| | CVE-2026-80536 | Red Hat | medium | 7.0 | 0.1%
| | In the Linux kernel, the following vulnerability has been resolved:
xfs: bounds-check buffer log ite… | Aug 26, 2026 | Aug 26, 2026 |
| | CVE-2026-80528 | Red Hat | medium | 7.0 | 0.5%
| | In the Linux kernel, the following vulnerability has been resolved:
ceph: avoid fs reclaim while usi… | Aug 26, 2026 | Aug 26, 2026 |
| | CVE-2026-80574 | Red Hat | medium | 5.5 | 0.1%
| | In the Linux kernel, the following vulnerability has been resolved:
Input: focaltech - fix array out… | Aug 26, 2026 | Aug 26, 2026 |
| | CVE-2026-80548 | Red Hat | medium | 5.5 | 0.1%
| | In the Linux kernel, the following vulnerability has been resolved:
s390/vfio_ccw: Selectively expan… | Aug 26, 2026 | Aug 26, 2026 |
| | CVE-2026-80551 | Red Hat | medium | 5.5 | 0.1%
| | In the Linux kernel, the following vulnerability has been resolved:
s390/vfio_ccw: Ensure first IDAW… | Aug 26, 2026 | Aug 26, 2026 |
| | CVE-2026-80579 | Red Hat | medium | 5.5 | 0.1%
| | In the Linux kernel, the following vulnerability has been resolved:
fbdev: clear fb_info->mode befor… | Aug 26, 2026 | Aug 26, 2026 |
| | CVE-2026-80549 | Red Hat | low | 5.5 | 0.1%
| | In the Linux kernel, the following vulnerability has been resolved:
s390/vfio_ccw: Move cp cleanup o… | Aug 26, 2026 | Aug 26, 2026 |
| | CVE-2026-74745 | Red Hat | low | 5.5 | 0.4%
| | In the Linux kernel, the following vulnerability has been resolved:
eth: bnxt: avoid deadlock when c… | Aug 26, 2026 | Aug 26, 2026 |
| | CVE-2026-80552 | Red Hat | medium | 7.0 | 0.1%
| | In the Linux kernel, the following vulnerability has been resolved:
s390/vfio_ccw: Ensure index for … | Aug 26, 2026 | Aug 26, 2026 |
| | CVE-2026-80588 | Red Hat | medium | 5.5 | 0.3%
| | In the Linux kernel, the following vulnerability has been resolved:
mptcp: reclaim forward-allocated… | Aug 26, 2026 | Aug 26, 2026 |
| | CVE-2026-80561 | Red Hat | medium | 7.0 | 0.5%
| | In the Linux kernel, the following vulnerability has been resolved:
libceph: fix multiple unsafe dec… | Aug 26, 2026 | Aug 26, 2026 |
| | CVE-2026-80560 | Red Hat | medium | 5.5 | 0.1%
| | In the Linux kernel, the following vulnerability has been resolved:
openrisc: signal: do not restore… | Aug 26, 2026 | Aug 26, 2026 |
| | CVE-2026-80534 | Red Hat | low | 4.7 | 0.2%
| | In the Linux kernel, the following vulnerability has been resolved:
xfs: fix ilock leak on error in … | Aug 26, 2026 | Aug 26, 2026 |
| | CVE-2026-80158 | Red Hat | medium | 5.5 | 0.1%
| | A flaw was found in the ipa_getkeytab module of the community.general
Ansible collection. The module… | Aug 26, 2026 | Aug 26, 2026 |
| | CVE-2026-57171 | Red Hat | high | 7.7 | 0.2%
| | Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance doc… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-57170 | Red Hat | high | 7.8 | 0.2%
| | Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance doc… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-41707 | VMware | high | 7.4 | 0.3%
| | Authentication Bypass by Capture-replay vulnerability in Spring Spring Security allows Spring Securi… | Aug 25, 2026 | Aug 28, 2026 |
| | CVE-2026-52776 | Red Hat | high | 8.1 | 0.4%
| | Compliance-trestle (Trestle) is a tooling platform for managing compliance as code. In versions befo… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-54757 | Red Hat | high | 7.8 | 0.2%
| | Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance doc… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-16645 | Red Hat | high | 7.5 | 0.2%
| | Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-73180 | Apache | medium | 6.8 | 0.5%
| | Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an a… | Aug 25, 2026 | Aug 27, 2026 |
| | CVE-2026-68763 | Apache | high | 7.5 | 0.8%
| | Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/… | Aug 25, 2026 | Aug 27, 2026 |
| | CVE-2026-68569 | Apache | high | 8.1 | 0.5%
| | Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT… | Aug 25, 2026 | Aug 27, 2026 |
| | CVE-2026-68525 | Apache | critical | 9.1 | 0.6%
| | Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypa… | Aug 25, 2026 | Aug 27, 2026 |
| | CVE-2026-66422 | Apache | high | 8.1 | 0.6%
| | Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being i… | Aug 25, 2026 | Aug 27, 2026 |
| | CVE-2026-65927 | Apache | high | 7.5 | 0.8%
| | Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the rewrite valves causes … | Aug 25, 2026 | Aug 27, 2026 |
| | CVE-2026-65905 | Apache | critical | 9.8 | 0.8%
| | Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, b… | Aug 25, 2026 | Aug 27, 2026 |
| | CVE-2026-65637 | Apache | critical | 9.8 | 0.8%
| | Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990.
