# Advisories: every advisory (newest first, up to 5000) # published | id cve | package | severity score | summary | source 2026-09-26 | CVE-2026-94396 CVE-2026-94396 | Elastic | medium 6.5 | Elasticsearch: resource exhaustion | https://discuss.elastic.co/t/elasticsearch-9-4-7-9-5-4-security-update-esa-2026-182/390686 2026-09-26 | CVE-2026-94397 CVE-2026-94397 | Elastic | medium 6.5 | Elasticsearch: resource exhaustion | https://discuss.elastic.co/t/elasticsearch-8-19-22-9-4-7-9-5-4-security-update-esa-2026-183/390687 2026-09-26 | CVE-2026-94398 CVE-2026-94398 | Elastic | medium 6.5 | Elasticsearch: resource exhaustion | https://discuss.elastic.co/t/elasticsearch-8-19-22-9-4-7-9-5-4-security-update-esa-2026-179/390683 2026-09-26 | CVE-2026-94399 CVE-2026-94399 | Elastic | medium 6.5 | Elasticsearch: resource exhaustion | https://discuss.elastic.co/t/elasticsearch-8-19-22-9-4-7-9-5-4-security-update-esa-2026-180/390684 2026-09-26 | CVE-2026-94400 CVE-2026-94400 | Elastic | medium 6.5 | Elastic Kibana: resource exhaustion | https://discuss.elastic.co/t/kibana-8-19-22-9-4-7-9-5-3-security-update-esa-2026-181/390685 2026-09-26 | CVE-2026-94408 CVE-2026-94408 | Elastic | medium 4.9 | Elasticsearch: resource exhaustion | https://discuss.elastic.co/t/elasticsearch-8-19-22-9-4-7-9-5-3-security-update-esa-2026-184/390688 2026-09-26 | CVE-2026-72662 CVE-2026-72662 | Elastic | medium 6.3 | Elastic Kibana: insecure direct object reference | https://discuss.elastic.co/t/kibana-8-19-22-9-4-6-security-update-esa-2026-103/390679 2026-09-26 | CVE-2026-72668 CVE-2026-72668 | Elastic | high 7.3 | Elastic Kibana: privilege escalation | https://discuss.elastic.co/t/kibana-9-4-7-9-5-0-security-update-esa-2026-85/390678 2026-09-26 | CVE-2026-78582 CVE-2026-78582 | Elastic | medium 6.5 | Elastic Kibana: missing authorization | https://discuss.elastic.co/t/kibana-8-19-22-9-4-7-9-5-3-security-update-esa-2026-139/390680 2026-09-26 | CVE-2026-82294 CVE-2026-82294 | Elastic | medium 6.5 | Elasticsearch: resource exhaustion | https://discuss.elastic.co/t/elasticsearch-8-19-21-9-4-6-9-5-3-security-update-esa-2026-170/390681 2026-09-26 | CVE-2026-82300 CVE-2026-82300 | Elastic | medium 6.5 | Elasticsearch: resource exhaustion | https://discuss.elastic.co/t/elasticsearch-8-19-22-9-4-7-9-5-4-security-update-esa-2026-176/390682 2026-09-25 | GHSA-62mm-xwmv-crhg | Khoj | high | khoj has an unauthenticated path traversal in /home/ endpoint that allows file read from server filesystem | https://github.com/advisories/GHSA-62mm-xwmv-crhg 2026-09-25 | GHSA-c4f4-pq98-f2p2 | Google | high 8.0 | Google: code injection | https://github.com/google/schema-dts/security/advisories/GHSA-c4f4-pq98-f2p2 2026-09-25 | GHSA-v234-4jrq-mgg6 | Anthropic | high 8.5 | Claude Desktop (macOS): opening a malicious file from a Cowork folder could run commands on the host | https://github.com/anthropics/claude-code/security/advisories/GHSA-v234-4jrq-mgg6 2026-09-25 | CVE-2026-10758 CVE-2026-10758 | Esri | high 7.5 | Esri Lerc: out-of-bounds write | https://github.com/Esri/lerc/security/advisories/GHSA-cw29-mw7w-pj37 2026-09-25 | CVE-2026-5267 CVE-2026-5267 | Ciena | high 7.5 | Ciena Navigator NCS: information disclosure | https://www.ciena.com/product-security 2026-09-25 | CVE-2026-100208 CVE-2026-100208 | Microsoft | high 7.5 | Microsoft Office Outlook: integer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-100208 2026-09-25 | GHSA-59g6-234f-frf6 | AWS | low | REMOVE_BASE_PATH strips every leading repetition of the base path, not just one | https://github.com/aws/aws-lambda-web-adapter/security/advisories/GHSA-59g6-234f-frf6 2026-09-25 | CVE-2026-96812 CVE-2026-96812 | Google | high 8.8 | Google gVisor: code execution | https://github.com/google/gvisor/commit/573a9e73cf844f 2026-09-25 | CVE-2026-84862 CVE-2026-84862 | IBM | high 7.2 | IBM Guardium Data Protection: unsafe deserialization | https://www.ibm.com/support/pages/node/7288040 2026-09-25 | CVE-2026-84882 CVE-2026-84882 | IBM | high 7.5 | IBM Guardium Data Protection: path traversal | https://www.ibm.com/support/pages/node/7288035 2026-09-25 | CVE-2026-93030 CVE-2026-93030 | IBM | medium 6.5 | IBM Financial Transaction Manager for Redhat OpenShift: information disclosure | https://www.ibm.com/support/pages/node/7288641 2026-09-25 | CVE-2026-93306 CVE-2026-93306 | IBM | high 7.1 | IBM Server Firmware: memory corruption | https://www.ibm.com/support/pages/node/7289331 2026-09-25 | CVE-2026-93834 CVE-2026-93834 | Red Hat | high 8.8 | Red Hat QEMU: use after free | https://access.redhat.com/security/cve/CVE-2026-93834 2026-09-25 | CVE-2026-85029 CVE-2026-85029 | IBM | high 7.5 | IBM Guardium Data Protection: information disclosure | https://www.ibm.com/support/pages/node/7288034 2026-09-25 | CVE-2026-85542 CVE-2026-85542 | IBM | high 8.8 | IBM Guardium Data Protection: command injection | https://www.ibm.com/support/pages/node/7288035 2026-09-25 | CVE-2026-84884 CVE-2026-84884 | IBM | high 7.5 | IBM Guardium Data Protection: plaintext password storage | https://www.ibm.com/support/pages/node/7288035 2026-09-25 | CVE-2026-84893 CVE-2026-84893 | IBM | high 7.6 | IBM Guardium Data Protection: SQL injection | https://www.ibm.com/support/pages/node/7288035 2026-09-25 | CVE-2026-97875 CVE-2026-97875 | Red Hat | high 8.1 | Rojo's "rojo serve" HTTP API | https://github.com/rojo-rbx/rojo/pull/1270 2026-09-25 | CVE-2026-97228 CVE-2026-97228 | Rapid7 | low 2.7 | Rapid7 Bulk Export MCP versions 0.2.5 through 0.6.1 suffer from a GraphQL query... | https://github.com/rapid7/rapid7-bulk-export-mcp/releases/tag/v0.6.2 2026-09-25 | CVE-2026-96448 CVE-2026-96448 | Red Hat | medium 6.6 | Red Hat Build of Keycloak: improper authorization | https://access.redhat.com/security/cve/CVE-2026-96448 2026-09-25 | CVE-2026-97846 CVE-2026-97846 | Red Hat | medium 6.8 | Red Hat Build of Keycloak: improper authentication | https://access.redhat.com/security/cve/CVE-2026-97846 2026-09-24 | CVE-2026-82164 CVE-2026-82164 | Dell Technologies | high 7.1 | Dell Technologies Trusted Device Client,: insecure permissions | https://www.dell.com/support/kbdoc/en-us/000506918/dsa-2026-408-security-update-for-dell-trusted-device-client-for-an-incorrect-permission-assignment-for-critical-resource-vulnerability 2026-09-24 | CVE-2026-89325 CVE-2026-89325 | Rapid7 | high 7.8 | Rapid7 Insight Agent: code execution | https://docs.rapid7.com/insight/release-notes-2026-september/#resolved-cve-2026-89325 2026-09-24 | CVE-2026-86857 CVE-2026-86857 | ServiceNow | high 8.4 | ServiceNow AI Platform: missing authorization | https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB3159623 2026-09-24 | CVE-2026-86858 CVE-2026-86858 | ServiceNow | high 8.7 | ServiceNow AI Platform: improper access control | https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB3159623 2026-09-24 | CVE-2026-86859 CVE-2026-86859 | ServiceNow | high 8.7 | ServiceNow AI Platform: unauthenticated user could access data within | https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB3159623 2026-09-24 | CVE-2026-86860 CVE-2026-86860 | ServiceNow | critical 9.3 | ServiceNow AI Platform: missing authorization | https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB3159623 2026-09-24 | CVE-2026-81455 CVE-2026-81455 | Dell Technologies | high 8.6 | Dell Technologies ThinOS 10: missing authentication | https://www.dell.com/support/kbdoc/en-us/000506503/dsa-2026-404-security-update-for-dell-thinos-10-for-multiple-vulnerabilities 2026-09-24 | CVE-2026-81473 CVE-2026-81473 | Dell Technologies | high 8.1 | Dell Technologies Rugged Control Center (RCC): improper authorization | https://www.dell.com/support/kbdoc/en-us/000506924/dsa-2026-410-security-update-for-dell-rugged-control-center-rcc-multiple-vulnerabilities 2026-09-24 | CVE-2026-82157 CVE-2026-82157 | Dell Technologies | high 8.3 | Dell Technologies ThinOS 10: improper certificate validation | https://www.dell.com/support/kbdoc/en-us/000506503/dsa-2026-404-security-update-for-dell-thinos-10-for-multiple-vulnerabilities 2026-09-24 | CVE-2026-56792 CVE-2026-56792 | Dell Technologies | medium 4.4 | Dell Technologies Rugged Control Center (RCC): improper authorization | https://www.dell.com/support/kbdoc/en-us/000506924/dsa-2026-410-security-update-for-dell-rugged-control-center-rcc-multiple-vulnerabilities 2026-09-24 | CVE-2026-13249 CVE-2026-13249 | Honeywell | critical 9.8 | Honeywell PD45 Industrial Printer: remote code execution via file upload | https://www.honeywell.com/us/en/legal/product-security#security-notices 2026-09-24 | CVE-2026-13248 CVE-2026-13248 | Honeywell | high 8.8 | Honeywell PD45 Industrial Printer: remote code execution | https://www.honeywell.com/us/en/legal/product-security#security-notices 2026-09-24 | CVE-2026-13016 CVE-2026-13016 | ServiceNow | critical 9.3 | ServiceNow AI Platform: SQL injection | https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB3159623 2026-09-24 | GHSA-v4x9-3549-crwv CVE-2026-96749 | MongoDB | high 7.5 | PYTHON-5996 Heap out-of-bounds write via signed size overflow in BSON document encoding | https://github.com/mongodb/mongo-python-driver/security/advisories/GHSA-v4x9-3549-crwv 2026-09-24 | GHSA-vp6j-j7w5-5xjj CVE-2026-96748 | MongoDB | high 8.3 | PYTHON-5986 Host injection in PyMongo connection string parsing via percent-encoded delimiters | https://github.com/mongodb/mongo-python-driver/security/advisories/GHSA-vp6j-j7w5-5xjj 2026-09-24 | GHSA-qx36-8mw2-4r3x CVE-2026-96747 | MongoDB | medium 5.3 | MongoDB: improper input validation | https://github.com/mongodb/mongo-python-driver/security/advisories/GHSA-qx36-8mw2-4r3x 2026-09-24 | CVE-2026-95985 CVE-2026-95985 | Amazon | high 8.6 | Amazon Kiro IDE: untrusted functionality included | https://aws.amazon.com/security/security-bulletins/2026-117-aws/ 2026-09-24 | CVE-2026-96744 CVE-2026-96744 | MongoDB | high 7.1 | Improper neutralization of special elements in data query logic in the cache... | https://github.com/mongodb/laravel-mongodb/pull/3579 2026-09-24 | CVE-2026-96750 CVE-2026-96750 | MongoDB | high 7.3 | MongoDB Compass: code injection | https://github.com/mongodb-js/compass/releases/tag/v1.49.12 2026-09-24 | GHSA-frjf-h5jg-4v46 CVE-2026-96746 | MongoDB | high 8.3 | Heap buffer overflow via mid-scan command list growth in client topology monitoring | https://github.com/mongodb/mongo-c-driver/security/advisories/GHSA-frjf-h5jg-4v46 2026-09-24 | GHSA-cmvj-vxvq-rh2c CVE-2026-96745 | MongoDB | medium 6.3 | PHP object injection via unsuppressible __pclass class inference in command monitoring events | https://github.com/mongodb/mongo-php-driver/security/advisories/GHSA-cmvj-vxvq-rh2c 2026-09-24 | CVE-2026-90959 CVE-2026-90959 | Red Hat | high 8.1 | Red Hat pulpcore: path traversal | https://access.redhat.com/security/cve/CVE-2026-90959 2026-09-24 | CVE-2026-81552 CVE-2026-81552 | IBM | high 8.8 | IBM DataStage on Cloud Pak for Data: remote code execution | https://www.ibm.com/support/pages/node/7288649 2026-09-24 | CVE-2026-82093 CVE-2026-82093 | IBM | high 8.8 | IBM DataStage on Cloud Pak for Data: remote code execution | https://www.ibm.com/support/pages/node/7288649 2026-09-24 | CVE-2026-82094 CVE-2026-82094 | IBM | high 7.1 | IBM DataStage on Cloud Pak for Data: path traversal | https://www.ibm.com/support/pages/node/7288649 2026-09-24 | CVE-2026-81539 CVE-2026-81539 | IBM | high 8.8 | IBM DataStage on Cloud Pak for Data: remote code execution | https://www.ibm.com/support/pages/node/7288649 2026-09-24 | CVE-2026-81545 CVE-2026-81545 | IBM | high 8.8 | IBM DataStage on Cloud Pak for Data: remote code execution | https://www.ibm.com/support/pages/node/7288649 2026-09-24 | CVE-2026-81547 CVE-2026-81547 | IBM | high 8.8 | IBM DataStage on Cloud Pak for Data: remote code execution | https://www.ibm.com/support/pages/node/7288649 2026-09-24 | CVE-2026-81548 CVE-2026-81548 | IBM | high 8.8 | IBM DataStage on Cloud Pak for Data: remote code execution | https://www.ibm.com/support/pages/node/7288649 2026-09-24 | CVE-2026-81549 CVE-2026-81549 | IBM | critical 9.6 | IBM DataStage on Cloud Pak for Data: information disclosure | https://www.ibm.com/support/pages/node/7288649 2026-09-24 | CVE-2026-77825 CVE-2026-77825 | IBM | medium 4.9 | IBM ContextForge MCP Gateway: path traversal | https://www.ibm.com/support/pages/node/7289314 2026-09-24 | CVE-2026-77874 CVE-2026-77874 | IBM | high 8.6 | IBM Enterprise Build of Quarkus: SQL injection | https://www.ibm.com/support/pages/node/7289050 2026-09-24 | CVE-2026-6544 CVE-2026-6544 | IBM | medium 6.2 | IBM Concert: exposed files | https://www.ibm.com/support/pages/node/7288830 2026-09-24 | CVE-2026-18870 CVE-2026-18870 | IBM | medium 4.3 | IBM PowerVM Hypervisor: information disclosure | https://www.ibm.com/support/pages/node/7289135 2026-09-24 | CVE-2026-19492 CVE-2026-19492 | IBM | low 3.2 | IBM PowerVM Hypervisor FW1120.00 through FW1120.01 | https://www.ibm.com/support/pages/node/7289137 2026-09-24 | CVE-2026-12559 CVE-2026-12559 | Open Text Corporation | high 7.3 | Open Text Vendor Invoice Management for SAP Solutions: cross-site scripting | https://support.opentext.com/csm?id=kb_article_view&sysparm_article=KB0869040 2026-09-24 | CVE-2026-95519 CVE-2026-95519 | Red Hat | high 7.8 | Red Hat rpm: code execution | https://access.redhat.com/security/cve/CVE-2026-95519 2026-09-24 | CVE-2026-95521 CVE-2026-95521 | Red Hat | high 7.8 | Red Hat rpm: command injection | https://access.redhat.com/security/cve/CVE-2026-95521 2026-09-24 | CVE-2026-77797 CVE-2026-77797 | Rapid7 | low 3.6 | Rapid7 Velociraptor: improper input validation | http://docs.velociraptor.app/announcements/advisories/cve-2026-7797/ 2026-09-24 | CVE-2026-77798 CVE-2026-77798 | Rapid7 | medium 6.5 | Velociraptor contains a deadlock condition | http://docs.velociraptor.app/announcements/advisories/cve-2026-7798/ 2026-09-24 | CVE-2026-17503 CVE-2026-17503 | IBM | medium 5.1 | IBM PowerVM Hypervisor: improper input validation | https://www.ibm.com/support/pages/node/7289133 2026-09-24 | CVE-2026-17504 CVE-2026-17504 | IBM | medium 5.1 | IBM PowerVM Hypervisor: memory corruption | https://www.ibm.com/support/pages/node/7289130 2026-09-24 | CVE-2026-17511 CVE-2026-17511 | IBM | low 3.4 | IBM PowerVM Hypervisor FW1120.00 through FW1120.01 | https://www.ibm.com/support/pages/node/7289132 2026-09-24 | CVE-2026-18104 CVE-2026-18104 | IBM | low 3.3 | IBM Db2 Mirror for i: information disclosure | https://www.ibm.com/support/pages/node/7289246 2026-09-24 | CVE-2026-18857 CVE-2026-18857 | IBM | low 3.4 | IBM OPENBMC: out-of-bounds read | https://www.ibm.com/support/pages/node/7289253 2026-09-24 | CVE-2026-17413 CVE-2026-17413 | IBM | medium 5.1 | IBM PowerVM Hypervisor: improper array index validation | https://www.ibm.com/support/pages/node/7289124 2026-09-24 | CVE-2026-94416 CVE-2026-94416 | Red Hat | medium 6.8 | Red Hat Ansible Automation Platform 2: authentication bypass by spoofing | https://access.redhat.com/security/cve/CVE-2026-94416 2026-09-24 | CVE-2026-19072 CVE-2026-19072 | Rapid7 | critical 9.9 | Velociraptor stores the compiled VQL in the hunt object internally to avoid... | https://docs.velociraptor.app/announcements/advisories/cve-2026-19072/ 2026-09-24 | GHSA-wcfm-jp7m-rffh | Google | high | Dell BOSS-N1 S-MCU Firmware Integrity and Cryptographic Verification Bypass | https://github.com/google/security-research/security/advisories/GHSA-wcfm-jp7m-rffh 2026-09-24 | CVE-2026-97311 CVE-2026-97311 | Red Hat | medium 4.3 | Red Hat Admin REST API of Keycloak: missing authorization | https://access.redhat.com/security/cve/CVE-2026-97311 2026-09-24 | AWS-2026-118 CVE-2026-96883 | AWS | high 8.8 | Type confusion in AWS pgcollection allows remote code execution | https://aws.amazon.com/security/security-bulletins/rss/2026-118-aws/ 2026-09-24 | CVE-2026-79680 CVE-2026-79680 | Qt Group Plc | medium 4.5 | qt: authentication bypass | https://codereview.qt-project.org/c/qt/tqtc-qtvncserver/+/759160 2026-09-24 | CVE-2026-78308 CVE-2026-78308 | Delta Electronics | critical 9.8 | Delta Electronics DIAEnergie: improper authentication | https://filecenter.deltaww.com/news/download/doc/Delta-PCSA-2026-00014_DIAEnergie%20Multiple%20Vulberabilities%20(CVE-2026-78308%20~%2078313).pdf 2026-09-24 | CVE-2026-78309 CVE-2026-78309 | Delta Electronics | high 8.8 | Delta Electronics DIAEnergie: SQL injection | https://filecenter.deltaww.com/news/download/doc/Delta-PCSA-2026-00014_DIAEnergie%20Multiple%20Vulberabilities%20(CVE-2026-78308%20~%2078313).pdf 2026-09-24 | CVE-2026-78310 CVE-2026-78310 | Delta Electronics | medium 4.3 | Delta Electronics DIAEnergie: insecure direct object reference | https://filecenter.deltaww.com/news/download/doc/Delta-PCSA-2026-00014_DIAEnergie%20Multiple%20Vulberabilities%20(CVE-2026-78308%20~%2078313).pdf 2026-09-24 | CVE-2026-78311 CVE-2026-78311 | Delta Electronics | high 8.8 | Delta Electronics DIAEnergie: SQL injection | https://filecenter.deltaww.com/news/download/doc/Delta-PCSA-2026-00014_DIAEnergie%20Multiple%20Vulberabilities%20(CVE-2026-78308%20~%2078313).pdf 2026-09-24 | CVE-2026-78312 CVE-2026-78312 | Delta Electronics | critical 9.1 | Delta Electronics DIAEnergie: path traversal | https://filecenter.deltaww.com/news/download/doc/Delta-PCSA-2026-00014_DIAEnergie%20Multiple%20Vulberabilities%20(CVE-2026-78308%20~%2078313).pdf 2026-09-24 | CVE-2026-78313 CVE-2026-78313 | Delta Electronics | medium 6.5 | Delta Electronics DIAEnergie: improper access control | https://filecenter.deltaww.com/news/download/doc/Delta-PCSA-2026-00014_DIAEnergie%20Multiple%20Vulberabilities%20(CVE-2026-78308%20~%2078313).pdf 2026-09-24 | CVE-2026-97185 CVE-2026-97185 | Red Hat | high 7.8 | Red Hat GIMP.: out-of-bounds write | https://access.redhat.com/security/cve/CVE-2026-97185 2026-09-24 | CVE-2026-81645 CVE-2026-81645 | Huawei | medium 5.9 | Huawei HarmonyOS: out-of-bounds read | https://consumer.huawei.com/en/support/bulletin/2026/9/ 2026-09-24 | CVE-2026-97176 CVE-2026-97176 | Red Hat | medium 4.2 | Red Hat Build of Keycloak: missing authorization | https://access.redhat.com/security/cve/CVE-2026-97176 2026-09-24 | CVE-2026-97177 CVE-2026-97177 | Red Hat | medium 6.6 | Red Hat Build of Keycloak: missing authorization | https://access.redhat.com/security/cve/CVE-2026-97177 2026-09-24 | CVE-2026-89078 CVE-2026-89078 | GitLab | critical 9.9 | GitLab: code execution | https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-4-1-released/ 2026-09-24 | CVE-2026-92470 CVE-2026-92470 | GitLab | high 7.7 | GitLab: missing authorization | https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-4-1-released/ 2026-09-24 | CVE-2026-92529 CVE-2026-92529 | GitLab | medium 4.3 | GitLab: improper authorization | https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-4-1-released/ 2026-09-24 | CVE-2026-92530 CVE-2026-92530 | GitLab | medium 4.3 | GitLab: authenticated user could spoof merge request authorship | https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-4-1-released/ 2026-09-24 | CVE-2026-92628 CVE-2026-92628 | GitLab | low 3.1 | GitLab: race condition | https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-4-1-released/ 2026-09-24 | CVE-2026-92874 CVE-2026-92874 | GitLab | medium 5.4 | GitLab: improper authorization | https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-4-1-released/ 2026-09-24 | CVE-2026-93577 CVE-2026-93577 | GitLab | critical 9.9 | GitLab: code execution | https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-4-1-released/ 2026-09-23 | PYSEC-2026-3987 | MemOS | unknown | MemoryOS 2.0.34 was published with a credential-stealing binary | https://osv.dev/vulnerability/PYSEC-2026-3987 2026-09-23 | MAL-2026-16475 | MemOS | unknown | Malicious code in memoryos (PyPI) | https://osv.dev/vulnerability/MAL-2026-16475 2026-09-23 | CVE-2026-70125 CVE-2026-70125 | Microsoft | high 8.8 | Microsoft 365 Apps for Enterprise: remote code execution | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70125 2026-09-23 | CVE-2026-75887 CVE-2026-75887 | Red Hat | high 7.5 | Red Hat OpenShift Container Platform 4: path traversal | https://access.redhat.com/security/cve/CVE-2026-75887 2026-09-23 | CVE-2026-80423 CVE-2026-80423 | IBM | high 8.8 | IBM DataStage on Cloud Pak for Data: information disclosure | https://www.ibm.com/support/pages/node/7288649 2026-09-23 | CVE-2026-81208 CVE-2026-81208 | IBM | high 7.7 | IBM DataStage on Cloud Pak for Data: information disclosure | https://www.ibm.com/support/pages/node/7288649 2026-09-23 | CVE-2026-81536 CVE-2026-81536 | IBM | high 7.7 | IBM DataStage on Cloud Pak for Data: information disclosure | https://www.ibm.com/support/pages/node/7288649 2026-09-23 | CVE-2026-81537 CVE-2026-81537 | IBM | high 8.8 | IBM DataStage on Cloud Pak for Data: remote code execution | https://www.ibm.com/support/pages/node/7288649 2026-09-23 | CVE-2026-80412 CVE-2026-80412 | IBM | high 8.8 | IBM DataStage on Cloud Pak for Data: remote code execution | https://www.ibm.com/support/pages/node/7288649 2026-09-23 | CVE-2026-80425 CVE-2026-80425 | IBM | high 8.8 | IBM DataStage on Cloud Pak for Data: remote code execution | https://www.ibm.com/support/pages/node/7288649 2026-09-23 | CVE-2026-6730 CVE-2026-6730 | IBM | critical 9.8 | IBM Concert: buffer overflow | https://www.ibm.com/support/pages/node/7288830 2026-09-23 | CVE-2026-6794 CVE-2026-6794 | IBM | high 7.8 | IBM Concert: double free | https://www.ibm.com/support/pages/node/7288830 2026-09-23 | CVE-2026-6925 CVE-2026-6925 | IBM | medium 5.3 | IBM Concert: path traversal | https://www.ibm.com/support/pages/node/7288830 2026-09-23 | CVE-2026-6928 CVE-2026-6928 | IBM | critical 9.8 | IBM Concert: code execution | https://www.ibm.com/support/pages/node/7288830 2026-09-23 | CVE-2026-6935 CVE-2026-6935 | IBM | high 7.8 | IBM Concert: uncontrolled search path | https://www.ibm.com/support/pages/node/7288830 2026-09-23 | CVE-2026-75886 CVE-2026-75886 | Red Hat | high 7.2 | Red Hat OpenShift Container Platform 4: attacker could send requests | https://access.redhat.com/security/cve/CVE-2026-75886 2026-09-23 | CVE-2026-80379 CVE-2026-80379 | IBM | high 8.8 | IBM DataStage on Cloud Pak for Data: remote code execution | https://www.ibm.com/support/pages/node/7288649 2026-09-23 | CVE-2026-6718 CVE-2026-6718 | IBM | medium 6.2 | IBM Concert: improper access control | https://www.ibm.com/support/pages/node/7288830 2026-09-23 | CVE-2026-6721 CVE-2026-6721 | IBM | critical 9.8 | IBM Concert: remote code execution | https://www.ibm.com/support/pages/node/7288830 2026-09-23 | GHSA-x78f-wrrj-4h24 | GitHub | high 8.3 | gh-aw: HTTPS egress allowlist bypass via TLS SNI domain fronting | https://github.com/github/gh-aw/security/advisories/GHSA-x78f-wrrj-4h24 2026-09-23 | CVE-2026-96889 CVE-2026-96889 | Red Hat | high 7.8 | Red Hat librsvg.: use after free | https://access.redhat.com/security/cve/CVE-2026-96889 2026-09-23 | CVE-2026-84724 CVE-2026-84724 | Red Hat | medium 6.6 | Red Hat: argument injection | https://access.redhat.com/errata/RHSA-2026:71113 2026-09-23 | CVE-2026-85475 CVE-2026-85475 | Red Hat | high 7.2 | A flaw was found in the Ansible Automation Platform automation controller | https://access.redhat.com/errata/RHSA-2026:71177 2026-09-23 | CVE-2026-84714 CVE-2026-84714 | Red Hat | high 7.1 | Red Hat: incomplete denylist | https://access.redhat.com/errata/RHSA-2026:71113 2026-09-23 | CVE-2026-84716 CVE-2026-84716 | Red Hat | medium 6.6 | A flaw was found in the automation-controller instance install-bundle endpoint | https://access.redhat.com/errata/RHSA-2026:71113 2026-09-23 | CVE-2026-84717 CVE-2026-84717 | Red Hat | medium 5.3 | A flaw was found in the Ansible Automation Platform automation-controller | https://access.redhat.com/errata/RHSA-2026:71113 2026-09-23 | CVE-2026-84718 CVE-2026-84718 | Red Hat | medium 4.3 | A flaw was found in the Ansible Automation Platform automation-controller | https://access.redhat.com/errata/RHSA-2026:71113 2026-09-23 | CVE-2026-84719 CVE-2026-84719 | Red Hat | critical 9.9 | Red Hat Ansible Automation: missing authorization | https://access.redhat.com/errata/RHSA-2026:71113 2026-09-23 | CVE-2026-84720 CVE-2026-84720 | Red Hat | medium 6.5 | Red Hat: insecure direct object reference | https://access.redhat.com/errata/RHSA-2026:71113 2026-09-23 | CVE-2026-84721 CVE-2026-84721 | Red Hat | medium 6.4 | Red Hat Ansible Automation Platform 2: server-side request forgery | https://access.redhat.com/errata/RHSA-2026:71177 2026-09-23 | CVE-2026-84683 CVE-2026-84683 | Red Hat | high 8.7 | Red Hat Ansible Automation Platform: cross-site scripting | https://access.redhat.com/errata/RHSA-2026:71113 2026-09-23 | CVE-2026-84691 CVE-2026-84691 | Red Hat | high 8.7 | Red Hat Ansible Automation Platform: format string | https://access.redhat.com/errata/RHSA-2026:71113 2026-09-23 | CVE-2026-84706 CVE-2026-84706 | Red Hat | high 7.6 | Red Hat Ansible Automation Platform: code execution | https://access.redhat.com/errata/RHSA-2026:71113 2026-09-23 | CVE-2026-84712 CVE-2026-84712 | Red Hat | medium 5.3 | Red Hat automation-controller API: system information exposure | https://access.redhat.com/errata/RHSA-2026:71113 2026-09-23 | CVE-2026-84713 CVE-2026-84713 | Red Hat | medium 6.5 | Red Hat Ansible Automation Platform 2: insecure direct object reference | https://access.redhat.com/errata/RHSA-2026:71177 2026-09-23 | CVE-2026-75884 CVE-2026-75884 | Red Hat | critical 9.1 | Red Hat AWX: privilege escalation | https://access.redhat.com/errata/RHSA-2026:71113 2026-09-23 | CVE-2026-96541 CVE-2026-96541 | Red Hat | high 7.5 | Red Hat gnome-remote-desktop: denial of service | https://access.redhat.com/security/cve/CVE-2026-96541 2026-09-23 | CVE-2026-96545 CVE-2026-96545 | Red Hat | medium 4.4 | Red Hat GIMP: out-of-bounds read | https://access.redhat.com/security/cve/CVE-2026-96545 2026-09-23 | CVE-2026-96546 CVE-2026-96546 | Red Hat | low 2.5 | Red Hat GIMP: information disclosure | https://access.redhat.com/security/cve/CVE-2026-96546 2026-09-23 | CVE-2026-84486 CVE-2026-84486 | Red Hat | high 8.2 | Red Hat Ansible Automation Platform: debug code left active | https://access.redhat.com/errata/RHSA-2026:71113 2026-09-23 | CVE-2026-84499 CVE-2026-84499 | Red Hat | high 7.7 | Red Hat Ansible Automation Platform: information disclosure in errors | https://access.redhat.com/errata/RHSA-2026:71113 2026-09-23 | CVE-2026-84502 CVE-2026-84502 | Red Hat | critical 9.9 | Red Hat Ansible Automation Platform: remote code execution | https://access.redhat.com/errata/RHSA-2026:71113 2026-09-23 | CVE-2026-84474 CVE-2026-84474 | Red Hat | critical 9.9 | Red Hat Ansible Automation Platform: spoofing | https://access.redhat.com/errata/RHSA-2026:71113 2026-09-23 | CVE-2026-76648 CVE-2026-76648 | Red Hat | high 8.5 | Red Hat Ansible Automation Platform 2: missing authorization | https://access.redhat.com/errata/RHSA-2026:71177 2026-09-23 | CVE-2026-71462 CVE-2026-71462 | Red Hat | medium 4.1 | StringListPathField.to_internal_value | https://access.redhat.com/errata/RHSA-2026:71113 2026-09-23 | CVE-2026-71463 CVE-2026-71463 | Red Hat | low 2.7 | Red Hat: information disclosure in errors | https://access.redhat.com/errata/RHSA-2026:71113 2026-09-23 | CVE-2026-71464 CVE-2026-71464 | Red Hat | low 3.1 | Red Hat: argument injection | https://access.redhat.com/errata/RHSA-2026:71113 2026-09-23 | CVE-2026-71465 CVE-2026-71465 | Red Hat | low 3.1 | Red Hat: argument injection | https://access.redhat.com/errata/RHSA-2026:71113 2026-09-23 | CVE-2026-71459 CVE-2026-71459 | Red Hat | medium 5.0 | Red Hat: missing authorization | https://access.redhat.com/errata/RHSA-2026:71113 2026-09-23 | CVE-2026-71460 CVE-2026-71460 | Red Hat | medium 4.3 | Red Hat: missing authorization | https://access.redhat.com/errata/RHSA-2026:71113 2026-09-23 | CVE-2026-71461 CVE-2026-71461 | Red Hat | medium 4.3 | Red Hat Ansible Automation Platform 2: information disclosure in errors | https://access.redhat.com/errata/RHSA-2026:71177 2026-09-23 | CVE-2026-71458 CVE-2026-71458 | Red Hat | medium 5.0 | URLModificationMiddleware resolves named-URL lookups against unfiltered... | https://access.redhat.com/errata/RHSA-2026:71113 2026-09-23 | CVE-2026-88831 CVE-2026-88831 | Red Hat | medium 5.3 | BusyBox httpd IP deny rules with invalid CIDR prefix lengths fail open | https://access.redhat.com/errata/RHSA-2026:72111 2026-09-23 | CVE-2026-88835 CVE-2026-88835 | Red Hat | medium 6.1 | Red Hat: out-of-bounds read | https://access.redhat.com/errata/RHSA-2026:72111 2026-09-23 | CVE-2026-88837 CVE-2026-88837 | Red Hat | medium 6.5 | BusyBox httpd treats yescrypt | https://access.redhat.com/errata/RHSA-2026:72111 2026-09-23 | CVE-2026-88839 CVE-2026-88839 | Red Hat | medium 6.7 | Red Hat: out-of-bounds write | https://access.redhat.com/errata/RHSA-2026:72111 2026-09-23 | CVE-2026-88840 CVE-2026-88840 | Red Hat | medium 5.3 | Red Hat Hardened Images: out-of-bounds read | https://access.redhat.com/security/cve/CVE-2026-88840 2026-09-23 | CVE-2026-86926 CVE-2026-86926 | Apple | high 7.8 | Apple FileMaker Server: buffer overflow | https://support.claris.com/s/answerview?anum=000049219&language=en_US 2026-09-23 | CVE-2026-86930 CVE-2026-86930 | Apple | critical 9.1 | Apple FileMaker Server: out-of-bounds read | https://support.claris.com/s/answerview?anum=000049218&language=en_US 2026-09-23 | CVE-2026-86934 CVE-2026-86934 | Apple | critical 9.1 | Apple FileMaker Server: insecure direct object reference | https://support.claris.com/s/answerview?anum=000049217&language=en_US 2026-09-23 | CVE-2026-86938 CVE-2026-86938 | Apple | high 7.3 | Apple FileMaker Pro: untrusted search path | https://support.claris.com/s/answerview?anum=000049220&language=en_US 2026-09-23 | CVE-2026-88830 CVE-2026-88830 | Red Hat | high 7.5 | Red Hat Hardened Images: buffer overflow | https://access.redhat.com/security/cve/CVE-2026-88830 2026-09-23 | CVE-2026-88832 CVE-2026-88832 | Red Hat | high 7.3 | Red Hat: buffer overflow | https://access.redhat.com/errata/RHSA-2026:72111 2026-09-23 | CVE-2026-3626 CVE-2026-3626 | IBM | medium 5.3 | IBM Concert: information disclosure | https://www.ibm.com/support/pages/node/7288830 2026-09-23 | CVE-2026-4921 CVE-2026-4921 | IBM | low 2.7 | IBM Guardium Data Protection: information disclosure | https://www.ibm.com/support/pages/node/7288827 2026-09-23 | CVE-2026-6327 CVE-2026-6327 | IBM | medium 4.3 | IBM Concert: unauthorized user could inject data into log messages | https://www.ibm.com/support/pages/node/7288830 2026-09-23 | CVE-2026-19179 CVE-2026-19179 | IBM | high 8.2 | IBM Financial Transaction Manager: remote attacker could manipulate database... | https://www.ibm.com/support/pages/node/7288641 2026-09-23 | CVE-2026-19267 CVE-2026-19267 | IBM | medium 6.2 | IBM Financial Transaction Manager for RedHat OpenShift: missing authentication | https://www.ibm.com/support/pages/node/7288641 2026-09-23 | CVE-2026-18181 CVE-2026-18181 | IBM | high 8.1 | IBM Financial Transaction Manager for RedHat OpenShift: authentication bypass | https://www.ibm.com/support/pages/node/7288641 2026-09-23 | CVE-2026-18184 CVE-2026-18184 | IBM | high 7.4 | IBM Financial Transaction Manager for RedHat OpenShift: information disclosure | https://www.ibm.com/support/pages/node/7288641 2026-09-23 | CVE-2026-18185 CVE-2026-18185 | IBM | high 7.3 | IBM Financial Transaction Manager for RedHat OpenShift: information disclosure | https://www.ibm.com/support/pages/node/7288641 2026-09-23 | CVE-2026-18490 CVE-2026-18490 | IBM | high 8.8 | IBM Financial Transaction Manager for RedHat OpenShift: remote code execution | https://www.ibm.com/support/pages/node/7288641 2026-09-23 | CVE-2026-18505 CVE-2026-18505 | IBM | medium 5.4 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift: open redirect | https://www.ibm.com/support/pages/node/7288641 2026-09-23 | CVE-2026-18872 CVE-2026-18872 | IBM | critical 9.3 | IBM Financial Transaction Manager for RedHat OpenShift: cross-site scripting | https://www.ibm.com/support/pages/node/7288641 2026-09-23 | CVE-2026-18875 CVE-2026-18875 | IBM | high 7.3 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift: injection | https://www.ibm.com/support/pages/node/7288641 2026-09-23 | CVE-2026-19087 CVE-2026-19087 | IBM | medium 4.4 | IBM Financial Transaction Manager for RedHat OpenShift: privilege escalation | https://www.ibm.com/support/pages/node/7288641 2026-09-23 | CVE-2026-18180 CVE-2026-18180 | IBM | medium 6.5 | IBM Financial Transaction Manager for RedHat OpenShift: information disclosure | https://www.ibm.com/support/pages/node/7288641 2026-09-23 | CVE-2026-96275 CVE-2026-96275 | Red Hat | high 8.8 | Red Hat Enterprise Linux: path traversal | https://access.redhat.com/security/cve/CVE-2026-96275 2026-09-23 | CVE-2026-96276 CVE-2026-96276 | Red Hat | critical 9.8 | Red Hat Enterprise Linux: path traversal | https://access.redhat.com/security/cve/CVE-2026-96276 2026-09-23 | CVE-2026-73591 CVE-2026-73591 | Dell Technologies | high 7.5 | Dell Technologies Secure Connect Gateway Policy Manager: information disclosure | https://www.dell.com/support/kbdoc/en-ca/000503592/dsa-2026-385-security-update-for-dell-secure-connect-gateway-policy-manager-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9 2026-09-23 | CVE-2026-73586 CVE-2026-73586 | Dell Technologies | medium 6.4 | Dell Technologies Secure Connect: insufficient session expiration | https://www.dell.com/support/kbdoc/en-ca/000503592/dsa-2026-385-security-update-for-dell-secure-connect-gateway-policy-manager-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9 2026-09-23 | CVE-2026-73587 CVE-2026-73587 | Dell Technologies | medium 6.8 | Dell Technologies Secure Connect: improper certificate validation | https://www.dell.com/support/kbdoc/en-ca/000503592/dsa-2026-385-security-update-for-dell-secure-connect-gateway-policy-manager-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9 2026-09-23 | CVE-2026-73588 CVE-2026-73588 | Dell Technologies | high 7.4 | Dell Technologies Secure Connect Gateway Policy Manager: missing authentication | https://www.dell.com/support/kbdoc/en-ca/000503592/dsa-2026-385-security-update-for-dell-secure-connect-gateway-policy-manager-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9 2026-09-23 | CVE-2026-73589 CVE-2026-73589 | Dell Technologies | medium 6.3 | Dell Technologies Secure Connect Gateway Policy Manager: information disclosure | https://www.dell.com/support/kbdoc/en-ca/000503592/dsa-2026-385-security-update-for-dell-secure-connect-gateway-policy-manager-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9 2026-09-23 | CVE-2026-71177 CVE-2026-71177 | Dell Technologies | medium 5.4 | Dell Technologies Secure Connect Gateway (SCG) Policy Manager: clickjacking | https://www.dell.com/support/kbdoc/en-ca/000503592/dsa-2026-385-security-update-for-dell-secure-connect-gateway-policy-manager-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9 2026-09-23 | CVE-2026-71178 CVE-2026-71178 | Dell Technologies | low 3.7 | Dell Secure Connect Gateway | https://www.dell.com/support/kbdoc/en-ca/000503592/dsa-2026-385-security-update-for-dell-secure-connect-gateway-policy-manager-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9 2026-09-23 | CVE-2026-61413 CVE-2026-61413 | Dell Technologies | medium 6.8 | Dell Technologies Secure Connect: improper privilege management | https://www.dell.com/support/kbdoc/en-ca/000503592/dsa-2026-385-security-update-for-dell-secure-connect-gateway-policy-manager-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9 2026-09-23 | CVE-2026-96512 CVE-2026-96512 | Red Hat | high 7.8 | Red Hat sudo.: code execution | https://access.redhat.com/errata/RHSA-2026:71609 2026-09-23 | CVE-2026-18177 CVE-2026-18177 | IBM | high 7.1 | IBM Financial Transaction Manager for RedHat OpenShift: missing authorization | https://www.ibm.com/support/pages/node/7288641 2026-09-23 | CVE-2026-18179 CVE-2026-18179 | IBM | medium 6.5 | IBM Financial Transaction Manager for RedHat OpenShift: improper authorization | https://www.ibm.com/support/pages/node/7288641 2026-09-23 | CVE-2026-95676 CVE-2026-95676 | WatchGuard Technologies | high 7.4 | WatchGuard Technologies AuthPoint Authentication: improper authentication | https://psirt.watchguard.com/CVE-2026-95676 2026-09-23 | CVE-2026-96445 CVE-2026-96445 | Red Hat | medium 6.8 | Red Hat Conditional OTP authenticator of Keycloak: improper authentication | https://access.redhat.com/security/cve/CVE-2026-96445 2026-09-23 | CVE-2026-96446 CVE-2026-96446 | Red Hat | medium 4.2 | Red Hat Build of Keycloak: missing authorization | https://access.redhat.com/security/cve/CVE-2026-96446 2026-09-23 | CVE-2026-78253 CVE-2026-78253 | Qt Group Plc | low 2.3 | qt: denial of service | https://codereview.qt-project.org/c/qt/qtbase/+/754345 2026-09-23 | CVE-2026-96442 CVE-2026-96442 | Red Hat | high 7.8 | Red Hat Emacs: code execution | https://access.redhat.com/security/cve/CVE-2026-96442 2026-09-23 | CVE-2026-79616 CVE-2026-79616 | Qt Group Plc | low 0.6 | qt: out-of-bounds read | https://codereview.qt-project.org/c/qt/qtdeclarative/+/754718 2026-09-23 | CVE-2026-91817 CVE-2026-91817 | Foxit | medium 6.1 | Foxit PDF: out-of-bounds read | https://www.foxit.com/support/security-bulletins.html 2026-09-23 | CVE-2026-91818 CVE-2026-91818 | Foxit | high 7.8 | Foxit PDF: use after free | https://www.foxit.com/support/security-bulletins.html 2026-09-23 | CVE-2026-91809 CVE-2026-91809 | Foxit | high 7.8 | Foxit PDF: use after free | https://www.foxit.com/support/security-bulletins.html 2026-09-23 | CVE-2026-91810 CVE-2026-91810 | Foxit | medium 6.1 | Foxit PDF: out-of-bounds read | https://www.foxit.com/support/security-bulletins.html 2026-09-23 | CVE-2026-91811 CVE-2026-91811 | Foxit | high 7.8 | Foxit PDF: out-of-bounds write | https://www.foxit.com/support/security-bulletins.html 2026-09-23 | CVE-2026-91812 CVE-2026-91812 | Foxit | high 7.9 | Foxit PDF: code execution | https://www.foxit.com/support/security-bulletins.html 2026-09-23 | CVE-2026-91813 CVE-2026-91813 | Foxit | high 8.8 | Foxit PDF: code execution | https://www.foxit.com/support/security-bulletins.html 2026-09-23 | CVE-2026-91814 CVE-2026-91814 | Foxit | medium 5.3 | Foxit PDF: spoofing | https://www.foxit.com/support/security-bulletins.html 2026-09-23 | CVE-2026-91815 CVE-2026-91815 | Foxit | high 7.8 | Foxit PDF: out-of-bounds write | https://www.foxit.com/support/security-bulletins.html 2026-09-23 | CVE-2026-91816 CVE-2026-91816 | Foxit | high 7.8 | Foxit PDF: use after free | https://www.foxit.com/support/security-bulletins.html 2026-09-23 | CVE-2026-91800 CVE-2026-91800 | Foxit | high 8.8 | Foxit PDF Editor: privilege escalation | https://www.foxit.com/support/security-bulletins.html 2026-09-23 | CVE-2026-91801 CVE-2026-91801 | Foxit | high 7.8 | Foxit PDF: path traversal | https://www.foxit.com/support/security-bulletins.html 2026-09-23 | CVE-2026-91802 CVE-2026-91802 | Foxit | high 7.8 | Foxit PDF: out-of-bounds write | https://www.foxit.com/support/security-bulletins.html 2026-09-23 | CVE-2026-91803 CVE-2026-91803 | Foxit | high 8.8 | Foxit PDF: privilege escalation | https://www.foxit.com/support/security-bulletins.html 2026-09-23 | CVE-2026-91804 CVE-2026-91804 | Foxit | high 7.8 | Foxit PDF: out-of-bounds write | https://www.foxit.com/support/security-bulletins.html 2026-09-23 | CVE-2026-91805 CVE-2026-91805 | Foxit | high 7.8 | Foxit PDF: use after free | https://www.foxit.com/support/security-bulletins.html 2026-09-23 | CVE-2026-91806 CVE-2026-91806 | Foxit | high 7.8 | Foxit PDF: use after free | https://www.foxit.com/support/security-bulletins.html 2026-09-23 | CVE-2026-91807 CVE-2026-91807 | Foxit | medium 6.1 | Foxit PDF: out-of-bounds read | https://www.foxit.com/support/security-bulletins.html 2026-09-23 | CVE-2026-91808 CVE-2026-91808 | Foxit | medium 6.1 | Foxit PDF: out-of-bounds read | https://www.foxit.com/support/security-bulletins.html 2026-09-23 | CVE-2026-91792 CVE-2026-91792 | Foxit | high 7.8 | Foxit PDF: use after free | https://www.foxit.com/support/security-bulletins.html 2026-09-23 | CVE-2026-91793 CVE-2026-91793 | Foxit | high 7.8 | Foxit PDF: use after free | https://www.foxit.com/support/security-bulletins.html 2026-09-23 | CVE-2026-91794 CVE-2026-91794 | Foxit | high 7.8 | Foxit PDF: out-of-bounds write | https://www.foxit.com/support/security-bulletins.html 2026-09-23 | CVE-2026-91795 CVE-2026-91795 | Foxit | high 7.8 | Foxit PDF: code execution | https://www.foxit.com/support/security-bulletins.html 2026-09-23 | CVE-2026-91796 CVE-2026-91796 | Foxit | medium 6.1 | Foxit PDF: protection mechanism failure | https://www.foxit.com/support/security-bulletins.html 2026-09-23 | CVE-2026-91797 CVE-2026-91797 | Foxit | high 7.8 | Foxit PDF: path traversal | https://www.foxit.com/support/security-bulletins.html 2026-09-23 | CVE-2026-91798 CVE-2026-91798 | Foxit | high 8.8 | Foxit PDF: privilege escalation | https://www.foxit.com/support/security-bulletins.html 2026-09-23 | CVE-2026-91799 CVE-2026-91799 | Foxit | high 7.8 | Foxit PDF: use after free | https://www.foxit.com/support/security-bulletins.html 2026-09-23 | CVE-2026-91788 CVE-2026-91788 | Foxit | medium 4.7 | Foxit PDF: resource exposure | https://www.foxit.com/support/security-bulletins.html 2026-09-23 | CVE-2026-91789 CVE-2026-91789 | Foxit | high 7.8 | Foxit PDF: out-of-bounds write | https://www.foxit.com/support/security-bulletins.html 2026-09-23 | CVE-2026-91790 CVE-2026-91790 | Foxit | high 7.8 | Foxit PDF: use after free | https://www.foxit.com/support/security-bulletins.html 2026-09-23 | CVE-2026-91791 CVE-2026-91791 | Foxit | high 7.8 | Foxit PDF: use after free | https://www.foxit.com/support/security-bulletins.html 2026-09-22 | GHSA-xpjq-3w4w-w5wr CVE-2026-86062 | LightRAG | medium 6.1 | LightRAG: cross-site scripting | https://github.com/advisories/GHSA-xpjq-3w4w-w5wr 2026-09-22 | GHSA-vv3m-f8x4-7377 CVE-2026-85740 | LightRAG | high 7.1 | LightRAG: server-side request forgery | https://github.com/advisories/GHSA-vv3m-f8x4-7377 2026-09-22 | GHSA-frch-4w6v-q5xx CVE-2026-85734 | LightRAG | critical 9.1 | lightrag-hku: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks | https://github.com/advisories/GHSA-frch-4w6v-q5xx 2026-09-22 | GHSA-c759-cx9p-mrwq CVE-2026-85725 | LightRAG | medium 5.9 | lightrag-hku: Plaintext Passwords Compared Without Constant-Time Function | https://github.com/advisories/GHSA-c759-cx9p-mrwq 2026-09-22 | GHSA-hrmj-7rvj-4hg8 CVE-2026-85709 | LightRAG | medium 5.3 | lightrag-hku: Sensitive Information Exposure Through Raw Exception Messages in API Error Responses | https://github.com/advisories/GHSA-hrmj-7rvj-4hg8 2026-09-22 | GHSA-xp3c-3jw3-4vcr CVE-2026-63131 | OpenBao | medium | OpenBao Skips Stricter Deny Policy for LIST operations | https://github.com/advisories/GHSA-xp3c-3jw3-4vcr 2026-09-22 | GHSA-34fc-gh42-pj53 CVE-2026-63132 | OpenBao | critical | OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack | https://github.com/advisories/GHSA-34fc-gh42-pj53 2026-09-22 | GHSA-59w7-v8rr-pr4p CVE-2026-71543 | OpenBao | high | OpenBao's Templated Policies Allow Privilege Escalation via Wildcard Characters | https://github.com/advisories/GHSA-59w7-v8rr-pr4p 2026-09-22 | GHSA-444v-8vxr-p36h CVE-2026-77285 | OpenBao | low | OpenBao Agent Writes Secrets to Stdout | https://github.com/advisories/GHSA-444v-8vxr-p36h 2026-09-22 | GHSA-m9c2-85gv-8xr5 CVE-2026-69190 | Graylog | medium 6.3 | Graylog: Manager-to-Owner privilege escalation on saved searches and dashboards | https://github.com/advisories/GHSA-m9c2-85gv-8xr5 2026-09-22 | CVE-2026-18173 CVE-2026-18173 | IBM | low 3.7 | IBM Financial Transaction Manager for RedHat OpenShift: information disclosure | https://www.ibm.com/support/pages/node/7288641 2026-09-22 | CVE-2026-18176 CVE-2026-18176 | IBM | high 7.4 | IBM Financial Transaction Manager for RedHat OpenShift: information disclosure | https://www.ibm.com/support/pages/node/7288641 2026-09-22 | CVE-2026-18162 CVE-2026-18162 | IBM | critical 9.8 | IBM Financial Transaction Manager for RedHat OpenShift: remote code execution | https://www.ibm.com/support/pages/node/7288641 2026-09-22 | CVE-2026-18163 CVE-2026-18163 | IBM | critical 9.8 | IBM Financial Transaction Manager for RedHat OpenShift: remote code execution | https://www.ibm.com/support/pages/node/7288641 2026-09-22 | CVE-2026-18169 CVE-2026-18169 | IBM | critical 9.9 | IBM Financial Transaction Manager for RedHat OpenShift: information disclosure | https://www.ibm.com/support/pages/node/7288641 2026-09-22 | CVE-2026-18170 CVE-2026-18170 | IBM | medium 6.5 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift: denial of service | https://www.ibm.com/support/pages/node/7288641 2026-09-22 | CVE-2026-18172 CVE-2026-18172 | IBM | high 7.4 | IBM Financial Transaction Manager for RedHat OpenShift: information disclosure | https://www.ibm.com/support/pages/node/7288641 2026-09-22 | CVE-2026-18161 CVE-2026-18161 | IBM | medium 4.3 | IBM Financial Transaction Manager: remote authenticated attacker could falsify... | https://www.ibm.com/support/pages/node/7288641 2026-09-22 | CVE-2026-19202 CVE-2026-19202 | Google | critical 9.1 | A caching flaw in the toolbox-core package of the mcp-toolbox-sdk-python SDK... | https://github.com/googleapis/mcp-toolbox-sdk-python/pull/675 2026-09-22 | CVE-2026-18132 CVE-2026-18132 | IBM | medium 6.5 | IBM Financial Transaction Manager for RedHat OpenShift: missing authorization | https://www.ibm.com/support/pages/node/7288641 2026-09-22 | CVE-2026-18133 CVE-2026-18133 | IBM | medium 5.4 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift: path traversal | https://www.ibm.com/support/pages/node/7288641 2026-09-22 | CVE-2026-18134 CVE-2026-18134 | IBM | high 7.5 | IBM Financial Transaction Manager for RedHat OpenShift: information disclosure | https://www.ibm.com/support/pages/node/7288641 2026-09-22 | CVE-2026-18137 CVE-2026-18137 | IBM | high 8.1 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift: SQL injection | https://www.ibm.com/support/pages/node/7288641 2026-09-22 | CVE-2026-18152 CVE-2026-18152 | IBM | high 7.4 | IBM Financial Transaction Manager for RedHat OpenShift: improper signature check | https://www.ibm.com/support/pages/node/7288641 2026-09-22 | CVE-2026-18153 CVE-2026-18153 | IBM | medium 5.4 | IBM Financial Transaction Manager for RedHat OpenShift: information disclosure | https://www.ibm.com/support/pages/node/7288641 2026-09-22 | CVE-2026-18154 CVE-2026-18154 | IBM | high 8.0 | IBM Financial Transaction Manager for RedHat OpenShift: information disclosure | https://www.ibm.com/support/pages/node/7288641 2026-09-22 | CVE-2026-18156 CVE-2026-18156 | IBM | medium 6.5 | IBM Financial Transaction Manager for RedHat OpenShift: improper authorization | https://www.ibm.com/support/pages/node/7288641 2026-09-22 | CVE-2026-18066 CVE-2026-18066 | IBM | high 7.9 | IBM Financial Transaction Manager for RedHat OpenShift: information disclosure | https://www.ibm.com/support/pages/node/7288641 2026-09-22 | CVE-2026-18074 CVE-2026-18074 | IBM | high 8.2 | IBM Financial Transaction Manager for RedHat OpenShift: improper authentication | https://www.ibm.com/support/pages/node/7288641 2026-09-22 | CVE-2026-18095 CVE-2026-18095 | IBM | high 8.5 | IBM Financial Transaction Manager for RedHat OpenShift: remote code execution | https://www.ibm.com/support/pages/node/7288641 2026-09-22 | CVE-2026-18114 CVE-2026-18114 | IBM | medium 6.5 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift: path traversal | https://www.ibm.com/support/pages/node/7288641 2026-09-22 | CVE-2026-18123 CVE-2026-18123 | IBM | high 7.6 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift: denial of service | https://www.ibm.com/support/pages/node/7288641 2026-09-22 | CVE-2026-18124 CVE-2026-18124 | IBM | medium 6.5 | IBM Financial Transaction Manager for RedHat OpenShift: information disclosure | https://www.ibm.com/support/pages/node/7288641 2026-09-22 | CVE-2026-18131 CVE-2026-18131 | IBM | high 8.2 | IBM Financial Transaction Manager for RedHat OpenShift: cross-site scripting | https://www.ibm.com/support/pages/node/7288641 2026-09-22 | CVE-2026-17635 CVE-2026-17635 | IBM | critical 9.1 | IBM Financial Transaction Manager for RedHat OpenShift: missing authentication | https://www.ibm.com/support/pages/node/7288641 2026-09-22 | CVE-2026-17636 CVE-2026-17636 | IBM | high 8.8 | IBM Financial Transaction Manager for RedHat OpenShift: remote code execution | https://www.ibm.com/support/pages/node/7288641 2026-09-22 | CVE-2026-17637 CVE-2026-17637 | IBM | high 8.8 | IBM Financial Transaction Manager for RedHat OpenShift: remote code execution | https://www.ibm.com/support/pages/node/7288641 2026-09-22 | CVE-2026-17643 CVE-2026-17643 | IBM | high 8.8 | IBM Financial Transaction Manager for RedHat OpenShift: information disclosure | https://www.ibm.com/support/pages/node/7288641 2026-09-22 | CVE-2026-17644 CVE-2026-17644 | IBM | high 8.8 | IBM Financial Transaction Manager for RedHat OpenShift: information disclosure | https://www.ibm.com/support/pages/node/7288641 2026-09-22 | CVE-2026-17645 CVE-2026-17645 | IBM | critical 9.1 | IBM Financial Transaction Manager for RedHat OpenShift: privilege escalation | https://www.ibm.com/support/pages/node/7288641 2026-09-22 | CVE-2026-17646 CVE-2026-17646 | IBM | high 8.5 | IBM Financial Transaction Manager for RedHat OpenShift: information disclosure | https://www.ibm.com/support/pages/node/7288641 2026-09-22 | CVE-2026-17647 CVE-2026-17647 | IBM | high 8.8 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift: code execution | https://www.ibm.com/support/pages/node/7288641 2026-09-22 | CVE-2026-16468 CVE-2026-16468 | IBM | high 8.8 | IBM DataStage on Cloud Pak for Data: remote code execution | https://www.ibm.com/support/pages/node/7288649 2026-09-22 | CVE-2026-16469 CVE-2026-16469 | IBM | high 8.8 | IBM DataStage on Cloud Pak for Data: remote code execution | https://www.ibm.com/support/pages/node/7288649 2026-09-22 | CVE-2026-16672 CVE-2026-16672 | IBM | high 8.8 | IBM DataStage on Cloud Pak for Data: remote code execution | https://www.ibm.com/support/pages/node/7288649 2026-09-22 | CVE-2026-17102 CVE-2026-17102 | IBM | high 8.8 | IBM DataStage on Cloud Pak for Data: remote code execution | https://www.ibm.com/support/pages/node/7288649 2026-09-22 | CVE-2026-17465 CVE-2026-17465 | IBM | medium 6.5 | IBM Concert: denial of service | https://www.ibm.com/support/pages/node/7288830 2026-09-22 | CVE-2026-17472 CVE-2026-17472 | IBM | critical 9.6 | IBM Concert: improper privilege management | https://www.ibm.com/support/pages/node/7288830 2026-09-22 | CVE-2026-17618 CVE-2026-17618 | IBM | high 7.3 | IBM Financial Transaction Manager for RedHat OpenShift: information disclosure | https://www.ibm.com/support/pages/node/7288641 2026-09-22 | CVE-2026-17620 CVE-2026-17620 | IBM | medium 5.3 | IBM Financial Transaction Manager | https://www.ibm.com/support/pages/node/7288641 2026-09-22 | CVE-2025-36084 CVE-2025-36084 | IBM | medium 5.9 | IBM Concert: information disclosure | https://www.ibm.com/support/pages/node/7288830 2026-09-22 | CVE-2026-15915 CVE-2026-15915 | IBM | medium 6.2 | IBM Concert: information disclosure | https://www.ibm.com/support/pages/node/7288830 2026-09-22 | CVE-2026-16346 CVE-2026-16346 | IBM | critical 9.9 | IBM DataStage on Cloud Pak for Data: remote code execution | https://www.ibm.com/support/pages/node/7288649 2026-09-22 | CVE-2026-16426 CVE-2026-16426 | IBM | medium 6.5 | IBM Concert: server-side request forgery | https://www.ibm.com/support/pages/node/7288830 2026-09-22 | CVE-2025-12767 CVE-2025-12767 | IBM | medium 5.3 | IBM Concert: denial of service | https://www.ibm.com/support/pages/node/7288830 2026-09-22 | CVE-2026-77912 CVE-2026-77912 | GitHub | high 7.4 | GitHub Enterprise Server: cross-site scripting | https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.21 2026-09-22 | CVE-2026-77987 CVE-2026-77987 | GitHub | critical 9.3 | GitHub Enterprise Server: server-side request forgery | https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.21 2026-09-22 | CVE-2026-75101 CVE-2026-75101 | GitHub | medium 6.0 | GitHub Enterprise Server: insecure direct object reference | https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.21 2026-09-22 | CVE-2026-76712 CVE-2026-76712 | Hewlett Packard Enterprise | high 7.3 | Hewlett Packard Enterprise ALE: information disclosure | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05137en_us&docLocale=en_US 2026-09-22 | CVE-2026-76713 CVE-2026-76713 | Hewlett Packard Enterprise | high 7.2 | Hewlett Packard Enterprise ALE: improper privilege management | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05137en_us&docLocale=en_US 2026-09-22 | CVE-2026-76714 CVE-2026-76714 | Hewlett Packard Enterprise | high 7.2 | Hewlett Packard Enterprise ALE: remote code execution | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05137en_us&docLocale=en_US 2026-09-22 | CVE-2026-76715 CVE-2026-76715 | Hewlett Packard Enterprise | high 7.1 | Hewlett Packard Enterprise ALE: remote code execution | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05137en_us&docLocale=en_US 2026-09-22 | CVE-2026-76716 CVE-2026-76716 | Hewlett Packard Enterprise | medium 5.3 | Hewlett Packard Enterprise ALE: denial of service | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05137en_us&docLocale=en_US 2026-09-22 | CVE-2026-76717 CVE-2026-76717 | Hewlett Packard Enterprise | medium 5.3 | Hewlett Packard Enterprise ALE: information disclosure | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05137en_us&docLocale=en_US 2026-09-22 | CVE-2026-76708 CVE-2026-76708 | Hewlett Packard Enterprise | critical 9.8 | Hewlett Packard Enterprise ALE: hard-coded credentials | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05137en_us&docLocale=en_US 2026-09-22 | CVE-2026-76709 CVE-2026-76709 | Hewlett Packard Enterprise | critical 9.8 | Hewlett Packard Enterprise ALE: unauthenticated remote attacker could gain... | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05137en_us&docLocale=en_US 2026-09-22 | CVE-2026-76710 CVE-2026-76710 | Hewlett Packard Enterprise | high 7.5 | Hewlett Packard Enterprise ALE: information disclosure | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05137en_us&docLocale=en_US 2026-09-22 | CVE-2026-76711 CVE-2026-76711 | Hewlett Packard Enterprise | high 7.5 | Hewlett Packard Enterprise ALE: improper input validation | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05137en_us&docLocale=en_US 2026-09-22 | CVE-2026-28324 CVE-2026-28324 | SolarWinds | critical 9.8 | SolarWinds Observability Self-Hosted: remote code execution | https://documentation.solarwinds.com/en/success_center/orionplatform/content/core-secure-configuration.htm 2026-09-22 | CVE-2026-28325 CVE-2026-28325 | SolarWinds | high 8.8 | SolarWinds Observability Self-Hosted: remote code execution | https://documentation.solarwinds.com/en/success_center/orionplatform/content/core-secure-configuration.htm 2026-09-22 | AWS-2026-037 CVE-2026-10591 | AWS | high 8.8 | Kiro IDE Insufficient File Write Restrictions to Execution-Sensitive Paths | https://aws.amazon.com/security/security-bulletins/rss/2026-037-aws/ 2026-09-22 | AWS-2026-039 CVE-2026-11400 | AWS | high 8.0 | Amazon Aurora PostgreSQL a fully managed relational database engine that's compatible... | https://aws.amazon.com/security/security-bulletins/rss/2026-039-aws/ 2026-09-22 | AWS-2026-038 CVE-2026-10584 | AWS | medium 5.9 | HTTPS Fallback to HTTP in Graph Explorer | https://aws.amazon.com/security/security-bulletins/rss/2026-038-aws/ 2026-09-22 | AWS-2026-040 CVE-2026-11393 | AWS | critical 9.0 | Code Injection via Improper Triple-Quote Escaping in AgentCore CLI Bedrock Agent Import | https://aws.amazon.com/security/security-bulletins/rss/2026-040-aws/ 2026-09-22 | AWS-2026-041 CVE-2026-10740 | AWS | medium 5.3 | Excessive memory allocation in s2n-quic | https://aws.amazon.com/security/security-bulletins/rss/2026-041-aws/ 2026-09-22 | AWS-2026-045 CVE-2026-11931 | AWS | medium 5.5 | Insecure Permissions on Authentication Token Cache File in Kiro IDE | https://aws.amazon.com/security/security-bulletins/rss/2026-045-aws/ 2026-09-22 | AWS-2026-048 CVE-2026-13762 | AWS | critical 9.8 | Issue with HTTP/2 multi-frame request body inspection in AWS WAF | https://aws.amazon.com/security/security-bulletins/rss/2026-048-aws/ 2026-09-22 | AWS-2026-049 CVE-2026-13769 | AWS | medium 5.5 | Insecure file permissions in AWS CLI | https://aws.amazon.com/security/security-bulletins/rss/2026-049-aws/ 2026-09-22 | AWS-2026-052 CVE-2026-14471 | AWS | high 8.1 | Authenticated SQL injection in the metrics-service retention policy subsystem of... | https://aws.amazon.com/security/security-bulletins/rss/2026-052-aws/ 2026-09-22 | AWS-2026-043 CVE-2026-12043 | AWS | high 8.8 | Heap double-free in AWS Common Runtime aws-c-http | https://aws.amazon.com/security/security-bulletins/rss/2026-043-aws/ 2026-09-22 | AWS-2026-044 CVE-2026-12530 | AWS | high 7.3 | Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK... | https://aws.amazon.com/security/security-bulletins/rss/2026-044-aws/ 2026-09-22 | AWS-2026-047 CVE-2026-12957 | AWS | high 7.8 | Issues in Language Servers for AWS and Amazon Q Developer Plugins | https://aws.amazon.com/security/security-bulletins/rss/2026-047-aws/ 2026-09-22 | AWS-2026-051 CVE-2026-14265 | AWS | high 7.5 | Deserialization of Untrusted Data in AWS Advanced JDBC Wrapper RemoteQueryCachePlugin | https://aws.amazon.com/security/security-bulletins/rss/2026-051-aws/ 2026-09-22 | AWS-2026-046 CVE-2026-50195 | AWS | critical 9.9 | Issue with containerd CRI Plugin - CVE-2026-50195, CVE-2026-53488, CVE-2026-53492... | https://aws.amazon.com/security/security-bulletins/rss/2026-046-aws/ 2026-09-22 | AWS-2026-050 CVE-2026-13760 | AWS | high 7.3 | OS Command Injection in NodejsFunction Docker Bundling in aws-cdk-lib | https://aws.amazon.com/security/security-bulletins/rss/2026-050-aws/ 2026-09-22 | CVE-2026-89277 CVE-2026-89277 | Adobe | medium 5.5 | Adobe Content Credentials: integer overflow | https://helpx.adobe.com/security/products/content-authenticity-sdk/apsb26-147.html 2026-09-22 | CVE-2026-83963 CVE-2026-83963 | Adobe | high 7.8 | Adobe Substance3D - Modeler: out-of-bounds write | https://helpx.adobe.com/security/products/substance3d-modeler/apsb26-155.html 2026-09-22 | CVE-2026-83964 CVE-2026-83964 | Adobe | medium 6.2 | Adobe Connect: improper certificate validation | https://helpx.adobe.com/security/products/connect/apsb26-150.html 2026-09-22 | CVE-2026-84395 CVE-2026-84395 | Adobe | high 7.1 | Adobe Premiere: server-side request forgery | https://helpx.adobe.com/security/products/premiere_pro/apsb26-157.html 2026-09-22 | CVE-2026-84396 CVE-2026-84396 | Adobe | medium 5.5 | Adobe InDesign Desktop: null pointer dereference | https://helpx.adobe.com/security/products/indesign/apsb26-145.html 2026-09-22 | CVE-2026-81998 CVE-2026-81998 | Adobe | high 7.8 | Adobe Substance3D - Modeler: out-of-bounds write | https://helpx.adobe.com/security/products/substance3d-modeler/apsb26-155.html 2026-09-22 | CVE-2026-81999 CVE-2026-81999 | Adobe | high 8.7 | Adobe AEM 6.5: server-side request forgery | https://helpx.adobe.com/security/products/aem-forms/apsb26-151.html 2026-09-22 | CVE-2026-82000 CVE-2026-82000 | Adobe | critical 9.6 | Adobe AEM 6.5: server-side request forgery | https://helpx.adobe.com/security/products/aem-forms/apsb26-151.html 2026-09-22 | CVE-2026-83962 CVE-2026-83962 | Adobe | high 7.8 | Adobe Substance3D - Modeler: stack buffer overflow | https://helpx.adobe.com/security/products/substance3d-modeler/apsb26-155.html 2026-09-22 | CVE-2026-79906 CVE-2026-79906 | Adobe | high 7.8 | Adobe Substance3D - Modeler: out-of-bounds write | https://helpx.adobe.com/security/products/substance3d-modeler/apsb26-155.html 2026-09-22 | CVE-2026-81995 CVE-2026-81995 | Adobe | critical 9.1 | Adobe AEM 6.5: improper input validation | https://helpx.adobe.com/security/products/aem-forms/apsb26-151.html 2026-09-22 | CVE-2026-75743 CVE-2026-75743 | Adobe | high 7.1 | Adobe AEM 6.5: cross-site request forgery | https://helpx.adobe.com/security/products/aem-forms/apsb26-151.html 2026-09-22 | CVE-2026-75744 CVE-2026-75744 | Adobe | high 8.1 | Adobe AEM 6.5: cross-site scripting | https://helpx.adobe.com/security/products/aem-forms/apsb26-151.html 2026-09-22 | CVE-2026-75745 CVE-2026-75745 | Adobe | critical 10.0 | Adobe AEM 6.5: improper authorization | https://helpx.adobe.com/security/products/aem-forms/apsb26-151.html 2026-09-22 | CVE-2026-76192 CVE-2026-76192 | Adobe | medium 5.5 | Adobe InDesign Desktop: null pointer dereference | https://helpx.adobe.com/security/products/indesign/apsb26-145.html 2026-09-22 | CVE-2026-76194 CVE-2026-76194 | Adobe | medium 4.3 | Adobe Content Credentials: improper input validation | https://helpx.adobe.com/security/products/content-authenticity-sdk/apsb26-147.html 2026-09-22 | CVE-2026-75676 CVE-2026-75676 | Adobe | high 7.8 | Adobe Bridge: stack buffer overflow | https://helpx.adobe.com/security/products/bridge/apsb26-148.html 2026-09-22 | CVE-2026-75682 CVE-2026-75682 | Adobe | critical 9.9 | Adobe Connect: SQL injection | https://helpx.adobe.com/security/products/connect/apsb26-150.html 2026-09-22 | CVE-2026-75684 CVE-2026-75684 | Adobe | critical 9.3 | Adobe Connect: cross-site scripting | https://helpx.adobe.com/security/products/connect/apsb26-150.html 2026-09-22 | CVE-2026-75686 CVE-2026-75686 | Adobe | critical 9.3 | Adobe Connect: improper input validation | https://helpx.adobe.com/security/products/connect/apsb26-150.html 2026-09-22 | CVE-2026-75689 CVE-2026-75689 | Adobe | critical 9.3 | Adobe Connect: cross-site scripting | https://helpx.adobe.com/security/products/connect/apsb26-150.html 2026-09-22 | CVE-2026-75697 CVE-2026-75697 | Adobe | critical 9.3 | Adobe Connect: cross-site scripting | https://helpx.adobe.com/security/products/connect/apsb26-150.html 2026-09-22 | CVE-2026-75698 CVE-2026-75698 | Adobe | critical 9.3 | Adobe Connect: cross-site scripting | https://helpx.adobe.com/security/products/connect/apsb26-150.html 2026-09-22 | CVE-2026-75638 CVE-2026-75638 | Adobe | medium 6.5 | Adobe Content Credentials: improper input validation | https://helpx.adobe.com/security/products/content-authenticity-sdk/apsb26-147.html 2026-09-22 | CVE-2026-75649 CVE-2026-75649 | Adobe | high 7.8 | Adobe Bridge: heap buffer overflow | https://helpx.adobe.com/security/products/bridge/apsb26-148.html 2026-09-22 | CVE-2026-75655 CVE-2026-75655 | Adobe | high 7.8 | Adobe Bridge: code execution | https://helpx.adobe.com/security/products/bridge/apsb26-148.html 2026-09-22 | CVE-2026-75656 CVE-2026-75656 | Adobe | medium 5.5 | Adobe Bridge: out-of-bounds read | https://helpx.adobe.com/security/products/bridge/apsb26-148.html 2026-09-22 | CVE-2026-75658 CVE-2026-75658 | Adobe | high 7.8 | Adobe Bridge: out-of-bounds write | https://helpx.adobe.com/security/products/bridge/apsb26-148.html 2026-09-22 | CVE-2026-75663 CVE-2026-75663 | Adobe | high 7.8 | Adobe Bridge: out-of-bounds write | https://helpx.adobe.com/security/products/bridge/apsb26-148.html 2026-09-22 | CVE-2026-75665 CVE-2026-75665 | Adobe | high 7.8 | Adobe Bridge: heap buffer overflow | https://helpx.adobe.com/security/products/bridge/apsb26-148.html 2026-09-22 | CVE-2026-75632 CVE-2026-75632 | Adobe | high 7.5 | Adobe Content Credentials: resource exhaustion | https://helpx.adobe.com/security/products/content-authenticity-sdk/apsb26-147.html 2026-09-22 | CVE-2026-75633 CVE-2026-75633 | Adobe | medium 5.5 | Adobe Content Credentials: improper input validation | https://helpx.adobe.com/security/products/content-authenticity-sdk/apsb26-147.html 2026-09-22 | CVE-2026-75634 CVE-2026-75634 | Adobe | medium 4.3 | Adobe Content Credentials: improper input validation | https://helpx.adobe.com/security/products/content-authenticity-sdk/apsb26-147.html 2026-09-22 | CVE-2026-19480 CVE-2026-19480 | Adobe | high 7.5 | Adobe Content Credentials: improper input validation | https://helpx.adobe.com/security/products/content-authenticity-sdk/apsb26-147.html 2026-09-22 | CVE-2026-34689 CVE-2026-34689 | Adobe | high 8.6 | Adobe Connect: path traversal | https://helpx.adobe.com/security/products/connect/apsb26-150.html 2026-09-22 | CVE-2026-48361 CVE-2026-48361 | Adobe | medium 6.1 | Adobe Connect: cross-site scripting | https://helpx.adobe.com/security/products/connect/apsb26-150.html 2026-09-22 | CVE-2026-89275 CVE-2026-89275 | Adobe | critical 10.0 | Adobe Campaign Classic: code injection | https://helpx.adobe.com/security/products/campaign/apsb26-142.html 2026-09-22 | CVE-2026-89276 CVE-2026-89276 | Adobe | critical 9.9 | Adobe Campaign Classic: code injection | https://helpx.adobe.com/security/products/campaign/apsb26-142.html 2026-09-22 | CVE-2026-83660 CVE-2026-83660 | Adobe | critical 9.9 | Adobe Campaign Classic: server-side request forgery | https://helpx.adobe.com/security/products/campaign/apsb26-142.html 2026-09-22 | CVE-2026-84412 CVE-2026-84412 | Adobe | critical 10.0 | Adobe Campaign Classic: code injection | https://helpx.adobe.com/security/products/campaign/apsb26-142.html 2026-09-22 | CVE-2026-82008 CVE-2026-82008 | Adobe | critical 9.9 | Adobe Campaign Classic: improper input validation | https://helpx.adobe.com/security/products/campaign/apsb26-142.html 2026-09-22 | CVE-2026-82009 CVE-2026-82009 | Adobe | critical 9.1 | Adobe Campaign Classic: SQL injection | https://helpx.adobe.com/security/products/campaign/apsb26-142.html 2026-09-22 | CVE-2026-82010 CVE-2026-82010 | Adobe | critical 9.9 | Adobe Campaign Classic: SQL injection | https://helpx.adobe.com/security/products/campaign/apsb26-142.html 2026-09-22 | CVE-2026-82011 CVE-2026-82011 | Adobe | critical 9.1 | Adobe Campaign Classic: SQL injection | https://helpx.adobe.com/security/products/campaign/apsb26-142.html 2026-09-22 | CVE-2026-82013 CVE-2026-82013 | Adobe | critical 9.9 | Adobe Campaign Classic: server-side request forgery | https://helpx.adobe.com/security/products/campaign/apsb26-142.html 2026-09-22 | CVE-2026-82443 CVE-2026-82443 | Adobe | critical 9.6 | Adobe Campaign Classic: server-side request forgery | https://helpx.adobe.com/security/products/campaign/apsb26-142.html 2026-09-22 | CVE-2026-82003 CVE-2026-82003 | Adobe | high 8.5 | Adobe Campaign Classic: improper input validation | https://helpx.adobe.com/security/products/campaign/apsb26-142.html 2026-09-22 | CVE-2026-75721 CVE-2026-75721 | Adobe | critical 10.0 | Adobe Campaign Classic: code injection | https://helpx.adobe.com/security/products/campaign/apsb26-142.html 2026-09-22 | CVE-2026-75723 CVE-2026-75723 | Adobe | critical 10.0 | Adobe Campaign Classic: improper authorization | https://helpx.adobe.com/security/products/campaign/apsb26-142.html 2026-09-22 | CVE-2026-75728 CVE-2026-75728 | Adobe | critical 9.1 | Adobe Campaign Classic: improper authorization | https://helpx.adobe.com/security/products/campaign/apsb26-142.html 2026-09-22 | CVE-2026-73369 CVE-2026-73369 | Adobe | critical 10.0 | Adobe Campaign Classic: code injection | https://helpx.adobe.com/security/products/campaign/apsb26-142.html 2026-09-22 | CVE-2026-75699 CVE-2026-75699 | Adobe | critical 10.0 | Adobe Campaign Classic: code injection | https://helpx.adobe.com/security/products/campaign/apsb26-142.html 2026-09-22 | CVE-2026-75703 CVE-2026-75703 | Adobe | critical 10.0 | Adobe Campaign Classic: code injection | https://helpx.adobe.com/security/products/campaign/apsb26-142.html 2026-09-22 | CVE-2026-13087 CVE-2026-13087 | Red Hat | high 8.8 | Red Hat Linux kernel: out-of-bounds write | https://access.redhat.com/security/cve/CVE-2026-13087 2026-09-22 | CVE-2026-94640 CVE-2026-94640 | Red Hat | high 7.5 | Red Hat rpcbind. This vulnerability: denial of service | https://access.redhat.com/security/cve/CVE-2026-94640 2026-09-22 | CVE-2026-90462 CVE-2026-90462 | Red Hat | medium 5.4 | Red Hat SSSD.: improper permission handling | https://access.redhat.com/security/cve/CVE-2026-90462 2026-09-22 | CVE-2026-94127 CVE-2026-94127 | F5 | critical 9.3 | F5 BIG-IP: remote code execution | https://my.f5.com/manage/s/article/K000162605 2026-09-22 | CVE-2026-84388 CVE-2026-84388 | Fortinet | critical 9.6 | Fortinet FortiPAM Chrome Extension: information disclosure | https://fortiguard.fortinet.com/psirt/FG-IR-26-168 2026-09-22 | CVE-2026-65127 CVE-2026-65127 | Nvidia | medium 4.1 | Nvidia Infrastructure Controller: information disclosure | https://github.com/NVIDIA/product-security/tree/main/2026/5879 2026-09-22 | CVE-2026-65128 CVE-2026-65128 | Nvidia | high 8.8 | Nvidia Infrastructure Controller: SQL injection | https://github.com/NVIDIA/product-security/tree/main/2026/5879 2026-09-22 | CVE-2026-65129 CVE-2026-65129 | Nvidia | medium 6.7 | Nvidia Infrastructure Controller: improper certificate validation | https://github.com/NVIDIA/product-security/tree/main/2026/5879 2026-09-22 | CVE-2026-65130 CVE-2026-65130 | Nvidia | high 8.0 | Nvidia Infrastructure Controller: command injection | https://github.com/NVIDIA/product-security/tree/main/2026/5879 2026-09-22 | CVE-2026-65178 CVE-2026-65178 | Nvidia | high 7.8 | Nvidia NeMo Speech: code execution | https://github.com/NVIDIA/product-security/tree/main/2026/5885 2026-09-22 | CVE-2026-65179 CVE-2026-65179 | Nvidia | high 8.8 | Nvidia NeMo Speech: code execution | https://github.com/NVIDIA/product-security/tree/main/2026/5885 2026-09-22 | CVE-2026-65117 CVE-2026-65117 | Nvidia | medium 5.0 | Nvidia Infrastructure Controller: hard-coded credentials | https://github.com/NVIDIA/product-security/tree/main/2026/5879 2026-09-22 | CVE-2026-65118 CVE-2026-65118 | Nvidia | high 7.5 | Nvidia Infrastructure Controller: improper certificate validation | https://github.com/NVIDIA/product-security/tree/main/2026/5879 2026-09-22 | CVE-2026-65121 CVE-2026-65121 | Nvidia | high 8.2 | Nvidia Infrastructure Controller: improper authentication | https://github.com/NVIDIA/product-security/tree/main/2026/5879 2026-09-22 | CVE-2026-65124 CVE-2026-65124 | Nvidia | medium 5.9 | Nvidia Infrastructure Controller: tampering | https://github.com/NVIDIA/product-security/tree/main/2026/5879 2026-09-22 | CVE-2026-65125 CVE-2026-65125 | Nvidia | medium 6.6 | Nvidia Infrastructure Controller: code execution | https://github.com/NVIDIA/product-security/tree/main/2026/5879 2026-09-22 | CVE-2026-65126 CVE-2026-65126 | Nvidia | medium 5.0 | Nvidia Infrastructure Controller: tampering | https://github.com/NVIDIA/product-security/tree/main/2026/5879 2026-09-22 | CVE-2026-65111 CVE-2026-65111 | Nvidia | high 7.8 | Nvidia NeMo Speech: code injection | https://github.com/NVIDIA/product-security/tree/main/2026/5885 2026-09-22 | CVE-2026-65112 CVE-2026-65112 | Nvidia | medium 6.5 | Nvidia Infrastructure Controller: resource exhaustion | https://github.com/NVIDIA/product-security/tree/main/2026/5879 2026-09-22 | CVE-2026-65113 CVE-2026-65113 | Nvidia | critical 9.8 | Nvidia Infrastructure Controller: hard-coded credentials | https://github.com/NVIDIA/product-security/tree/main/2026/5879 2026-09-22 | CVE-2026-65114 CVE-2026-65114 | Nvidia | high 8.3 | Nvidia Infrastructure Controller: missing authentication | https://github.com/NVIDIA/product-security/tree/main/2026/5879 2026-09-22 | CVE-2026-65115 CVE-2026-65115 | Nvidia | medium 6.5 | Nvidia Infrastructure Controller: resource exhaustion | https://github.com/NVIDIA/product-security/tree/main/2026/5879 2026-09-22 | CVE-2026-24239 CVE-2026-24239 | Nvidia | high 7.8 | Nvidia NeMo Speech: remote code execution | https://github.com/NVIDIA/product-security/tree/main/2026/5885 2026-09-22 | CVE-2026-24267 CVE-2026-24267 | Nvidia | high 7.8 | Nvidia NeMo Speech: remote code execution | https://github.com/NVIDIA/product-security/tree/main/2026/5885 2026-09-22 | CVE-2026-19915 CVE-2026-19915 | HP Inc. | high 7.3 | HP Support Assistant: privilege escalation | https://support.hp.com/us-en/document/ish_15677182-15677204-16/hpsbgn04141 2026-09-22 | CVE-2026-95619 CVE-2026-95619 | Red Hat | high 7.7 | Red Hat libstdc++. An integer overflow can occur: integer overflow | https://access.redhat.com/errata/RHSA-2026:58503 2026-09-22 | CVE-2026-93616 CVE-2026-93616 | Check Point | critical 9.8 | Check Point Quantum Security Management: path traversal | https://support.checkpoint.com/results/sk/sk1000171 2026-09-22 | AWS-2026-116 CVE-2026-94450 | AWS | high 7.5 | Potential denial of service when configured to send Retry packets in s2n-quic | https://aws.amazon.com/security/security-bulletins/rss/2026-116-aws/ 2026-09-22 | CVE-2026-25264 CVE-2026-25264 | Qualcomm | high 8.8 | Qualcomm Snapdragon: privilege escalation | https://docs.qualcomm.com/product/publicresources/securitybulletin/june-2026-bulletin.html 2026-09-22 | CVE-2026-25265 CVE-2026-25265 | Qualcomm | high 8.8 | Qualcomm Snapdragon: privilege escalation | https://docs.qualcomm.com/product/publicresources/securitybulletin/june-2026-bulletin.html 2026-09-22 | CVE-2026-25254 CVE-2026-25254 | Qualcomm | critical 9.8 | Qualcomm Snapdragon: improper authorization | https://docs.qualcomm.com/product/publicresources/securitybulletin/may-2026-bulletin.html 2026-09-22 | CVE-2026-25255 CVE-2026-25255 | Qualcomm | high 8.8 | Qualcomm Snapdragon: privilege escalation | https://docs.qualcomm.com/product/publicresources/securitybulletin/may-2026-bulletin.html 2026-09-22 | CVE-2026-25262 CVE-2026-25262 | Qualcomm | medium 6.9 | Qualcomm Snapdragon: memory corruption | https://docs.qualcomm.com/product/publicresources/securitybulletin/may-2026-bulletin.html 2026-09-22 | AWS-2026-115 CVE-2026-94384 | AWS | high 8.1 | Missing Authorization in AmazonConnectSalesforceLambda sfExecuteAWSService | https://aws.amazon.com/security/security-bulletins/rss/2026-115-aws/ 2026-09-22 | CVE-2026-95508 CVE-2026-95508 | Red Hat | high 7.4 | Red Hat Enterprise Linux 10: heap buffer overflow | https://access.redhat.com/security/cve/CVE-2026-95508 2026-09-22 | CVE-2026-93952 CVE-2026-93952 | Arista Networks | critical 9.5 | Arista Networks VeloCloud Orchestrator: remote attacker could access privileged... | https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183 2026-09-22 | CVE-2026-95503 CVE-2026-95503 | Red Hat | medium 6.8 | Red Hat Kerberos federation provider of Keycloak: