| | CVE-2026-87616 | Red Hat | high | 9.0 | 0.3%
| | An improper initialization flaw was found in the Views component of the Chromium browser.
Upstream b… | Sep 9, 2026 | Sep 9, 2026 |
| | CVE-2026-87635 | Red Hat | medium | 5.4 | 0.3%
| | An ui misrepresentation flaw was found in the Payments component of the Chromium browser.
Upstream b… | Sep 9, 2026 | Sep 9, 2026 |
| | CVE-2026-87468 | Red Hat | high | 7.4 | 0.2%
| | An incorrect authorization flaw was found in the Isolated component of the Chromium browser.
Upstrea… | Sep 9, 2026 | Sep 9, 2026 |
| | CVE-2026-87566 | Red Hat | medium | 6.5 | 0.2%
| | An observable discrepancy flaw was found in the Layout component of the Chromium browser.
Upstream b… | Sep 9, 2026 | Sep 9, 2026 |
| | CVE-2026-87626 | Red Hat | medium | 6.5 | 0.2%
| | An incorrect authorization flaw was found in the DeviceBoundSessionCredentials component of the Chro… | Sep 9, 2026 | Sep 9, 2026 |
| | CVE-2026-87598 | Red Hat | medium | 5.4 | 0.2%
| | An incorrect authorization flaw was found in the ServiceWorker component of the Chromium browser.
Up… | Sep 9, 2026 | Sep 9, 2026 |
| | CVE-2026-87619 | Red Hat | medium | 4.3 | 0.2%
| | An observable discrepancy flaw was found in the Prefetch component of the Chromium browser.
Upstream… | Sep 9, 2026 | Sep 9, 2026 |
| | CVE-2026-87083 | Red Hat | medium | 5.5 | 0.2%
| | A flaw was found in tile-ai tilelang. This vulnerability, located in the Kernel Cache component's `K… | Sep 9, 2026 | Sep 9, 2026 |
| | CVE-2026-61907 | Red Hat | medium | 4.3 | — | | No description is available for this CVE. | Sep 9, 2026 | Sep 9, 2026 |
| | CVE-2026-87795 | Red Hat | high | 8.2 | — | | A flaw was found in zstd-jni. This vulnerability occurs due to insufficient validation of offset and… | Sep 9, 2026 | Sep 9, 2026 |
| | CVE-2026-41870 | Apache | medium | — | — | | Missing Authorization, Improper Control of Generation of Code ('Code Injection'), Improper Control o… | Sep 9, 2026 | Sep 9, 2026 |
| | CVE-2026-74761 | Apache | medium | — | — | | Improper input validation in TopicRegion in Apache ActiveMQ, Apache ActiveMQ Broker, and Apache Acti… | Sep 9, 2026 | Sep 9, 2026 |
| | CVE-2026-41869 | Apache | critical | 9.1 | 0.2%
| | Missing Authorization, Improper Resource Shutdown and Job Interruption vulnerability in Apache Nutch… | Sep 9, 2026 | Sep 10, 2026 |
| | CVE-2026-41871 | Apache | critical | 9.8 | 0.4%
| | Missing Authorization, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflect… | Sep 9, 2026 | Sep 10, 2026 |
| | CVE-2026-54048 | Apache | medium | 5.3 | 0.2%
| | Specifying tblproperties('avro.schema.url'=' http://...' ) or with a 'file:///' URI on a table in Im… | Sep 9, 2026 | Sep 10, 2026 |
| | CVE-2026-56207 | Apache | critical | 9.8 | 0.2%
| | Signature of Bearer token is not verified in last step of SAML2 authentication for Impala's hs2-http… | Sep 9, 2026 | Sep 10, 2026 |
| | CVE-2026-57866 | Apache | high | 8.8 | 0.2%
| | Server side request forgery in Apache Impala versions 4.4.x and 4.5.x. Authenticated Impala users w… | Sep 9, 2026 | Sep 10, 2026 |
| | CVE-2026-65181 | Apache | high | 8.1 | 0.4%
| | Insufficient authorization of Data Source tables in Impala 2.7-4.5 allows a client with privileges t… | Sep 9, 2026 | Sep 10, 2026 |
| | CVE-2026-73334 | Apache | high | 8.1 | 0.2%
| | Potential problem for users of the org.apache.parquet.crypto.keytools package in Apache Parquet, ver… | Sep 9, 2026 | Sep 10, 2026 |
| | CVE-2026-87818 | Red Hat | medium | 6.5 | — | | A flaw was found in GitPython. This vulnerability allows an attacker to read arbitrary files on the … | Sep 9, 2026 | Sep 9, 2026 |
| | CVE-2026-87817 | Red Hat | high | 8.8 | — | | A flaw was found in GitPython. This vulnerability allows a remote attacker to execute arbitrary code… | Sep 9, 2026 | Sep 9, 2026 |
| | CVE-2026-85102 | Check Point | critical | 9.8 | — | | Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway… | Sep 9, 2026 | Sep 10, 2026 |
| | CVE-2026-85103 | Check Point | critical | 9.8 | — | | A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote a… | Sep 9, 2026 | Sep 10, 2026 |
| | CVE-2026-56711 | Red Hat | high | 8.8 | — | | A flaw was found in VLC media player. An integer overflow vulnerability exists when computing the si… | Sep 9, 2026 | Sep 9, 2026 |
| | CVE-2026-87853 | Red Hat | medium | 7.5 | — | | A flaw was found in SSSD's IdP authentication provider. The eval_access_token_buf() function compare… | Sep 9, 2026 | Sep 9, 2026 |
