| | CVE-2026-17653 | Red Hat | critical | 9.0 | — | | An use after free flaw was found in the Skia component of the Chromium browser.
Upstream bug(s):
htt… | Jul 30, 2026 | Jul 30, 2026 |
| | CVE-2026-62946 | Red Hat | medium | 5.1 | — | | A flaw was found in ImageMagick. When processing extremely large JNX image files on 32-bit systems, … | Jul 30, 2026 | Jul 30, 2026 |
| | CVE-2026-62363 | Red Hat | medium | 5.0 | — | | A flaw was found in ImageMagick. A local attacker with low privileges could cause a heap buffer over… | Jul 30, 2026 | Jul 30, 2026 |
| | CVE-2026-16524 | Red Hat | high | 7.8 | — | | A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the n… | Jul 30, 2026 | Jul 30, 2026 |
| | CVE-2026-16526 | Red Hat | high | 8.8 | — | | A flaw in the PCP linux_sockets module exposes an unsecured internal connection.
An attacker with in… | Jul 30, 2026 | Jul 30, 2026 |
| | CVE-2026-16527 | Red Hat | high | 7.3 | — | | An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP… | Jul 30, 2026 | Jul 30, 2026 |
| | CVE-2026-16529 | Red Hat | high | 7.5 | — | | A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted network pack… | Jul 30, 2026 | Jul 30, 2026 |
| | CVE-2026-16530 | Red Hat | medium | 6.5 | — | | A flaw was found in the PCP (Performance Co-Pilot) `pmproxy` service. A remote attacker can exploit … | Jul 30, 2026 | Jul 30, 2026 |
| | CVE-2026-16531 | Red Hat | medium | 5.3 | — | | An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy log… | Jul 30, 2026 | Jul 30, 2026 |
| | CVE-2026-18378 | Red Hat | high | 7.6 | — | | A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resourc… | Jul 30, 2026 | Jul 30, 2026 |
| | CVE-2026-18381 | Red Hat | high | 7.6 | — | | A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMe… | Jul 30, 2026 | Jul 30, 2026 |
| | CVE-2026-18382 | Red Hat | medium | 6.8 | — | | A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resourc… | Jul 30, 2026 | Jul 30, 2026 |
| | CVE-2026-20316 | Cisco | medium | 5.3 | 0.8%
| ⚠ KEV | A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could… | Jul 29, 2026 | Aug 1, 2026 |
| | CVE-2026-55707 | Red Hat | high | 7.1 | — | | An authorization bypass was found in the OpenStack Neutron subnetpool onboarding API endpoint (PUT /… | Jul 29, 2026 | Jul 29, 2026 |
| | CVE-2026-55995 | Red Hat | high | 7.5 | — | | A flaw was found in open-iscsi. An unauthenticated man-in-the-middle (MITM) attacker can exploit a d… | Jul 29, 2026 | Jul 29, 2026 |
| | CVE-2026-67216 | Red Hat | medium | 5.9 | — | | A flaw was found in cJSON. An inefficient algorithmic complexity flaw in the `cJSON_Compare()` funct… | Jul 29, 2026 | Jul 29, 2026 |
| | CVE-2026-16308 | Red Hat | high | 7.5 | — | ✓ Fix | A flaw was found in Quarkus REST. An unauthenticated remote attacker can exploit this vulnerability … | Jul 29, 2026 | Jul 29, 2026 |
| | CVE-2026-44944 | Red Hat | high | 7.8 | — | | A flaw was found in open-iscsi. An incorrect authorization vulnerability allows unprivileged local u… | Jul 29, 2026 | Jul 29, 2026 |
| | CVE-2026-44943 | Red Hat | high | 8.6 | — | | A flaw was found in open-iscsi. This vulnerability, known as Path Traversal, allows remote Man-in-th… | Jul 29, 2026 | Jul 29, 2026 |
| | CVE-2026-65100 | Apache | medium | 4.8 | 0.3%
| | Apache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming the header block enco… | Jul 29, 2026 | Aug 3, 2026 |
| | CVE-2026-59243 | Apache | critical | 9.8 | 0.5%
| | The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID … | Jul 29, 2026 | Aug 5, 2026 |
| | CVE-2026-58189 | Apache | high | 7.5 | 0.4%
| | Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SS… | Jul 29, 2026 | Aug 3, 2026 |
| | CVE-2026-58188 | Apache | high | 8.2 | 0.4%
| | Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors.
This… | Jul 29, 2026 | Aug 3, 2026 |
| | CVE-2026-58187 | Apache | low | 3.7 | 0.5%
| | The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on upstream input, ena… | Jul 29, 2026 | Jul 31, 2026 |
| | CVE-2026-58186 | Apache | high | 7.5 | 0.5%
| | The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable … | Jul 29, 2026 | Jul 31, 2026 |
| | CVE-2026-58185 | Apache | medium | 5.9 | 0.4%
| | The Apache Traffic Server intercept plugin has a use-after-free.