authentication bypass | https://access.redhat.com/security/cve/CVE-2026-95503 2026-09-22 | CVE-2026-76974 CVE-2026-76974 | SAP | medium 5.3 | SAP Fiori Launchpad: information disclosure | https://me.sap.com/notes/3680888 2026-09-21 | PYSEC-2026-3989 CVE-2026-82355 | Apache Airflow | medium 4.2 | When a request to the Airflow core API carries both a session cookie and an... | https://osv.dev/vulnerability/PYSEC-2026-3989 2026-09-21 | PYSEC-2026-3990 CVE-2026-86473 | Apache Airflow | critical 9.1 | Apache Airflow: the Core API logout endpoint revokes only a session token... | https://osv.dev/vulnerability/PYSEC-2026-3990 2026-09-21 | PYSEC-2026-3988 CVE-2026-75158 | Apache Airflow | medium 4.3 | Apache Airflow: improper access control | https://osv.dev/vulnerability/PYSEC-2026-3988 2026-09-21 | CVE-2026-93433 CVE-2026-93433 | Red Hat | medium 5.5 | Red Hat libstoragemgmt: buffer overflow | https://access.redhat.com/security/cve/CVE-2026-93433 2026-09-21 | CVE-2026-81469 CVE-2026-81469 | Dell Technologies | high 7.8 | Dell Technologies Inventory Collector Client: code execution | https://www.dell.com/support/kbdoc/en-us/000502474/dsa-2026-381-security-update-for-dell-supportassist-for-pcs-home-and-business-dell-optimizer-dell-trusted-device-dell-command-update-for-an-unquoted-search-path-or-element-vulnerability 2026-09-21 | CVE-2026-49811 CVE-2026-49811 | Dell Technologies | high 8.4 | Dell Technologies Command | Monitor (DCM): insecure permissions | https://www.dell.com/support/kbdoc/en-us/000502473/dsa-2026-380-security-update-for-dell-command-monitor-dcm-for-an-incorrect-permission-assignment-for-critical-resource-vulnerability 2026-09-21 | CVE-2026-82165 CVE-2026-82165 | Dell Technologies | medium 5.5 | Dell Technologies Command | Integration Suite: insecure permissions | https://www.dell.com/support/kbdoc/en-us/000506922/dsa-2026-409-security-update-for-dell-command-integration-suite-for-system-center-for-an-incorrect-default-permissions-vulnerability 2026-09-21 | CVE-2026-82163 CVE-2026-82163 | Dell Technologies | medium 5.5 | Dell Technologies Command | Intel vPro Out of Band: insecure permissions | https://www.dell.com/support/kbdoc/en-us/000502470/dsa-2026-377-security-update-for-dell-command-intel-vpro-out-of-band-for-an-incorrect-default-permissions-vulnerability 2026-09-21 | CVE-2026-49810 CVE-2026-49810 | Dell Technologies | high 7.8 | Dell Technologies Command Powershell Provider (DCPP): information disclosure | https://www.dell.com/support/kbdoc/en-us/000502472/dsa-2026-379-security-update-for-dell-command-powershell-provider-dcpp-for-a-credential-theft-via-powershell-event-log-vulnerability 2026-09-21 | CVE-2026-92382 CVE-2026-92382 | Red Hat | medium 4.1 | usbredir: out-of-bounds write | https://access.redhat.com/security/cve/CVE-2026-92382 2026-09-21 | CVE-2026-94449 CVE-2026-94449 | Red Hat | high 7.5 | Red Hat SmallRye Fault Tolerance: resource exhaustion | https://access.redhat.com/security/cve/CVE-2026-94449 2026-09-21 | CVE-2026-94184 CVE-2026-94184 | Red Hat | high 8.1 | Red Hat fetchmail: stack buffer overflow | https://access.redhat.com/security/cve/CVE-2026-94184 2026-09-21 | CVE-2026-80110 CVE-2026-80110 | Red Hat | high 8.1 | Red Hat pki-core: improper authorization | https://access.redhat.com/security/cve/CVE-2026-80110 2026-09-21 | CVE-2026-75939 CVE-2026-75939 | Red Hat | high 7.4 | Red Hat OpenShift Container Platform 4: improper signature check | https://access.redhat.com/security/cve/CVE-2026-75939 2026-09-21 | CVE-2026-84285 CVE-2026-84285 | Dassault Systèmes | high 8.8 | Dassault Systèmes Tuleap Enterprise Edition: command injection | https://www.3ds.com/trust-center/security/security-advisories/cve-2026-84285 2026-09-21 | CVE-2026-94368 CVE-2026-94368 | Red Hat | high 7.1 | Red Hat Openshift Data Foundation 4: improper signature check | https://access.redhat.com/security/cve/CVE-2026-94368 2026-09-21 | CVE-2026-92574 CVE-2026-92574 | Red Hat | high 8.8 | Red Hat Confidential Compute Attestation: excessive privileges | https://access.redhat.com/security/cve/CVE-2026-92574 2026-09-21 | CVE-2026-15801 CVE-2026-15801 | Red Hat | high 8.0 | Red Hat OpenShift Container Platform 4: path traversal | https://access.redhat.com/security/cve/CVE-2026-15801 2026-09-21 | CVE-2026-94213 CVE-2026-94213 | Red Hat | medium 4.9 | Red Hat Authorization Services: missing authorization | https://access.redhat.com/security/cve/CVE-2026-94213 2026-09-21 | CVE-2026-94215 CVE-2026-94215 | Red Hat | medium 5.5 | Red Hat Admin REST API of Keycloak: missing authorization | https://access.redhat.com/security/cve/CVE-2026-94215 2026-09-21 | CVE-2026-94217 CVE-2026-94217 | Red Hat | low 3.5 | Red Hat Build of Keycloak: missing authorization | https://access.redhat.com/security/cve/CVE-2026-94217 2026-09-21 | CVE-2026-94218 CVE-2026-94218 | Red Hat | low 3.1 | Red Hat authentication session management of Keycloak: missing authorization | https://access.redhat.com/security/cve/CVE-2026-94218 2026-09-21 | CVE-2026-90860 CVE-2026-90860 | Canva | high 7.1 | The Canva Mobile App for HarmonyOS before v1.15.1 did not restrict the headers... | https://trust.canva.com?tcuUid=c17214e0-e758-4472-8238-abeb79faff07 2026-09-19 | CVE-2026-93999 CVE-2026-93999 | Red Hat | medium 4.2 | Red Hat OIDC protocol implementation of Keycloak: missing authorization | https://access.redhat.com/security/cve/CVE-2026-93999 2026-09-19 | CVE-2026-94000 CVE-2026-94000 | Red Hat | medium 6.6 | Red Hat Admin REST API of Keycloak: missing authorization | https://access.redhat.com/security/cve/CVE-2026-94000 2026-09-19 | CVE-2026-94001 CVE-2026-94001 | Red Hat | medium 6.5 | Red Hat Admin REST API of Keycloak: missing authorization | https://access.redhat.com/security/cve/CVE-2026-94001 2026-09-18 | GHSA-39wr-7q6h-cf68 | LMDeploy | high 7.5 | LMDeploy has an SSRF bypass | https://github.com/advisories/GHSA-39wr-7q6h-cf68 2026-09-18 | GHSA-3hmm-rh5q-gwwr CVE-2026-33625 | LMDeploy | high 8.8 | LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loading | https://github.com/advisories/GHSA-3hmm-rh5q-gwwr 2026-09-18 | GHSA-2vh9-42vm-xmv2 CVE-2025-66455 | LMDeploy | critical 9.8 | LMDeploy: unsafe deserialization | https://github.com/advisories/GHSA-2vh9-42vm-xmv2 2026-09-18 | CVE-2026-75885 CVE-2026-75885 | Red Hat | critical 9.3 | Red Hat OpenShift Container Platform 4: server-side request forgery | https://access.redhat.com/security/cve/CVE-2026-75885 2026-09-18 | CVE-2026-93574 CVE-2026-93574 | Red Hat | medium 6.5 | Red Hat Netty: request smuggling | https://access.redhat.com/errata/RHSA-2026:69440 2026-09-18 | CVE-2026-93562 CVE-2026-93562 | Red Hat | medium 6.5 | Red Hat Netty: request smuggling | https://access.redhat.com/errata/RHSA-2026:69440 2026-09-18 | CVE-2026-88097 CVE-2026-88097 | Microsoft | high 8.1 | Microsoft Edge (Chromium-based): use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-88097 2026-09-18 | CVE-2026-84241 CVE-2026-84241 | IBM | high 8.1 | IBM Guardium Data Protection: improper authorization | https://www.ibm.com/support/pages/node/7288035 2026-09-18 | CVE-2026-91202 CVE-2026-91202 | Red Hat | medium 6.1 | A flaw was found in cockpit-files | https://access.redhat.com/security/cve/CVE-2026-91202 2026-09-18 | CVE-2026-91203 CVE-2026-91203 | Red Hat | medium 6.0 | Red Hat cockpit-files. This vulnerability: race condition | https://access.redhat.com/security/cve/CVE-2026-91203 2026-09-18 | CVE-2026-91205 CVE-2026-91205 | Red Hat | medium 6.0 | Red Hat cockpit-files: race condition | https://access.redhat.com/security/cve/CVE-2026-91205 2026-09-18 | CVE-2026-84084 CVE-2026-84084 | IBM | high 8.8 | IBM Guardium Data Protection: cross-site request forgery | https://www.ibm.com/support/pages/node/7288035 2026-09-18 | CVE-2026-84085 CVE-2026-84085 | IBM | high 8.1 | IBM Guardium Data Protection: command injection | https://www.ibm.com/support/pages/node/7288035 2026-09-18 | CVE-2026-84086 CVE-2026-84086 | IBM | high 7.2 | IBM Guardium Data Protection: remote code execution | https://www.ibm.com/support/pages/node/7288035 2026-09-18 | CVE-2026-84089 CVE-2026-84089 | IBM | high 7.8 | IBM Guardium Data Protection: privilege escalation | https://www.ibm.com/support/pages/node/7288035 2026-09-18 | CVE-2026-84105 CVE-2026-84105 | IBM | high 7.7 | IBM Guardium Data Protection: information disclosure | https://www.ibm.com/support/pages/node/7288035 2026-09-18 | CVE-2026-84106 CVE-2026-84106 | IBM | high 8.9 | IBM Guardium Data Protection: remote code execution | https://www.ibm.com/support/pages/node/7288035 2026-09-18 | CVE-2026-84108 CVE-2026-84108 | IBM | high 8.1 | IBM Guardium Data Protection: remote code execution | https://www.ibm.com/support/pages/node/7288035 2026-09-18 | CVE-2026-84239 CVE-2026-84239 | IBM | high 7.6 | IBM Guardium Data Protection: information disclosure | https://www.ibm.com/support/pages/node/7288035 2026-09-18 | CVE-2026-84075 CVE-2026-84075 | IBM | critical 9.9 | IBM Guardium Data Protection: missing authentication | https://www.ibm.com/support/pages/node/7288040 2026-09-18 | CVE-2026-84076 CVE-2026-84076 | IBM | high 7.6 | IBM Guardium Data Protection: improper authorization | https://www.ibm.com/support/pages/node/7288035 2026-09-18 | CVE-2026-84077 CVE-2026-84077 | IBM | high 8.1 | IBM Guardium Data Protection: cross-site request forgery | https://www.ibm.com/support/pages/node/7288035 2026-09-18 | CVE-2026-84078 CVE-2026-84078 | IBM | critical 9.9 | IBM Guardium Data Protection: missing authentication | https://www.ibm.com/support/pages/node/7288040 2026-09-18 | CVE-2026-84081 CVE-2026-84081 | IBM | high 8.1 | IBM Guardium Data Protection: improper certificate validation | https://www.ibm.com/support/pages/node/7288035 2026-09-18 | CVE-2026-84082 CVE-2026-84082 | IBM | critical 9.8 | IBM Guardium Data Protection: SQL injection | https://www.ibm.com/support/pages/node/7288040 2026-09-18 | CVE-2026-84083 CVE-2026-84083 | IBM | high 7.8 | IBM Guardium Data Protection: privilege escalation | https://www.ibm.com/support/pages/node/7288035 2026-09-18 | CVE-2026-84031 CVE-2026-84031 | IBM | critical 9.0 | IBM Guardium Data Protection: remote code execution | https://www.ibm.com/support/pages/node/7288040 2026-09-18 | CVE-2026-84034 CVE-2026-84034 | IBM | high 8.8 | IBM Guardium Data Protection: hard-coded credentials | https://www.ibm.com/support/pages/node/7288040 2026-09-18 | CVE-2026-84036 CVE-2026-84036 | IBM | high 7.4 | IBM Guardium Data Protection: improper authorization | https://www.ibm.com/support/pages/node/7288035 2026-09-18 | CVE-2026-84064 CVE-2026-84064 | IBM | critical 9.9 | IBM Guardium Data Protection: SQL injection | https://www.ibm.com/support/pages/node/7288040 2026-09-18 | CVE-2026-84070 CVE-2026-84070 | IBM | high 8.9 | IBM Guardium Data Protection: remote code execution | https://www.ibm.com/support/pages/node/7288035 2026-09-18 | CVE-2026-84071 CVE-2026-84071 | IBM | high 7.2 | IBM Guardium Data Protection: command injection | https://www.ibm.com/support/pages/node/7288040 2026-09-18 | CVE-2026-84073 CVE-2026-84073 | IBM | critical 9.1 | IBM Guardium Data Protection: SQL injection | https://www.ibm.com/support/pages/node/7288040 2026-09-18 | CVE-2026-84074 CVE-2026-84074 | IBM | high 8.9 | IBM Guardium Data Protection: remote code execution | https://www.ibm.com/support/pages/node/7288035 2026-09-18 | CVE-2026-82890 CVE-2026-82890 | IBM | medium 5.9 | IBM Guardium Data Protection: cross-site scripting | https://www.ibm.com/support/pages/node/7288035 2026-09-18 | CVE-2026-82892 CVE-2026-82892 | IBM | high 8.1 | IBM Guardium Data Protection: remote code execution | https://www.ibm.com/support/pages/node/7288035 2026-09-18 | CVE-2026-82893 CVE-2026-82893 | IBM | high 7.8 | IBM Guardium Data Protection: privilege escalation | https://www.ibm.com/support/pages/node/7288035 2026-09-18 | CVE-2026-82896 CVE-2026-82896 | IBM | high 7.6 | IBM Guardium Data Protection: path traversal | https://www.ibm.com/support/pages/node/7288035 2026-09-18 | CVE-2026-82967 CVE-2026-82967 | IBM | critical 9.8 | IBM Guardium Data Protection: authentication bypass | https://www.ibm.com/support/pages/node/7288035 2026-09-18 | CVE-2026-81669 CVE-2026-81669 | IBM | high 7.2 | IBM Guardium Data Protection: command injection | https://www.ibm.com/support/pages/node/7288040 2026-09-18 | CVE-2026-81933 CVE-2026-81933 | IBM | high 8.8 | IBM Guardium Data Protection: SQL injection | https://www.ibm.com/support/pages/node/7288040 2026-09-18 | CVE-2026-81937 CVE-2026-81937 | IBM | high 7.2 | IBM Guardium Data Protection: command injection | https://www.ibm.com/support/pages/node/7288040 2026-09-18 | CVE-2026-82340 CVE-2026-82340 | IBM | critical 9.8 | IBM Guardium Data Protection: unsafe deserialization | https://www.ibm.com/support/pages/node/7288040 2026-09-18 | CVE-2026-82832 CVE-2026-82832 | IBM | critical 9.6 | IBM Guardium Data Protection: remote code execution | https://www.ibm.com/support/pages/node/7288035 2026-09-18 | CVE-2026-82885 CVE-2026-82885 | IBM | high 8.8 | IBM Guardium Data Protection: privilege escalation | https://www.ibm.com/support/pages/node/7288035 2026-09-18 | CVE-2026-82887 CVE-2026-82887 | IBM | high 8.8 | IBM Guardium Data Protection: remote code execution | https://www.ibm.com/support/pages/node/7288035 2026-09-18 | CVE-2026-80441 CVE-2026-80441 | IBM | critical 9.8 | IBM Guardium Data Protection: SQL injection | https://www.ibm.com/support/pages/node/7288040 2026-09-18 | CVE-2026-80442 CVE-2026-80442 | IBM | critical 9.9 | IBM Guardium Data Protection: command injection | https://www.ibm.com/support/pages/node/7288040 2026-09-18 | CVE-2026-81623 CVE-2026-81623 | IBM | medium 6.3 | IBM Guardium Data Protection: code execution | https://www.ibm.com/support/pages/node/7288040 2026-09-18 | CVE-2026-81626 CVE-2026-81626 | IBM | high 8.6 | IBM Guardium Data Protection: SQL injection | https://www.ibm.com/support/pages/node/7288040 2026-09-18 | CVE-2026-81656 CVE-2026-81656 | IBM | high 8.8 | IBM Guardium Data Protection: SQL injection | https://www.ibm.com/support/pages/node/7288040 2026-09-18 | CVE-2026-81657 CVE-2026-81657 | IBM | critical 9.8 | IBM Guardium Data Protection: remote code execution | https://www.ibm.com/support/pages/node/7288040 2026-09-18 | CVE-2026-75878 CVE-2026-75878 | IBM | critical 9.1 | IBM Sterling File Gateway: authentication bypass | https://www.ibm.com/support/pages/node/7287497 2026-09-18 | CVE-2026-75895 CVE-2026-75895 | Red Hat | high 7.5 | Red Hat libsmpp34: memory corruption | https://cgit.osmocom.org/libsmpp34/commit/?id=af0e2912057551dab97bbe26e6a41f18a75f3bbb 2026-09-18 | CVE-2026-17619 CVE-2026-17619 | IBM | high 8.6 | spectrum-lsf : IBM Platform RTM: SQL injection | https://www.ibm.com/support/pages/node/7287769 2026-09-18 | CVE-2026-18869 CVE-2026-18869 | IBM | medium 6.4 | IBM i: server-side request forgery | https://www.ibm.com/support/pages/node/7287873 2026-09-18 | CVE-2026-17262 CVE-2026-17262 | IBM | medium 5.4 | IBM i: denial of service | https://www.ibm.com/support/pages/node/7287873 2026-09-18 | CVE-2026-11727 CVE-2026-11727 | IBM | high 8.1 | IBM MQ for HPE NonStop: denial of service | https://www.ibm.com/support/pages/node/7287708 2026-09-18 | CVE-2026-11722 CVE-2026-11722 | IBM | medium 4.8 | IBM CICS TX Advanced: request smuggling | https://www.ibm.com/support/pages/node/7287740 2026-09-18 | CVE-2026-11725 CVE-2026-11725 | IBM | high 8.8 | IBM MQ: denial of service | https://www.ibm.com/support/pages/node/7284944 2026-09-18 | CVE-2026-11726 CVE-2026-11726 | IBM | high 8.1 | IBM MQ for HPE NonStop: information disclosure | https://www.ibm.com/support/pages/node/7287707 2026-09-18 | CVE-2026-11716 CVE-2026-11716 | IBM | high 7.5 | IBM MQ for HPE NonStop: denial of service | https://www.ibm.com/support/pages/node/7287705 2026-09-18 | CVE-2026-11710 CVE-2026-11710 | IBM | medium 6.5 | IBM WebSphere Application Server: request smuggling | https://www.ibm.com/support/pages/node/7286731 2026-09-18 | CVE-2026-11711 CVE-2026-11711 | IBM | medium 6.5 | IBM WebSphere Application Server: unsafe deserialization | https://www.ibm.com/support/pages/node/7286610 2026-09-18 | CVE-2026-11539 CVE-2026-11539 | IBM | medium 5.3 | IBM WebSphere Application Server: authentication bypass | https://www.ibm.com/support/pages/node/7286610 2026-09-18 | CVE-2026-11540 CVE-2026-11540 | IBM | medium 5.3 | IBM WebSphere Application Server: information disclosure | https://www.ibm.com/support/pages/node/7286610 2026-09-18 | CVE-2026-11545 CVE-2026-11545 | IBM | low 3.7 | IBM WebSphere Application Server: information disclosure | https://www.ibm.com/support/pages/node/7286730 2026-09-18 | CVE-2026-11548 CVE-2026-11548 | IBM | medium 4.8 | IBM CICS TX Advanced: request smuggling | https://www.ibm.com/support/pages/node/7287740 2026-09-18 | CVE-2026-11549 CVE-2026-11549 | IBM | medium 6.5 | IBM CICS TX Advanced: improper access control | https://www.ibm.com/support/pages/node/7287740 2026-09-18 | CVE-2026-75892 CVE-2026-75892 | Red Hat | medium 6.5 | Red Hat osmo-ggsn: out-of-bounds write | https://cgit.osmocom.org/osmo-ggsn/commit/?id=6c322f4dd339401a437da3c89c95f2bf64bca995 2026-09-18 | CVE-2026-75893 CVE-2026-75893 | Red Hat | high 7.5 | Red Hat osmo-bsc: heap buffer overflow | https://cgit.osmocom.org/osmo-bsc/commit/?id=2852a03c153cd9418c2a86d0b2193ac41169dbb7 2026-09-18 | CVE-2026-75894 CVE-2026-75894 | Red Hat | high 7.5 | Red Hat osmo-iuh: denial of service | https://cgit.osmocom.org/osmo-iuh/commit/?id=f06967126f486bcb185ccf3d1a8f9bc02c4da1f6 2026-09-18 | CVE-2026-11538 CVE-2026-11538 | IBM | low 3.7 | IBM WebSphere Application Server 9.0 and 8.5 is affected by a log injection... | https://www.ibm.com/support/pages/node/7286610 2026-09-18 | CVE-2026-93762 CVE-2026-93762 | MongoDB | critical 9.2 | MongoDB Mongoid: unsafe reflection | https://jira.mongodb.org/browse/MONGOID-5973 2026-09-18 | CVE-2026-93763 CVE-2026-93763 | MongoDB | high 7.1 | MongoDB Mongoid: information disclosure | https://jira.mongodb.org/browse/MONGOID-5984 2026-09-18 | CVE-2026-93764 CVE-2026-93764 | MongoDB | high 7.1 | MongoDB Mongoid: cleartext storage | https://jira.mongodb.org/browse/MONGOID-5989 2026-09-18 | CVE-2026-93759 CVE-2026-93759 | MongoDB | high 8.8 | MongoDB Mongoid: code injection | https://jira.mongodb.org/browse/MONGOID-5993 2026-09-18 | CVE-2026-93760 CVE-2026-93760 | MongoDB | high 8.3 | Mongoid does not restrict | https://jira.mongodb.org/browse/MONGOID-5994 2026-09-18 | CVE-2026-93761 CVE-2026-93761 | MongoDB | high 8.7 | MongoDB Mongoid: regular expression denial of service | https://jira.mongodb.org/browse/MONGOID-5981 2026-09-18 | CVE-2026-93432 CVE-2026-93432 | Red Hat | medium 6.1 | Red Hat Quarkus Qute template engine.: cross-site scripting | https://access.redhat.com/security/cve/CVE-2026-93432 2026-09-18 | CVE-2026-92768 CVE-2026-92768 | Red Hat | medium 5.5 | Red Hat cockpit-machines. This vulnerability: information disclosure | https://access.redhat.com/security/cve/CVE-2026-92768 2026-09-18 | CVE-2026-92745 CVE-2026-92745 | Red Hat | medium 5.0 | Red Hat cockpit-machines. This: local attacker could inspect process metadata... | https://access.redhat.com/security/cve/CVE-2026-92745 2026-09-18 | CVE-2026-92747 CVE-2026-92747 | Red Hat | medium 5.0 | Red Hat Enterprise Linux: local attacker could inspect running processes to... | https://access.redhat.com/security/cve/CVE-2026-92747 2026-09-18 | CVE-2026-93758 CVE-2026-93758 | MongoDB | high 8.6 | MongoDB Mongoid: insecure direct object reference | https://jira.mongodb.org/browse/MONGOID-5992 2026-09-18 | CVE-2026-93765 CVE-2026-93765 | MongoDB | high 8.3 | MongoDB Mongoid: unsafe reflection | https://jira.mongodb.org/browse/MONGOID-5973 2026-09-18 | CVE-2026-93579 CVE-2026-93579 | Red Hat | medium 6.5 | Red Hat Netty: request smuggling | https://access.redhat.com/errata/RHSA-2026:69440 2026-09-18 | CVE-2026-91142 CVE-2026-91142 | Red Hat | low 3.6 | Red Hat Cockpit. An integer overflow vulnerability: integer overflow | https://access.redhat.com/security/cve/CVE-2026-91142 2026-09-18 | CVE-2026-91147 CVE-2026-91147 | Red Hat | medium 5.9 | Red Hat Enterprise Linux 10: denial of service | https://access.redhat.com/security/cve/CVE-2026-91147 2026-09-18 | CVE-2026-91149 CVE-2026-91149 | Red Hat | high 7.5 | Red Hat Cockpit: denial of service | https://access.redhat.com/security/cve/CVE-2026-91149 2026-09-18 | CVE-2026-75031 CVE-2026-75031 | Red Hat | critical 9.8 | Red Hat Interchange: remote code execution | https://github.com/interchange/interchange/commit/65b6ea9d3761dd1fd2071c962819562afa335e4e 2026-09-18 | CVE-2026-75883 CVE-2026-75883 | Red Hat | medium 6.8 | Red Hat ppp: heap buffer overflow | https://github.com/ppp-project/ppp/security/advisories/GHSA-rwr9-4vx8-vc35 2026-09-18 | CVE-2026-1025 CVE-2026-1025 | IBM | medium 6.1 | IBM Common Licensing: cross-site scripting | https://www.ibm.com/support/pages/node/7286490 2026-09-18 | CVE-2026-1029 CVE-2026-1029 | IBM | medium 5.4 | IBM Common Licensing: cross-site scripting | https://www.ibm.com/support/pages/node/7286490 2026-09-18 | CVE-2026-1030 CVE-2026-1030 | IBM | medium 4.3 | IBM Common Licensing: information disclosure | https://www.ibm.com/support/pages/node/7286490 2026-09-18 | CVE-2026-1031 CVE-2026-1031 | IBM | medium 6.1 | IBM Common Licensing: cross-site scripting | https://www.ibm.com/support/pages/node/7286490 2026-09-18 | CVE-2026-1037 CVE-2026-1037 | IBM | medium 6.1 | IBM Common Licensing: cross-site scripting | https://www.ibm.com/support/pages/node/7286490 2026-09-18 | CVE-2026-10841 CVE-2026-10841 | IBM | medium 4.2 | IBM CICS TX Advanced: request smuggling | https://www.ibm.com/support/pages/node/7287740 2026-09-18 | CVE-2026-10853 CVE-2026-10853 | IBM | high 7.5 | IBM MQ: denial of service | https://www.ibm.com/support/pages/node/7284905 2026-09-18 | CVE-2026-10858 CVE-2026-10858 | IBM | critical 9.9 | IBM MQ for HPE NonStop: denial of service | https://www.ibm.com/support/pages/node/7287704 2026-09-18 | CVE-2026-11375 CVE-2026-11375 | IBM | high 8.8 | IBM MQ: denial of service | https://www.ibm.com/support/pages/node/7284948 2026-09-18 | CVE-2026-11378 CVE-2026-11378 | IBM | high 8.8 | IBM MQ: denial of service | https://www.ibm.com/support/pages/node/7284945 2026-09-18 | CVE-2026-11381 CVE-2026-11381 | IBM | high 8.8 | IBM MQ for HPE NonStop: denial of service | https://www.ibm.com/support/pages/node/7287706 2026-09-18 | CVE-2026-11537 CVE-2026-11537 | IBM | medium 4.3 | IBM WebSphere Application Server: information disclosure | https://www.ibm.com/support/pages/node/7286610 2026-09-18 | CVE-2026-10030 CVE-2026-10030 | IBM | high 7.1 | IBM MQ: improper authorization | https://www.ibm.com/support/pages/node/7284894 2026-09-18 | CVE-2026-10575 CVE-2026-10575 | IBM | high 8.8 | IBM MQ: denial of service | https://www.ibm.com/support/pages/node/7287778 2026-09-18 | CVE-2026-10744 CVE-2026-10744 | IBM | high 7.5 | IBM MQ for HPE NonStop: denial of service | https://www.ibm.com/support/pages/node/7287702 2026-09-18 | CVE-2026-10747 CVE-2026-10747 | IBM | critical 10.0 | IBM MQ Appliance: denial of service | https://www.ibm.com/support/pages/node/7284690 2026-09-18 | CVE-2026-10751 CVE-2026-10751 | IBM | high 7.5 | IBM MQ: code execution | https://www.ibm.com/support/pages/node/7284898 2026-09-18 | CVE-2025-36147 CVE-2025-36147 | IBM | medium 6.1 | IBM Financial Transaction Manager: cross-site scripting | https://www.ibm.com/support/pages/node/7285838 2026-09-18 | CVE-2025-36178 CVE-2025-36178 | IBM | medium 5.4 | IBM Controller: improper quantity validation | https://www.ibm.com/support/pages/node/7287970 2026-09-18 | CVE-2025-36421 CVE-2025-36421 | IBM | medium 5.9 | IBM Controller: information disclosure | https://www.ibm.com/support/pages/node/7287970 2026-09-18 | CVE-2026-10027 CVE-2026-10027 | IBM | high 8.1 | IBM MQ: denial of service | https://www.ibm.com/support/pages/node/7284893 2026-09-18 | CVE-2025-14753 CVE-2025-14753 | IBM | high 7.5 | IBM Cloud Pak for Data: path traversal | https://www.ibm.com/support/pages/node/7287141 2026-09-18 | CVE-2025-14754 CVE-2025-14754 | IBM | high 8.8 | IBM Cloud Pak for Data: code execution | https://www.ibm.com/support/pages/node/7287142 2026-09-18 | CVE-2025-15399 CVE-2025-15399 | IBM | critical 10.0 | IBM Common Licensing: cross-site request forgery | https://www.ibm.com/support/pages/node/7286490 2026-09-18 | CVE-2025-33141 CVE-2025-33141 | IBM | medium 6.5 | IBM QRadar: information disclosure | https://www.ibm.com/support/pages/node/7286014 2026-09-18 | CVE-2025-33147 CVE-2025-33147 | IBM | medium 5.9 | IBM Cognos Analytics: information disclosure | https://www.ibm.com/support/pages/node/7287209 2026-09-18 | CVE-2025-36045 CVE-2025-36045 | IBM | medium 4.3 | IBM TS4300: denial of service | https://www.ibm.com/support/pages/node/7287022 2026-09-18 | CVE-2025-36076 CVE-2025-36076 | IBM | medium 4.3 | IBM Cognos Analytics: information disclosure | https://www.ibm.com/support/pages/node/7287209 2026-09-18 | CVE-2026-93653 CVE-2026-93653 | Red Hat | medium 5.5 | Red Hat Poppler: denial of service | https://access.redhat.com/security/cve/CVE-2026-93653 2026-09-18 | CVE-2026-93676 CVE-2026-93676 | Red Hat | low 3.2 | Red Hat Enterprise Linux: information disclosure | https://access.redhat.com/security/cve/CVE-2026-93676 2026-09-18 | CVE-2026-93685 CVE-2026-93685 | Red Hat | medium 5.4 | Red Hat Advanced Cluster Management for Kubernetes 2: remote code execution | https://access.redhat.com/security/cve/CVE-2026-93685 2026-09-18 | CVE-2026-93573 CVE-2026-93573 | Red Hat | medium 6.5 | Red Hat Netty: request smuggling | https://access.redhat.com/errata/RHSA-2026:69440 2026-09-18 | CVE-2026-93576 CVE-2026-93576 | Red Hat | high 7.5 | Red Hat Netty netty-codec-smtp. The: spoofing | https://access.redhat.com/security/cve/CVE-2026-93576 2026-09-18 | CVE-2026-93565 CVE-2026-93565 | Red Hat | high 7.5 | Red Hat Netty RtspDecoder: attacker could bypass method-based access controls | https://access.redhat.com/errata/RHSA-2026:69440 2026-09-18 | CVE-2026-93566 CVE-2026-93566 | Red Hat | medium 6.5 | Red Hat Netty. A remote attacker: request smuggling | https://access.redhat.com/errata/RHSA-2026:69440 2026-09-18 | CVE-2026-93567 CVE-2026-93567 | Red Hat | high 7.5 | Red Hat Netty: improper input validation | https://access.redhat.com/errata/RHSA-2026:69440 2026-09-18 | CVE-2026-93568 CVE-2026-93568 | Red Hat | high 7.5 | Red Hat Netty. A remote attacker: attacker could bypass security policies | https://access.redhat.com/errata/RHSA-2026:69440 2026-09-18 | CVE-2026-93569 CVE-2026-93569 | Red Hat | high 8.2 | Red Hat Netty: request smuggling | https://access.redhat.com/errata/RHSA-2026:69440 2026-09-18 | CVE-2026-93558 CVE-2026-93558 | Red Hat | high 7.5 | Red Hat Netty: resource exhaustion | https://access.redhat.com/errata/RHSA-2026:69440 2026-09-18 | CVE-2026-93564 CVE-2026-93564 | Red Hat | high 7.5 | Red Hat Netty. A reference-count leak: denial of service | https://access.redhat.com/errata/RHSA-2026:69440 2026-09-18 | CVE-2026-85511 CVE-2026-85511 | Red Hat | medium 4.2 | Red Hat EAP: authentication bypass by spoofing | https://access.redhat.com/errata/RHSA-2026:70228 2026-09-18 | CVE-2026-25684 CVE-2026-25684 | Zscaler | medium 4.4 | Zscaler: improper input validation | https://help.zscaler.com/zia/release-upgrade-summary-2026 2026-09-18 | CVE-2025-1350 CVE-2025-1350 | IBM | medium 5.3 | IBM Controller: information disclosure | https://www.ibm.com/support/pages/node/7287970 2026-09-18 | CVE-2025-13882 CVE-2025-13882 | IBM | medium 5.3 | IBM Sterling Partner Engagement Manager: denial of service | https://www.ibm.com/support/pages/node/7288365 2026-09-18 | CVE-2026-10832 CVE-2026-10832 | Red Hat | medium 5.9 | Red Hat DERDecoder class within wildfly-elytron-asn1: resource exhaustion | https://access.redhat.com/errata/RHSA-2026:70228 2026-09-18 | CVE-2024-56344 CVE-2024-56344 | IBM | medium 5.9 | IBM Cognos Analytics: information disclosure | https://www.ibm.com/support/pages/node/7287211 2026-09-18 | CVE-2026-93560 CVE-2026-93560 | Red Hat | high 7.5 | Red Hat Netty STOMP codec. A remote attacker: denial of service | https://access.redhat.com/security/cve/CVE-2026-93560 2026-09-18 | CVE-2026-93491 CVE-2026-93491 | Red Hat | high 7.5 | Red Hat Netty: denial of service | https://access.redhat.com/errata/RHSA-2026:69440 2026-09-18 | CVE-2026-93492 CVE-2026-93492 | Red Hat | medium 5.3 | Red Hat Netty: denial of service | https://access.redhat.com/errata/RHSA-2026:69440 2026-09-18 | GHSA-72hg-9rq2-f4xr CVE-2026-93393 | MongoDB | high 8.1 | Heap overflow via oversized decrypted TLS record sequence in Windows Secure Channel stream | https://github.com/mongodb/mongo-c-driver/security/advisories/GHSA-72hg-9rq2-f4xr 2026-09-18 | CVE-2026-93488 CVE-2026-93488 | Red Hat | high 7.5 | Red Hat Netty: denial of service | https://access.redhat.com/errata/RHSA-2026:69440 2026-09-18 | CVE-2026-93575 CVE-2026-93575 | Red Hat | high 7.5 | Red Hat Netty: resource exhaustion | https://access.redhat.com/security/cve/CVE-2026-93575 2026-09-18 | CVE-2026-93578 CVE-2026-93578 | Red Hat | medium 5.9 | A flaw was found in Netty's Online Certificate Status Protocol (OCSP) Client | https://access.redhat.com/security/cve/CVE-2026-93578 2026-09-18 | CVE-2026-93561 CVE-2026-93561 | Red Hat | medium 6.5 | A flaw was found in io.netty/netty-codec-memcache | https://access.redhat.com/security/cve/CVE-2026-93561 2026-09-18 | CVE-2026-93563 CVE-2026-93563 | Red Hat | high 7.5 | Red Hat Netty: denial of service | https://access.redhat.com/security/cve/CVE-2026-93563 2026-09-18 | CVE-2026-93572 CVE-2026-93572 | Red Hat | high 7.5 | Red Hat Netty: denial of service | https://access.redhat.com/security/cve/CVE-2026-93572 2026-09-18 | CVE-2026-81627 CVE-2026-81627 | Red Hat | high 8.2 | Red Hat QEMU. The VAPIC setup hypercall: out-of-bounds write | https://access.redhat.com/security/cve/CVE-2026-81627 2026-09-18 | CVE-2026-87743 CVE-2026-87743 | Red Hat | high 7.5 | Red Hat Quarkus HTTP security: information disclosure | https://access.redhat.com/errata/RHSA-2026:69440 2026-09-18 | CVE-2026-93493 CVE-2026-93493 | Red Hat | medium 5.9 | A flaw was found in Netty's `netty-handler-ssl-ocsp` component | https://access.redhat.com/security/cve/CVE-2026-93493 2026-09-18 | CVE-2026-93494 CVE-2026-93494 | Red Hat | high 7.5 | Red Hat Netty: denial of service | https://access.redhat.com/security/cve/CVE-2026-93494 2026-09-18 | CVE-2026-89058 CVE-2026-89058 | Red Hat | high 7.4 | A flaw was found in RESTEasy's CorsFilter | https://access.redhat.com/security/cve/CVE-2026-89058 2026-09-18 | CVE-2026-89059 CVE-2026-89059 | Red Hat | high 7.5 | Red Hat RESTEasy: denial of service | https://access.redhat.com/security/cve/CVE-2026-89059 2026-09-18 | CVE-2026-85878 CVE-2026-85878 | Microsoft | critical 9.9 | Microsoft Azure HorizonDB: improper authorization | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85878 2026-09-18 | CVE-2026-85887 CVE-2026-85887 | Microsoft | high 7.7 | Microsoft 365 Copilot: insecure permissions | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85887 2026-09-18 | CVE-2026-83946 CVE-2026-83946 | Microsoft | high 8.2 | Microsoft Azure Portal: cross-site scripting | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83946 2026-09-18 | CVE-2026-69843 CVE-2026-69843 | Microsoft | critical 10.0 | Microsoft Fabric: authentication bypass | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69843 2026-09-18 | CVE-2026-62874 CVE-2026-62874 | Microsoft | critical 10.0 | Microsoft Azure Billing: privilege escalation | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62874 2026-09-17 | GHSA-c3mw-737p-c7g2 CVE-2026-86049 | Jupyter | high 7.1 | Jupyter Server: 5xx request logging leaks token-bearing Referer header values | https://github.com/advisories/GHSA-c3mw-737p-c7g2 2026-09-17 | GHSA-hpj9-grjp-7vc7 CVE-2026-73245 | kestra | medium 6.5 | kestra: missing authentication | https://github.com/advisories/GHSA-hpj9-grjp-7vc7 2026-09-17 | GHSA-8pw2-6jv3-mj5j CVE-2026-69147 | vLLM | medium 6.5 | vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation | https://github.com/advisories/GHSA-8pw2-6jv3-mj5j 2026-09-17 | GHSA-hx8v-g79f-8w5f CVE-2026-59823 | LiteLLM | medium | LiteLLM Proxy has server-side request forgery via the `user_config` request parameter | https://github.com/advisories/GHSA-hx8v-g79f-8w5f 2026-09-17 | CVE-2026-85885 CVE-2026-85885 | Microsoft | critical 9.9 | Microsoft 365 Copilot: command injection | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85885 2026-09-17 | CVE-2026-85889 CVE-2026-85889 | Microsoft | critical 10.0 | Microsoft Azure AI Foundry: missing authentication | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85889 2026-09-17 | CVE-2026-85917 CVE-2026-85917 | Microsoft | high 7.5 | Microsoft Azure AI Foundry: server-side request forgery | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85917 2026-09-17 | CVE-2026-87701 CVE-2026-87701 | Microsoft | critical 9.6 | Microsoft Azure Cosmos DB: privilege escalation | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87701 2026-09-17 | CVE-2026-87886 CVE-2026-87886 | Acronis | high 7.8 | Acronis Backup: privilege escalation | https://security-advisory.acronis.com/advisories/SEC-10986 2026-09-17 | CVE-2026-83944 CVE-2026-83944 | Microsoft | critical 10.0 | Microsoft Azure Logic Apps: improper access control | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83944 2026-09-17 | CVE-2026-78501 CVE-2026-78501 | Microsoft | high 7.4 | Microsoft 365 Copilot's Business Chat: command injection | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78501 2026-09-17 | CVE-2026-77903 CVE-2026-77903 | Microsoft | critical 9.0 | Microsoft Dataverse: authentication bypass | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77903 2026-09-17 | CVE-2026-70200 CVE-2026-70200 | Microsoft | critical 10.0 | Microsoft Azure Logic Apps: path traversal | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70200 2026-09-17 | CVE-2026-70009 CVE-2026-70009 | Microsoft | critical 9.3 | Microsoft Azure ARC: path traversal | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70009 2026-09-17 | CVE-2026-69865 CVE-2026-69865 | Microsoft | critical 10.0 | Microsoft Azure Container Registry: privilege escalation | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69865 2026-09-17 | CVE-2026-69399 CVE-2026-69399 | Microsoft | critical 10.0 | Microsoft Azure ARC: privilege escalation | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69399 2026-09-17 | CVE-2026-68791 CVE-2026-68791 | Microsoft | high 8.6 | Microsoft Azure Machine Learning: improper authorization | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68791 2026-09-17 | CVE-2026-55946 CVE-2026-55946 | Microsoft | medium 6.1 | Microsoft Copilot: command injection | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55946 2026-09-17 | GHSA-h5c2-f56c-mcqh CVE-2026-92758 | MongoDB | medium 5.7 | Insertion of Sensitive Information into Log File | https://github.com/mongodb/mongo-efcore-provider/security/advisories/GHSA-h5c2-f56c-mcqh 2026-09-17 | GHSA-4jh6-4wjh-9mgp CVE-2026-92757 | MongoDB | medium 6.8 | Silent plaintext storage of encrypted fields via mis-keyed encryption map in the EF Core provider | https://github.com/mongodb/mongo-efcore-provider/security/advisories/GHSA-4jh6-4wjh-9mgp 2026-09-17 | CVE-2026-93387 CVE-2026-93387 | Google | medium 4.3 | Google Chrome: remote attacker could obtain cross-origin data | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0194356994.html 2026-09-17 | CVE-2026-93394 CVE-2026-93394 | MongoDB | medium 6.3 | A flaw in libmongoc's SCRAM authentication implementation caused the client to... | https://jira.mongodb.org/browse/CDRIVER-6315 2026-09-17 | CVE-2026-93395 CVE-2026-93395 | MongoDB | medium 6.9 | MongoDB C Driver: integer overflow | https://jira.mongodb.org/browse/CDRIVER-6343 2026-09-17 | CVE-2026-93377 CVE-2026-93377 | Google | high 8.8 | Google Chrome: type confusion | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0194356994.html 2026-09-17 | CVE-2026-93378 CVE-2026-93378 | Google | low 3.1 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0194356994.html 2026-09-17 | CVE-2026-93379 CVE-2026-93379 | Google | medium 4.3 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0194356994.html 2026-09-17 | CVE-2026-93380 CVE-2026-93380 | Google | low 3.1 | Google Chrome: race condition | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0194356994.html 2026-09-17 | CVE-2026-93381 CVE-2026-93381 | Google | high 8.8 | Google Chrome: buffer overflow | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0194356994.html 2026-09-17 | CVE-2026-93382 CVE-2026-93382 | Google | high 8.8 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0194356994.html 2026-09-17 | CVE-2026-93383 CVE-2026-93383 | Google | medium 4.3 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0194356994.html 2026-09-17 | CVE-2026-93384 CVE-2026-93384 | Google | low 3.7 | Google Chrome: server-side request forgery | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0194356994.html 2026-09-17 | CVE-2026-93385 CVE-2026-93385 | Google | medium 6.5 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0194356994.html 2026-09-17 | CVE-2026-93386 CVE-2026-93386 | Google | medium 5.4 | Google Chrome: spoofing | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0194356994.html 2026-09-17 | CVE-2026-93372 CVE-2026-93372 | Google | critical 9.6 | Google Chrome: buffer overflow | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0194356994.html 2026-09-17 | CVE-2026-93373 CVE-2026-93373 | Google | critical 9.6 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0194356994.html 2026-09-17 | CVE-2026-93374 CVE-2026-93374 | Google | critical 9.6 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0194356994.html 2026-09-17 | CVE-2026-93375 CVE-2026-93375 | Google | high 8.1 | Google Chrome: code execution | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0194356994.html 2026-09-17 | CVE-2026-93376 CVE-2026-93376 | Google | medium 6.3 | Google Chrome: out-of-bounds read | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0194356994.html 2026-09-17 | CVE-2026-76154 CVE-2026-76154 | Grafana Labs | high 7.3 | Grafana: cross-site scripting | https://grafana.com/security/security-advisories/cve-2026-76154 2026-09-17 | CVE-2026-15815 CVE-2026-15815 | Grafana Labs | high 8.8 | Grafana: remote code execution | https://grafana.com/security/security-advisories/cve-2026-15815 2026-09-17 | CVE-2026-92756 CVE-2026-92756 | MongoDB | medium 6.8 | MongoDB Entity Framework Core Provider: missing encryption | https://jira.mongodb.org/browse/EF-388 2026-09-17 | CVE-2026-90997 CVE-2026-90997 | Red Hat | high 7.4 | Red Hat Keycloak.: capture-replay | https://access.redhat.com/security/cve/CVE-2026-90997 2026-09-17 | CVE-2026-19477 CVE-2026-19477 | National Instruments | high 8.6 | National Instruments Universal Library for Linux (uldaq): stack buffer overflow | https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/2026/stack-based-buffer-overflow-vulnerability-linux-uldaq.html 2026-09-17 | CVE-2026-28326 CVE-2026-28326 | SolarWinds | high 8.8 | SolarWinds Access Rights Manager: remote code execution | https://documentation.solarwinds.com/en/success_center/arm/content/secure-your-arm-deployment.htm 2026-09-17 | CVE-2026-76781 CVE-2026-76781 | Red Hat | medium 5.5 | Red Hat libxml2: null pointer dereference | https://access.redhat.com/errata/RHSA-2026:57604 2026-09-17 | CVE-2026-56795 CVE-2026-56795 | Dell Technologies | high 8.2 | Dell Technologies Driver Pack For Linux OS: code execution | https://www.dell.com/support/kbdoc/en-us/000509930/dsa-2026-422-security-update-for-dell-server-update-utility-suu-vulnerability 2026-09-17 | CVE-2026-87742 CVE-2026-87742 | Red Hat | high 7.5 | Red Hat quarkus-websockets-next. This vulnerability: denial of service | https://access.redhat.com/errata/RHSA-2026:69440 2026-09-17 | CVE-2026-81445 CVE-2026-81445 | Dell Technologies | high 7.2 | Dell Technologies OpenManage Server: improper privilege management | https://www.dell.com/support/kbdoc/en-us/000506586/dsa-2026-403-security-update-for-dell-openmanage-server-administrator-omsa-network-access-vulnerabilitiesv 2026-09-17 | CVE-2026-81446 CVE-2026-81446 | Dell Technologies | high 7.4 | Dell Technologies OpenManage Server: server-side request forgery | https://www.dell.com/support/kbdoc/en-us/000506586/dsa-2026-403-security-update-for-dell-openmanage-server-administrator-omsa-network-access-vulnerabilitiesv 2026-09-17 | CVE-2026-81447 CVE-2026-81447 | Dell Technologies | medium 6.8 | Dell Technologies OpenManage Server: improper certificate validation | https://www.dell.com/support/kbdoc/en-us/000506586/dsa-2026-403-security-update-for-dell-openmanage-server-administrator-omsa-network-access-vulnerabilitiesv 2026-09-17 | CVE-2026-80356 CVE-2026-80356 | Dell Technologies | high 7.3 | Dell Technologies OpenManage Server: information disclosure | https://www.dell.com/support/kbdoc/en-us/000506586/dsa-2026-403-security-update-for-dell-openmanage-server-administrator-omsa-network-access-vulnerabilitiesv 2026-09-17 | CVE-2026-54471 CVE-2026-54471 | Dell Technologies | low 3.5 | Dell Technologies SmartFabric Manager: information disclosure | https://www.dell.com/support/kbdoc/en-us/000489671/dsa-2026-317-security-update-for-dell-smartfabric-manager-multiple-third-party-component-vulnerabilities 2026-09-17 | CVE-2026-26950 CVE-2026-26950 | Dell Technologies | high 8.1 | Dell Technologies SmartFabric Manager: insufficient authenticity check | https://www.dell.com/support/kbdoc/en-us/000489671/dsa-2026-317-security-update-for-dell-smartfabric-manager-multiple-third-party-component-vulnerabilities 2026-09-17 | CVE-2026-89418 CVE-2026-89418 | Google | high 8.7 | protobuf-javascript (aka google-protobuf npm package): uncontrolled recursion | https://github.com/protocolbuffers/protobuf-javascript/security/advisories/GHSA-5h29-r2cp-hfmr 2026-09-17 | CVE-2026-81829 CVE-2026-81829 | Red Hat | medium 5.3 | Red Hat SmallRye JWT: path traversal | https://access.redhat.com/errata/RHSA-2026:69470 2026-09-17 | CVE-2026-81442 CVE-2026-81442 | Dell Technologies | high 8.1 | Dell Technologies OpenManage Server Administrator Managed Node: tampering | https://www.dell.com/support/kbdoc/en-us/000506586/dsa-2026-403-security-update-for-dell-openmanage-server-administrator-omsa-network-access-vulnerabilitiesv 2026-09-17 | CVE-2026-81443 CVE-2026-81443 | Dell Technologies | medium 6.4 | Dell Technologies OpenManage Server: server-side request forgery | https://www.dell.com/support/kbdoc/en-us/000506586/dsa-2026-403-security-update-for-dell-openmanage-server-administrator-omsa-network-access-vulnerabilitiesv 2026-09-17 | CVE-2026-81453 CVE-2026-81453 | Dell Technologies | medium 6.5 | Dell Technologies OpenManage Server Administrator Managed Node: path traversal | https://www.dell.com/support/kbdoc/en-us/000506586/dsa-2026-403-security-update-for-dell-openmanage-server-administrator-omsa-network-access-vulnerabilitiesv 2026-09-17 | CVE-2026-80355 CVE-2026-80355 | Dell Technologies | medium 5.4 | Dell Technologies OpenManage Server: cross-site request forgery | https://www.dell.com/support/kbdoc/en-us/000506586/dsa-2026-403-security-update-for-dell-openmanage-server-administrator-omsa-network-access-vulnerabilitiesv 2026-09-17 | CVE-2026-71568 CVE-2026-71568 | Red Hat | medium 5.3 | Red Hat bmctest: missing authentication | https://github.com/openshift-metal3/bmctest/security/advisories/GHSA-53vv-qh77-2hqh 2026-09-17 | CVE-2026-92904 CVE-2026-92904 | Red Hat | medium 4.3 | Red Hat Satellite 6: improper authorization | https://access.redhat.com/security/cve/CVE-2026-92904 2026-09-17 | CVE-2026-81481 CVE-2026-81481 | Dell Technologies | high 7.5 | Dell Technologies OpenManage Server Administrator Managed Node: path traversal | https://www.dell.com/support/kbdoc/en-us/000506586/dsa-2026-403-security-update-for-dell-openmanage-server-administrator-omsa-network-access-vulnerabilitiesv 2026-09-17 | CVE-2026-92925 CVE-2026-92925 | Red Hat | high 7.1 | Redis community: out-of-bounds read | https://access.redhat.com/errata/RHSA-2026:65120 2026-09-17 | CVE-2026-81480 CVE-2026-81480 | Dell Technologies | high 7.2 | Dell Technologies OpenManage Server: stack buffer overflow | https://www.dell.com/support/kbdoc/en-us/000506586/dsa-2026-403-security-update-for-dell-openmanage-server-administrator-omsa-network-access-vulnerabilitiesv 2026-09-17 | CVE-2026-81440 CVE-2026-81440 | Dell Technologies | high 7.3 | Dell Technologies OpenManage Server: hard-coded credentials | https://www.dell.com/support/kbdoc/en-us/000506586/dsa-2026-403-security-update-for-dell-openmanage-server-administrator-omsa-network-access-vulnerabilitiesv 2026-09-17 | CVE-2026-81441 CVE-2026-81441 | Dell Technologies | medium 4.0 | Dell Technologies OpenManage Server: missing authentication | https://www.dell.com/support/kbdoc/en-us/000506586/dsa-2026-403-security-update-for-dell-openmanage-server-administrator-omsa-network-access-vulnerabilitiesv 2026-09-17 | CVE-2026-81475 CVE-2026-81475 | Dell Technologies | high 8.1 | Dell Technologies OpenManage Server: missing authentication | https://www.dell.com/support/kbdoc/en-us/000506586/dsa-2026-403-security-update-for-dell-openmanage-server-administrator-omsa-network-access-vulnerabilitiesv 2026-09-17 | CVE-2026-81476 CVE-2026-81476 | Dell Technologies | high 8.1 | Dell Technologies OpenManage Server: command injection | https://www.dell.com/support/kbdoc/en-us/000506586/dsa-2026-403-security-update-for-dell-openmanage-server-administrator-omsa-network-access-vulnerabilitiesv 2026-09-17 | CVE-2026-81477 CVE-2026-81477 | Dell Technologies | high 7.2 | Dell Technologies OpenManage Server: heap buffer overflow | https://www.dell.com/support/kbdoc/en-us/000506586/dsa-2026-403-security-update-for-dell-openmanage-server-administrator-omsa-network-access-vulnerabilitiesv 2026-09-17 | CVE-2026-81478 CVE-2026-81478 | Dell Technologies | high 8.1 | Dell Technologies OpenManage Server Administrator Managed Node: hard-coded key | https://www.dell.com/support/kbdoc/en-us/000506586/dsa-2026-403-security-update-for-dell-openmanage-server-administrator-omsa-network-access-vulnerabilitiesv 2026-09-17 | CVE-2026-81479 CVE-2026-81479 | Dell Technologies | medium 5.8 | Dell Technologies OpenManage Server: denial of service | https://www.dell.com/support/kbdoc/en-us/000506586/dsa-2026-403-security-update-for-dell-openmanage-server-administrator-omsa-network-access-vulnerabilitiesv 2026-09-17 | AWS-2026-114 CVE-2026-92943 | AWS | high 8.1 | Improper validation of certificate with host mismatch in AWS IoT Device SDK for Python | https://aws.amazon.com/security/security-bulletins/rss/2026-114-aws/ 2026-09-17 | CVE-2026-81474 CVE-2026-81474 | Dell Technologies | high 7.8 | Dell Technologies OpenManage Server: heap buffer overflow | https://www.dell.com/support/kbdoc/en-us/000506586/dsa-2026-403-security-update-for-dell-openmanage-server-administrator-omsa-network-access-vulnerabilitiesv 2026-09-17 | CVE-2026-92893 CVE-2026-92893 | Red Hat | medium 4.3 | Red Hat Satellite 6: improper authorization | https://access.redhat.com/security/cve/CVE-2026-92893 2026-09-17 | CVE-2026-92903 CVE-2026-92903 | Snowflake | high 8.2 | Snowflake CLI: improper input validation | https://github.com/snowflakedb/snowflake-cli/releases/tag/v3.27.0 2026-09-17 | CVE-2026-66269 CVE-2026-66269 | Dell Technologies | high 7.3 | Dell OpenManage Server Administrator Managed Node: unsafe reflection | https://www.dell.com/support/kbdoc/en-us/000506586/dsa-2026-403-security-update-for-dell-openmanage-server-administrator-omsa-network-access-vulnerabilitiesv 2026-09-17 | CVE-2026-81438 CVE-2026-81438 | Dell Technologies | low 3.7 | Dell OpenManage Server Administrator Managed Node (Patch) fo: weak cryptography | https://www.dell.com/support/kbdoc/en-us/000506586/dsa-2026-403-security-update-for-dell-openmanage-server-administrator-omsa-network-access-vulnerabilitiesv 2026-09-17 | CVE-2026-81439 CVE-2026-81439 | Dell Technologies | low 3.7 | Dell Technologies OpenManage Server: improper authorization | https://www.dell.com/support/kbdoc/en-us/000506586/dsa-2026-403-security-update-for-dell-openmanage-server-administrator-omsa-network-access-vulnerabilitiesv 2026-09-17 | CVE-2026-92894 CVE-2026-92894 | Red Hat | medium 4.3 | Red Hat Satellite 6: improper authorization | https://access.redhat.com/security/cve/CVE-2026-92894 2026-09-17 | CVE-2026-86320 CVE-2026-86320 | Red Hat | high 7.8 | Red Hat flatpak-builder: code execution | https://access.redhat.com/security/cve/CVE-2026-86320 2026-09-17 | CVE-2026-25281 CVE-2026-25281 | Qualcomm | high 7.4 | Qualcomm Snapdragon: resource exhaustion | https://docs.qualcomm.com/product/publicresources/securitybulletin/september-2026-bulletin.html 2026-09-17 | CVE-2026-25282 CVE-2026-25282 | Qualcomm | high 7.9 | Qualcomm Snapdragon: out-of-bounds read | https://docs.qualcomm.com/product/publicresources/securitybulletin/september-2026-bulletin.html 2026-09-17 | CVE-2026-25283 CVE-2026-25283 | Qualcomm | high 8.8 | Qualcomm Snapdragon: memory corruption | https://docs.qualcomm.com/product/publicresources/securitybulletin/september-2026-bulletin.html 2026-09-17 | CVE-2026-25284 CVE-2026-25284 | Qualcomm | high 7.3 | Qualcomm Snapdragon: information disclosure | https://docs.qualcomm.com/product/publicresources/securitybulletin/september-2026-bulletin.html 2026-09-17 | CVE-2026-25290 CVE-2026-25290 | Qualcomm | high 7.8 | Qualcomm Snapdragon: memory corruption | https://docs.qualcomm.com/product/publicresources/securitybulletin/september-2026-bulletin.html 2026-09-17 | CVE-2026-25294 CVE-2026-25294 | Qualcomm | high 7.4 | Transient DOS while parsing frame during channel usage | https://docs.qualcomm.com/product/publicresources/securitybulletin/september-2026-bulletin.html 2026-09-17 | CVE-2026-24075 CVE-2026-24075 | Qualcomm | high 7.8 | Qualcomm Snapdragon: memory corruption | https://docs.qualcomm.com/product/publicresources/securitybulletin/september-2026-bulletin.html 2026-09-17 | CVE-2026-24081 CVE-2026-24081 | Qualcomm | high 7.4 | Transient DOS when processing a channel map with insufficient used channels and... | https://docs.qualcomm.com/product/publicresources/securitybulletin/september-2026-bulletin.html 2026-09-17 | CVE-2026-25261 CVE-2026-25261 | Qualcomm | medium 6.7 | Qualcomm Snapdragon: memory corruption | https://docs.qualcomm.com/product/publicresources/securitybulletin/september-2026-bulletin.html 2026-09-17 | CVE-2026-25275 CVE-2026-25275 | Qualcomm | high 7.5 | Transient DOS when processing authentication frames with invalid FILS... | https://docs.qualcomm.com/product/publicresources/securitybulletin/september-2026-bulletin.html 2026-09-17 | CVE-2026-25278 CVE-2026-25278 | Qualcomm | high 7.8 | Qualcomm Snapdragon: memory corruption | https://docs.qualcomm.com/product/publicresources/securitybulletin/september-2026-bulletin.html 2026-09-17 | CVE-2026-25280 CVE-2026-25280 | Qualcomm | high 7.8 | Qualcomm Snapdragon: memory corruption | https://docs.qualcomm.com/product/publicresources/securitybulletin/september-2026-bulletin.html 2026-09-17 | CVE-2026-24073 CVE-2026-24073 | Qualcomm | high 7.8 | Qualcomm Snapdragon: memory corruption | https://docs.qualcomm.com/product/publicresources/securitybulletin/september-2026-bulletin.html 2026-09-17 | CVE-2026-24074 CVE-2026-24074 | Qualcomm | high 7.8 | Qualcomm Snapdragon: memory corruption | https://docs.qualcomm.com/product/publicresources/securitybulletin/september-2026-bulletin.html 2026-09-17 | CVE-2025-59607 CVE-2025-59607 | Qualcomm | high 7.8 | Qualcomm Snapdragon: memory corruption | https://docs.qualcomm.com/product/publicresources/securitybulletin/september-2026-bulletin.html 2026-09-17 | CVE-2026-92839 CVE-2026-92839 | Canva | medium 4.3 | Canva Desktop before v1.125.0 performed double decoding in the deeplink handler | https://trust.canva.com/?tcuUid=d98fa5aa-50ac-4e45-8fec-2c8d07f2b9b6 2026-09-17 | CVE-2026-81546 CVE-2026-81546 | Canva | high 7.7 | Canva Affinity: stack buffer overflow | https://trust.canva.com?tcuUid=43596908-8a36-4a18-b2e7-5c99b67ab38a 2026-09-16 | GHSA-hcwq-8wjf-3gcr CVE-2026-57173 | vLLM | medium 6.5 | vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions | https://github.com/advisories/GHSA-hcwq-8wjf-3gcr 2026-09-16 | GHSA-5h8j-6crg-7rmw CVE-2025-59953 | LMDeploy | critical 9.8 | LMDeploy: remote code execution | https://github.com/advisories/GHSA-5h8j-6crg-7rmw 2026-09-16 | CVE-2026-85469 CVE-2026-85469 | Red Hat | high 8.0 | Red Hat Quay 3: attacker could inject arbitrary code | https://access.redhat.com/security/cve/CVE-2026-85469 2026-09-16 | CVE-2026-76449 CVE-2026-76449 | Cisco | medium 4.9 | Cisco ISE Passive Identity Connector: SQL injection | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multisql-inject-JnHK54Rq 2026-09-16 | CVE-2026-76450 CVE-2026-76450 | Cisco | medium 4.9 | Cisco ISE Passive Identity: authenticated, remote attacker could conduct an SQL... | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multisql-inject-JnHK54Rq 2026-09-16 | CVE-2026-76451 CVE-2026-76451 | Cisco | medium 4.9 | Cisco ISE Passive Identity: authenticated, remote attacker could conduct an SQL... | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multisql-inject-JnHK54Rq 2026-09-16 | CVE-2026-76460 CVE-2026-76460 | Cisco | critical 10.0 | Cisco ISE Passive Identity Connector: authentication bypass | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5 2026-09-16 | CVE-2026-76446 CVE-2026-76446 | Cisco | medium 4.9 | Cisco ISE Passive Identity Connector: XML external entity | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multiauth-bypass-sgD2HbL4 2026-09-16 | CVE-2026-76447 CVE-2026-76447 | Cisco | medium 5.3 | Cisco ISE Passive Identity Connector: missing authentication | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multiauth-bypass-sgD2HbL4 2026-09-16 | CVE-2026-76448 CVE-2026-76448 | Cisco | medium 4.9 | Cisco ISE Passive Identity Connector: SQL injection | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multisql-inject-JnHK54Rq 2026-09-16 | CVE-2026-76439 CVE-2026-76439 | Cisco | medium 5.3 | Cisco ISE Passive Identity Connector: missing authentication | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multiauth-bypass-sgD2HbL4 2026-09-16 | CVE-2026-76444 CVE-2026-76444 | Cisco | medium 5.3 | Cisco ISE Passive Identity Connector: missing authentication | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multiauth-bypass-sgD2HbL4 2026-09-16 | CVE-2026-76433 CVE-2026-76433 | Cisco | medium 5.3 | Cisco ISE Passive Identity Connector: path traversal | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-traversal-WDTgYCdn 2026-09-16 | CVE-2026-76434 CVE-2026-76434 | Cisco | medium 4.9 | Cisco ISE Passive Identity Connector: information disclosure | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-traversal-WDTgYCdn 2026-09-16 | CVE-2026-76438 CVE-2026-76438 | Cisco | medium 6.5 | Cisco BroadWorks: missing authorization | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-auth-bypass-broadwor-57m9dmm5 2026-09-16 | CVE-2026-76425 CVE-2026-76425 | Cisco | high 7.6 | Cisco Identity Services Engine Software: SQL injection | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-hrP9jQSQ 2026-09-16 | CVE-2026-76426 CVE-2026-76426 | Cisco | medium 4.9 | Cisco ISE: SQL injection | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-hrP9jQSQ 2026-09-16 | CVE-2026-76427 CVE-2026-76427 | Cisco | medium 4.9 | Cisco ISE Passive Identity Connector: XML external entity | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-hrP9jQSQ 2026-09-16 | CVE-2026-76428 CVE-2026-76428 | Cisco | medium 4.9 | Cisco ISE: SQL injection | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-hrP9jQSQ 2026-09-16 | CVE-2026-76431 CVE-2026-76431 | Cisco | medium 4.9 | Cisco ISE Passive Identity Connector: path traversal | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-traversal-WDTgYCdn 2026-09-16 | CVE-2026-76432 CVE-2026-76432 | Cisco | medium 4.9 | Cisco ISE Passive Identity Connector: path traversal | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-traversal-WDTgYCdn 2026-09-16 | CVE-2026-76409 CVE-2026-76409 | Cisco | high 8.8 | Cisco Nexus Dashboard: path traversal | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-ndw1-psFvnrg 2026-09-16 | CVE-2026-76412 CVE-2026-76412 | Cisco | high 8.5 | Cisco Secure Firewall Management Center (FMC): privilege escalation | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc2-multivulns-HXgcqRG 2026-09-16 | CVE-2026-76413 CVE-2026-76413 | Cisco | high 8.2 | A vulnerability in Cisco Adaptive Security Device Manager | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc2-multivulns-HXgcqRG 2026-09-16 | CVE-2026-76424 CVE-2026-76424 | Cisco | high 7.2 | Cisco Identity Services Engine Software: remote code execution | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-hrP9jQSQ 2026-09-16 | CVE-2026-20350 CVE-2026-20350 | Cisco | medium 4.7 | Cisco ThousandEyes Enterprise Agent: command injection | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-teva-os-command-W4GAO6jp 2026-09-16 | CVE-2026-20352 CVE-2026-20352 | Cisco | high 8.6 | Cisco Identity Services Engine Software: denial of service | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-RADIUS-dos-wR3hYPMw 2026-09-16 | CVE-2026-20360 CVE-2026-20360 | Cisco | high 8.8 | Cisco Nexus Dashboard: information disclosure | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-ndw1-psFvnrg 2026-09-16 | CVE-2026-20335 CVE-2026-20335 | Cisco | high 8.1 | As part of Cisco's ongoing commitment to proactive security and product quality | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-asaftdfmc-uvpPROhN 2026-09-16 | CVE-2026-20336 CVE-2026-20336 | Cisco | high 8.8 | As part of Cisco's ongoing commitment to proactive security and product quality | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-asaftdfmc-uvpPROhN 2026-09-16 | CVE-2026-20340 CVE-2026-20340 | Cisco | high 8.8 | Cisco Secure Firewall Management Center (FMC): remote code execution | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-mulivulns-4PsnFwvx 2026-09-16 | CVE-2026-20342 CVE-2026-20342 | Cisco | high 7.7 | Cisco Secure Firewall Management Center (FMC): insecure direct object reference | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-mulivulns-4PsnFwvx 2026-09-16 | CVE-2026-20343 CVE-2026-20343 | Cisco | high 7.5 | Cisco Secure Firewall Management Center (FMC): denial of service | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-mulivulns-4PsnFwvx 2026-09-16 | CVE-2026-20344 CVE-2026-20344 | Cisco | high 8.8 | Cisco Secure Firewall Management Center (FMC): SQL injection | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-mulivulns-4PsnFwvx 2026-09-16 | CVE-2026-20309 CVE-2026-20309 | Cisco | medium 6.1 | Cisco Identity Services Engine Software: cross-site scripting | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-xss-Uz9VWRQ 2026-09-16 | CVE-2026-20323 CVE-2026-20323 | Cisco | high 8.3 | Cisco Secure Firewall: improper certificate validation | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmcftd-sftun-multivulns-WGVHOrN3 2026-09-16 | CVE-2026-20332 CVE-2026-20332 | Cisco | critical 9.9 | Cisco Secure Firewall: improper access control | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-asaftdfmc-uvpPROhN 2026-09-16 | CVE-2026-20333 CVE-2026-20333 | Cisco | high 8.8 | Cisco Secure Firewall: incorrect comparison | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-asaftdfmc-uvpPROhN 2026-09-16 | CVE-2026-20334 CVE-2026-20334 | Cisco | high 8.4 | As part of Cisco's ongoing commitment to proactive security and product quality | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-asaftdfmc-uvpPROhN 2026-09-16 | CVE-2026-20284 CVE-2026-20284 | Cisco | critical 9.1 | Cisco Identity Services Engine Software: SQL injection | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-mult-vul-ymSsTLCc 2026-09-16 | CVE-2026-20285 CVE-2026-20285 | Cisco | medium 4.3 | Cisco ISE Passive Identity Connector: improper authorization | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-auth-bypass-1-MxcTNgwx 2026-09-16 | CVE-2026-20286 CVE-2026-20286 | Cisco | medium 4.3 | Cisco Identity Services Engine Software: improper authorization | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-auth-bypass-1-MxcTNgwx 2026-09-16 | CVE-2026-20287 CVE-2026-20287 | Cisco | medium 6.5 | Cisco ISE Passive Identity Connector: improper privilege management | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-ise-XU5EwX5T 2026-09-16 | CVE-2026-20290 CVE-2026-20290 | Cisco | medium 5.8 | Cisco Secure Firewall Threat Defense (FTD) Software: denial of service | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-snort2-ssldos-Mw7WYX9c 2026-09-16 | CVE-2026-20295 CVE-2026-20295 | Cisco | high 8.6 | Cisco Secure Firewall: denial of service | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmcftd-sftun-multivulns-WGVHOrN3 2026-09-16 | CVE-2026-20300 CVE-2026-20300 | Cisco | high 7.1 | Cisco Identity Services Engine Software: SQL injection | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-sql-inj-3QTKR947 2026-09-16 | CVE-2026-20235 CVE-2026-20235 | Cisco | medium 4.9 | Cisco Identity Services Engine Software: information disclosure | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-inf-disc-LFWvcCu 2026-09-16 | CVE-2026-20247 CVE-2026-20247 | Cisco | high 7.5 | Cisco Identity Services Engine Software: SQL injection | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-sql-inj-3QTKR947 2026-09-16 | CVE-2026-20248 CVE-2026-20248 | Cisco | medium 6.8 | Cisco Secure Firewall: denial of service | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-tcpdns-dos-p6dUnjr5 2026-09-16 | CVE-2026-20249 CVE-2026-20249 | Cisco | high 8.6 | Cisco Secure Firewall: denial of service | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ikev2cert-dos-uWyc2xtv 2026-09-16 | CVE-2026-20250 CVE-2026-20250 | Cisco | high 8.6 | Cisco Secure Firewall: denial of service | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-dtls-dos-Kp57HkyO 2026-09-16 | CVE-2026-20282 CVE-2026-20282 | Cisco | medium 4.9 | Cisco Identity Services Engine: authenticated, remote attacker could obtain... | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-mult-vul-ymSsTLCc 2026-09-16 | CVE-2026-20283 CVE-2026-20283 | Cisco | medium 6.5 | Cisco Identity Services Engine Software: remote code execution | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-mult-vul-ymSsTLCc 2026-09-16 | CVE-2026-20071 CVE-2026-20071 | Cisco | low 3.8 | Cisco Identity Services Engine Software: spoofing | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-vuln-kWLeNnRD 2026-09-16 | CVE-2026-20072 CVE-2026-20072 | Cisco | medium 4.9 | Cisco Identity Services Engine Software: information disclosure | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-vuln-kWLeNnRD 2026-09-16 | CVE-2026-20120 CVE-2026-20120 | Cisco | medium 5.8 | Cisco Secure Firewall: improper access control | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-acl-bypass-8p6vFvw 2026-09-16 | CVE-2026-20121 CVE-2026-20121 | Cisco | medium 5.3 | Cisco Secure Firewall: improper access control | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-acl-bypass-8p6vFvw 2026-09-16 | CVE-2026-20135 CVE-2026-20135 | Cisco | high 8.6 | Cisco Secure Firewall Threat Defense (FTD) Software: denial of service | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-tls1.3-dos-dLxwFWgF 2026-09-16 | CVE-2026-20154 CVE-2026-20154 | Cisco | high 8.6 | Cisco Secure Firewall: denial of service | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-ftd-logging-dos-ZXXNesfN 2026-09-16 | CVE-2026-20222 CVE-2026-20222 | Cisco | high 7.4 | Cisco Secure Firewall: denial of service | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-eigrp-dos-GOhNejSj 2026-09-16 | CVE-2026-89082 CVE-2026-89082 | HP Inc. | critical 9.3 | HP AC Print & Scan: privilege escalation | https://support.hp.com/us-en/document/ish_15646496-15646518-16/hpsbpi04149 2026-09-16 | CVE-2026-89083 CVE-2026-89083 | HP Inc. | critical 9.3 | HP AC Print & Scan: privilege escalation | https://support.hp.com/us-en/document/ish_15646496-15646518-16/hpsbpi04149 2026-09-16 | CVE-2026-89084 CVE-2026-89084 | HP Inc. | high 8.8 | HP AC Print & Scan: privilege escalation | https://support.hp.com/us-en/document/ish_15646496-15646518-16/hpsbpi04149 2026-09-16 | CVE-2026-76423 CVE-2026-76423 | Cisco | critical 10.0 | Cisco ISE: authentication bypass by spoofing | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-hrP9jQSQ 2026-09-16 | CVE-2026-20341 CVE-2026-20341 | Cisco | critical 9.1 | Cisco Secure Firewall Management Center (FMC): unsafe deserialization | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-mulivulns-4PsnFwvx 2026-09-16 | CVE-2026-20361 CVE-2026-20361 | Cisco | high 8.8 | Cisco Nexus Dashboard: SQL injection | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-ndw1-psFvnrg 2026-09-16 | CVE-2026-20322 CVE-2026-20322 | Cisco | critical 9.9 | Cisco Nexus Dashboard: improper access control | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-ndw1-psFvnrg 2026-09-16 | CVE-2026-20324 CVE-2026-20324 | Cisco | critical 9.9 | Cisco Secure Firewall Management Center (FMC): remote code execution | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-sftunn-codex-c3O4Jft2 2026-09-16 | CVE-2026-20325 CVE-2026-20325 | Cisco | critical 9.9 | Cisco Nexus Dashboard: command injection | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-ndw1-psFvnrg 2026-09-16 | CVE-2026-20326 CVE-2026-20326 | Cisco | critical 9.8 | Cisco Nexus Dashboard: missing authentication | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-ndw1-psFvnrg 2026-09-16 | CVE-2026-20329 CVE-2026-20329 | Cisco | critical 9.9 | Cisco Secure Firewall: unhandled exceptional condition | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-asaftdfmc-uvpPROhN 2026-09-16 | CVE-2026-20330 CVE-2026-20330 | Cisco | critical 9.9 | As part of Cisco's ongoing commitment to proactive security and product quality | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-asaftdfmc-uvpPROhN 2026-09-16 | CVE-2026-20194 CVE-2026-20194 | Cisco | critical 9.1 | Cisco ISE Passive Identity Connector: incorrect resource transfer | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-ise-XU5EwX5T 2026-09-16 | CVE-2026-20211 CVE-2026-20211 | Cisco | critical 9.1 | Cisco Identity Services Engine Software: remote code execution | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-se7bYU57 2026-09-16 | CVE-2026-20237 CVE-2026-20237 | Cisco | critical 9.1 | Cisco ISE Passive Identity Connector: improper input validation | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-ise-XU5EwX5T 2026-09-16 | CVE-2026-20242 CVE-2026-20242 | Cisco | critical 9.8 | Cisco Secure Firewall Management Center (FMC): remote code execution | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-javarce-y2NypXwk 2026-09-16 | CVE-2026-20130 CVE-2026-20130 | Cisco | critical 10.0 | Cisco ISE Passive Identity Connector: injection | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-ise-XU5EwX5T 2026-09-16 | CVE-2026-20176 CVE-2026-20176 | Cisco | critical 9.1 | Cisco Identity Services Engine Software: remote code execution | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-se7bYU57 2026-09-16 | CVE-2026-20192 CVE-2026-20192 | Cisco | critical 10.0 | Cisco ISE Passive Identity Connector: improper access control | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-ise-XU5EwX5T 2026-09-16 | CVE-2026-91102 CVE-2026-91102 | HP Inc. | high 8.4 | HP Linux Imaging and Printing Software (HPLIP): remote code execution | https://support.hp.com/us-en/document/ish_15646959-15646984-16/hpsbpi04151 2026-09-16 | CVE-2026-91103 CVE-2026-91103 | HP Inc. | medium 5.1 | HP Linux Imaging and Printing Software (HPLIP): remote code execution | https://support.hp.com/us-en/document/ish_15646959-15646984-16/hpsbpi04151 2026-09-16 | CVE-2026-91104 CVE-2026-91104 | HP Inc. | critical 9.3 | HP Linux Imaging and Printing Software (HPLIP): remote code execution | https://support.hp.com/us-en/document/ish_15646959-15646984-16/hpsbpi04151 2026-09-16 | CVE-2026-91105 CVE-2026-91105 | HP Inc. | high 8.6 | HP Linux Imaging and Printing Software (HPLIP): remote code execution | https://support.hp.com/us-en/document/ish_15646959-15646984-16/hpsbpi04151 2026-09-16 | CVE-2026-91106 CVE-2026-91106 | HP Inc. | critical 9.3 | HP Linux Imaging and Printing Software (HPLIP): remote code execution | https://support.hp.com/us-en/document/ish_15646959-15646984-16/hpsbpi04151 2026-09-16 | CVE-2026-91097 CVE-2026-91097 | HP Inc. | high 7.0 | HP Linux Imaging and Printing Software (HPLIP): remote code execution | https://support.hp.com/us-en/document/ish_15646959-15646984-16/hpsbpi04151 2026-09-16 | CVE-2026-91098 CVE-2026-91098 | HP Inc. | high 8.6 | HP Linux Imaging and Printing Software (HPLIP): remote code execution | https://support.hp.com/us-en/document/ish_15646959-15646984-16/hpsbpi04151 2026-09-16 | CVE-2026-91099 CVE-2026-91099 | HP Inc. | medium 5.1 | HP Linux Imaging and Printing Software (HPLIP): remote code execution | https://support.hp.com/us-en/document/ish_15646959-15646984-16/hpsbpi04151 2026-09-16 | CVE-2026-91100 CVE-2026-91100 | HP Inc. | medium 6.8 | HP Linux Imaging and Printing Software (HPLIP): remote code execution | https://support.hp.com/us-en/document/ish_15646959-15646984-16/hpsbpi04151 2026-09-16 | CVE-2026-91101 CVE-2026-91101 | HP Inc. | medium 5.1 | HP Linux Imaging and Printing Software (HPLIP): remote code execution | https://support.hp.com/us-en/document/ish_15646959-15646984-16/hpsbpi04151 2026-09-16 | CVE-2026-73456 CVE-2026-73456 | Arista Networks | critical 9.2 | Arista Networks EOS: remote code execution | https://www.arista.com/en/support/advisories-notices/security-advisory/24714-security-advisory-0158 2026-09-16 | CVE-2026-73457 CVE-2026-73457 | Arista Networks | medium 6.0 | Arista Networks EOS: secrets in logs | https://www.arista.com/en/support/advisories-notices/security-advisory/24714-security-advisory-0158 2026-09-16 | CVE-2026-73462 CVE-2026-73462 | Arista Networks | high 7.1 | Arista Networks EOS: out-of-bounds read | https://www.arista.com/en/support/advisories-notices/security-advisory/24715-security-advisory-0159 2026-09-16 | CVE-2026-73442 CVE-2026-73442 | Arista Networks | low 2.1 | Arista Networks EOS: secrets in logs | https://www.arista.com/en/support/advisories-notices/security-advisory/24713-security-advisory-0157 2026-09-16 | CVE-2026-73443 CVE-2026-73443 | Arista Networks | medium 5.3 | Arista Networks EOS: denial of service | https://www.arista.com/en/support/advisories-notices/security-advisory/24713-security-advisory-0157 2026-09-16 | CVE-2026-84397 CVE-2026-84397 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-16 | CVE-2026-86358 CVE-2026-86358 | Dell Technologies | medium 6.5 | Dell Technologies Update Package Framework: stack buffer overflow | https://www.dell.com/support/kbdoc/en-us/000509455/dsa-2026-417-security-update-for-dell-update-package-dup-framework-vulnerabilities 2026-09-16 | CVE-2026-86359 CVE-2026-86359 | Dell Technologies | high 8.5 | Dell Technologies Repository Manager: insecure permissions | https://www.dell.com/support/kbdoc/en-us/000509459/dsa-2026-419-security-update-for-dell-repository-manager-drm-vulnerability 2026-09-16 | CVE-2026-76420 CVE-2026-76420 | Cisco | critical 9.0 | Cisco Secure Firewall Management Center (FMC): remote code execution | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc2-multivulns-HXgcqRG 2026-09-16 | CVE-2026-71180 CVE-2026-71180 | Dell Technologies | high 8.2 | Dell Update Package Framework | https://www.dell.com/support/kbdoc/en-us/000509455/dsa-2026-417-security-update-for-dell-update-package-dup-framework-vulnerabilities 2026-09-16 | CVE-2026-71181 CVE-2026-71181 | Dell Technologies | low 3.0 | Dell Technologies Update Package Framework: link following | https://www.dell.com/support/kbdoc/en-us/000509455/dsa-2026-417-security-update-for-dell-update-package-dup-framework-vulnerabilities 2026-09-16 | CVE-2026-71182 CVE-2026-71182 | Dell Technologies | low 3.0 | Dell Technologies Update Package Framework: link following | https://www.dell.com/support/kbdoc/en-us/000509455/dsa-2026-417-security-update-for-dell-update-package-dup-framework-vulnerabilities 2026-09-16 | CVE-2026-71179 CVE-2026-71179 | Dell Technologies | high 7.3 | Dell Technologies Update Package Framework: command injection | https://www.dell.com/support/kbdoc/en-us/000509455/dsa-2026-417-security-update-for-dell-update-package-dup-framework-vulnerabilities 2026-09-16 | CVE-2026-42784 CVE-2026-42784 | Red Hat | high 7.4 | Red Hat sequoia-openpgp. The: improper signature check | https://access.redhat.com/errata/RHSA-2026:42902 2026-09-16 | CVE-2026-20331 CVE-2026-20331 | Cisco | critical 9.6 | Cisco Secure Firewall: protection mechanism failure | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-asaftdfmc-uvpPROhN 2026-09-16 | CVE-2026-20234 CVE-2026-20234 | Cisco | critical 9.9 | Cisco ISE Passive Identity Connector: weakly protected credentials | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-ise-XU5EwX5T 2026-09-16 | CVE-2026-20305 CVE-2026-20305 | Cisco | critical 9.1 | Cisco ISE Passive Identity Connector: command injection | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-cmd-inj-e2CuZCYZ 2026-09-16 | CVE-2026-20306 CVE-2026-20306 | Cisco | critical 9.1 | Cisco ISE: command injection | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-cmd-inj-e2CuZCYZ 2026-09-16 | CVE-2026-20307 CVE-2026-20307 | Cisco | critical 9.9 | Cisco Identity Services Engine Software: remote code execution | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-se7bYU57 2026-09-16 | CVE-2026-92615 CVE-2026-92615 | Red Hat | medium 6.6 | Red Hat flightctl: race condition | https://access.redhat.com/security/cve/CVE-2026-92615 2026-09-16 | CVE-2026-92625 CVE-2026-92625 | Tenable | high 7.5 | Tenable iDSecure: denial of service | https://www.tenable.com/security/research/tra-2026-56 2026-09-16 | CVE-2026-92626 CVE-2026-92626 | Tenable | high 7.5 | Tenable iDSecure: denial of service | https://www.tenable.com/security/research/tra-2026-56 