| | CVE-2026-17527 | Red Hat | high | 7.7 | — | | In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to p… | Jul 27, 2026 | Jul 27, 2026 |
| | CVE-2026-57990 | Microsoft | high | 7.4 | 0.9%
| | Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an una… | Jul 26, 2026 | Aug 3, 2026 |
| | CVE-2026-57989 | Microsoft | high | 7.4 | 0.4%
| | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclo… | Jul 26, 2026 | Aug 3, 2026 |
| | CVE-2026-57978 | Microsoft | medium | 5.4 | 0.2%
| | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perfor… | Jul 26, 2026 | Aug 3, 2026 |
| | CVE-2026-62835 | Microsoft | critical | 9.3 | 1.0%
| | Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over … | Jul 24, 2026 | Jul 29, 2026 |
| | CVE-2026-17107 | Red Hat | high | 8.5 | 0.2%
| | A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Manag… | Jul 24, 2026 | Jul 24, 2026 |
| | CVE-2026-58630 | Microsoft | critical | 10.0 | 0.8%
| | Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges o… | Jul 24, 2026 | Aug 6, 2026 |
| | CVE-2026-57106 | Microsoft | critical | 10.0 | 0.9%
| | Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privil… | Jul 24, 2026 | Jul 29, 2026 |
| | CVE-2026-56163 | Microsoft | critical | 10.0 | 0.9%
| | Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unautho… | Jul 24, 2026 | Jul 29, 2026 |
| | CVE-2026-49326 | Apache | medium | 6.5 | 0.2%
| | Missing Authorization vulnerability in Apache HBase thrift and rest delegation service.
A scan oper… | Jul 24, 2026 | Aug 6, 2026 |
| | CVE-2026-17059 | Red Hat | medium | 6.5 | 0.2%
| | A flaw was found in the role-users endpoint of the keycloak-services library, which is the core comp… | Jul 24, 2026 | Jul 24, 2026 |
| | CVE-2026-66144 | Apache | high | 7.5 | 0.3%
| | Although remote policy references are not retrieved during policy normalization, if they are manuall… | Jul 24, 2026 | Jul 27, 2026 |
| | CVE-2026-66143 | Apache | high | 7.5 | 0.3%
| | It is possible to bypass the maximum number of normalized policy alternatives that was introduced in… | Jul 24, 2026 | Jul 27, 2026 |
| | CVE-2026-66142 | Apache | high | 7.5 | 0.3%
| | Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or … | Jul 24, 2026 | Jul 27, 2026 |
| | CVE-2026-46452 | Apache | medium | 5.3 | 0.3%
| | Improper Input Validation vulnerability in Apache NimBLE in Mesh Proxy SAR reassembly could result i… | Jul 24, 2026 | Jul 27, 2026 |
| | CVE-2026-45816 | Apache | high | 7.5 | 0.4%
| | NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event.
This req… | Jul 24, 2026 | Jul 27, 2026 |
| | CVE-2026-45815 | Apache | high | 7.5 | 0.4%
| | Reachable Assertion vulnerability in Apache NimBLE.
A specially crafted ATT Read Multiple Variable R… | Jul 24, 2026 | Jul 27, 2026 |
| | CVE-2026-45813 | Apache | high | 8.8 | 0.3%
| | Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS serv… | Jul 24, 2026 | Jul 27, 2026 |
| | CVE-2026-45812 | Apache | medium | 6.5 | 0.3%
| | Incorrect Calculation of Buffer Size vulnerability in Apache NimBLE when processing Legacy Advertisi… | Jul 24, 2026 | Jul 27, 2026 |
| | CVE-2026-45811 | Apache | high | 7.5 | 0.3%
| | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBL… | Jul 24, 2026 | Jul 27, 2026 |
| | CVE-2026-9765 | Grafana | high | 7.1 | — | | Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue.