This issue affects Apache Traffic … | Jul 29, 2026 | Jul 31, 2026 |
| | CVE-2026-58184 | Apache | high | 8.2 | 0.5%
| | The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations… | Jul 29, 2026 | Jul 31, 2026 |
| | CVE-2026-58183 | Apache | medium | 5.9 | 0.5%
| | The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input.
This… | Jul 29, 2026 | Jul 31, 2026 |
| | CVE-2026-58182 | Apache | high | 8.6 | 0.5%
| | The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instan… | Jul 29, 2026 | Jul 31, 2026 |
| | CVE-2026-58181 | Apache | high | 7.5 | 0.5%
| | The Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack or crash on attacker… | Jul 29, 2026 | Jul 31, 2026 |
| | CVE-2026-58180 | Apache | high | 7.5 | 0.6%
| | The Apache Traffic Server txn_box plugin overflows the stack from attacker-controlled input.
This i… | Jul 29, 2026 | Jul 31, 2026 |
| | CVE-2026-58179 | Apache | high | 8.1 | 0.6%
| | The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution inpu… | Jul 29, 2026 | Jul 31, 2026 |
| | CVE-2026-58178 | Apache | high | 7.5 | 0.6%
| | The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs.
… | Jul 29, 2026 | Jul 31, 2026 |
| | CVE-2026-58177 | Apache | high | 8.1 | 0.5%
| | The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-f… | Jul 29, 2026 | Jul 31, 2026 |
| | CVE-2026-58175 | Apache | high | 7.5 | 0.6%
| | Apache Traffic Server leaks memory when handling HostDB SRV records.
This issue affects Apache Traf… | Jul 29, 2026 | Jul 31, 2026 |
| | CVE-2026-58164 | Apache | high | 7.5 | 0.4%
| | Apache Traffic Server has use-after-free and time-of-check/time-of-use errors in remap configuration… | Jul 29, 2026 | Aug 3, 2026 |
| | CVE-2026-58163 | Apache | high | 7.5 | 0.4%
| | Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or cras… | Jul 29, 2026 | Aug 3, 2026 |
| | CVE-2026-58162 | Apache | critical | 10.0 | 0.2%
| | The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled clien… | Jul 29, 2026 | Aug 3, 2026 |
| | CVE-2026-58161 | Apache | high | 7.5 | 0.4%
| | Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handli… | Jul 29, 2026 | Aug 3, 2026 |
| | CVE-2026-58160 | Apache | medium | 6.5 | 0.4%
| | Apache Traffic Server reads out of bounds while parsing DNS answers.
This issue affects Apache Traf… | Jul 29, 2026 | Aug 3, 2026 |
| | CVE-2026-58159 | Apache | high | 8.2 | 0.4%
| | Apache Traffic Server can bypass IP access controls on UDS listeners and through ACL matching errors… | Jul 29, 2026 | Aug 3, 2026 |
| | CVE-2026-58158 | Apache | medium | 5.9 | 0.4%
| | Apache Traffic Server mishandles PROXY protocol input, truncating ports and overflowing the stack.
… | Jul 29, 2026 | Aug 3, 2026 |
| | CVE-2026-58157 | Apache | high | 8.7 | 0.3%
| | Apache Traffic Server can reuse server sessions and tunnels improperly, exposing data across client … | Jul 29, 2026 | Aug 3, 2026 |
| | CVE-2026-50622 | Apache | high | 8.8 | 0.3%
| | Description:
Missing Authorization in Apache Atlas.
A missing authorization vulnerability in Apache … | Jul 29, 2026 | Aug 5, 2026 |
| | CVE-2026-23904 | Apache | high | 7.3 | 0.3%
| | Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to th… | Jul 29, 2026 | Aug 5, 2026 |
| | CVE-2026-50642 | Red Hat | medium | 4.4 | — | | A flaw was found in diff-so-fancy. The application does not properly sanitize non-SGR (Select Graphi… | Jul 29, 2026 | Jul 29, 2026 |
| | CVE-2026-18220 | Red Hat | high | 7.8 | — | | An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c… | Jul 29, 2026 | Jul 29, 2026 |
| | CVE-2026-65325 | Apache | medium | 4.8 | 0.1%
| | Apache Traffic Server reuses multiplexed HTTP/2 origin connections without verifying the server cert… | Jul 29, 2026 | Aug 3, 2026 |
| | CVE-2026-65324 | Apache | high | 7.5 | 0.3%
| | Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses, le… | Jul 29, 2026 | Aug 3, 2026 |
| | CVE-2026-58156 | Apache | medium | 4.9 | 0.1%
| | Apache Traffic Server mis-parses ports in URLs and userinfo, allowing port-based access-control bypa… | Jul 29, 2026 | Aug 3, 2026 |