2026-09-16 | CVE-2026-76104 CVE-2026-76104 | Dell Technologies | medium 5.5 | Dell Technologies ObjectScale: insecure permissions | https://www.dell.com/support/kbdoc/en-in/000505935/dsa-2026-393-security-update-for-dell-objectscale-multiple-vulnerabilities 2026-09-16 | CVE-2026-70416 CVE-2026-70416 | Dell Technologies | critical 10.0 | Dell Technologies ObjectScale: unsafe deserialization | https://www.dell.com/support/kbdoc/en-in/000505935/dsa-2026-393-security-update-for-dell-objectscale-multiple-vulnerabilities 2026-09-16 | CVE-2026-26947 CVE-2026-26947 | Dell Technologies | medium 6.7 | Dell Technologies ECS: improper privilege management | https://www.dell.com/support/kbdoc/en-in/000505935/dsa-2026-393-security-update-for-dell-objectscale-multiple-vulnerabilities 2026-09-16 | CVE-2026-19607 CVE-2026-19607 | Red Hat | medium 5.3 | Red Hat first-broker-login flow: improper authentication | https://access.redhat.com/errata/RHSA-2026:68276 2026-09-16 | CVE-2026-17526 CVE-2026-17526 | Red Hat | high 7.2 | Red Hat Data Grid 8: missing authorization | https://access.redhat.com/errata/RHSA-2026:68276 2026-09-16 | CVE-2025-43936 CVE-2025-43936 | Dell Technologies | high 8.1 | Dell Technologies ObjectScale: improper authentication | https://www.dell.com/support/kbdoc/en-in/000505935/dsa-2026-393-security-update-for-dell-objectscale-multiple-vulnerabilities 2026-09-16 | CVE-2026-84858 CVE-2026-84858 | Tenable | high 8.8 | Tenable Scada-LTS: remote code execution | https://www.tenable.com/security/research/tra-2026-60 2026-09-16 | CVE-2026-84859 CVE-2026-84859 | Tenable | medium 6.5 | Tenable Scada-LTS: SQL injection | https://www.tenable.com/security/research/tra-2026-60 2026-09-16 | CVE-2026-84860 CVE-2026-84860 | Tenable | high 8.8 | Tenable Scada-LTS: improper access control | https://www.tenable.com/security/research/tra-2026-60 2026-09-16 | CVE-2026-79651 CVE-2026-79651 | Red Hat | high 7.5 | Red Hat build of Keycloak: resource exhaustion | https://access.redhat.com/errata/RHSA-2026:68276 2026-09-16 | CVE-2026-74909 CVE-2026-74909 | Red Hat | high 8.1 | Red Hat Single Sign-On 7: path traversal | https://access.redhat.com/errata/RHSA-2026:68276 2026-09-16 | CVE-2026-18212 CVE-2026-18212 | Red Hat | high 7.5 | SAML Redirect Binding implementation of Keycloak: denial of service | https://access.redhat.com/errata/RHSA-2026:68276 2026-09-16 | CVE-2025-36591 CVE-2025-36591 | Dell Technologies | medium 4.4 | Dell Technologies Elastic Cloud Storage (ECS): weak cryptography | https://www.dell.com/support/kbdoc/en-in/000505935/dsa-2026-393-security-update-for-dell-objectscale-multiple-vulnerabilities 2026-09-16 | CVE-2026-91843 CVE-2026-91843 | Check Point | critical 9.8 | Check Point Quantum Security Management: stack buffer overflow | https://support.checkpoint.com/results/sk/sk1000155 2026-09-16 | AWS-2026-113 CVE-2026-86831 | AWS | high 8.7 | Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS | https://aws.amazon.com/security/security-bulletins/rss/2026-113-aws/ 2026-09-16 | CVE-2026-86106 CVE-2026-86106 | Arista Networks | high 8.7 | Arista Networks VeloCloud Edge: missing authentication | https://www.arista.com/en/support/advisories-notices/security-advisory/24735-security-advisory-0179 2026-09-16 | CVE-2026-86107 CVE-2026-86107 | Arista Networks | high 8.2 | Arista Networks VeloCloud: out-of-bounds write | https://www.arista.com/en/support/advisories-notices/security-advisory/24736-security-advisory-0180 2026-09-16 | CVE-2026-77190 CVE-2026-77190 | Arista Networks | medium 6.0 | Arista Networks EOS: denial of service | https://www.arista.com/en/support/advisories-notices/security-advisory/24733-security-advisory-0177 2026-09-16 | CVE-2026-73453 CVE-2026-73453 | Arista Networks | critical 9.5 | Arista Networks EOS: remote code execution | https://www.arista.com/en/support/advisories-notices/security-advisory/24730-security-advisory-0174 2026-09-16 | CVE-2026-73455 CVE-2026-73455 | Arista Networks | high 8.9 | On affected platforms running Arista EOS with Open Shortest Path First version... | https://www.arista.com/en/support/advisories-notices/security-advisory/24729-security-advisory-0173 2026-09-16 | CVE-2026-73468 CVE-2026-73468 | Arista Networks | high 7.1 | Arista Networks EOS: incorrect control flow | https://www.arista.com/en/support/advisories-notices/security-advisory/24731-security-advisory-0175 2026-09-16 | CVE-2026-73469 CVE-2026-73469 | Arista Networks | medium 6.9 | Arista Networks EOS: improper authorization | https://www.arista.com/en/support/advisories-notices/security-advisory/24732-security-advisory-0176 2026-09-16 | CVE-2026-76151 CVE-2026-76151 | Qt Group Plc | medium 4.6 | qt: out-of-bounds read | https://codereview.qt-project.org/c/qt/qtbase/+/752129 2026-09-16 | CVE-2026-73435 CVE-2026-73435 | Arista Networks | high 7.0 | Arista Networks EOS: insufficient authenticity check | https://www.arista.com/en/support/advisories-notices/security-advisory/24727-security-advisory-0171 2026-09-16 | CVE-2026-73436 CVE-2026-73436 | Arista Networks | medium 6.0 | Arista Networks EOS: out-of-bounds read | https://www.arista.com/en/support/advisories-notices/security-advisory/24727-security-advisory-0171 2026-09-16 | CVE-2026-73438 CVE-2026-73438 | Arista Networks | high 7.0 | Arista Networks EOS: reachable assertion | https://www.arista.com/en/support/advisories-notices/security-advisory/24728-security-advisory-0172 2026-09-16 | CVE-2026-73440 CVE-2026-73440 | Arista Networks | low 2.3 | Arista Networks EOS: information disclosure | https://www.arista.com/en/support/advisories-notices/security-advisory/24734-security-advisory-0178 2026-09-16 | CVE-2026-19640 CVE-2026-19640 | Arista Networks | low 2.3 | Arista Networks EOS: improper authorization | https://www.arista.com/en/support/advisories-notices/security-advisory/24726-security-advisory-0170 2026-09-16 | CVE-2026-73454 CVE-2026-73454 | Arista Networks | high 8.6 | Arista Networks EOS: command injection | https://www.arista.com/en/support/advisories-notices/security-advisory/24721-security-advisory-0165 2026-09-16 | CVE-2026-73461 CVE-2026-73461 | Arista Networks | critical 9.4 | On affected EOS platforms with AAA-based gRPC authorization enabled for... | https://www.arista.com/en/support/advisories-notices/security-advisory/24719-security-advisory-0163 2026-09-16 | CVE-2026-73463 CVE-2026-73463 | Arista Networks | medium 6.0 | Arista Networks EOS: race condition | https://www.arista.com/en/support/advisories-notices/security-advisory/24725-security-advisory-0169 2026-09-16 | CVE-2026-73464 CVE-2026-73464 | Arista Networks | high 8.7 | Arista Networks EOS: remote code execution | https://www.arista.com/en/support/advisories-notices/security-advisory/24722-security-advisory-0166 2026-09-16 | CVE-2026-2380 CVE-2026-2380 | Arista Networks | medium 5.1 | Arista Networks EOS: information disclosure | https://www.arista.com/en/support/advisories-notices/security-advisory/24724-security-advisory-0168 2026-09-16 | CVE-2026-73439 CVE-2026-73439 | Arista Networks | high 7.7 | On affected platforms running Arista EOS | https://www.arista.com/en/support/advisories-notices/security-advisory/24720-security-advisory-0164 2026-09-16 | CVE-2026-73445 CVE-2026-73445 | Arista Networks | medium 6.9 | Arista Networks EOS: improper input validation | https://www.arista.com/en/support/advisories-notices/security-advisory/24723-security-advisory-0167 2026-09-16 | CVE-2026-86341 CVE-2026-86341 | GitLab | medium 4.4 | GitLab: improper access control | https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/ 2026-09-16 | CVE-2026-89207 CVE-2026-89207 | Siemens | medium 6.9 | Siemens WTV676-HB6035 Web Interface: unauthenticated remote attacker could... | https://cert-portal.siemens.com/productcert/html/ssa-823812.html 2026-09-16 | CVE-2026-92091 CVE-2026-92091 | Red Hat | medium 5.9 | Red Hat Ansible Automation Platform 2: resource exhaustion | https://access.redhat.com/security/cve/CVE-2026-92091 2026-09-16 | CVE-2026-73447 CVE-2026-73447 | Arista Networks | critical 9.4 | Arista Networks EOS: code execution | https://www.arista.com/en/support/advisories-notices/security-advisory/24718-security-advisory-0162 2026-09-16 | CVE-2026-7514 CVE-2026-7514 | GitLab | medium 4.3 | GitLab: improper authorization | https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/ 2026-09-16 | CVE-2026-78252 CVE-2026-78252 | GitLab | high 8.2 | GitLab: cross-site scripting | https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/ 2026-09-16 | CVE-2026-79708 CVE-2026-79708 | GitLab | high 8.5 | GitLab: improper authorization | https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/ 2026-09-16 | CVE-2026-8030 CVE-2026-8030 | GitLab | medium 4.3 | GitLab: missing authorization | https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/ 2026-09-16 | CVE-2026-1168 CVE-2026-1168 | GitLab | high 7.5 | GitLab: denial of service | https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/ 2026-09-16 | CVE-2026-19619 CVE-2026-19619 | GitLab | medium 4.7 | GitLab: cross-site scripting | https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/ 2026-09-16 | CVE-2026-3855 CVE-2026-3855 | GitLab | low 3.1 | GitLab: denial of service | https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/ 2026-09-16 | CVE-2025-14871 CVE-2025-14871 | GitLab | high 7.5 | GitLab: denial of service | https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/ 2026-09-16 | CVE-2026-16794 CVE-2026-16794 | GitLab | medium 4.3 | GitLab: improper authorization | https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/ 2026-09-16 | CVE-2026-19248 CVE-2026-19248 | Qt Group Plc | high 7.1 | qt: denial of service | https://codereview.qt-project.org/c/qt/qtbase/+/740427 2026-09-16 | CVE-2024-11222 CVE-2024-11222 | GitLab | medium 6.4 | GitLab: race condition | https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/ 2026-09-16 | CVE-2026-92358 CVE-2026-92358 | Red Hat | medium 6.4 | Red Hat first broker login flow of Keycloak.: insufficient session expiration | https://access.redhat.com/security/cve/CVE-2026-92358 2026-09-16 | CVE-2026-86108 CVE-2026-86108 | Arista Networks | high 7.5 | Arista Networks VeloCloud Edge: command injection | https://www.arista.com/zh/support/advisories-notices/security-advisory/24737-security-advisory-0181 2026-09-16 | CVE-2026-86109 CVE-2026-86109 | Arista Networks | high 7.5 | Arista Networks VeloCloud Edge: improper signature check | https://www.arista.com/zh/support/advisories-notices/security-advisory/24738-security-advisory-0182 2026-09-16 | CVE-2026-73450 CVE-2026-73450 | Arista Networks | high 7.0 | Arista Networks EOS: insufficient authenticity check | https://www.arista.com/en/support/advisories-notices/security-advisory/24717-security-advisory-0161 2026-09-16 | CVE-2026-73446 CVE-2026-73446 | Arista Networks | high 7.0 | On affected platforms running Arista EOS with IS-IS configured on a broadcast... | https://www.arista.com/en/support/advisories-notices/security-advisory/24716-security-advisory-0160 2026-09-16 | CVE-2026-73459 CVE-2026-73459 | Arista Networks | high 7.0 | On affected platforms running Arista EOS with IS-IS configured | https://www.arista.com/en/support/advisories-notices/security-advisory/24716-security-advisory-0160 2026-09-16 | CVE-2026-73460 CVE-2026-73460 | Arista Networks | high 7.0 | Arista Networks EOS: improper authorization | https://www.arista.com/en/support/advisories-notices/security-advisory/24716-security-advisory-0160 2026-09-15 | CVE-2026-85893 CVE-2026-85893 | Microsoft | high 8.8 | Microsoft Edge (Chromium-based): use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85893 2026-09-15 | CVE-2026-69486 CVE-2026-69486 | Microsoft | high 8.8 | Microsoft Edge (Chromium-based): heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69486 2026-09-15 | CVE-2025-11395 CVE-2025-11395 | Red Hat | medium 5.5 | Red Hat Podman: insecure permissions | https://access.redhat.com/errata/RHSA-2026:70640 2026-09-15 | CVE-2026-92248 CVE-2026-92248 | Red Hat | high 7.8 | Red Hat file-psd plugin: integer overflow | https://access.redhat.com/security/cve/CVE-2026-92248 2026-09-15 | CVE-2026-92259 CVE-2026-92259 | Samsung | medium 5.5 | Samsung Escargot: integer overflow | https://github.com/Samsung/escargot/pull/1650 2026-09-15 | CVE-2026-83357 CVE-2026-83357 | Oracle | high 8.1 | Oracle GraalVM for JDK: takeover via Compiler | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83368 CVE-2026-83368 | Oracle | high 7.0 | Oracle GraalVM for JDK: data tampering via Compiler | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83408 CVE-2026-83408 | Oracle | high 8.1 | Oracle GraalVM for JDK: takeover via Compiler | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-73437 CVE-2026-73437 | Arista Networks | medium 6.5 | Arista Networks EOS: denial of service | https://www.arista.com/en/support/advisories-notices/security-advisory/24712-security-advisory-0156 2026-09-15 | CVE-2026-73444 CVE-2026-73444 | Arista Networks | medium 5.3 | On affected platforms running Arista EOS with VRRPv2 IP Authentication Header | https://www.arista.com/en/support/advisories-notices/security-advisory/24713-security-advisory-0157 2026-09-15 | CVE-2026-91743 CVE-2026-91743 | Google | high 8.3 | Google Chrome: race condition | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html 2026-09-15 | CVE-2026-91744 CVE-2026-91744 | Google | medium 5.3 | Google Chrome: race condition | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html 2026-09-15 | CVE-2026-91745 CVE-2026-91745 | Google | high 8.8 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html 2026-09-15 | CVE-2026-91746 CVE-2026-91746 | Google | medium 4.3 | Google Chrome: integer overflow | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html 2026-09-15 | CVE-2026-91747 CVE-2026-91747 | Google | low 3.1 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html 2026-09-15 | CVE-2026-91748 CVE-2026-91748 | Google | high 8.3 | Google Chrome: race condition | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html 2026-09-15 | CVE-2026-91749 CVE-2026-91749 | Google | critical 9.6 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html 2026-09-15 | CVE-2026-91735 CVE-2026-91735 | Google | high 8.3 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html 2026-09-15 | CVE-2026-91736 CVE-2026-91736 | Google | high 8.8 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html 2026-09-15 | CVE-2026-91737 CVE-2026-91737 | Google | high 8.8 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html 2026-09-15 | CVE-2026-91738 CVE-2026-91738 | Google | critical 9.6 | Google Chrome: improper input validation | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html 2026-09-15 | CVE-2026-91739 CVE-2026-91739 | Google | medium 4.2 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html 2026-09-15 | CVE-2026-91740 CVE-2026-91740 | Google | medium 4.3 | Google Chrome: uninitialized resource | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html 2026-09-15 | CVE-2026-91741 CVE-2026-91741 | Google | high 8.8 | Google Chrome: type confusion | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html 2026-09-15 | CVE-2026-91742 CVE-2026-91742 | Google | medium 4.8 | Confused deputy in PriceTracking in Google Chrome on on iOS prior to... | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html 2026-09-15 | CVE-2026-91728 CVE-2026-91728 | Google | critical 9.6 | Google Chrome: integer overflow | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html 2026-09-15 | CVE-2026-91729 CVE-2026-91729 | Google | critical 9.6 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html 2026-09-15 | CVE-2026-91730 CVE-2026-91730 | Google | low 3.1 | Google Chrome: incomplete cleanup | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html 2026-09-15 | CVE-2026-91731 CVE-2026-91731 | Google | high 8.8 | Google Chrome: type confusion | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html 2026-09-15 | CVE-2026-91732 CVE-2026-91732 | Google | high 8.1 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html 2026-09-15 | CVE-2026-91733 CVE-2026-91733 | Google | high 8.3 | Google Chrome: unchecked exceptional condition | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html 2026-09-15 | CVE-2026-91734 CVE-2026-91734 | Google | high 7.4 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html 2026-09-15 | CVE-2026-91720 CVE-2026-91720 | Google | medium 4.7 | Google Chrome: uninitialized resource | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html 2026-09-15 | CVE-2026-91721 CVE-2026-91721 | Google | high 8.8 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html 2026-09-15 | CVE-2026-91722 CVE-2026-91722 | Google | high 8.8 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html 2026-09-15 | CVE-2026-91723 CVE-2026-91723 | Google | low 3.1 | Google Chrome: race condition | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html 2026-09-15 | CVE-2026-91724 CVE-2026-91724 | Google | high 8.3 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html 2026-09-15 | CVE-2026-91725 CVE-2026-91725 | Google | medium 5.3 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html 2026-09-15 | CVE-2026-91726 CVE-2026-91726 | Google | medium 4.7 | Google Chrome: out-of-bounds read | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html 2026-09-15 | CVE-2026-91727 CVE-2026-91727 | Google | high 8.1 | Google Chrome: code execution | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html 2026-09-15 | CVE-2026-91712 CVE-2026-91712 | Google | high 8.3 | Google Chrome: race condition | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html 2026-09-15 | CVE-2026-91713 CVE-2026-91713 | Google | medium 4.2 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html 2026-09-15 | CVE-2026-91714 CVE-2026-91714 | Google | medium 5.3 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html 2026-09-15 | CVE-2026-91715 CVE-2026-91715 | Google | high 8.8 | Google Chrome: type confusion | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html 2026-09-15 | CVE-2026-91716 CVE-2026-91716 | Google | critical 9.6 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html 2026-09-15 | CVE-2026-91717 CVE-2026-91717 | Google | medium 5.1 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html 2026-09-15 | CVE-2026-91718 CVE-2026-91718 | Google | critical 9.6 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html 2026-09-15 | CVE-2026-91719 CVE-2026-91719 | Google | high 8.1 | Google Chrome: code injection | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html 2026-09-15 | CVE-2026-91708 CVE-2026-91708 | Google | low 3.1 | Google Chrome: race condition | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html 2026-09-15 | CVE-2026-91709 CVE-2026-91709 | Google | high 8.8 | Google Chrome: type confusion | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html 2026-09-15 | CVE-2026-91710 CVE-2026-91710 | Google | critical 9.6 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html 2026-09-15 | CVE-2026-91711 CVE-2026-91711 | Google | high 8.8 | Google Chrome: out-of-bounds write | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html 2026-09-15 | CVE-2026-79994 CVE-2026-79994 | Docker | high 8.7 | Docker Sandboxes: race condition | https://docs.docker.com/ai/sandboxes/ 2026-09-15 | CVE-2026-19655 CVE-2026-19655 | Arista Networks | high 7.1 | Arista Networks EOS: improper input validation | https://www.arista.com/en/support/advisories-notices/security-advisory/24711-security-advisory-0155 2026-09-15 | CVE-2026-88922 CVE-2026-88922 | HashiCorp | medium 6.7 | HashiCorp Shared library: privilege escalation | https://discuss.hashicorp.com/t/hcsec-2026-39-go-getter-vulnerable-to-a-privilege-escalation-issue-in-its-archive-decompression-handling/77752 2026-09-15 | CVE-2026-87284 CVE-2026-87284 | Oracle | low 3.2 | Oracle VM VirtualBox: flaw in Core | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87285 CVE-2026-87285 | Oracle | medium 6.0 | Oracle VM VirtualBox: denial of service via Core | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87286 CVE-2026-87286 | Oracle | high 8.1 | Oracle GraalVM: takeover via Compiler | https://www.oracle.com/security-alerts/oracle-open-source-cves-outside-other-oracle-public-documents.html 2026-09-15 | CVE-2026-87287 CVE-2026-87287 | Oracle | high 8.1 | Oracle GraalVM: takeover via Compiler | https://www.oracle.com/security-alerts/oracle-open-source-cves-outside-other-oracle-public-documents.html 2026-09-15 | CVE-2026-87288 CVE-2026-87288 | Oracle | high 8.1 | Oracle GraalVM: takeover via Compiler | https://www.oracle.com/security-alerts/oracle-open-source-cves-outside-other-oracle-public-documents.html 2026-09-15 | CVE-2026-87289 CVE-2026-87289 | Oracle | high 7.5 | Helidon: denial of service via helidon-webserver-static-content | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87282 CVE-2026-87282 | Oracle | medium 6.0 | Oracle VM VirtualBox: denial of service via Core | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87283 CVE-2026-87283 | Oracle | medium 6.0 | Oracle VM VirtualBox: denial of service via Core | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87273 CVE-2026-87273 | Oracle | high 8.6 | Oracle VM VirtualBox: takeover via Core | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87274 CVE-2026-87274 | Oracle | medium 4.4 | Oracle VM VirtualBox: denial of service via Core | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87275 CVE-2026-87275 | Oracle | medium 4.6 | Oracle VM VirtualBox: data exposure via Core | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87276 CVE-2026-87276 | Oracle | high 7.5 | Oracle VM VirtualBox: takeover via Core | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87277 CVE-2026-87277 | Oracle | high 7.5 | Oracle VM VirtualBox: denial of service via Core | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87278 CVE-2026-87278 | Oracle | medium 6.1 | Oracle VM VirtualBox: denial of service via Core | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87279 CVE-2026-87279 | Oracle | medium 6.1 | Oracle VM VirtualBox: denial of service via Core | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87280 CVE-2026-87280 | Oracle | medium 4.2 | Oracle VM VirtualBox: denial of service via Core | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87281 CVE-2026-87281 | Oracle | low 3.2 | Oracle VM VirtualBox: data exposure via Core | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87264 CVE-2026-87264 | Oracle | high 7.7 | PeopleSoft Enterprise PeopleTools: data tampering via Integration Broker | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87265 CVE-2026-87265 | Oracle | high 8.1 | Oracle Purchasing: data tampering via Other issue | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87266 CVE-2026-87266 | Oracle | high 8.2 | Oracle Agile PLM: data exposure via Application Server | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87267 CVE-2026-87267 | Oracle | medium 5.3 | Oracle VM VirtualBox: denial of service via Core | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87268 CVE-2026-87268 | Oracle | high 7.8 | Oracle VM VirtualBox: takeover via Core | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87269 CVE-2026-87269 | Oracle | high 7.8 | Oracle VM VirtualBox: takeover via Core | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87270 CVE-2026-87270 | Oracle | high 7.8 | Oracle VM VirtualBox: takeover via Core | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87271 CVE-2026-87271 | Oracle | high 7.8 | Oracle VM VirtualBox: takeover via Core | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87272 CVE-2026-87272 | Oracle | high 7.8 | Oracle VM VirtualBox: takeover via Core | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87253 CVE-2026-87253 | Oracle | medium 6.1 | Oracle Agile PLM: data tampering via Web Client | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87254 CVE-2026-87254 | Oracle | high 7.5 | Oracle Agile PLM: takeover via Folders | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87256 CVE-2026-87256 | Oracle | high 7.7 | Oracle Agile PLM: data exposure via Application Server | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87257 CVE-2026-87257 | Oracle | high 7.7 | Oracle Agile PLM: data exposure via SDK | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87258 CVE-2026-87258 | Oracle | high 7.6 | Oracle Agile PLM: data tampering via Folders | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87259 CVE-2026-87259 | Oracle | high 8.4 | Oracle Agile Engineering Data Management: data tampering via Engineering... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87260 CVE-2026-87260 | Oracle | high 7.3 | Oracle Agile Engineering Data Management: data tampering via Engineering... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87261 CVE-2026-87261 | Oracle | high 7.3 | Oracle Agile Engineering Data Management: data tampering via Engineering... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87262 CVE-2026-87262 | Oracle | high 7.1 | Oracle Agile Engineering Data Management: data tampering via Engineering... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87243 CVE-2026-87243 | Oracle | high 8.0 | Oracle Hyperion Financial Management: data tampering via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87244 CVE-2026-87244 | Oracle | high 7.2 | Oracle Hyperion Financial Management: takeover via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87245 CVE-2026-87245 | Oracle | high 8.0 | Oracle Hyperion Financial Management: takeover via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87246 CVE-2026-87246 | Oracle | high 7.2 | Oracle Hyperion Financial Management: takeover via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87247 CVE-2026-87247 | Oracle | high 7.5 | Oracle Hyperion Financial Management: takeover via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87248 CVE-2026-87248 | Oracle | medium 6.7 | Oracle Hyperion Financial Management: takeover via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87249 CVE-2026-87249 | Oracle | high 7.1 | Oracle Hyperion Financial Management: data tampering via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87250 CVE-2026-87250 | Oracle | high 7.6 | Oracle Hyperion Financial Management: data tampering via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87252 CVE-2026-87252 | Oracle | medium 6.8 | Oracle Agile PLM: data tampering via Application Server | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87235 CVE-2026-87235 | Oracle | high 7.4 | Oracle Hyperion Financial Management: data tampering via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87236 CVE-2026-87236 | Oracle | high 7.1 | Oracle Hyperion Financial Management: data exposure via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87237 CVE-2026-87237 | Oracle | high 7.5 | Oracle Hyperion Financial Management: takeover via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87238 CVE-2026-87238 | Oracle | high 8.8 | Oracle Hyperion Financial Management: takeover via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87239 CVE-2026-87239 | Oracle | high 7.2 | Oracle Hyperion Financial Management: takeover via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87240 CVE-2026-87240 | Oracle | high 7.0 | Oracle Hyperion Financial Management: takeover via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87241 CVE-2026-87241 | Oracle | high 8.1 | Oracle Hyperion Financial Management: data tampering via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87242 CVE-2026-87242 | Oracle | high 7.4 | Oracle Hyperion Financial Management: data tampering via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87227 CVE-2026-87227 | Oracle | high 8.8 | Oracle Hyperion Financial Management: takeover via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87228 CVE-2026-87228 | Oracle | high 8.2 | Oracle Hyperion Financial Management: data tampering via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87229 CVE-2026-87229 | Oracle | high 8.2 | Oracle Hyperion Financial Management: data tampering via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87230 CVE-2026-87230 | Oracle | critical 10.0 | Oracle Hyperion Financial Management: data tampering via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87231 CVE-2026-87231 | Oracle | high 8.1 | Oracle Hyperion Financial Management: takeover via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87232 CVE-2026-87232 | Oracle | high 8.1 | Oracle Hyperion Financial Management: data tampering via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87233 CVE-2026-87233 | Oracle | high 7.6 | Oracle Hyperion Financial Management: data exposure via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87234 CVE-2026-87234 | Oracle | high 8.1 | Oracle Hyperion Financial Management: data tampering via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87218 CVE-2026-87218 | Oracle | high 8.1 | Oracle Hyperion Financial Management: denial of service via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87219 CVE-2026-87219 | Oracle | high 8.4 | Oracle Hyperion Financial Management: data tampering via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87220 CVE-2026-87220 | Oracle | high 7.1 | Oracle Hyperion Financial Management: denial of service via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87221 CVE-2026-87221 | Oracle | high 7.5 | Oracle Hyperion Financial Management: data exposure via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87222 CVE-2026-87222 | Oracle | high 7.5 | Oracle Hyperion Financial Management: denial of service via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87223 CVE-2026-87223 | Oracle | critical 9.1 | Oracle Hyperion Financial Management: denial of service via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87224 CVE-2026-87224 | Oracle | high 8.8 | Oracle Hyperion Financial Management: takeover via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87225 CVE-2026-87225 | Oracle | high 7.1 | Oracle Hyperion Financial Management: data exposure via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87226 CVE-2026-87226 | Oracle | high 8.8 | Oracle Hyperion Financial Management: takeover via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87209 CVE-2026-87209 | Oracle | high 7.1 | Oracle Hyperion Financial Management: data exposure via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87210 CVE-2026-87210 | Oracle | high 8.3 | Oracle Hyperion Financial Management: data tampering via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87211 CVE-2026-87211 | Oracle | high 7.5 | Oracle Hyperion Financial Management: data exposure via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87212 CVE-2026-87212 | Oracle | high 7.4 | Oracle Hyperion Financial Management: data tampering via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87213 CVE-2026-87213 | Oracle | high 7.4 | Oracle Hyperion Financial Management: data tampering via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87214 CVE-2026-87214 | Oracle | critical 9.1 | Oracle Hyperion Financial Management: takeover via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87215 CVE-2026-87215 | Oracle | high 7.5 | Oracle Hyperion Financial Management: denial of service via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87216 CVE-2026-87216 | Oracle | high 7.8 | Oracle Hyperion Financial Management: takeover via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87217 CVE-2026-87217 | Oracle | critical 9.1 | Oracle Hyperion Financial Management: data tampering via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87199 CVE-2026-87199 | Oracle | high 7.5 | Oracle Hyperion Financial Management: denial of service via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87200 CVE-2026-87200 | Oracle | high 8.2 | Oracle Hyperion Financial Management: data tampering via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87201 CVE-2026-87201 | Oracle | high 8.8 | Oracle Hyperion Financial Management: takeover via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87202 CVE-2026-87202 | Oracle | high 8.8 | Oracle Hyperion Financial Management: takeover via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87203 CVE-2026-87203 | Oracle | high 7.5 | Oracle Hyperion Financial Management: takeover via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87204 CVE-2026-87204 | Oracle | high 8.8 | Oracle Hyperion Financial Management: takeover via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87205 CVE-2026-87205 | Oracle | high 7.5 | Oracle Hyperion Financial Management: data exposure via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87206 CVE-2026-87206 | Oracle | high 7.4 | Oracle Hyperion Financial Management: data tampering via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87207 CVE-2026-87207 | Oracle | high 7.2 | Oracle Hyperion Financial Management: takeover via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87208 CVE-2026-87208 | Oracle | high 7.1 | Oracle Hyperion Financial Management: data tampering via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87191 CVE-2026-87191 | Oracle | high 7.1 | Oracle Hyperion Financial Management: data exposure via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87192 CVE-2026-87192 | Oracle | high 7.1 | Oracle Hyperion Financial Management: data exposure via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87193 CVE-2026-87193 | Oracle | high 7.5 | Oracle Hyperion Financial Management: data exposure via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87194 CVE-2026-87194 | Oracle | high 7.5 | Oracle Hyperion Financial Management: data exposure via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87195 CVE-2026-87195 | Oracle | high 7.4 | Oracle Hyperion Financial Management: data tampering via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87196 CVE-2026-87196 | Oracle | high 8.2 | Oracle Hyperion Financial Management: data tampering via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87197 CVE-2026-87197 | Oracle | high 8.2 | Oracle Hyperion Financial Management: data tampering via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87198 CVE-2026-87198 | Oracle | high 7.4 | Oracle Hyperion Financial Management: data tampering via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87182 CVE-2026-87182 | Oracle | high 8.8 | Oracle Hyperion Financial Management: takeover via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87183 CVE-2026-87183 | Oracle | high 7.7 | Oracle Hyperion Financial Management: takeover via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87184 CVE-2026-87184 | Oracle | critical 9.8 | Oracle Hyperion Financial Management: takeover via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87185 CVE-2026-87185 | Oracle | high 8.8 | Oracle Hyperion Financial Management: takeover via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87186 CVE-2026-87186 | Oracle | critical 9.6 | Oracle Hyperion Financial Management: takeover via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87187 CVE-2026-87187 | Oracle | high 8.8 | Oracle Hyperion Financial Management: takeover via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87188 CVE-2026-87188 | Oracle | critical 9.8 | Oracle Hyperion Financial Management: takeover via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87189 CVE-2026-87189 | Oracle | critical 9.1 | Oracle Hyperion Financial Management: takeover via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87190 CVE-2026-87190 | Oracle | high 7.5 | Oracle Hyperion Financial Management: takeover via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87173 CVE-2026-87173 | Oracle | critical 9.1 | Oracle Hyperion Financial Management: data tampering via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87174 CVE-2026-87174 | Oracle | high 8.2 | Oracle Hyperion Financial Management: data tampering via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87175 CVE-2026-87175 | Oracle | critical 9.1 | Oracle Hyperion Financial Management: data tampering via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87176 CVE-2026-87176 | Oracle | critical 9.1 | Oracle Hyperion Financial Management: data tampering via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87177 CVE-2026-87177 | Oracle | high 8.5 | Oracle Hyperion Financial Management: data tampering via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87178 CVE-2026-87178 | Oracle | high 8.7 | Oracle Hyperion Financial Management: data tampering via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87179 CVE-2026-87179 | Oracle | high 8.8 | Oracle Hyperion Financial Management: takeover via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87180 CVE-2026-87180 | Oracle | high 8.8 | Oracle Hyperion Financial Management: takeover via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87181 CVE-2026-87181 | Oracle | high 8.8 | Oracle Hyperion Financial Management: takeover via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87164 CVE-2026-87164 | Oracle | high 8.0 | Oracle Banking Branch: takeover via Reports | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87165 CVE-2026-87165 | Oracle | high 8.8 | Oracle Contract Lifecycle Management for Public Sector: takeover via ECC For... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87166 CVE-2026-87166 | Oracle | high 8.1 | Oracle Purchasing: data tampering via Other issue | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87167 CVE-2026-87167 | Oracle | high 8.1 | Oracle Purchasing: data tampering via G-Invoicing | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87168 CVE-2026-87168 | Oracle | high 8.1 | Oracle Purchasing: data tampering via G-Invoicing | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87169 CVE-2026-87169 | Oracle | medium 6.1 | Oracle Contract Lifecycle Management for Public Sector: data tampering via Wage... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87170 CVE-2026-87170 | Oracle | critical 9.1 | Oracle Hyperion Financial Management: data tampering via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87171 CVE-2026-87171 | Oracle | high 8.7 | Oracle Hyperion Financial Management: data tampering via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87172 CVE-2026-87172 | Oracle | critical 9.9 | Oracle Hyperion Financial Management: takeover via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87156 CVE-2026-87156 | Oracle | high 7.1 | Oracle Product Hub: data tampering via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87157 CVE-2026-87157 | Oracle | high 8.1 | Oracle Order Management: data tampering via Product Diagnostic Tools | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87158 CVE-2026-87158 | Oracle | high 7.1 | Oracle Order Management: data tampering via Enterprise Command Center | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87159 CVE-2026-87159 | Oracle | high 8.1 | Oracle HRMS (India): data tampering via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87160 CVE-2026-87160 | Oracle | high 7.1 | Oracle HRMS (India): data tampering via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87161 CVE-2026-87161 | Oracle | high 8.5 | Oracle HRMS (India): data tampering via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87162 CVE-2026-87162 | Oracle | high 8.8 | Oracle Contract Lifecycle Management for Public Sector: takeover via Award/PO | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87163 CVE-2026-87163 | Oracle | high 8.8 | Oracle Purchasing: takeover via Other issue | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87147 CVE-2026-87147 | Oracle | high 7.7 | Oracle Hyperion Data Relationship Management: data tampering via Access and... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87148 CVE-2026-87148 | Oracle | high 7.5 | Oracle Hyperion Data Relationship Management: denial of service via Access and... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87149 CVE-2026-87149 | Oracle | high 7.1 | Oracle Contract Lifecycle Management for Public Sector: data tampering via... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87150 CVE-2026-87150 | Oracle | high 8.8 | Oracle Bills of Material: takeover via Setup Workbench | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87151 CVE-2026-87151 | Oracle | high 7.7 | Oracle Bills of Material: data exposure via Setup Workbench | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87152 CVE-2026-87152 | Oracle | high 8.1 | Oracle Installed Base: data tampering via Create Item Instance | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87153 CVE-2026-87153 | Oracle | high 8.1 | Oracle Product Hub: data tampering via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87154 CVE-2026-87154 | Oracle | high 8.1 | Oracle Product Hub: data tampering via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87155 CVE-2026-87155 | Oracle | high 8.8 | Oracle Product Hub: takeover via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87139 CVE-2026-87139 | Oracle | high 7.5 | Oracle Hyperion Data Relationship Management: takeover via Access and security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87140 CVE-2026-87140 | Oracle | high 7.5 | Oracle Hyperion Data Relationship Management: takeover via Access and security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87141 CVE-2026-87141 | Oracle | high 7.7 | Oracle Hyperion Data Relationship Management: data exposure via Access and... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87142 CVE-2026-87142 | Oracle | high 7.1 | Oracle Hyperion Data Relationship Management: data tampering via Access and... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87143 CVE-2026-87143 | Oracle | high 7.4 | Oracle Hyperion Data Relationship Management: data tampering via Access and... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87144 CVE-2026-87144 | Oracle | high 7.6 | Oracle Hyperion Data Relationship Management: data tampering via Access and... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87145 CVE-2026-87145 | Oracle | high 7.3 | Oracle Hyperion Data Relationship Management: data tampering via Access and... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87146 CVE-2026-87146 | Oracle | high 7.1 | Oracle Hyperion Data Relationship Management: data tampering via Access and... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87130 CVE-2026-87130 | Oracle | high 7.4 | Oracle Hyperion Data Relationship Management: data tampering via Access and... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87131 CVE-2026-87131 | Oracle | high 7.6 | Oracle Hyperion Data Relationship Management: data tampering via Access and... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87132 CVE-2026-87132 | Oracle | high 7.6 | Oracle Hyperion Data Relationship Management: data tampering via Access and... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87133 CVE-2026-87133 | Oracle | high 7.6 | Oracle Hyperion Data Relationship Management: data tampering via Access and... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87134 CVE-2026-87134 | Oracle | high 7.7 | Oracle Hyperion Data Relationship Management: data exposure via Access and... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87135 CVE-2026-87135 | Oracle | high 7.1 | Oracle Hyperion Data Relationship Management: data tampering via Access and... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87136 CVE-2026-87136 | Oracle | high 7.5 | Oracle Hyperion Data Relationship Management: data exposure via Access and... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87137 CVE-2026-87137 | Oracle | high 7.6 | Oracle Hyperion Data Relationship Management: data tampering via Access and... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87138 CVE-2026-87138 | Oracle | high 7.5 | Oracle Hyperion Data Relationship Management: denial of service via Access and... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87124 CVE-2026-87124 | Oracle | high 7.7 | Oracle iRecruitment: data exposure via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87125 CVE-2026-87125 | Oracle | high 8.3 | Oracle Financials for Asia/Pacific: data tampering via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87126 CVE-2026-87126 | Oracle | high 7.1 | Oracle Report Manager: data exposure via Reports Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87127 CVE-2026-87127 | Oracle | high 7.7 | Oracle Purchasing: data exposure via G-Invoicing | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87128 CVE-2026-87128 | Oracle | critical 9.1 | Oracle Hyperion Data Relationship Management: data tampering via Access and... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-87129 CVE-2026-87129 | Oracle | critical 9.1 | Oracle Hyperion Data Relationship Management: data tampering via Access and... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83483 CVE-2026-83483 | Oracle | high 8.0 | Oracle Advanced Benefits: takeover via Self-serv What-if Analysis | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83484 CVE-2026-83484 | Oracle | high 7.1 | Oracle US Federal Human Resources: data tampering via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83485 CVE-2026-83485 | Oracle | high 7.7 | Oracle Product Hub: data exposure via Item Catalog | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83486 CVE-2026-83486 | Oracle | high 7.7 | Oracle Product Hub: data exposure via Item Catalog | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83487 CVE-2026-83487 | Oracle | high 7.7 | Oracle Product Hub: data exposure via Item Catalog | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83488 CVE-2026-83488 | Oracle | medium 5.4 | Helidon: data tampering via helidon-microprofile-security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83489 CVE-2026-83489 | Oracle | high 7.5 | Oracle Banking Origination: takeover via Onboarding Batch Processes | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83490 CVE-2026-83490 | Oracle | high 8.5 | Oracle iRecruitment: data tampering via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83491 CVE-2026-83491 | Oracle | medium 6.8 | Oracle iRecruitment: data tampering via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83462 CVE-2026-83462 | Oracle | critical 9.8 | Oracle Mobile Application Server: takeover via MWA Terminal Server | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83463 CVE-2026-83463 | Oracle | high 7.5 | Oracle Mobile Application Server: takeover via MWA Terminal Server | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83464 CVE-2026-83464 | Oracle | high 8.1 | Oracle Mobile Application Server: takeover via MWA Terminal Server | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83465 CVE-2026-83465 | Oracle | high 8.2 | Oracle Mobile Application Server: denial of service via MWA Terminal Server | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83477 CVE-2026-83477 | Oracle | high 8.1 | Oracle Work in Process: data tampering via Workbenches | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83479 CVE-2026-83479 | Oracle | high 8.8 | Oracle Contracts: takeover via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83480 CVE-2026-83480 | Oracle | medium 5.3 | Helidon: flaw in WebSocket | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83481 CVE-2026-83481 | Oracle | high 7.2 | Oracle Contracts: takeover via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83482 CVE-2026-83482 | Oracle | high 7.2 | Oracle Contracts: takeover via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83453 CVE-2026-83453 | Oracle | high 7.2 | Oracle Document Management: takeover via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83454 CVE-2026-83454 | Oracle | high 8.8 | Oracle Document Management: takeover via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83455 CVE-2026-83455 | Oracle | high 8.1 | Oracle Demand Signal Repository: data tampering via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83456 CVE-2026-83456 | Oracle | high 8.8 | Oracle Demand Signal Repository: takeover via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83457 CVE-2026-83457 | Oracle | high 8.1 | Oracle Demand Signal Repository: denial of service via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83458 CVE-2026-83458 | Oracle | medium 5.3 | Helidon: flaw in JSON | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83459 CVE-2026-83459 | Oracle | medium 5.3 | Helidon: flaw in helidon-media-multipart | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83460 CVE-2026-83460 | Oracle | medium 6.5 | Helidon: data tampering via LRA | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83461 CVE-2026-83461 | Oracle | high 8.2 | Oracle Mobile Application Server: data exposure via MWA Terminal Server | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83444 CVE-2026-83444 | Oracle | high 8.8 | Oracle Product Hub: takeover via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83445 CVE-2026-83445 | Oracle | high 8.8 | Oracle Complex Maintenance: takeover via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83446 CVE-2026-83446 | Oracle | high 8.1 | Oracle Financials Common Modules: data tampering via Common Components | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83447 CVE-2026-83447 | Oracle | high 8.1 | Oracle Bills of Material: data tampering via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83448 CVE-2026-83448 | Oracle | high 8.1 | Oracle Bills of Material: data tampering via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83449 CVE-2026-83449 | Oracle | high 8.5 | Oracle Bills of Material: data exposure via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83450 CVE-2026-83450 | Oracle | high 8.0 | Oracle Bills of Material: takeover via Setup Workbench | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83451 CVE-2026-83451 | Oracle | high 8.5 | Oracle Product Workbench: takeover via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83452 CVE-2026-83452 | Oracle | critical 9.8 | Oracle Document Management: takeover via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83435 CVE-2026-83435 | Oracle | high 8.2 | Oracle Bills of Material: data tampering via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83436 CVE-2026-83436 | Oracle | high 7.1 | Oracle Depot Repair: data exposure via Recall Management | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83437 CVE-2026-83437 | Oracle | high 7.7 | Oracle Engineering: data exposure via Change Management | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83438 CVE-2026-83438 | Oracle | high 8.2 | Oracle Engineering: data tampering via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83439 CVE-2026-83439 | Oracle | high 8.1 | Helidon: data tampering via helidon-security-providers-idcs-mapper | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83440 CVE-2026-83440 | Oracle | high 7.2 | Oracle Product Hub: takeover via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83441 CVE-2026-83441 | Oracle | medium 6.8 | Oracle Product Hub: data tampering via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83442 CVE-2026-83442 | Oracle | high 7.2 | Oracle Product Hub: takeover via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83443 CVE-2026-83443 | Oracle | medium 6.5 | Oracle Assets: data exposure via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83424 CVE-2026-83424 | Oracle | high 7.5 | Oracle JDeveloper: data exposure via Oracle JDeveloper | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83425 CVE-2026-83425 | Oracle | high 8.5 | Oracle Complex Maintenance: data exposure via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83428 CVE-2026-83428 | Oracle | high 8.1 | Oracle Demand Signal Repository: data tampering via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83429 CVE-2026-83429 | Oracle | high 8.1 | Oracle Demand Signal Repository: data tampering via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83430 CVE-2026-83430 | Oracle | high 8.1 | Oracle Product Workbench: data tampering via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83431 CVE-2026-83431 | Oracle | medium 5.4 | Oracle Product Workbench: data tampering via WebUI | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83432 CVE-2026-83432 | Oracle | high 8.1 | Oracle Depot Repair: data tampering via Estimate and Actual Charges | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83433 CVE-2026-83433 | Oracle | medium 6.5 | Oracle Depot Repair: data tampering via Depot Repair Diagnostics | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83434 CVE-2026-83434 | Oracle | high 8.1 | Oracle Product Workbench: data tampering via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83416 CVE-2026-83416 | Oracle | medium 4.3 | Oracle Coherence: flaw in Core | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83417 CVE-2026-83417 | Oracle | high 7.1 | Oracle Communications Cloud Native Core Security Edge Protection Proxy: data... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83418 CVE-2026-83418 | Oracle | high 8.2 | Oracle Communications Cloud Native Core Security Edge Protection Proxy: data... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83419 CVE-2026-83419 | Oracle | medium 5.4 | Oracle Communications Cloud Native Core Security Edge Protection Proxy: data... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83420 CVE-2026-83420 | Oracle | high 7.8 | PeopleSoft Enterprise FIN Engineering Brazil: takeover via Engineering | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83422 CVE-2026-83422 | Oracle | high 8.1 | Oracle Identity Manager: data tampering via OIM Legacy UI | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83423 CVE-2026-83423 | Oracle | high 8.8 | Oracle JDeveloper: takeover via Security Framework | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83355 CVE-2026-83355 | Oracle | critical 9.8 | Oracle Enterprise Manager for Fusion Middleware: takeover via Metrics | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83356 CVE-2026-83356 | Oracle | high 7.7 | Enterprise Command Center Framework: data exposure via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83369 CVE-2026-83369 | Oracle | low 3.1 | Oracle Access Manager: flaw in Access SDK | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83410 CVE-2026-83410 | Oracle | high 8.8 | Oracle Coherence: takeover via Core | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83411 CVE-2026-83411 | Oracle | high 8.8 | Oracle Coherence: takeover via Core | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83412 CVE-2026-83412 | Oracle | high 8.1 | Oracle Coherence: data tampering via Core | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83413 CVE-2026-83413 | Oracle | low 1.9 | Oracle Coherence: data tampering via Core | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83414 CVE-2026-83414 | Oracle | low 2.5 | Oracle Coherence: data exposure via Core | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83415 CVE-2026-83415 | Oracle | high 7.5 | Oracle Coherence: takeover via Core | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83346 CVE-2026-83346 | Oracle | medium 5.4 | Oracle Fusion Middleware Control: data tampering via Framework | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83347 CVE-2026-83347 | Oracle | medium 6.5 | Oracle Database Server: resource exhaustion | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83348 CVE-2026-83348 | Oracle | high 8.8 | Oracle Database Server: improper privilege management | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83349 CVE-2026-83349 | Oracle | high 7.5 | Oracle Database Server: resource exhaustion | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83350 CVE-2026-83350 | Oracle | high 7.5 | Oracle Database Server: resource exhaustion | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83351 CVE-2026-83351 | Oracle | high 8.1 | Oracle Database Server: improper privilege management | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83352 CVE-2026-83352 | Oracle | high 7.1 | Oracle XML Gateway: data exposure via Install | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83353 CVE-2026-83353 | Oracle | high 7.8 | Oracle WebCenter Content: takeover via Content Server | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83354 CVE-2026-83354 | Oracle | medium 6.3 | Oracle Coherence: data exposure via Core | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83337 CVE-2026-83337 | Oracle | high 7.8 | Oracle Middleware Common Libraries: takeover via Remote Diagnostic Agent | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83338 CVE-2026-83338 | Oracle | high 8.8 | Oracle Applications Manager: takeover via Oracle Diagnostics Interfaces | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83339 CVE-2026-83339 | Oracle | critical 9.8 | Oracle WebCenter Enterprise Capture: takeover via Client Bundle | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83340 CVE-2026-83340 | Oracle | high 8.8 | Oracle Identity Manager: takeover via Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83341 CVE-2026-83341 | Oracle | high 7.5 | Oracle Applications Manager: data exposure via Command Line - RapidClone | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83342 CVE-2026-83342 | Oracle | high 7.8 | Oracle Utilities Network Management System: takeover via System Wide | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83343 CVE-2026-83343 | Oracle | high 8.2 | Oracle Utilities Network Management System: data tampering via System Wide | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83344 CVE-2026-83344 | Oracle | high 7.2 | Oracle Identity Manager Connector: takeover via Database Application Table | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83345 CVE-2026-83345 | Oracle | high 7.1 | Oracle XML Gateway: data exposure via Install | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83329 CVE-2026-83329 | Oracle | high 8.8 | Oracle Applications Framework: takeover via Personalization | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83330 CVE-2026-83330 | Oracle | high 7.5 | Helidon: denial of service via WebSocket | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83331 CVE-2026-83331 | Oracle | high 8.8 | Oracle Applications Framework: takeover via Personalization | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83332 CVE-2026-83332 | Oracle | high 7.1 | Oracle Applications Framework: data tampering via Personalization | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83333 CVE-2026-83333 | Oracle | high 7.5 | Oracle Database Server: resource exhaustion | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83334 CVE-2026-83334 | Oracle | high 7.4 | Oracle Web Services Manager: denial of service via Web Services Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83335 CVE-2026-83335 | Oracle | high 8.8 | Oracle Business Intelligence Enterprise Edition: takeover via Analytics Server | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83336 CVE-2026-83336 | Oracle | high 7.8 | Oracle Business Intelligence Enterprise Edition: takeover via Analytics Server | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83320 CVE-2026-83320 | Oracle | high 7.6 | Oracle BI Publisher: data tampering via Administration | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83321 CVE-2026-83321 | Oracle | high 8.5 | Oracle Business Intelligence Enterprise Edition: data tampering via Analytics... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83322 CVE-2026-83322 | Oracle | high 7.2 | Oracle Business Intelligence Enterprise Edition: takeover via Platform Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83323 CVE-2026-83323 | Oracle | high 7.5 | Oracle Business Intelligence Enterprise Edition: takeover via Platform Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83324 CVE-2026-83324 | Oracle | high 7.1 | Oracle Business Intelligence Enterprise Edition: data tampering via BI Platform... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83325 CVE-2026-83325 | Oracle | high 7.2 | Oracle Business Intelligence Enterprise Edition: takeover via Platform Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83326 CVE-2026-83326 | Oracle | high 7.5 | Siebel CRM Integration: data exposure via Open Integration | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83327 CVE-2026-83327 | Oracle | critical 9.8 | Oracle Applications Framework: takeover via Personalization | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83328 CVE-2026-83328 | Oracle | high 7.2 | Oracle Applications Framework: takeover via Personalization | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83311 CVE-2026-83311 | Oracle | high 8.5 | Oracle BI Publisher: data tampering via BI Platform Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83312 CVE-2026-83312 | Oracle | high 7.7 | Oracle BI Publisher: data exposure via E-Business Suite - XDO | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83313 CVE-2026-83313 | Oracle | high 7.7 | Oracle BI Publisher: data exposure via BI Platform Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83314 CVE-2026-83314 | Oracle | high 8.1 | Oracle BI Publisher: denial of service via Web Service API | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83315 CVE-2026-83315 | Oracle | high 8.8 | Oracle BI Publisher: takeover via BI Platform Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83316 CVE-2026-83316 | Oracle | high 7.0 | Oracle Business Intelligence Enterprise Edition: takeover via Platform Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83317 CVE-2026-83317 | Oracle | high 7.8 | Oracle Business Intelligence Enterprise Edition: takeover via Installation | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83318 CVE-2026-83318 | Oracle | high 7.5 | Oracle BI Publisher: takeover via Administration | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83319 CVE-2026-83319 | Oracle | high 7.7 | Oracle BI Publisher: data exposure via Web Service API | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83302 CVE-2026-83302 | Oracle | high 8.5 | Oracle BI Publisher: data exposure via BI Publisher Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83303 CVE-2026-83303 | Oracle | high 8.5 | Oracle BI Publisher: data tampering via BI Platform Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83304 CVE-2026-83304 | Oracle | high 8.9 | Oracle Business Intelligence Enterprise Edition: data tampering via Analytics... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83305 CVE-2026-83305 | Oracle | high 8.6 | Oracle BI Publisher: data tampering via BI Platform Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83306 CVE-2026-83306 | Oracle | high 8.8 | Oracle JDeveloper: takeover via Resource Catalog Services | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83307 CVE-2026-83307 | Oracle | high 8.3 | Oracle BI Publisher: data tampering via BI Platform Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83308 CVE-2026-83308 | Oracle | high 8.1 | Oracle BI Publisher: denial of service via BI Platform Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83309 CVE-2026-83309 | Oracle | high 8.5 | Oracle BI Publisher: data tampering via Web Server | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83310 CVE-2026-83310 | Oracle | high 8.7 | Oracle BI Publisher: data tampering via BI Platform Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83293 CVE-2026-83293 | Oracle | high 7.8 | Oracle Business Intelligence Enterprise Edition: takeover via FNDN | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83294 CVE-2026-83294 | Oracle | high 7.8 | Oracle Business Intelligence Enterprise Edition: takeover via Platform Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83295 CVE-2026-83295 | Oracle | high 7.5 | Oracle Business Intelligence Enterprise Edition: takeover via Presentation... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83296 CVE-2026-83296 | Oracle | high 7.5 | Oracle Business Intelligence Enterprise Edition: takeover via BI Search | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83297 CVE-2026-83297 | Oracle | high 8.1 | Oracle BI Publisher: data tampering via BI Platform Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83298 CVE-2026-83298 | Oracle | high 7.2 | Oracle BI Publisher: takeover via BI Platform Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83299 CVE-2026-83299 | Oracle | high 8.1 | Oracle Business Intelligence Enterprise Edition: takeover via Analytics Web... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83300 CVE-2026-83300 | Oracle | high 7.1 | Oracle XML Gateway: data exposure via Install | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83301 CVE-2026-83301 | Oracle | high 8.8 | Oracle Business Intelligence Enterprise Edition: takeover via Service... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83284 CVE-2026-83284 | Oracle | high 8.6 | Oracle BI Publisher: denial of service via BI Platform Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83285 CVE-2026-83285 | Oracle | high 8.3 | Oracle Business Intelligence Enterprise Edition: data tampering via BI Search | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83286 CVE-2026-83286 | Oracle | high 8.1 | Oracle Business Intelligence Enterprise Edition: takeover via Platform Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83287 CVE-2026-83287 | Oracle | high 7.7 | Oracle Business Intelligence Enterprise Edition: data exposure via Presentation... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83288 CVE-2026-83288 | Oracle | high 7.8 | Oracle Business Intelligence Enterprise Edition: takeover via BI Search | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83289 CVE-2026-83289 | Oracle | high 7.5 | Oracle Business Intelligence Enterprise Edition: takeover via Analytics Web... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83290 CVE-2026-83290 | Oracle | high 7.8 | Oracle Business Intelligence Enterprise Edition: takeover via Platform Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83291 CVE-2026-83291 | Oracle | high 7.8 | Oracle Business Intelligence Enterprise Edition: takeover via Platform Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83292 CVE-2026-83292 | Oracle | high 7.5 | Oracle Business Intelligence Enterprise Edition: takeover via Platform Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83276 CVE-2026-83276 | Oracle | high 7.5 | Helidon: denial of service via helidon-webclient-http2 | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83277 CVE-2026-83277 | Oracle | high 7.3 | Oracle Agile PLM MCAD Connector: data tampering via CAX Client | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83278 CVE-2026-83278 | Oracle | medium 6.8 | Helidon: data tampering via helidon-integrations-neo4j | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83279 CVE-2026-83279 | Oracle | medium 5.5 | Oracle Agile PLM MCAD Connector: data exposure via CAX Client | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83280 CVE-2026-83280 | Oracle | high 7.5 | Helidon: denial of service via helidon-webserver-http2 | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83281 CVE-2026-83281 | Oracle | high 7.5 | Helidon: denial of service via helidon-webserver | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83282 CVE-2026-83282 | Oracle | critical 9.9 | Oracle Business Intelligence Enterprise Edition: takeover via Platform Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83283 CVE-2026-83283 | Oracle | critical 9.8 | Oracle Business Intelligence Enterprise Edition: takeover via Platform Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83267 CVE-2026-83267 | Oracle | high 8.5 | Oracle BI Publisher: data tampering via BI Publisher Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83268 CVE-2026-83268 | Oracle | critical 9.1 | Oracle BI Publisher: takeover via BI Platform Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83269 CVE-2026-83269 | Oracle | critical 9.8 | Oracle BI Publisher: takeover via BI Platform Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83270 CVE-2026-83270 | Oracle | high 7.5 | Oracle Business Intelligence Enterprise Edition: data exposure via BI Platform... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83271 CVE-2026-83271 | Oracle | high 8.8 | Oracle Database Server: improper privilege management | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83272 CVE-2026-83272 | Oracle | high 8.5 | Oracle Database Server: improper privilege management | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83273 CVE-2026-83273 | Oracle | high 7.2 | Oracle Business Intelligence Enterprise Edition: takeover via Platform Security | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83274 CVE-2026-83274 | Oracle | medium 5.5 | Oracle Agile PLM MCAD Connector: data exposure via CAX Client | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83258 CVE-2026-83258 | Oracle | high 8.1 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager: takeover... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83259 CVE-2026-83259 | Oracle | high 7.1 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager: data... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83260 CVE-2026-83260 | Oracle | critical 9.1 | Oracle Agile PLM: takeover via Event Java PX | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83261 CVE-2026-83261 | Oracle | critical 9.8 | Oracle Product Lifecycle Analytics: takeover via Core | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83262 CVE-2026-83262 | Oracle | high 7.5 | Oracle Product Lifecycle Analytics: takeover via Installation Issues | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83263 CVE-2026-83263 | Oracle | high 7.5 | Oracle Product Lifecycle Analytics: takeover via Installation Issues | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83264 CVE-2026-83264 | Oracle | high 8.4 | Oracle Product Lifecycle Analytics: data tampering via Installation Issues | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83265 CVE-2026-83265 | Oracle | high 8.2 | Oracle Web Services Manager: data tampering via Web Services Agent | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83266 CVE-2026-83266 | Oracle | high 8.2 | Oracle JDeveloper: data exposure via Resource Catalog Services | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83249 CVE-2026-83249 | Oracle | high 7.8 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager: takeover... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83250 CVE-2026-83250 | Oracle | medium 6.5 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager: data... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83251 CVE-2026-83251 | Oracle | medium 6.5 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager: denial of... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83252 CVE-2026-83252 | Oracle | high 7.0 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager: data... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83253 CVE-2026-83253 | Oracle | high 7.8 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager: takeover... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83254 CVE-2026-83254 | Oracle | high 8.1 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager: takeover... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83255 CVE-2026-83255 | Oracle | high 8.1 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager: takeover... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83256 CVE-2026-83256 | Oracle | high 8.1 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager: takeover... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83257 CVE-2026-83257 | Oracle | high 7.5 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager: takeover... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83240 CVE-2026-83240 | Oracle | high 7.1 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager: denial of... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83241 CVE-2026-83241 | Oracle | high 7.5 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager: takeover... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83242 CVE-2026-83242 | Oracle | high 7.3 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager: data... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83243 CVE-2026-83243 | Oracle | high 7.7 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager: data... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83244 CVE-2026-83244 | Oracle | high 7.1 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager: denial of... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83245 CVE-2026-83245 | Oracle | high 8.1 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager: takeover... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83246 CVE-2026-83246 | Oracle | high 8.1 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager: takeover... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83247 CVE-2026-83247 | Oracle | high 7.8 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager: takeover... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83248 CVE-2026-83248 | Oracle | high 8.2 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager: denial of... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83232 CVE-2026-83232 | Oracle | critical 9.8 | Oracle Data Integrator: takeover via Console / Repository Explorer | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83233 CVE-2026-83233 | Oracle | high 7.7 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager: data... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83234 CVE-2026-83234 | Oracle | high 8.2 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager: data... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83235 CVE-2026-83235 | Oracle | high 7.5 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager: data... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83236 CVE-2026-83236 | Oracle | high 8.2 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager: data... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83237 CVE-2026-83237 | Oracle | high 7.1 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager: data... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83238 CVE-2026-83238 | Oracle | high 7.1 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager: data... