| | CVE-2026-61484 | Apache | critical | 9.8 | 0.4%
| | ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy.
Thi… | Aug 5, 2026 | Aug 6, 2026 |
| | CVE-2026-61483 | Apache | high | 7.5 | 0.2%
| | ** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy.
This issue aff… | Aug 5, 2026 | Aug 6, 2026 |
| | CVE-2026-68080 | Apache | medium | 6.5 | 0.3%
| | It was not possible to govern the rate at which the broker would respond to an echo flow, enabling a… | Aug 5, 2026 | Aug 6, 2026 |
| | CVE-2026-68078 | Apache | medium | 6.5 | 0.3%
| | It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling … | Aug 5, 2026 | Aug 6, 2026 |
| | CVE-2026-68077 | Apache | medium | 6.5 | 0.2%
| | An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessi… | Aug 5, 2026 | Aug 6, 2026 |
| | CVE-2026-68075 | Apache | medium | 6.5 | 0.2%
| | An authenticated attacker could exceed the session flow control incoming window potentially leading … | Aug 5, 2026 | Aug 6, 2026 |
| | CVE-2026-68073 | Apache | high | 7.5 | 0.2%
| | A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially … | Aug 5, 2026 | Aug 6, 2026 |
| | CVE-2026-67592 | Apache | high | 7.5 | 0.5%
| | It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling … | Aug 5, 2026 | Aug 7, 2026 |
| | CVE-2026-67591 | Apache | medium | 6.5 | 0.4%
| | An authenticated attacker could exceed the session flow control incoming window potentially leading … | Aug 5, 2026 | Aug 7, 2026 |
| | CVE-2026-67590 | Apache | high | 7.5 | 0.5%
| | A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially … | Aug 5, 2026 | Aug 7, 2026 |
| | CVE-2026-67555 | Apache | medium | 6.5 | 0.3%
| | It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling … | Aug 5, 2026 | Aug 7, 2026 |
| | CVE-2026-67554 | Apache | medium | 6.5 | 0.3%
| | An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessi… | Aug 5, 2026 | Aug 7, 2026 |
| | CVE-2026-67553 | Apache | medium | 6.5 | 0.3%
| | An authenticated attacker could exceed the session flow control incoming window potentially leading … | Aug 5, 2026 | Aug 7, 2026 |
| | CVE-2026-67552 | Apache | high | 7.5 | 0.4%
| | A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially … | Aug 5, 2026 | Aug 7, 2026 |
| | CVE-2026-66277 | Apache | medium | 6.5 | 0.3%
| | It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling … | Aug 5, 2026 | Aug 7, 2026 |
| | CVE-2026-66276 | Apache | medium | 6.5 | 0.3%
| | An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessi… | Aug 5, 2026 | Aug 7, 2026 |
| | CVE-2026-66275 | Apache | medium | 6.5 | 0.4%
| | An authenticated attacker could exceed the session flow control incoming window potentially leading … | Aug 5, 2026 | Aug 7, 2026 |
| | CVE-2026-66274 | Apache | high | 7.5 | 0.5%
| | A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially … | Aug 5, 2026 | Aug 7, 2026 |
| | CVE-2026-71202 | Red Hat | high | 7.5 | — | | A flaw was found in the `raster` Rust crate. A remote attacker could exploit an integer underflow vu… | Aug 5, 2026 | Aug 5, 2026 |
| | CVE-2026-68074 | Apache | high | 7.5 | 0.4%
| | A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaus… | Aug 5, 2026 | Aug 7, 2026 |
| | CVE-2026-68060 | Apache | high | 7.5 | 0.5%
| | A pre-authentication attacker could leverage type size/count handling to cause excessive allocation … | Aug 5, 2026 | Aug 7, 2026 |
| | CVE-2026-67589 | Apache | high | 7.5 | 0.5%
| | A pre-authentication attacker could leverage type size/count handling to cause excessive allocation … | Aug 5, 2026 | Aug 7, 2026 |
| | CVE-2026-67588 | Apache | high | 7.5 | 0.5%
| | A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaus… | Aug 5, 2026 | Aug 7, 2026 |
| | CVE-2026-67551 | Apache | high | 7.5 | 0.5%
| | pre-authentication attacker could leverage type size/count handling to cause excessive allocation le… | Aug 5, 2026 | Aug 7, 2026 |
| | CVE-2026-67465 | Apache | high | 7.5 | 0.4%
| | A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaus… | Aug 5, 2026 | Aug 7, 2026 |
