| | CVE-2026-80190 | Apache | medium | — | — | | Apache Allura: stored XSS via SVN code repositories. Git repositories are not known to be affected.… | Sep 4, 2026 | Sep 4, 2026 |
| | CVE-2026-81666 | Red Hat | medium | 6.5 | 0.3%
| | An integer overflow was found in Corosync's handling of membership commit token messages. The length… | Sep 4, 2026 | Sep 4, 2026 |
| | CVE-2026-85525 | Red Hat | high | 7.4 | 0.1%
| | A flaw was found in Snowflake drivers, including Python, Go, JDBC, and Node.js. This flaw involves i… | Sep 4, 2026 | Sep 4, 2026 |
| | CVE-2026-71196 | Red Hat | high | 7.7 | — | | A server-side request forgery (SSRF) vulnerability was found in OpenStack Glance. The web-download i… | Sep 4, 2026 | Sep 4, 2026 |
| | CVE-2026-81665 | Red Hat | high | 7.5 | 0.2%
| | A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembl… | Sep 4, 2026 | Sep 4, 2026 |
| | CVE-2026-71197 | Red Hat | medium | 4.3 | — | | A flaw was found in OpenStack Glance. The web-download image import method can bypass host-based blo… | Sep 4, 2026 | Sep 4, 2026 |
| | CVE-2026-71198 | Red Hat | high | 7.7 | — | | A server-side request forgery (SSRF) vulnerability was found in OpenStack Glance. When the HTTP stor… | Sep 4, 2026 | Sep 4, 2026 |
| | CVE-2026-84504 | Red Hat | high | 8.1 | 0.4%
| | A flaw was found in fastify. An authenticated low-privilege caller can exploit a vulnerability where… | Sep 4, 2026 | Sep 4, 2026 |
| | CVE-2026-76169 | Red Hat | high | 7.5 | 0.5%
| | A flaw was found in fastify. Malformed URLs can be routed to a custom not-found handler of a differe… | Sep 4, 2026 | Sep 4, 2026 |
| | CVE-2026-84469 | Red Hat | high | 7.5 | 0.5%
| | A flaw was found in fastify. An unauthenticated remote attacker can bypass request validation by exp… | Sep 4, 2026 | Sep 4, 2026 |
| | CVE-2026-84428 | Red Hat | high | 7.5 | — | | A flaw was found in fastify. Due to incomplete case normalization of HTTP header names within a rout… | Sep 4, 2026 | Sep 4, 2026 |
| | CVE-2026-85730 | Red Hat | high | 7.5 | 0.4%
| | A flaw was found in smol-toml, a TOML parser and serializer. A remote attacker could exploit an infi… | Sep 4, 2026 | Sep 4, 2026 |
| | CVE-2026-85024 | Red Hat | medium | 5.9 | 0.3%
| ✓ Fix | A flaw was found in undici. A remote, unauthenticated attacker can trigger a Denial of Service (DoS)… | Sep 4, 2026 | Sep 4, 2026 |
| | CVE-2026-85014 | Red Hat | medium | 5.9 | 0.4%
| ✓ Fix | A flaw was found in undici's experimental WebSocketStream client. A remote attacker, operating as an… | Sep 4, 2026 | Sep 4, 2026 |
| | CVE-2026-85152 | Red Hat | high | 7.4 | 0.2%
| ✓ Fix | A flaw was found in undici. When the cache or deduplicate interceptor is directly composed onto a Cl… | Sep 4, 2026 | Sep 4, 2026 |
| | CVE-2026-85008 | Red Hat | low | 3.7 | 0.1%
| ✓ Fix | A flaw was found in undici. The cache interceptor incorrectly caches responses to unsafe HTTP method… | Sep 4, 2026 | Sep 4, 2026 |
| | CVE-2026-84961 | Red Hat | high | 7.4 | 0.1%
| | A flaw was found in undici's BalancedPool component. This vulnerability allows a remote attacker to … | Sep 4, 2026 | Sep 4, 2026 |
| | CVE-2026-84947 | Red Hat | medium | 6.5 | 0.2%
| ✓ Fix | A flaw was found in undici, a Node.js HTTP/1.1 client. When the dump interceptor processes oversized… | Sep 4, 2026 | Sep 4, 2026 |
| | CVE-2026-84933 | Red Hat | medium | 6.5 | 0.2%
| ✓ Fix | A flaw was found in undici. The software's caching mechanism, when operating in shared cache mode, i… | Sep 4, 2026 | Sep 4, 2026 |
| | CVE-2026-84890 | Red Hat | medium | 5.9 | 0.3%
| ✓ Fix | A flaw was found in undici. The decompress interceptor in undici processes compressed response bodie… | Sep 4, 2026 | Sep 4, 2026 |
| | CVE-2026-19534 | Red Hat | high | 7.5 | 0.4%
| | A flaw was found in undici. A remote attacker can exploit this vulnerability by responding with an u… | Sep 4, 2026 | Sep 4, 2026 |
| | CVE-2026-18540 | Red Hat | low | 3.7 | 0.2%
| | A flaw was found in undici. An attacker-controlled upstream server can exploit a vulnerability in th… | Sep 4, 2026 | Sep 4, 2026 |
| | CVE-2026-18149 | Red Hat | medium | 5.9 | 0.3%
| ✓ Fix | A flaw was found in undici. A remote attacker, by controlling a server, could exploit a vulnerabilit… | Sep 4, 2026 | Sep 4, 2026 |
| | CVE-2026-86315 | Red Hat | medium | 6.2 | — | | A flaw was found in Samsung Open Source Escargot. This out-of-bounds write vulnerability, caused by … | Sep 7, 2026 | Sep 7, 2026 |
