| | CVE-2026-63509 | Microsoft | critical | 9.9 | 0.6%
| | Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over… | Aug 20, 2026 | Sep 4, 2026 |
| | CVE-2026-65770 | Microsoft | critical | 10.0 | 0.6%
| | Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed … | Aug 20, 2026 | Aug 25, 2026 |
| | CVE-2026-65801 | Microsoft | critical | 10.0 | 0.5%
| | Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to e… | Aug 20, 2026 | Aug 24, 2026 |
| | CVE-2026-65816 | Microsoft | critical | 10.0 | 0.5%
| | Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevat… | Aug 20, 2026 | Aug 24, 2026 |
| | CVE-2026-66309 | Microsoft | critical | 9.1 | 0.5%
| | Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges ov… | Aug 20, 2026 | Aug 24, 2026 |
| | CVE-2026-66800 | Microsoft | high | 8.6 | 0.5%
| | Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose… | Aug 20, 2026 | Aug 24, 2026 |
| | CVE-2026-68782 | Microsoft | critical | 9.9 | 0.5%
| | Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Da… | Aug 20, 2026 | Aug 24, 2026 |
| | CVE-2026-68789 | Microsoft | critical | 9.9 | 0.5%
| | Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Da… | Aug 20, 2026 | Aug 24, 2026 |
| | CVE-2026-69400 | Microsoft | critical | 9.6 | 0.6%
| | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps a… | Aug 20, 2026 | Aug 24, 2026 |
| | CVE-2026-69419 | Microsoft | high | 8.5 | 0.4%
| | Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to exe… | Aug 20, 2026 | Sep 4, 2026 |
| | CVE-2026-69519 | Microsoft | high | 8.6 | 0.6%
| | Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose infor… | Aug 20, 2026 | Aug 25, 2026 |
| | CVE-2026-69543 | Microsoft | high | 8.5 | 0.3%
| | Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevat… | Aug 20, 2026 | Aug 26, 2026 |
| | CVE-2026-69555 | Microsoft | critical | 10.0 | 0.4%
| | Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a ne… | Aug 20, 2026 | Aug 24, 2026 |
| | CVE-2026-69558 | Microsoft | high | 8.6 | 0.5%
| | Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized … | Aug 20, 2026 | Aug 25, 2026 |
| | CVE-2026-69836 | Microsoft | critical | 10.0 | 1.6%
| | Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute c… | Aug 20, 2026 | Aug 25, 2026 |
| | CVE-2026-69851 | Microsoft | critical | 9.9 | 0.4%
| | Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevat… | Aug 20, 2026 | Aug 25, 2026 |
| | CVE-2026-69855 | Microsoft | high | 7.7 | 0.5%
| | Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to di… | Aug 20, 2026 | Sep 8, 2026 |
| | CVE-2026-70105 | Microsoft | medium | 6.5 | 0.5%
| | Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose infor… | Aug 20, 2026 | Sep 4, 2026 |
| | CVE-2026-77648 | Red Hat | low | 2.2 | 0.2%
| | In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that
bypass import_f… | Aug 20, 2026 | Aug 20, 2026 |
| | CVE-2026-79992 | Red Hat | high | 7.8 | 0.1%
| | A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing mal… | Aug 21, 2026 | Aug 21, 2026 |
| | CVE-2026-74582 | Red Hat | high | 7.0 | 0.1%
| | In the Linux kernel, the following vulnerability has been resolved:
packet: use consistent hard_head… | Aug 21, 2026 | Aug 21, 2026 |
| | CVE-2026-74580 | Red Hat | high | 7.3 | 0.1%
| | In the Linux kernel, the following vulnerability has been resolved:
vhost: reset the vring metadata … | Aug 21, 2026 | Aug 21, 2026 |
| | CVE-2026-74583 | Red Hat | high | 7.8 | 0.1%
| | In the Linux kernel, the following vulnerability has been resolved:
net/sched: cls_route: fix fastma… | Aug 21, 2026 | Aug 21, 2026 |
| | CVE-2026-74581 | Red Hat | high | 7.8 | 0.4%
| ✓ Fix | In the Linux kernel, the following vulnerability has been resolved:
net: ipv6: clear suppressed fib6… | Aug 21, 2026 | Aug 21, 2026 |
| | CVE-2026-77680 | Red Hat | medium | 5.3 | 0.3%
| | An algorithmic complexity flaw exists in libsoup's HTTP Range header processing that persists after … | Aug 21, 2026 | Aug 21, 2026 |
| | CVE-2026-79655 | Red Hat | high | 7.8 | 0.1%
| | A flaw was found in sos clean, a utility within the sos package. This vulnerability allows a local a… | Aug 21, 2026 | Aug 21, 2026 |