| | CVE-2026-66273 | Apache | high | 7.5 | 0.3%
| | A pre-authentication attacker could leverage type size/count handling to cause excessive allocation … | Aug 5, 2026 | Aug 7, 2026 |
| | CVE-2026-66257 | Apache | high | 7.5 | 0.3%
| | A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaus… | Aug 5, 2026 | Aug 7, 2026 |
| | CVE-2026-15572 | Red Hat | high | 8.8 | — | ✓ Fix | A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Al… | Aug 5, 2026 | Aug 5, 2026 |
| | CVE-2026-15573 | Red Hat | high | 8.1 | — | ✓ Fix | A flaw was found in Keycloak's Authorization Services. The component responsible for matching reques… | Aug 5, 2026 | Aug 5, 2026 |
| | CVE-2026-16071 | Red Hat | medium | 5.4 | — | ✓ Fix | A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities… | Aug 5, 2026 | Aug 5, 2026 |
| | CVE-2026-16100 | Red Hat | medium | 6.5 | — | ✓ Fix | A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the syst… | Aug 5, 2026 | Aug 5, 2026 |
| | CVE-2026-16102 | Red Hat | high | 8.1 | — | ✓ Fix | A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and acc… | Aug 5, 2026 | Aug 5, 2026 |
| | CVE-2026-16442 | Red Hat | high | 7.4 | — | ✓ Fix | A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federati… | Aug 5, 2026 | Aug 5, 2026 |
| | CVE-2026-64634 | Veeam | medium | — | 0.1%
| | A vulnerability allowing local privilege escalation to the Reporter service context. | Aug 4, 2026 | Sep 3, 2026 |
| | CVE-2026-64633 | Veeam | medium | — | 0.5%
| | A vulnerability allowing remote unauthenticated code execution on the agent host. | Aug 4, 2026 | Sep 3, 2026 |
| | CVE-2026-64631 | Veeam | medium | — | 0.3%
| | A vulnerability allowing a low-privileged user to inject SQL and extract database contents. | Aug 4, 2026 | Sep 3, 2026 |
| | CVE-2026-64630 | Veeam | medium | — | 0.2%
| | A vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared… | Aug 4, 2026 | Sep 3, 2026 |
| | CVE-2026-58075 | Veeam | medium | — | 0.3%
| | A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which ca… | Aug 4, 2026 | Sep 3, 2026 |
| | CVE-2026-58074 | Veeam | medium | — | 0.4%
| | A vulnerability allowing a high-privileged user to execute arbitrary code on the server. | Aug 4, 2026 | Sep 3, 2026 |
| | CVE-2026-58073 | Veeam | medium | — | 0.3%
| | A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonat… | Aug 4, 2026 | Sep 3, 2026 |
| | CVE-2026-58072 | Veeam | medium | — | 0.5%
| | A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management se… | Aug 4, 2026 | Sep 3, 2026 |
| | CVE-2026-58071 | Veeam | medium | — | 0.4%
| | A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the… | Aug 4, 2026 | Sep 3, 2026 |
| | CVE-2026-58067 | Veeam | medium | — | 0.4%
| | A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust ho… | Aug 4, 2026 | Sep 3, 2026 |
| | CVE-2026-70368 | Red Hat | medium | 6.5 | — | | A stack-based out-of-bounds read vulnerability exists in the "s_vlog" function of stunnel, when hand… | Aug 4, 2026 | Aug 4, 2026 |
| | CVE-2026-70367 | Red Hat | medium | 5.4 | — | | A Server-Side Request Forgery (SSRF) bypass vulnerability exists in “stunnel” 5.79 and lower when co… | Aug 4, 2026 | Aug 4, 2026 |
| | CVE-2026-17614 | Red Hat | medium | 4.4 | 0.9%
| | A path traversal flaw was found in WildFly's domain mode
implementation. The LocalFileRepository.get… | Aug 4, 2026 | Aug 4, 2026 |
| | CVE-2026-42169 | Red Hat | medium | 7.3 | 0.1%
| | A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) file loader of GIMP. This fla… | Aug 4, 2026 | Aug 4, 2026 |
| | CVE-2026-42170 | Red Hat | high | 7.8 | — | | A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Surface) file parser. … | Aug 4, 2026 | Aug 4, 2026 |
| | CVE-2026-66326 | Microsoft | medium | 6.5 | 0.7%
| | Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute … | Aug 4, 2026 | Aug 6, 2026 |
| | CVE-2026-66325 | Microsoft | medium | 6.1 | 0.4%
| | Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacke… | Aug 4, 2026 | Aug 6, 2026 |