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83239 CVE-2026-83239 | Oracle | high 7.0 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager: takeover... | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83223 CVE-2026-83223 | Oracle | high 7.5 | Siebel CRM Deployment: takeover via Siebel Remote | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83224 CVE-2026-83224 | Oracle | high 7.1 | Siebel CRM Deployment: data exposure via Server Infrastructure | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83225 CVE-2026-83225 | Oracle | high 7.5 | Siebel CRM Deployment: denial of service via Server Infrastructure | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83226 CVE-2026-83226 | Oracle | high 7.5 | Siebel CRM Deployment: takeover via Server Infrastructure | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83227 CVE-2026-83227 | Oracle | high 7.5 | Siebel CRM Integration: takeover via EAI | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83228 CVE-2026-83228 | Oracle | high 7.5 | Siebel CRM Deployment: denial of service via Server Infrastructure | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83229 CVE-2026-83229 | Oracle | critical 9.1 | Siebel CRM Deployment: takeover via Siebel Management Console | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83230 CVE-2026-83230 | Oracle | high 7.1 | Siebel CRM Deployment: data tampering via Siebel Management Console | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83231 CVE-2026-83231 | Oracle | high 7.0 | Helidon: data tampering via helidon-dbclient-mongodb | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83214 CVE-2026-83214 | Oracle | high 7.8 | Siebel CRM Deployment: takeover via Server Infrastructure | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83215 CVE-2026-83215 | Oracle | high 8.2 | Siebel CRM Deployment: data tampering via Server Infrastructure | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83216 CVE-2026-83216 | Oracle | high 7.8 | Siebel CRM Deployment: takeover via Server Infrastructure | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83217 CVE-2026-83217 | Oracle | high 7.1 | Siebel CRM End User: data tampering via Open UI | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83218 CVE-2026-83218 | Oracle | high 7.4 | Siebel CRM Deployment: data tampering via Server Infrastructure | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83219 CVE-2026-83219 | Oracle | high 7.1 | Siebel CRM Deployment: data tampering via Server Infrastructure | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83220 CVE-2026-83220 | Oracle | high 8.1 | Siebel CRM Integration: data tampering via Event Publish and Subscribe | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83221 CVE-2026-83221 | Oracle | high 7.1 | Siebel CRM Integration: data tampering via EAI | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83222 CVE-2026-83222 | Oracle | high 7.5 | Siebel CRM Deployment: denial of service via Server Infrastructure | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83205 CVE-2026-83205 | Oracle | high 8.8 | Oracle Applications Framework: takeover via Personalization | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83206 CVE-2026-83206 | Oracle | high 7.1 | Oracle Banking Corporate Lending Process Management: takeover via Base | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83207 CVE-2026-83207 | Oracle | high 7.6 | Siebel CRM Development: denial of service via Integration - Scripting | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83208 CVE-2026-83208 | Oracle | high 8.8 | Siebel CRM Deployment: takeover via Migration | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83209 CVE-2026-83209 | Oracle | high 8.8 | Siebel CRM Development: takeover via Workflow | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83210 CVE-2026-83210 | Oracle | high 8.8 | Siebel CRM Deployment: takeover via Server Infrastructure | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83211 CVE-2026-83211 | Oracle | high 7.8 | Siebel CRM Deployment: takeover via Server Infrastructure | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83212 CVE-2026-83212 | Oracle | high 8.8 | Siebel Apps - Self Service: takeover via Helpdesk/Training | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83213 CVE-2026-83213 | Oracle | high 7.5 | Siebel CRM End User: data exposure via Reports | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83196 CVE-2026-83196 | Oracle | critical 9.1 | Siebel CRM Deployment: takeover via Server Infrastructure | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83197 CVE-2026-83197 | Oracle | critical 9.1 | Siebel Apps - Financial Services: denial of service via Financial Accounts | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83198 CVE-2026-83198 | Oracle | medium 5.4 | Oracle Field Service: data tampering via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83199 CVE-2026-83199 | Oracle | high 8.8 | Siebel CRM Deployment: takeover via Server Infrastructure | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83200 CVE-2026-83200 | Oracle | medium 6.5 | Oracle Process Manufacturing Intelligence: data exposure via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83201 CVE-2026-83201 | Oracle | critical 9.1 | Siebel CRM Deployment: data tampering via Server Infrastructure | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83202 CVE-2026-83202 | Oracle | critical 9.1 | Siebel CRM Deployment: data tampering via Server Infrastructure | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83203 CVE-2026-83203 | Oracle | high 8.6 | Siebel CRM End User: data tampering via Open UI | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83204 CVE-2026-83204 | Oracle | high 7.5 | Oracle Sourcing: takeover via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83188 CVE-2026-83188 | Oracle | high 7.2 | Oracle Depot Repair: takeover via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83189 CVE-2026-83189 | Oracle | high 8.8 | Oracle User Management: takeover via Proxy User Delegation | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83190 CVE-2026-83190 | Oracle | high 7.3 | Siebel CRM Deployment: takeover via Server Infrastructure | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83191 CVE-2026-83191 | Oracle | high 8.1 | Siebel CRM Deployment: takeover via Server Infrastructure | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83192 CVE-2026-83192 | Oracle | high 8.1 | Siebel CRM End User: takeover via Open UI | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83193 CVE-2026-83193 | Oracle | high 7.3 | Siebel Apps - Life Sciences: takeover via Life Sciences | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83194 CVE-2026-83194 | Oracle | high 8.8 | Oracle Depot Repair: takeover via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83195 CVE-2026-83195 | Oracle | high 7.2 | Siebel CRM Deployment: takeover via Server Infrastructure | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83179 CVE-2026-83179 | Oracle | high 7.1 | Oracle Common Applications Calendar: data tampering via Applications Calendar | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83180 CVE-2026-83180 | Oracle | high 8.8 | Siebel CRM Deployment: takeover via Server Infrastructure | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83181 CVE-2026-83181 | Oracle | high 8.2 | Siebel CRM Development: data exposure via Workspaces | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83182 CVE-2026-83182 | Oracle | high 7.5 | Siebel CRM Development: takeover via Configuration Tools | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83183 CVE-2026-83183 | Oracle | high 7.5 | Siebel CRM Deployment: denial of service via Server Infrastructure | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83184 CVE-2026-83184 | Oracle | high 7.4 | Oracle Application Object Library: data tampering via Core | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83185 CVE-2026-83185 | Oracle | high 7.3 | Oracle Common Applications: data tampering via CRM User Management Framework | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83186 CVE-2026-83186 | Oracle | high 7.1 | Oracle Common Applications Calendar: data tampering via Applications Calendar | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83187 CVE-2026-83187 | Oracle | high 7.1 | Oracle Common Applications Calendar: data tampering via Applications Calendar | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83171 CVE-2026-83171 | Oracle | high 7.1 | Oracle One-to-One Fulfillment: data exposure via Documents | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83172 CVE-2026-83172 | Oracle | high 8.5 | Oracle Sales Online: data tampering via OSO Other | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83173 CVE-2026-83173 | Oracle | high 7.1 | Oracle One-to-One Fulfillment: data exposure via Documents | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83174 CVE-2026-83174 | Oracle | high 8.1 | Oracle CRM Technical Foundation: data tampering via Application Framework | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83175 CVE-2026-83175 | Oracle | medium 6.5 | Oracle Application Object Library: data exposure via Core | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83176 CVE-2026-83176 | Oracle | high 7.2 | Oracle Common Applications: takeover via CRM User Management Framework | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83177 CVE-2026-83177 | Oracle | high 8.1 | Oracle One-to-One Fulfillment: data tampering via Documents | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83178 CVE-2026-83178 | Oracle | high 8.0 | Oracle Application Object Library: takeover via Core | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83161 CVE-2026-83161 | Oracle | high 7.1 | Oracle Project Intelligence: data tampering via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83162 CVE-2026-83162 | Oracle | high 7.4 | Oracle Application Object Library: data tampering via Core | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83163 CVE-2026-83163 | Oracle | high 8.8 | Oracle Application Object Library: takeover via Attachments / File Upload | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83164 CVE-2026-83164 | Oracle | high 8.8 | Oracle Customer Interaction History: takeover via Outcome-Result | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83165 CVE-2026-83165 | Oracle | high 8.8 | Oracle Customer Interaction History: takeover via User Interface | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83166 CVE-2026-83166 | Oracle | high 7.7 | Oracle Customer Interaction History: data exposure via Outcome-Result | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83167 CVE-2026-83167 | Oracle | high 7.5 | Oracle Application Object Library: data exposure via Core | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83168 CVE-2026-83168 | Oracle | high 8.8 | Oracle Applications Manager: takeover via Oracle Diagnostics Interfaces | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83169 CVE-2026-83169 | Oracle | high 8.1 | Oracle One-to-One Fulfillment: takeover via Java Server Issues | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83170 CVE-2026-83170 | Oracle | high 8.0 | Oracle One-to-One Fulfillment: takeover via Documents | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83153 CVE-2026-83153 | Oracle | high 8.8 | Siebel CRM Deployment: takeover via Server Infrastructure | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83154 CVE-2026-83154 | Oracle | critical 9.1 | Siebel CRM End User: data tampering via Open UI | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83155 CVE-2026-83155 | Oracle | high 7.3 | Siebel CRM Deployment: denial of service via Server Infrastructure | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83156 CVE-2026-83156 | Oracle | high 7.5 | Oracle Database Server: improper access control | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83157 CVE-2026-83157 | Oracle | high 8.0 | Oracle Applications Manager: takeover via Command Line - RapidClone | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83158 CVE-2026-83158 | Oracle | high 7.1 | Oracle Applications Manager: data tampering via Command Line - RapidClone | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83159 CVE-2026-83159 | Oracle | high 7.8 | Applications DBA: takeover via ADPatch | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83160 CVE-2026-83160 | Oracle | high 8.8 | Oracle Database Server: improper access control | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83144 CVE-2026-83144 | Oracle | high 8.7 | Siebel Apps - Customer Order Management: data tampering via Order Management | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83145 CVE-2026-83145 | Oracle | high 8.7 | Siebel Apps - Customer Order Management: data tampering via Order Management | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83146 CVE-2026-83146 | Oracle | high 7.7 | Siebel CRM End User: data tampering via Open UI | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83147 CVE-2026-83147 | Oracle | high 7.8 | PeopleSoft Enterprise FIN Inventory Brazil: takeover via Inventory | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83148 CVE-2026-83148 | Oracle | high 8.8 | Oracle Application Testing Suite: improper privilege management | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83149 CVE-2026-83149 | Oracle | critical 9.1 | Oracle Application Testing Suite: improper access control | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83150 CVE-2026-83150 | Oracle | high 7.0 | Oracle Application Testing Suite: improper privilege management | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83151 CVE-2026-83151 | Oracle | critical 9.8 | Service Delivery Platform: takeover via Messaging Enabler | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83152 CVE-2026-83152 | Oracle | high 8.1 | Oracle Project Intelligence: data tampering via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83134 CVE-2026-83134 | Oracle | high 7.7 | Oracle iStore: data exposure via Shopping Cart | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83135 CVE-2026-83135 | Oracle | high 8.7 | Oracle iStore: data tampering via Shopping Cart | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83136 CVE-2026-83136 | Oracle | high 8.8 | Oracle Spares Management: takeover via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83137 CVE-2026-83137 | Oracle | high 8.8 | Oracle Spares Management: takeover via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83138 CVE-2026-83138 | Oracle | high 8.0 | Oracle Spares Management: takeover via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83140 CVE-2026-83140 | Oracle | medium 6.5 | Oracle Field Service: data exposure via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83141 CVE-2026-83141 | Oracle | high 7.7 | Oracle Field Service: data exposure via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83142 CVE-2026-83142 | Oracle | high 7.7 | Oracle Proposals: data exposure via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83143 CVE-2026-83143 | Oracle | high 8.1 | Siebel Apps - Life Sciences: data tampering via eDetailing | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83126 CVE-2026-83126 | Oracle | high 7.6 | Oracle Sales Online: data tampering via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83127 CVE-2026-83127 | Oracle | high 7.7 | Oracle Sales Offline: data exposure via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83128 CVE-2026-83128 | Oracle | high 7.5 | Oracle Sales Offline: data exposure via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83129 CVE-2026-83129 | Oracle | high 7.7 | Oracle Sales: data exposure via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83130 CVE-2026-83130 | Oracle | high 7.1 | Oracle Site Hub: data tampering via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83131 CVE-2026-83131 | Oracle | high 7.7 | Oracle Web Applications Desktop Integrator: data exposure via File download | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83132 CVE-2026-83132 | Oracle | high 8.1 | Oracle iStore: data tampering via Shopping Cart | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83133 CVE-2026-83133 | Oracle | high 7.5 | Oracle iStore: data exposure via Shopping Cart | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83117 CVE-2026-83117 | Oracle | high 7.2 | Applications DBA: takeover via AD Utilities | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83118 CVE-2026-83118 | Oracle | high 7.8 | Applications DBA: takeover via AD Utilities | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83119 CVE-2026-83119 | Oracle | high 8.8 | Oracle User Management: takeover via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83120 CVE-2026-83120 | Oracle | high 8.8 | Oracle Alert: takeover via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83121 CVE-2026-83121 | Oracle | high 8.8 | Oracle Marketing: takeover via Audience | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83122 CVE-2026-83122 | Oracle | high 8.8 | Oracle Report Manager: takeover via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83123 CVE-2026-83123 | Oracle | high 7.1 | Oracle Report Manager: data exposure via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83124 CVE-2026-83124 | Oracle | high 8.8 | Oracle Sales Online: takeover via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83125 CVE-2026-83125 | Oracle | high 8.8 | Oracle Report Manager: takeover via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83108 CVE-2026-83108 | Oracle | critical 9.8 | Oracle Forms: takeover via Forms Services | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83109 CVE-2026-83109 | Oracle | medium 5.3 | Oracle Forms: data exposure via Forms Services | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83110 CVE-2026-83110 | Oracle | high 7.5 | Oracle Marketing: data exposure via Audience | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83111 CVE-2026-83111 | Oracle | high 7.1 | Oracle Partner Management: data tampering via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83112 CVE-2026-83112 | Oracle | high 7.2 | Oracle Lease: takeover via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83113 CVE-2026-83113 | Oracle | high 7.1 | Oracle Quality: data tampering via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83114 CVE-2026-83114 | Oracle | high 7.5 | Oracle Quality: takeover via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83115 CVE-2026-83115 | Oracle | high 7.5 | Oracle Applications Manager: data exposure via Command Line - RapidClone | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83116 CVE-2026-83116 | Oracle | high 7.7 | Oracle Order Management: data exposure via Product Diagnostic Tools | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83099 CVE-2026-83099 | Oracle | critical 10.0 | Oracle Forms: takeover via Forms Services | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83100 CVE-2026-83100 | Oracle | critical 9.8 | Oracle Forms: takeover via Forms Services | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83101 CVE-2026-83101 | Oracle | high 8.1 | Oracle Forms: takeover via Forms Services | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83102 CVE-2026-83102 | Oracle | high 7.4 | Oracle Forms: data tampering via Forms Services | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83103 CVE-2026-83103 | Oracle | critical 9.1 | Oracle Forms: takeover via Forms Services | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83104 CVE-2026-83104 | Oracle | critical 9.1 | Oracle Forms: data tampering via Forms Services | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83105 CVE-2026-83105 | Oracle | critical 9.0 | Oracle Forms: takeover via Forms Services | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83106 CVE-2026-83106 | Oracle | high 7.5 | Oracle Forms: takeover via Forms Services | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83107 CVE-2026-83107 | Oracle | critical 9.1 | Oracle Forms: takeover via Forms Services | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83092 CVE-2026-83092 | Oracle | high 7.1 | Oracle Field Service: data tampering via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83093 CVE-2026-83093 | Oracle | high 8.6 | Oracle Forms: data exposure via Forms Services | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83094 CVE-2026-83094 | Oracle | critical 9.8 | Oracle Forms: takeover via Forms Services | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83095 CVE-2026-83095 | Oracle | critical 9.8 | Oracle Forms: takeover via Forms Services | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83096 CVE-2026-83096 | Oracle | high 7.9 | Oracle Forms: data tampering via Forms Services | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83097 CVE-2026-83097 | Oracle | medium 6.5 | Oracle Forms: denial of service via Forms Services | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83098 CVE-2026-83098 | Oracle | critical 9.8 | Oracle Forms: takeover via Forms Services | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83083 CVE-2026-83083 | Oracle | high 8.5 | Oracle Marketing: data tampering via Audience | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83084 CVE-2026-83084 | Oracle | high 7.7 | Oracle Marketing: data exposure via Audience | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83085 CVE-2026-83085 | Oracle | high 8.2 | Siebel CRM Cloud Applications: data tampering via Siebel Cloud Manager | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83086 CVE-2026-83086 | Oracle | high 8.8 | Siebel CRM Cloud Applications: takeover via Siebel Cloud Manager | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83087 CVE-2026-83087 | Oracle | high 8.2 | Siebel CRM Cloud Applications: data tampering via Siebel Cloud Manager | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83088 CVE-2026-83088 | Oracle | high 7.7 | Oracle Database Server: improper access control | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83089 CVE-2026-83089 | Oracle | high 8.1 | Oracle Alert: data tampering via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83090 CVE-2026-83090 | Oracle | high 8.8 | Oracle Spares Management: takeover via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83091 CVE-2026-83091 | Oracle | high 7.6 | Oracle Field Service: data tampering via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83074 CVE-2026-83074 | Oracle | high 8.6 | Siebel CRM Cloud Applications: data exposure via Siebel Cloud Manager | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83075 CVE-2026-83075 | Oracle | high 7.5 | Siebel CRM Cloud Applications: data exposure via Siebel Cloud Manager | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83076 CVE-2026-83076 | Oracle | medium 6.8 | Oracle HR Intelligence: denial of service via Internal Operations | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83077 CVE-2026-83077 | Oracle | medium 6.4 | Siebel CRM Cloud Applications: data tampering via Siebel Cloud Manager | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83078 CVE-2026-83078 | Oracle | high 8.2 | Siebel CRM Cloud Applications: data tampering via Siebel Cloud Manager | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83079 CVE-2026-83079 | Oracle | high 7.9 | Siebel CRM Cloud Applications: data tampering via Siebel Cloud Manager | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83080 CVE-2026-83080 | Oracle | high 7.1 | Oracle Banking Branch: takeover via Reports | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83081 CVE-2026-83081 | Oracle | high 8.0 | Oracle Banking Corporate Lending: data tampering via Core | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83082 CVE-2026-83082 | Oracle | high 7.2 | Oracle Marketing: takeover via Audience | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83071 CVE-2026-83071 | Oracle | high 7.8 | Oracle Business Intelligence Enterprise Edition: takeover via Machine Learning | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83072 CVE-2026-83072 | Oracle | high 8.1 | Oracle Applications Framework: data tampering via Search Bean [Incl. Advanced] | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83073 CVE-2026-83073 | Oracle | high 8.1 | Siebel CRM Cloud Applications: data tampering via Siebel Cloud Manager | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83063 CVE-2026-83063 | Oracle | high 7.2 | Oracle Internet Directory: takeover via OID LDAP Server | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83064 CVE-2026-83064 | Oracle | critical 9.1 | Oracle WebCenter Portal: takeover via Runtime Tools | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83065 CVE-2026-83065 | Oracle | high 7.5 | Oracle WebCenter Portal: takeover via Runtime Tools | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83066 CVE-2026-83066 | Oracle | critical 9.8 | Oracle Internet Directory: takeover via OID LDAP Server | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83067 CVE-2026-83067 | Oracle | high 8.1 | Oracle JDeveloper: denial of service via ADF Shared Components | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83068 CVE-2026-83068 | Oracle | high 7.7 | Oracle Enterprise Manager for Oracle Database: data exposure via Core | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83069 CVE-2026-83069 | Oracle | high 8.8 | Oracle Fusion Middleware Control: takeover via Framework | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83070 CVE-2026-83070 | Oracle | high 7.7 | PeopleSoft Enterprise PRTL Interaction Hub: data exposure via Enterprise Portal | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83054 CVE-2026-83054 | Oracle | critical 9.8 | Oracle Internet Directory: takeover via OID LDAP Server | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83055 CVE-2026-83055 | Oracle | critical 9.9 | Oracle Internet Directory: takeover via OID LDAP Server | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83056 CVE-2026-83056 | Oracle | critical 9.9 | Oracle Internet Directory: takeover via OID LDAP Server | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83057 CVE-2026-83057 | Oracle | critical 9.9 | Oracle Internet Directory: takeover via OID LDAP Server | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83058 CVE-2026-83058 | Oracle | critical 9.9 | Oracle Internet Directory: takeover via OID LDAP Server | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83059 CVE-2026-83059 | Oracle | critical 10.0 | Oracle Internet Directory: takeover via OID LDAP Server | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83060 CVE-2026-83060 | Oracle | critical 9.8 | Oracle Internet Directory: takeover via OID LDAP Server | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83061 CVE-2026-83061 | Oracle | critical 9.8 | Oracle Internet Directory: takeover via OID LDAP Server | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83062 CVE-2026-83062 | Oracle | critical 9.8 | Oracle Internet Directory: takeover via OID LDAP Server | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83046 CVE-2026-83046 | Oracle | high 7.1 | Oracle WebCenter Portal: data exposure via Runtime Tools | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83047 CVE-2026-83047 | Oracle | high 8.2 | Oracle WebCenter Portal: data tampering via Runtime Tools | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83048 CVE-2026-83048 | Oracle | high 7.7 | Oracle WebCenter Portal: data exposure via Runtime Tools | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83049 CVE-2026-83049 | Oracle | high 8.5 | Oracle WebCenter Portal: data tampering via Security Framework | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83050 CVE-2026-83050 | Oracle | high 7.1 | Oracle WebCenter Portal: data tampering via Runtime Tools | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83051 CVE-2026-83051 | Oracle | high 7.5 | Oracle WebCenter Portal: data exposure via Runtime Tools | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83052 CVE-2026-83052 | Oracle | high 7.6 | Oracle WebCenter Portal: data tampering via Runtime Tools | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83053 CVE-2026-83053 | Oracle | high 8.8 | Oracle WebCenter Portal: takeover via Runtime Tools | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83037 CVE-2026-83037 | Oracle | critical 9.8 | Oracle WebCenter Sites: takeover via WebCenter Sites | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83038 CVE-2026-83038 | Oracle | critical 9.9 | Oracle WebLogic Server: takeover via TopLink Integration | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83039 CVE-2026-83039 | Oracle | critical 9.9 | Oracle WebCenter Portal: takeover via Composer | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83040 CVE-2026-83040 | Oracle | critical 9.6 | Oracle WebCenter Portal: takeover via Portlet Services | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83041 CVE-2026-83041 | Oracle | high 7.7 | Oracle WebCenter Portal: data exposure via Portlet Services | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83042 CVE-2026-83042 | Oracle | critical 9.8 | Oracle Identity Manager: takeover via OIM Legacy UI | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83043 CVE-2026-83043 | Oracle | critical 9.6 | Oracle WebCenter Portal: takeover via Composer | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83044 CVE-2026-83044 | Oracle | high 7.1 | Oracle XML Gateway: data exposure via Install | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83045 CVE-2026-83045 | Oracle | high 8.5 | Oracle WebCenter Portal: data tampering via Runtime Tools | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83029 CVE-2026-83029 | Oracle | critical 9.6 | Oracle Managed File Transfer: data tampering via MFT Runtime Server | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83030 CVE-2026-83030 | Oracle | high 8.3 | Oracle Managed File Transfer: denial of service via MFT Runtime Server | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83031 CVE-2026-83031 | Oracle | critical 9.9 | Oracle WebCenter Sites: takeover via WebCenter Sites | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83032 CVE-2026-83032 | Oracle | high 8.8 | Oracle WebCenter Sites: takeover via WebCenter Sites | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83033 CVE-2026-83033 | Oracle | high 8.8 | Oracle WebCenter Sites: takeover via WebCenter Sites | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83034 CVE-2026-83034 | Oracle | high 7.5 | Oracle WebCenter Sites: data exposure via WebCenter Sites | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83035 CVE-2026-83035 | Oracle | critical 9.8 | Oracle WebCenter Sites: takeover via WebCenter Sites | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83036 CVE-2026-83036 | Oracle | critical 9.8 | Oracle WebCenter Sites: takeover via WebCenter Sites | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83022 CVE-2026-83022 | Oracle | high 7.9 | Oracle WebCenter Enterprise Capture: takeover via Client Bundle | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83023 CVE-2026-83023 | Oracle | high 8.6 | Oracle Identity Manager Connector: data exposure via Core | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83024 CVE-2026-83024 | Oracle | high 7.8 | Oracle Identity Manager Connector: takeover via Core | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83025 CVE-2026-83025 | Oracle | high 8.7 | Oracle Identity Manager Connector: data tampering via Core | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83026 CVE-2026-83026 | Oracle | high 8.3 | Oracle Identity Manager Connector: takeover via Core | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83027 CVE-2026-83027 | Oracle | critical 9.3 | Oracle Identity Manager Connector: data tampering via Core | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83028 CVE-2026-83028 | Oracle | high 7.5 | Oracle Identity Manager Connector: takeover via Core | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83020 CVE-2026-83020 | Oracle | critical 10.0 | Oracle Platform Security for Java: takeover via Centralized Thirdparty Jars | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83021 CVE-2026-83021 | Oracle | critical 10.0 | Oracle WebLogic Server: takeover via Web Container | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83013 CVE-2026-83013 | Oracle | high 8.8 | Oracle WebCenter Enterprise Capture: takeover via Client Bundle | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83014 CVE-2026-83014 | Oracle | high 8.1 | PeopleSoft Enterprise PeopleTools: denial of service via Cube Manager | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83015 CVE-2026-83015 | Oracle | high 7.0 | PeopleSoft Enterprise PeopleTools: takeover via Cube Manager | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83016 CVE-2026-83016 | Oracle | high 7.2 | PeopleSoft Enterprise PeopleTools: takeover via SQR | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83017 CVE-2026-83017 | Oracle | high 8.8 | PeopleSoft Enterprise PeopleTools: takeover via Report Distribution | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83018 CVE-2026-83018 | Oracle | high 7.8 | PeopleSoft Enterprise PeopleTools: takeover via SQR | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83019 CVE-2026-83019 | Oracle | high 8.1 | PeopleSoft Enterprise PeopleTools: denial of service via SQR | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83004 CVE-2026-83004 | Oracle | high 7.2 | Oracle WebCenter Enterprise Capture: data tampering via Client Bundle | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83005 CVE-2026-83005 | Oracle | high 8.8 | Oracle WebCenter Enterprise Capture: takeover via Client Bundle | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83006 CVE-2026-83006 | Oracle | critical 9.1 | Oracle WebCenter Enterprise Capture: takeover via Client Bundle | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83007 CVE-2026-83007 | Oracle | high 8.5 | Oracle WebCenter Enterprise Capture: data tampering via Client Bundle | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83008 CVE-2026-83008 | Oracle | high 8.8 | Oracle WebCenter Enterprise Capture: takeover via Client Bundle | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83009 CVE-2026-83009 | Oracle | high 8.8 | Oracle WebCenter Enterprise Capture: takeover via Client Bundle | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83010 CVE-2026-83010 | Oracle | high 8.1 | Oracle WebCenter Enterprise Capture: data tampering via Client Bundle | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83011 CVE-2026-83011 | Oracle | high 8.1 | Oracle Platform Security for Java: takeover via Centralized Thirdparty Jars | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83012 CVE-2026-83012 | Oracle | high 7.7 | Oracle WebCenter Enterprise Capture: data exposure via Client Bundle | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-82995 CVE-2026-82995 | Oracle | critical 9.8 | Oracle Platform Security for Java: takeover via Centralized Thirdparty Jars | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-82996 CVE-2026-82996 | Oracle | high 7.8 | Oracle Platform Security for Java: takeover via Centralized Thirdparty Jars | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-82997 CVE-2026-82997 | Oracle | critical 9.9 | Service Delivery Platform: takeover via Messaging Enabler | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-82998 CVE-2026-82998 | Oracle | critical 9.9 | Service Delivery Platform: takeover via Messaging Enabler | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-82999 CVE-2026-82999 | Oracle | critical 9.9 | Service Delivery Platform: takeover via Messaging Enabler | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83000 CVE-2026-83000 | Oracle | critical 9.8 | Service Delivery Platform: takeover via Messaging Enabler | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83001 CVE-2026-83001 | Oracle | critical 9.1 | Oracle Access Manager: takeover via Authentication Engine | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83002 CVE-2026-83002 | Oracle | high 8.5 | Oracle Access Manager: takeover via Authentication Engine | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-83003 CVE-2026-83003 | Oracle | high 8.5 | Oracle WebCenter Enterprise Capture: data tampering via Client Bundle | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-82992 CVE-2026-82992 | Oracle | high 7.8 | Siebel CRM Deployment: takeover via Installation | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-82993 CVE-2026-82993 | Oracle | high 8.5 | PeopleSoft Enterprise PeopleTools: data tampering via Business Interlink | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-82994 CVE-2026-82994 | Oracle | critical 9.8 | Oracle Platform Security for Java: takeover via Centralized Thirdparty Jars | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-76707 CVE-2026-76707 | Hewlett Packard Enterprise | medium 4.3 | Hewlett Packard Enterprise EdgeConnect SD-WAN Gateways: information disclosure | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US 2026-09-15 | CVE-2026-76705 CVE-2026-76705 | Hewlett Packard Enterprise | medium 5.5 | Hewlett Packard Enterprise EdgeConnect SD-WAN Gateways: buffer overflow | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US 2026-09-15 | CVE-2026-76706 CVE-2026-76706 | Hewlett Packard Enterprise | medium 5.3 | Hewlett Packard Enterprise EdgeConnect SD-WAN Gateways: information disclosure | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US 2026-09-15 | CVE-2026-76698 CVE-2026-76698 | Hewlett Packard Enterprise | medium 6.5 | Hewlett Packard Enterprise EdgeConnect SD-WAN Gateways: command injection | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US 2026-09-15 | CVE-2026-76699 CVE-2026-76699 | Hewlett Packard Enterprise | medium 6.4 | Hewlett Packard Enterprise EdgeConnect SD-WAN Gateways: buffer overflow | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US 2026-09-15 | CVE-2026-76700 CVE-2026-76700 | Hewlett Packard Enterprise | medium 5.9 | Hewlett Packard Enterprise EdgeConnect SD-WAN Gateways: denial of service | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US 2026-09-15 | CVE-2026-76701 CVE-2026-76701 | Hewlett Packard Enterprise | medium 5.9 | Hewlett Packard Enterprise EdgeConnect SD-WAN Gateways: information disclosure | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US 2026-09-15 | CVE-2026-76702 CVE-2026-76702 | Hewlett Packard Enterprise | medium 5.8 | Hewlett Packard Enterprise EdgeConnect SD-WAN Gateways: denial of service | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US 2026-09-15 | CVE-2026-76703 CVE-2026-76703 | Hewlett Packard Enterprise | medium 5.5 | Hewlett Packard Enterprise EdgeConnect SD-WAN Gateways: buffer overflow | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US 2026-09-15 | CVE-2026-76704 CVE-2026-76704 | Hewlett Packard Enterprise | medium 5.5 | Hewlett Packard Enterprise EdgeConnect SD-WAN Gateways: information disclosure | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US 2026-09-15 | CVE-2026-76696 CVE-2026-76696 | Hewlett Packard Enterprise | medium 6.5 | Hewlett Packard Enterprise EdgeConnect SD-WAN Gateways: denial of service | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US 2026-09-15 | CVE-2026-76697 CVE-2026-76697 | Hewlett Packard Enterprise | medium 6.5 | Hewlett Packard Enterprise EdgeConnect SD-WAN Gateways: information disclosure | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US 2026-09-15 | CVE-2026-76694 CVE-2026-76694 | Hewlett Packard Enterprise | medium 6.6 | Hewlett Packard Enterprise EdgeConnect SD-WAN Gateways: privilege escalation | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US 2026-09-15 | CVE-2026-76695 CVE-2026-76695 | Hewlett Packard Enterprise | medium 6.5 | Hewlett Packard Enterprise EdgeConnect SD-WAN Gateways: buffer overflow | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US 2026-09-15 | CVE-2026-76690 CVE-2026-76690 | Hewlett Packard Enterprise | high 7.2 | Hewlett Packard Enterprise EdgeConnect SD-WAN Gateways: remote code execution | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US 2026-09-15 | CVE-2026-76691 CVE-2026-76691 | Hewlett Packard Enterprise | high 7.2 | Hewlett Packard Enterprise EdgeConnect SD-WAN Gateways: buffer overflow | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US 2026-09-15 | CVE-2026-76692 CVE-2026-76692 | Hewlett Packard Enterprise | high 7.1 | Hewlett Packard Enterprise EdgeConnect SD-WAN Gateways: denial of service | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US 2026-09-15 | CVE-2026-76693 CVE-2026-76693 | Hewlett Packard Enterprise | high 7.0 | Hewlett Packard Enterprise EdgeConnect SD-WAN Gateways: denial of service | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US 2026-09-15 | CVE-2026-76681 CVE-2026-76681 | Hewlett Packard Enterprise | high 8.5 | Hewlett Packard Enterprise EdgeConnect SD-WAN Gateways: information disclosure | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US 2026-09-15 | CVE-2026-76682 CVE-2026-76682 | Hewlett Packard Enterprise | high 8.2 | Hewlett Packard Enterprise EdgeConnect SD-WAN Gateways: buffer overflow | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US 2026-09-15 | CVE-2026-76683 CVE-2026-76683 | Hewlett Packard Enterprise | high 8.1 | Hewlett Packard Enterprise EdgeConnect SD-WAN Gateways: buffer overflow | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US 2026-09-15 | CVE-2026-76684 CVE-2026-76684 | Hewlett Packard Enterprise | high 8.1 | Hewlett Packard Enterprise EdgeConnect SD-WAN Gateways: improper authentication | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US 2026-09-15 | CVE-2026-76685 CVE-2026-76685 | Hewlett Packard Enterprise | high 8.1 | Hewlett Packard Enterprise EdgeConnect SD-WAN Gateways: integer overflow | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US 2026-09-15 | CVE-2026-76686 CVE-2026-76686 | Hewlett Packard Enterprise | high 7.5 | Hewlett Packard Enterprise EdgeConnect SD-WAN Gateways: denial of service | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US 2026-09-15 | CVE-2026-76687 CVE-2026-76687 | Hewlett Packard Enterprise | high 7.5 | Hewlett Packard Enterprise EdgeConnect SD-WAN Gateways: privilege escalation | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US 2026-09-15 | CVE-2026-76688 CVE-2026-76688 | Hewlett Packard Enterprise | high 7.5 | Hewlett Packard Enterprise EdgeConnect SD-WAN Gateways: improper authentication | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US 2026-09-15 | CVE-2026-76689 CVE-2026-76689 | Hewlett Packard Enterprise | high 7.2 | Hewlett Packard Enterprise EdgeConnect SD-WAN Gateways: stack buffer overflow | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US 2026-09-15 | CVE-2026-76673 CVE-2026-76673 | Hewlett Packard Enterprise | critical 9.8 | Hewlett Packard Enterprise EdgeConnect SD-WAN Gateways: improper authentication | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US 2026-09-15 | CVE-2026-76674 CVE-2026-76674 | Hewlett Packard Enterprise | critical 9.8 | Hewlett Packard Enterprise EdgeConnect SD-WAN Gateways: buffer overflow | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US 2026-09-15 | CVE-2026-76675 CVE-2026-76675 | Hewlett Packard Enterprise | critical 9.1 | Hewlett Packard Enterprise EdgeConnect SD-WAN Gateways: command injection | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US 2026-09-15 | CVE-2026-76676 CVE-2026-76676 | Hewlett Packard Enterprise | high 8.8 | Hewlett Packard Enterprise EdgeConnect SD-WAN Gateways: buffer overflow | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US 2026-09-15 | CVE-2026-76677 CVE-2026-76677 | Hewlett Packard Enterprise | high 8.8 | Hewlett Packard Enterprise EdgeConnect SD-WAN Gateways: privilege escalation | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US 2026-09-15 | CVE-2026-76678 CVE-2026-76678 | Hewlett Packard Enterprise | high 8.8 | Hewlett Packard Enterprise EdgeConnect SD-WAN Gateways: privilege escalation | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US 2026-09-15 | CVE-2026-76679 CVE-2026-76679 | Hewlett Packard Enterprise | high 8.6 | Hewlett Packard Enterprise EdgeConnect SD-WAN Gateways: denial of service | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US 2026-09-15 | CVE-2026-76680 CVE-2026-76680 | Hewlett Packard Enterprise | high 8.5 | Hewlett Packard Enterprise EdgeConnect: server-side request forgery | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US 2026-09-15 | CVE-2026-76669 CVE-2026-76669 | Hewlett Packard Enterprise | critical 9.9 | Hewlett Packard Enterprise EdgeConnect SD-WAN Gateways: privilege escalation | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US 2026-09-15 | CVE-2026-76670 CVE-2026-76670 | Hewlett Packard Enterprise | critical 9.9 | Hewlett Packard Enterprise EdgeConnect SD-WAN Gateways: privilege escalation | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US 2026-09-15 | CVE-2026-76672 CVE-2026-76672 | Hewlett Packard Enterprise | critical 9.9 | Hewlett Packard Enterprise EdgeConnect SD-WAN Gateways: information disclosure | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US 2026-09-15 | CVE-2026-73959 CVE-2026-73959 | Oracle | high 8.8 | Oracle WebCenter Portal: takeover via Composer | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-73960 CVE-2026-73960 | Oracle | high 7.5 | PeopleSoft Enterprise PeopleTools: denial of service via Ren Server | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-73961 CVE-2026-73961 | Oracle | critical 9.8 | Oracle JDeveloper: takeover via ADF Faces | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-73962 CVE-2026-73962 | Oracle | critical 9.6 | Oracle Access Manager: data tampering via Authentication Engine | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-73963 CVE-2026-73963 | Oracle | critical 9.8 | Oracle WebCenter Portal: takeover via Portlet Services | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-73965 CVE-2026-73965 | Oracle | medium 6.8 | Siebel CRM Deployment: data tampering via Cloud Gateway | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-73966 CVE-2026-73966 | Oracle | high 7.2 | Siebel Apps - Marketing: takeover via Marketing | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-73949 CVE-2026-73949 | Oracle | high 8.8 | Oracle WebCenter Portal: takeover via Portlet Services | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-73950 CVE-2026-73950 | Oracle | critical 9.8 | Oracle Access Manager: takeover via Authentication Engine | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-73951 CVE-2026-73951 | Oracle | high 8.1 | Oracle WebCenter Portal: takeover via Portlet Services | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-73952 CVE-2026-73952 | Oracle | critical 9.1 | Oracle WebCenter Portal: data tampering via Portlet Services | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-73953 CVE-2026-73953 | Oracle | critical 9.8 | Oracle WebCenter Portal: takeover via Portlet Services | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-73954 CVE-2026-73954 | Oracle | high 8.1 | PeopleSoft Enterprise PeopleTools: takeover via Business Interlink | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-73955 CVE-2026-73955 | Oracle | high 7.3 | PeopleSoft Enterprise PeopleTools: data tampering via Charting | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-73956 CVE-2026-73956 | Oracle | critical 9.8 | Oracle WebCenter Portal: takeover via Composer | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-73957 CVE-2026-73957 | Oracle | critical 9.3 | Oracle WebCenter Portal: data tampering via Portlet Services | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-73958 CVE-2026-73958 | Oracle | high 8.1 | Oracle Access Manager: takeover via Authentication Engine | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-73941 CVE-2026-73941 | Oracle | high 8.6 | Oracle Access Manager: data exposure via Authentication Engine | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-73942 CVE-2026-73942 | Oracle | high 8.8 | Oracle Identity Manager: takeover via OIM Legacy UI | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-73943 CVE-2026-73943 | Oracle | high 7.6 | Oracle Identity Manager: data tampering via OIM Legacy UI | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-73944 CVE-2026-73944 | Oracle | critical 9.1 | Oracle Access Manager: data tampering via Authentication Engine | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-73945 CVE-2026-73945 | Oracle | critical 9.9 | Oracle Access Manager: takeover via Authentication Engine | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-73946 CVE-2026-73946 | Oracle | critical 9.1 | Oracle Access Manager: takeover via Authentication Engine | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-73947 CVE-2026-73947 | Oracle | critical 9.8 | Oracle Access Manager: takeover via Authentication Engine | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-73948 CVE-2026-73948 | Oracle | critical 9.9 | Oracle WebCenter Portal: takeover via Composer | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-73926 CVE-2026-73926 | Oracle | high 8.7 | Oracle Access Manager: data tampering via Authentication Engine | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-73940 CVE-2026-73940 | Oracle | critical 9.8 | Oracle Access Manager: takeover via Authentication Engine | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-73458 CVE-2026-73458 | Arista Networks | critical 9.2 | On affected platforms running Arista EOS with authenticated Bidirectional... | https://www.arista.com/en/support/advisories-notices/security-advisory/24710-security-advisory-0154 2026-09-15 | CVE-2026-70915 CVE-2026-70915 | Oracle | high 8.8 | Oracle Identity Manager: takeover via Core | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-71047 CVE-2026-71047 | Oracle | high 8.8 | Oracle Identity Manager: takeover via Core | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-71133 CVE-2026-71133 | Oracle | critical 10.0 | Oracle Access Manager: takeover via Authentication Engine | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-71163 CVE-2026-71163 | Oracle | critical 9.9 | Oracle Access Manager: data tampering via Authentication Engine | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-70748 CVE-2026-70748 | Oracle | critical 9.8 | Oracle WebLogic Server: takeover via Core | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-70755 CVE-2026-70755 | Oracle | medium 6.5 | Oracle Web Applications Desktop Integrator: data exposure via File download | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-70756 CVE-2026-70756 | Oracle | critical 9.8 | Oracle WebLogic Server: takeover via Core | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-70757 CVE-2026-70757 | Oracle | critical 9.8 | Oracle WebLogic Server: takeover via Core | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-70913 CVE-2026-70913 | Oracle | critical 9.8 | Oracle Identity Manager: takeover via Core | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-62597 CVE-2026-62597 | Oracle | medium 6.5 | Oracle Enterprise Manager Base Platform: data tampering via Event Management | https://www.oracle.com/security-alerts/cspusep2026.html 2026-09-15 | CVE-2026-73465 CVE-2026-73465 | Arista Networks | medium 6.0 | Arista Networks EOS: secrets in logs | https://www.arista.com/en/support/advisories-notices/security-advisory/24709-security-advisory-0153 2026-09-15 | CVE-2026-73466 CVE-2026-73466 | Arista Networks | medium 6.0 | Arista Networks EOS: secrets in logs | https://www.arista.com/en/support/advisories-notices/security-advisory/24709-security-advisory-0153 2026-09-15 | CVE-2026-73467 CVE-2026-73467 | Arista Networks | medium 6.0 | Arista Networks EOS: secrets in logs | https://www.arista.com/en/support/advisories-notices/security-advisory/24709-security-advisory-0153 2026-09-15 | CVE-2026-73451 CVE-2026-73451 | Arista Networks | medium 6.3 | On affected platforms running Arista EOS with dual switch cards and with... | https://www.arista.com/en/support/advisories-notices/security-advisory/24707-security-advisory-0151 2026-09-15 | CVE-2026-58767 CVE-2026-58767 | Google | medium 6.7 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-58773 CVE-2026-58773 | Google | medium 6.7 | Google Android: out-of-bounds write | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-58728 CVE-2026-58728 | Google | high 7.0 | Google Android: memory corruption | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-58731 CVE-2026-58731 | Google | medium 6.2 | Google Android: out-of-bounds read | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-58734 CVE-2026-58734 | Google | high 7.0 | Google Android: out-of-bounds write | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-58739 CVE-2026-58739 | Google | medium 6.7 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-58744 CVE-2026-58744 | Google | high 7.8 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-58747 CVE-2026-58747 | Google | medium 6.7 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-58751 CVE-2026-58751 | Google | medium 6.7 | Google Android: use after free | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-58755 CVE-2026-58755 | Google | medium 6.7 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-58765 CVE-2026-58765 | Google | medium 6.7 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-58766 CVE-2026-58766 | Google | high 7.8 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-58699 CVE-2026-58699 | Google | high 8.4 | Google Android: out-of-bounds read | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-58701 CVE-2026-58701 | Google | high 7.0 | Google Android: out-of-bounds write | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-58704 CVE-2026-58704 | Google | high 8.8 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-58710 CVE-2026-58710 | Google | high 8.8 | Google Android: out-of-bounds write | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-58716 CVE-2026-58716 | Google | medium 6.7 | Google Android: race condition | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-58718 CVE-2026-58718 | Google | medium 6.7 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-58721 CVE-2026-58721 | Google | medium 4.4 | Google Android: information disclosure | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-58724 CVE-2026-58724 | Google | high 7.0 | Google Android: use after free | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-58726 CVE-2026-58726 | Google | medium 6.7 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-58678 CVE-2026-58678 | Google | high 7.8 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-58679 CVE-2026-58679 | Google | high 8.4 | Google Android: buffer overflow | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-58683 CVE-2026-58683 | Google | high 8.8 | Google Android: out-of-bounds write | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-58691 CVE-2026-58691 | Google | high 8.4 | Google Android: improper input validation | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-58695 CVE-2026-58695 | Google | high 7.8 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-58698 CVE-2026-58698 | Google | medium 6.7 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-56988 CVE-2026-56988 | Google | medium 6.4 | Google Android: use after free | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-56989 CVE-2026-56989 | Google | medium 6.7 | Google Android: out-of-bounds write | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-56992 CVE-2026-56992 | Google | medium 6.7 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-56997 CVE-2026-56997 | Google | high 8.8 | Google Android: out-of-bounds write | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-57006 CVE-2026-57006 | Google | medium 4.4 | Google Android: information disclosure | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-57008 CVE-2026-57008 | Google | high 7.5 | Google Android: information disclosure | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-57012 CVE-2026-57012 | Google | high 8.4 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-57014 CVE-2026-57014 | Google | high 7.8 | Google Android: out-of-bounds write | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-57035 CVE-2026-57035 | Google | medium 6.7 | Google Android: out-of-bounds write | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-57042 CVE-2026-57042 | Google | medium 6.7 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-56970 CVE-2026-56970 | Google | high 8.4 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-56972 CVE-2026-56972 | Google | medium 6.7 | Google Android: out-of-bounds write | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-56973 CVE-2026-56973 | Google | medium 6.7 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-56974 CVE-2026-56974 | Google | high 8.8 | Google Android: out-of-bounds write | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-56975 CVE-2026-56975 | Google | medium 6.5 | Google Android: denial of service | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-56978 CVE-2026-56978 | Google | high 8.4 | Google Android: out-of-bounds read | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-56979 CVE-2026-56979 | Google | medium 6.7 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-56982 CVE-2026-56982 | Google | high 7.8 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-56985 CVE-2026-56985 | Google | high 8.4 | Google Android: type confusion | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-56986 CVE-2026-56986 | Google | high 8.4 | Google Android: out-of-bounds read | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-56923 CVE-2026-56923 | Google | medium 6.4 | Google Android: memory corruption | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-56932 CVE-2026-56932 | Google | medium 6.7 | Google Android: memory corruption | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-56941 CVE-2026-56941 | Google | high 8.4 | Google Android: use after free | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-56942 CVE-2026-56942 | Google | high 8.8 | Google Android: out-of-bounds write | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-56945 CVE-2026-56945 | Google | high 7.8 | Google Android: out-of-bounds write | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-56950 CVE-2026-56950 | Google | medium 4.4 | Google Android: information disclosure | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-56958 CVE-2026-56958 | Google | medium 5.5 | Google Android: out-of-bounds read | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-56960 CVE-2026-56960 | Google | critical 9.8 | Google Android: use after free | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-56964 CVE-2026-56964 | Google | medium 6.4 | Google Android: use after free | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-56967 CVE-2026-56967 | Google | high 8.0 | Google Android: out-of-bounds write | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-56922 CVE-2026-56922 | Google | medium 6.7 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-56914 CVE-2026-56914 | Google | high 8.4 | Google Android: use after free | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-56915 CVE-2026-56915 | Google | medium 6.4 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-56920 CVE-2026-56920 | Google | high 8.8 | Google Android: out-of-bounds write | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-56882 CVE-2026-56882 | Google | high 8.8 | Google Android: information disclosure | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-56888 CVE-2026-56888 | Google | medium 6.2 | Google Android: information disclosure | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-56889 CVE-2026-56889 | Google | medium 6.7 | Google Android: integer overflow | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-56892 CVE-2026-56892 | Google | medium 6.2 | Google Android: information disclosure | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-56907 CVE-2026-56907 | Google | medium 6.7 | Google Android: improper input validation | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-56879 CVE-2026-56879 | Google | medium 6.7 | Google Android: memory corruption | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-56881 CVE-2026-56881 | Google | high 8.4 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-55365 CVE-2026-55365 | Google | medium 6.7 | Google Android: out-of-bounds write | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-55366 CVE-2026-55366 | Google | critical 9.8 | Google Android: authentication bypass | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-55306 CVE-2026-55306 | Google | high 7.5 | Google Android: denial of service | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-55317 CVE-2026-55317 | Google | medium 6.7 | Google Android: out-of-bounds write | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-55318 CVE-2026-55318 | Google | high 8.8 | Google Android: use after free | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-55323 CVE-2026-55323 | Google | high 7.8 | Google Android: out-of-bounds write | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-55331 CVE-2026-55331 | Google | high 8.8 | Google Android: out-of-bounds write | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-55332 CVE-2026-55332 | Google | medium 6.7 | Google Android: out-of-bounds write | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-55343 CVE-2026-55343 | Google | high 8.0 | Google Android: out-of-bounds write | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-55351 CVE-2026-55351 | Google | high 7.8 | Google Android: out-of-bounds write | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-55359 CVE-2026-55359 | Google | high 7.8 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-55301 CVE-2026-55301 | Google | high 8.4 | Google Android: out-of-bounds write | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-55302 CVE-2026-55302 | Google | medium 6.7 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-55304 CVE-2026-55304 | Google | medium 6.7 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-19641 CVE-2026-19641 | Arista Networks | medium 6.9 | Arista Networks EOS: improper output encoding | https://www.arista.com/en/support/advisories-notices/security-advisory/24708-security-advisory-0152 2026-09-15 | CVE-2026-0199 CVE-2026-0199 | Google | high 7.8 | Google Android: out-of-bounds write | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-0200 CVE-2026-0200 | Google | high 8.8 | Google Android: out-of-bounds write | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-0171 CVE-2026-0171 | Google | high 8.8 | Google Android: out-of-bounds write | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-0177 CVE-2026-0177 | Google | medium 4.4 | Google Android: out-of-bounds read | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-0179 CVE-2026-0179 | Google | medium 6.7 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-0183 CVE-2026-0183 | Google | medium 4.4 | Google Android: information disclosure | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-0186 CVE-2026-0186 | Google | medium 6.7 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-0187 CVE-2026-0187 | Google | medium 6.7 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-0189 CVE-2026-0189 | Google | high 8.4 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-0192 CVE-2026-0192 | Google | medium 6.7 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-0194 CVE-2026-0194 | Google | high 8.4 | Google Android: integer overflow | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-0197 CVE-2026-0197 | Google | medium 4.4 | Google Android: information disclosure | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-0159 CVE-2026-0159 | Google | high 8.8 | Google Android: out-of-bounds write | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-0170 CVE-2026-0170 | Google | high 8.8 | Google Android: out-of-bounds write | https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01 2026-09-15 | CVE-2026-88765 CVE-2026-88765 | GitLab | high 8.5 | GitLab: remote code execution | https://gitlab.com/gitlab-org/gitlab/-/work_items/627435 2026-09-15 | CVE-2026-85234 CVE-2026-85234 | Red Hat | high 7.5 | Red Hat tftp-hpa.: out-of-bounds read | https://access.redhat.com/security/cve/CVE-2026-85234 2026-09-15 | CVE-2026-82837 CVE-2026-82837 | GitLab | medium 5.3 | GitLab: improper authorization | https://gitlab.com/gitlab-org/gitlab/-/work_items/610136 2026-09-15 | CVE-2026-81235 CVE-2026-81235 | Dell Technologies | high 8.0 | Dell Technologies Wyse Management Suite: tampering | https://www.dell.com/support/kbdoc/en-us/000502744/dsa-2026-387-security-update-for-dell-wyse-management-suite-wms-for-multiple-vulnerabilities 2026-09-15 | CVE-2026-81236 CVE-2026-81236 | Dell Technologies | high 8.6 | Dell Technologies Wyse Management Suite: arbitrary file upload | https://www.dell.com/support/kbdoc/en-us/000502744/dsa-2026-387-security-update-for-dell-wyse-management-suite-wms-for-multiple-vulnerabilities 2026-09-15 | CVE-2026-81237 CVE-2026-81237 | Dell Technologies | medium 6.5 | Dell Technologies Wyse Management Suite: improper authentication | https://www.dell.com/support/kbdoc/en-us/000502744/dsa-2026-387-security-update-for-dell-wyse-management-suite-wms-for-multiple-vulnerabilities 2026-09-15 | CVE-2026-81238 CVE-2026-81238 | Dell Technologies | high 7.5 | Dell Technologies Wyse Management Suite: missing authentication | https://www.dell.com/support/kbdoc/en-us/000502744/dsa-2026-387-security-update-for-dell-wyse-management-suite-wms-for-multiple-vulnerabilities 2026-09-15 | CVE-2026-81239 CVE-2026-81239 | Dell Technologies | high 8.6 | Dell Technologies Wyse Management Suite: arbitrary file upload | https://www.dell.com/support/kbdoc/en-us/000502744/dsa-2026-387-security-update-for-dell-wyse-management-suite-wms-for-multiple-vulnerabilities 2026-09-15 | CVE-2026-81240 CVE-2026-81240 | Dell Technologies | high 8.6 | Dell Technologies Wyse Management Suite: arbitrary file upload | https://www.dell.com/support/kbdoc/en-us/000502744/dsa-2026-387-security-update-for-dell-wyse-management-suite-wms-for-multiple-vulnerabilities 2026-09-15 | CVE-2026-40058 CVE-2026-40058 | CrowdStrike | high 8.8 | CrowdStrike Falcon sensor for Windows: arbitrary file write | https://www.crowdstrike.com/en-us/security-advisories/cve-2026-40058/ 2026-09-15 | CVE-2026-12910 CVE-2026-12910 | GitLab | medium 5.4 | GitLab: missing authentication | https://gitlab.com/gitlab-org/gitlab/-/work_items/603742 2026-09-15 | CVE-2026-13210 CVE-2026-13210 | GitLab | high 7.7 | GitLab: improper input validation | https://gitlab.com/gitlab-org/gitlab/-/work_items/603978 2026-09-15 | CVE-2026-12751 CVE-2026-12751 | IBM | medium 5.4 | IBM Cloud Pak for Business Automation: cross-site scripting | https://www.ibm.com/support/pages/node/7285931 2026-09-15 | CVE-2026-12752 CVE-2026-12752 | IBM | high 7.1 | IBM Business Automation Workflow containers and traditional: XML external entity | https://www.ibm.com/support/pages/node/7285930 2026-09-15 | CVE-2026-12358 CVE-2026-12358 | IBM | high 7.5 | IBM Security Verify Access: denial of service | https://www.ibm.com/support/pages/node/7286188 2026-09-15 | CVE-2026-12666 CVE-2026-12666 | IBM | high 8.1 | IBM MQ: information disclosure | https://www.ibm.com/support/pages/node/7284939 2026-09-15 | CVE-2026-12667 CVE-2026-12667 | IBM | high 7.1 | IBM MQ: denial of service | https://www.ibm.com/support/pages/node/7284936 2026-09-15 | CVE-2026-12728 CVE-2026-12728 | IBM | high 8.8 | IBM MQ: code execution | https://www.ibm.com/support/pages/node/7284942 2026-09-15 | CVE-2026-12742 CVE-2026-12742 | IBM | medium 5.4 | IBM Business Automation Workflow: missing authorization | https://www.ibm.com/support/pages/node/7285930 2026-09-15 | CVE-2026-12749 CVE-2026-12749 | IBM | medium 6.4 | IBM Cloud Pak for Business Automation: cross-site scripting | https://www.ibm.com/support/pages/node/7285931 2026-09-15 | CVE-2026-12750 CVE-2026-12750 | IBM | medium 6.4 | IBM Cloud Pak for Business Automation: cross-site scripting | https://www.ibm.com/support/pages/node/7285931 2026-09-15 | CVE-2026-11927 CVE-2026-11927 | IBM | medium 6.5 | IBM Security Verify Access: injection | https://www.ibm.com/support/pages/node/7286188 2026-09-15 | CVE-2026-11928 CVE-2026-11928 | IBM | critical 9.8 | IBM Security Verify Access: buffer overflow | https://www.ibm.com/support/pages/node/7286188 2026-09-15 | CVE-2026-11929 CVE-2026-11929 | IBM | high 7.5 | IBM Security Verify Access: broken cryptography | https://www.ibm.com/support/pages/node/7286188 2026-09-15 | CVE-2026-11934 CVE-2026-11934 | IBM | high 7.2 | IBM Security Verify Access: improper authorization | https://www.ibm.com/support/pages/node/7286188 2026-09-15 | CVE-2026-12101 CVE-2026-12101 | IBM | high 8.1 | IBM Security Verify Access: administrator could execute additional commands... | https://www.ibm.com/support/pages/node/7286188 2026-09-15 | CVE-2026-12150 CVE-2026-12150 | IBM | high 7.0 | IBM MQ: denial of service | https://www.ibm.com/support/pages/node/7284911 2026-09-15 | CVE-2026-12351 CVE-2026-12351 | IBM | critical 9.8 | IBM MQ: remote code execution | https://www.ibm.com/support/pages/node/7284541 2026-09-15 | CVE-2026-12354 CVE-2026-12354 | IBM | high 7.5 | IBM MQ: code execution | https://www.ibm.com/support/pages/node/7284908 2026-09-15 | CVE-2026-12355 CVE-2026-12355 | IBM | high 8.1 | IBM MQ: information disclosure | https://www.ibm.com/support/pages/node/7284912 2026-09-15 | CVE-2026-11728 CVE-2026-11728 | IBM | high 8.1 | IBM MQ: denial of service | https://www.ibm.com/support/pages/node/7284943 2026-09-15 | CVE-2026-11729 CVE-2026-11729 | IBM | high 8.5 | IBM MQ: code execution | https://www.ibm.com/support/pages/node/7284941 2026-09-15 | CVE-2026-11864 CVE-2026-11864 | IBM | medium 6.5 | IBM Cloud Pak for Business Automation: XPath injection | https://www.ibm.com/support/pages/node/7285931 2026-09-15 | CVE-2026-11918 CVE-2026-11918 | IBM | medium 5.4 | IBM ContextForge MCP Gateway: incomplete denylist | https://www.ibm.com/support/pages/node/7285720 2026-09-15 | CVE-2026-11921 CVE-2026-11921 | IBM | critical 9.1 | IBM Security Verify Access: weakly protected credentials | https://www.ibm.com/support/pages/node/7286188 2026-09-15 | CVE-2026-11926 CVE-2026-11926 | IBM | high 7.5 | IBM Security Verify Access: denial of service | https://www.ibm.com/support/pages/node/7286188 2026-09-15 | CVE-2026-79699 CVE-2026-79699 | Red Hat | medium 4.4 | Red Hat containers/storage: link following | https://access.redhat.com/security/cve/CVE-2026-79699 2026-09-15 | CVE-2026-79705 CVE-2026-79705 | Red Hat | medium 4.5 | Red Hat buildah/copier Go: path traversal | https://access.redhat.com/security/cve/CVE-2026-79705 2026-09-15 | CVE-2026-21588 CVE-2026-21588 | Atlassian | high 7.1 | Atlassian Confluence Data Center: denial of service | https://confluence.atlassian.com/pages/viewpage.action?pageId=1822852209 2026-09-15 | CVE-2026-21586 CVE-2026-21586 | Atlassian | high 7.1 | Atlassian Confluence Data Center: improper authorization | https://confluence.atlassian.com/pages/viewpage.action?pageId=1822852209 2026-09-15 | CVE-2026-21587 CVE-2026-21587 | Atlassian | high 7.1 | Atlassian Jira Service Management Data Center: improper authorization | https://confluence.atlassian.com/pages/viewpage.action?pageId=1822852209 2026-09-15 | CVE-2026-85013 CVE-2026-85013 | Red Hat | high 7.3 | Red Hat environment-modules: command injection | https://access.redhat.com/errata/RHSA-2026:64766 2026-09-15 | CVE-2026-19407 CVE-2026-19407 | Google Cloud | high 7.7 | Google Cloud Gemini Enterprise Agent Platform SDK: remote code execution | https://docs.cloud.google.com/gemini-enterprise-agent-platform/release-notes#March_31_2026 2026-09-15 | GHSA-x24p-wj69-446q CVE-2026-88030 | MongoDB | medium 6.1 | RUBY-3941 Require exact match when reading/writing GridFS via ID | https://github.com/mongodb/mongo-ruby-driver/security/advisories/GHSA-x24p-wj69-446q 2026-09-15 | GHSA-8fvv-fgr5-f8ch CVE-2026-88029 | MongoDB | medium 6.1 | PYTHON-5994 Use exact match for file ID in GridFS delete methods | https://github.com/mongodb/mongo-python-driver/security/advisories/GHSA-8fvv-fgr5-f8ch 2026-09-15 | CVE-2026-90439 CVE-2026-90439 | F5 | medium 6.9 | F5 NGINX: buffer overflow | https://my.f5.com/manage/s/article/K000162604 2026-09-15 | CVE-2026-63695 CVE-2026-63695 | Dell Technologies | critical 9.8 | Dell Technologies SmartFabric OS10 Software: session fixation | https://www.dell.com/support/kbdoc/en-us/000507473/dsa-2026-343-security-update-for-dell-networking-os10-vulnerabilities 2026-09-15 | CVE-2026-63696 CVE-2026-63696 | Dell Technologies | critical 9.1 | Dell Technologies SmartFabric OS10 Software: remote code execution | https://www.dell.com/support/kbdoc/en-us/000507473/dsa-2026-343-security-update-for-dell-networking-os10-vulnerabilities 2026-09-15 | CVE-2026-77179 CVE-2026-77179 | Docker | critical 9.4 | Docker Sandboxes: code execution | https://docs.docker.com/ai/sandboxes/ 2026-09-15 | CVE-2026-91926 CVE-2026-91926 | Red Hat | low 3.7 | Red Hat Enterprise Linux 8: denial of service | https://access.redhat.com/security/cve/CVE-2026-91926 2026-09-15 | CVE-2026-91786 CVE-2026-91786 | Red Hat | medium 6.1 | Red Hat GNOME Shell.: out-of-bounds read | https://access.redhat.com/security/cve/CVE-2026-91786 2026-09-15 | CVE-2026-59341 CVE-2026-59341 | VMware | medium 4.2 | VMware sealed-secrets: observable discrepancy | https://github.com/bitnami/sealed-secrets 2026-09-15 | CVE-2026-91826 CVE-2026-91826 | Samsung | medium 4.4 | Samsung rLottie: stack buffer overflow | https://github.com/Samsung/rlottie/pull/607 2026-09-15 | CVE-2026-75092 CVE-2026-75092 | Red Hat | high 7.3 | Red Hat Enterprise Linux 8: privilege escalation | https://access.redhat.com/errata/RHSA-2026:67608 2026-09-15 | CVE-2026-81303 CVE-2026-81303 | Red Hat | medium 6.3 | A flaw was found in hawtio-operator | https://access.redhat.com/security/cve/CVE-2026-81303 2026-09-15 | CVE-2026-81320 CVE-2026-81320 | Red Hat | medium 5.5 | Red Hat build of Apache Camel - HawtIO 4: secrets in logs | https://access.redhat.com/security/cve/CVE-2026-81320 