| | CVE-2026-15562 | Red Hat | high | 7.5 | 0.3%
| | A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who can reach :8080 (or … | Aug 11, 2026 | Aug 11, 2026 |
| | CVE-2026-15561 | Red Hat | high | 7.5 | 0.3%
| | A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and cou… | Aug 11, 2026 | Aug 11, 2026 |
| | CVE-2026-4757 | Red Hat | high | 7.2 | 0.4%
| | A flaw was found in Axis. An attacker with an administrator-privileged service account could exploit… | Aug 11, 2026 | Aug 11, 2026 |
| | CVE-2026-15560 | Red Hat | high | 8.1 | 0.3%
| | when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs … | Aug 11, 2026 | Aug 11, 2026 |
| | CVE-2026-15555 | Red Hat | high | 8.8 | 0.2%
| | A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicat… | Aug 11, 2026 | Aug 11, 2026 |
| | CVE-2026-15554 | Red Hat | high | 7.4 | 0.2%
| | the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any sh… | Aug 11, 2026 | Aug 11, 2026 |
| | CVE-2026-10579 | Red Hat | critical | 9.8 | 0.4%
| | A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged … | Aug 11, 2026 | Aug 11, 2026 |
| | CVE-2026-5304 | Red Hat | medium | 5.7 | 0.2%
| | A flaw was found in Axis devices. An attacker could exploit a lack of input validation in an ACAP (A… | Aug 11, 2026 | Aug 11, 2026 |
| | CVE-2026-19516 | Grafana | critical | 9.1 | 0.2%
| | A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound re… | Aug 11, 2026 | Aug 12, 2026 |
| | CVE-2026-66799 | Red Hat | high | 7.1 | — | | A flaw was found in the cluster-backup-operator. A privileged user with administrative access to a s… | Aug 11, 2026 | Aug 11, 2026 |
| | CVE-2025-32736 | ForgeRock | medium | — | 0.2%
| | Cross-Site Request Forgery weaknesses in the Administrative Console of PingFederate versions before … | Aug 10, 2026 | Aug 28, 2026 |
| | CVE-2026-18947 | Red Hat | high | 8.5 | — | | A flaw was found in Feast. An authorization bypass vulnerability exists in the /materialize and /mat… | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-68872 | Apache | medium | 6.5 | 0.2%
| | The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon prov… | Aug 10, 2026 | Aug 17, 2026 |
| | CVE-2026-68871 | Apache | medium | 6.5 | 0.2%
| | The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connec… | Aug 10, 2026 | Aug 17, 2026 |
| | CVE-2026-18982 | Red Hat | critical | 8.8 | — | | A flaw was found in the RHOAI training-operator. This vulnerability allows a user with standard edit… | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-18951 | Red Hat | critical | 8.8 | — | | A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI ov… | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-18950 | Red Hat | critical | 8.8 | — | | A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerabilit… | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-18949 | Red Hat | critical | 8.8 | — | | A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the da… | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-18948 | Red Hat | critical | 9.9 | — | | A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored i… | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-18942 | Red Hat | high | 5.5 | — | | A flaw was found in the Feast operator. A malicious tenant could inject arbitrary code into their fe… | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-18941 | Red Hat | high | 7.7 | — | | A flaw was found in Feast and feast-operator. The default configuration for both the Feast SDK and t… | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-18621 | Red Hat | high | 7.6 | — | | A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can b… | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-18620 | Red Hat | medium | 7.1 | — | | A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper au… | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-18618 | Red Hat | medium | 7.5 | — | | A flaw was found in ml-metadata. The statically-linked gRPC stack in ml-metadata is outdated, making… | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-18617 | Red Hat | high | 8.8 | — | | A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a vul… | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-18611 | Red Hat | medium | 7.5 | — | | A flaw was found in the Data Science Pipelines Operator. This