| | CVE-2026-59851 | Red Hat | high | 8.8 | — | | A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does no… | Jul 21, 2026 | Jul 21, 2026 |
| | CVE-2026-59850 | Red Hat | medium | 4.3 | — | | A flaw was found in libssh. If data packets are processed after a channel is closed, channel data ca… | Jul 21, 2026 | Jul 21, 2026 |
| | CVE-2026-59849 | Red Hat | low | 3.1 | — | | A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication ca… | Jul 21, 2026 | Jul 21, 2026 |
| | CVE-2026-59848 | Red Hat | medium | 5.3 | — | | A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that … | Jul 21, 2026 | Jul 21, 2026 |
| | CVE-2026-59847 | Red Hat | medium | 5.9 | — | | A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backen… | Jul 21, 2026 | Jul 21, 2026 |
| | CVE-2026-59846 | Red Hat | low | 3.9 | — | | A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can in… | Jul 21, 2026 | Jul 21, 2026 |
| | CVE-2026-60080 | Apache | high | 7.3 | 0.2%
| | Use After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects Ap… | Jul 21, 2026 | Jul 27, 2026 |
| | CVE-2026-59845 | Red Hat | medium | 5.3 | — | | A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as … | Jul 21, 2026 | Jul 21, 2026 |
| | CVE-2026-59844 | Red Hat | medium | 6.5 | — | | A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an ar… | Jul 21, 2026 | Jul 21, 2026 |
| | CVE-2026-64606 | Apache | critical | 9.8 | 0.5%
| | Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypas… | Jul 21, 2026 | Jul 27, 2026 |
| | CVE-2026-59843 | Red Hat | medium | 6.5 | — | | A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in … | Jul 21, 2026 | Jul 21, 2026 |
| | CVE-2026-59842 | Red Hat | low | 3.7 | — | | A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 pub… | Jul 21, 2026 | Jul 21, 2026 |
| | CVE-2026-64609 | Apache | critical | 9.1 | 0.3%
| | Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is… | Jul 21, 2026 | Jul 27, 2026 |
| | CVE-2026-64608 | Apache | critical | 9.8 | 0.4%
| | Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deseria… | Jul 21, 2026 | Aug 11, 2026 |
| | CVE-2026-15370 | Red Hat | medium | 6.7 | — | | A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed … | Jul 21, 2026 | Jul 21, 2026 |
| | CVE-2026-16445 | Red Hat | high | 7.5 | — | ✓ Fix | A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability… | Jul 21, 2026 | Jul 21, 2026 |
| | CVE-2026-58624 | Apache | medium | 5.4 | 0.2%
| | Improper input validation in sshd-git in Apache MINA SSHD. Apache MINA SSHD is a Java library for cl… | Jul 20, 2026 | Jul 27, 2026 |
| | CVE-2026-56624 | Apache | high | 7.3 | 0.2%
| | Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java librar… | Jul 20, 2026 | Jul 27, 2026 |
| | CVE-2026-56623 | Apache | high | 7.1 | 0.3%
| | Path traversal on Windows in Apache MINA SSHD component sshd-git. Apache MINA SSHD is a Java library… | Jul 20, 2026 | Jul 27, 2026 |
| | CVE-2026-56452 | Apache | high | 7.5 | 0.4%
| | Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for… | Jul 20, 2026 | Jul 27, 2026 |
| | CVE-2026-63071 | Apache | critical | 9.8 | 0.4%
| | Improper Isolation or Compartmentalization vulnerability in Apache Syncope.
An administrator with a… | Jul 20, 2026 | Jul 27, 2026 |
| | CVE-2026-62418 | Apache | high | 8.1 | 0.2%
| | Low-privileged authenticated Server-Side Request Forgery (SSRF)
vulnerability in Apache Syncope via… | Jul 20, 2026 | Jul 27, 2026 |
| | CVE-2026-62183 | Apache | critical | 9.8 | 0.3%
| | Improper Privilege Management vulnerability in Apache Syncope.
When:
* the all-Java user workflow … | Jul 20, 2026 | Jul 27, 2026 |
| | CVE-2026-57308 | Apache | critical | 9.8 | 0.4%
| | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i… | Jul 20, 2026 | Jul 27, 2026 |
| | CVE-2026-53421 | Apache | critical | 9.8 | 0.5%
| | Improper Isolation or Compartmentalization vulnerability in Apache Syncope.
An administrator with… | Jul 20, 2026 | Jul 27, 2026 |
| | CVE-2026-53405 | Apache | critical | 9.8 | 0.3%
| | Improper Isolation or Compartmentalization vulnerability in Apache Syncope.