2026-09-14 | CVE-2026-77191 CVE-2026-77191 | Arista Networks | low 2.1 | Arista Networks EOS: missing authorization | https://www.arista.com/en/support/advisories-notices/security-advisory/24706-security-advisory-0150 2026-09-14 | CVE-2026-75943 CVE-2026-75943 | Arista Networks | low 2.1 | Arista Networks EOS: incomplete cleanup | https://www.arista.com/en/support/advisories-notices/security-advisory/24706-security-advisory-0150 2026-09-14 | CVE-2026-75944 CVE-2026-75944 | Arista Networks | medium 5.6 | Arista Networks EOS: race condition | https://www.arista.com/en/support/advisories-notices/security-advisory/24706-security-advisory-0150 2026-09-14 | CVE-2026-75945 CVE-2026-75945 | Arista Networks | low 2.1 | Arista Networks EOS: race condition | https://www.arista.com/en/support/advisories-notices/security-advisory/24706-security-advisory-0150 2026-09-14 | CVE-2026-13265 CVE-2026-13265 | IBM | medium 6.8 | IBM MQ: information disclosure | https://www.ibm.com/support/pages/node/7284895 2026-09-14 | CVE-2026-73449 CVE-2026-73449 | Arista Networks | medium 5.9 | Arista Networks EOS: improper access control | https://www.arista.com/en/support/advisories-notices/security-advisory/24705-security-advisory-0149 2026-09-14 | CVE-2026-12756 CVE-2026-12756 | IBM | high 7.1 | IBM Business Automation Workflow containers and traditional: XML external entity | https://www.ibm.com/support/pages/node/7285930 2026-09-14 | CVE-2026-12758 CVE-2026-12758 | IBM | medium 5.4 | IBM Cloud Pak for Business Automation: missing authorization | https://www.ibm.com/support/pages/node/7285931 2026-09-14 | CVE-2026-12759 CVE-2026-12759 | IBM | medium 6.5 | IBM Cloud Pak for Business Automation: denial of service | https://www.ibm.com/support/pages/node/7285931 2026-09-14 | CVE-2026-12944 CVE-2026-12944 | IBM | critical 9.6 | IBM Langflow OSS: server-side request forgery | https://www.ibm.com/support/pages/node/7278919 2026-09-14 | CVE-2026-86902 CVE-2026-86902 | Apple | medium 5.5 | Apple macOS: path traversal | https://support.apple.com/en-us/128072 2026-09-14 | CVE-2026-86903 CVE-2026-86903 | Apple | medium 5.5 | Apple iOS and iPadOS: out-of-bounds read | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-86904 CVE-2026-86904 | Apple | high 7.5 | A privacy issue was addressed with improved state management | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-86905 CVE-2026-86905 | Apple | medium 5.5 | Apple iOS and iPadOS: improper access control | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-86909 CVE-2026-86909 | Apple | medium 4.4 | Apple macOS: protection mechanism failure | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-86910 CVE-2026-86910 | Apple | medium 5.5 | Apple macOS: path traversal | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-86911 CVE-2026-86911 | Apple | medium 5.5 | Apple macOS: clickjacking | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-86917 CVE-2026-86917 | Apple | high 7.8 | Apple macOS: privilege escalation | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-86924 CVE-2026-86924 | Apple | medium 5.5 | Apple iOS and iPadOS: memory corruption | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-86891 CVE-2026-86891 | Apple | low 3.5 | Apple macOS: improper authorization | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-86892 CVE-2026-86892 | Apple | medium 5.5 | Apple iOS and iPadOS: denial of service | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-86893 CVE-2026-86893 | Apple | low 3.3 | Apple iOS and iPadOS: improper privilege management | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-86894 CVE-2026-86894 | Apple | high 7.5 | Apple macOS: protection mechanism failure | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-86895 CVE-2026-86895 | Apple | high 7.5 | Apple iOS and iPadOS: information disclosure | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-86897 CVE-2026-86897 | Apple | medium 5.5 | Apple Safari: missing authorization | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-86898 CVE-2026-86898 | Apple | medium 5.4 | Apple Safari: cross-site scripting | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-86900 CVE-2026-86900 | Apple | medium 6.5 | Apple macOS: out-of-bounds read | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-86901 CVE-2026-86901 | Apple | high 7.1 | Apple macOS: out-of-bounds write | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-86881 CVE-2026-86881 | Apple | critical 9.1 | Apple iOS and iPadOS: improper certificate validation | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-86882 CVE-2026-86882 | Apple | medium 6.5 | Apple iOS and iPadOS: out-of-bounds write | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-86883 CVE-2026-86883 | Apple | medium 5.5 | Apple iOS and iPadOS: information disclosure | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-86884 CVE-2026-86884 | Apple | medium 5.5 | Apple iOS and iPadOS: improper privilege management | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-86885 CVE-2026-86885 | Apple | medium 6.5 | Apple iOS and iPadOS: improper input validation | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-86886 CVE-2026-86886 | Apple | medium 5.5 | Apple iOS and iPadOS: path traversal | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-86887 CVE-2026-86887 | Apple | low 3.3 | Apple iOS and iPadOS: information disclosure | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-86888 CVE-2026-86888 | Apple | low 3.3 | Apple iOS and iPadOS: improper privilege management | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-86889 CVE-2026-86889 | Apple | medium 4.8 | Apple macOS: improper certificate validation | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-86890 CVE-2026-86890 | Apple | medium 4.6 | Apple iOS and iPadOS: improper authentication | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84631 CVE-2026-84631 | Apple | high 7.8 | Apple macOS: privilege escalation | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84632 CVE-2026-84632 | Apple | high 7.3 | Apple iOS and iPadOS: memory corruption | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84635 CVE-2026-84635 | Apple | medium 6.5 | Apple Safari: type confusion | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84636 CVE-2026-84636 | Apple | medium 5.5 | Apple iOS and iPadOS: improper authorization | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-86869 CVE-2026-86869 | Apple | medium 6.5 | Apple iOS and iPadOS: out-of-bounds write | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-86870 CVE-2026-86870 | Apple | medium 6.5 | Apple iOS and iPadOS: buffer overflow | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-86876 CVE-2026-86876 | Apple | medium 5.2 | Apple iOS and iPadOS: out-of-bounds write | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-86878 CVE-2026-86878 | Apple | medium 5.5 | Apple iOS and iPadOS: information disclosure | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-86879 CVE-2026-86879 | Apple | medium 6.5 | Apple iOS and iPadOS: denial of service | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84621 CVE-2026-84621 | Apple | medium 5.5 | Apple iOS and iPadOS: improper access control | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84622 CVE-2026-84622 | Apple | medium 6.2 | Apple iOS and iPadOS: uninitialized resource | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84623 CVE-2026-84623 | Apple | high 7.5 | Apple iOS and iPadOS: improper authentication | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84624 CVE-2026-84624 | Apple | medium 5.5 | Apple iOS and iPadOS: path traversal | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84625 CVE-2026-84625 | Apple | critical 9.1 | Apple iOS and iPadOS: information disclosure | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84626 CVE-2026-84626 | Apple | low 3.3 | Apple iOS and iPadOS: information disclosure | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84628 CVE-2026-84628 | Apple | medium 5.5 | Apple iOS and iPadOS: improper authorization | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84629 CVE-2026-84629 | Apple | high 7.5 | Apple iOS and iPadOS: missing authorization | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84630 CVE-2026-84630 | Apple | medium 4.7 | Apple iOS and iPadOS: race condition | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84607 CVE-2026-84607 | Apple | high 7.8 | Apple iOS and iPadOS: race condition | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84609 CVE-2026-84609 | Apple | critical 9.8 | Apple iOS and iPadOS: buffer overflow | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84611 CVE-2026-84611 | Apple | high 7.3 | Apple iOS and iPadOS: out-of-bounds write | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84612 CVE-2026-84612 | Apple | medium 5.5 | Apple iOS and iPadOS: improper access control | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84615 CVE-2026-84615 | Apple | medium 5.5 | Apple iOS and iPadOS: improper authorization | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84616 CVE-2026-84616 | Apple | medium 5.5 | Apple iOS and iPadOS: type confusion | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84617 CVE-2026-84617 | Apple | medium 5.5 | Apple iOS and iPadOS: improper authorization | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84618 CVE-2026-84618 | Apple | medium 5.5 | Apple macOS: improper authorization | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84619 CVE-2026-84619 | Apple | medium 6.1 | Apple macOS: out-of-bounds write | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84620 CVE-2026-84620 | Apple | high 7.3 | Apple iOS and iPadOS: integer overflow | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84593 CVE-2026-84593 | Apple | medium 5.5 | Apple iOS and iPadOS: use after free | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84596 CVE-2026-84596 | Apple | medium 6.5 | Apple iOS and iPadOS: out-of-bounds read | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84597 CVE-2026-84597 | Apple | medium 6.5 | Apple iOS and iPadOS: out-of-bounds read | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84598 CVE-2026-84598 | Apple | high 7.5 | Apple iOS and iPadOS: path traversal | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84600 CVE-2026-84600 | Apple | medium 5.4 | Apple iOS and iPadOS: improper authorization | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84601 CVE-2026-84601 | Apple | medium 5.5 | Apple macOS: improper authorization | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84602 CVE-2026-84602 | Apple | medium 5.5 | Apple iOS and iPadOS: type confusion | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84603 CVE-2026-84603 | Apple | medium 5.5 | Apple iOS and iPadOS: improper privilege management | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84606 CVE-2026-84606 | Apple | high 7.5 | Apple iOS and iPadOS: improper authentication | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84578 CVE-2026-84578 | Apple | high 8.8 | Apple macOS: protection mechanism failure | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84580 CVE-2026-84580 | Apple | high 8.4 | Apple macOS: missing authorization | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84581 CVE-2026-84581 | Apple | high 8.4 | Apple macOS: buffer overflow | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84583 CVE-2026-84583 | Apple | medium 5.5 | Apple iOS and iPadOS: information disclosure | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84584 CVE-2026-84584 | Apple | high 8.4 | Apple macOS: link following | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84585 CVE-2026-84585 | Apple | medium 5.5 | Apple macOS: improper access control | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84586 CVE-2026-84586 | Apple | medium 5.5 | Apple macOS: information disclosure | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84587 CVE-2026-84587 | Apple | medium 5.5 | Apple macOS: improper privilege management | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84588 CVE-2026-84588 | Apple | medium 6.5 | Apple macOS: memory corruption | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84589 CVE-2026-84589 | Apple | medium 5.5 | Apple macOS: improper authorization | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84568 CVE-2026-84568 | Apple | high 7.8 | Apple macOS: path traversal | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84569 CVE-2026-84569 | Apple | medium 5.5 | Apple macOS: missing authorization | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84570 CVE-2026-84570 | Apple | medium 4.4 | Apple macOS: protection mechanism failure | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84571 CVE-2026-84571 | Apple | medium 4.3 | Apple iOS and iPadOS: buffer overflow | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84572 CVE-2026-84572 | Apple | high 7.1 | Apple macOS: out-of-bounds read | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84573 CVE-2026-84573 | Apple | medium 5.5 | Apple macOS: improper access control | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84574 CVE-2026-84574 | Apple | medium 4.4 | Apple macOS: improper access control | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84575 CVE-2026-84575 | Apple | high 7.8 | Apple iOS and iPadOS: out-of-bounds write | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84576 CVE-2026-84576 | Apple | medium 5.5 | Apple macOS: information disclosure | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84577 CVE-2026-84577 | Apple | high 8.2 | Apple macOS: buffer overflow | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84560 CVE-2026-84560 | Apple | medium 6.1 | Apple iOS and iPadOS: improper authorization | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84561 CVE-2026-84561 | Apple | critical 9.8 | Apple iOS and iPadOS: double free | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84562 CVE-2026-84562 | Apple | medium 4.7 | Apple macOS: race condition | https://support.apple.com/en-us/128067 2026-09-14 | CVE-2026-84563 CVE-2026-84563 | Apple | high 7.5 | Apple macOS: type confusion | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84564 CVE-2026-84564 | Apple | medium 4.3 | An uninitialized memory issue was addressed with improved memory initialization | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84565 CVE-2026-84565 | Apple | high 7.1 | Apple macOS: out-of-bounds read | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84566 CVE-2026-84566 | Apple | high 7.8 | Apple iOS and iPadOS: memory corruption | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84567 CVE-2026-84567 | Apple | medium 5.5 | Apple macOS: memory corruption | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84549 CVE-2026-84549 | Apple | high 7.5 | Apple macOS: out-of-bounds read | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84550 CVE-2026-84550 | Apple | medium 4.7 | Apple macOS: race condition | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84551 CVE-2026-84551 | Apple | medium 4.4 | Apple iOS and iPadOS: missing authorization | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84552 CVE-2026-84552 | Apple | medium 5.5 | Apple iOS and iPadOS: out-of-bounds read | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84553 CVE-2026-84553 | Apple | high 7.5 | Apple macOS: resource exhaustion | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84554 CVE-2026-84554 | Apple | medium 5.9 | Apple macOS: integer overflow | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84555 CVE-2026-84555 | Apple | medium 5.5 | Apple macOS: improper access control | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84556 CVE-2026-84556 | Apple | medium 5.5 | Apple macOS: improper access control | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84558 CVE-2026-84558 | Apple | medium 5.5 | Apple macOS: double free | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84559 CVE-2026-84559 | Apple | medium 5.5 | Apple macOS: protection mechanism failure | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84536 CVE-2026-84536 | Apple | medium 6.5 | Apple macOS: integer overflow | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84537 CVE-2026-84537 | Apple | medium 6.6 | Apple macOS: memory corruption | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84538 CVE-2026-84538 | Apple | medium 6.5 | Apple macOS: denial of service | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84540 CVE-2026-84540 | Apple | medium 5.5 | Apple macOS: improper authorization | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84541 CVE-2026-84541 | Apple | medium 5.5 | Apple macOS: path traversal | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84543 CVE-2026-84543 | Apple | high 7.5 | Apple macOS: out-of-bounds read | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84544 CVE-2026-84544 | Apple | high 7.5 | Apple macOS: integer overflow | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84546 CVE-2026-84546 | Apple | high 8.4 | Apple iOS and iPadOS: out-of-bounds write | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84548 CVE-2026-84548 | Apple | high 7.1 | Apple macOS: integer overflow | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84525 CVE-2026-84525 | Apple | medium 5.5 | Apple macOS: secrets in logs | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84526 CVE-2026-84526 | Apple | medium 4.3 | Apple iOS and iPadOS: out-of-bounds write | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84527 CVE-2026-84527 | Apple | medium 5.5 | Apple iOS and iPadOS: secrets in logs | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84530 CVE-2026-84530 | Apple | low 3.3 | Apple iOS and iPadOS: information disclosure | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84531 CVE-2026-84531 | Apple | medium 6.2 | Apple iOS and iPadOS: out-of-bounds write | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84532 CVE-2026-84532 | Apple | medium 5.4 | Apple iOS and iPadOS: out-of-bounds read | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84533 CVE-2026-84533 | Apple | medium 5.3 | A cryptographic issue was addressed with improved integrity checks | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84534 CVE-2026-84534 | Apple | medium 5.5 | Apple iOS and iPadOS: path traversal | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84535 CVE-2026-84535 | Apple | high 8.2 | Apple macOS: improper access control | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84515 CVE-2026-84515 | Apple | high 7.8 | Apple macOS: out-of-bounds write | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84516 CVE-2026-84516 | Apple | high 8.1 | Apple macOS: out-of-bounds read | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84517 CVE-2026-84517 | Apple | medium 5.5 | Apple macOS: integer overflow | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84518 CVE-2026-84518 | Apple | medium 4.3 | This issue was addressed through improved state management | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84519 CVE-2026-84519 | Apple | medium 6.5 | Apple iOS and iPadOS: out-of-bounds write | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84520 CVE-2026-84520 | Apple | critical 9.8 | Apple macOS: buffer overflow | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84521 CVE-2026-84521 | Apple | medium 5.5 | Apple iOS and iPadOS: use after free | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84522 CVE-2026-84522 | Apple | medium 5.9 | Apple macOS: race condition | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84523 CVE-2026-84523 | Apple | medium 5.5 | Apple iOS and iPadOS: out-of-bounds write | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84524 CVE-2026-84524 | Apple | medium 4.3 | Apple iOS and iPadOS: out-of-bounds read | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84505 CVE-2026-84505 | Apple | high 7.8 | Apple macOS: out-of-bounds write | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84506 CVE-2026-84506 | Apple | high 7.8 | Apple macOS: use after free | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84507 CVE-2026-84507 | Apple | high 7.8 | Apple iOS and iPadOS: race condition | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84509 CVE-2026-84509 | Apple | medium 6.5 | Apple macOS: out-of-bounds read | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84510 CVE-2026-84510 | Apple | medium 6.5 | Apple iOS and iPadOS: buffer overflow | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84511 CVE-2026-84511 | Apple | high 7.8 | Apple iOS and iPadOS: out-of-bounds write | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84512 CVE-2026-84512 | Apple | high 8.8 | Apple macOS: buffer overflow | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84513 CVE-2026-84513 | Apple | medium 5.5 | Apple iOS and iPadOS: secrets in logs | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84514 CVE-2026-84514 | Apple | medium 5.5 | Apple macOS: missing authorization | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-84487 CVE-2026-84487 | Apple | medium 6.5 | Apple iOS and iPadOS: integer overflow | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84489 CVE-2026-84489 | Apple | medium 5.5 | Apple iOS and iPadOS: buffer overflow | https://support.apple.com/en-us/128071 2026-09-14 | CVE-2026-84491 CVE-2026-84491 | Apple | medium 5.5 | Apple iOS and iPadOS: improper access control | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84492 CVE-2026-84492 | Apple | medium 4.7 | Apple iOS and iPadOS: race condition | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-84497 CVE-2026-84497 | Apple | high 7.8 | Apple iOS and iPadOS: buffer overflow | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-65414 CVE-2026-65414 | Apple | critical 9.8 | Apple iOS and iPadOS: out-of-bounds write | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-65415 CVE-2026-65415 | Apple | high 8.1 | Apple iOS and iPadOS: race condition | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-75792 CVE-2026-75792 | IBM | medium 4.3 | IBM Sterling Secure Proxy: improper authorization | https://www.ibm.com/support/pages/node/7287369 2026-09-14 | CVE-2026-78415 CVE-2026-78415 | IBM | medium 5.4 | IBM Sterling Secure Proxy: spoofing | https://www.ibm.com/support/pages/node/7287369 2026-09-14 | CVE-2026-7884 CVE-2026-7884 | IBM | medium 5.4 | IBM Cognos Analytics: cross-site scripting | https://www.ibm.com/support/pages/node/7287209 2026-09-14 | CVE-2026-65405 CVE-2026-65405 | Apple | medium 5.5 | A memory initialization issue was addressed with improved memory handling | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-65406 CVE-2026-65406 | Apple | medium 5.5 | Apple iOS and iPadOS: protection mechanism failure | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-65407 CVE-2026-65407 | Apple | medium 5.5 | Apple iOS and iPadOS: use after free | https://support.apple.com/en-us/128066 2026-09-14 | CVE-2026-65408 CVE-2026-65408 | Apple | medium 5.5 | Apple iOS and iPadOS: integer overflow | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-65409 CVE-2026-65409 | Apple | medium 5.5 | Apple iOS and iPadOS: type confusion | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-65410 CVE-2026-65410 | Apple | high 7.5 | Apple iOS and iPadOS: resource exhaustion | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-65411 CVE-2026-65411 | Apple | medium 5.5 | Apple iOS and iPadOS: path traversal | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-65412 CVE-2026-65412 | Apple | medium 6.5 | Apple iOS and iPadOS: null pointer dereference | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-65413 CVE-2026-65413 | Apple | medium 5.5 | Apple macOS: integer overflow | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-65395 CVE-2026-65395 | Apple | medium 6.5 | Apple iOS and iPadOS: out-of-bounds write | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-65398 CVE-2026-65398 | Apple | high 7.8 | Apple iOS and iPadOS: buffer overflow | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-65399 CVE-2026-65399 | Apple | medium 4.4 | Apple iOS and iPadOS: authentication bypass by spoofing | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-65401 CVE-2026-65401 | Apple | medium 5.5 | Apple macOS: race condition | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-65402 CVE-2026-65402 | Apple | medium 5.5 | Apple iOS and iPadOS: use after free | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-65403 CVE-2026-65403 | Apple | medium 5.5 | Apple iOS and iPadOS: improper access control | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-65404 CVE-2026-65404 | Apple | medium 5.5 | Apple iOS and iPadOS: improper authorization | https://support.apple.com/en-us/128071 2026-09-14 | CVE-2026-65376 CVE-2026-65376 | Apple | medium 5.5 | Apple macOS: out-of-bounds read | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-65377 CVE-2026-65377 | Apple | medium 5.5 | Apple iOS and iPadOS: memory corruption | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-65378 CVE-2026-65378 | Apple | high 7.5 | Apple macOS: improper authorization | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-65380 CVE-2026-65380 | Apple | medium 5.5 | Apple macOS: improper authorization | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-65381 CVE-2026-65381 | Apple | critical 10.0 | Apple macOS: missing authorization | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-65382 CVE-2026-65382 | Apple | medium 5.5 | Apple macOS: path traversal | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-65383 CVE-2026-65383 | Apple | medium 4.4 | Apple macOS: improper access control | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-65390 CVE-2026-65390 | Apple | high 8.8 | Apple Safari: integer overflow | https://support.apple.com/en-us/148281 2026-09-14 | CVE-2026-65391 CVE-2026-65391 | Apple | high 8.8 | Apple Safari: out-of-bounds write | https://support.apple.com/en-us/148281 2026-09-14 | CVE-2026-65393 CVE-2026-65393 | Apple | medium 5.5 | Apple Xcode: improper authorization | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-65360 CVE-2026-65360 | Apple | medium 4.7 | Apple iOS and iPadOS: race condition | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-65361 CVE-2026-65361 | Apple | medium 5.5 | Apple macOS: improper access control | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-65362 CVE-2026-65362 | Apple | high 7.8 | Apple macOS: privilege escalation | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-65364 CVE-2026-65364 | Apple | high 7.5 | Apple macOS: out-of-bounds read | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-65365 CVE-2026-65365 | Apple | medium 6.5 | Apple macOS: out-of-bounds read | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-65369 CVE-2026-65369 | Apple | medium 5.5 | Apple macOS: protection mechanism failure | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-65371 CVE-2026-65371 | Apple | low 3.3 | Apple iOS and iPadOS: information disclosure | https://support.apple.com/en-us/128066 2026-09-14 | CVE-2026-65374 CVE-2026-65374 | Apple | high 8.8 | Apple macOS: memory corruption | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-65375 CVE-2026-65375 | Apple | high 7.5 | Apple macOS: improper authentication | https://support.apple.com/en-us/128067 2026-09-14 | CVE-2026-65352 CVE-2026-65352 | Apple | medium 4.3 | Apple iOS and iPadOS: information disclosure | https://support.apple.com/en-us/148281 2026-09-14 | CVE-2026-65353 CVE-2026-65353 | Apple | medium 5.5 | Apple iOS and iPadOS: improper authorization | https://support.apple.com/en-us/128066 2026-09-14 | CVE-2026-65354 CVE-2026-65354 | Apple | high 8.2 | Apple iOS and iPadOS: improper privilege management | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-65355 CVE-2026-65355 | Apple | medium 4.3 | Apple iOS and iPadOS: information disclosure | https://support.apple.com/en-us/148281 2026-09-14 | CVE-2026-65357 CVE-2026-65357 | Apple | high 7.8 | Apple iOS and iPadOS: buffer overflow | https://support.apple.com/en-us/128066 2026-09-14 | CVE-2026-65358 CVE-2026-65358 | Apple | medium 4.7 | Apple iOS and iPadOS: race condition | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-65359 CVE-2026-65359 | Apple | high 7.1 | Apple iOS and iPadOS: out-of-bounds read | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-65342 CVE-2026-65342 | Apple | high 7.5 | Apple macOS: missing authorization | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-65344 CVE-2026-65344 | Apple | high 7.8 | Apple iOS and iPadOS: out-of-bounds write | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-65345 CVE-2026-65345 | Apple | medium 5.5 | Apple iOS and iPadOS: improper access control | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-65348 CVE-2026-65348 | Apple | medium 5.5 | Apple iOS and iPadOS: insecure permissions | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-64790 CVE-2026-64790 | Apple | high 7.8 | Apple macOS: privilege escalation | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-64761 CVE-2026-64761 | Apple | high 7.5 | Apple iOS and iPadOS: information disclosure | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-64714 CVE-2026-64714 | Apple | medium 5.5 | Apple iOS and iPadOS: memory corruption | https://support.apple.com/en-us/128071 2026-09-14 | CVE-2026-64717 CVE-2026-64717 | Apple | medium 6.3 | Apple iOS and iPadOS: race condition | https://support.apple.com/en-us/128066 2026-09-14 | CVE-2026-64736 CVE-2026-64736 | Apple | high 7.1 | Apple iOS and iPadOS: out-of-bounds read | https://support.apple.com/en-us/148281 2026-09-14 | CVE-2026-64752 CVE-2026-64752 | Apple | high 7.3 | Apple iOS and iPadOS: memory corruption | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-64753 CVE-2026-64753 | Apple | medium 6.5 | Apple Safari: information disclosure | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-64756 CVE-2026-64756 | Apple | medium 5.5 | Apple iOS and iPadOS: path traversal | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-64701 CVE-2026-64701 | Apple | high 7.8 | Apple macOS: privilege escalation | https://support.apple.com/en-us/128067 2026-09-14 | CVE-2026-64712 CVE-2026-64712 | Apple | high 7.8 | Apple macOS: privilege escalation | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-43808 CVE-2026-43808 | Apple | medium 5.5 | Apple iOS and iPadOS: use after free | https://support.apple.com/en-us/128066 2026-09-14 | CVE-2026-43815 CVE-2026-43815 | Apple | high 8.8 | Apple macOS: buffer overflow | https://support.apple.com/en-us/128067 2026-09-14 | CVE-2026-43783 CVE-2026-43783 | Apple | high 7.8 | Apple macOS: race condition | https://support.apple.com/en-us/128067 2026-09-14 | CVE-2026-43785 CVE-2026-43785 | Apple | medium 5.5 | Apple iOS and iPadOS: improper authorization | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-43786 CVE-2026-43786 | Apple | high 7.8 | Apple macOS: privilege escalation | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-43787 CVE-2026-43787 | Apple | medium 5.9 | Apple macOS: protection mechanism failure | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-43788 CVE-2026-43788 | Apple | medium 6.6 | Apple macOS: integer overflow | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-43789 CVE-2026-43789 | Apple | high 7.5 | Apple macOS: missing authorization | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-43790 CVE-2026-43790 | Apple | critical 9.1 | Apple macOS: out-of-bounds write | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-43791 CVE-2026-43791 | Apple | medium 6.5 | Apple macOS: path traversal | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-43761 CVE-2026-43761 | Apple | medium 6.5 | Apple macOS: out-of-bounds write | https://support.apple.com/en-us/128067 2026-09-14 | CVE-2026-43762 CVE-2026-43762 | Apple | medium 5.5 | Apple iOS and iPadOS: improper access control | https://support.apple.com/en-us/128066 2026-09-14 | CVE-2026-43702 CVE-2026-43702 | Apple | high 7.8 | Apple iOS and iPadOS: memory corruption | https://support.apple.com/en-us/128066 2026-09-14 | CVE-2026-43719 CVE-2026-43719 | Apple | medium 6.5 | Apple macOS: use after free | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-43737 CVE-2026-43737 | Apple | medium 5.5 | Apple iOS and iPadOS: improper authorization | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-43741 CVE-2026-43741 | Apple | medium 5.5 | Apple macOS: improper access control | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-43687 CVE-2026-43687 | Apple | medium 6.5 | Apple iOS and iPadOS: information disclosure | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-43688 CVE-2026-43688 | Apple | high 7.8 | Apple iOS and iPadOS: memory corruption | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-43689 CVE-2026-43689 | Apple | high 7.8 | Apple iOS and iPadOS: privilege escalation | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-43690 CVE-2026-43690 | Apple | medium 4.7 | Apple macOS: race condition | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-43691 CVE-2026-43691 | Apple | high 7.8 | Apple macOS: privilege escalation | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-43692 CVE-2026-43692 | Apple | high 8.8 | Apple macOS: remote code execution | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-43695 CVE-2026-43695 | Apple | medium 5.5 | Apple iOS and iPadOS: improper authorization | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-43696 CVE-2026-43696 | Apple | medium 5.3 | Apple macOS: missing authorization | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-43697 CVE-2026-43697 | Apple | high 7.1 | Apple macOS: out-of-bounds read | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-43677 CVE-2026-43677 | Apple | medium 6.5 | Apple macOS: out-of-bounds write | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-43683 CVE-2026-43683 | Apple | high 7.1 | Apple macOS: out-of-bounds read | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-43684 CVE-2026-43684 | Apple | high 7.8 | Apple iOS and iPadOS: use after free | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-43686 CVE-2026-43686 | Apple | high 8.8 | Apple iOS and iPadOS: use after free | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-28968 CVE-2026-28968 | Apple | medium 5.5 | Apple iOS and iPadOS: out-of-bounds write | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-43664 CVE-2026-43664 | Apple | medium 5.5 | Apple iOS and iPadOS: information disclosure | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-43674 CVE-2026-43674 | Apple | medium 4.6 | Apple iOS and iPadOS: improper authentication | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-28836 CVE-2026-28836 | Apple | medium 6.1 | A correctness issue was addressed with improved checks | https://support.apple.com/en-us/128072 2026-09-14 | CVE-2026-28899 CVE-2026-28899 | Apple | medium 5.5 | Apple macOS: protection mechanism failure | https://support.apple.com/en-us/128067 2026-09-14 | CVE-2026-28933 CVE-2026-28933 | Apple | medium 5.5 | Apple macOS: use after free | https://support.apple.com/en-us/128067 2026-09-14 | CVE-2026-28934 CVE-2026-28934 | Apple | medium 6.5 | Apple macOS: buffer overflow | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-28935 CVE-2026-28935 | Apple | high 7.5 | Apple iOS and iPadOS: memory corruption | https://support.apple.com/en-us/148281 2026-09-14 | CVE-2026-28937 CVE-2026-28937 | Apple | medium 5.5 | Apple macOS: improper access control | https://support.apple.com/en-us/149035 2026-09-14 | CVE-2026-28938 CVE-2026-28938 | Apple | high 7.5 | A privacy issue was addressed by moving sensitive data | https://support.apple.com/en-us/128066 2026-09-14 | CVE-2026-28960 CVE-2026-28960 | Apple | high 7.5 | Apple iOS and iPadOS: denial of service | https://support.apple.com/en-us/148287 2026-09-14 | CVE-2026-28966 CVE-2026-28966 | Apple | medium 4.3 | Apple iOS and iPadOS: out-of-bounds write | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-18069 CVE-2026-18069 | IBM | medium 6.0 | IBM i: race condition | https://www.ibm.com/support/pages/node/7287408 2026-09-14 | CVE-2026-19086 CVE-2026-19086 | IBM | low 3.3 | IBM i: denial of service | https://www.ibm.com/support/pages/node/7287409 2026-09-14 | CVE-2026-19273 CVE-2026-19273 | IBM | medium 5.4 | IBM Sterling: improper authentication | https://www.ibm.com/support/pages/node/7287190 2026-09-14 | CVE-2026-19280 CVE-2026-19280 | IBM | medium 5.2 | IBM i: denial of service | https://www.ibm.com/support/pages/node/7287409 2026-09-14 | CVE-2026-19290 CVE-2026-19290 | IBM | high 7.5 | IBM Sterling File Gateway: information disclosure | https://www.ibm.com/support/pages/node/7287180 2026-09-14 | CVE-2026-20683 CVE-2026-20683 | Apple | high 7.1 | Apple iOS and iPadOS: improper authentication | https://support.apple.com/en-us/149034 2026-09-14 | CVE-2026-13293 CVE-2026-13293 | IBM | high 8.8 | IBM MQ: remote code execution | https://www.ibm.com/support/pages/node/7284896 2026-09-14 | CVE-2026-14275 CVE-2026-14275 | IBM | medium 6.3 | IBM i Access Family: code execution | https://www.ibm.com/support/pages/node/7287166 2026-09-14 | CVE-2026-14276 CVE-2026-14276 | IBM | medium 6.3 | IBM i Access Family: code execution | https://www.ibm.com/support/pages/node/7287166 2026-09-14 | CVE-2026-14277 CVE-2026-14277 | IBM | medium 6.3 | IBM i Access Family: code execution | https://www.ibm.com/support/pages/node/7287166 2026-09-14 | CVE-2026-13260 CVE-2026-13260 | IBM | high 7.5 | IBM Security Verify Access: denial of service | https://www.ibm.com/support/pages/node/7286188 2026-09-14 | CVE-2026-13272 CVE-2026-13272 | IBM | medium 5.4 | IBM Security Verify Access: remote attacker could perform operations as the... | https://www.ibm.com/support/pages/node/7286188 2026-09-14 | CVE-2026-13275 CVE-2026-13275 | IBM | high 7.1 | IBM MQ: server-side request forgery | https://www.ibm.com/support/pages/node/7284897 2026-09-14 | CVE-2026-13276 CVE-2026-13276 | IBM | medium 6.1 | IBM Security Verify Access: cross-site scripting | https://www.ibm.com/support/pages/node/7286188 2026-09-14 | CVE-2026-13277 CVE-2026-13277 | IBM | medium 4.7 | IBM Security Verify Access: open redirect | https://www.ibm.com/support/pages/node/7286188 2026-09-14 | CVE-2026-13285 CVE-2026-13285 | IBM | high 7.1 | IBM MQ: XML external entity | https://www.ibm.com/support/pages/node/7284940 2026-09-14 | CVE-2026-13287 CVE-2026-13287 | IBM | high 7.1 | IBM MQ: XML external entity | https://www.ibm.com/support/pages/node/7284937 2026-09-14 | CVE-2026-12763 CVE-2026-12763 | IBM | medium 4.2 | IBM Langflow OSS: missing authentication | https://www.ibm.com/support/pages/node/7286662 2026-09-14 | CVE-2026-12765 CVE-2026-12765 | IBM | medium 6.5 | IBM Langflow OSS: server-side request forgery | https://www.ibm.com/support/pages/node/7285644 2026-09-14 | CVE-2026-12766 CVE-2026-12766 | IBM | medium 5.4 | IBM Langflow OSS: server-side request forgery | https://www.ibm.com/support/pages/node/7285639 2026-09-14 | CVE-2026-12767 CVE-2026-12767 | IBM | medium 6.5 | IBM Langflow OSS: server-side request forgery | https://www.ibm.com/support/pages/node/7286665 2026-09-14 | CVE-2026-13107 CVE-2026-13107 | IBM | high 7.1 | IBM Business Automation Workflow containers and traditional: XML external entity | https://www.ibm.com/support/pages/node/7285930 2026-09-14 | CVE-2026-17467 CVE-2026-17467 | IBM | high 8.2 | IBM Cloud Pak for Data System (Yosemite 1.0): information disclosure | https://www.ibm.com/support/pages/node/7286491 2026-09-14 | CVE-2026-17628 CVE-2026-17628 | IBM | medium 5.4 | IBM Langflow OSS: improper authentication | https://www.ibm.com/support/pages/node/7286684 2026-09-14 | CVE-2026-18065 CVE-2026-18065 | IBM | medium 5.3 | IBM i: information disclosure | https://www.ibm.com/support/pages/node/7286974 2026-09-14 | CVE-2026-18251 CVE-2026-18251 | IBM | medium 4.3 | IBM i: information disclosure | https://www.ibm.com/support/pages/node/7286974 2026-09-14 | CVE-2026-16673 CVE-2026-16673 | IBM | high 8.8 | IBM DataStage on Cloud Pak for Data: command injection | https://www.ibm.com/support/pages/node/7286562 2026-09-14 | CVE-2026-16702 CVE-2026-16702 | IBM | medium 6.5 | IBM Db2: denial of service | https://www.ibm.com/support/pages/node/7286981 2026-09-14 | CVE-2026-17047 CVE-2026-17047 | IBM | medium 5.4 | IBM Db2 Mirror for i: information disclosure | https://www.ibm.com/support/pages/node/7286970 2026-09-14 | CVE-2026-17133 CVE-2026-17133 | IBM | high 7.8 | IBM App Connect Enterprise: code execution | https://www.ibm.com/support/pages/node/7286530 2026-09-14 | CVE-2026-17156 CVE-2026-17156 | IBM | high 7.8 | IBM App Connect Enterprise: code execution | https://www.ibm.com/support/pages/node/7286530 2026-09-14 | CVE-2026-17416 CVE-2026-17416 | IBM | high 7.8 | IBM App Connect Enterprise: code execution | https://www.ibm.com/support/pages/node/7286530 2026-09-14 | CVE-2026-17463 CVE-2026-17463 | IBM | medium 6.5 | IBM Db2: denial of service | https://www.ibm.com/support/pages/node/7286983 2026-09-14 | CVE-2026-16189 CVE-2026-16189 | IBM | medium 4.8 | IBM WebSphere Application Server: remote attacker could inject forged log... | https://www.ibm.com/support/pages/node/7286610 2026-09-14 | CVE-2026-16190 CVE-2026-16190 | IBM | low 3.1 | IBM WebSphere Application Server: missing authorization | https://www.ibm.com/support/pages/node/7286610 2026-09-14 | CVE-2026-16335 CVE-2026-16335 | IBM | high 8.1 | IBM DataStage on Cloud Pak for Data: path traversal | https://www.ibm.com/support/pages/node/7286562 2026-09-14 | CVE-2026-16338 CVE-2026-16338 | IBM | critical 9.9 | IBM DataStage on Cloud Pak for Data: arbitrary file write | https://www.ibm.com/support/pages/node/7286562 2026-09-14 | CVE-2026-16428 CVE-2026-16428 | IBM | high 8.8 | IBM DataStage on Cloud Pak for Data: remote code execution | https://www.ibm.com/support/pages/node/7286562 2026-09-14 | CVE-2026-16432 CVE-2026-16432 | IBM | high 7.7 | IBM DataStage on Cloud Pak for Data: information disclosure | https://www.ibm.com/support/pages/node/7286562 2026-09-14 | CVE-2026-16435 CVE-2026-16435 | IBM | medium 5.9 | IBM WebSphere Application Server: authentication bypass | https://www.ibm.com/support/pages/node/7286610 2026-09-14 | CVE-2026-16466 CVE-2026-16466 | IBM | high 8.8 | IBM DataStage on Cloud Pak for Data: remote code execution | https://www.ibm.com/support/pages/node/7286562 2026-09-14 | CVE-2026-15955 CVE-2026-15955 | IBM | high 7.5 | IBM Db2: arbitrary file write | https://www.ibm.com/support/pages/node/7286998 2026-09-14 | CVE-2026-16185 CVE-2026-16185 | IBM | medium 6.4 | IBM WebSphere Application Server: authentication bypass | https://www.ibm.com/support/pages/node/7286610 2026-09-14 | CVE-2026-16186 CVE-2026-16186 | IBM | medium 5.4 | IBM WebSphere Application Server: cross-site scripting | https://www.ibm.com/support/pages/node/7286610 2026-09-14 | CVE-2026-16187 CVE-2026-16187 | IBM | medium 6.5 | IBM WebSphere Application Server: authentication bypass | https://www.ibm.com/support/pages/node/7286610 2026-09-14 | CVE-2026-16188 CVE-2026-16188 | IBM | medium 5.3 | IBM WebSphere Application Server: remote attacker could inject forged log... | https://www.ibm.com/support/pages/node/7286610 2026-09-14 | CVE-2026-15396 CVE-2026-15396 | IBM | medium 6.5 | IBM WebSphere Application Server: request smuggling | https://www.ibm.com/support/pages/node/7286610 2026-09-14 | CVE-2026-15412 CVE-2026-15412 | IBM | medium 6.5 | IBM WebSphere Application Server: open redirect | https://www.ibm.com/support/pages/node/7286610 2026-09-14 | CVE-2026-15634 CVE-2026-15634 | IBM | medium 6.5 | IBM WebSphere Application Server: request smuggling | https://www.ibm.com/support/pages/node/7286610 2026-09-14 | CVE-2026-15887 CVE-2026-15887 | IBM | medium 5.4 | IBM WebSphere Application Server: server-side request forgery | https://www.ibm.com/support/pages/node/7286610 2026-09-14 | CVE-2026-18515 CVE-2026-18515 | IBM | medium 4.3 | IBM i: path traversal | https://www.ibm.com/support/pages/node/7286974 2026-09-14 | CVE-2026-19543 CVE-2026-19543 | IBM | medium 6.2 | IBM Common Licensing: improper input validation | https://www.ibm.com/support/pages/node/7286490 2026-09-14 | CVE-2026-18151 CVE-2026-18151 | IBM | medium 4.2 | IBM i: information disclosure | https://www.ibm.com/support/pages/node/7286974 2026-09-14 | CVE-2026-85921 CVE-2026-85921 | Microsoft | high 8.2 | Microsoft Windows 11 version 26H1: double free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85921 2026-09-14 | CVE-2026-85892 CVE-2026-85892 | Microsoft | high 7.8 | Microsoft Edge (Chromium-based): race condition | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85892 2026-09-14 | CVE-2026-76461 CVE-2026-76461 | Cisco | critical 9.8 | Cisco Secure Email: remote code execution | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX 2026-09-14 | CVE-2026-76440 CVE-2026-76440 | Cisco | critical 9.8 | Cisco Secure Email: path traversal | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm 2026-09-14 | CVE-2026-76441 CVE-2026-76441 | Cisco | critical 9.8 | Cisco Secure Email and Web Manager: improper access control | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm 2026-09-14 | CVE-2026-76442 CVE-2026-76442 | Cisco | high 7.5 | Cisco Secure Email: improper quantity validation | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm 2026-09-14 | CVE-2026-76443 CVE-2026-76443 | Cisco | critical 9.8 | As part of Cisco's ongoing commitment to proactive security and product quality | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm 2026-09-14 | CVE-2026-20353 CVE-2026-20353 | Cisco | critical 9.8 | As part of Cisco's ongoing commitment to proactive security and product quality | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm 2026-09-14 | CVE-2026-90994 CVE-2026-90994 | Red Hat | medium 4.0 | Red Hat sssd: out-of-bounds read | https://access.redhat.com/security/cve/CVE-2026-90994 2026-09-14 | CVE-2026-90995 CVE-2026-90995 | Red Hat | medium 5.5 | Red Hat Enterprise Linux 10: null pointer dereference | https://access.redhat.com/security/cve/CVE-2026-90995 2026-09-14 | CVE-2026-90996 CVE-2026-90996 | Red Hat | medium 4.0 | Red Hat sssd. A local unprivileged user: denial of service | https://access.redhat.com/security/cve/CVE-2026-90996 2026-09-14 | CVE-2026-90947 CVE-2026-90947 | Red Hat | high 7.8 | Red Hat GIMP.: out-of-bounds write | https://access.redhat.com/security/cve/CVE-2026-90947 2026-09-14 | CVE-2026-90463 CVE-2026-90463 | Red Hat | medium 4.0 | Red Hat sssd NSS responder: out-of-bounds read | https://access.redhat.com/security/cve/CVE-2026-90463 2026-09-14 | CVE-2026-59569 CVE-2026-59569 | Zscaler | high 8.1 | Zscaler Client Connector: improper input validation | https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026 2026-09-14 | CVE-2026-59570 CVE-2026-59570 | Zscaler | high 7.5 | Zscaler Client Connector: improper input validation | https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026 2026-09-14 | CVE-2026-25687 CVE-2026-25687 | Zscaler | high 8.1 | Zscaler Client Connector: race condition | https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026 2026-09-14 | CVE-2026-90948 CVE-2026-90948 | Red Hat | high 7.8 | Red Hat GIMP: integer overflow | https://access.redhat.com/security/cve/CVE-2026-90948 2026-09-14 | CVE-2026-90949 CVE-2026-90949 | Red Hat | high 7.8 | Red Hat GIMP: heap buffer overflow | https://access.redhat.com/security/cve/CVE-2026-90949 2026-09-14 | AWS-2026-112 CVE-2026-86830 | AWS | high 7.2 | Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM... | https://aws.amazon.com/security/security-bulletins/rss/2026-112-aws/ 2026-09-14 | CVE-2026-12518 CVE-2026-12518 | Logitech | high 8.5 | Logitech Logi Options+: privilege escalation | https://blog.amberwolf.com/blog/2026/september/a-peripheral-path-to-system---exploiting-logi-options+-for-system-shells/ 2026-09-12 | PYSEC-2026-3985 CVE-2026-90553 | vLLM | high 7.8 | vLLM: remote code execution | https://osv.dev/vulnerability/PYSEC-2026-3985 2026-09-12 | CVE-2026-89172 CVE-2026-89172 | Microchip | medium 5.6 | Improper protection of physical side channels vulnerability in Microchip AN1044 | https://www.microchip.com/en-us/application-notes/an1044 2026-09-12 | GHSA-h4mw-j7qp-8mwm CVE-2026-96620 | Anthropic | critical 9.2 | Argument Injection via resume Option Allows Arbitrary Command Execution | https://github.com/anthropics/claude-agent-sdk-python/security/advisories/GHSA-h4mw-j7qp-8mwm 2026-09-12 | CVE-2026-87719 CVE-2026-87719 | GitLab | critical 9.9 | GitLab: unsafe deserialization | https://gitlab.com/gitlab-org/gitlab/-/work_items/628160 2026-09-12 | CVE-2026-85706 CVE-2026-85706 | GitLab | critical 10.0 | GitLab: missing authentication | https://gitlab.com/gitlab-org/gitlab/-/work_items/627748 2026-09-11 | CVE-2026-78546 CVE-2026-78546 | Citrix | medium 4.8 | Citrix Workspace app for Windows: out-of-bounds read | https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697034&articleTitle=Citrix_Workspace_app_for_Windows_Security_Bulletin_CVE_2026_78546_and_CVE_2026_78547 2026-09-11 | CVE-2026-78547 CVE-2026-78547 | Citrix | medium 4.4 | Citrix Workspace app for Windows: out-of-bounds write | https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697034&articleTitle=Citrix_Workspace_app_for_Windows_Security_Bulletin_CVE_2026_78546_and_CVE_2026_78547 2026-09-11 | CVE-2026-77490 CVE-2026-77490 | Microsoft | medium 6.1 | Microsoft Edge (Chromium-based): cross-site scripting | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77490 2026-09-11 | CVE-2026-89329 CVE-2026-89329 | Red Hat | medium 6.2 | Red Hat Enterprise Linux 10: denial of service | https://access.redhat.com/security/cve/CVE-2026-89329 2026-09-11 | CVE-2026-89099 CVE-2026-89099 | MongoDB | high 7.7 | MongoDB Server: race condition | https://jira.mongodb.org/browse/SERVER-134063 2026-09-11 | CVE-2026-18495 CVE-2026-18495 | Red Hat | medium 6.1 | Red Hat Ceph Storage 4: buffer overflow | https://access.redhat.com/errata/RHSA-2026:53467 2026-09-11 | CVE-2026-81861 CVE-2026-81861 | Schneider Electric | medium 5.9 | Schneider Electric SCADAPack: weakly protected credentials | https://download.se.com/files?p_Doc_Ref=SEVD-2026-251-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-251-03.pdf 2026-09-11 | CVE-2026-70341 CVE-2026-70341 | Microsoft | high 8.5 | Microsoft Edge: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70341 2026-09-11 | CVE-2026-3869 CVE-2026-3869 | Schneider Electric | critical 9.2 | CWE-303 : Incorrect Implementation of Authentication Algorithm vulnerability... | https://download.se.com/files?p_Doc_Ref=SEVD-2026-251-04&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-251-04.pdf 2026-09-11 | CVE-2026-89298 CVE-2026-89298 | Red Hat | medium 4.9 | Red Hat Dynamic Client Registration service of Keycloak: information disclosure | https://access.redhat.com/security/cve/CVE-2026-89298 2026-09-11 | CVE-2026-15710 CVE-2026-15710 | Netskope | medium 6.8 | Netskope Endpoint DLP: uninitialized resource | https://www.netskope.com/resources/netskope-resources/netskope-security-advisory-nskpsa-2026-006 2026-09-11 | CVE-2026-80462 CVE-2026-80462 | Progress Software | critical 10.0 | Progress Software Chef Automate: missing authentication | https://community.progress.com/s/article/Critical-Security-Bulletin---August-2026---Chef-Automate-Security-Vulnerability 2026-09-11 | CVE-2026-84390 CVE-2026-84390 | Fortinet | critical 9.8 | Fortinet FortiMonitorOnSight: information disclosure | https://fortiguard.fortinet.com/psirt/FG-IR-26-170 2026-09-11 | AWS-2026-111 CVE-2026-89332 | AWS | medium 5.5 | Kiro IDE Sensitive Workspace Data Exfiltration via Agent-Written Workspace Configuration | https://aws.amazon.com/security/security-bulletins/rss/2026-111-aws/ 2026-09-11 | CVE-2026-77159 CVE-2026-77159 | Red Hat | medium 5.5 | A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost | https://access.redhat.com/security/cve/CVE-2026-77159 2026-09-11 | CVE-2026-47839 CVE-2026-47839 | VMware | critical 9.2 | VMware UAA: improper access control | https://www.cloudfoundry.org/blog/cve-2026-47839-federated-oidc-users-can-bypass-externalgroupswhitelist-to-gain-uaa-admin/ 2026-09-11 | AWS-2026-110 CVE-2026-89090 | AWS | medium 5.9 | Denial of service in the event stream header decoder in AWS SDK for Go v2 | https://aws.amazon.com/security/security-bulletins/rss/2026-110-aws/ 2026-09-11 | AWS-2026-109 CVE-2026-18061 | AWS | medium 5.9 | XML External Entity (XXE) in AWS Advanced JDBC Wrapper RemoteQueryCachePlugin | https://aws.amazon.com/security/security-bulletins/rss/2026-109-aws/ 2026-09-11 | CVE-2026-19486 CVE-2026-19486 | Google Cloud | high 8.7 | Google Cloud Gemini Enterprise: server-side request forgery | https://docs.cloud.google.com/gemini-enterprise-agent-platform/release-notes#July_20_2026 2026-09-11 | AWS-2026-108 CVE-2026-89065 | AWS | high 7.1 | Issue with projen - Path traversal and OS command injection | https://aws.amazon.com/security/security-bulletins/rss/2026-108-aws/ 2026-09-11 | CVE-2026-73784 CVE-2026-73784 | Hewlett Packard Enterprise | high 8.8 | Hewlett Packard Enterprise HPE IceWall products: improper signature check | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbmu05142en_us&docLocale=en_US 2026-09-11 | CVE-2026-73785 CVE-2026-73785 | Hewlett Packard Enterprise | high 7.5 | Hewlett Packard Enterprise HPE IceWall products: denial of service | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbmu05147en_us&docLocale=en_US 2026-09-11 | CVE-2026-13326 CVE-2026-13326 | Qt Group Plc | medium 6.9 | qt: out-of-bounds read | https://codereview.qt-project.org/c/qt/qtconnectivity/+/743136 2026-09-11 | GHSA-jxxg-hqjr-9h33 CVE-2026-88027 | MongoDB | high 7.1 | ### Impact Improper neutralization of special elements in data query logic in... | https://github.com/mongodb/laravel-mongodb/security/advisories/GHSA-jxxg-hqjr-9h33 2026-09-11 | GHSA-54r7-f4f5-j542 CVE-2026-88028 | MongoDB | high 7.1 | ### Impact Improper neutralization of special elements in data query logic in... | https://github.com/mongodb/laravel-mongodb/security/advisories/GHSA-54r7-f4f5-j542 2026-09-11 | GHSA-68xx-ccm2-m445 CVE-2026-88022 | MongoDB | high 8.4 | ### Impact Improper neutralization of special elements in data query logic in... | https://github.com/mongodb/laravel-mongodb/security/advisories/GHSA-68xx-ccm2-m445 2026-09-11 | GHSA-8fxw-fmj8-xp7j CVE-2026-88023 | MongoDB | medium 6.1 | GridFS data disclosure and deletion via query-operator injection in file IDs | https://github.com/mongodb/mongo-php-library/security/advisories/GHSA-8fxw-fmj8-xp7j 2026-09-11 | GHSA-vw3f-p33h-39j3 CVE-2026-88034 | MongoDB | medium 6.1 | GridFS data disclosure and deletion via query-operator injection in file IDs | https://github.com/mongodb/mongo-cxx-driver/security/advisories/GHSA-vw3f-p33h-39j3 2026-09-11 | GHSA-83f3-hpv5-58cq CVE-2026-88035 | MongoDB | medium 5.7 | Heap buffer overflow via wrapped size check during SASL username canonicalization | https://github.com/mongodb/mongo-c-driver/security/advisories/GHSA-83f3-hpv5-58cq 2026-09-11 | GHSA-6v9c-36h3-hgmp CVE-2026-88036 | MongoDB | medium 6.1 | GridFS data disclosure and deletion via query-operator injection in file IDs | https://github.com/mongodb/mongo-c-driver/security/advisories/GHSA-6v9c-36h3-hgmp 2026-09-11 | CVE-2026-89060 CVE-2026-89060 | Red Hat | high 7.7 | Red Hat, Inc.: CVE: user could modify a managed cluster’s ManagedClusterAddOn | https://access.redhat.com/errata/RHSA-2026:67539 2026-09-11 | CVE-2026-88914 CVE-2026-88914 | Red Hat | medium 4.4 | Red Hat GStreamer: integer overflow | https://access.redhat.com/security/cve/CVE-2026-88914 2026-09-10 | GHSA-wvm9-9g5j-623f CVE-2026-88006 | Open WebUI | medium 6.5 | Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange | https://github.com/advisories/GHSA-wvm9-9g5j-623f 2026-09-10 | GHSA-3g9q-v48f-hh9w CVE-2026-87011 | Open WebUI | high 7.5 | Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout | https://github.com/advisories/GHSA-3g9q-v48f-hh9w 2026-09-10 | GHSA-v39v-59xw-j98g CVE-2026-87012 | Open WebUI | medium 4.3 | Open WebUI: Any authenticated user can suppress calendar alerts instance-wide via a non-numeric alert value | https://github.com/advisories/GHSA-v39v-59xw-j98g 2026-09-10 | GHSA-8r35-5x5r-hv74 CVE-2026-87013 | Open WebUI | medium 4.3 | Open WebUI: Any authenticated user can start a non-terminating request via a folder parent cycle | https://github.com/advisories/GHSA-8r35-5x5r-hv74 2026-09-10 | GHSA-wjwr-xfp9-r66p CVE-2026-87014 | Open WebUI | medium 6.5 | Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes | https://github.com/advisories/GHSA-wjwr-xfp9-r66p 2026-09-10 | GHSA-p78m-89r6-pgf7 CVE-2026-87015 | Open WebUI | medium 6.8 | Open WebUI: A user's session cookies are sent to tool servers configured for bearer authentication | https://github.com/advisories/GHSA-p78m-89r6-pgf7 2026-09-10 | GHSA-wpmr-8h3q-fwj7 CVE-2026-87016 | Open WebUI | high 8.1 | Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite | https://github.com/advisories/GHSA-wpmr-8h3q-fwj7 2026-09-10 | GHSA-cw9w-vv67-hf73 CVE-2026-86073 | n8n | medium | n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution | https://github.com/advisories/GHSA-cw9w-vv67-hf73 2026-09-10 | GHSA-q5wm-mgqx-fv2f CVE-2026-86074 | n8n | medium | n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content | https://github.com/advisories/GHSA-q5wm-mgqx-fv2f 2026-09-10 | GHSA-qgpw-8g46-w95v CVE-2026-86995 | n8n | medium | n8n: path traversal | https://github.com/advisories/GHSA-qgpw-8g46-w95v 2026-09-10 | GHSA-cqr2-h44g-v75v CVE-2026-86085 | n8n | medium | n8n: missing authorization | https://github.com/advisories/GHSA-cqr2-h44g-v75v 2026-09-10 | GHSA-pq6c-vh67-xpm3 CVE-2026-86993 | n8n | medium | n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check | https://github.com/advisories/GHSA-pq6c-vh67-xpm3 2026-09-10 | GHSA-pf83-w3f9-8m37 CVE-2026-86084 | n8n | medium | n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions | https://github.com/advisories/GHSA-pf83-w3f9-8m37 2026-09-10 | GHSA-5m98-cgcr-xx3q CVE-2026-86080 | n8n | medium | n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open | https://github.com/advisories/GHSA-5m98-cgcr-xx3q 2026-09-10 | GHSA-f2cp-m7mv-8jpv CVE-2026-86079 | n8n | medium | n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers | https://github.com/advisories/GHSA-f2cp-m7mv-8jpv 2026-09-10 | GHSA-679f-58pq-4v2c CVE-2026-86078 | n8n | medium | n8n: Prototype Pollution via Workflow Structure Summary Can Lead to Denial of Service | https://github.com/advisories/GHSA-679f-58pq-4v2c 2026-09-10 | GHSA-65xw-2v52-jhxc CVE-2026-86994 | n8n | medium | n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId Filter | https://github.com/advisories/GHSA-65xw-2v52-jhxc 2026-09-10 | GHSA-6xcw-7xm6-48c6 CVE-2026-86083 | n8n | high | n8n: Expression Sandbox Escape via Shared Builtin Tampering and Code-Printer Injection Leads to Code Execution | https://github.com/advisories/GHSA-6xcw-7xm6-48c6 2026-09-10 | GHSA-35jj-42hp-8gmq CVE-2026-86077 | n8n | medium | n8n: Anonymous Approval-Gate Bypass via Reused resumeToken over the Chat WebSocket | https://github.com/advisories/GHSA-35jj-42hp-8gmq 2026-09-10 | PYSEC-2026-3974 CVE-2024-5452 | pytorch-lightning | critical 9.8 | Remote code execution in pytorch lightning | https://osv.dev/vulnerability/PYSEC-2026-3974 2026-09-10 | PYSEC-2026-3975 CVE-2024-5980 | pytorch-lightning | critical 9.1 | pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint | https://osv.dev/vulnerability/PYSEC-2026-3975 2026-09-10 | GHSA-34ff-336r-5q23 CVE-2026-86082 | n8n | high | n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Node | https://github.com/advisories/GHSA-34ff-336r-5q23 2026-09-10 | GHSA-j535-v25q-vx3q CVE-2026-86081 | n8n | high | n8n: Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone Path | https://github.com/advisories/GHSA-j535-v25q-vx3q 2026-09-10 | GHSA-hh89-3r9w-qj3j CVE-2026-86075 | n8n | high | n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint | https://github.com/advisories/GHSA-hh89-3r9w-qj3j 2026-09-10 | GHSA-hw8v-xxg5-vvvx CVE-2026-86076 | n8n | high | n8n: Expression Sandbox Escape via Class-Field Sanitizer Rebinding Can Lead to Code Execution | https://github.com/advisories/GHSA-hw8v-xxg5-vvvx 2026-09-10 | GHSA-pcvc-8vrv-8q6w CVE-2026-87017 | Open WebUI | medium 4.3 | Open WebUI: improper access control | https://github.com/advisories/GHSA-pcvc-8vrv-8q6w 2026-09-10 | GHSA-fmqh-xp37-5hr8 CVE-2026-87994 | Open WebUI | medium 4.3 | Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint | https://github.com/advisories/GHSA-fmqh-xp37-5hr8 2026-09-10 | GHSA-jmc6-2wr8-h3wj CVE-2026-87995 | Open WebUI | high 8.7 | Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin | https://github.com/advisories/GHSA-jmc6-2wr8-h3wj 2026-09-10 | GHSA-4v28-j6q3-5m4r CVE-2026-87996 | Open WebUI | high 7.7 | Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader | https://github.com/advisories/GHSA-4v28-j6q3-5m4r 2026-09-10 | GHSA-3pf7-q2g3-wj28 CVE-2026-87997 | Open WebUI | medium 4.3 | Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions | https://github.com/advisories/GHSA-3pf7-q2g3-wj28 2026-09-10 | GHSA-2724-6cpj-gf3v CVE-2026-87998 | Open WebUI | high 7.1 | Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion | https://github.com/advisories/GHSA-2724-6cpj-gf3v 2026-09-10 | GHSA-34r3-9m95-vq73 CVE-2026-87999 | Open WebUI | high 7.1 | Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch | https://github.com/advisories/GHSA-34r3-9m95-vq73 2026-09-10 | GHSA-4qg5-cxx4-g927 CVE-2026-88005 | Open WebUI | medium 6.5 | Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange | https://github.com/advisories/GHSA-4qg5-cxx4-g927 2026-09-10 | CVE-2026-16174 CVE-2026-16174 | Netskope | high 8.7 | Netskope Endpoint DLP: integer overflow | https://support.netskope.com/s/article/Netskope-Security-Advisory-Netskope-Client-Endpoint-DLP-Security-Notice---NSKPSA-2026-010 2026-09-10 | CVE-2026-16172 CVE-2026-16172 | Netskope | medium 6.0 | Netskope Endpoint DLP: out-of-bounds read | https://support.netskope.com/s/article/Netskope-Security-Advisory-Netskope-Client-Endpoint-DLP-Security-Notice---NSKPSA-2026-008 2026-09-10 | CVE-2026-82100 CVE-2026-82100 | IBM | critical 9.6 | IBM DataStage on Cloud Pak for Data: denial of service | https://www.ibm.com/support/pages/node/7286562 2026-09-10 | CVE-2026-82107 CVE-2026-82107 | IBM | critical 9.6 | IBM DataStage on Cloud Pak for Data: information disclosure | https://www.ibm.com/support/pages/node/7286562 2026-09-10 | CVE-2026-84889 CVE-2026-84889 | IBM | high 8.8 | IBM Langflow OSS: remote code execution | https://www.ibm.com/support/pages/node/7286656 2026-09-10 | CVE-2026-86087 CVE-2026-86087 | IBM | medium 4.3 | IBM Db2: path traversal | https://www.ibm.com/support/pages/node/7286985 2026-09-10 | CVE-2026-86093 CVE-2026-86093 | IBM | high 7.5 | IBM Db2: code execution | https://www.ibm.com/support/pages/node/7286993 2026-09-10 | CVE-2026-87958 CVE-2026-87958 | IBM | high 8.1 | IBM Db2: denial of service | https://www.ibm.com/support/pages/node/7286987 2026-09-10 | CVE-2026-81940 CVE-2026-81940 | IBM | high 8.8 | IBM Langflow OSS: remote code execution | https://www.ibm.com/support/pages/node/7286666 2026-09-10 | CVE-2026-81941 CVE-2026-81941 | IBM | high 8.8 | IBM Langflow OSS: improper access control | https://www.ibm.com/support/pages/node/7286666 2026-09-10 | CVE-2026-82092 CVE-2026-82092 | IBM | high 8.8 | IBM DataStage on Cloud Pak for Data: information disclosure | https://www.ibm.com/support/pages/node/7286562 2026-09-10 | CVE-2026-82095 CVE-2026-82095 | IBM | high 8.8 | IBM DataStage on Cloud Pak for Data: remote code execution | https://www.ibm.com/support/pages/node/7286562 2026-09-10 | CVE-2026-82097 CVE-2026-82097 | IBM | high 8.8 | IBM DataStage on Cloud Pak for Data: remote code execution | https://www.ibm.com/support/pages/node/7286562 2026-09-10 | CVE-2026-82098 CVE-2026-82098 | IBM | high 8.8 | IBM DataStage on Cloud Pak for Data: remote code execution | https://www.ibm.com/support/pages/node/7286562 2026-09-10 | CVE-2026-82099 CVE-2026-82099 | IBM | high 8.8 | IBM DataStage on Cloud Pak for Data: remote code execution | https://www.ibm.com/support/pages/node/7286562 2026-09-10 | CVE-2026-81213 CVE-2026-81213 | IBM | high 8.6 | IBM Langflow OSS: information disclosure | https://www.ibm.com/support/pages/node/7286665 2026-09-10 | CVE-2026-81265 CVE-2026-81265 | IBM | high 7.5 | IBM Langflow OSS: server-side request forgery | https://www.ibm.com/support/pages/node/7286665 2026-09-10 | CVE-2026-81268 CVE-2026-81268 | IBM | high 8.1 | IBM Langflow OSS: information disclosure | https://www.ibm.com/support/pages/node/7286662 2026-09-10 | CVE-2026-81540 CVE-2026-81540 | IBM | high 8.5 | IBM DataStage on Cloud Pak for Data: path traversal | https://www.ibm.com/support/pages/node/7286562 2026-09-10 | CVE-2026-81550 CVE-2026-81550 | IBM | high 8.8 | IBM DataStage on Cloud Pak for Data: remote code execution | https://www.ibm.com/support/pages/node/7286562 2026-09-10 | CVE-2026-81551 CVE-2026-81551 | IBM | high 8.8 | IBM DataStage on Cloud Pak for Data: path traversal | https://www.ibm.com/support/pages/node/7286562 2026-09-10 | CVE-2026-81554 CVE-2026-81554 | IBM | high 8.8 | IBM DataStage on Cloud Pak for Data: information disclosure | https://www.ibm.com/support/pages/node/7286562 2026-09-10 | CVE-2026-80380 CVE-2026-80380 | IBM | high 7.1 | IBM DataStage on Cloud Pak for Data: cross-site request forgery | https://www.ibm.com/support/pages/node/7286562 2026-09-10 | CVE-2026-80424 CVE-2026-80424 | IBM | critical 9.1 | IBM DataStage on Cloud Pak for Data: path traversal | https://www.ibm.com/support/pages/node/7286562 2026-09-10 | CVE-2026-80434 CVE-2026-80434 | IBM | high 7.4 | IBM DataStage on Cloud Pak for Data: denial of service | https://www.ibm.com/support/pages/node/7286562 2026-09-10 | CVE-2026-80436 CVE-2026-80436 | IBM | high 8.5 | IBM DataStage on Cloud Pak for Data: denial of service | https://www.ibm.com/support/pages/node/7286562 2026-09-10 | CVE-2026-81204 CVE-2026-81204 | IBM | critical 9.8 | IBM Langflow OSS: remote code execution | https://www.ibm.com/support/pages/node/7286666 2026-09-10 | CVE-2026-81207 CVE-2026-81207 | IBM | high 8.5 | IBM DataStage on Cloud Pak for Data: server-side request forgery | https://www.ibm.com/support/pages/node/7286562 2026-09-10 | CVE-2026-81210 CVE-2026-81210 | IBM | high 7.7 | IBM DataStage on Cloud Pak for Data: insecure direct object reference | https://www.ibm.com/support/pages/node/7286562 2026-09-10 | CVE-2026-81211 CVE-2026-81211 | IBM | high 8.8 | IBM Langflow OSS: improper authorization | https://www.ibm.com/support/pages/node/7286666 2026-09-10 | CVE-2026-78575 CVE-2026-78575 | IBM | high 8.8 | IBM Langflow OSS: remote code execution | https://www.ibm.com/support/pages/node/7286666 2026-09-10 | CVE-2026-79723 CVE-2026-79723 | IBM | medium 5.0 | IBM Langflow OSS: information disclosure | https://www.ibm.com/support/pages/node/7286665 2026-09-10 | CVE-2026-79724 CVE-2026-79724 | IBM | critical 9.8 | IBM Langflow OSS: command injection | https://www.ibm.com/support/pages/node/7286666 2026-09-10 | CVE-2026-79725 CVE-2026-79725 | IBM | medium 6.5 | IBM Langflow OSS: improper access control | https://www.ibm.com/support/pages/node/7286657 2026-09-10 | CVE-2026-79742 CVE-2026-79742 | IBM | high 8.8 | IBM Langflow OSS: remote code execution | https://www.ibm.com/support/pages/node/7286666 2026-09-10 | CVE-2026-80378 CVE-2026-80378 | IBM | high 8.5 | IBM DataStage on Cloud Pak for Data: denial of service | https://www.ibm.com/support/pages/node/7286562 2026-09-10 | CVE-2026-75624 CVE-2026-75624 | IBM | high 8.8 | IBM App Connect Enterprise: improper authorization | https://www.ibm.com/support/pages/node/7286532 2026-09-10 | CVE-2026-75777 CVE-2026-75777 | IBM | high 8.8 | IBM Aspera Enterprise WebApps: improper privilege management | https://www.ibm.com/support/pages/node/7286738 2026-09-10 | CVE-2026-76059 CVE-2026-76059 | IBM | high 8.8 | IBM Langflow OSS: protection mechanism failure | https://www.ibm.com/support/pages/node/7286666 2026-09-10 | CVE-2026-78569 CVE-2026-78569 | IBM | high 8.8 | IBM Langflow OSS: code execution | https://www.ibm.com/support/pages/node/7286666 2026-09-10 | CVE-2026-78571 CVE-2026-78571 | IBM | high 8.8 | IBM Langflow OSS: remote code execution | https://www.ibm.com/support/pages/node/7286666 2026-09-10 | CVE-2026-78573 CVE-2026-78573 | IBM | critical 9.8 | IBM ContextForge MCP Gateway: remote attacker could gain administrative access | https://www.ibm.com/support/pages/node/7286834 2026-09-10 | CVE-2026-19646 CVE-2026-19646 | IBM | critical 9.1 | IBM Common Licensing: remote attacker could redirect users to an arbitrary... | https://www.ibm.com/support/pages/node/7286490 2026-09-10 | CVE-2026-2310 CVE-2026-2310 | IBM | high 7.8 | IBM webMethods Integration Server: XML external entity | https://www.ibm.com/support/pages/node/7286620 2026-09-10 | GHSA-c4c8-c376-3p6c CVE-2026-88032 | MongoDB | high 8.2 | Application denial of service via cancellation race in reactive client-side encryption in MongoDB Java Driver | https://github.com/mongodb/mongo-java-driver/security/advisories/GHSA-c4c8-c376-3p6c 2026-09-10 | CVE-2026-9176 CVE-2026-9176 | IBM | medium 6.7 | IBM WebSphere Application Server: improper authentication | https://www.ibm.com/support/pages/node/7286610 2026-09-10 | CVE-2026-9225 CVE-2026-9225 | IBM | medium 6.5 | IBM Langflow OSS: improper access control | https://www.ibm.com/support/pages/node/7286657 2026-09-10 | CVE-2026-9327 CVE-2026-9327 | IBM | medium 6.3 | IBM WebSphere Application Server: information disclosure | https://www.ibm.com/support/pages/node/7286610 2026-09-10 | CVE-2026-9667 CVE-2026-9667 | IBM | medium 5.3 | IBM WebSphere Application Server: server-side request forgery | https://www.ibm.com/support/pages/node/7286610 2026-09-10 | CVE-2026-85025 CVE-2026-85025 | IBM | critical 9.8 | IBM Langflow OSS: remote code execution | https://www.ibm.com/support/pages/node/7286666 2026-09-10 | CVE-2026-75940 CVE-2026-75940 | Lenovo | critical 9.3 | Lenovo Health Application: hard-coded credentials | https://iknow.lenovo.com.cn/detail/442248 2026-09-10 | CVE-2026-63427 CVE-2026-63427 | Lenovo | high 8.5 | Lenovo Software Fix: authentication bypass | https://support.lenovo.com/us/en/downloads/ds101291-rescue-and-smart-assistant-lmsa 2026-09-10 | CVE-2026-18994 CVE-2026-18994 | Lenovo | high 8.4 | Lenovo File Manager Application: improper authorization | https://iknow.lenovo.com.cn/detail/442247 2026-09-10 | CVE-2026-19136 CVE-2026-19136 | Lenovo | high 8.4 | Lenovo Tianxi AI Agent PC Application: command injection | https://iknow.lenovo.com.cn/detail/442249 2026-09-10 | CVE-2026-11813 CVE-2026-11813 | Lenovo | high 8.5 | Lenovo Filez Client application: insecure permissions | https://www.filez.com/en/securityPolicy/5.html?1788882250 2026-09-10 | GHSA-556f-q76p-2vxq CVE-2026-88033 | MongoDB | high 8.3 | GridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB Java Driver | https://github.com/mongodb/mongo-java-driver/security/advisories/GHSA-556f-q76p-2vxq 2026-09-10 | GHSA-f8f6-5x8j-2c9f CVE-2026-88026 | MongoDB | high 7.1 | Regular expression injection via unescaped characters in LINQ query translation | https://github.com/mongodb/mongo-csharp-driver/security/advisories/GHSA-f8f6-5x8j-2c9f 2026-09-10 | GHSA-r6rm-7qqx-vx45 CVE-2026-88025 | MongoDB | medium 6.1 | GridFS data disclosure and deletion via query-operator injection in file IDs | https://github.com/mongodb/mongo-csharp-driver/security/advisories/GHSA-r6rm-7qqx-vx45 2026-09-10 | GHSA-69mc-2wv2-rcr5 CVE-2026-88031 | MongoDB | medium 6.1 | GridFS data deletion via operator-document injection in file IDs | https://github.com/mongodb/mongo-go-driver/security/advisories/GHSA-69mc-2wv2-rcr5 2026-09-10 | CVE-2026-9336 CVE-2026-9336 | IBM | medium 6.5 | IBM WebSphere Application Server: denial of service | https://www.ibm.com/support/pages/node/7286610 2026-09-10 | CVE-2026-9338 CVE-2026-9338 | IBM | medium 5.3 | IBM WebSphere Application Server: denial of service | https://www.ibm.com/support/pages/node/7286610 2026-09-10 | CVE-2026-87993 CVE-2026-87993 | HashiCorp | high 7.7 | HashiCorp Tooling: information disclosure | https://discuss.hashicorp.com/t/hcsec-2026-38-consul-template-vulnerable-to-an-information-disclosure-issue-in-error-handling/77740 2026-09-10 | CVE-2026-88021 CVE-2026-88021 | HashiCorp | high 7.1 | Consul and Consul Enterprise are vulnerable to an authorization bypass in the... | https://discuss.hashicorp.com/t/hcsec-2026-37-consul-vulnerable-to-an-authorization-bypass-in-the-connect-service-mesh/77739 2026-09-10 | CVE-2026-87090 CVE-2026-87090 | HashiCorp | high 8.3 | HashiCorp Consul: improper authorization | https://discuss.hashicorp.com/t/hcsec-2026-34-consul-vulnerable-to-an-authorization-bypass-in-the-catalog-node-write-path/77736 2026-09-10 | CVE-2026-87106 CVE-2026-87106 | HashiCorp | medium 6.5 | HashiCorp Consul: denial of service | https://discuss.hashicorp.com/t/hcsec-2026-35-consul-vulnerable-to-a-denial-of-service-in-the-native-rpc-listener/77737 2026-09-10 | CVE-2026-87107 CVE-2026-87107 | HashiCorp | medium 5.4 | HashiCorp Consul: improper authorization | https://discuss.hashicorp.com/t/hcsec-2026-36-consul-vulnerable-to-an-authorization-bypass-in-the-catalog-deregistration-path/77738 2026-09-10 | GHSA-wj2p-8jf9-wqxx CVE-2026-88024 | MongoDB | medium 6.1 | GridFS data disclosure and deletion via query-operator injection in file IDs | https://github.com/mongodb/mongo-rust-driver/security/advisories/GHSA-wj2p-8jf9-wqxx 2026-09-10 | GHSA-qqj6-54q6-cxv6 CVE-2026-86597 | Snowflake | medium 6.5 | Sensitive information written to logs by Snowflake drivers | https://github.com/snowflakedb/snowflake-connector-nodejs/security/advisories/GHSA-qqj6-54q6-cxv6 2026-09-10 | GHSA-q57w-g8rw-8595 CVE-2026-86600 | Snowflake | high 8.2 | Workload identity attestation generated before login host validation in Snowflake drivers | https://github.com/snowflakedb/snowflake-connector-nodejs/security/advisories/GHSA-q57w-g8rw-8595 2026-09-10 | GHSA-qc84-pr5g-62fj CVE-2026-85525 | Snowflake | high 7.4 | Improper OCSP response validation in Snowflake drivers | https://github.com/snowflakedb/snowflake-connector-nodejs/security/advisories/GHSA-qc84-pr5g-62fj 2026-09-10 | GHSA-vgvm-56qr-qvcr CVE-2026-85528 | Snowflake | medium 5.3 | Snowflake JDBC Driver auto-configuration account validation permits credential redirection | https://github.com/snowflakedb/snowflake-jdbc/security/advisories/GHSA-vgvm-56qr-qvcr 2026-09-10 | CVE-2026-81467 CVE-2026-81467 | Dell Technologies | critical 9.8 | Dell Technologies ThinOS 10: command injection | https://www.dell.com/support/kbdoc/en-us/000502746/dsa-2026-389-security-update-for-dell-thinos-10-for-multiple-vulnerabilities 2026-09-10 | CVE-2026-81468 CVE-2026-81468 | Dell Technologies | critical 9.1 | Dell Technologies ThinOS 10: command injection | https://www.dell.com/support/kbdoc/en-us/000502746/dsa-2026-389-security-update-for-dell-thinos-10-for-multiple-vulnerabilities 2026-09-10 | CVE-2026-81046 CVE-2026-81046 | Dell Technologies | critical 9.4 | Dell Technologies ThinOS 10: remote code execution | https://www.dell.com/support/kbdoc/en-us/000502746/dsa-2026-389-security-update-for-dell-thinos-10-for-multiple-vulnerabilities 2026-09-10 | CVE-2026-81048 CVE-2026-81048 | Dell Technologies | critical 9.6 | Dell Technologies ThinOS 10: command injection | https://www.dell.com/support/kbdoc/en-us/000502746/dsa-2026-389-security-update-for-dell-thinos-10-for-multiple-vulnerabilities 2026-09-10 | CVE-2026-81049 CVE-2026-81049 | Dell Technologies | medium 4.4 | Dell Technologies ThinOS 10: code execution | https://www.dell.com/support/kbdoc/en-us/000502746/dsa-2026-389-security-update-for-dell-thinos-10-for-multiple-vulnerabilities 2026-09-10 | CVE-2026-81051 CVE-2026-81051 | Dell Technologies | medium 6.6 | Dell ThinOS 10, versions prior to 2605_10.2616 | https://www.dell.com/support/kbdoc/en-us/000502746/dsa-2026-389-security-update-for-dell-thinos-10-for-multiple-vulnerabilities 2026-09-10 | CVE-2026-81052 CVE-2026-81052 | Dell Technologies | medium 6.8 | Dell Technologies ThinOS 10: remote code execution | https://www.dell.com/support/kbdoc/en-us/000502746/dsa-2026-389-security-update-for-dell-thinos-10-for-multiple-vulnerabilities 2026-09-10 | CVE-2026-4129 CVE-2026-4129 | National Instruments | high 8.6 | National Instruments NI SystemLink: improper access control | https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/2026/improper-access-controls-in-ni-systemlink.html 2026-09-10 | CVE-2026-4130 CVE-2026-4130 | National Instruments | high 8.4 | National Instruments SystemLink: information disclosure | https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/2026/storage-of-sensitive-information-in-cleartext-in-ni-systemlink.html 2026-09-10 | CVE-2026-88924 CVE-2026-88924 | Red Hat | high 7.0 | Red Hat admin backend of gvfs: race condition | https://access.redhat.com/security/cve/CVE-2026-88924 2026-09-10 | CVE-2026-85217 CVE-2026-85217 | Autodesk | high 8.6 | Autodesk Fusion: information disclosure | https://dl.appstreaming.autodesk.com/production/installers/Fusion%20Client%20Downloader.exe 2026-09-10 | CVE-2026-84828 CVE-2026-84828 | Red Hat | medium 6.5 | Red Hat Enterprise Linux 10: insecure permissions | https://access.redhat.com/security/cve/CVE-2026-84828 2026-09-10 | CVE-2026-88859 CVE-2026-88859 | Red Hat | medium 6.3 | A flaw was found in Evolution | https://access.redhat.com/security/cve/CVE-2026-88859 2026-09-10 | AWS-2026-107 CVE-2026-89049 | AWS | critical 9.9 | Server-side request forgery in the Session Manager port forwarding functionality in AWS... | https://aws.amazon.com/security/security-bulletins/rss/2026-107-aws/ 2026-09-10 | AWS-2026-106 CVE-2026-85228 | AWS | critical 9.1 | Integer overflow in tensor buffer validation in Deep Java Library | https://aws.amazon.com/security/security-bulletins/rss/2026-106-aws/ 2026-09-10 | CVE-2026-84042 CVE-2026-84042 | Red Hat | high 7.8 | Red Hat crun.: improper privilege management | https://access.redhat.com/security/cve/CVE-2026-84042 2026-09-10 | CVE-2026-88264 CVE-2026-88264 | Red Hat | medium 5.6 | Red Hat crun.: link following | https://access.redhat.com/errata/RHSA-2026:71668 2026-09-10 | CVE-2026-88265 CVE-2026-88265 | Red Hat | medium 5.6 | Red Hat crun. After pivot_root: link following | https://access.redhat.com/security/cve/CVE-2026-88265 2026-09-10 | CVE-2026-13745 CVE-2026-13745 | Google Cloud | high 7.7 | Google Cloud Gemini CLI: code execution | https://github.com/google-gemini/gemini-cli/releases/tag/v0.39.1 2026-09-10 | AWS-2026-105 CVE-2026-87912 | AWS | medium 5.9 | Missing S3 bucket ownership verification in the AWS Security Agent plugin for... | https://aws.amazon.com/security/security-bulletins/rss/2026-105-aws/ 2026-09-10 | CVE-2026-88763 CVE-2026-88763 | Red Hat | medium 5.9 | Red Hat Service Interconnect 2: denial of service | https://access.redhat.com/security/cve/CVE-2026-88763 2026-09-10 | CVE-2026-88770 CVE-2026-88770 | Red Hat | medium 6.5 | Red Hat Device Authorization Grant flow of Keycloak: no brute-force limit | https://access.redhat.com/security/cve/CVE-2026-88770 2026-09-10 | CVE-2026-0303 CVE-2026-0303 | Palo Alto Networks | low 2.4 | Palo Alto Networks Checkov by Prisma Cloud: code execution | https://security.paloaltonetworks.com/CVE-2026-0303 2026-09-10 | CVE-2026-0304 CVE-2026-0304 | Palo Alto Networks | medium 4.8 | Palo Alto Networks Cortex XDR Broker VM: privilege escalation | https://security.paloaltonetworks.com/CVE-2026-0304 2026-09-10 | CVE-2026-0302 CVE-2026-0302 | Palo Alto Networks | low 1.1 | Palo Alto Networks Checkov by Prisma Cloud: command injection | https://security.paloaltonetworks.com/CVE-2026-0302 2026-09-10 | CVE-2026-0310 CVE-2026-0310 | Palo Alto Networks | high 7.2 | Palo Alto Networks Cloud NGFW: buffer overflow | https://security.paloaltonetworks.com/CVE-2026-0310 2026-09-10 | CVE-2026-0306 CVE-2026-0306 | Palo Alto Networks | medium 5.8 | Palo Alto Networks Prisma: local user could bypass configured DLP policy... | https://security.paloaltonetworks.com/CVE-2026-0306 2026-09-10 | CVE-2026-0307 CVE-2026-0307 | Palo Alto Networks | medium 5.9 | Palo Alto Networks GlobalProtect App: privilege escalation | https://security.paloaltonetworks.com/CVE-2026-0307 2026-09-10 | CVE-2026-0308 CVE-2026-0308 | Palo Alto Networks | low 1.1 | Palo Alto Networks PAN-OS: cross-site scripting | https://security.paloaltonetworks.com/CVE-2026-0308 2026-09-10 | CVE-2026-0309 CVE-2026-0309 | Palo Alto Networks | medium 4.0 | Palo Alto Networks PAN-OS: command injection | https://security.paloaltonetworks.com/CVE-2026-0309 2026-09-10 | CVE-2026-0305 CVE-2026-0305 | Palo Alto Networks | medium 4.3 | Palo Alto Networks Prisma Access Agent: information disclosure | https://security.paloaltonetworks.com/CVE-2026-0305 2026-09-10 | CVE-2026-19584 CVE-2026-19584 | Rapid7 | high 7.7 | Rapid7 Velociraptor: code injection | http://docs.velociraptor.app/announcements/advisories/cve-2026-19584/ 2026-09-10 | CVE-2026-19583 CVE-2026-19583 | Rapid7 | critical 9.9 | Rapid7 Velociraptor: insecure permissions | http://docs.velociraptor.app/announcements/advisories/cve-2026-19583/ 2026-09-09 | GHSA-3cgp-3cqx-j8w2 CVE-2026-88000 | Open WebUI | medium 6.5 | Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree | https://github.com/advisories/GHSA-3cgp-3cqx-j8w2 2026-09-09 | GHSA-5x7x-4c3c-qf5w CVE-2026-88001 | Open WebUI | medium 5.0 | Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets | https://github.com/advisories/GHSA-5x7x-4c3c-qf5w 2026-09-09 | GHSA-jqhh-cjmq-vmv6 CVE-2026-88002 | Open WebUI | medium 6.5 | Open WebUI: Any authenticated user can hang the server via a cyclic chat message history | https://github.com/advisories/GHSA-jqhh-cjmq-vmv6 2026-09-09 | AWS-2026-067 CVE-2026-18140 | AWS | high 7.5 | Uncontrolled recursion in the aws-smithy-json unknown-key skip path allows... | https://aws.amazon.com/security/security-bulletins/rss/2026-067-aws/ 2026-09-09 | CVE-2026-73769 CVE-2026-73769 | Hewlett Packard Enterprise | high 7.2 | Hewlett Packard Enterprise ClearPass Policy Manager: remote code execution | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05130en_us&docLocale=en_US 2026-09-09 | CVE-2026-73786 CVE-2026-73786 | Hewlett Packard Enterprise | high 7.5 | Hewlett Packard Enterprise ClearPass Policy Manager (CPPM): denial of service | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05130en_us&docLocale=en_US 2026-09-09 | CVE-2026-73787 CVE-2026-73787 | Hewlett Packard Enterprise | high 7.2 | Hewlett Packard Enterprise ClearPass Policy Manager: remote code execution | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05130en_us&docLocale=en_US 2026-09-09 | CVE-2026-73788 CVE-2026-73788 | Hewlett Packard Enterprise | medium 6.5 | Hewlett Packard Enterprise ClearPass: improper privilege management | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05130en_us&docLocale=en_US 2026-09-09 | CVE-2026-73789 CVE-2026-73789 | Hewlett Packard Enterprise | medium 5.3 | Hewlett Packard Enterprise ClearPass: unauthenticated remote attacker could... | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05130en_us&docLocale=en_US 2026-09-09 | GHSA-4587-w9mm-xxvh | Apple | medium | OCI image load follows symlinks for `oci-layout` and `index.json` outside the extraction directory | https://github.com/apple/containerization/security/advisories/GHSA-4587-w9mm-xxvh 2026-09-09 | GHSA-rgqp-277h-gcwj | Apple | medium | `UnixType.init(path:)` uses a macOS length limit longer than the `sockaddr_un.sun_path` buffer it copies into | https://github.com/apple/containerization/security/advisories/GHSA-rgqp-277h-gcwj 2026-09-09 | CVE-2026-8044 CVE-2026-8044 | Schneider Electric | high 8.6 | Schneider Electric EcoStruxure IT: argument injection | https://download.se.com/files?p_Doc_Ref=SEVD-2026-251-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-251-01.pdf 2026-09-09 | CVE-2026-87874 CVE-2026-87874 | Red Hat | high 8.1 | Red Hat memcached cache plugin of the community: remote code execution | https://access.redhat.com/security/cve/CVE-2026-87874 2026-09-09 | CVE-2026-87875 CVE-2026-87875 | Red Hat | medium 4.3 | Red Hat Enterprise Linux 10: out-of-bounds read | https://access.redhat.com/errata/RHSA-2026:66600 2026-09-09 | CVE-2026-87876 CVE-2026-87876 | Red Hat | low 3.0 | Two case-insensitive comparisons on request-derived usernames outside the main... | https://access.redhat.com/errata/RHSA-2026:67568 2026-09-09 | CVE-2026-87853 CVE-2026-87853 | Red Hat | high 7.5 | A flaw was found in SSSD's IdP authentication provider | https://access.redhat.com/security/cve/CVE-2026-87853 2026-09-09 | CVE-2026-87872 CVE-2026-87872 | Red Hat | medium 6.8 | Red Hat Ceph Storage 5: improper certificate validation | https://access.redhat.com/security/cve/CVE-2026-87872 2026-09-09 | CVE-2026-77120 CVE-2026-77120 | Schneider Electric | high 8.7 | Schneider Electric PowerLogic T300: command injection | https://download.se.com/files?p_Doc_Ref=SEVD-2026-251-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-251-02.pdf 2026-09-09 | CVE-2026-70425 CVE-2026-70425 | Dell Technologies | medium 6.7 | Dell Technologies PowerScale OneFS: command injection | https://www.dell.com/support/kbdoc/en-us/000505684/dsa-2026-360-security-update-for-dell-powerscale-onefs-multiple-vulnerabilities 2026-09-09 | CVE-2026-40635 CVE-2026-40635 | Dell Technologies | medium 5.4 | Dell Technologies PowerScale OneFS: denial of service | https://www.dell.com/support/kbdoc/en-us/000505684/dsa-2026-360-security-update-for-dell-powerscale-onefs-multiple-vulnerabilities 2026-09-09 | CVE-2026-46460 CVE-2026-46460 | Dell Technologies | low 3.5 | Dell Technologies PowerScale OneFS: improper authorization | https://www.dell.com/support/kbdoc/en-us/000505684/dsa-2026-360-security-update-for-dell-powerscale-onefs-multiple-vulnerabilities 2026-09-09 | CVE-2026-23855 CVE-2026-23855 | Dell Technologies | high 7.2 | Dell Technologies iDRAC10: command injection | https://www.dell.com/support/kbdoc/en-us/000504998/dsa-2026-392-security-update-for-dell-idrac9-and-idrac10-vulnerability 2026-09-09 | CVE-2026-18147 CVE-2026-18147 | Red Hat | high 8.1 | Red Hat FreeIPA. An unauthenticated remote attacker: cross-site scripting | https://access.redhat.com/errata/RHSA-2026:70564 2026-09-09 | CVE-2026-19233 CVE-2026-19233 | Schneider Electric | high 8.6 | Schneider Electric EcoStruxure IT: server-side request forgery | https://download.se.com/files?p_Doc_Ref=SEVD-2026-251-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-251-01.pdf 2026-09-09 | CVE-2026-79741 CVE-2026-79741 | Dell Technologies | medium 5.3 | Dell Technologies Secure Connect Gateway 5.0: command injection | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-79942 CVE-2026-79942 | Dell Technologies | low 3.4 | Dell Technologies Secure Connect Gateway 5.0: excessive privileges | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-79944 CVE-2026-79944 | Dell Technologies | low 3.4 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0... | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-79945 CVE-2026-79945 | Dell Technologies | medium 5.5 | Dell Technologies Secure Connect Gateway 5.0: command injection | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-79946 CVE-2026-79946 | Dell Technologies | medium 5.3 | Dell Technologies Secure Connect Gateway 5.0: cross-site scripting | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-79947 CVE-2026-79947 | Dell Technologies | medium 5.5 | Dell Technologies Secure Connect Gateway 5.0: command injection | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-79689 CVE-2026-79689 | Dell Technologies | medium 5.3 | Dell Technologies Secure Connect Gateway 5.0: command injection | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-79693 CVE-2026-79693 | Dell Technologies | low 3.4 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0... | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-79735 CVE-2026-79735 | Dell Technologies | medium 4.4 | Dell Technologies Secure Connect Gateway 5.0: information disclosure | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-78484 CVE-2026-78484 | Dell Technologies | medium 5.5 | Dell Technologies Secure Connect Gateway 5.0: command injection | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-78493 CVE-2026-78493 | Dell Technologies | medium 5.5 | Dell Technologies Secure Connect Gateway 5.0: command injection | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-83530 CVE-2026-83530 | Google | medium 6.9 | Google cel-go: excessive memory allocation | https://github.com/cel-expr/cel-go/pull/1302 2026-09-09 | CVE-2026-79732 CVE-2026-79732 | Dell Technologies | low 3.7 | Dell Technologies Secure Connect Gateway 5.0: improper certificate validation | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-79736 CVE-2026-79736 | Dell Technologies | low 3.7 | Dell Technologies Secure Connect Gateway 5.0: improper certificate validation | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-79941 CVE-2026-79941 | Dell Technologies | medium 5.3 | Dell Technologies Secure Connect Gateway 5.0: command injection | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-79690 CVE-2026-79690 | Dell Technologies | low 3.7 | Dell Technologies Secure Connect Gateway 5.0: improper certificate validation | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-79729 CVE-2026-79729 | Dell Technologies | low 3.7 | Dell Technologies Secure Connect Gateway 5.0: improper certificate validation | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-78482 CVE-2026-78482 | Dell Technologies | medium 5.5 | Dell Technologies Secure Connect Gateway 5.0: command injection | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-79740 CVE-2026-79740 | Dell Technologies | high 7.5 | Dell Technologies Secure Connect Gateway 5.0: hard-coded credentials | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-79950 CVE-2026-79950 | Dell Technologies | high 7.5 | Dell Technologies Secure Connect Gateway 5.0: hard-coded credentials | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-79952 CVE-2026-79952 | Dell Technologies | medium 5.3 | Dell Technologies Secure Connect Gateway 5.0: improper output encoding | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-79964 CVE-2026-79964 | Dell Technologies | medium 5.3 | Dell Technologies Secure Connect Gateway 5.0: improper output encoding | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-79971 CVE-2026-79971 | Dell Technologies | medium 5.3 | Dell Technologies Secure Connect Gateway 5.0: CSV injection | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-78483 CVE-2026-78483 | Dell Technologies | medium 5.9 | Dell Technologies Secure Connect Gateway 5.0: improper certificate validation | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-78486 CVE-2026-78486 | Dell Technologies | medium 4.4 | Dell Technologies Secure Connect Gateway 5.0: hard-coded key | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-79731 CVE-2026-79731 | Dell Technologies | medium 4.4 | Dell Technologies Secure Connect Gateway 5.0: hard-coded credentials | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-79738 CVE-2026-79738 | Dell Technologies | high 7.5 | Dell Technologies Secure Connect Gateway 5.0: hard-coded credentials | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-80169 CVE-2026-80169 | Dell Technologies | low 3.3 | Dell Technologies Secure Connect Gateway 5.0: information disclosure | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-85102 CVE-2026-85102 | Check Point | critical 9.8 | Check Point Quantum Security Gateway: remote code execution | https://support.checkpoint.com/results/sk/sk1000117 2026-09-09 | CVE-2026-85103 CVE-2026-85103 | Check Point | critical 9.8 | Check Point Quantum Security: heap buffer overflow | https://support.checkpoint.com/results/sk/sk1000118 2026-09-09 | CVE-2026-79965 CVE-2026-79965 | Dell Technologies | medium 5.3 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0... | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-79966 CVE-2026-79966 | Dell Technologies | low 3.3 | Dell Technologies Secure Connect Gateway 5.0: information disclosure | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-79968 CVE-2026-79968 | Dell Technologies | medium 5.6 | Dell Technologies Secure Connect Gateway 5.0: race condition | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-79969 CVE-2026-79969 | Dell Technologies | medium 5.3 | Dell Technologies Secure Connect Gateway 5.0: race condition | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-79728 CVE-2026-79728 | Dell Technologies | medium 6.5 | Dell Technologies Secure Connect Gateway 5.0: path traversal | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-79961 CVE-2026-79961 | Dell Technologies | medium 5.3 | Dell Technologies Secure Connect Gateway 5.0: missing authentication | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-79962 CVE-2026-79962 | Dell Technologies | medium 5.3 | Dell Technologies Secure Connect Gateway 5.0: race condition | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-79638 CVE-2026-79638 | Dell Technologies | medium 5.3 | Dell Technologies Secure Connect Gateway 5.0: cross-site scripting | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-79694 CVE-2026-79694 | Dell Technologies | medium 5.5 | Dell Technologies Secure Connect Gateway 5.0: information disclosure | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-15140 CVE-2026-15140 | Everpure | high 7.7 | Everpure Portworx Operator: privilege escalation | https://support.everpuredata.com/r/security-bulletins/security-bulletins 2026-09-09 | CVE-2026-80172 CVE-2026-80172 | Dell Technologies | critical 9.8 | Dell Technologies Secure Connect Gateway 5.0: insufficient authenticity check | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-79692 CVE-2026-79692 | Dell Technologies | high 7.3 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0... | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-79695 CVE-2026-79695 | Dell Technologies | high 7.3 | Dell Technologies Secure Connect Gateway 5.0: denial of service | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-79730 CVE-2026-79730 | Dell Technologies | medium 5.6 | Dell Technologies Secure Connect Gateway 5.0: race condition | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-79963 CVE-2026-79963 | Dell Technologies | high 7.4 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0... | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-79970 CVE-2026-79970 | Dell Technologies | medium 5.6 | Dell Technologies Secure Connect Gateway 5.0: improper signature check | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-79972 CVE-2026-79972 | Dell Technologies | high 7.2 | Dell Technologies Secure Connect Gateway 5.0: SQL injection | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-80171 CVE-2026-80171 | Dell Technologies | medium 4.7 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0... | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-78481 CVE-2026-78481 | Dell Technologies | medium 6.5 | Dell Technologies Secure Connect Gateway 5.0: hard-coded key | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-78485 CVE-2026-78485 | Dell Technologies | high 7.3 | Dell Technologies Secure Connect Gateway 5.0: path traversal | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-78489 CVE-2026-78489 | Dell Technologies | medium 5.9 | Dell Technologies Secure Connect Gateway 5.0: improper certificate validation | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-78490 CVE-2026-78490 | Dell Technologies | high 7.5 | Dell Technologies Secure Connect Gateway 5.0: no brute-force limit | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-78492 CVE-2026-78492 | Dell Technologies | high 7.4 | Dell Technologies Secure Connect Gateway 5.0: improper certificate validation | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-79637 CVE-2026-79637 | Dell Technologies | high 7.7 | Dell Technologies Secure Connect Gateway 5.0: improper certificate validation | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-79635 CVE-2026-79635 | Dell Technologies | high 7.3 | Dell Technologies Secure Connect Gateway 5.0: server-side request forgery | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-79641 CVE-2026-79641 | Dell Technologies | high 7.5 | Dell Technologies Secure Connect Gateway 5.0: command injection | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-79727 CVE-2026-79727 | Dell Technologies | low 3.3 | Dell Technologies Secure Connect Gateway 5.0: information disclosure | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-80174 CVE-2026-80174 | Dell Technologies | medium 5.3 | Dell Technologies Secure Connect Gateway 5.0: insufficient session expiration | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-80239 CVE-2026-80239 | Dell Technologies | low 2.4 | Dell Technologies Secure Connect Gateway 5.0: information disclosure | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2025-3271 CVE-2025-3271 | Open Text Corporation | medium 4.8 | Open Text Documentum Webtop: cross-site scripting | https://support.opentext.com/csm?id=ot_kb_unauthenticated&sysparm_article=KB0869472 2026-09-09 | AWS-2026-103 CVE-2026-85788 | AWS | medium 5.5 | Issue with awslabs mysql-mcp-server | https://aws.amazon.com/security/security-bulletins/rss/2026-103-aws/ 2026-09-09 | CVE-2026-80122 CVE-2026-80122 | Dell Technologies | high 7.3 | Dell Technologies Secure Connect Gateway 5.0: improper certificate validation | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-80175 CVE-2026-80175 | Dell Technologies | low 3.3 | Dell Technologies Secure Connect Gateway 5.0: information disclosure | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-87766 CVE-2026-87766 | Red Hat | high 8.8 | Red Hat bubblewrap. During sandbox setup: link following | https://access.redhat.com/security/cve/CVE-2026-87766 2026-09-09 | CVE-2026-79640 CVE-2026-79640 | Dell Technologies | medium 5.4 | Dell Technologies Secure Connect Gateway 5.0: SQL injection | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-79696 CVE-2026-79696 | Google Cloud | critical 10.0 | Google Cloud Agent Development Kit (ADK) for Python: code injection | https://github.com/google/adk-python/commit/a16f6da3314b8dcd9925884cd6fc7fc9ffdd570d 2026-09-09 | CVE-2026-79967 CVE-2026-79967 | Dell Technologies | medium 5.6 | Dell Technologies Secure Connect Gateway 5.0: improper certificate validation | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-79973 CVE-2026-79973 | Dell Technologies | medium 6.3 | Dell Technologies Secure Connect Gateway 5.0: denial of service | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-79974 CVE-2026-79974 | Dell Technologies | medium 6.4 | Dell Technologies Secure Connect Gateway 5.0: improper authentication | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-12858 CVE-2026-12858 | ESET | high 8.5 | ESET AV Remover (standalone): privilege escalation | https://support.eset.com/en/ca9000-eset-customer-advisory-local-privilege-escalation-vulnerability-in-eset-av-remover-fixed 2026-09-09 | CVE-2026-78491 CVE-2026-78491 | Dell Technologies | high 8.2 | Dell Technologies Secure Connect Gateway 5.0: improper certificate validation | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-78494 CVE-2026-78494 | Dell Technologies | high 7.4 | Dell Technologies Secure Connect Gateway 5.0: improper certificate validation | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-79636 CVE-2026-79636 | Dell Technologies | high 7.0 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0... | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-80055 CVE-2026-80055 | Dell Technologies | medium 4.4 | Dell Technologies Secure Connect Gateway 5.0: LDAP injection | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-80123 CVE-2026-80123 | Dell Technologies | high 7.3 | Dell Technologies Secure Connect Gateway 5.0: server-side request forgery | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-80124 CVE-2026-80124 | Dell Technologies | medium 5.5 | Dell Technologies Secure Connect Gateway 5.0: information disclosure | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-80177 CVE-2026-80177 | Dell Technologies | medium 6.5 | Dell Technologies Secure Connect Gateway 5.0: SQL injection | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-09 | CVE-2026-19729 CVE-2026-19729 | Red Hat | medium 4.9 | Red Hat key provider: path traversal | https://access.redhat.com/errata/RHSA-2026:68276 2026-09-09 | CVE-2026-21106 CVE-2026-21106 | Samsung | medium 5.1 | Samsung Cloud Assistant: local attacker could disable enhanced data protection | https://security.samsungmobile.com/serviceWeb.smsb?year=2026&month=09 2026-09-09 | CVE-2026-21107 CVE-2026-21107 | Samsung | medium 6.9 | Samsung Notes: out-of-bounds write | https://security.samsungmobile.com/serviceWeb.smsb?year=2026&month=09 2026-09-09 | CVE-2026-21108 CVE-2026-21108 | Samsung | medium 6.9 | Samsung Bixby Touch: information disclosure | https://security.samsungmobile.com/serviceWeb.smsb?year=2026&month=09 2026-09-09 | CVE-2026-21109 CVE-2026-21109 | Samsung | low 2.1 | Samsung Watch Plugin: improper access control | https://security.samsungmobile.com/serviceWeb.smsb?year=2026&month=09 2026-09-09 | CVE-2026-21110 CVE-2026-21110 | Samsung | medium 6.9 | Samsung: out-of-bounds write | https://security.samsungmobile.com/serviceWeb.smsb?year=2026&month=09 2026-09-09 | CVE-2026-21111 CVE-2026-21111 | Samsung | medium 6.9 | Samsung: out-of-bounds write | https://security.samsungmobile.com/serviceWeb.smsb?year=2026&month=09 2026-09-09 | CVE-2026-21112 CVE-2026-21112 | Samsung | medium 5.1 | Samsung Tips: improper input validation | https://security.samsungmobile.com/serviceWeb.smsb?year=2026&month=09 2026-09-09 | CVE-2026-21113 CVE-2026-21113 | Samsung | medium 4.8 | Samsung Visual Voicemail: exported component | https://security.samsungmobile.com/serviceWeb.smsb?year=2026&month=09 2026-09-09 | CVE-2026-21098 CVE-2026-21098 | Samsung | medium 6.9 | Samsung: improper access control | https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=09 2026-09-09 | CVE-2026-21099 CVE-2026-21099 | Samsung | medium 5.1 | Samsung SettingsProvider: improper access control | https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=09 2026-09-09 | CVE-2026-21100 CVE-2026-21100 | Samsung | medium 6.9 | Samsung SystemUI: improper access control | https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=09 2026-09-09 | CVE-2026-21101 CVE-2026-21101 | Samsung | high 8.4 | Samsung: improper input validation | https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=09 2026-09-09 | CVE-2026-21102 CVE-2026-21102 | Samsung | critical 9.3 | Samsung DualDAR: use after free | https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=09 2026-09-09 | CVE-2026-21103 CVE-2026-21103 | Samsung | medium 6.8 | Samsung GalaxyDiagnostics: path traversal | https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=09 2026-09-09 | CVE-2026-21104 CVE-2026-21104 | Samsung | high 7.1 | Samsung: heap buffer overflow | https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=09 2026-09-09 | CVE-2026-21105 CVE-2026-21105 | Samsung | medium 5.9 | Samsung Collection: improper access control | https://security.samsungmobile.com/serviceWeb.smsb?year=2026&month=09 2026-09-09 | CVE-2026-21090 CVE-2026-21090 | Samsung | medium 4.8 | Samsung: out-of-bounds write | https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=09 2026-09-09 | CVE-2026-21091 CVE-2026-21091 | Samsung | medium 4.8 | Samsung: out-of-bounds write | https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=09 2026-09-09 | CVE-2026-21092 CVE-2026-21092 | Samsung | high 8.8 | Samsung ImsService: path traversal | https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=09 2026-09-09 | CVE-2026-21093 CVE-2026-21093 | Samsung | medium 5.6 | Samsung: stack buffer overflow | https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=09 2026-09-09 | CVE-2026-21094 CVE-2026-21094 | Samsung | medium 6.1 | Samsung: improper input validation | https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=09 2026-09-09 | CVE-2026-21095 CVE-2026-21095 | Samsung | critical 9.2 | Samsung: heap buffer overflow | https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=09 2026-09-09 | CVE-2026-21096 CVE-2026-21096 | Samsung | critical 9.2 | Samsung: heap buffer overflow | https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=09 2026-09-09 | CVE-2026-21097 CVE-2026-21097 | Samsung | medium 4.6 | Samsung ActivityTaskManagerService: improper authentication | https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=09 2026-09-09 | CVE-2026-21085 CVE-2026-21085 | Samsung | high 8.4 | Samsung: out-of-bounds write | https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=09 2026-09-09 | CVE-2026-21086 CVE-2026-21086 | Samsung | medium 4.8 | Samsung ProxyHandler: improper authorization | https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=09 2026-09-09 | CVE-2026-21087 CVE-2026-21087 | Samsung | high 8.6 | Samsung: out-of-bounds write | https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=09 2026-09-09 | CVE-2026-21088 CVE-2026-21088 | Samsung | medium 6.9 | Samsung: improper input validation | https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=09 2026-09-09 | CVE-2026-21089 CVE-2026-21089 | Samsung | medium 6.9 | Samsung: improper input validation | https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=09 2026-09-09 | CVE-2026-81644 CVE-2026-81644 | Huawei | medium 4.3 | Huawei HarmonyOS: denial of service | https://consumer.huawei.com/en/support/bulletin/2026/9/ 2026-09-09 | CVE-2026-81646 CVE-2026-81646 | Huawei | medium 5.9 | Huawei HarmonyOS: out-of-bounds read | https://consumer.huawei.com/en/support/bulletin/2026/9/ 2026-09-09 | CVE-2026-81647 CVE-2026-81647 | Huawei | medium 5.3 | Huawei HarmonyOS: out-of-bounds read | https://consumer.huawei.com/en/support/bulletin/2026/9/ 2026-09-09 | CVE-2026-49313 CVE-2026-49313 | Huawei | medium 5.5 | Permission control vulnerability in the app lock module | https://consumer.huawei.com/en/support/bulletin/2026/9/ 2026-09-09 | CVE-2026-49314 CVE-2026-49314 | Huawei | high 7.3 | Huawei HarmonyOS: out-of-bounds read | https://consumer.huawei.com/en/support/bulletin/2026/9/ 2026-09-09 | CVE-2026-49315 CVE-2026-49315 | Huawei | high 7.1 | Huawei EMUI: denial of service | https://consumer.huawei.com/en/support/bulletin/2026/9/ 2026-09-09 | CVE-2026-49310 CVE-2026-49310 | Huawei | high 8.6 | Permission control vulnerability in the event notification module | https://consumer.huawei.com/en/support/bulletin/2026/9/ 2026-09-09 | CVE-2026-49311 CVE-2026-49311 | Huawei | medium 6.2 | Permission control vulnerability in the event notification module.Impact | https://consumer.huawei.com/en/support/bulletin/2026/9/ 2026-09-09 | CVE-2026-49312 CVE-2026-49312 | Huawei | medium 4.0 | Permission control vulnerability in the window module | https://consumer.huawei.com/en/support/bulletin/2026/9/ 2026-09-09 | CVE-2026-41987 CVE-2026-41987 | Huawei | medium 6.2 | Permission control vulnerability in the app management module | https://consumer.huawei.com/en/support/bulletin/2026/9/ 2026-09-09 | CVE-2026-49309 CVE-2026-49309 | Huawei | medium 4.8 | Permission control vulnerability in the Settings module | https://consumer.huawei.com/en/support/bulletin/2026/9/ 2026-09-09 | CVE-2026-87655 CVE-2026-87655 | Google | medium 5.4 | Google Chrome: clickjacking | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87656 CVE-2026-87656 | Google | medium 5.4 | Google Chrome: remote attacker could bypass system access restrictions | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87657 CVE-2026-87657 | Google | low 3.1 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87658 CVE-2026-87658 | Google | medium 4.3 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87646 CVE-2026-87646 | Google | critical 9.6 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87647 CVE-2026-87647 | Google | low 3.4 | Google Chrome: uninitialized resource | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87648 CVE-2026-87648 | Google | high 8.3 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87649 CVE-2026-87649 | Google | medium 5.4 | Google Chrome: spoofing | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87650 CVE-2026-87650 | Google | critical 9.6 | Google Chrome: out-of-bounds read | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87651 CVE-2026-87651 | Google | medium 4.3 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87652 CVE-2026-87652 | Google | low 3.1 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87653 CVE-2026-87653 | Google | medium 5.4 | Google Chrome: spoofing | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87654 CVE-2026-87654 | Google | critical 9.6 | Google Chrome: buffer overflow | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87637 CVE-2026-87637 | Google | critical 9.6 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87638 CVE-2026-87638 | Google | critical 9.6 | Google Chrome: out-of-bounds write | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87639 CVE-2026-87639 | Google | high 8.3 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87640 CVE-2026-87640 | Google | medium 6.1 | Google Chrome: out-of-bounds read | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87641 CVE-2026-87641 | Google | medium 4.2 | Google Chrome: race condition | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87642 CVE-2026-87642 | Google | medium 4.3 | Google Chrome: uninitialized resource | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87643 CVE-2026-87643 | Google | critical 9.6 | Google Chrome: integer overflow | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87644 CVE-2026-87644 | Google | high 8.3 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87645 CVE-2026-87645 | Google | medium 5.4 | Google Chrome: remote attacker could bypass system access restrictions | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87628 CVE-2026-87628 | Google | high 8.3 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87629 CVE-2026-87629 | Google | medium 6.5 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87630 CVE-2026-87630 | Google | medium 4.3 | Google Chrome: integer overflow | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87631 CVE-2026-87631 | Google | medium 6.5 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87632 CVE-2026-87632 | Google | medium 4.3 | Google Chrome: cross-site scripting | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87633 CVE-2026-87633 | Google | high 8.6 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87634 CVE-2026-87634 | Google | critical 9.6 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87635 CVE-2026-87635 | Google | medium 5.4 | Google Chrome: spoofing | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87636 CVE-2026-87636 | Google | high 8.8 | Google Chrome: type confusion | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87619 CVE-2026-87619 | Google | medium 4.3 | Google Chrome: observable discrepancy | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87620 CVE-2026-87620 | Google | medium 6.5 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87621 CVE-2026-87621 | Google | critical 9.6 | Google Chrome: out-of-bounds write | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87622 CVE-2026-87622 | Google | medium 4.3 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87623 CVE-2026-87623 | Google | medium 6.5 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87624 CVE-2026-87624 | Google | medium 4.2 | Google Chrome: spoofing | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87625 CVE-2026-87625 | Google | high 8.8 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87626 CVE-2026-87626 | Google | medium 6.5 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87627 CVE-2026-87627 | Google | medium 6.5 | Interpretation conflict in Safebrowsing in Google Chrome on on Mac prior to... | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87610 CVE-2026-87610 | Google | medium 6.5 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87611 CVE-2026-87611 | Google | low 3.1 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87612 CVE-2026-87612 | Google | high 8.8 | Google Chrome: type confusion | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87613 CVE-2026-87613 | Google | critical 9.0 | Google Chrome: remote code execution | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87614 CVE-2026-87614 | Google | low 3.1 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87615 CVE-2026-87615 | Google | medium 5.4 | Google Chrome: race condition | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87616 CVE-2026-87616 | Google | high 8.3 | Google Chrome: remote code execution | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87617 CVE-2026-87617 | Google | high 8.8 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87618 CVE-2026-87618 | Google | high 8.3 | Google Chrome: remote code execution | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87600 CVE-2026-87600 | Google | medium 6.5 | Google Chrome: improper input validation | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87601 CVE-2026-87601 | Google | high 7.5 | Google Chrome: race condition | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87602 CVE-2026-87602 | Google | medium 4.7 | Google Chrome: out-of-bounds read | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87603 CVE-2026-87603 | Google | medium 6.5 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87604 CVE-2026-87604 | Google | high 8.3 | Google Chrome: out-of-bounds read | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87605 CVE-2026-87605 | Google | medium 5.3 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87606 CVE-2026-87606 | Google | high 8.1 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87607 CVE-2026-87607 | Google | critical 9.6 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87608 CVE-2026-87608 | Google | high 7.5 | Google Chrome: improper certificate validation | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87609 CVE-2026-87609 | Google | critical 9.6 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87591 CVE-2026-87591 | Google | medium 6.5 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87592 CVE-2026-87592 | Google | medium 4.3 | Google Chrome: out-of-bounds read | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87593 CVE-2026-87593 | Google | medium 6.5 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87594 CVE-2026-87594 | Google | medium 5.3 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87595 CVE-2026-87595 | Google | critical 9.8 | Google Chrome: server-side request forgery | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87596 CVE-2026-87596 | Google | medium 4.3 | Google Chrome: out-of-bounds read | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87597 CVE-2026-87597 | Google | medium 4.8 | Google Chrome: spoofing | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87598 CVE-2026-87598 | Google | medium 4.3 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87599 CVE-2026-87599 | Google | medium 5.4 | Google Chrome: improper input validation | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87582 CVE-2026-87582 | Google | high 8.3 | Google Chrome: remote code execution | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87583 CVE-2026-87583 | Google | medium 5.4 | Google Chrome: spoofing | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87584 CVE-2026-87584 | Google | medium 6.5 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87585 CVE-2026-87585 | Google | high 8.8 | Google Chrome: double free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87586 CVE-2026-87586 | Google | medium 4.3 | Google Chrome: out-of-bounds read | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87587 CVE-2026-87587 | Google | high 8.8 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87588 CVE-2026-87588 | Google | high 8.8 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87589 CVE-2026-87589 | Google | medium 6.5 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87590 CVE-2026-87590 | Google | medium 5.9 | Google Chrome: improper input validation | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87573 CVE-2026-87573 | Google | medium 4.3 | Google Chrome: improper input validation | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87574 CVE-2026-87574 | Google | medium 4.3 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87575 CVE-2026-87575 | Google | medium 5.4 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87576 CVE-2026-87576 | Google | low 3.4 | Google Chrome: uninitialized resource | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87577 CVE-2026-87577 | Google | medium 4.3 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87578 CVE-2026-87578 | Google | high 8.3 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87579 CVE-2026-87579 | Google | high 8.8 | Google Chrome: buffer overflow | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87580 CVE-2026-87580 | Google | medium 6.5 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87581 CVE-2026-87581 | Google | critical 9.6 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87564 CVE-2026-87564 | Google | medium 4.3 | Google Chrome: type confusion | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87565 CVE-2026-87565 | Google | medium 6.5 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87566 CVE-2026-87566 | Google | medium 5.3 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87567 CVE-2026-87567 | Google | medium 4.3 | Google Chrome: spoofing | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87568 CVE-2026-87568 | Google | medium 4.3 | Google Chrome: improper input validation | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87569 CVE-2026-87569 | Google | high 8.8 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87570 CVE-2026-87570 | Google | high 8.8 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87571 CVE-2026-87571 | Google | medium 5.4 | Google Chrome: improper certificate validation | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87572 CVE-2026-87572 | Google | high 8.3 | Google Chrome: remote code execution | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87554 CVE-2026-87554 | Google | high 8.1 | Google Chrome: race condition | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87555 CVE-2026-87555 | Google | medium 4.7 | Google Chrome: uninitialized resource | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87556 CVE-2026-87556 | Google | medium 4.3 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87557 CVE-2026-87557 | Google | medium 4.3 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87558 CVE-2026-87558 | Google | critical 9.6 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87559 CVE-2026-87559 | Google | medium 4.2 | Google Chrome: spoofing | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87560 CVE-2026-87560 | Google | medium 4.3 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87561 CVE-2026-87561 | Google | medium 4.3 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87562 CVE-2026-87562 | Google | medium 4.3 | Google Chrome: remote attacker could potentially spoof UI elements | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87563 CVE-2026-87563 | Google | medium 4.3 | Google Chrome: origin validation error | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87545 CVE-2026-87545 | Google | medium 6.5 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87546 CVE-2026-87546 | Google | medium 4.3 | Google Chrome: type confusion | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87547 CVE-2026-87547 | Google | critical 9.6 | Google Chrome: remote code execution | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87548 CVE-2026-87548 | Google | medium 4.3 | Google Chrome: remote attacker could bypass system access restrictions | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87549 CVE-2026-87549 | Google | medium 6.5 | Google Chrome: incomplete cleanup | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87550 CVE-2026-87550 | Google | medium 4.3 | Google Chrome: improper output encoding | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87551 CVE-2026-87551 | Google | medium 4.3 | Google Chrome: improper certificate validation | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87552 CVE-2026-87552 | Google | medium 5.5 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87553 CVE-2026-87553 | Google | high 8.3 | Google Chrome: improper input validation | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87536 CVE-2026-87536 | Google | high 8.8 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87537 CVE-2026-87537 | Google | high 8.1 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87538 CVE-2026-87538 | Google | medium 4.2 | Google Chrome: clickjacking | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87539 CVE-2026-87539 | Google | low 3.1 | Google Chrome: observable discrepancy | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87540 CVE-2026-87540 | Google | medium 5.4 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87541 CVE-2026-87541 | Google | medium 6.5 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87542 CVE-2026-87542 | Google | high 8.8 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87543 CVE-2026-87543 | Google | medium 4.3 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87544 CVE-2026-87544 | Google | critical 9.8 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87528 CVE-2026-87528 | Google | critical 9.6 | Google Chrome: type confusion | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87529 CVE-2026-87529 | Google | critical 9.6 | Google Chrome: remote code execution | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87530 CVE-2026-87530 | Google | high 8.1 | Google Chrome: code execution | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87531 CVE-2026-87531 | Google | low 3.1 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87532 CVE-2026-87532 | Google | medium 6.5 | Google Chrome: remote attacker could bypass system access restrictions | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87533 CVE-2026-87533 | Google | high 8.1 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87534 CVE-2026-87534 | Google | critical 9.8 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87535 CVE-2026-87535 | Google | medium 6.5 | Google Chrome: remote attacker could bypass system access restrictions | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87519 CVE-2026-87519 | Google | medium 6.5 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87520 CVE-2026-87520 | Google | critical 9.6 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87521 CVE-2026-87521 | Google | low 3.1 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87522 CVE-2026-87522 | Google | medium 6.5 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87523 CVE-2026-87523 | Google | medium 5.3 | Google Chrome: race condition | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87524 CVE-2026-87524 | Google | high 8.3 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87525 CVE-2026-87525 | Google | low 2.7 | Google Chrome: out-of-bounds read | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87526 CVE-2026-87526 | Google | critical 9.6 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87527 CVE-2026-87527 | Google | critical 9.6 | Google Chrome: buffer overflow | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87510 CVE-2026-87510 | Google | high 8.3 | Google Chrome: improper input validation | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87511 CVE-2026-87511 | Google | medium 4.3 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87512 CVE-2026-87512 | Google | critical 9.6 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87513 CVE-2026-87513 | Google | medium 6.5 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87514 CVE-2026-87514 | Google | high 8.1 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87515 CVE-2026-87515 | Google | medium 6.5 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87516 CVE-2026-87516 | Google | medium 4.3 | Google Chrome: observable discrepancy | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87517 CVE-2026-87517 | Google | low 3.1 | Google Chrome: race condition | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87518 CVE-2026-87518 | Google | medium 5.3 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87501 CVE-2026-87501 | Google | medium 5.4 | Google Chrome: spoofing | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87502 CVE-2026-87502 | Google | medium 4.2 | Confused deputy in Fullscreen in Google Chrome prior to 153.0.8010.36 allowed a... | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87503 CVE-2026-87503 | Google | medium 6.5 | Inappropriate implementation in Downloads in Google Chrome on on Android prior... | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87504 CVE-2026-87504 | Google | critical 9.6 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87505 CVE-2026-87505 | Google | high 8.1 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87506 CVE-2026-87506 | Google | high 8.3 | Google Chrome: remote code execution | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87507 CVE-2026-87507 | Google | medium 5.4 | Google Chrome: spoofing | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87508 CVE-2026-87508 | Google | medium 4.3 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87509 CVE-2026-87509 | Google | high 8.1 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87493 CVE-2026-87493 | Google | medium 6.5 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87494 CVE-2026-87494 | Google | critical 9.6 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87495 CVE-2026-87495 | Google | medium 4.3 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87496 CVE-2026-87496 | Google | medium 5.4 | Google Chrome: spoofing | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87497 CVE-2026-87497 | Google | medium 4.3 | Google Chrome: uninitialized resource | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87498 CVE-2026-87498 | Google | low 3.1 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87499 CVE-2026-87499 | Google | high 8.1 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87500 CVE-2026-87500 | Google | critical 9.6 | Google Chrome: remote code execution | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87484 CVE-2026-87484 | Google | medium 5.4 | Google Chrome: spoofing | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87485 CVE-2026-87485 | Google | low 3.1 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87486 CVE-2026-87486 | Google | medium 4.0 | Google Chrome: clickjacking | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87487 CVE-2026-87487 | Google | high 8.3 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87488 CVE-2026-87488 | Google | critical 9.6 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87489 CVE-2026-87489 | Google | high 8.8 | Google Chrome: memory corruption | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87490 CVE-2026-87490 | Google | medium 6.5 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87491 CVE-2026-87491 | Google | high 8.8 | Google Chrome: out-of-bounds write | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87492 CVE-2026-87492 | Google | critical 9.6 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87475 CVE-2026-87475 | Google | medium 6.5 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87476 CVE-2026-87476 | Google | medium 6.5 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87477 CVE-2026-87477 | Google | medium 6.5 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87478 CVE-2026-87478 | Google | medium 6.5 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87479 CVE-2026-87479 | Google | high 8.3 | Google Chrome: remote code execution | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87480 CVE-2026-87480 | Google | high 8.3 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87481 CVE-2026-87481 | Google | high 8.3 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87482 CVE-2026-87482 | Google | medium 5.9 | Google Chrome: cleartext secrets | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87483 CVE-2026-87483 | Google | medium 6.5 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87465 CVE-2026-87465 | Google | medium 4.2 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87466 CVE-2026-87466 | Google | medium 4.3 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87467 CVE-2026-87467 | Google | high 8.1 | Google Chrome: race condition | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87468 CVE-2026-87468 | Google | medium 6.5 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87469 CVE-2026-87469 | Google | medium 4.3 | Google Chrome: improper input validation | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87470 CVE-2026-87470 | Google | critical 9.6 | Google Chrome: remote code execution | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87471 CVE-2026-87471 | Google | high 8.1 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87472 CVE-2026-87472 | Google | medium 4.2 | Google Chrome: improper input validation | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87473 CVE-2026-87473 | Google | medium 6.5 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87474 CVE-2026-87474 | Google | critical 9.6 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87457 CVE-2026-87457 | Google | high 8.1 | Google Chrome: race condition | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87458 CVE-2026-87458 | Google | medium 5.4 | Google Chrome: spoofing | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87459 CVE-2026-87459 | Google | medium 6.5 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87460 CVE-2026-87460 | Google | high 8.8 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87461 CVE-2026-87461 | Google | medium 4.3 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87462 CVE-2026-87462 | Google | medium 5.4 | Google Chrome: spoofing | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87463 CVE-2026-87463 | Google | medium 4.8 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87464 CVE-2026-87464 | Google | critical 9.6 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87447 CVE-2026-87447 | Google | medium 6.5 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87448 CVE-2026-87448 | Google | critical 9.6 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87449 CVE-2026-87449 | Google | medium 4.3 | Google Chrome: cross-site request forgery | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87450 CVE-2026-87450 | Google | high 7.5 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87451 CVE-2026-87451 | Google | low 3.1 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87452 CVE-2026-87452 | Google | low 3.1 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87453 CVE-2026-87453 | Google | medium 5.3 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87454 CVE-2026-87454 | Google | medium 6.5 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87455 CVE-2026-87455 | Google | critical 9.6 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87456 CVE-2026-87456 | Google | low 3.4 | Google Chrome: uninitialized resource | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87438 CVE-2026-87438 | Google | critical 9.6 | Google Chrome: out-of-bounds write | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87439 CVE-2026-87439 | Google | medium 5.3 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87440 CVE-2026-87440 | Google | high 8.8 | Google Chrome: out-of-bounds read | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87441 CVE-2026-87441 | Google | medium 6.5 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87442 CVE-2026-87442 | Google | low 3.1 | Confused deputy in Prerender in Google Chrome prior to 153.0.8010.36 allowed a... | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87443 CVE-2026-87443 | Google | medium 6.5 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87444 CVE-2026-87444 | Google | high 8.8 | Google Chrome: memory corruption | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87445 CVE-2026-87445 | Google | medium 5.4 | Google Chrome: spoofing | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87446 CVE-2026-87446 | Google | medium 6.5 | Google Chrome: incomplete cleanup | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87429 CVE-2026-87429 | Google | medium 6.5 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87430 CVE-2026-87430 | Google | high 8.8 | Google Chrome: buffer overflow | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87431 CVE-2026-87431 | Google | high 7.5 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87432 CVE-2026-87432 | Google | medium 4.2 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87433 CVE-2026-87433 | Google | high 8.8 | Google Chrome: race condition | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87434 CVE-2026-87434 | Google | low 3.1 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87435 CVE-2026-87435 | Google | medium 5.3 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87436 CVE-2026-87436 | Google | medium 6.5 | Google Chrome: incomplete cleanup | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-87437 CVE-2026-87437 | Google | medium 6.5 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html 2026-09-09 | CVE-2026-19201 CVE-2026-19201 | Google | medium 6.6 | Google go-attestation: denial of service | https://github.com/google/go-attestation/pull/506 2026-09-08 | GHSA-7hgx-277f-7vmg CVE-2026-86996 | n8n | medium | n8n: Agent Workflow Tool Bypasses Sub-Workflow Caller Policy | https://github.com/advisories/GHSA-7hgx-277f-7vmg 2026-09-08 | GHSA-4hhp-h66f-j5j7 CVE-2026-73560 | vLLM | medium 6.5 | vLLM: server-side request forgery | https://github.com/advisories/GHSA-4hhp-h66f-j5j7 2026-09-08 | GHSA-8mpw-7fpc-4gqj CVE-2026-81725 | NLTK | medium | NLTK: Pl196xCorpusReader has quadratic ReDoS on malformed TEI blocks | https://github.com/advisories/GHSA-8mpw-7fpc-4gqj 2026-09-08 | GHSA-w3v8-gmh9-3wv7 CVE-2026-80206 | NLTK | high | NLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions | https://github.com/advisories/GHSA-w3v8-gmh9-3wv7 2026-09-08 | GHSA-rrv8-h7p8-rx55 CVE-2026-80205 | NLTK | high 7.5 | NLTK: ReDoS in nltk.text.Text.findall() via unvalidated user-supplied regular expressions | https://github.com/advisories/GHSA-rrv8-h7p8-rx55 2026-09-08 | GHSA-7m6h-x95x-82q5 CVE-2026-73558 | vLLM | medium 5.3 | vLLM: Cross-User Data Leak Vulnerability | https://github.com/advisories/GHSA-7m6h-x95x-82q5 2026-09-08 | GHSA-3gq4-3j92-5w49 CVE-2026-79674 | NLTK | high | NLTK: Corpus Reader Sandbox Bypass | https://github.com/advisories/GHSA-3gq4-3j92-5w49 2026-09-08 | GHSA-p4rw-rvv2-7xwr CVE-2026-79676 | NLTK | high | NLTK: Corpus readers follow symlinks outside trusted roots despite pathsec enforcement | https://github.com/advisories/GHSA-p4rw-rvv2-7xwr 2026-09-08 | GHSA-x99w-6fgc-pmfw CVE-2026-79657 | NLTK | critical | NLTK: Allowlisted pickle loaders still permit code execution in current source | https://github.com/advisories/GHSA-x99w-6fgc-pmfw 2026-09-08 | GHSA-97qj-x29f-37w7 CVE-2026-78681 | NLTK | high | NLTK: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parses | https://github.com/advisories/GHSA-97qj-x29f-37w7 2026-09-08 | GHSA-6ww7-3frv-cqxh CVE-2026-78682 | NLTK | high | NLTK: pathsec SSRF protection can be bypassed when a proxy is configured | https://github.com/advisories/GHSA-6ww7-3frv-cqxh 2026-09-08 | GHSA-rhp5-r9x4-f5g2 CVE-2026-78683 | NLTK | critical | NLTK: Unsafe Pickle Deserialization in TransitionParser Allows Remote Code Execution | https://github.com/advisories/GHSA-rhp5-r9x4-f5g2 2026-09-08 | GHSA-3hhw-38pf-pxj6 CVE-2026-62383 | NLTK | medium 5.5 | NLTK: Symlink-based arbitrary file read in IPIPANCorpusReader, bypasses nltk.pathsec entirely | https://github.com/advisories/GHSA-3hhw-38pf-pxj6 2026-09-08 | GHSA-f833-7jw8-xwrv CVE-2026-62384 | NLTK | high 7.5 | NLTK: Symlink-based sandbox bypass in FramenetCorpusReader (bypasses the fix for CVE-2026-54292) | https://github.com/advisories/GHSA-f833-7jw8-xwrv 2026-09-08 | GHSA-568f-pv23-39p4 CVE-2026-62385 | NLTK | high 5.9 | NLTK: Stable FrameNet and NKJP readers parse outside-root XML | https://github.com/advisories/GHSA-568f-pv23-39p4 2026-09-08 | GHSA-5wp5-5229-5g6q CVE-2026-12259 | NLTK | medium 5.3 | NLTK: Missing Post-Download Integrity Verification Allows Malicious Package Injection | https://github.com/advisories/GHSA-5wp5-5229-5g6q 2026-09-08 | GHSA-x5ph-mj9p-rfr8 CVE-2026-63312 | NLTK | high | NLTK: StreamBackedCorpusView Bypasses pathsec.ENFORCE - Arbitrary Local File Read | https://github.com/advisories/GHSA-x5ph-mj9p-rfr8 2026-09-08 | GHSA-72r2-7mfr-5xr9 CVE-2026-65915 | NLTK | medium 6.5 | NLTK: FileSystemPathPointer.open() sandbox check is dead code , arbitrary file read via file:// protocol | https://github.com/advisories/GHSA-72r2-7mfr-5xr9 2026-09-08 | GHSA-r6gq-whwq-mvg9 CVE-2026-70626 | NLTK | high 6.2 | NLTK: Symlink escape in CorpusReader allows arbitrary local file read outside the corpus root | https://github.com/advisories/GHSA-r6gq-whwq-mvg9 2026-09-08 | CVE-2026-86564 CVE-2026-86564 | Red Hat | low 3.3 | Red Hat DPDK lib/vhost. Missing length validation: out-of-bounds read | https://access.redhat.com/security/cve/CVE-2026-86564 2026-09-08 | CVE-2026-18090 CVE-2026-18090 | Red Hat | medium 6.1 | Red Hat gdk-pixbuf. This vulnerability: out-of-bounds read | https://access.redhat.com/security/cve/CVE-2026-18090 2026-09-08 | CVE-2026-85981 CVE-2026-85981 | Okta | medium 6.7 | Okta Auth0 AD/LDAP Connector: missing authentication | https://trust.okta.com/security-advisories/unauthenticated-localhost-admin-panel-in-auth0-ad-ldap-connector-cve-2026-85981 2026-09-08 | CVE-2026-85982 CVE-2026-85982 | Okta | critical 9.0 | Okta Auth0 AD/LDAP Connector: cross-site scripting | https://trust.okta.com/security-advisories/stored-cross-site-scripting-xss-in-auth0-ad-ldap-connector-cve-2026-85982 2026-09-08 | CVE-2026-85983 CVE-2026-85983 | Okta | high 7.8 | Okta Auth0 AD/LDAP Connector: code execution | https://trust.okta.com/security-advisories/local-privilege-escalation-in-auth0-ad-ldap-connector-cve-2026-85983 2026-09-08 | CVE-2026-81993 CVE-2026-81993 | Adobe | medium 5.5 | Adobe Acrobat 2024: heap buffer overflow | https://helpx.adobe.com/security/products/acrobat/apsb26-141.html 2026-09-08 | CVE-2026-81994 CVE-2026-81994 | Adobe | high 8.2 | Adobe Acrobat 2024: prototype pollution | https://helpx.adobe.com/security/products/acrobat/apsb26-141.html 2026-09-08 | CVE-2026-81996 CVE-2026-81996 | Adobe | high 8.8 | Adobe Acrobat 2024: improper authorization | https://helpx.adobe.com/security/products/acrobat/apsb26-141.html 2026-09-08 | CVE-2026-81997 CVE-2026-81997 | Adobe | medium 6.3 | Adobe Acrobat 2024: improper authorization | https://helpx.adobe.com/security/products/acrobat/apsb26-141.html 2026-09-08 | CVE-2026-82001 CVE-2026-82001 | Adobe | medium 5.5 | Adobe Acrobat 2024: resource exhaustion | https://helpx.adobe.com/security/products/acrobat/apsb26-141.html 2026-09-08 | CVE-2026-84685 CVE-2026-84685 | Okta | medium 6.5 | The react-native-auth0 SDK's web platform implementation does not scope its... | https://trust.okta.com/security-advisories/improper-cache-isolation-in-auth0-react-native-auth0-sdk-web-platform-credential-management-cve-2026-84685 2026-09-08 | CVE-2026-81985 CVE-2026-81985 | Adobe | high 7.8 | Adobe Acrobat 2024: use after free | https://helpx.adobe.com/security/products/acrobat/apsb26-141.html 2026-09-08 | CVE-2026-81986 CVE-2026-81986 | Adobe | high 7.8 | Adobe Acrobat 2024: use after free | https://helpx.adobe.com/security/products/acrobat/apsb26-141.html 2026-09-08 | CVE-2026-81987 CVE-2026-81987 | Adobe | high 7.8 | Adobe Acrobat 2024: integer overflow | https://helpx.adobe.com/security/products/acrobat/apsb26-141.html 2026-09-08 | CVE-2026-81988 CVE-2026-81988 | Adobe | high 7.8 | Adobe Acrobat 2024: use after free | https://helpx.adobe.com/security/products/acrobat/apsb26-141.html 2026-09-08 | CVE-2026-81989 CVE-2026-81989 | Adobe | high 7.8 | Adobe Acrobat 2024: use after free | https://helpx.adobe.com/security/products/acrobat/apsb26-141.html 2026-09-08 | CVE-2026-81990 CVE-2026-81990 | Adobe | high 7.8 | Adobe Acrobat 2024: use after free | https://helpx.adobe.com/security/products/acrobat/apsb26-141.html 2026-09-08 | CVE-2026-81991 CVE-2026-81991 | Adobe | medium 5.5 | Adobe Acrobat 2024: out-of-bounds read | https://helpx.adobe.com/security/products/acrobat/apsb26-141.html 2026-09-08 | CVE-2026-81992 CVE-2026-81992 | Adobe | high 7.8 | Adobe Acrobat 2024: heap buffer overflow | https://helpx.adobe.com/security/products/acrobat/apsb26-141.html 2026-09-08 | CVE-2026-81976 CVE-2026-81976 | Adobe | high 7.8 | Adobe Acrobat 2024: use after free | https://helpx.adobe.com/security/products/acrobat/apsb26-141.html 2026-09-08 | CVE-2026-81977 CVE-2026-81977 | Adobe | medium 5.5 | Adobe Acrobat 2024: integer overflow | https://helpx.adobe.com/security/products/acrobat/apsb26-141.html 2026-09-08 | CVE-2026-81978 CVE-2026-81978 | Adobe | medium 5.5 | Adobe Acrobat 2024: out-of-bounds read | https://helpx.adobe.com/security/products/acrobat/apsb26-141.html 2026-09-08 | CVE-2026-81979 CVE-2026-81979 | Adobe | high 7.8 | Adobe Acrobat 2024: out-of-bounds write | https://helpx.adobe.com/security/products/acrobat/apsb26-141.html 2026-09-08 | CVE-2026-81980 CVE-2026-81980 | Adobe | high 7.8 | Adobe Acrobat 2024: out-of-bounds write | https://helpx.adobe.com/security/products/acrobat/apsb26-141.html 2026-09-08 | CVE-2026-81981 CVE-2026-81981 | Adobe | high 7.8 | Adobe Acrobat 2024: out-of-bounds write | https://helpx.adobe.com/security/products/acrobat/apsb26-141.html 2026-09-08 | CVE-2026-81982 CVE-2026-81982 | Adobe | medium 5.5 | Adobe Acrobat 2024: out-of-bounds read | https://helpx.adobe.com/security/products/acrobat/apsb26-141.html 2026-09-08 | CVE-2026-81983 CVE-2026-81983 | Adobe | high 7.8 | Adobe Acrobat 2024: out-of-bounds write | https://helpx.adobe.com/security/products/acrobat/apsb26-141.html 2026-09-08 | CVE-2026-81984 CVE-2026-81984 | Adobe | medium 5.5 | Adobe Acrobat 2024: use after free | https://helpx.adobe.com/security/products/acrobat/apsb26-141.html 2026-09-08 | CVE-2026-80160 CVE-2026-80160 | Adobe | medium 5.5 | Adobe Acrobat 2024: out-of-bounds read | https://helpx.adobe.com/security/products/acrobat/apsb26-141.html 2026-09-08 | CVE-2026-80161 CVE-2026-80161 | Adobe | high 7.8 | Adobe Acrobat 2024: type confusion | https://helpx.adobe.com/security/products/acrobat/apsb26-141.html 2026-09-08 | CVE-2026-80162 CVE-2026-80162 | Adobe | medium 5.5 | Adobe Acrobat 2024: use after free | https://helpx.adobe.com/security/products/acrobat/apsb26-141.html 2026-09-08 | CVE-2026-81973 CVE-2026-81973 | Adobe | high 7.8 | Adobe Acrobat 2024: use after free | https://helpx.adobe.com/security/products/acrobat/apsb26-141.html 2026-09-08 | CVE-2026-81975 CVE-2026-81975 | Adobe | high 7.8 | Adobe Acrobat 2024: use after free | https://helpx.adobe.com/security/products/acrobat/apsb26-141.html 2026-09-08 | CVE-2026-79907 CVE-2026-79907 | Adobe | high 7.8 | Adobe Acrobat 2024: double free | https://helpx.adobe.com/security/products/acrobat/apsb26-141.html 2026-09-08 | CVE-2026-79908 CVE-2026-79908 | Adobe | high 7.8 | Adobe Acrobat 2024: out-of-bounds write | https://helpx.adobe.com/security/products/acrobat/apsb26-141.html 2026-09-08 | CVE-2026-79909 CVE-2026-79909 | Adobe | high 7.8 | Adobe Acrobat 2024: use after free | https://helpx.adobe.com/security/products/acrobat/apsb26-141.html 2026-09-08 | CVE-2026-79910 CVE-2026-79910 | Adobe | medium 5.5 | Adobe Acrobat 2024: out-of-bounds read | https://helpx.adobe.com/security/products/acrobat/apsb26-141.html 2026-09-08 | CVE-2026-80159 CVE-2026-80159 | Adobe | medium 4.0 | Adobe Acrobat 2024: untrusted search path | https://helpx.adobe.com/security/products/acrobat/apsb26-141.html 2026-09-08 | CVE-2026-78622 CVE-2026-78622 | Okta | medium 6.0 | Okta Verify for Windows: link following | https://trust.okta.com/security-advisories/improper-link-resolution-in-okta-verify-for-windows-uninstaller-data-removal-cve-2026-78622 2026-09-08 | CVE-2026-78629 CVE-2026-78629 | Okta | medium 5.6 | The Okta Hyperdrive agent plugin returns a success response without a signed... | https://trust.okta.com/security-advisories/improper-authentication-verification-in-the-okta-hyperdrive-agent-mfa-response-handling-cve-2026-78629 2026-09-08 | CVE-2026-78630 CVE-2026-78630 | Okta | medium 6.7 | Okta Access Gateway: command injection | https://trust.okta.com/security-advisories/improper-input-neutralization-in-okta-access-gateway-snmp-configuration-processing-cve-2026-78630 2026-09-08 | CVE-2026-78631 CVE-2026-78631 | Okta | medium 5.3 | Okta Hyperdrive Agent: information disclosure | https://trust.okta.com/security-advisories/improper-restriction-of-sensitive-information-in-okta-hyperdrive-agent-logging-cve-2026-78631 2026-09-08 | CVE-2026-78635 CVE-2026-78635 | Okta | medium 5.0 | Okta Privileged Access Client: argument injection | https://trust.okta.com/security-advisories/improper-input-validation-in-the-okta-privileged-access-ssh-client-url-handler-argument-cve-2026-78635 2026-09-08 | CVE-2026-19651 CVE-2026-19651 | IBM | high 7.4 | IBM Enterprise Build of Quarkus: insecure direct object reference | https://www.ibm.com/support/pages/node/7286498 2026-09-08 | CVE-2026-19625 CVE-2026-19625 | IBM | medium 5.3 | IBM Enterprise Build of Quarkus: improper access control | https://www.ibm.com/support/pages/node/7286498 2026-09-08 | CVE-2026-82007 CVE-2026-82007 | Adobe | high 7.8 | Adobe Photoshop: integer overflow | https://helpx.adobe.com/security/products/photoshop/apsb26-130.html 2026-09-08 | CVE-2026-82005 CVE-2026-82005 | Adobe | high 7.8 | Adobe Photoshop: out-of-bounds write | https://helpx.adobe.com/security/products/photoshop/apsb26-130.html 2026-09-08 | CVE-2026-82006 CVE-2026-82006 | Adobe | high 7.8 | Adobe Photoshop: heap buffer overflow | https://helpx.adobe.com/security/products/photoshop/apsb26-130.html 2026-09-08 | CVE-2026-79905 CVE-2026-79905 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-78626 CVE-2026-78626 | Okta | high 8.1 | Okta Access Gateway: improper authorization | https://trust.okta.com/security-advisories/improper-input-sanitization-in-okta-access-gateway-protected-rules-cve-2026-78626 2026-09-08 | CVE-2026-78627 CVE-2026-78627 | Okta | high 7.3 | Okta Hyperdrive Integration Plugin: secrets in logs | https://trust.okta.com/security-advisories/improper-credential-protection-in-okta-hyperdrive-integration-installer-logging-cve-2026-78627 2026-09-08 | CVE-2026-78623 CVE-2026-78623 | Okta | high 7.7 | Okta Access Gateway: SQL injection | https://trust.okta.com/security-advisories/improper-handling-of-saml-assertion-attributes-in-okta-access-gateway-advanced-mode-datastores-cve-2026-78623 2026-09-08 | CVE-2026-78624 CVE-2026-78624 | Okta | medium 4.9 | Okta Access Gateway: path traversal | https://trust.okta.com/security-advisories/improper-path-validation-in-okta-access-gateway-backup-and-restore-functionality-cve-2026-78624 2026-09-08 | CVE-2026-78625 CVE-2026-78625 | Okta | medium 6.7 | Okta Access Gateway: code injection | https://trust.okta.com/security-advisories/insufficient-validation-of-dashboard-application-labels-in-okta-access-gateway-dashboard-site-configuration-cve-2026-78625 2026-09-08 | CVE-2026-78552 CVE-2026-78552 | Okta | medium 6.0 | Okta Access Gateway: protection mechanism failure | https://trust.okta.com/security-advisories/validation-bypass-in-okta-access-gateway-custom-directives-cve-2026-78552 2026-09-08 | CVE-2026-78560 CVE-2026-78560 | Okta | medium 4.8 | Okta Access Gateway: improper authentication | https://trust.okta.com/security-advisories/improper-authentication-validation-in-okta-access-gateway-pass-through-authentication-source-cve-2026-78560 2026-09-08 | CVE-2026-78574 CVE-2026-78574 | Okta | high 7.5 | Okta Hyperdrive Integration