| | CVE-2026-66909 | Apache | critical | 9.8 | — | | Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java … | Aug 6, 2026 | Aug 7, 2026 |
| | CVE-2026-65432 | Apache | high | 7.5 | — | | Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs and e… | Aug 6, 2026 | Aug 7, 2026 |
| | CVE-2026-64958 | Apache | high | 7.5 | — | | An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service … | Aug 6, 2026 | Aug 6, 2026 |
| | CVE-2026-57819 | Apache | high | 7.5 | — | | Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the "maxFo… | Aug 6, 2026 | Aug 7, 2026 |
| | CVE-2026-57817 | Apache | high | 8.1 | — | | The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter … | Aug 6, 2026 | Aug 7, 2026 |
| | CVE-2026-54225 | Apache | high | 7.5 | — | | Apache CXF allows to control the maximum attachment size via the "attachment-max-size". Prior to Apa… | Aug 6, 2026 | Aug 7, 2026 |
| | CVE-2026-64640 | Apache | medium | 6.5 | 0.3%
| | Apache Polaris did not consistently validate storage locations supplied during table and view regist… | Aug 6, 2026 | Aug 6, 2026 |
| | CVE-2026-18649 | Red Hat | medium | 7.5 | 0.6%
| | A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP de… | Aug 6, 2026 | Aug 6, 2026 |
| | CVE-2026-7867 | Red Hat | high | 7.8 | — | | A flaw was found in udisks2. A local attacker with an active console session can exploit insufficien… | Aug 6, 2026 | Aug 6, 2026 |
| | CVE-2026-18839 | Red Hat | low | 2.2 | — | | An integer underflow was found in the popt library when formatting help text for option tables that … | Aug 5, 2026 | Aug 5, 2026 |
| | CVE-2026-20313 | Cisco | high | 7.7 | 0.3%
| | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst … | Aug 5, 2026 | Aug 14, 2026 |
| | CVE-2026-20312 | Cisco | high | 8.8 | 0.2%
| | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst … | Aug 5, 2026 | Aug 14, 2026 |
| | CVE-2026-20311 | Cisco | medium | 6.3 | 0.2%
| | A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authen… | Aug 5, 2026 | Aug 6, 2026 |
| | CVE-2026-20310 | Cisco | critical | 9.1 | 0.4%
| | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst … | Aug 5, 2026 | Aug 14, 2026 |
| | CVE-2026-20308 | Cisco | medium | 4.3 | 0.3%
| | A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authen… | Aug 5, 2026 | Aug 6, 2026 |
| | CVE-2026-20304 | Cisco | critical | 9.9 | 0.3%
| | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst … | Aug 5, 2026 | Aug 14, 2026 |
| | CVE-2026-20303 | Cisco | critical | 9.9 | 0.3%
| | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst … | Aug 5, 2026 | Aug 14, 2026 |
| | CVE-2026-20301 | Cisco | high | 8.6 | 0.3%
| | A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External… | Aug 5, 2026 | Aug 6, 2026 |
| | CVE-2026-20294 | Cisco | medium | 6.5 | 0.1%
| | A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow a… | Aug 5, 2026 | Aug 6, 2026 |
| | CVE-2026-20289 | Cisco | medium | 5.7 | 0.2%
| | A vulnerability in the logging subsystem of Cisco RoomOS could allow an authenticated, local attacke… | Aug 5, 2026 | Aug 17, 2026 |
| | CVE-2026-20288 | Cisco | medium | 6.5 | 0.4%
| | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, rem… | Aug 5, 2026 | Aug 31, 2026 |
| | CVE-2026-20273 | Cisco | high | 8.6 | 0.3%
| | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE So… | Aug 5, 2026 | Aug 17, 2026 |
| | CVE-2026-20272 | Cisco | critical | 9.8 | 0.4%
| | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE So… | Aug 5, 2026 | Aug 14, 2026 |
| | CVE-2026-20271 | Cisco | high | 8.6 | 0.3%
| | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE So… | Aug 5, 2026 | Aug 14, 2026 |
| | CVE-2026-20270 | Cisco | high | 8.6 | 0.3%
| | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE So… | Aug 5, 2026 | Aug 14, 2026 |
| | CVE-2026-20269 | Cisco | high | 8.6 | 0.3%
| | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE So… | Aug 5, 2026 | Aug 14, 2026 |
| | CVE-2026-20268 | Cisco | high | 8.6 | 0.3%
| | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE So… | Aug 5, 2026 | Aug 14, 2026 |
| | CVE-2026-20267 | Cisco | critical | 9.0 | 0.2%
| | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE So… | Aug 5, 2026 | Aug 14, 2026 |
| | CVE-2026-20263 | Cisco | high | 8.6 | 0.3%
| | A vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE Software c… | Aug 5, 2026 | Aug 6, 2026 |
| | CVE-2026-20200 | Cisco | high | 8.8 | 5.2%
| | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, rem… | Aug 5, 2026 | Aug 31, 2026 |
| | CVE-2026-20198 | Cisco | medium | 4.8 | 0.2%
| | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC… | Aug 5, 2026 | Aug 6, 2026 |
| | CVE-2026-20124 | Cisco | high | 7.7 | 0.3%
| | A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software … | Aug 5, 2026 | Aug 6, 2026 |
| | CVE-2026-20028 | Cisco | medium | 5.0 | 0.3%
| | A vulnerability in the network driver of Cisco Terminal Service (TS) Agent could allow an authentica… | Aug 5, 2026 | Aug 6, 2026 |
| | CVE-2026-60053 | Apache | critical | 9.1 | 0.3%
| | Insufficient Session Expiration vulnerability in Apache Answer.
