat | medium | 5.7 | 0.2%
| | A flaw was found in Axis devices. An attacker could exploit a lack of input validation in an ACAP (A… | Aug 11, 2026 | Aug 11, 2026 |
| | CVE-2026-10579 | Red Hat | critical | 9.8 | 0.4%
| | A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged … | Aug 11, 2026 | Aug 11, 2026 |
| | CVE-2026-15554 | Red Hat | high | 7.4 | 0.2%
| | the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any sh… | Aug 11, 2026 | Aug 11, 2026 |
| | CVE-2026-15555 | Red Hat | high | 8.8 | 0.2%
| | A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicat… | Aug 11, 2026 | Aug 11, 2026 |
| | CVE-2026-15560 | Red Hat | high | 8.1 | 0.3%
| | when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs … | Aug 11, 2026 | Aug 11, 2026 |
| | CVE-2026-4757 | Red Hat | high | 7.2 | 0.4%
| | A flaw was found in Axis. An attacker with an administrator-privileged service account could exploit… | Aug 11, 2026 | Aug 11, 2026 |
| | CVE-2026-15561 | Red Hat | high | 7.5 | 0.3%
| | A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and cou… | Aug 11, 2026 | Aug 11, 2026 |
| | CVE-2026-15562 | Red Hat | high | 7.5 | 0.3%
| | A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who can reach :8080 (or … | Aug 11, 2026 | Aug 11, 2026 |
| | CVE-2026-15563 | Red Hat | high | 7.4 | 0.2%
| | A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without auth… | Aug 11, 2026 | Aug 11, 2026 |
| | CVE-2026-15556 | Red Hat | high | 8.1 | 0.2%
| | A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion … | Aug 11, 2026 | Aug 11, 2026 |
| | CVE-2026-15567 | Red Hat | high | 7.5 | 0.3%
| | A flaw was found in Wildfly. A remote unauthenticated attacker can trigger OutOfMemoryError as CSIv2… | Aug 11, 2026 | Aug 11, 2026 |
| | CVE-2026-15565 | Red Hat | high | 7.5 | 0.4%
| | A flaw was found in Undertow. A remote attacker can cause Out of Memory on websockets endpoint witho… | Aug 11, 2026 | Aug 11, 2026 |
| | CVE-2026-72693 | Red Hat | medium | 7.8 | 0.1%
| | `openvt -u` is intended to identify the owner of the current VT and then execute `login` as that use… | Aug 11, 2026 | Aug 11, 2026 |
| | CVE-2026-72694 | Red Hat | high | 7.1 | 0.1%
| | A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops priv… | Aug 11, 2026 | Aug 11, 2026 |
| | CVE-2026-71218 | Red Hat | medium | 5.3 | 0.3%
| | A flaw was found in iperf3. A remote unauthenticated attacker can exploit a vulnerability in the `JS… | Aug 11, 2026 | Aug 11, 2026 |
| | CVE-2026-71217 | Red Hat | high | 7.5 | 0.3%
| | A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted cont… | Aug 11, 2026 | Aug 11, 2026 |
| | CVE-2026-19546 | Red Hat | high | 8.8 | — | | A flaw was found in DBI. This is a fix for a partial fix for CVE-2026-14380 for RHEL 9.8.z and 10.2.… | Aug 11, 2026 | Aug 11, 2026 |
| | CVE-2026-50236 | Red Hat | high | 7.4 | — | | An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supp… | Aug 11, 2026 | Aug 11, 2026 |
| | CVE-2026-50237 | Red Hat | high | 7.4 | — | | A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog … | Aug 11, 2026 | Aug 11, 2026 |
| | CVE-2026-33921 | Red Hat | medium | 5.2 | 0.1%
| | A flaw was found in the Npcap driver. The Windows installer for Arc deployed Npcap with insecure def… | Aug 11, 2026 | Aug 11, 2026 |