An administrator with a… | Jul 20, 2026 | Jul 27, 2026 |
| | CVE-2026-16277 | Red Hat | medium | 6.5 | — | | A stack-based buffer overflow was found in rpcbind's rpcinfo utility. When querying a remote rpcbind… | Jul 20, 2026 | Jul 20, 2026 |
| | CVE-2026-12701 | Red Hat | high | 9.0 | — | ✓ Fix | A path traversal vulnerability was found in pulpcore. The relative_path_validator function only veri… | Jul 20, 2026 | Jul 20, 2026 |
| | CVE-2026-64621 | Red Hat | high | 7.3 | — | | A flaw was found in FreeRDP, a free implementation of the Remote Desktop Protocol. A double-free vul… | Jul 20, 2026 | Jul 20, 2026 |
| | CVE-2026-16254 | Red Hat | medium | 4.3 | — | | A flaw was found in claircore's apk package scanner. Malformed package-database data in a container … | Jul 20, 2026 | Jul 20, 2026 |
| | CVE-2026-59173 | Apache | high | 7.5 | 0.5%
| | Uncontrolled Resource Consumption vulnerability in Apache Traffic Server.
This issue affects Apache… | Jul 18, 2026 | Aug 6, 2026 |
| | CVE-2026-47871 | VMware | high | 8.8 | 0.9%
| | VMware Avi Load Balancer contains a directory traversal vulnerability. Flaws in file path validation… | Jul 18, 2026 | Jul 23, 2026 |
| | CVE-2026-47870 | VMware | high | 7.1 | 0.4%
| | VMware Avi Load Balancer contains a privilege escalation vulnerability. A malicious authenticated us… | Jul 18, 2026 | Jul 23, 2026 |
| | CVE-2026-47869 | VMware | high | 8.7 | 0.7%
| | VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious authenticated u… | Jul 18, 2026 | Jul 23, 2026 |
| | CVE-2026-47868 | VMware | high | 7.8 | 0.1%
| | VMware Avi Load Balancer contains a local privilege escalation vulnerability. A malicious user with … | Jul 18, 2026 | Jul 23, 2026 |
| | CVE-2026-47867 | VMware | high | 8.7 | 0.7%
| | VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious user with netwo… | Jul 18, 2026 | Jul 23, 2026 |
| | CVE-2026-47866 | VMware | high | 8.3 | 0.4%
| | VMware Avi Load Balancer contains an authorization bypass vulnerability. A malicious actor on the ne… | Jul 18, 2026 | Jul 23, 2026 |
| | CVE-2026-47865 | VMware | critical | 9.8 | 0.7%
| | VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with netw… | Jul 18, 2026 | Jul 23, 2026 |
| | CVE-2026-57980 | Microsoft | medium | 5.4 | 0.2%
| | Authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows a… | Jul 17, 2026 | Jul 21, 2026 |
| | CVE-2026-56171 | Microsoft | high | 7.1 | 0.6%
| | Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthori… | Jul 17, 2026 | Jul 22, 2026 |
| | CVE-2026-16089 | Red Hat | medium | 5.4 | 0.2%
| | A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs b… | Jul 17, 2026 | Jul 17, 2026 |
| | CVE-2026-62764 | Apache | medium | 6.5 | 0.3%
| | Improper Handling of Insufficient Privileges vulnerability in Apache Accumulo.
An authenticated, but… | Jul 17, 2026 | Aug 11, 2026 |
| | CVE-2026-21770 | Microsoft | medium | 6.5 | 0.1%
| | HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which coul… | Jul 17, 2026 | Jul 17, 2026 |
| | CVE-2026-62826 | Microsoft | medium | 4.6 | 0.2%
| | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of… | Jul 16, 2026 | Jul 22, 2026 |
| | CVE-2026-59117 | Microsoft | high | 7.5 | 0.4%
| | Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code o… | Jul 16, 2026 | Jul 30, 2026 |
| | CVE-2026-58643 | Microsoft | medium | 6.1 | 0.2%
| | Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admi… | Jul 16, 2026 | Aug 14, 2026 |
| | CVE-2026-59866 | Microsoft | critical | 9.3 | — | | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, Kiota emitted x-ms-kiota-info… | Jul 16, 2026 | Jul 17, 2026 |
| | CVE-2026-59864 | Microsoft | critical | 9.3 | — | | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota plugin add` and `kiota… | Jul 16, 2026 | Jul 17, 2026 |
| | CVE-2026-59865 | Microsoft | critical | 9.3 | — | | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota info` read x-ms-kiota-… | Jul 16, 2026 | Jul 17, 2026 |
| | CVE-2026-59859 | Microsoft | high | 8.7 | — | | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.4, Kiota's PHP generator embedde… | Jul 16, 2026 | Jul 17, 2026 |