vulnerability allows an unauthenticate… | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-18608 | Red Hat | high | 8.7 | — | | A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which de… | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-16456 | Red Hat | high | 6.5 | — | | A flaw was found in the `odh-model-controller`. An authenticated user with permissions to create cus… | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-15581 | Red Hat | high | 8.0 | — | | A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the … | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-15467 | Red Hat | high | 8.1 | — | | A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user with… | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-14450 | Red Hat | high | 9.9 | — | | A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to bypass the… | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-13717 | Red Hat | high | 8.8 | — | | A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway. Improper configuration of the Gat… | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-68870 | Microsoft | medium | — | 0.1%
| | The Azure Key Vault secrets backend in Apache Airflow's Microsoft Azure provider resolved a team-sco… | Aug 10, 2026 | Aug 11, 2026 |
| | CVE-2026-71576 | Red Hat | high | 8.5 | — | | A flaw was found in multicluster-global-hub. The manager component improperly validates the source i… | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-71577 | Red Hat | medium | 6.3 | — | | A flaw was found in multicluster-global-hub. During a ManagedClusterMigration, the system incorrectl… | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-66801 | Red Hat | critical | 9.9 | — | ✓ Fix | A flaw was found in multicluster-global-hub. An attacker who compromises a managed hub can leverage … | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-65948 | Apache | high | 7.3 | 0.3%
| | UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8.0.
Note: UnixAuth is NOT a … | Aug 10, 2026 | Aug 17, 2026 |
| | CVE-2026-65945 | Apache | medium | 6.5 | 0.3%
| | Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0
Users are recommended to upgra… | Aug 10, 2026 | Aug 17, 2026 |
| | CVE-2026-65942 | Apache | high | 7.5 | 0.4%
| | TLS hostname verification issue in Apache Ranger Client Code in versions <= 2.8.0.
Users are recomme… | Aug 10, 2026 | Aug 17, 2026 |
| | CVE-2026-61899 | Apache | high | 7.5 | 0.4%
| | Vulnerability in tapestry-core in Apache Tapestry 5.5.0+ on all platforms allows attackers to downlo… | Aug 10, 2026 | Aug 18, 2026 |
| | CVE-2026-55814 | Apache | high | 7.5 | 0.5%
| | Missing Authentication in Apache Ranger Download APIs on versions <= 2.8.0.
Users are recommended to… | Aug 10, 2026 | Aug 17, 2026 |
| | CVE-2026-55799 | Apache | critical | 9.8 | 0.9%
| | Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0
Users are … | Aug 10, 2026 | Aug 17, 2026 |
| | CVE-2026-44416 | Apache | critical | 9.8 | 0.9%
| | Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apach… | Aug 10, 2026 | Aug 17, 2026 |
| | CVE-2026-42537 | Apache | critical | 9.8 | 0.9%
| | Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0
Users are recommended to upgr… | Aug 10, 2026 | Aug 17, 2026 |
| | CVE-2026-40920 | Apache | critical | 9.8 | 0.5%
| | Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0.
Users are re… | Aug 10, 2026 | Aug 17, 2026 |
| | CVE-2026-32227 | Apache | critical | 9.8 | 0.5%
| | SQL Injection vulnerability vulnerability in Apache Ranger.
This issue affects .
Users are recomme… | Aug 10, 2026 | Aug 17, 2026 |
| | CVE-2026-28672 | Apache | critical | 9.8 | 2.0%
| | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in… | Aug 10, 2026 | Aug 17, 2026 |
| | CVE-2026-72585 | Grafana | medium | 6.5 | 0.2%
| | An authorization bypass vulnerability in Grafana through 13.2.0 allows an Editor-role user to delete… | Aug 10, 2026 | Aug 18, 2026 |
| | CVE-2026-44630 | Apache | medium | — | — | | Improper validation of length fields in the Apache IoTDB RPC service may allow a remote unauthentica… | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-19411 | Red Hat | low | 3.9 | — | | A NULL pointer vulnerability has been found in the the shim application of dp.c library. A missing N… | Aug 10, 2026 | Aug 10, 2026 |