Plugin: untrusted search path | https://trust.okta.com/security-advisories/improper-assembly-resolution-in-okta-hyperdrive-integration-plugin-registry-handling-cve-2026-78574 2026-09-08 | CVE-2026-78579 CVE-2026-78579 | Okta | medium 6.8 | The Okta Access Gateway does not sanitize SAML assertion attribute values... | https://trust.okta.com/security-advisories/improper-input-sanitization-in-okta-access-gateway-ldap-datastore-filter-interpolation-cve-2026-78579 2026-09-08 | CVE-2026-78620 CVE-2026-78620 | Okta | medium 5.9 | The Okta Access Gateway Kerberos configuration handler does not validate file... | https://trust.okta.com/security-advisories/improper-path-validation-in-okta-access-gateway-kerberos-configuration-handling-cve-2026-78620 2026-09-08 | CVE-2026-78545 CVE-2026-78545 | Okta | medium 6.6 | Okta Access Gateway: code injection | https://trust.okta.com/security-advisories/improper-input-sanitization-in-okta-access-gateway-application-label-configuration-cve-2026-78545/ 2026-09-08 | CVE-2026-78550 CVE-2026-78550 | Okta | medium 6.6 | Okta Access Gateway: code execution | https://trust.okta.com/security-advisories/improper-input-handling-in-okta-access-gateway-management-console-exception-handler-cve-2026-78550 2026-09-08 | CVE-2026-76002 CVE-2026-76002 | Adobe | medium 6.1 | Adobe ColdFusion: cross-site scripting | https://helpx.adobe.com/security/products/coldfusion/apsb26-119.html 2026-09-08 | CVE-2026-76190 CVE-2026-76190 | Adobe | high 8.6 | Adobe ColdFusion: code execution | https://helpx.adobe.com/security/products/coldfusion/apsb26-119.html 2026-09-08 | CVE-2026-76199 CVE-2026-76199 | Adobe | high 8.6 | Adobe Photoshop: code execution | https://helpx.adobe.com/security/products/photoshop/apsb26-130.html 2026-09-08 | CVE-2026-75991 CVE-2026-75991 | Adobe | high 8.6 | Adobe Illustrator Desktop: improper input validation | https://helpx.adobe.com/security/products/illustrator/apsb26-131.html 2026-09-08 | CVE-2026-75992 CVE-2026-75992 | Adobe | high 7.8 | Adobe Illustrator Desktop: out-of-bounds write | https://helpx.adobe.com/security/products/illustrator/apsb26-131.html 2026-09-08 | CVE-2026-75993 CVE-2026-75993 | Adobe | high 8.5 | Adobe ColdFusion: cross-site scripting | https://helpx.adobe.com/security/products/coldfusion/apsb26-119.html 2026-09-08 | CVE-2026-75998 CVE-2026-75998 | Adobe | high 7.5 | Adobe ColdFusion: improper access control | https://helpx.adobe.com/security/products/coldfusion/apsb26-119.html 2026-09-08 | CVE-2026-75999 CVE-2026-75999 | Adobe | high 8.4 | Adobe ColdFusion: improper input validation | https://helpx.adobe.com/security/products/coldfusion/apsb26-119.html 2026-09-08 | CVE-2026-76000 CVE-2026-76000 | Adobe | medium 6.5 | Adobe ColdFusion: resource exhaustion | https://helpx.adobe.com/security/products/coldfusion/apsb26-119.html 2026-09-08 | CVE-2026-75742 CVE-2026-75742 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75746 CVE-2026-75746 | Adobe | critical 9.1 | Adobe ColdFusion: SQL injection | https://helpx.adobe.com/security/products/coldfusion/apsb26-119.html 2026-09-08 | CVE-2026-75771 CVE-2026-75771 | Adobe | high 7.8 | Adobe Photoshop: integer overflow | https://helpx.adobe.com/security/products/photoshop/apsb26-130.html 2026-09-08 | CVE-2026-75862 CVE-2026-75862 | Adobe | high 7.8 | Adobe Photoshop: integer overflow | https://helpx.adobe.com/security/products/photoshop/apsb26-130.html 2026-09-08 | CVE-2026-75863 CVE-2026-75863 | Adobe | high 7.8 | Adobe Photoshop: integer overflow | https://helpx.adobe.com/security/products/photoshop/apsb26-130.html 2026-09-08 | CVE-2026-75990 CVE-2026-75990 | Adobe | high 8.6 | Adobe Illustrator Desktop: improper authorization | https://helpx.adobe.com/security/products/illustrator/apsb26-131.html 2026-09-08 | CVE-2026-75734 CVE-2026-75734 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75735 CVE-2026-75735 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75736 CVE-2026-75736 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75737 CVE-2026-75737 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75738 CVE-2026-75738 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75739 CVE-2026-75739 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75740 CVE-2026-75740 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75741 CVE-2026-75741 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75722 CVE-2026-75722 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75724 CVE-2026-75724 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75725 CVE-2026-75725 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75726 CVE-2026-75726 | Adobe | low 3.5 | Adobe Experience Manager: improper input validation | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75727 CVE-2026-75727 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75729 CVE-2026-75729 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75730 CVE-2026-75730 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75731 CVE-2026-75731 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75733 CVE-2026-75733 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75713 CVE-2026-75713 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75714 CVE-2026-75714 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75715 CVE-2026-75715 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75716 CVE-2026-75716 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75717 CVE-2026-75717 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75718 CVE-2026-75718 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75719 CVE-2026-75719 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75720 CVE-2026-75720 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75704 CVE-2026-75704 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75705 CVE-2026-75705 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75706 CVE-2026-75706 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75707 CVE-2026-75707 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75708 CVE-2026-75708 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75709 CVE-2026-75709 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75710 CVE-2026-75710 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75711 CVE-2026-75711 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75712 CVE-2026-75712 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75692 CVE-2026-75692 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75693 CVE-2026-75693 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75694 CVE-2026-75694 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75695 CVE-2026-75695 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75696 CVE-2026-75696 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75700 CVE-2026-75700 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75701 CVE-2026-75701 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75702 CVE-2026-75702 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75679 CVE-2026-75679 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75680 CVE-2026-75680 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75681 CVE-2026-75681 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75683 CVE-2026-75683 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75685 CVE-2026-75685 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75687 CVE-2026-75687 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75690 CVE-2026-75690 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75691 CVE-2026-75691 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75668 CVE-2026-75668 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75669 CVE-2026-75669 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75670 CVE-2026-75670 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75671 CVE-2026-75671 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75672 CVE-2026-75672 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75674 CVE-2026-75674 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75675 CVE-2026-75675 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75677 CVE-2026-75677 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75678 CVE-2026-75678 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75651 CVE-2026-75651 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75652 CVE-2026-75652 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75657 CVE-2026-75657 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75659 CVE-2026-75659 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75660 CVE-2026-75660 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75661 CVE-2026-75661 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75666 CVE-2026-75666 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75667 CVE-2026-75667 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75637 CVE-2026-75637 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75639 CVE-2026-75639 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75640 CVE-2026-75640 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75642 CVE-2026-75642 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75643 CVE-2026-75643 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75644 CVE-2026-75644 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75646 CVE-2026-75646 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75647 CVE-2026-75647 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75629 CVE-2026-75629 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75631 CVE-2026-75631 | Adobe | high 7.8 | Adobe Photoshop: out-of-bounds write | https://helpx.adobe.com/security/products/photoshop/apsb26-130.html 2026-09-08 | CVE-2026-75635 CVE-2026-75635 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-75636 CVE-2026-75636 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-72626 CVE-2026-72626 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-72627 CVE-2026-72627 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-71565 CVE-2026-71565 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-71356 CVE-2026-71356 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-71357 CVE-2026-71357 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-71388 CVE-2026-71388 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-71440 CVE-2026-71440 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-48273 CVE-2026-48273 | Adobe | critical 9.9 | Adobe ColdFusion: code execution | https://helpx.adobe.com/security/products/coldfusion/apsb26-119.html 2026-09-08 | CVE-2026-49883 CVE-2026-49883 | Google | critical 10.0 | Google Android Wear: information disclosure | https://source.android.com/docs/security/bulletin/wear/2026/2026-09-01 2026-09-08 | CVE-2026-28659 CVE-2026-28659 | Google | critical 10.0 | Google Android XR: privilege escalation | https://source.android.com/docs/security/bulletin/xr/2026/2026-09-01 2026-09-08 | CVE-2026-27227 CVE-2026-27227 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-19479 CVE-2026-19479 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-19612 CVE-2026-19612 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-19644 CVE-2026-19644 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-19713 CVE-2026-19713 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-19232 CVE-2026-19232 | Adobe | critical 9.9 | Adobe Experience Manager: improper authorization | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2025-64866 CVE-2025-64866 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2025-64868 CVE-2025-64868 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2025-64584 CVE-2025-64584 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2025-64588 CVE-2025-64588 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2025-64589 CVE-2025-64589 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2025-64610 CVE-2025-64610 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2025-64618 CVE-2025-64618 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2025-64830 CVE-2025-64830 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2025-64838 CVE-2025-64838 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2025-64854 CVE-2025-64854 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2025-64542 CVE-2025-64542 | Adobe | medium 5.4 | Adobe Experience Manager: cross-site scripting | https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html 2026-09-08 | CVE-2026-82004 CVE-2026-82004 | Adobe | critical 10.0 | Adobe Campaign Classic: command injection | https://helpx.adobe.com/security/products/campaign/apsb26-142.html 2026-09-08 | CVE-2026-77774 CVE-2026-77774 | Adobe | high 8.6 | Adobe Commerce: improper authorization | https://helpx.adobe.com/security/products/magento/apsb26-138.html 2026-09-08 | CVE-2026-76202 CVE-2026-76202 | Adobe | high 8.2 | Adobe Commerce: improper authorization | https://helpx.adobe.com/security/products/magento/apsb26-138.html 2026-09-08 | CVE-2026-77108 CVE-2026-77108 | Adobe | high 7.5 | Adobe Commerce: improper authorization | https://helpx.adobe.com/security/products/magento/apsb26-138.html 2026-09-08 | CVE-2026-77109 CVE-2026-77109 | Adobe | high 8.6 | Adobe Commerce: improper authorization | https://helpx.adobe.com/security/products/magento/apsb26-138.html 2026-09-08 | CVE-2026-77110 CVE-2026-77110 | Adobe | high 7.6 | Adobe Commerce: path traversal | https://helpx.adobe.com/security/products/magento/apsb26-138.html 2026-09-08 | CVE-2026-77111 CVE-2026-77111 | Adobe | high 8.7 | Adobe Commerce: improper authorization | https://helpx.adobe.com/security/products/magento/apsb26-138.html 2026-09-08 | CVE-2026-76200 CVE-2026-76200 | Adobe | critical 9.3 | Adobe Commerce: cross-site scripting | https://helpx.adobe.com/security/products/magento/apsb26-138.html 2026-09-08 | CVE-2026-76201 CVE-2026-76201 | Adobe | critical 9.3 | Adobe Commerce: cross-site scripting | https://helpx.adobe.com/security/products/magento/apsb26-138.html 2026-09-08 | CVE-2026-69646 CVE-2026-69646 | Microsoft | high 8.3 | Microsoft Skype for Business: spoofing | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69646 2026-09-08 | CVE-2026-69642 CVE-2026-69642 | Microsoft | medium 6.5 | Microsoft Skype for Business: cross-site scripting | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69642 2026-09-08 | CVE-2026-66305 CVE-2026-66305 | Microsoft | high 7.1 | Microsoft Skype for Business: spoofing | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66305 2026-09-08 | CVE-2026-66306 CVE-2026-66306 | Microsoft | medium 6.5 | Microsoft Skype for Business: information disclosure | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66306 2026-09-08 | CVE-2026-66307 CVE-2026-66307 | Microsoft | high 7.5 | Microsoft Skype for Business: integer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66307 2026-09-08 | CVE-2026-66308 CVE-2026-66308 | Microsoft | medium 6.5 | Microsoft Skype for Business: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66308 2026-09-08 | CVE-2026-63523 CVE-2026-63523 | Microsoft | medium 6.5 | Microsoft Skype for Business: cross-site scripting | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63523 2026-09-08 | CVE-2026-66302 CVE-2026-66302 | Microsoft | critical 9.8 | Microsoft Skype for Business: remote code execution | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66302 2026-09-08 | CVE-2026-66303 CVE-2026-66303 | Microsoft | medium 6.5 | Microsoft Skype for Business: null pointer dereference | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66303 2026-09-08 | CVE-2026-66304 CVE-2026-66304 | Microsoft | high 7.5 | Microsoft Skype for Business: server-side request forgery | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66304 2026-09-08 | CVE-2026-58846 CVE-2026-58846 | Google | high 7.8 | Google Android: use after free | https://android.googlesource.com/kernel/common/+/ad34d15396568919a8ddd306ce2120e76d111b7c 2026-09-08 | CVE-2026-58848 CVE-2026-58848 | Google | high 7.0 | Google Android: race condition | https://android.googlesource.com/kernel/common/+/8f68185b8289dbe43e96f3d2b036c81c83cc58aa 2026-09-08 | CVE-2026-58874 CVE-2026-58874 | Google | high 7.8 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-58941 CVE-2026-58941 | Google | high 7.8 | Google Android: out-of-bounds read | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-58820 CVE-2026-58820 | Google | high 7.8 | Google Android: integer overflow | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-58822 CVE-2026-58822 | Google | critical 9.8 | Google Android: remote code execution | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-58823 CVE-2026-58823 | Google | high 7.8 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-58839 CVE-2026-58839 | Google | high 7.8 | Google Android: out-of-bounds read | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-55273 CVE-2026-55273 | Google | high 7.8 | Google Android: improper input validation | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-55277 CVE-2026-55277 | Google | high 8.0 | Google Android: out-of-bounds write | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-55285 CVE-2026-55285 | Google | high 7.8 | Google Android: out-of-bounds write | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-55290 CVE-2026-55290 | Google | low 3.3 | Google Android: information disclosure | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-55294 CVE-2026-55294 | Google | high 7.8 | Google Android: out-of-bounds write | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-55256 CVE-2026-55256 | Google | medium 6.5 | Google Android: denial of service | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-49918 CVE-2026-49918 | Google | high 7.8 | Google Android: out-of-bounds write | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-49919 CVE-2026-49919 | Google | high 7.8 | Google Android: remote code execution | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-49921 CVE-2026-49921 | Google | critical 9.8 | Google Android: buffer overflow | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-49927 CVE-2026-49927 | Google | high 7.8 | Google Android: out-of-bounds write | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-49932 CVE-2026-49932 | Google | high 7.8 | Google Android: out-of-bounds read | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-45528 CVE-2026-45528 | Google | high 7.3 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-45531 CVE-2026-45531 | Google | high 7.8 | Google Android: out-of-bounds read | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-49879 CVE-2026-49879 | Google | high 8.8 | Google Android: out-of-bounds write | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-49881 CVE-2026-49881 | Google | high 7.8 | Google Android: code execution | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-49882 CVE-2026-49882 | Google | high 8.8 | Google Android: buffer overflow | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-49884 CVE-2026-49884 | Google | high 7.8 | Google Android: out-of-bounds write | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-49887 CVE-2026-49887 | Google | high 7.8 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-49895 CVE-2026-49895 | Google | low 3.5 | Google Android: out-of-bounds read | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28671 CVE-2026-28671 | Google | low 3.3 | Google Android: race condition | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-45515 CVE-2026-45515 | Google | high 7.8 | Google Android: out-of-bounds write | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-45519 CVE-2026-45519 | Google | low 3.3 | Google Android: information disclosure | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-45520 CVE-2026-45520 | Google | high 7.8 | Google Android: authentication bypass | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-45521 CVE-2026-45521 | Google | low 3.3 | Google Android: information disclosure | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-45525 CVE-2026-45525 | Google | low 3.3 | Google Android: information disclosure | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-45527 CVE-2026-45527 | Google | medium 4.3 | Google Android: denial of service | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28656 CVE-2026-28656 | Google | high 7.3 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/wear/2026/2026-09-01 2026-09-08 | CVE-2026-28657 CVE-2026-28657 | Google | high 7.8 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28658 CVE-2026-28658 | Google | high 7.8 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28660 CVE-2026-28660 | Google | low 3.3 | Google Android: information disclosure | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28662 CVE-2026-28662 | Google | high 8.0 | Google Android: out-of-bounds write | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28663 CVE-2026-28663 | Google | high 7.8 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28664 CVE-2026-28664 | Google | high 7.8 | Google Android: tampering | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28666 CVE-2026-28666 | Google | high 8.8 | Google Android: denial of service | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28668 CVE-2026-28668 | Google | high 7.8 | Google Android: use after free | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28634 CVE-2026-28634 | Google | high 7.8 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28636 CVE-2026-28636 | Google | high 7.8 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28638 CVE-2026-28638 | Google | low 3.3 | Google Android: information disclosure | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28639 CVE-2026-28639 | Google | high 7.8 | Google Android: out-of-bounds write | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28642 CVE-2026-28642 | Google | high 7.8 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28644 CVE-2026-28644 | Google | high 7.8 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28650 CVE-2026-28650 | Google | high 7.8 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28652 CVE-2026-28652 | Google | low 3.1 | Google Android: information disclosure | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28653 CVE-2026-28653 | Google | high 7.8 | Google Android: out-of-bounds write | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28655 CVE-2026-28655 | Google | high 7.8 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28620 CVE-2026-28620 | Google | high 7.8 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28622 CVE-2026-28622 | Google | low 3.3 | Google Android: information disclosure | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28623 CVE-2026-28623 | Google | low 3.3 | Google Android: information disclosure | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28624 CVE-2026-28624 | Google | high 7.8 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28626 CVE-2026-28626 | Google | high 7.3 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28627 CVE-2026-28627 | Google | medium 4.3 | Google Android: information disclosure | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28630 CVE-2026-28630 | Google | low 3.3 | Google Android: information disclosure | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28631 CVE-2026-28631 | Google | high 7.8 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28633 CVE-2026-28633 | Google | medium 5.5 | Google Android: denial of service | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28609 CVE-2026-28609 | Google | high 8.8 | Google Android: out-of-bounds write | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28611 CVE-2026-28611 | Google | high 7.8 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28612 CVE-2026-28612 | Google | high 7.8 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28613 CVE-2026-28613 | Google | high 7.3 | Google Android: improper input validation | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28614 CVE-2026-28614 | Google | high 7.8 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28616 CVE-2026-28616 | Google | high 7.8 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28617 CVE-2026-28617 | Google | medium 5.5 | Google Android: resource exhaustion | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28618 CVE-2026-28618 | Google | high 8.8 | Google Android: buffer overflow | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28593 CVE-2026-28593 | Google | high 7.8 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28594 CVE-2026-28594 | Google | high 7.8 | Google Android: use after free | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28596 CVE-2026-28596 | Google | medium 5.5 | Google Android: denial of service | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28599 CVE-2026-28599 | Google | high 7.8 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28600 CVE-2026-28600 | Google | high 7.8 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28602 CVE-2026-28602 | Google | high 7.8 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28603 CVE-2026-28603 | Google | high 7.8 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28604 CVE-2026-28604 | Google | high 7.5 | Google Android: use after free | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28606 CVE-2026-28606 | Google | critical 9.8 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28607 CVE-2026-28607 | Google | high 7.8 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28572 CVE-2026-28572 | Google | high 7.8 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28582 CVE-2026-28582 | Google | low 3.3 | Google Android: information disclosure | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28583 CVE-2026-28583 | Google | high 7.8 | Google Android: out-of-bounds write | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28584 CVE-2026-28584 | Google | medium 5.5 | Google Android: denial of service | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-28590 CVE-2026-28590 | Google | high 7.8 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-0084 CVE-2026-0084 | Google | high 7.8 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-0054 CVE-2026-0054 | Google | low 3.3 | Google Android: information disclosure | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | CVE-2026-0065 CVE-2026-0065 | Google | high 7.8 | Google Android: privilege escalation | https://source.android.com/docs/security/bulletin/2026/2026-09-01 2026-09-08 | GHSA-4gv7-q2x8-32p8 CVE-2026-81378 | Microsoft | high 8.2 | Agent Network Filter Security Feature Bypass | https://github.com/microsoft/vscode/security/advisories/GHSA-4gv7-q2x8-32p8 2026-09-08 | GHSA-4xcg-6mm5-hj26 CVE-2026-81357 | Microsoft | high 8.2 | Agent Network Filter Security Feature Bypass | https://github.com/microsoft/vscode/security/advisories/GHSA-4xcg-6mm5-hj26 2026-09-08 | GHSA-vww8-mqc2-4x8v CVE-2026-81380 | Microsoft | medium 5.3 | Information Disclosure through Automatic Remote Image Fetch in Chat | https://github.com/microsoft/vscode/security/advisories/GHSA-vww8-mqc2-4x8v 2026-09-08 | GHSA-g6p5-6xp8-5jwg CVE-2026-81377 | Microsoft | medium 6.5 | Visual Studio Code MCP gallery metadata path traversal | https://github.com/microsoft/vscode/security/advisories/GHSA-g6p5-6xp8-5jwg 2026-09-08 | GHSA-rvgr-2w56-2j67 CVE-2026-81381 | Microsoft | medium 6.5 | Azure DevOps access token disclosure through GitHub Copilot Chat workspace settings | https://github.com/microsoft/vscode/security/advisories/GHSA-rvgr-2w56-2j67 2026-09-08 | GHSA-x5qc-gqm7-93qp CVE-2026-81383 | Microsoft | high 7.4 | Visual Studio Code webview resource path containment bypass | https://github.com/microsoft/vscode/security/advisories/GHSA-x5qc-gqm7-93qp 2026-09-08 | GHSA-2cmq-rv52-5rf6 CVE-2026-78462 | Microsoft | high 8.8 | Remote code execution through workspace-configured remote agent host connections | https://github.com/microsoft/vscode/security/advisories/GHSA-2cmq-rv52-5rf6 2026-09-08 | GHSA-r2gr-w3c8-wvqv CVE-2026-81376 | Microsoft | critical 9.6 | Visual Studio Code Workspace Trust bypass through attacker-controlled services | https://github.com/microsoft/vscode/security/advisories/GHSA-r2gr-w3c8-wvqv 2026-09-08 | GHSA-q2f8-hh8x-wpc2 CVE-2026-70334 | Microsoft | high 7.8 | Visual Studio Code Restricted Mode bypass via nested configuration objects | https://github.com/microsoft/vscode/security/advisories/GHSA-q2f8-hh8x-wpc2 2026-09-08 | GHSA-hr37-8jwr-q8p8 CVE-2026-81379 | Microsoft | high 8.2 | Agent Network Filter Bypass Vulnerability | https://github.com/microsoft/vscode/security/advisories/GHSA-hr37-8jwr-q8p8 2026-09-08 | CVE-2026-85880 CVE-2026-85880 | Microsoft | high 7.8 | Microsoft Windows ALPC: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85880 2026-09-08 | CVE-2026-85875 CVE-2026-85875 | Microsoft | medium 5.5 | Microsoft Office Excel: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85875 2026-09-08 | CVE-2026-85877 CVE-2026-85877 | Microsoft | high 8.8 | Microsoft Windows 11 Version 24H2: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85877 2026-09-08 | CVE-2026-85360 CVE-2026-85360 | Microsoft | high 7.0 | Microsoft Windows Kernel: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85360 2026-09-08 | CVE-2026-84001 CVE-2026-84001 | Microsoft | high 7.5 | Microsoft Windows Key Distribution Center: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-84001 2026-09-08 | CVE-2026-84003 CVE-2026-84003 | Microsoft | high 7.4 | Microsoft Authentication Library: authentication bypass | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-84003 2026-09-08 | CVE-2026-83995 CVE-2026-83995 | Microsoft | high 7.8 | Microsoft Windows NTFS: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83995 2026-09-08 | CVE-2026-83996 CVE-2026-83996 | Microsoft | high 8.8 | Microsoft Windows Error Reporting: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83996 2026-09-08 | CVE-2026-83997 CVE-2026-83997 | Microsoft | high 8.1 | Microsoft Windows Message Queuing: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83997 2026-09-08 | CVE-2026-83998 CVE-2026-83998 | Microsoft | high 8.8 | Microsoft Remote Desktop Client: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83998 2026-09-08 | CVE-2026-83999 CVE-2026-83999 | Microsoft | high 7.0 | Microsoft Windows: privilege escalation | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83999 2026-09-08 | CVE-2026-84000 CVE-2026-84000 | Microsoft | high 7.8 | Microsoft Graphics Component: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-84000 2026-09-08 | CVE-2026-83986 CVE-2026-83986 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83986 2026-09-08 | CVE-2026-83987 CVE-2026-83987 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83987 2026-09-08 | CVE-2026-83988 CVE-2026-83988 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83988 2026-09-08 | CVE-2026-83989 CVE-2026-83989 | Microsoft | high 7.5 | Microsoft Windows Services for NFS ONCRPC XDR Driver: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83989 2026-09-08 | CVE-2026-83990 CVE-2026-83990 | Microsoft | high 7.8 | Microsoft Graphics Component: stack buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83990 2026-09-08 | CVE-2026-83991 CVE-2026-83991 | Microsoft | medium 5.5 | Microsoft Windows Cloud Files Mini Filter Driver: missing authentication | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83991 2026-09-08 | CVE-2026-83992 CVE-2026-83992 | Microsoft | high 8.8 | Microsoft Windows Imaging Component: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83992 2026-09-08 | CVE-2026-83979 CVE-2026-83979 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83979 2026-09-08 | CVE-2026-83980 CVE-2026-83980 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83980 2026-09-08 | CVE-2026-83981 CVE-2026-83981 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83981 2026-09-08 | CVE-2026-83982 CVE-2026-83982 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83982 2026-09-08 | CVE-2026-83983 CVE-2026-83983 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83983 2026-09-08 | CVE-2026-83985 CVE-2026-83985 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83985 2026-09-08 | CVE-2026-83974 CVE-2026-83974 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83974 2026-09-08 | CVE-2026-83975 CVE-2026-83975 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83975 2026-09-08 | CVE-2026-83976 CVE-2026-83976 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83976 2026-09-08 | CVE-2026-83977 CVE-2026-83977 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83977 2026-09-08 | CVE-2026-83978 CVE-2026-83978 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83978 2026-09-08 | CVE-2026-83968 CVE-2026-83968 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83968 2026-09-08 | CVE-2026-83969 CVE-2026-83969 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83969 2026-09-08 | CVE-2026-83970 CVE-2026-83970 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83970 2026-09-08 | CVE-2026-83971 CVE-2026-83971 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83971 2026-09-08 | CVE-2026-83972 CVE-2026-83972 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83972 2026-09-08 | CVE-2026-83973 CVE-2026-83973 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83973 2026-09-08 | CVE-2026-83948 CVE-2026-83948 | Microsoft | high 8.0 | Microsoft Azure CLI: command injection | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83948 2026-09-08 | CVE-2026-83949 CVE-2026-83949 | Microsoft | medium 5.5 | Microsoft Office Word: unauthorized attacker could disclose information locally | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83949 2026-09-08 | CVE-2026-83951 CVE-2026-83951 | Microsoft | medium 5.5 | Microsoft Office Word: unauthorized attacker could disclose information locally | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83951 2026-09-08 | CVE-2026-83952 CVE-2026-83952 | Microsoft | high 7.8 | Microsoft Windows: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83952 2026-09-08 | CVE-2026-83954 CVE-2026-83954 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83954 2026-09-08 | CVE-2026-83955 CVE-2026-83955 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83955 2026-09-08 | CVE-2026-83967 CVE-2026-83967 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83967 2026-09-08 | CVE-2026-83498 CVE-2026-83498 | Microsoft | high 7.8 | Microsoft Windows: privilege escalation | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83498 2026-09-08 | CVE-2026-83501 CVE-2026-83501 | Microsoft | medium 5.5 | Microsoft Windows: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83501 2026-09-08 | CVE-2026-83939 CVE-2026-83939 | Microsoft | high 8.2 | Microsoft Windows 11 version 26H1: privilege escalation | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83939 2026-09-08 | CVE-2026-83940 CVE-2026-83940 | Microsoft | high 7.0 | Microsoft Windows Device Association Service: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83940 2026-09-08 | CVE-2026-83941 CVE-2026-83941 | Microsoft | critical 9.9 | Microsoft Entra: missing authorization | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83941 2026-09-08 | CVE-2026-83942 CVE-2026-83942 | Microsoft | high 7.8 | Microsoft Windows Kernel: missing authorization | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83942 2026-09-08 | CVE-2026-81963 CVE-2026-81963 | Microsoft | high 7.8 | Microsoft Windows Update Stack: privilege escalation | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81963 2026-09-08 | CVE-2026-81955 CVE-2026-81955 | Microsoft | high 8.8 | Microsoft Graphics Component: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81955 2026-09-08 | CVE-2026-81956 CVE-2026-81956 | Microsoft | high 7.8 | Microsoft Office Excel: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81956 2026-09-08 | CVE-2026-81957 CVE-2026-81957 | Microsoft | high 7.8 | Microsoft Office Excel: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81957 2026-09-08 | CVE-2026-81958 CVE-2026-81958 | Microsoft | medium 5.5 | Microsoft Office Excel: uninitialized resource | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81958 2026-09-08 | CVE-2026-81959 CVE-2026-81959 | Microsoft | high 7.8 | Microsoft Office Excel: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81959 2026-09-08 | CVE-2026-81960 CVE-2026-81960 | Microsoft | high 7.8 | Microsoft Office Excel: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81960 2026-09-08 | CVE-2026-81947 CVE-2026-81947 | Microsoft | high 7.8 | Microsoft Office Excel: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81947 2026-09-08 | CVE-2026-81948 CVE-2026-81948 | Microsoft | high 7.8 | Microsoft Office Excel: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81948 2026-09-08 | CVE-2026-81949 CVE-2026-81949 | Microsoft | high 7.8 | Microsoft Office Excel: integer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81949 2026-09-08 | CVE-2026-81950 CVE-2026-81950 | Microsoft | high 7.8 | Microsoft Office Excel: double free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81950 2026-09-08 | CVE-2026-81951 CVE-2026-81951 | Microsoft | high 7.8 | Microsoft Office Excel: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81951 2026-09-08 | CVE-2026-81952 CVE-2026-81952 | Microsoft | high 8.8 | Microsoft Office Word: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81952 2026-09-08 | CVE-2026-81953 CVE-2026-81953 | Microsoft | high 7.8 | Microsoft Office Excel: stack buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81953 2026-09-08 | CVE-2026-81954 CVE-2026-81954 | Microsoft | high 7.8 | Microsoft Office Excel: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81954 2026-09-08 | CVE-2026-81395 CVE-2026-81395 | Microsoft | medium 5.5 | Microsoft Office Excel: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81395 2026-09-08 | CVE-2026-81396 CVE-2026-81396 | Microsoft | high 7.8 | Microsoft Office Excel: stack buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81396 2026-09-08 | CVE-2026-81397 CVE-2026-81397 | Microsoft | high 7.8 | Microsoft Office Excel: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81397 2026-09-08 | CVE-2026-81398 CVE-2026-81398 | Microsoft | high 7.8 | Microsoft Office Excel: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81398 2026-09-08 | CVE-2026-81399 CVE-2026-81399 | Microsoft | medium 5.5 | Microsoft Office Excel: unauthorized attacker could disclose information locally | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81399 2026-09-08 | CVE-2026-81400 CVE-2026-81400 | Microsoft | medium 5.5 | Microsoft Office Excel: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81400 2026-09-08 | CVE-2026-81401 CVE-2026-81401 | Microsoft | medium 5.5 | Microsoft Office Excel: type confusion | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81401 2026-09-08 | CVE-2026-81388 CVE-2026-81388 | Microsoft | high 7.8 | Microsoft Office Excel: stack buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81388 2026-09-08 | CVE-2026-81389 CVE-2026-81389 | Microsoft | high 7.0 | Microsoft Office Excel: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81389 2026-09-08 | CVE-2026-81390 CVE-2026-81390 | Microsoft | medium 5.5 | Microsoft Office Excel: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81390 2026-09-08 | CVE-2026-81391 CVE-2026-81391 | Microsoft | medium 5.5 | Microsoft Office Excel: uninitialized resource | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81391 2026-09-08 | CVE-2026-81392 CVE-2026-81392 | Microsoft | medium 5.5 | Microsoft Office Excel: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81392 2026-09-08 | CVE-2026-81393 CVE-2026-81393 | Microsoft | medium 5.5 | Microsoft Office Excel: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81393 2026-09-08 | CVE-2026-81394 CVE-2026-81394 | Microsoft | medium 5.5 | Microsoft Office Excel: system information exposure | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81394 2026-09-08 | CVE-2026-81385 CVE-2026-81385 | Microsoft | high 8.8 | Microsoft Office Publisher: unsafe deserialization | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81385 2026-09-08 | CVE-2026-81386 CVE-2026-81386 | Microsoft | high 7.8 | Microsoft Office Excel: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81386 2026-09-08 | CVE-2026-81387 CVE-2026-81387 | Microsoft | medium 5.5 | Microsoft Office Excel: system information exposure | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81387 2026-09-08 | CVE-2026-81353 CVE-2026-81353 | Microsoft | high 7.8 | Microsoft HEIF Image Extension: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81353 2026-09-08 | CVE-2026-81354 CVE-2026-81354 | Microsoft | high 8.2 | Microsoft Windows Hello: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81354 2026-09-08 | CVE-2026-81355 CVE-2026-81355 | Microsoft | high 7.5 | Microsoft Windows: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81355 2026-09-08 | CVE-2026-80097 CVE-2026-80097 | Microsoft | high 8.6 | Microsoft Authenticator for Android: improper authentication | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-80097 2026-09-08 | CVE-2026-81349 CVE-2026-81349 | Microsoft | high 7.2 | Microsoft Azure HDInsight: command injection | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81349 2026-09-08 | CVE-2026-81352 CVE-2026-81352 | Microsoft | high 8.8 | Microsoft Web Media Extensions: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81352 2026-09-08 | CVE-2026-80086 CVE-2026-80086 | Microsoft | medium 6.5 | Microsoft Office PowerPoint: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-80086 2026-09-08 | CVE-2026-80087 CVE-2026-80087 | Microsoft | medium 6.5 | Microsoft Office: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-80087 2026-09-08 | CVE-2026-80088 CVE-2026-80088 | Microsoft | medium 6.5 | Microsoft Office Word: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-80088 2026-09-08 | CVE-2026-80089 CVE-2026-80089 | Microsoft | medium 6.5 | Microsoft Office: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-80089 2026-09-08 | CVE-2026-80090 CVE-2026-80090 | Microsoft | medium 6.5 | Microsoft Office Word: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-80090 2026-09-08 | CVE-2026-80091 CVE-2026-80091 | Microsoft | medium 6.5 | Microsoft Office: uninitialized resource | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-80091 2026-09-08 | CVE-2026-80093 CVE-2026-80093 | Microsoft | high 7.0 | Microsoft Windows Cloud Files Mini Filter Driver: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-80093 2026-09-08 | CVE-2026-80096 CVE-2026-80096 | Microsoft | high 8.8 | Microsoft Windows Remote Desktop Services: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-80096 2026-09-08 | CVE-2026-80079 CVE-2026-80079 | Microsoft | medium 6.5 | Microsoft Office Word: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-80079 2026-09-08 | CVE-2026-80080 CVE-2026-80080 | Microsoft | high 8.8 | Microsoft Office Word: double free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-80080 2026-09-08 | CVE-2026-80081 CVE-2026-80081 | Microsoft | high 8.8 | Microsoft 365 Apps for Enterprise: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-80081 2026-09-08 | CVE-2026-80082 CVE-2026-80082 | Microsoft | medium 6.5 | Microsoft Office: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-80082 2026-09-08 | CVE-2026-80083 CVE-2026-80083 | Microsoft | high 8.8 | Microsoft Windows Hyper-V: code execution | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-80083 2026-09-08 | CVE-2026-80084 CVE-2026-80084 | Microsoft | medium 6.5 | Microsoft Office Outlook: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-80084 2026-09-08 | CVE-2026-80085 CVE-2026-80085 | Microsoft | high 8.8 | Microsoft Office Word: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-80085 2026-09-08 | CVE-2026-79904 CVE-2026-79904 | Adobe | medium 5.0 | Adobe Photoshop Android: path traversal | https://helpx.adobe.com/security/products/photoshop/apsb26-136.html 2026-09-08 | CVE-2026-80073 CVE-2026-80073 | Microsoft | medium 6.5 | Microsoft Office Outlook: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-80073 2026-09-08 | CVE-2026-80074 CVE-2026-80074 | Microsoft | high 8.8 | Microsoft Remote Desktop client for Windows Desktop: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-80074 2026-09-08 | CVE-2026-80075 CVE-2026-80075 | Microsoft | high 7.8 | Microsoft Windows Work Folders: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-80075 2026-09-08 | CVE-2026-80076 CVE-2026-80076 | Microsoft | medium 6.5 | Microsoft Office: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-80076 2026-09-08 | CVE-2026-80077 CVE-2026-80077 | Microsoft | high 8.8 | Microsoft Remote Desktop client for Windows Desktop: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-80077 2026-09-08 | CVE-2026-80078 CVE-2026-80078 | Microsoft | medium 6.5 | Microsoft Office: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-80078 2026-09-08 | CVE-2026-78524 CVE-2026-78524 | Microsoft | high 8.8 | Microsoft Office: out-of-bounds write | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78524 2026-09-08 | CVE-2026-78525 CVE-2026-78525 | Microsoft | high 8.8 | Microsoft Office Outlook: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78525 2026-09-08 | CVE-2026-78526 CVE-2026-78526 | Microsoft | high 8.8 | Microsoft Office Word: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78526 2026-09-08 | CVE-2026-78517 CVE-2026-78517 | Microsoft | high 8.8 | Microsoft Office Word: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78517 2026-09-08 | CVE-2026-78518 CVE-2026-78518 | Microsoft | high 8.8 | Microsoft Office Excel: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78518 2026-09-08 | CVE-2026-78519 CVE-2026-78519 | Microsoft | high 8.8 | Microsoft Office Outlook: remote code execution | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78519 2026-09-08 | CVE-2026-78520 CVE-2026-78520 | Microsoft | medium 6.5 | Microsoft Office Outlook: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78520 2026-09-08 | CVE-2026-78521 CVE-2026-78521 | Microsoft | high 8.8 | Microsoft Office Word: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78521 2026-09-08 | CVE-2026-78522 CVE-2026-78522 | Microsoft | medium 6.5 | Microsoft Office Word: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78522 2026-09-08 | CVE-2026-78523 CVE-2026-78523 | Microsoft | medium 5.9 | Microsoft Windows DNS: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78523 2026-09-08 | CVE-2026-78509 CVE-2026-78509 | Microsoft | critical 9.8 | Microsoft Office Outlook: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78509 2026-09-08 | CVE-2026-78510 CVE-2026-78510 | Microsoft | high 8.4 | Microsoft Office: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78510 2026-09-08 | CVE-2026-78511 CVE-2026-78511 | Microsoft | high 8.8 | Microsoft Office Word: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78511 2026-09-08 | CVE-2026-78512 CVE-2026-78512 | Microsoft | high 8.8 | Microsoft Office Word: remote code execution | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78512 2026-09-08 | CVE-2026-78513 CVE-2026-78513 | Microsoft | medium 5.5 | Microsoft Office PowerPoint: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78513 2026-09-08 | CVE-2026-78514 CVE-2026-78514 | Microsoft | high 8.8 | Microsoft Office Word: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78514 2026-09-08 | CVE-2026-78515 CVE-2026-78515 | Microsoft | medium 6.5 | Microsoft Office Excel: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78515 2026-09-08 | CVE-2026-78516 CVE-2026-78516 | Microsoft | medium 4.3 | Microsoft Windows Storage: information disclosure | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78516 2026-09-08 | CVE-2026-78502 CVE-2026-78502 | Microsoft | medium 6.5 | Microsoft Office Word: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78502 2026-09-08 | CVE-2026-78503 CVE-2026-78503 | Microsoft | medium 6.5 | Microsoft Office Word: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78503 2026-09-08 | CVE-2026-78504 CVE-2026-78504 | Microsoft | high 8.8 | Microsoft Office Word: stack buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78504 2026-09-08 | CVE-2026-78505 CVE-2026-78505 | Microsoft | high 8.8 | Microsoft Office: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78505 2026-09-08 | CVE-2026-78506 CVE-2026-78506 | Microsoft | medium 5.5 | Microsoft Office Word: unauthorized attacker could disclose information locally | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78506 2026-09-08 | CVE-2026-78507 CVE-2026-78507 | Microsoft | high 8.8 | Microsoft Office Word: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78507 2026-09-08 | CVE-2026-78508 CVE-2026-78508 | Microsoft | medium 4.6 | Microsoft Windows CD-ROM Driver: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78508 2026-09-08 | CVE-2026-78455 CVE-2026-78455 | Microsoft | medium 4.3 | Microsoft Xbox: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78455 2026-09-08 | CVE-2026-78456 CVE-2026-78456 | Microsoft | high 8.8 | Microsoft SQL Server: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78456 2026-09-08 | CVE-2026-78457 CVE-2026-78457 | Microsoft | high 7.0 | Microsoft Windows Security Health Service: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78457 2026-09-08 | CVE-2026-78461 CVE-2026-78461 | Microsoft | high 7.4 | Microsoft Visual Studio Code: path traversal | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78461 2026-09-08 | CVE-2026-78463 CVE-2026-78463 | Microsoft | high 8.8 | Microsoft Remote Desktop client for Windows Desktop: code injection | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78463 2026-09-08 | CVE-2026-78464 CVE-2026-78464 | Microsoft | high 7.0 | Microsoft Windows MIDI Service Module: race condition | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78464 2026-09-08 | CVE-2026-78450 CVE-2026-78450 | Microsoft | high 8.1 | Microsoft Windows: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78450 2026-09-08 | CVE-2026-78451 CVE-2026-78451 | Microsoft | medium 6.8 | Microsoft Windows SCSI Class System File: privilege escalation | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78451 2026-09-08 | CVE-2026-78452 CVE-2026-78452 | Microsoft | medium 4.6 | Microsoft Windows SCSI Class System File: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78452 2026-09-08 | CVE-2026-78453 CVE-2026-78453 | Microsoft | medium 6.5 | Microsoft Windows SCSI Class System File: integer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78453 2026-09-08 | CVE-2026-78454 CVE-2026-78454 | Microsoft | medium 5.5 | Microsoft Windows CD-ROM Driver: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78454 2026-09-08 | CVE-2026-78442 CVE-2026-78442 | Microsoft | high 8.8 | Microsoft Windows OLE DB: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78442 2026-09-08 | CVE-2026-78444 CVE-2026-78444 | Microsoft | high 8.1 | Microsoft Windows Failover Cluster: remote code execution | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78444 2026-09-08 | CVE-2026-78445 CVE-2026-78445 | Microsoft | critical 9.8 | Microsoft Windows Services for NFS ONCRPC XDR Driver: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78445 2026-09-08 | CVE-2026-78446 CVE-2026-78446 | Microsoft | medium 5.3 | Microsoft Windows: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78446 2026-09-08 | CVE-2026-78447 CVE-2026-78447 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78447 2026-09-08 | CVE-2026-78448 CVE-2026-78448 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78448 2026-09-08 | CVE-2026-78449 CVE-2026-78449 | Microsoft | high 8.1 | Microsoft Windows: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78449 2026-09-08 | CVE-2026-77908 CVE-2026-77908 | Microsoft | high 8.8 | Microsoft Dynamics 365 Customer Engagement V9.1: code injection | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77908 2026-09-08 | CVE-2026-77909 CVE-2026-77909 | Microsoft | high 7.7 | Microsoft Azure CycleCloud 8.9.2: weakly protected credentials | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77909 2026-09-08 | CVE-2026-77911 CVE-2026-77911 | Microsoft | medium 6.5 | Microsoft Office Word: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77911 2026-09-08 | CVE-2026-78439 CVE-2026-78439 | Microsoft | high 8.8 | Microsoft Graphics Component: stack buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78439 2026-09-08 | CVE-2026-78441 CVE-2026-78441 | Microsoft | medium 6.5 | Microsoft Windows OLE DB: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78441 2026-09-08 | CVE-2026-77899 CVE-2026-77899 | Microsoft | high 7.0 | Microsoft Windows Security Center: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77899 2026-09-08 | CVE-2026-77901 CVE-2026-77901 | Microsoft | high 8.8 | Microsoft Office Word: null pointer dereference | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77901 2026-09-08 | CVE-2026-77904 CVE-2026-77904 | Microsoft | high 7.8 | Microsoft Windows Volume Manager Extension Driver: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77904 2026-09-08 | CVE-2026-77905 CVE-2026-77905 | Microsoft | high 7.0 | Microsoft Windows Management Instrumentation: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77905 2026-09-08 | CVE-2026-77906 CVE-2026-77906 | Microsoft | high 8.8 | Microsoft Visual Studio 2026 version 18.9: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77906 2026-09-08 | CVE-2026-77907 CVE-2026-77907 | Microsoft | high 8.8 | Microsoft Visual Studio 2026 version 18.9: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77907 2026-09-08 | CVE-2026-77892 CVE-2026-77892 | Microsoft | medium 6.8 | Microsoft Windows Boot Manager: privilege escalation | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77892 2026-09-08 | CVE-2026-77893 CVE-2026-77893 | Microsoft | high 7.5 | Microsoft Windows DHCP Server: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77893 2026-09-08 | CVE-2026-77894 CVE-2026-77894 | Microsoft | high 7.0 | Microsoft Windows Installer: race condition | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77894 2026-09-08 | CVE-2026-77895 CVE-2026-77895 | Microsoft | high 7.5 | Microsoft Windows DHCP Server: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77895 2026-09-08 | CVE-2026-77896 CVE-2026-77896 | Microsoft | medium 6.5 | Microsoft Remote Desktop Client: integer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77896 2026-09-08 | CVE-2026-77897 CVE-2026-77897 | Microsoft | high 7.0 | Microsoft Power Automate: path traversal | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77897 2026-09-08 | CVE-2026-77898 CVE-2026-77898 | Microsoft | high 7.5 | Microsoft Office: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77898 2026-09-08 | CVE-2026-77886 CVE-2026-77886 | Microsoft | high 7.5 | Microsoft Windows DHCP Server: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77886 2026-09-08 | CVE-2026-77887 CVE-2026-77887 | Microsoft | medium 6.4 | Microsoft Windows DHCP Server: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77887 2026-09-08 | CVE-2026-77888 CVE-2026-77888 | Microsoft | high 7.5 | Microsoft Windows DHCP Server: type confusion | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77888 2026-09-08 | CVE-2026-77889 CVE-2026-77889 | Microsoft | high 7.5 | Microsoft Windows DHCP Server: type confusion | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77889 2026-09-08 | CVE-2026-77890 CVE-2026-77890 | Microsoft | high 7.5 | Microsoft Windows DHCP Server: type confusion | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77890 2026-09-08 | CVE-2026-77891 CVE-2026-77891 | Microsoft | medium 6.4 | Microsoft Windows DHCP Server: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77891 2026-09-08 | CVE-2026-77501 CVE-2026-77501 | Microsoft | high 7.5 | Microsoft Windows DHCP Server: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77501 2026-09-08 | CVE-2026-77502 CVE-2026-77502 | Microsoft | high 7.5 | Microsoft Windows DHCP Server: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77502 2026-09-08 | CVE-2026-77503 CVE-2026-77503 | Microsoft | high 8.4 | Microsoft Windows NTFS: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77503 2026-09-08 | CVE-2026-77504 CVE-2026-77504 | Microsoft | high 8.8 | Microsoft Office Word: double free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77504 2026-09-08 | CVE-2026-77505 CVE-2026-77505 | Microsoft | high 8.1 | Microsoft DNS Server: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77505 2026-09-08 | CVE-2026-77498 CVE-2026-77498 | Microsoft | high 7.5 | Microsoft Windows DHCP Server: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77498 2026-09-08 | CVE-2026-77499 CVE-2026-77499 | Microsoft | high 7.5 | Microsoft Windows DHCP Server: type confusion | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77499 2026-09-08 | CVE-2026-77500 CVE-2026-77500 | Microsoft | high 7.8 | Microsoft Windows Device Association Service: privilege escalation | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77500 2026-09-08 | CVE-2026-77492 CVE-2026-77492 | Microsoft | medium 5.5 | Microsoft Storage Port Driver: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77492 2026-09-08 | CVE-2026-77493 CVE-2026-77493 | Microsoft | critical 9.8 | Microsoft Graphics Component: double free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77493 2026-09-08 | CVE-2026-77494 CVE-2026-77494 | Microsoft | high 7.5 | Microsoft Windows DHCP Server: type confusion | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77494 2026-09-08 | CVE-2026-77495 CVE-2026-77495 | Microsoft | high 8.8 | Microsoft Windows Imaging Component: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77495 2026-09-08 | CVE-2026-77484 CVE-2026-77484 | Microsoft | high 8.8 | Microsoft SQL Server: unsafe deserialization | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77484 2026-09-08 | CVE-2026-77485 CVE-2026-77485 | Microsoft | high 7.0 | Microsoft SQL Server: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77485 2026-09-08 | CVE-2026-77486 CVE-2026-77486 | Microsoft | high 8.8 | Microsoft SQL Server: integer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77486 2026-09-08 | CVE-2026-77487 CVE-2026-77487 | Microsoft | high 8.8 | Microsoft SQL Server: improper access control | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77487 2026-09-08 | CVE-2026-77488 CVE-2026-77488 | Microsoft | medium 5.5 | Microsoft SQL Server: integer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77488 2026-09-08 | CVE-2026-77489 CVE-2026-77489 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: null pointer dereference | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77489 2026-09-08 | CVE-2026-77491 CVE-2026-77491 | Microsoft | medium 5.5 | Microsoft Windows GDI: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77491 2026-09-08 | CVE-2026-76191 CVE-2026-76191 | Adobe | high 8.2 | Adobe Animate: code injection | https://helpx.adobe.com/security/products/animate/apsb26-132.html 2026-09-08 | CVE-2026-76196 CVE-2026-76196 | Adobe | high 7.4 | Adobe Photoshop Android: session fixation | https://helpx.adobe.com/security/products/photoshop/apsb26-136.html 2026-09-08 | CVE-2026-77480 CVE-2026-77480 | Microsoft | high 8.8 | Microsoft SQL Server: improper access control | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77480 2026-09-08 | CVE-2026-77481 CVE-2026-77481 | Microsoft | high 8.8 | Microsoft SQL Server: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77481 2026-09-08 | CVE-2026-77482 CVE-2026-77482 | Microsoft | high 8.8 | Microsoft SQL Server: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77482 2026-09-08 | CVE-2026-77483 CVE-2026-77483 | Microsoft | high 8.8 | Microsoft SQL Server: privilege escalation | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77483 2026-09-08 | CVE-2026-73023 CVE-2026-73023 | Microsoft | high 8.8 | Microsoft Windows Imaging Component: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-73023 2026-09-08 | CVE-2026-73024 CVE-2026-73024 | Microsoft | high 7.8 | Microsoft Windows Services for NFS ONCRPC XDR Driver: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-73024 2026-09-08 | CVE-2026-73025 CVE-2026-73025 | Microsoft | critical 9.8 | Microsoft Windows: unauthorized attacker could bypass a security feature over | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-73025 2026-09-08 | CVE-2026-73026 CVE-2026-73026 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-73026 2026-09-08 | CVE-2026-73028 CVE-2026-73028 | Microsoft | high 8.8 | Microsoft SQL Server: improper access control | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-73028 2026-09-08 | CVE-2026-73029 CVE-2026-73029 | Microsoft | medium 6.5 | Buffer over-read in SQL Server | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-73029 2026-09-08 | CVE-2026-73017 CVE-2026-73017 | Microsoft | high 7.5 | Microsoft Windows Graphics Kernel: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-73017 2026-09-08 | CVE-2026-73018 CVE-2026-73018 | Microsoft | high 8.8 | Microsoft Graphic Fonts: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-73018 2026-09-08 | CVE-2026-73019 CVE-2026-73019 | Microsoft | medium 4.3 | Microsoft Windows URL Moniker: unauthorized attacker could bypass a security... | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-73019 2026-09-08 | CVE-2026-73020 CVE-2026-73020 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-73020 2026-09-08 | CVE-2026-73021 CVE-2026-73021 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-73021 2026-09-08 | CVE-2026-73022 CVE-2026-73022 | Microsoft | high 7.0 | Microsoft Windows: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-73022 2026-09-08 | CVE-2026-73011 CVE-2026-73011 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-73011 2026-09-08 | CVE-2026-73012 CVE-2026-73012 | Microsoft | high 8.8 | Microsoft Windows Management Services: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-73012 2026-09-08 | CVE-2026-73013 CVE-2026-73013 | Microsoft | high 8.8 | Microsoft Windows Imaging Component: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-73013 2026-09-08 | CVE-2026-73014 CVE-2026-73014 | Microsoft | high 7.8 | Microsoft Data Sharing Service Client: missing authorization | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-73014 2026-09-08 | CVE-2026-73015 CVE-2026-73015 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-73015 2026-09-08 | CVE-2026-73016 CVE-2026-73016 | Microsoft | high 8.8 | Microsoft Graphics Component: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-73016 2026-09-08 | CVE-2026-73004 CVE-2026-73004 | Microsoft | medium 5.5 | Microsoft Windows Autopilot: missing authentication | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-73004 2026-09-08 | CVE-2026-73005 CVE-2026-73005 | Microsoft | high 7.0 | Microsoft Windows Authentication Methods: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-73005 2026-09-08 | CVE-2026-73006 CVE-2026-73006 | Microsoft | high 8.8 | Microsoft Graphics Component: stack buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-73006 2026-09-08 | CVE-2026-73007 CVE-2026-73007 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-73007 2026-09-08 | CVE-2026-73008 CVE-2026-73008 | Microsoft | medium 5.5 | Exposure of private personal information to an unauthorized actor in Windows... | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-73008 2026-09-08 | CVE-2026-73009 CVE-2026-73009 | Microsoft | critical 9.8 | Microsoft Windows: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-73009 2026-09-08 | CVE-2026-73010 CVE-2026-73010 | Microsoft | critical 9.8 | Microsoft Windows Failover Cluster: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-73010 2026-09-08 | CVE-2026-72997 CVE-2026-72997 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72997 2026-09-08 | CVE-2026-72999 CVE-2026-72999 | Microsoft | medium 6.8 | Microsoft Windows USB Hub Driver: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72999 2026-09-08 | CVE-2026-73000 CVE-2026-73000 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-73000 2026-09-08 | CVE-2026-73001 CVE-2026-73001 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-73001 2026-09-08 | CVE-2026-73002 CVE-2026-73002 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: integer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-73002 2026-09-08 | CVE-2026-73003 CVE-2026-73003 | Microsoft | high 7.0 | Microsoft Windows: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-73003 2026-09-08 | CVE-2026-72992 CVE-2026-72992 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72992 2026-09-08 | CVE-2026-72993 CVE-2026-72993 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72993 2026-09-08 | CVE-2026-72994 CVE-2026-72994 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72994 2026-09-08 | CVE-2026-72995 CVE-2026-72995 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72995 2026-09-08 | CVE-2026-72996 CVE-2026-72996 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72996 2026-09-08 | CVE-2026-72989 CVE-2026-72989 | Microsoft | high 7.5 | Microsoft Windows Failover Cluster: uninitialized resource | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72989 2026-09-08 | CVE-2026-72990 CVE-2026-72990 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72990 2026-09-08 | CVE-2026-72991 CVE-2026-72991 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72991 2026-09-08 | CVE-2026-72983 CVE-2026-72983 | Microsoft | critical 9.8 | Microsoft Windows: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72983 2026-09-08 | CVE-2026-72985 CVE-2026-72985 | Microsoft | medium 6.8 | Microsoft Windows Volume Shadow Copy: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72985 2026-09-08 | CVE-2026-72986 CVE-2026-72986 | Microsoft | high 8.8 | Microsoft Graphic Fonts: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72986 2026-09-08 | CVE-2026-72987 CVE-2026-72987 | Microsoft | high 8.1 | Microsoft Windows DNS: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72987 2026-09-08 | CVE-2026-72988 CVE-2026-72988 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72988 2026-09-08 | CVE-2026-72977 CVE-2026-72977 | Microsoft | medium 6.5 | Microsoft Office PowerPoint: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72977 2026-09-08 | CVE-2026-72978 CVE-2026-72978 | Microsoft | medium 5.9 | Microsoft Windows: resource exhaustion | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72978 2026-09-08 | CVE-2026-72979 CVE-2026-72979 | Microsoft | critical 9.8 | Microsoft Windows DHCP Server: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72979 2026-09-08 | CVE-2026-72980 CVE-2026-72980 | Microsoft | medium 4.4 | Microsoft Windows Hello: uncontrolled search path | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72980 2026-09-08 | CVE-2026-72981 CVE-2026-72981 | Microsoft | high 8.1 | Microsoft IP Helper: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72981 2026-09-08 | CVE-2026-72982 CVE-2026-72982 | Microsoft | critical 9.8 | Microsoft Windows Netlogon: stack buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72982 2026-09-08 | CVE-2026-72972 CVE-2026-72972 | Microsoft | high 8.8 | Microsoft Office Word: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72972 2026-09-08 | CVE-2026-72973 CVE-2026-72973 | Microsoft | high 8.8 | Microsoft Office Word: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72973 2026-09-08 | CVE-2026-72974 CVE-2026-72974 | Microsoft | medium 6.5 | Microsoft Office Excel: unauthorized attacker could disclose information over | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72974 2026-09-08 | CVE-2026-72975 CVE-2026-72975 | Microsoft | medium 6.5 | Microsoft Office PowerPoint: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72975 2026-09-08 | CVE-2026-72976 CVE-2026-72976 | Microsoft | medium 5.0 | Microsoft Office Word: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72976 2026-09-08 | CVE-2026-72962 CVE-2026-72962 | Microsoft | high 8.2 | Microsoft Windows USB Video Driver: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72962 2026-09-08 | CVE-2026-72963 CVE-2026-72963 | Microsoft | high 7.0 | Microsoft Windows Modern Execution Server: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72963 2026-09-08 | CVE-2026-72964 CVE-2026-72964 | Microsoft | medium 5.5 | Microsoft Windows: missing authentication | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72964 2026-09-08 | CVE-2026-72965 CVE-2026-72965 | Microsoft | high 7.8 | Microsoft Windows WebClient Service: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72965 2026-09-08 | CVE-2026-72966 CVE-2026-72966 | Microsoft | medium 5.5 | Microsoft Windows Remote Access Connection Manager: missing authorization | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72966 2026-09-08 | CVE-2026-72967 CVE-2026-72967 | Microsoft | high 7.8 | Microsoft Windows Network Connection Broker: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72967 2026-09-08 | CVE-2026-72956 CVE-2026-72956 | Microsoft | medium 6.5 | Microsoft Office PowerPoint: untrusted pointer dereference | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72956 2026-09-08 | CVE-2026-72957 CVE-2026-72957 | Microsoft | high 7.8 | Microsoft Windows Deployment Services: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72957 2026-09-08 | CVE-2026-72958 CVE-2026-72958 | Microsoft | high 8.2 | Microsoft Windows Credential Guard: double free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72958 2026-09-08 | CVE-2026-72959 CVE-2026-72959 | Microsoft | high 8.8 | Microsoft Windows: remote code execution | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72959 2026-09-08 | CVE-2026-72960 CVE-2026-72960 | Microsoft | high 8.8 | Microsoft Windows Media Player: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72960 2026-09-08 | CVE-2026-72961 CVE-2026-72961 | Microsoft | high 8.2 | Microsoft Windows Hyper-V: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72961 2026-09-08 | CVE-2026-72947 CVE-2026-72947 | Microsoft | medium 6.4 | Microsoft Windows File History Service: integer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72947 2026-09-08 | CVE-2026-72948 CVE-2026-72948 | Microsoft | medium 6.7 | Microsoft Windows DNS: path traversal | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72948 2026-09-08 | CVE-2026-72949 CVE-2026-72949 | Microsoft | high 7.5 | Microsoft Windows: null pointer dereference | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72949 2026-09-08 | CVE-2026-72950 CVE-2026-72950 | Microsoft | high 8.8 | Microsoft Windows: remote code execution | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72950 2026-09-08 | CVE-2026-72952 CVE-2026-72952 | Microsoft | high 7.0 | Microsoft Windows Spaceport.sys: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72952 2026-09-08 | CVE-2026-72953 CVE-2026-72953 | Microsoft | high 7.8 | Microsoft Windows USB Driver: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72953 2026-09-08 | CVE-2026-72954 CVE-2026-72954 | Microsoft | high 7.5 | Microsoft Windows Deployment Services: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72954 2026-09-08 | CVE-2026-72941 CVE-2026-72941 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72941 2026-09-08 | CVE-2026-72942 CVE-2026-72942 | Microsoft | medium 6.5 | Microsoft Windows Spaceport.sys: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72942 2026-09-08 | CVE-2026-72943 CVE-2026-72943 | Microsoft | high 7.5 | Microsoft Windows Deployment Services: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72943 2026-09-08 | CVE-2026-72944 CVE-2026-72944 | Microsoft | high 7.8 | Microsoft Windows Fax Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72944 2026-09-08 | CVE-2026-72945 CVE-2026-72945 | Microsoft | medium 5.5 | Microsoft Windows Task Scheduler: uninitialized resource | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72945 2026-09-08 | CVE-2026-72946 CVE-2026-72946 | Microsoft | high 7.8 | Microsoft Storage Port Driver: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72946 2026-09-08 | CVE-2026-72935 CVE-2026-72935 | Microsoft | medium 6.7 | Microsoft Windows NTFS: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72935 2026-09-08 | CVE-2026-72936 CVE-2026-72936 | Microsoft | high 8.1 | Microsoft Windows SMB Client: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72936 2026-09-08 | CVE-2026-72937 CVE-2026-72937 | Microsoft | medium 5.5 | Microsoft Storage Port Driver: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72937 2026-09-08 | CVE-2026-72938 CVE-2026-72938 | Microsoft | medium 6.5 | Microsoft Office PowerPoint: type confusion | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72938 2026-09-08 | CVE-2026-72939 CVE-2026-72939 | Microsoft | medium 6.5 | Microsoft Windows: null pointer dereference | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72939 2026-09-08 | CVE-2026-72940 CVE-2026-72940 | Microsoft | high 8.8 | Microsoft Windows Schannel: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72940 2026-09-08 | CVE-2026-72928 CVE-2026-72928 | Microsoft | high 7.5 | Microsoft Windows DNS: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72928 2026-09-08 | CVE-2026-72929 CVE-2026-72929 | Microsoft | high 7.8 | Microsoft Windows Installer: privilege escalation | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72929 2026-09-08 | CVE-2026-72930 CVE-2026-72930 | Microsoft | high 7.0 | Microsoft Windows: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72930 2026-09-08 | CVE-2026-72931 CVE-2026-72931 | Microsoft | medium 4.7 | Microsoft Windows: resource leak | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72931 2026-09-08 | CVE-2026-72932 CVE-2026-72932 | Microsoft | high 7.5 | Microsoft Windows Message Queuing: unauthorized attacker could disclose... | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72932 2026-09-08 | CVE-2026-72933 CVE-2026-72933 | Microsoft | high 8.8 | Microsoft Windows: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72933 2026-09-08 | CVE-2026-71353 CVE-2026-71353 | Microsoft | high 7.0 | Microsoft Windows: double free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-71353 2026-09-08 | CVE-2026-72926 CVE-2026-72926 | Microsoft | high 7.0 | Microsoft Windows: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72926 2026-09-08 | CVE-2026-72927 CVE-2026-72927 | Microsoft | medium 6.7 | Microsoft Winsock: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72927 