… | Aug 25, 2026 | Aug 27, 2026 |
| | CVE-2026-65183 | Apache | high | 8.1 | 0.5%
| | Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix … | Aug 25, 2026 | Aug 27, 2026 |
| | CVE-2026-65182 | Apache | critical | 9.1 | 0.6%
| | Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security co… | Aug 25, 2026 | Aug 27, 2026 |
| | CVE-2026-32637 | VMware | medium | — | 0.5%
| | Velero is an open source tool for backing up, restoring, and migrating Kubernetes cluster resources … | Aug 25, 2026 | Aug 28, 2026 |
| | CVE-2026-72924 | Red Hat | medium | 4.6 | 0.2%
| | GitHub CLI (gh) is GitHub's official command line tool. Versions 2.28.0 through 2.97.0 bind the loca… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-68515 | Red Hat | high | 7.1 | 0.1%
| | OpenEXR is the reference implementation and specification for the EXR image format, widely used in t… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-19913 | Red Hat | high | 7.5 | 0.4%
| | The Kaltura HTML5 player (mwEmbed / html5lib) contains a local file disclosure vulnerability due to … | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-55553 | Red Hat | high | 7.5 | 0.4%
| | urllib is an HTTP client for Node.js that supports authentication, redirects, timeouts, and other re… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-63075 | Red Hat | low | 7.5 | 0.5%
| ✓ Fix | Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly
sends ack-eliciting p… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-79781 | Red Hat | medium | 6.5 | 0.3%
| | rclone serve s3 before 1.74.4 contains a path traversal vulnerability that allows attackers to read … | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-79779 | Red Hat | medium | 5.3 | 0.1%
| | rclone versions before v1.75.0 fail to reject transport downgrades in redirect handling, allowing Ba… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-79780 | Red Hat | medium | 5.3 | 0.1%
| | rclone before v1.75.0 fails to sanitize IBM IAM bearer tokens and SSE-C encryption keys during S3 re… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-79776 | Red Hat | high | 7.5 | 0.3%
| | rclone before 1.75.0 mounts the pprof debug handler as its own router route, bypassing the fail-clos… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-79772 | Red Hat | medium | 5.3 | 0.3%
| | Nokogiri versions before 1.19.1 fail to check the return value from xmlC14NExecute in the canonicali… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-79770 | Red Hat | high | 7.5 | 0.3%
| | Nokogiri versions before 1.19.3 contain regular expression denial of service vulnerabilities in the … | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-79771 | Red Hat | medium | 5.3 | 0.3%
| | Nokogiri versions before 1.19.3 contain a memory leak in the XSLT Stylesheet transform method when p… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-79769 | Red Hat | medium | 5.5 | 0.2%
| | Nokogiri versions before 1.19.4 contain a possible invalid (out-of-bounds) memory read in the protec… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-79676 | Red Hat | medium | 5.9 | 0.3%
| | NLTK versions before 3.10.3 contain a path traversal vulnerability in corpus readers that reopen roo… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2026-79674 | Red Hat | high | 7.5 | 0.2%
| | NLTK versions before 3.10.3 contain a path sandbox bypass vulnerability in corpus-reader constructor… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2025-71406 | Red Hat | high | 7.8 | 0.2%
| | Nokogiri before 1.18.4 bundles a vulnerable version of libxslt (prior to 1.1.43) that contains two u… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2025-71346 | Red Hat | low | 2.9 | 0.2%
| | Nokogiri before 1.18.8 packages a vulnerable version of libxml2 (before 2.13.8) that contains a heap… | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2023-54354 | Red Hat | medium | 5.9 | 0.4%
| | Nokogiri before 1.14.3 (CRuby implementation only, when using the packaged libxml2) bundles libxml2 … | Aug 25, 2026 | Aug 25, 2026 |
| | CVE-2022-50999 | Red Hat | high | 7.0 | 0.3%
| | Nokogiri versions before 1.13.5 contain an integer overflow vulnerability in packaged libxml2 buffer… | Aug 25, 2026 | Aug 25, 2026 |