This issue affects Apache Answer: t… | Aug 5, 2026 | Aug 7, 2026 |
| | CVE-2026-60023 | Apache | high | 7.5 | 0.2%
| | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer.
This iss… | Aug 5, 2026 | Aug 6, 2026 |
| | CVE-2026-50749 | Apache | medium | 6.5 | 0.2%
| | Improper Authorization vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.… | Aug 5, 2026 | Aug 6, 2026 |
| | CVE-2026-48912 | Apache | medium | 6.5 | 0.2%
| | Improper Input Validation vulnerability in Apache Answer.
This issue affects Apache Answer: through… | Aug 5, 2026 | Aug 6, 2026 |
| | CVE-2026-48911 | Apache | high | 7.5 | 0.2%
| | Insufficient Verification of Data Authenticity vulnerability in Apache Answer.
This issue affects A… | Aug 5, 2026 | Aug 6, 2026 |
| | CVE-2026-48834 | Apache | high | 7.5 | 0.2%
| | Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer.
This issue affe… | Aug 5, 2026 | Aug 6, 2026 |
| | CVE-2026-49331 | Red Hat | medium | 6.5 | — | | A flaw was found in openshift/oauth-proxy. On paths configured to bypass authentication (skip-auth-r… | Aug 5, 2026 | Aug 5, 2026 |
| | CVE-2026-16443 | Red Hat | high | 7.4 | — | ✓ Fix | A flaw was found in the SAML metadata import functionality of the keycloak-services component, which… | Aug 5, 2026 | Aug 5, 2026 |
| | CVE-2026-71227 | Red Hat | medium | 5.1 | — | | A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchrono… | Aug 5, 2026 | Aug 5, 2026 |
| | CVE-2026-71281 | Red Hat | high | 8.8 | — | | A flaw was found in peft. The LoRA-GA and CorDA initialization modules within Hugging Face peft impr… | Aug 5, 2026 | Aug 5, 2026 |
| | CVE-2026-71226 | Red Hat | medium | 7.3 | — | | Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an e… | Aug 5, 2026 | Aug 5, 2026 |
| | CVE-2026-71225 | Red Hat | medium | 6.5 | — | | A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (… | Aug 5, 2026 | Aug 5, 2026 |
| | CVE-2026-71235 | Red Hat | high | 8.8 | — | | A flaw was found in Magistrala's Rules Engine. An authenticated low-privileged user can exploit this… | Aug 5, 2026 | Aug 5, 2026 |
| | CVE-2026-10059 | Red Hat | high | 9.1 | — | | A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant admin… | Aug 5, 2026 | Aug 5, 2026 |
| | CVE-2026-10090 | Red Hat | high | 9.9 | — | | A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of… | Aug 5, 2026 | Aug 5, 2026 |
| | CVE-2026-61486 | Apache | critical | 9.8 | 0.4%
| | ** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy.
This issu… | Aug 5, 2026 | Aug 6, 2026 |
| | CVE-2026-61485 | Apache | high | 7.5 | 0.3%
| | ** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size Value vulnerability in Apache … | Aug 5, 2026 | Aug 6, 2026 |