| | CVE-2026-18147 | Red Hat | high | 8.1 | — | | A flaw was found in FreeIPA. An unauthenticated remote attacker could exploit a DOM Cross-Site Scrip… | Sep 9, 2026 | Sep 9, 2026 |
| | CVE-2026-87872 | Red Hat | medium | 6.8 | — | | A flaw was found in the OCAPI modules (ocapi_command, ocapi_info) of the
community.general Ansible c… | Sep 9, 2026 | Sep 9, 2026 |
| | CVE-2026-87822 | Red Hat | high | 7.5 | — | | A flaw was found in t-digest. A remote attacker can exploit a vulnerability in the `MergingDigest.fr… | Sep 9, 2026 | Sep 9, 2026 |
| | CVE-2026-73769 | HPE | high | 7.2 | 0.9%
| | A vulnerability in the web-based management interface of vulnerable CPPM systems could allow an auth… | Sep 9, 2026 | Sep 11, 2026 |
| | CVE-2026-73787 | HPE | high | 7.2 | 0.8%
| | A vulnerability in the CPPM web interface could allow an authenticated remote attacker to access dir… | Sep 9, 2026 | Sep 11, 2026 |
| | CVE-2026-19816 | Red Hat | high | 7.1 | — | | A flaw was found in PackageKit. In the dnf5 backend, the RepoRemove handler ignores the SIMULATE tra… | Sep 9, 2026 | Sep 9, 2026 |
| | CVE-2026-88264 | Red Hat | medium | 5.6 | — | | A flaw was found in crun. When the container configuration does not give /dev a dedicated mount, ter… | Sep 10, 2026 | Sep 10, 2026 |
| | CVE-2026-84042 | Red Hat | high | 7.8 | — | | A flaw was found in crun. When crun is built with libkrun and a container is started rootful with pa… | Sep 10, 2026 | Sep 10, 2026 |
| | CVE-2026-75880 | Apache | medium | — | — | | An authenticated client could attach a consumer with a selector containing crafted wildcard usage th… | Sep 10, 2026 | Sep 10, 2026 |
| | CVE-2026-49362 | Apache | medium | — | — | | An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol, leadin… | Sep 10, 2026 | Sep 10, 2026 |
| | CVE-2026-84939 | Apache | medium | — | — | | Path traversal vulnerability in Apache FreeMarker template loading mechanism, if the attacker can sp… | Sep 10, 2026 | Sep 10, 2026 |
| | CVE-2026-67593 | Red Hat | high | 8.2 | — | | An unauthenticated network attacker can delete arbitrary durable queues on any Apache Artemis broker… | Sep 10, 2026 | Sep 10, 2026 |
| | CVE-2026-49364 | Red Hat | high | 8.0 | — | | Artemis and JGroups lack of access controls in certain situations can allow an attacker to spoof a p… | Sep 10, 2026 | Sep 10, 2026 |
| | CVE-2026-57967 | Red Hat | high | 7.4 | — | | in Apache Artemis, the REATTACH_SESSION handler performs zero authentication — it looks up the sessi… | Sep 10, 2026 | Sep 10, 2026 |
| | CVE-2026-49363 | Red Hat | medium | 5.3 | — | | A missing authentication vulnerability was found in Apache ActiveMQ Artemis. The SUBSCRIBE_TOPOLOGY_… | Sep 10, 2026 | Sep 10, 2026 |
| | CVE-2026-57822 | Red Hat | medium | 4.9 | — | | A flaw was found in Apache ActiveMQ Artemis. The JsonUtil.fromJsonArray() method
uses ObjectInputStr… | Sep 10, 2026 | Sep 10, 2026 |
| | CVE-2026-88763 | Red Hat | medium | 5.9 | — | | A flaw was found in the skupper-router component of Red Hat Service Interconnect, which is used to p… | Sep 10, 2026 | Sep 10, 2026 |
| | CVE-2026-80352 | Apache | medium | — | — | | Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Camel K.
A YAML… | Sep 10, 2026 | Sep 10, 2026 |
| | CVE-2026-61908 | Red Hat | medium | 4.3 | — | | A flaw was found in cyrus-imapd. An authenticated user could exploit this vulnerability by attemptin… | Sep 10, 2026 | Sep 10, 2026 |
| | CVE-2026-61909 | Red Hat | medium | 5.0 | — | | A flaw was found in cyrus-imapd. An authenticated DAV (Distributed Authoring and Versioning) user wi… | Sep 10, 2026 | Sep 10, 2026 |
| | CVE-2026-80351 | Apache | medium | — | — | | Improper neutralization of directives in dynamically evaluated code ('eval injection') vulnerability… | Sep 10, 2026 | Sep 10, 2026 |
| | CVE-2026-80354 | Apache | medium | — | — | | Authorization bypass through User-Controlled key vulnerability in Apache Camel K.
An authorizatio… | Sep 10, 2026 | Sep 10, 2026 |
| | CVE-2026-61910 | Red Hat | medium | 4.2 | — | | A flaw was found in cyrus-imapd. An authenticated user with specific permissions on another user's m… | Sep 10, 2026 | Sep 10, 2026 |
| | CVE-2026-61911 | Red Hat | medium | 4.3 | — | | A flaw was found in cyrus-imapd. An authenticated user could install a Sieve script to determine if … | Sep 10, 2026 | Sep 10, 2026 |
| | CVE-2026-61915 | Red Hat | medium | 4.2 | — | | A flaw was found in cyrus-imapd. An authenticated calendar user could trigger a double-free vulnerab… | Sep 10, 2026 | Sep 10, 2026 |