| | CVE-2026-74866 | Red Hat | medium | 5.8 | 0.2%
| | @fastify/busboy is a multipart form-data parser for Node.js. Its multipart part-header parser splits… | Aug 21, 2026 | Aug 21, 2026 |
| | CVE-2026-47359 | Apache | high | 8.8 | 1.1%
| | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerabi… | Aug 21, 2026 | Aug 27, 2026 |
| | CVE-2026-50112 | Apache | high | 8.8 | 0.5%
| | SSRF via Metalink Mirror URL Resolution:
An authenticated tenant can register a template pointing t… | Aug 21, 2026 | Aug 27, 2026 |
| | CVE-2026-50222 | Apache | high | 7.5 | 0.3%
| | Missing Authorization, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in A… | Aug 21, 2026 | Aug 27, 2026 |
| | CVE-2026-59085 | Apache | critical | 9.1 | 0.3%
| | Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook module, exploitable … | Aug 21, 2026 | Aug 27, 2026 |
| | CVE-2026-59655 | Apache | high | 7.5 | 0.3%
| | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAut… | Aug 21, 2026 | Aug 27, 2026 |
| | CVE-2026-59657 | Apache | high | 7.5 | 0.2%
| | Cleartext Storage of Sensitive Information vulnerability in Apache CloudStack with AsyncJob storage … | Aug 21, 2026 | Aug 27, 2026 |
| | CVE-2026-59780 | Apache | high | 7.5 | 0.3%
| | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's LDAP… | Aug 21, 2026 | Aug 27, 2026 |
| | CVE-2026-59799 | Apache | high | 8.8 | 0.3%
| | Improper Privilege Management vulnerability in Apache CloudStack's Two-factor authentication plugin … | Aug 21, 2026 | Aug 27, 2026 |
| | CVE-2026-61397 | Apache | high | 7.5 | 0.3%
| | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAut… | Aug 21, 2026 | Aug 27, 2026 |
| | CVE-2026-61398 | Apache | critical | 9.1 | 0.3%
| | Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Instance… | Aug 21, 2026 | Aug 27, 2026 |
| | CVE-2026-61399 | Apache | medium | 4.8 | 0.3%
| | Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Lock Use… | Aug 21, 2026 | Aug 27, 2026 |
| | CVE-2026-61400 | Apache | high | 8.8 | 1.5%
| | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in… | Aug 21, 2026 | Aug 27, 2026 |
| | CVE-2026-61422 | Apache | medium | 4.3 | 0.2%
| | Authenticated pre-validation SSRF vulnerability in Apache CloudStack's template and ISO registration… | Aug 21, 2026 | Aug 27, 2026 |
| | CVE-2026-62440 | Apache | critical | 9.1 | 0.3%
| | Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service (CKS) plugin, allowi… | Aug 21, 2026 | Aug 27, 2026 |
| | CVE-2026-63046 | Apache | high | 8.8 | 0.4%
| | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in … | Aug 21, 2026 | Aug 27, 2026 |
| | CVE-2026-65613 | Apache | medium | 4.3 | 0.3%
| | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's Webh… | Aug 21, 2026 | Aug 27, 2026 |
| | CVE-2026-66721 | Apache | low | 2.7 | 0.3%
| | Missing authorization issue for domain admins in CloudStack's host tags listing functionality.
D… | Aug 21, 2026 | Aug 27, 2026 |
| | CVE-2026-66722 | Apache | high | 7.2 | 0.3%
| | Improper authorization for CRUD operations on Project Roles and Project Role permissions for domain … | Aug 21, 2026 | Aug 27, 2026 |
| | CVE-2026-66797 | Apache | medium | 5.4 | 0.3%
| | Improper access control in CloudStack's annotation functionality allows unauthorized comment creatio… | Aug 21, 2026 | Aug 27, 2026 |
| | CVE-2026-68745 | Apache | high | 8.1 | 0.1%
| | Certificate validation failures in SAML authentication in Apache CloudStack 4.20.3.0 and 4.22.1.0 on… | Aug 21, 2026 | Aug 27, 2026 |
| | CVE-2026-59296 | Red Hat | medium | 5.9 | 0.2%
| | Using untrusted, non-normalized input as-is for metrics data (such as metric names, tag keys, or tag… | Aug 21, 2026 | Aug 21, 2026 |
| | CVE-2026-59654 | Apache | high | 7.5 | 0.3%
| | Missing Release of Resource after Effective Lifetime vulnerability in Apache CloudStack's scoped glo… | Aug 21, 2026 | Aug 27, 2026 |
| | CVE-2026-48749 | Red Hat | critical | 9.9 | 0.8%
| | Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted… | Aug 21, 2026 | Aug 21, 2026 |