| | CVE-2026-50697 | Microsoft | high | 7.8 | 0.3%
| | Exposure of sensitive information to an unauthorized actor in Windows Common Log File System Driver … | Jul 14, 2026 | Jul 16, 2026 |
| | CVE-2026-54990 | Microsoft | critical | 9.8 | — | | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code … | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-54987 | Microsoft | high | 7.8 | 0.2%
| | Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privil… | Jul 14, 2026 | Jul 23, 2026 |
| | CVE-2026-54989 | Microsoft | high | 7.0 | 0.2%
| | Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows an authorized attack… | Jul 14, 2026 | Jul 23, 2026 |
| | CVE-2026-54129 | Microsoft | high | 7.0 | — | | Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-49784 | Microsoft | high | 7.0 | 0.2%
| | Concurrent execution using shared resource with improper synchronization ('race condition') in Micro… | Jul 14, 2026 | Jul 23, 2026 |
| | CVE-2026-49173 | Microsoft | high | 7.8 | — | | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-49172 | Microsoft | critical | 9.8 | 0.7%
| | Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code ov… | Jul 14, 2026 | Jul 23, 2026 |
| | CVE-2026-49175 | Microsoft | high | 7.8 | 0.2%
| | Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locall… | Jul 14, 2026 | Jul 16, 2026 |
| | CVE-2026-49176 | Microsoft | high | 7.8 | — | | Improper privilege management in Windows WalletService allows an authorized attacker to elevate priv… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-49171 | Microsoft | high | 7.5 | — | | Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges local… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-49170 | Microsoft | high | 7.8 | — | | Insufficient granularity of access control in Windows StateRepository API allows an authorized attac… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-49169 | Microsoft | high | 8.0 | 0.5%
| | Use after free in DNS Server allows an authorized attacker to execute code over a network. | Jul 14, 2026 | Jul 16, 2026 |
| | CVE-2026-49167 | Microsoft | medium | 4.7 | — | | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-49166 | Microsoft | high | 7.8 | — | | Use after free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges loca… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-49165 | Microsoft | high | 7.1 | 0.2%
| | Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclo… | Jul 14, 2026 | Jul 23, 2026 |
| | CVE-2026-49164 | Microsoft | high | 8.1 | — | | Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to ex… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-49162 | Microsoft | high | 7.0 | — | | Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privilege… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-48571 | Microsoft | high | 7.0 | 0.2%
| | Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally. | Jul 14, 2026 | Jul 16, 2026 |
| | CVE-2026-48572 | Microsoft | high | 7.0 | 0.2%
| | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | Jul 14, 2026 | Jul 16, 2026 |
| | CVE-2026-42990 | Microsoft | critical | 9.8 | 0.7%
| | Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code… | Jul 14, 2026 | Jul 22, 2026 |
| | CVE-2026-42975 | Microsoft | high | 8.0 | 0.3%
| | Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execu… | Jul 14, 2026 | Jul 23, 2026 |
| | CVE-2026-42900 | Microsoft | high | 8.1 | 0.4%
| | Concurrent execution using shared resource with improper synchronization ('race condition') in Windo… | Jul 14, 2026 | Jul 23, 2026 |
| | CVE-2026-34346 | Microsoft | medium | 5.5 | 0.2%
| | Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock all… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-59841 | Fortinet | high | 7.5 | — | | A improper restriction of communication channel to intended endpoints vulnerability in Fortinet Fort… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-59840 | Fortinet | medium | 4.3 | 0.2%
| | A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.… | Jul 14, 2026 | Aug 11, 2026 |
| | CVE-2026-59839 | Fortinet | medium | 5.5 | 0.2%
| | A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fo… | Jul 14, 2026 | Aug 11, 2026 |
| | CVE-2026-59837 | Fortinet | medium | 6.6 | 0.6%
| | A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all… | Jul 14, 2026 | Aug 11, 2026 |
| | CVE-2026-59836 | Fortinet | high | 7.5 | 0.1%
| | A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, Fort… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-23573 | Fortinet | medium | 6.1 | 0.3%
| | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit… | Jul 14, 2026 | Aug 11, 2026 |
| | CVE-2025-62826 | Fortinet | low | 3.1 | 0.3%
| | An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerabili… | Jul 14, 2026 | Aug 11, 2026 |
| | CVE-2025-62675 | Fortinet | low | 3.4 | 0.2%
| | An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerabili… | Jul 14, 2026 | Aug 11, 2026 |
| | CVE-2025-53379 | Fortinet | high | 7.5 | 0.4%
| | A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenti… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2025-43892 | Fortinet | medium | 4.3 | 0.3%
| | A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.… | Jul 14, 2026 | Aug 11, 2026 |
| | CVE-2026-15265 | Tenable | critical | 9.1 | 0.6%
| | A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged atta… | Jul 14, 2026 | Aug 25, 2026 |
| | CVE-2026-59835 | Fortinet | high | 7.7 | 0.4%
| | A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, F… | Jul 14, 2026 | Jul 16, 2026 |
| | CVE-2026-62393 | Apache | medium | 4.3 | 0.5%
| | Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. Improper … | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-62392 | Apache | critical | 9.8 | — | | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerabi… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-62390 | Apache | critical | 9.8 | — | | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i… | Jul 14, 2026 | Jul 14, 2026 |
| | CVE-2026-49488 | Apache | medium | 6.5 | 0.7%
| | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apac… | Jul 14, 2026 | Jul 15, 2026 |
| | CVE-2026-12588 | Trellix | medium | 6.0 | — | | An attacker with access to an HX 10.0.0 and previous versions, may send specially-crafted data to t… | Jul 14, 2026 | Jul 14, 2026 |
| | CVE-2026-15713 | Red Hat | low | 5.9 | — | | A vulnerability was found in libsoup's HTTP/2 protocol implementation. The library fails to correctl… | Jul 14, 2026 | Jul 14, 2026 |
| | CVE-2026-15714 | Red Hat | medium | 6.5 | — | | An out-of-bounds read vulnerability was found in libsoup's multipart processing subsystem. The flaw … | Jul 14, 2026 | Jul 14, 2026 |
| | CVE-2026-58319 | Apache | critical | 9.1 | 0.3%
| | Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication.… | Jul 14, 2026 | Jul 14, 2026 |
| | CVE-2026-15712 | Red Hat | low | 5.9 | — | | A heap buffer over-read vulnerability was discovered in libsoup's (versions: libsoup 3.0 to 3.7.0) H… | Jul 14, 2026 | Jul 14, 2026 |
| | CVE-2026-15711 | Red Hat | medium | 7.5 | — | | A vulnerability was found in libsoup's WebSocket frame parsing implementation. The library fails to … | Jul 14, 2026 | Jul 14, 2026 |
| | CVE-2026-15709 | Red Hat | medium | 7.5 | — | | A flaw was found in libsoup's WebSocket implementation when using the permessage-deflate extension. … | Jul 14, 2026 | Jul 14, 2026 |
| | CVE-2026-59084 | Apache | critical | 9.1 | 0.2%
| | Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to secure… | Jul 14, 2026 | Jul 14, 2026 |
| | CVE-2026-59083 | Apache | critical | 9.1 | 0.2%
| | Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allo… | Jul 14, 2026 | Jul 14, 2026 |
| | CVE-2026-59674 | Red Hat | high | 8.8 | 0.1%
| | A flaw was found in suricata. This vulnerability, related to improper handling of symbolic links, al… | Jul 14, 2026 | Jul 14, 2026 |