… | Jul 24, 2026 | Jul 24, 2026 |
| | CVE-2026-66010 | Red Hat | medium | 6.1 | 0.2%
| | A flaw was found in DOMPurify. This vulnerability allows attackers to bypass application security po… | Jul 24, 2026 | Jul 24, 2026 |
| | CVE-2026-63317 | Apache | medium | 5.6 | 0.3%
| | Arbitrary Class Instantiation via XML Feature Generator Descriptor and Format Name in Apache OpenNLP… | Jul 24, 2026 | Aug 6, 2026 |
| | CVE-2026-56392 | Red Hat | medium | 4.4 | 0.1%
| | A flaw was found in GNU coreutils, specifically in the `unexpand` utility. This vulnerability, a hea… | Jul 24, 2026 | Jul 24, 2026 |
| | CVE-2026-62825 | Microsoft | critical | 10.0 | 0.7%
| | Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges ove… | Jul 24, 2026 | Aug 7, 2026 |
| | CVE-2026-58275 | Microsoft | critical | 10.0 | 0.7%
| | Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a netw… | Jul 24, 2026 | Aug 7, 2026 |
| | CVE-2026-56191 | Microsoft | critical | 10.0 | 0.7%
| | Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tamp… | Jul 24, 2026 | Jul 29, 2026 |
| | CVE-2026-56167 | Microsoft | high | 8.5 | 0.4%
| | Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privi… | Jul 24, 2026 | Jul 29, 2026 |
| | CVE-2026-56165 | Microsoft | critical | 9.8 | 0.7%
| | Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over… | Jul 24, 2026 | Jul 30, 2026 |
| | CVE-2026-56160 | Microsoft | critical | 9.1 | 0.6%
| | Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate pri… | Jul 24, 2026 | Aug 7, 2026 |
| | CVE-2026-54120 | Microsoft | critical | 9.9 | 0.7%
| | Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a … | Jul 24, 2026 | Aug 6, 2026 |
| | CVE-2026-50517 | Microsoft | critical | 9.9 | 1.3%
| | Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over… | Jul 24, 2026 | Jul 29, 2026 |
| | CVE-2026-49159 | Microsoft | medium | 6.5 | 0.6%
| | Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized a… | Jul 24, 2026 | Jul 29, 2026 |
| | CVE-2026-35425 | Microsoft | high | 8.0 | 0.5%
| | Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code… | Jul 24, 2026 | Aug 17, 2026 |
| | CVE-2026-17039 | Red Hat | low | 3.1 | 0.2%
| | A flaw was found in pki-core. The certificate authority (CA) renewal request path does not perform t… | Jul 24, 2026 | Jul 24, 2026 |
| | CVE-2026-21723 | Grafana | medium | 5.3 | 0.2%
| | The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) ca… | Jul 23, 2026 | Aug 12, 2026 |
| | CVE-2026-16232 | Check Point | critical | 9.8 | 71.4%
| ⚠ KEV | An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unaut… | Jul 22, 2026 | Aug 10, 2026 |
| | CVE-2026-62145 | Check Point | high | 7.5 | 0.4%
| | A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Port… | Jul 22, 2026 | Jul 24, 2026 |
| | CVE-2026-62144 | Check Point | medium | — | 1.0%
| | An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security … | Jul 22, 2026 | Jul 24, 2026 |
| | CVE-2026-56844 | Veeam | high | 8.4 | 0.1%
| | A vulnerability in the Veeam Updater component of the Veeam Software Appliance that could allow a lo… | Jul 22, 2026 | Jul 22, 2026 |
| | CVE-2026-16544 | Red Hat | medium | 6.5 | — | | A flaw was found in AWX. The websocket event consumer performs RBAC authorization checks only for ev… | Jul 22, 2026 | Jul 22, 2026 |
| | CVE-2026-64881 | Tenable | high | 8.8 | 1.4%
| | The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow int… | Jul 21, 2026 | Aug 18, 2026 |
| | CVE-2026-64880 | Tenable | high | 7.1 | 0.2%
| | Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL que… | Jul 21, 2026 | Aug 18, 2026 |
| | CVE-2026-64879 | Tenable | critical | 9.9 | 2.6%
| | A filename supplied during file upload is not properly sanitized before being used in system command… | Jul 21, 2026 | Aug 18, 2026 |
| | CVE-2026-64878 | Tenable | critical | 9.9 | 0.5%
| | Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument … | Jul 21, 2026 | Aug 18, 2026 |
| | CVE-2026-64877 | Tenable | high | 8.4 | 0.2%
| | An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access… | Jul 21, 2026 | Aug 18, 2026 |
| | CVE-2026-63454 | HPE | high | 7.2 | 0.5%
| | An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vuln… | Jul 21, 2026 | Jul 24, 2026 |
| | CVE-2026-63453 | HPE | high | 7.2 | 0.4%
| | Buffer overflow vulnerabilities exist in the command line interface of AOS-CX. Successful exploitati… | Jul 21, 2026 | Jul 24, 2026 |
| | CVE-2026-44880 | HPE | high | 8.8 | 0.5%
| | A buffer overflow vulnerability was found in the command line interface of AOS-CX. Successful exploi… | Jul 21, 2026 | Jul 24, 2026 |
| | CVE-2026-16493 | Red Hat | high | 7.8 | — | | A flaw was found in ansible-core. The _extract_collection_from_git() function in ansible-core's conc… | Jul 21, 2026 | Jul 21, 2026 |