| | CVE-2026-86332 | Red Hat | medium | 6.5 | — | | A flaw was found in odh-dashboard in Red Hat OpenShift AI. The backend-for-frontend route GET /api/n… | Sep 7, 2026 | Sep 7, 2026 |
| | CVE-2026-78043 | Red Hat | medium | 5.5 | 0.2%
| | A flaw was found in OpenVPN. The Windows Interactive Service allows local authenticated users to byp… | Sep 7, 2026 | Sep 7, 2026 |
| | CVE-2026-78221 | Red Hat | high | 7.5 | 0.1%
| | A flaw was found in OpenVPN. An incorrect buffer size calculation within the Windows Interactive Ser… | Sep 7, 2026 | Sep 7, 2026 |
| | CVE-2026-81738 | Red Hat | low | 4.2 | 0.3%
| | A flaw was found in OpenVPN when using the tap-windows6 driver. A remote attacker could exploit this… | Sep 7, 2026 | Sep 7, 2026 |
| | CVE-2026-81830 | Red Hat | medium | 5.5 | 0.1%
| | A flaw was found in OpenVPN. The Windows interactive service in OpenVPN contains an incorrect file p… | Sep 7, 2026 | Sep 7, 2026 |
| | CVE-2026-82312 | Red Hat | medium | 5.5 | 0.1%
| | A flaw was found in OpenVPN on Windows. A local authenticated user could exploit a vulnerability rel… | Sep 7, 2026 | Sep 7, 2026 |
| | CVE-2026-84226 | Red Hat | high | 7.8 | 0.1%
| | A flaw was found in OpenVPN on Windows. A local authenticated user could perform a binary planting a… | Sep 7, 2026 | Sep 7, 2026 |
| | CVE-2026-84256 | Red Hat | high | 8.8 | — | | A flaw was found in OpenVPN on Windows. An argument parsing issue allows remote authenticated users … | Sep 7, 2026 | Sep 7, 2026 |
| | CVE-2026-14296 | F5 | high | 7.5 | — | | When using the Direct XIP
update strategy, the main application image starts other cores (i.e. radio… | Sep 7, 2026 | Sep 7, 2026 |
| | CVE-2026-18796 | F5 | medium | 6.8 | 0.1%
| | Any application that
uses external QSPI flash for encrypted XIP on nRF5340 and relies on that
… | Sep 7, 2026 | Sep 10, 2026 |
| | CVE-2026-84732 | Red Hat | high | 7.5 | — | | A flaw was found in OpenVPN. Remote unauthenticated attackers can cause a denial of service by sendi… | Sep 7, 2026 | Sep 7, 2026 |
| | CVE-2026-78254 | Apache | high | 7.4 | 0.4%
| | The ftp and scp tasks of Apache Ant can download files from a remote server. A malicious server can … | Sep 7, 2026 | Sep 9, 2026 |
| | CVE-2026-18453 | Red Hat | high | 7.5 | — | | A flaw was found in 389 Directory Server. A missing NULL pointer check in the paged results handling… | Sep 7, 2026 | Sep 7, 2026 |
| | CVE-2026-18355 | Red Hat | high | 7.5 | — | | A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). I… | Sep 7, 2026 | Sep 7, 2026 |
| | CVE-2026-86404 | Apache | high | 8.8 | — | | EAP's Artemis deserialization configuration permits deserialization by default. ObjectMessage.getObj… | Sep 7, 2026 | Sep 7, 2026 |
| | CVE-2026-79678 | Red Hat | high | 8.1 | — | | A flaw was found in FreeIPA's idp-add command, where insufficiently validated --organization/--base-… | Sep 7, 2026 | Sep 7, 2026 |
| | CVE-2026-76578 | Red Hat | critical | 9.8 | — | | A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does… | Sep 7, 2026 | Sep 7, 2026 |
| | CVE-2026-76560 | Red Hat | high | 7.5 | — | | A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an … | Sep 7, 2026 | Sep 7, 2026 |
| | CVE-2026-19843 | Red Hat | high | 8.4 | — | | A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch comm… | Sep 7, 2026 | Sep 7, 2026 |
| | CVE-2026-18922 | Red Hat | critical | 9.8 | — | | A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried… | Sep 7, 2026 | Sep 7, 2026 |
| | CVE-2026-86420 | Red Hat | low | 3.7 | — | | A flaw was found in ImageMagick. This vulnerability occurs when the software fails to correctly mana… | Sep 7, 2026 | Sep 7, 2026 |
| | CVE-2026-86421 | Red Hat | low | 3.7 | — | | A flaw was found in ImageMagick. A remote attacker could exploit this vulnerability by providing a s… | Sep 7, 2026 | Sep 7, 2026 |
| | CVE-2026-86422 | Red Hat | low | 3.3 | — | | A flaw was found in ImageMagick. This vulnerability, known as a time-of-check-time-of-use (TOCTOU) f… | Sep 7, 2026 | Sep 7, 2026 |
| | CVE-2026-86423 | Red Hat | low | 3.3 | — | | A flaw was found in ImageMagick, specifically within the PerlMagick component's GetList method. A lo… | Sep 7, 2026 | Sep 7, 2026 |
| | CVE-2026-86424 | Red Hat | low | 2.5 | — | | A flaw was found in ImageMagick. This time-of-check-time-of-use (TOCTOU) vulnerability, involving a … | Sep 7, 2026 | Sep 7, 2026 |
| | CVE-2026-86425 | Red Hat | low | 3.3 | — | | A flaw was found in ImageMagick and PerlMagick. An attacker can exploit a heap-use-after-free vulner… | Sep 7, 2026 | Sep 7, 2026 |