2026-09-08 | CVE-2026-71350 CVE-2026-71350 | Microsoft | medium 6.8 | Microsoft Windows Spaceport.sys: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-71350 2026-09-08 | CVE-2026-71351 CVE-2026-71351 | Microsoft | high 7.0 | Microsoft Windows: double free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-71351 2026-09-08 | CVE-2026-71352 CVE-2026-71352 | Microsoft | high 8.8 | Microsoft Windows Remote Access Connection Manager: integer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-71352 2026-09-08 | CVE-2026-71341 CVE-2026-71341 | Microsoft | medium 5.5 | Microsoft Windows Partition Management Driver: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-71341 2026-09-08 | CVE-2026-71342 CVE-2026-71342 | Microsoft | high 7.0 | Microsoft Windows Remote Access Connection Manager: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-71342 2026-09-08 | CVE-2026-71343 CVE-2026-71343 | Microsoft | high 7.8 | Microsoft Windows Remote Access Connection Manager: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-71343 2026-09-08 | CVE-2026-71345 CVE-2026-71345 | Microsoft | high 7.8 | Microsoft Windows Spaceport.sys: out-of-bounds write | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-71345 2026-09-08 | CVE-2026-71348 CVE-2026-71348 | Microsoft | medium 6.8 | Microsoft Windows Spaceport.sys: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-71348 2026-09-08 | CVE-2026-71349 CVE-2026-71349 | Microsoft | medium 6.8 | Microsoft Windows Spaceport.sys: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-71349 2026-09-08 | CVE-2026-71334 CVE-2026-71334 | Microsoft | high 7.8 | Microsoft Windows NFS Portmapper: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-71334 2026-09-08 | CVE-2026-71336 CVE-2026-71336 | Microsoft | high 8.8 | Microsoft Windows Work Folder Service: integer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-71336 2026-09-08 | CVE-2026-71337 CVE-2026-71337 | Microsoft | high 7.8 | Microsoft Windows Storage Management Provider: stack buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-71337 2026-09-08 | CVE-2026-71338 CVE-2026-71338 | Microsoft | medium 6.4 | Microsoft Windows Failover Cluster: double free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-71338 2026-09-08 | CVE-2026-71339 CVE-2026-71339 | Microsoft | medium 6.7 | Microsoft Windows Installer: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-71339 2026-09-08 | CVE-2026-71340 CVE-2026-71340 | Microsoft | high 7.0 | Microsoft Windows File History Service: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-71340 2026-09-08 | CVE-2026-71328 CVE-2026-71328 | Microsoft | high 8.8 | Microsoft Visual Studio: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-71328 2026-09-08 | CVE-2026-71329 CVE-2026-71329 | Microsoft | medium 6.8 | Microsoft Windows NTFS: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-71329 2026-09-08 | CVE-2026-71330 CVE-2026-71330 | Microsoft | high 7.5 | Microsoft Windows Services: system information exposure | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-71330 2026-09-08 | CVE-2026-71332 CVE-2026-71332 | Microsoft | high 7.0 | Microsoft Windows: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-71332 2026-09-08 | CVE-2026-71333 CVE-2026-71333 | Microsoft | high 7.0 | Microsoft Windows Remote Access Connection Manager: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-71333 2026-09-08 | CVE-2026-70582 CVE-2026-70582 | Microsoft | medium 6.4 | Microsoft Windows Management Instrumentation: race condition | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70582 2026-09-08 | CVE-2026-70583 CVE-2026-70583 | Microsoft | high 7.8 | Microsoft Windows Core Messaging: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70583 2026-09-08 | CVE-2026-70584 CVE-2026-70584 | Microsoft | high 7.8 | Microsoft Windows Core Messaging: type confusion | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70584 2026-09-08 | CVE-2026-70585 CVE-2026-70585 | Microsoft | high 7.0 | Microsoft Windows Services for NFS ONCRPC XDR Driver: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70585 2026-09-08 | CVE-2026-70586 CVE-2026-70586 | Microsoft | high 8.8 | Microsoft Windows Paint: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70586 2026-09-08 | CVE-2026-70587 CVE-2026-70587 | Microsoft | high 7.5 | Microsoft Windows Remote Desktop: unauthorized attacker could disclose... | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70587 2026-09-08 | CVE-2026-70573 CVE-2026-70573 | Microsoft | high 7.0 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70573 2026-09-08 | CVE-2026-70574 CVE-2026-70574 | Microsoft | high 7.8 | Microsoft Windows: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70574 2026-09-08 | CVE-2026-70575 CVE-2026-70575 | Microsoft | medium 5.3 | Microsoft Windows Schannel: null pointer dereference | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70575 2026-09-08 | CVE-2026-70577 CVE-2026-70577 | Microsoft | high 7.0 | Microsoft Windows: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70577 2026-09-08 | CVE-2026-70578 CVE-2026-70578 | Microsoft | high 7.0 | Microsoft Windows Credential Guard: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70578 2026-09-08 | CVE-2026-70579 CVE-2026-70579 | Microsoft | high 7.5 | Microsoft Windows Mobile Broadband: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70579 2026-09-08 | CVE-2026-70581 CVE-2026-70581 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: integer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70581 2026-09-08 | CVE-2026-70565 CVE-2026-70565 | Microsoft | high 7.0 | Microsoft Windows AF_UNIX Socket Provider: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70565 2026-09-08 | CVE-2026-70567 CVE-2026-70567 | Microsoft | high 7.0 | Microsoft Windows Display Enhancement Service: double free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70567 2026-09-08 | CVE-2026-70568 CVE-2026-70568 | Microsoft | high 7.0 | Microsoft Windows Defender Firewall Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70568 2026-09-08 | CVE-2026-70569 CVE-2026-70569 | Microsoft | high 7.8 | Microsoft Windows Spaceport.sys: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70569 2026-09-08 | CVE-2026-70570 CVE-2026-70570 | Microsoft | high 7.5 | Microsoft Windows: remote code execution | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70570 2026-09-08 | CVE-2026-70572 CVE-2026-70572 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: integer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70572 2026-09-08 | CVE-2026-70351 CVE-2026-70351 | Microsoft | high 8.8 | Microsoft WebP Image Extension: integer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70351 2026-09-08 | CVE-2026-70562 CVE-2026-70562 | Microsoft | high 7.0 | Microsoft Windows Audio Service: double free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70562 2026-09-08 | CVE-2026-70563 CVE-2026-70563 | Microsoft | high 8.1 | Microsoft Windows Shell: spoofing | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70563 2026-09-08 | CVE-2026-70564 CVE-2026-70564 | Microsoft | high 7.8 | Microsoft Windows Print Spooler Components: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70564 2026-09-08 | CVE-2026-70342 CVE-2026-70342 | Microsoft | high 8.1 | Microsoft Windows Ancillary Function Driver for WinSock: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70342 2026-09-08 | CVE-2026-70203 CVE-2026-70203 | Microsoft | high 8.8 | Microsoft Windows Media Player: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70203 2026-09-08 | CVE-2026-70283 CVE-2026-70283 | Microsoft | high 7.0 | Microsoft Windows Win32K: improper authorization | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70283 2026-09-08 | CVE-2026-70289 CVE-2026-70289 | Microsoft | high 7.8 | Microsoft Windows Win32 Kernel Subsystem: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70289 2026-09-08 | CVE-2026-70290 CVE-2026-70290 | Microsoft | medium 5.5 | Microsoft Windows Win32 Kernel Subsystem: uninitialized resource | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70290 2026-09-08 | CVE-2026-70296 CVE-2026-70296 | Microsoft | critical 9.8 | Microsoft Windows Imaging Component: out-of-bounds write | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70296 2026-09-08 | CVE-2026-69989 CVE-2026-69989 | Microsoft | high 8.1 | Microsoft DNS Server: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69989 2026-09-08 | CVE-2026-70019 CVE-2026-70019 | Microsoft | medium 6.5 | Microsoft Windows Compressed Folder: unauthorized attacker could disclose... | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70019 2026-09-08 | CVE-2026-70065 CVE-2026-70065 | Microsoft | high 7.5 | Microsoft Windows DHCP Server: memory leak | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70065 2026-09-08 | CVE-2026-70091 CVE-2026-70091 | Microsoft | medium 5.9 | Microsoft Windows DNS: race condition | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70091 2026-09-08 | CVE-2026-70124 CVE-2026-70124 | Microsoft | medium 5.9 | Microsoft Windows DHCP Server: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70124 2026-09-08 | CVE-2026-70145 CVE-2026-70145 | Microsoft | medium 5.5 | Microsoft Windows Search Component: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70145 2026-09-08 | CVE-2026-69910 CVE-2026-69910 | Microsoft | critical 9.8 | Microsoft Windows Hyper-V: stack buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69910 2026-09-08 | CVE-2026-69911 CVE-2026-69911 | Microsoft | high 7.0 | Microsoft Windows Search Component: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69911 2026-09-08 | CVE-2026-69921 CVE-2026-69921 | Microsoft | high 7.8 | Microsoft Windows Print Spooler Components: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69921 2026-09-08 | CVE-2026-69929 CVE-2026-69929 | Microsoft | medium 5.9 | Microsoft Windows DHCP Server: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69929 2026-09-08 | CVE-2026-69930 CVE-2026-69930 | Microsoft | medium 5.9 | Microsoft Windows DHCP Server: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69930 2026-09-08 | CVE-2026-69907 CVE-2026-69907 | Microsoft | high 7.8 | Microsoft Windows Enterprise App Management: privilege escalation | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69907 2026-09-08 | CVE-2026-69891 CVE-2026-69891 | Microsoft | high 7.0 | Microsoft Windows Media: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69891 2026-09-08 | CVE-2026-69895 CVE-2026-69895 | Microsoft | medium 4.7 | Microsoft Windows Spaceport.sys: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69895 2026-09-08 | CVE-2026-69896 CVE-2026-69896 | Microsoft | high 7.0 | Microsoft Windows Error Reporting: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69896 2026-09-08 | CVE-2026-69900 CVE-2026-69900 | Microsoft | high 7.8 | Microsoft Kernel Streaming WOW Thunk Service Driver: privilege escalation | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69900 2026-09-08 | CVE-2026-69904 CVE-2026-69904 | Microsoft | low 3.5 | Microsoft SharePoint Server Subscription Edition: server-side request forgery | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69904 2026-09-08 | CVE-2026-69906 CVE-2026-69906 | Microsoft | high 8.2 | Microsoft Windows Secure Kernel Mode: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69906 2026-09-08 | CVE-2026-69878 CVE-2026-69878 | Microsoft | medium 6.4 | Microsoft Windows DHCP Server: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69878 2026-09-08 | CVE-2026-69881 CVE-2026-69881 | Microsoft | high 7.5 | Microsoft Windows IKE Extension: null pointer dereference | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69881 2026-09-08 | CVE-2026-69889 CVE-2026-69889 | Microsoft | high 7.0 | Microsoft Windows Bluetooth Service: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69889 2026-09-08 | CVE-2026-69890 CVE-2026-69890 | Microsoft | high 7.5 | Microsoft Windows Virtual Trusted Platform Module: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69890 2026-09-08 | CVE-2026-69874 CVE-2026-69874 | Microsoft | high 8.2 | Microsoft Windows ALPC: privilege escalation | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69874 2026-09-08 | CVE-2026-69875 CVE-2026-69875 | Microsoft | high 8.0 | Microsoft Windows NTFS: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69875 2026-09-08 | CVE-2026-69876 CVE-2026-69876 | Microsoft | high 8.0 | Microsoft Windows DHCP Server: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69876 2026-09-08 | CVE-2026-69858 CVE-2026-69858 | Microsoft | high 8.1 | Microsoft Windows DNS: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69858 2026-09-08 | CVE-2026-69859 CVE-2026-69859 | Microsoft | high 7.0 | Microsoft Windows: race condition | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69859 2026-09-08 | CVE-2026-69860 CVE-2026-69860 | Microsoft | high 8.8 | Microsoft Windows Imaging Component: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69860 2026-09-08 | CVE-2026-69862 CVE-2026-69862 | Microsoft | medium 5.5 | Microsoft Windows Wireless Wide Area Network Service: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69862 2026-09-08 | CVE-2026-69864 CVE-2026-69864 | Microsoft | high 7.8 | Microsoft Windows Hello: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69864 2026-09-08 | CVE-2026-69866 CVE-2026-69866 | Microsoft | high 7.0 | Microsoft Windows Device Association Service: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69866 2026-09-08 | CVE-2026-69845 CVE-2026-69845 | Microsoft | critical 9.8 | Microsoft Windows DHCP Server: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69845 2026-09-08 | CVE-2026-69846 CVE-2026-69846 | Microsoft | high 8.2 | Microsoft Windows Secure Kernel Mode: integer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69846 2026-09-08 | CVE-2026-69847 CVE-2026-69847 | Microsoft | high 8.0 | Microsoft Windows DHCP Server: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69847 2026-09-08 | CVE-2026-69852 CVE-2026-69852 | Microsoft | high 7.5 | Microsoft Windows: remote code execution | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69852 2026-09-08 | CVE-2026-69853 CVE-2026-69853 | Microsoft | medium 4.7 | Microsoft Windows Win32K: uninitialized resource | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69853 2026-09-08 | CVE-2026-69854 CVE-2026-69854 | Microsoft | critical 9.0 | Microsoft Spring Cloud Azure: improper authentication | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69854 2026-09-08 | CVE-2026-69834 CVE-2026-69834 | Microsoft | high 7.0 | Microsoft Windows ALPC: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69834 2026-09-08 | CVE-2026-69838 CVE-2026-69838 | Microsoft | high 7.0 | Microsoft Windows Print Spooler Components: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69838 2026-09-08 | CVE-2026-69839 CVE-2026-69839 | Microsoft | medium 6.5 | Uncaught exception in Windows iSCSI Target Service | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69839 2026-09-08 | CVE-2026-69841 CVE-2026-69841 | Microsoft | high 7.8 | Microsoft Windows: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69841 2026-09-08 | CVE-2026-69844 CVE-2026-69844 | Microsoft | high 7.8 | Microsoft Windows Win32K: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69844 2026-09-08 | CVE-2026-69822 CVE-2026-69822 | Microsoft | high 7.8 | Microsoft Windows Kerberos: privilege escalation | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69822 2026-09-08 | CVE-2026-69824 CVE-2026-69824 | Microsoft | critical 9.8 | Microsoft Standard XPS: integer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69824 2026-09-08 | CVE-2026-69826 CVE-2026-69826 | Microsoft | high 8.0 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69826 2026-09-08 | CVE-2026-69827 CVE-2026-69827 | Microsoft | high 8.1 | Microsoft DNS Server: race condition | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69827 2026-09-08 | CVE-2026-69829 CVE-2026-69829 | Microsoft | critical 9.8 | Microsoft Windows Shell: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69829 2026-09-08 | CVE-2026-69832 CVE-2026-69832 | Microsoft | medium 5.6 | Microsoft Windows Win32K: system information exposure | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69832 2026-09-08 | CVE-2026-69816 CVE-2026-69816 | Microsoft | high 7.0 | Microsoft Windows Accounts Control: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69816 2026-09-08 | CVE-2026-69817 CVE-2026-69817 | Microsoft | high 7.0 | Microsoft Windows Bluetooth Port Driver: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69817 2026-09-08 | CVE-2026-69818 CVE-2026-69818 | Microsoft | high 7.0 | Microsoft Windows Win32K: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69818 2026-09-08 | CVE-2026-69819 CVE-2026-69819 | Microsoft | critical 9.8 | Microsoft RPC Runtime: out-of-bounds write | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69819 2026-09-08 | CVE-2026-69820 CVE-2026-69820 | Microsoft | high 8.2 | Microsoft Windows Hello: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69820 2026-09-08 | CVE-2026-69821 CVE-2026-69821 | Microsoft | high 7.8 | Microsoft Windows: privilege escalation | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69821 2026-09-08 | CVE-2026-69805 CVE-2026-69805 | Microsoft | high 7.5 | Microsoft Visual Studio 2022 version 17.14: privilege escalation | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69805 2026-09-08 | CVE-2026-69806 CVE-2026-69806 | Microsoft | high 7.0 | Microsoft .NET 10.0: information disclosure | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69806 2026-09-08 | CVE-2026-69807 CVE-2026-69807 | Microsoft | high 8.0 | Microsoft Windows PowerShell: path traversal | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69807 2026-09-08 | CVE-2026-69808 CVE-2026-69808 | Microsoft | medium 5.5 | Microsoft Windows Win32K: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69808 2026-09-08 | CVE-2026-69809 CVE-2026-69809 | Microsoft | high 7.5 | Microsoft Active Directory Domain Services: memory leak | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69809 2026-09-08 | CVE-2026-69813 CVE-2026-69813 | Microsoft | high 8.1 | Microsoft Windows DNS: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69813 2026-09-08 | CVE-2026-69814 CVE-2026-69814 | Microsoft | high 7.0 | Microsoft Windows Credential Providers: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69814 2026-09-08 | CVE-2026-69794 CVE-2026-69794 | Microsoft | medium 5.5 | Buffer over-read in Windows Encrypting File System | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69794 2026-09-08 | CVE-2026-69797 CVE-2026-69797 | Microsoft | high 8.8 | Microsoft Office PowerPoint: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69797 2026-09-08 | CVE-2026-69799 CVE-2026-69799 | Microsoft | high 7.8 | Microsoft Windows Hello: race condition | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69799 2026-09-08 | CVE-2026-69801 CVE-2026-69801 | Microsoft | high 7.8 | Microsoft Windows Audio Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69801 2026-09-08 | CVE-2026-69803 CVE-2026-69803 | Microsoft | medium 5.9 | Microsoft Windows DHCP Server: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69803 2026-09-08 | CVE-2026-69804 CVE-2026-69804 | Microsoft | high 7.5 | Microsoft SharePoint Server Subscription Edition: race condition | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69804 2026-09-08 | CVE-2026-69786 CVE-2026-69786 | Microsoft | high 8.1 | Microsoft Windows Text Shaping: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69786 2026-09-08 | CVE-2026-69787 CVE-2026-69787 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69787 2026-09-08 | CVE-2026-69790 CVE-2026-69790 | Microsoft | high 7.8 | Microsoft Windows Credential Providers: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69790 2026-09-08 | CVE-2026-69791 CVE-2026-69791 | Microsoft | high 7.0 | Microsoft Windows Device Association Service: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69791 2026-09-08 | CVE-2026-69792 CVE-2026-69792 | Microsoft | medium 4.7 | Microsoft Windows Win32K: race condition | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69792 2026-09-08 | CVE-2026-69793 CVE-2026-69793 | Microsoft | high 7.5 | Microsoft Windows TCP/IP: unauthorized attacker could bypass a security feature... | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69793 2026-09-08 | CVE-2026-69777 CVE-2026-69777 | Microsoft | high 8.0 | Microsoft Windows DHCP Client: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69777 2026-09-08 | CVE-2026-69778 CVE-2026-69778 | Microsoft | high 8.8 | Microsoft Office Access: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69778 2026-09-08 | CVE-2026-69779 CVE-2026-69779 | Microsoft | high 7.0 | Microsoft Windows Win32K: race condition | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69779 2026-09-08 | CVE-2026-69781 CVE-2026-69781 | Microsoft | medium 6.5 | Microsoft Windows DHCP Client: memory leak | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69781 2026-09-08 | CVE-2026-69782 CVE-2026-69782 | Microsoft | high 8.1 | Microsoft DNS Server: race condition | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69782 2026-09-08 | CVE-2026-69784 CVE-2026-69784 | Microsoft | high 8.8 | Microsoft Windows Hello: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69784 2026-09-08 | CVE-2026-69785 CVE-2026-69785 | Microsoft | high 7.8 | Microsoft Windows Smart Card: untrusted search path | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69785 2026-09-08 | CVE-2026-69769 CVE-2026-69769 | Microsoft | critical 9.8 | Microsoft Windows HTTP Print Provider: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69769 2026-09-08 | CVE-2026-69770 CVE-2026-69770 | Microsoft | medium 5.5 | Microsoft Windows Spaceport.sys: uninitialized resource | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69770 2026-09-08 | CVE-2026-69771 CVE-2026-69771 | Microsoft | medium 4.7 | Microsoft Windows Container Manager Service: link following | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69771 2026-09-08 | CVE-2026-69772 CVE-2026-69772 | Microsoft | high 8.8 | Microsoft Windows Network File System: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69772 2026-09-08 | CVE-2026-69773 CVE-2026-69773 | Microsoft | high 8.0 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69773 2026-09-08 | CVE-2026-69775 CVE-2026-69775 | Microsoft | high 7.1 | Microsoft Windows DWM Core Library: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69775 2026-09-08 | CVE-2026-69759 CVE-2026-69759 | Microsoft | high 8.8 | Microsoft Office Word: stack buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69759 2026-09-08 | CVE-2026-69760 CVE-2026-69760 | Microsoft | high 7.5 | Microsoft Windows Kerberos: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69760 2026-09-08 | CVE-2026-69761 CVE-2026-69761 | Microsoft | high 7.1 | Microsoft Windows TCP/IP: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69761 2026-09-08 | CVE-2026-69762 CVE-2026-69762 | Microsoft | high 8.0 | Microsoft Windows Win32K: stack buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69762 2026-09-08 | CVE-2026-69764 CVE-2026-69764 | Microsoft | high 8.8 | Microsoft Office Word: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69764 2026-09-08 | CVE-2026-69767 CVE-2026-69767 | Microsoft | high 8.8 | Microsoft Office PowerPoint: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69767 2026-09-08 | CVE-2026-69768 CVE-2026-69768 | Microsoft | critical 9.8 | Microsoft Windows RNDIS: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69768 2026-09-08 | CVE-2026-69739 CVE-2026-69739 | Microsoft | medium 6.5 | Microsoft Office: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69739 2026-09-08 | CVE-2026-69740 CVE-2026-69740 | Microsoft | high 8.8 | Microsoft Windows Hello: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69740 2026-09-08 | CVE-2026-69741 CVE-2026-69741 | Microsoft | medium 5.5 | Microsoft Windows Spaceport.sys: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69741 2026-09-08 | CVE-2026-69742 CVE-2026-69742 | Microsoft | high 8.8 | Microsoft Office Publisher: integer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69742 2026-09-08 | CVE-2026-69744 CVE-2026-69744 | Microsoft | high 7.5 | Microsoft Windows Kerberos: null pointer dereference | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69744 2026-09-08 | CVE-2026-69757 CVE-2026-69757 | Microsoft | high 7.1 | Microsoft Windows TCP/IP: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69757 2026-09-08 | CVE-2026-69758 CVE-2026-69758 | Microsoft | high 7.8 | Microsoft Windows: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69758 2026-09-08 | CVE-2026-69729 CVE-2026-69729 | Microsoft | high 8.8 | Microsoft Windows Credential Providers: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69729 2026-09-08 | CVE-2026-69730 CVE-2026-69730 | Microsoft | critical 9.8 | Microsoft Windows DNS: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69730 2026-09-08 | CVE-2026-69731 CVE-2026-69731 | Microsoft | high 7.8 | Microsoft Windows: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69731 2026-09-08 | CVE-2026-69732 CVE-2026-69732 | Microsoft | high 8.1 | Microsoft Windows Link Layer Topology Discovery Protocol: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69732 2026-09-08 | CVE-2026-69734 CVE-2026-69734 | Microsoft | medium 6.5 | Microsoft Office Word: integer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69734 2026-09-08 | CVE-2026-69735 CVE-2026-69735 | Microsoft | high 7.0 | Microsoft Windows Broadcast DVR User Service: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69735 2026-09-08 | CVE-2026-69738 CVE-2026-69738 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: integer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69738 2026-09-08 | CVE-2026-69719 CVE-2026-69719 | Microsoft | medium 6.5 | Microsoft Office Word: unauthorized attacker could disclose information over | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69719 2026-09-08 | CVE-2026-69720 CVE-2026-69720 | Microsoft | high 7.8 | Microsoft Windows MIDI Service Module: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69720 2026-09-08 | CVE-2026-69722 CVE-2026-69722 | Microsoft | high 8.8 | Microsoft Office Word: stack buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69722 2026-09-08 | CVE-2026-69723 CVE-2026-69723 | Microsoft | medium 5.7 | Microsoft Windows Kernel: system information exposure | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69723 2026-09-08 | CVE-2026-69724 CVE-2026-69724 | Microsoft | high 8.8 | Microsoft SharePoint Server Subscription Edition: missing authorization | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69724 2026-09-08 | CVE-2026-69725 CVE-2026-69725 | Microsoft | high 7.8 | Microsoft Windows Hello: double free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69725 2026-09-08 | CVE-2026-69727 CVE-2026-69727 | Microsoft | high 8.0 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69727 2026-09-08 | CVE-2026-69712 CVE-2026-69712 | Microsoft | high 8.8 | Microsoft Windows Key Distribution Center: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69712 2026-09-08 | CVE-2026-69713 CVE-2026-69713 | Microsoft | medium 4.4 | Dependency on vulnerable third-party component in Windows Secure Boot | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69713 2026-09-08 | CVE-2026-69714 CVE-2026-69714 | Microsoft | high 8.0 | Microsoft Windows Device Association Service: stack buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69714 2026-09-08 | CVE-2026-69715 CVE-2026-69715 | Microsoft | critical 9.8 | Microsoft Windows Direct Show: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69715 2026-09-08 | CVE-2026-69716 CVE-2026-69716 | Microsoft | high 8.8 | Microsoft SharePoint Server Subscription Edition: SQL injection | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69716 2026-09-08 | CVE-2026-69717 CVE-2026-69717 | Microsoft | high 8.0 | Microsoft Windows Group Policy: privilege escalation | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69717 2026-09-08 | CVE-2026-69706 CVE-2026-69706 | Microsoft | high 7.1 | Microsoft Windows Win32K: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69706 2026-09-08 | CVE-2026-69707 CVE-2026-69707 | Microsoft | high 7.8 | Microsoft Windows: integer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69707 2026-09-08 | CVE-2026-69708 CVE-2026-69708 | Microsoft | high 7.0 | Microsoft Windows Web Platform Storage: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69708 2026-09-08 | CVE-2026-69709 CVE-2026-69709 | Microsoft | high 7.8 | Microsoft Windows NTFS: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69709 2026-09-08 | CVE-2026-69710 CVE-2026-69710 | Microsoft | high 7.5 | Microsoft Windows Hello: race condition | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69710 2026-09-08 | CVE-2026-69711 CVE-2026-69711 | Microsoft | high 7.0 | Microsoft Windows Device Association Service: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69711 2026-09-08 | CVE-2026-69689 CVE-2026-69689 | Microsoft | high 8.0 | Microsoft Windows Win32K: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69689 2026-09-08 | CVE-2026-69690 CVE-2026-69690 | Microsoft | medium 4.6 | Microsoft SharePoint Server Subscription Edition: cross-site scripting | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69690 2026-09-08 | CVE-2026-69691 CVE-2026-69691 | Microsoft | high 7.8 | Microsoft Windows Spaceport.sys: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69691 2026-09-08 | CVE-2026-69692 CVE-2026-69692 | Microsoft | high 7.0 | Microsoft Windows Audio Service: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69692 2026-09-08 | CVE-2026-69693 CVE-2026-69693 | Microsoft | high 7.0 | Microsoft Windows: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69693 2026-09-08 | CVE-2026-69694 CVE-2026-69694 | Microsoft | high 7.0 | Microsoft Windows: unsafe deserialization | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69694 2026-09-08 | CVE-2026-69683 CVE-2026-69683 | Microsoft | medium 6.5 | Microsoft SharePoint Server Subscription Edition: server-side request forgery | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69683 2026-09-08 | CVE-2026-69684 CVE-2026-69684 | Microsoft | medium 5.5 | Microsoft Windows Error Reporting: information disclosure | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69684 2026-09-08 | CVE-2026-69685 CVE-2026-69685 | Microsoft | high 7.8 | Microsoft Windows Kerberos: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69685 2026-09-08 | CVE-2026-69686 CVE-2026-69686 | Microsoft | high 8.8 | Microsoft Office Word: stack buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69686 2026-09-08 | CVE-2026-69687 CVE-2026-69687 | Microsoft | high 7.8 | Microsoft Windows: integer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69687 2026-09-08 | CVE-2026-69688 CVE-2026-69688 | Microsoft | high 7.1 | Microsoft Windows: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69688 2026-09-08 | CVE-2026-69676 CVE-2026-69676 | Microsoft | high 8.8 | Microsoft Windows Kerberos: authentication bypass | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69676 2026-09-08 | CVE-2026-69678 CVE-2026-69678 | Microsoft | high 8.8 | Microsoft Office PowerPoint: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69678 2026-09-08 | CVE-2026-69679 CVE-2026-69679 | Microsoft | medium 5.7 | Microsoft Windows DHCP Server: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69679 2026-09-08 | CVE-2026-69680 CVE-2026-69680 | Microsoft | high 8.1 | Microsoft Windows DNS: spoofing | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69680 2026-09-08 | CVE-2026-69681 CVE-2026-69681 | Microsoft | high 8.0 | Microsoft Windows: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69681 2026-09-08 | CVE-2026-69682 CVE-2026-69682 | Microsoft | high 7.0 | Microsoft Windows Host Guardian Service: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69682 2026-09-08 | CVE-2026-69649 CVE-2026-69649 | Microsoft | high 8.8 | Microsoft Raw Image Extension: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69649 2026-09-08 | CVE-2026-69652 CVE-2026-69652 | Microsoft | high 7.0 | Microsoft Windows Win32K: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69652 2026-09-08 | CVE-2026-69654 CVE-2026-69654 | Microsoft | high 7.0 | Microsoft Windows Accounts Control: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69654 2026-09-08 | CVE-2026-69669 CVE-2026-69669 | Microsoft | high 8.8 | Microsoft Windows Kernel: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69669 2026-09-08 | CVE-2026-69671 CVE-2026-69671 | Microsoft | high 8.8 | Microsoft Office Word: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69671 2026-09-08 | CVE-2026-69672 CVE-2026-69672 | Microsoft | medium 5.5 | Microsoft Windows DNS: uninitialized resource | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69672 2026-09-08 | CVE-2026-69674 CVE-2026-69674 | Microsoft | medium 5.5 | Microsoft Windows: missing authentication | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69674 2026-09-08 | CVE-2026-69648 CVE-2026-69648 | Microsoft | high 7.0 | Microsoft Windows Notification: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69648 2026-09-08 | CVE-2026-69638 CVE-2026-69638 | Microsoft | high 8.4 | Microsoft Windows NTFS: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69638 2026-09-08 | CVE-2026-69641 CVE-2026-69641 | Microsoft | critical 9.1 | Microsoft Exchange Server: missing authorization | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69641 2026-09-08 | CVE-2026-69643 CVE-2026-69643 | Microsoft | high 8.0 | Microsoft Windows Spaceport.sys: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69643 2026-09-08 | CVE-2026-69645 CVE-2026-69645 | Microsoft | high 7.0 | Microsoft Windows Message Queuing: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69645 2026-09-08 | CVE-2026-69628 CVE-2026-69628 | Microsoft | high 8.8 | Microsoft Windows: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69628 2026-09-08 | CVE-2026-69629 CVE-2026-69629 | Microsoft | high 8.8 | Microsoft Office Outlook: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69629 2026-09-08 | CVE-2026-69630 CVE-2026-69630 | Microsoft | high 7.0 | Microsoft Windows Win32K: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69630 2026-09-08 | CVE-2026-69631 CVE-2026-69631 | Microsoft | high 7.5 | Microsoft Windows DNS: integer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69631 2026-09-08 | CVE-2026-69632 CVE-2026-69632 | Microsoft | high 8.8 | Microsoft Office: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69632 2026-09-08 | CVE-2026-69636 CVE-2026-69636 | Microsoft | medium 6.5 | Microsoft SharePoint Server Subscription Edition: SQL injection | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69636 2026-09-08 | CVE-2026-69637 CVE-2026-69637 | Microsoft | medium 5.7 | Microsoft Windows DHCP Server: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69637 2026-09-08 | CVE-2026-69621 CVE-2026-69621 | Microsoft | high 7.0 | Microsoft Windows Fax Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69621 2026-09-08 | CVE-2026-69623 CVE-2026-69623 | Microsoft | high 8.0 | Microsoft Windows HTTP Print Provider: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69623 2026-09-08 | CVE-2026-69624 CVE-2026-69624 | Microsoft | medium 6.5 | Microsoft Windows: tampering | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69624 2026-09-08 | CVE-2026-69625 CVE-2026-69625 | Microsoft | high 8.0 | Microsoft Windows Connected User Experiences: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69625 2026-09-08 | CVE-2026-69626 CVE-2026-69626 | Microsoft | medium 6.5 | Microsoft Office: unauthorized attacker could disclose information over | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69626 2026-09-08 | CVE-2026-69627 CVE-2026-69627 | Microsoft | medium 5.5 | Microsoft Windows Remote Desktop Licensing Service: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69627 2026-09-08 | CVE-2026-69614 CVE-2026-69614 | Microsoft | high 8.8 | Microsoft Office Access: stack buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69614 2026-09-08 | CVE-2026-69615 CVE-2026-69615 | Microsoft | low 3.5 | Microsoft SharePoint Server Subscription Edition: cross-site scripting | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69615 2026-09-08 | CVE-2026-69616 CVE-2026-69616 | Microsoft | medium 5.5 | Microsoft Windows Remote Desktop Services: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69616 2026-09-08 | CVE-2026-69617 CVE-2026-69617 | Microsoft | high 7.0 | Microsoft Windows: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69617 2026-09-08 | CVE-2026-69618 CVE-2026-69618 | Microsoft | medium 5.5 | Microsoft Windows SMB Client: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69618 2026-09-08 | CVE-2026-69619 CVE-2026-69619 | Microsoft | high 8.0 | Microsoft Windows: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69619 2026-09-08 | CVE-2026-69620 CVE-2026-69620 | Microsoft | high 8.1 | Microsoft Windows DHCP Server: stack buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69620 2026-09-08 | CVE-2026-69609 CVE-2026-69609 | Microsoft | medium 5.5 | Microsoft Windows Win32K: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69609 2026-09-08 | CVE-2026-69610 CVE-2026-69610 | Microsoft | high 7.0 | Microsoft Windows Win32K: privilege escalation | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69610 2026-09-08 | CVE-2026-69611 CVE-2026-69611 | Microsoft | high 7.0 | Microsoft Windows: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69611 2026-09-08 | CVE-2026-69612 CVE-2026-69612 | Microsoft | high 7.8 | Microsoft Windows Error Reporting: path traversal | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69612 2026-09-08 | CVE-2026-69613 CVE-2026-69613 | Microsoft | high 7.0 | Microsoft Windows Image Acquisition: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69613 2026-09-08 | CVE-2026-69602 CVE-2026-69602 | Microsoft | high 7.1 | Microsoft Windows PrintWorkflowUserSvc: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69602 2026-09-08 | CVE-2026-69603 CVE-2026-69603 | Microsoft | high 8.8 | Microsoft Windows Hyper-V: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69603 2026-09-08 | CVE-2026-69604 CVE-2026-69604 | Microsoft | high 7.8 | Microsoft Windows Audio Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69604 2026-09-08 | CVE-2026-69605 CVE-2026-69605 | Microsoft | high 7.0 | Microsoft Install Service: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69605 2026-09-08 | CVE-2026-69606 CVE-2026-69606 | Microsoft | high 7.0 | Microsoft Windows Shell: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69606 2026-09-08 | CVE-2026-69607 CVE-2026-69607 | Microsoft | high 7.5 | Microsoft Windows Deployment Services: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69607 2026-09-08 | CVE-2026-69608 CVE-2026-69608 | Microsoft | high 7.8 | Microsoft Windows Search Component: integer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69608 2026-09-08 | CVE-2026-69595 CVE-2026-69595 | Microsoft | critical 9.8 | Microsoft Windows Services for NFS ONCRPC XDR Driver: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69595 2026-09-08 | CVE-2026-69597 CVE-2026-69597 | Microsoft | high 7.1 | Microsoft Windows HTTP.sys: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69597 2026-09-08 | CVE-2026-69598 CVE-2026-69598 | Microsoft | high 8.8 | Microsoft Windows: remote code execution | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69598 2026-09-08 | CVE-2026-69599 CVE-2026-69599 | Microsoft | high 7.5 | Microsoft Windows Remote Desktop Services: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69599 2026-09-08 | CVE-2026-69600 CVE-2026-69600 | Microsoft | high 7.0 | Microsoft Windows Search Component: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69600 2026-09-08 | CVE-2026-69601 CVE-2026-69601 | Microsoft | high 8.8 | Microsoft Windows Media Foundation: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69601 2026-09-08 | CVE-2026-69588 CVE-2026-69588 | Microsoft | high 7.5 | Microsoft Windows TCP/IP: memory leak | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69588 2026-09-08 | CVE-2026-69589 CVE-2026-69589 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69589 2026-09-08 | CVE-2026-69590 CVE-2026-69590 | Microsoft | critical 9.8 | Microsoft Windows: remote code execution | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69590 2026-09-08 | CVE-2026-69591 CVE-2026-69591 | Microsoft | medium 5.7 | Microsoft Windows NTFS: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69591 2026-09-08 | CVE-2026-69592 CVE-2026-69592 | Microsoft | high 7.8 | Microsoft Windows: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69592 2026-09-08 | CVE-2026-69593 CVE-2026-69593 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69593 2026-09-08 | CVE-2026-69594 CVE-2026-69594 | Microsoft | high 7.8 | Microsoft Windows: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69594 2026-09-08 | CVE-2026-69583 CVE-2026-69583 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69583 2026-09-08 | CVE-2026-69584 CVE-2026-69584 | Microsoft | high 7.8 | Microsoft Windows USB Video Driver: integer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69584 2026-09-08 | CVE-2026-69585 CVE-2026-69585 | Microsoft | high 7.8 | Microsoft Windows Search Component: privilege escalation | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69585 2026-09-08 | CVE-2026-69586 CVE-2026-69586 | Microsoft | critical 9.8 | Microsoft Windows PDF: integer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69586 2026-09-08 | CVE-2026-69587 CVE-2026-69587 | Microsoft | high 7.5 | Microsoft Windows IKE Extension: null pointer dereference | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69587 2026-09-08 | CVE-2026-69576 CVE-2026-69576 | Microsoft | high 7.8 | Microsoft Graphic Fonts: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69576 2026-09-08 | CVE-2026-69578 CVE-2026-69578 | Microsoft | high 7.0 | Microsoft Windows Kernel: privilege escalation | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69578 2026-09-08 | CVE-2026-69579 CVE-2026-69579 | Microsoft | critical 9.8 | Microsoft Windows Message Queuing: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69579 2026-09-08 | CVE-2026-69580 CVE-2026-69580 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69580 2026-09-08 | CVE-2026-69581 CVE-2026-69581 | Microsoft | high 7.0 | Microsoft Windows Device Association Service: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69581 2026-09-08 | CVE-2026-69582 CVE-2026-69582 | Microsoft | high 7.8 | Microsoft Windows Volume Manager Extension Driver: privilege escalation | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69582 2026-09-08 | CVE-2026-69569 CVE-2026-69569 | Microsoft | medium 5.7 | Microsoft Windows Print Spooler Components: untrusted pointer dereference | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69569 2026-09-08 | CVE-2026-69571 CVE-2026-69571 | Microsoft | high 7.8 | Microsoft Windows: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69571 2026-09-08 | CVE-2026-69572 CVE-2026-69572 | Microsoft | medium 5.7 | Microsoft Windows SMB Client: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69572 2026-09-08 | CVE-2026-69573 CVE-2026-69573 | Microsoft | high 7.0 | Microsoft Windows: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69573 2026-09-08 | CVE-2026-69574 CVE-2026-69574 | Microsoft | high 7.0 | Microsoft Windows Device Association Service: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69574 2026-09-08 | CVE-2026-69575 CVE-2026-69575 | Microsoft | high 7.0 | Microsoft Windows Storage Spaces Controller: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69575 2026-09-08 | CVE-2026-69562 CVE-2026-69562 | Microsoft | medium 6.5 | Microsoft SQL Server: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69562 2026-09-08 | CVE-2026-69563 CVE-2026-69563 | Microsoft | high 7.0 | Microsoft Windows Program Compatibility Assistant Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69563 2026-09-08 | CVE-2026-69564 CVE-2026-69564 | Microsoft | high 7.0 | Microsoft Windows: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69564 2026-09-08 | CVE-2026-69566 CVE-2026-69566 | Microsoft | medium 6.8 | Microsoft Windows NTFS: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69566 2026-09-08 | CVE-2026-69567 CVE-2026-69567 | Microsoft | high 7.0 | Microsoft Windows NTFS: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69567 2026-09-08 | CVE-2026-69568 CVE-2026-69568 | Microsoft | medium 5.5 | Microsoft Windows Storage Spaces Controller: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69568 2026-09-08 | CVE-2026-69553 CVE-2026-69553 | Microsoft | high 7.1 | Microsoft Windows Hyper-V: missing authorization | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69553 2026-09-08 | CVE-2026-69554 CVE-2026-69554 | Microsoft | medium 5.5 | Microsoft Windows Search Component: missing authentication | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69554 2026-09-08 | CVE-2026-69556 CVE-2026-69556 | Microsoft | high 8.8 | Microsoft Office Word: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69556 2026-09-08 | CVE-2026-69559 CVE-2026-69559 | Microsoft | medium 5.8 | Microsoft Teams for Android: origin validation error | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69559 2026-09-08 | CVE-2026-69560 CVE-2026-69560 | Microsoft | high 7.0 | Microsoft Windows Work Folder Service: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69560 2026-09-08 | CVE-2026-69561 CVE-2026-69561 | Microsoft | high 7.8 | Microsoft Windows CD-ROM Driver: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69561 2026-09-08 | CVE-2026-69547 CVE-2026-69547 | Microsoft | high 8.8 | Microsoft Windows DHCP Server: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69547 2026-09-08 | CVE-2026-69548 CVE-2026-69548 | Microsoft | medium 4.6 | Microsoft Windows RNDIS: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69548 2026-09-08 | CVE-2026-69549 CVE-2026-69549 | Microsoft | high 7.0 | Microsoft Windows: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69549 2026-09-08 | CVE-2026-69551 CVE-2026-69551 | Microsoft | high 8.8 | Microsoft Windows DNS: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69551 2026-09-08 | CVE-2026-69552 CVE-2026-69552 | Microsoft | medium 5.7 | Microsoft Windows Print Spooler Components: information disclosure | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69552 2026-09-08 | CVE-2026-69539 CVE-2026-69539 | Microsoft | high 7.5 | Microsoft Windows Remote Desktop Services: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69539 2026-09-08 | CVE-2026-69540 CVE-2026-69540 | Microsoft | high 7.0 | Microsoft Windows Audio Service: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69540 2026-09-08 | CVE-2026-69541 CVE-2026-69541 | Microsoft | high 7.8 | Microsoft Windows: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69541 2026-09-08 | CVE-2026-69542 CVE-2026-69542 | Microsoft | high 7.8 | Microsoft Windows Camera Frame Server Monitor: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69542 2026-09-08 | CVE-2026-69544 CVE-2026-69544 | Microsoft | high 7.8 | Microsoft Windows 11 version 26H1: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69544 2026-09-08 | CVE-2026-69546 CVE-2026-69546 | Microsoft | high 8.1 | Microsoft Active Directory Domain Services: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69546 2026-09-08 | CVE-2026-69531 CVE-2026-69531 | Microsoft | medium 5.5 | Microsoft Windows Speech: tampering | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69531 2026-09-08 | CVE-2026-69532 CVE-2026-69532 | Microsoft | high 7.8 | Microsoft Windows NTFS: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69532 2026-09-08 | CVE-2026-69534 CVE-2026-69534 | Microsoft | high 7.8 | Microsoft Windows Program Compatibility Assistant Service: command injection | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69534 2026-09-08 | CVE-2026-69535 CVE-2026-69535 | Microsoft | high 7.8 | Microsoft Windows Spaceport.sys: privilege escalation | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69535 2026-09-08 | CVE-2026-69536 CVE-2026-69536 | Microsoft | high 7.1 | Microsoft Windows Remote Desktop Services: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69536 2026-09-08 | CVE-2026-69538 CVE-2026-69538 | Microsoft | high 7.8 | Microsoft Windows Spaceport.sys: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69538 2026-09-08 | CVE-2026-69525 CVE-2026-69525 | Microsoft | critical 9.8 | Microsoft Windows Remote Desktop Services: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69525 2026-09-08 | CVE-2026-69527 CVE-2026-69527 | Microsoft | medium 5.5 | Microsoft Windows USB Mass Storage Class Driver: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69527 2026-09-08 | CVE-2026-69528 CVE-2026-69528 | Microsoft | high 7.8 | Microsoft Windows Shell: missing authentication | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69528 2026-09-08 | CVE-2026-69529 CVE-2026-69529 | Microsoft | high 8.8 | Microsoft Office Access: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69529 2026-09-08 | CVE-2026-69530 CVE-2026-69530 | Microsoft | high 8.1 | Microsoft Windows: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69530 2026-09-08 | CVE-2026-69516 CVE-2026-69516 | Microsoft | high 7.0 | Microsoft Windows: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69516 2026-09-08 | CVE-2026-69517 CVE-2026-69517 | Microsoft | high 7.0 | Microsoft Windows Wireless Networking: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69517 2026-09-08 | CVE-2026-69518 CVE-2026-69518 | Microsoft | high 8.8 | Microsoft Windows Remote Desktop: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69518 2026-09-08 | CVE-2026-69522 CVE-2026-69522 | Microsoft | high 8.8 | Microsoft Visual Studio: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69522 2026-09-08 | CVE-2026-69524 CVE-2026-69524 | Microsoft | high 8.1 | Microsoft Active Directory Domain Services: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69524 2026-09-08 | CVE-2026-69509 CVE-2026-69509 | Microsoft | high 7.8 | Microsoft Windows Fax Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69509 2026-09-08 | CVE-2026-69510 CVE-2026-69510 | Microsoft | high 8.1 | Microsoft Windows DHCP Server: stack buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69510 2026-09-08 | CVE-2026-69511 CVE-2026-69511 | Microsoft | high 8.8 | Microsoft Windows Media Foundation: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69511 2026-09-08 | CVE-2026-69512 CVE-2026-69512 | Microsoft | high 8.0 | Microsoft Windows Spaceport.sys: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69512 2026-09-08 | CVE-2026-69513 CVE-2026-69513 | Microsoft | high 7.8 | Microsoft Windows Error Reporting: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69513 2026-09-08 | CVE-2026-69514 CVE-2026-69514 | Microsoft | high 7.5 | Microsoft Windows Remote Desktop Services: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69514 2026-09-08 | CVE-2026-69501 CVE-2026-69501 | Microsoft | high 7.0 | Microsoft Windows Secure Kernel Mode: privilege escalation | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69501 2026-09-08 | CVE-2026-69503 CVE-2026-69503 | Microsoft | high 8.0 | Microsoft Windows USB Driver: stack buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69503 2026-09-08 | CVE-2026-69504 CVE-2026-69504 | Microsoft | medium 5.5 | Microsoft Windows NTFS: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69504 2026-09-08 | CVE-2026-69505 CVE-2026-69505 | Microsoft | high 8.0 | Microsoft Windows NTFS: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69505 2026-09-08 | CVE-2026-69507 CVE-2026-69507 | Microsoft | medium 5.7 | Microsoft Windows Search Component: information disclosure | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69507 2026-09-08 | CVE-2026-69508 CVE-2026-69508 | Microsoft | high 7.8 | Microsoft Windows MIDI Service Module: stack buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69508 2026-09-08 | CVE-2026-69495 CVE-2026-69495 | Microsoft | high 8.8 | Microsoft Windows Event Logging Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69495 2026-09-08 | CVE-2026-69496 CVE-2026-69496 | Microsoft | critical 9.8 | Microsoft Windows Compressed Folder: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69496 2026-09-08 | CVE-2026-69497 CVE-2026-69497 | Microsoft | medium 6.5 | Microsoft Windows DHCP Server: memory leak | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69497 2026-09-08 | CVE-2026-69498 CVE-2026-69498 | Microsoft | high 7.0 | Microsoft Windows Win32K: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69498 2026-09-08 | CVE-2026-69499 CVE-2026-69499 | Microsoft | high 8.8 | Microsoft Windows Imaging Component: integer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69499 2026-09-08 | CVE-2026-69500 CVE-2026-69500 | Microsoft | high 7.0 | Microsoft Windows Image Acquisition: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69500 2026-09-08 | CVE-2026-69489 CVE-2026-69489 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69489 2026-09-08 | CVE-2026-69490 CVE-2026-69490 | Microsoft | medium 6.8 | Microsoft Windows USB Mass Storage Class Driver: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69490 2026-09-08 | CVE-2026-69491 CVE-2026-69491 | Microsoft | critical 9.8 | Windows Microsoft DirectMusic: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69491 2026-09-08 | CVE-2026-69492 CVE-2026-69492 | Microsoft | high 7.0 | Microsoft Windows Partition Management Driver: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69492 2026-09-08 | CVE-2026-69493 CVE-2026-69493 | Microsoft | critical 9.8 | Microsoft Windows Event Logging Service: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69493 2026-09-08 | CVE-2026-69494 CVE-2026-69494 | Microsoft | high 8.8 | Microsoft Windows Event Logging Service: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69494 2026-09-08 | CVE-2026-69481 CVE-2026-69481 | Microsoft | high 8.0 | Microsoft Windows Enterprise App Management: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69481 2026-09-08 | CVE-2026-69482 CVE-2026-69482 | Microsoft | high 7.1 | Microsoft Windows Error Reporting: insecure permissions | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69482 2026-09-08 | CVE-2026-69483 CVE-2026-69483 | Microsoft | medium 4.7 | Microsoft Windows Image Acquisition: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69483 2026-09-08 | CVE-2026-69485 CVE-2026-69485 | Microsoft | high 8.8 | Microsoft Remote Desktop Client: remote code execution | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69485 2026-09-08 | CVE-2026-69488 CVE-2026-69488 | Microsoft | high 7.0 | Microsoft Windows Device Association Service: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69488 2026-09-08 | CVE-2026-69475 CVE-2026-69475 | Microsoft | high 7.8 | Microsoft Windows Remote Desktop Services: privilege escalation | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69475 2026-09-08 | CVE-2026-69476 CVE-2026-69476 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69476 2026-09-08 | CVE-2026-69477 CVE-2026-69477 | Microsoft | high 7.3 | Microsoft Office Access: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69477 2026-09-08 | CVE-2026-69478 CVE-2026-69478 | Microsoft | high 7.8 | Microsoft Windows Device Association Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69478 2026-09-08 | CVE-2026-69479 CVE-2026-69479 | Microsoft | high 8.4 | Microsoft Windows NTFS: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69479 2026-09-08 | CVE-2026-69480 CVE-2026-69480 | Microsoft | high 7.8 | Microsoft Windows Partition Management Driver: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69480 2026-09-08 | CVE-2026-69468 CVE-2026-69468 | Microsoft | high 7.0 | Microsoft Windows Volume Manager Extension Driver: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69468 2026-09-08 | CVE-2026-69469 CVE-2026-69469 | Microsoft | medium 6.6 | Microsoft Windows: integer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69469 2026-09-08 | CVE-2026-69470 CVE-2026-69470 | Microsoft | high 7.0 | Microsoft Windows Connected User Experiences: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69470 2026-09-08 | CVE-2026-69472 CVE-2026-69472 | Microsoft | high 7.0 | Microsoft Windows Devices Human Interface: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69472 2026-09-08 | CVE-2026-69473 CVE-2026-69473 | Microsoft | high 7.0 | Microsoft Windows Kernel: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69473 2026-09-08 | CVE-2026-69474 CVE-2026-69474 | Microsoft | medium 4.8 | Microsoft Windows Overlay Filter: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69474 2026-09-08 | CVE-2026-69461 CVE-2026-69461 | Microsoft | high 8.8 | Microsoft Windows NTFS: stack buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69461 2026-09-08 | CVE-2026-69462 CVE-2026-69462 | Microsoft | high 8.0 | Microsoft Windows Error Reporting: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69462 2026-09-08 | CVE-2026-69463 CVE-2026-69463 | Microsoft | critical 9.8 | Microsoft Windows NTFS: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69463 2026-09-08 | CVE-2026-69464 CVE-2026-69464 | Microsoft | high 8.8 | Microsoft SharePoint Server Subscription Edition: privilege escalation | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69464 2026-09-08 | CVE-2026-69465 CVE-2026-69465 | Microsoft | high 8.8 | Microsoft SharePoint Server Subscription Edition: missing authorization | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69465 2026-09-08 | CVE-2026-69466 CVE-2026-69466 | Microsoft | high 7.0 | Microsoft Windows Kernel: race condition | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69466 2026-09-08 | CVE-2026-69467 CVE-2026-69467 | Microsoft | high 7.8 | Microsoft Graphics Component: stack buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69467 2026-09-08 | CVE-2026-69455 CVE-2026-69455 | Microsoft | high 7.8 | Microsoft Windows Remote Access Connection Manager: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69455 2026-09-08 | CVE-2026-69456 CVE-2026-69456 | Microsoft | high 7.8 | Microsoft Windows Speech: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69456 2026-09-08 | CVE-2026-69457 CVE-2026-69457 | Microsoft | medium 5.5 | Microsoft Windows USB Driver: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69457 2026-09-08 | CVE-2026-69458 CVE-2026-69458 | Microsoft | high 8.0 | Microsoft Windows BitLocker: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69458 2026-09-08 | CVE-2026-69459 CVE-2026-69459 | Microsoft | high 7.8 | Microsoft Windows Power Dependency Coordinator: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69459 2026-09-08 | CVE-2026-69460 CVE-2026-69460 | Microsoft | high 7.1 | Microsoft Windows: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69460 2026-09-08 | CVE-2026-69447 CVE-2026-69447 | Microsoft | high 7.8 | Microsoft Windows Audio Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69447 2026-09-08 | CVE-2026-69448 CVE-2026-69448 | Microsoft | high 7.0 | Microsoft Windows Bluetooth Service: race condition | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69448 2026-09-08 | CVE-2026-69449 CVE-2026-69449 | Microsoft | medium 6.7 | Microsoft Windows BitLocker: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69449 2026-09-08 | CVE-2026-69450 CVE-2026-69450 | Microsoft | high 7.8 | Microsoft Windows Error Reporting: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69450 2026-09-08 | CVE-2026-69451 CVE-2026-69451 | Microsoft | high 7.1 | Microsoft Windows Management Instrumentation: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69451 2026-09-08 | CVE-2026-69453 CVE-2026-69453 | Microsoft | medium 5.5 | Microsoft Windows Search Component: missing authorization | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69453 2026-09-08 | CVE-2026-69440 CVE-2026-69440 | Microsoft | high 7.0 | Microsoft Windows MIDI Service Module: race condition | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69440 2026-09-08 | CVE-2026-69441 CVE-2026-69441 | Microsoft | high 7.0 | Microsoft Windows Installer: race condition | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69441 2026-09-08 | CVE-2026-69442 CVE-2026-69442 | Microsoft | high 8.8 | Microsoft Office: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69442 2026-09-08 | CVE-2026-69443 CVE-2026-69443 | Microsoft | high 7.5 | Microsoft Windows: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69443 2026-09-08 | CVE-2026-69444 CVE-2026-69444 | Microsoft | high 7.8 | Microsoft Windows Speech: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69444 2026-09-08 | CVE-2026-69445 CVE-2026-69445 | Microsoft | high 7.8 | Microsoft Windows Compressed Folder: path traversal | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69445 2026-09-08 | CVE-2026-69432 CVE-2026-69432 | Microsoft | high 7.8 | Microsoft Volume Manager Driver: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69432 2026-09-08 | CVE-2026-69433 CVE-2026-69433 | Microsoft | high 7.8 | Microsoft Windows Error Reporting: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69433 2026-09-08 | CVE-2026-69434 CVE-2026-69434 | Microsoft | high 8.8 | Microsoft Windows URL Moniker: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69434 2026-09-08 | CVE-2026-69436 CVE-2026-69436 | Microsoft | high 7.8 | Microsoft Windows Error Reporting: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69436 2026-09-08 | CVE-2026-69438 CVE-2026-69438 | Microsoft | high 8.1 | Microsoft JScript: remote code execution | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69438 2026-09-08 | CVE-2026-69439 CVE-2026-69439 | Microsoft | high 8.8 | Microsoft .NET 10.0: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69439 2026-09-08 | CVE-2026-69426 CVE-2026-69426 | Microsoft | high 7.8 | Microsoft Windows VOLSNAP.SYS: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69426 2026-09-08 | CVE-2026-69427 CVE-2026-69427 | Microsoft | high 8.0 | Microsoft Windows VOLSNAP.SYS: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69427 2026-09-08 | CVE-2026-69428 CVE-2026-69428 | Microsoft | high 7.5 | Microsoft Windows: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69428 2026-09-08 | CVE-2026-69429 CVE-2026-69429 | Microsoft | high 7.5 | Microsoft Windows IKE Extension: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69429 2026-09-08 | CVE-2026-69430 CVE-2026-69430 | Microsoft | high 7.0 | Microsoft Windows Embedded Mode Service: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69430 2026-09-08 | CVE-2026-69431 CVE-2026-69431 | Microsoft | critical 9.8 | Microsoft Telnet Client: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69431 2026-09-08 | CVE-2026-69420 CVE-2026-69420 | Microsoft | high 7.8 | Microsoft Windows VOLSNAP.SYS: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69420 2026-09-08 | CVE-2026-69421 CVE-2026-69421 | Microsoft | high 7.8 | Microsoft Windows Kernel Mode Driver: integer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69421 2026-09-08 | CVE-2026-69422 CVE-2026-69422 | Microsoft | high 7.0 | Microsoft Windows USB Video Driver: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69422 2026-09-08 | CVE-2026-69423 CVE-2026-69423 | Microsoft | high 8.0 | Microsoft Windows USB Video Driver: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69423 2026-09-08 | CVE-2026-69424 CVE-2026-69424 | Microsoft | high 7.8 | Microsoft Windows: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69424 2026-09-08 | CVE-2026-69425 CVE-2026-69425 | Microsoft | medium 4.7 | Microsoft Windows NTFS: tampering | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69425 2026-09-08 | CVE-2026-69413 CVE-2026-69413 | Microsoft | high 7.0 | Microsoft Windows: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69413 2026-09-08 | CVE-2026-69415 CVE-2026-69415 | Microsoft | medium 6.8 | Microsoft Windows DHCP Server: missing authentication | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69415 2026-09-08 | CVE-2026-69416 CVE-2026-69416 | Microsoft | medium 5.7 | Buffer over-read in Windows DHCP Server | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69416 2026-09-08 | CVE-2026-69417 CVE-2026-69417 | Microsoft | high 7.3 | Microsoft SharePoint Server Subscription Edition: cross-site scripting | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69417 2026-09-08 | CVE-2026-69418 CVE-2026-69418 | Microsoft | high 8.0 | Microsoft Volume Manager Driver: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69418 2026-09-08 | CVE-2026-69405 CVE-2026-69405 | Microsoft | medium 5.7 | Microsoft Windows DHCP Server: memory leak | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69405 2026-09-08 | CVE-2026-69406 CVE-2026-69406 | Microsoft | medium 5.5 | Microsoft Windows Kernel: system information exposure | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69406 2026-09-08 | CVE-2026-69407 CVE-2026-69407 | Microsoft | high 7.8 | Microsoft Volume Manager Driver: integer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69407 2026-09-08 | CVE-2026-69408 CVE-2026-69408 | Microsoft | critical 9.8 | Microsoft Windows Media Foundation: integer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69408 2026-09-08 | CVE-2026-69409 CVE-2026-69409 | Microsoft | medium 6.5 | Microsoft SharePoint Server Subscription Edition: excessive privileges | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69409 2026-09-08 | CVE-2026-69410 CVE-2026-69410 | Microsoft | high 7.0 | Microsoft Windows Win32K: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69410 2026-09-08 | CVE-2026-69412 CVE-2026-69412 | Microsoft | high 8.0 | Microsoft Windows DHCP Server: stack buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69412 2026-09-08 | CVE-2026-69397 CVE-2026-69397 | Microsoft | high 7.5 | Microsoft OpenSSH for Windows: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69397 2026-09-08 | CVE-2026-69398 CVE-2026-69398 | Microsoft | high 7.0 | Microsoft Windows Bluetooth Service: race condition | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69398 2026-09-08 | CVE-2026-69401 CVE-2026-69401 | Microsoft | high 7.0 | Microsoft Audio Video Control Transport Protocol: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69401 2026-09-08 | CVE-2026-69402 CVE-2026-69402 | Microsoft | high 7.3 | Microsoft SharePoint Server Subscription Edition: cross-site scripting | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69402 2026-09-08 | CVE-2026-69403 CVE-2026-69403 | Microsoft | medium 5.5 | Microsoft Windows SMB Server: missing authorization | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69403 2026-09-08 | CVE-2026-69404 CVE-2026-69404 | Microsoft | high 7.0 | Microsoft Windows TCP/IP: race condition | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69404 2026-09-08 | CVE-2026-69391 CVE-2026-69391 | Microsoft | high 7.8 | Microsoft Windows Broker Infrastructure Service: stack buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69391 2026-09-08 | CVE-2026-69392 CVE-2026-69392 | Microsoft | high 7.8 | Microsoft Windows Shell: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69392 2026-09-08 | CVE-2026-69393 CVE-2026-69393 | Microsoft | medium 5.7 | Microsoft Windows Spaceport.sys: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69393 2026-09-08 | CVE-2026-69394 CVE-2026-69394 | Microsoft | high 7.0 | Microsoft Windows Audio Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69394 2026-09-08 | CVE-2026-69395 CVE-2026-69395 | Microsoft | medium 6.5 | Microsoft Windows: format string | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69395 2026-09-08 | CVE-2026-69396 CVE-2026-69396 | Microsoft | high 7.1 | Microsoft Windows NDIS: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69396 2026-09-08 | CVE-2026-69389 CVE-2026-69389 | Microsoft | high 7.8 | Microsoft Windows Storage Management Provider: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69389 2026-09-08 | CVE-2026-69390 CVE-2026-69390 | Microsoft | medium 5.5 | Microsoft Windows Spaceport.sys: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69390 2026-09-08 | CVE-2026-69382 CVE-2026-69382 | Microsoft | medium 5.9 | Microsoft Exchange Server: weak cryptography | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69382 2026-09-08 | CVE-2026-69383 CVE-2026-69383 | Microsoft | high 7.0 | Microsoft Windows Shell: privilege escalation | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69383 2026-09-08 | CVE-2026-69384 CVE-2026-69384 | Microsoft | high 7.1 | Microsoft Windows: null pointer dereference | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69384 2026-09-08 | CVE-2026-69385 CVE-2026-69385 | Microsoft | high 7.0 | Microsoft Windows TCP/IP: race condition | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69385 2026-09-08 | CVE-2026-69386 CVE-2026-69386 | Microsoft | high 8.8 | Microsoft Windows Media Foundation: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69386 2026-09-08 | CVE-2026-69388 CVE-2026-69388 | Microsoft | high 7.0 | Microsoft Windows Bluetooth Service: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69388 2026-09-08 | CVE-2026-69375 CVE-2026-69375 | Microsoft | medium 6.5 | Microsoft Exchange Server: tampering | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69375 2026-09-08 | CVE-2026-69376 CVE-2026-69376 | Microsoft | medium 5.5 | Microsoft Standard XPS: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69376 2026-09-08 | CVE-2026-69377 CVE-2026-69377 | Microsoft | high 7.8 | Microsoft Windows: missing authorization | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69377 2026-09-08 | CVE-2026-69378 CVE-2026-69378 | Microsoft | high 7.5 | Microsoft Exchange Server: uncontrolled recursion | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69378 2026-09-08 | CVE-2026-69379 CVE-2026-69379 | Microsoft | high 7.0 | Microsoft Windows NTFS: privilege escalation | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69379 2026-09-08 | CVE-2026-69380 CVE-2026-69380 | Microsoft | high 8.1 | Microsoft Exchange Server: missing authorization | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69380 2026-09-08 | CVE-2026-69381 CVE-2026-69381 | Microsoft | medium 4.6 | Microsoft Windows Storage Port Driver: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69381 2026-09-08 | CVE-2026-69368 CVE-2026-69368 | Microsoft | high 7.8 | Microsoft Windows Overlay Filter: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69368 2026-09-08 | CVE-2026-69369 CVE-2026-69369 | Microsoft | medium 5.5 | Microsoft Windows DNS: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69369 2026-09-08 | CVE-2026-69371 CVE-2026-69371 | Microsoft | high 8.0 | Microsoft Windows Overlay Filter: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69371 2026-09-08 | CVE-2026-69372 CVE-2026-69372 | Microsoft | medium 5.7 | Microsoft Windows Network File System: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69372 2026-09-08 | CVE-2026-69373 CVE-2026-69373 | Microsoft | medium 6.7 | Microsoft Windows Overlay Filter: integer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69373 2026-09-08 | CVE-2026-69374 CVE-2026-69374 | Microsoft | medium 6.5 | Microsoft Windows SMB Server: resource exhaustion | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69374 2026-09-08 | CVE-2026-69362 CVE-2026-69362 | Microsoft | high 7.0 | Microsoft Windows Error Reporting: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69362 2026-09-08 | CVE-2026-69364 CVE-2026-69364 | Microsoft | high 7.1 | Microsoft Windows Print Spooler Components: race condition | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69364 2026-09-08 | CVE-2026-69365 CVE-2026-69365 | Microsoft | high 8.0 | Microsoft Windows: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69365 2026-09-08 | CVE-2026-69366 CVE-2026-69366 | Microsoft | high 7.1 | Microsoft Windows Kernel: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69366 2026-09-08 | CVE-2026-69367 CVE-2026-69367 | Microsoft | medium 5.5 | Microsoft Standard XPS: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69367 2026-09-08 | CVE-2026-69356 CVE-2026-69356 | Microsoft | critical 9.3 | Microsoft Exchange Server: cross-site scripting | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69356 2026-09-08 | CVE-2026-69357 CVE-2026-69357 | Microsoft | high 7.1 | Microsoft Windows NDIS: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69357 2026-09-08 | CVE-2026-69358 CVE-2026-69358 | Microsoft | high 7.1 | Microsoft Remote Desktop Client: remote code execution | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69358 2026-09-08 | CVE-2026-69359 CVE-2026-69359 | Microsoft | high 7.8 | Microsoft Active Directory Domain Services: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69359 2026-09-08 | CVE-2026-69360 CVE-2026-69360 | Microsoft | high 8.8 | Microsoft Office Word: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69360 2026-09-08 | CVE-2026-69361 CVE-2026-69361 | Microsoft | medium 6.5 | Microsoft Exchange Server: server-side request forgery | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69361 2026-09-08 | CVE-2026-69350 CVE-2026-69350 | Microsoft | medium 6.7 | Microsoft Windows Overlay Filter: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69350 2026-09-08 | CVE-2026-69351 CVE-2026-69351 | Microsoft | medium 5.5 | Exposure of private personal information to an unauthorized actor in Windows... | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69351 2026-09-08 | CVE-2026-69352 CVE-2026-69352 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69352 2026-09-08 | CVE-2026-69353 CVE-2026-69353 | Microsoft | medium 5.5 | Microsoft Windows Text Shaping: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69353 2026-09-08 | CVE-2026-69355 CVE-2026-69355 | Microsoft | high 8.8 | Microsoft Exchange Server: remote code execution | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69355 2026-09-08 | CVE-2026-69344 CVE-2026-69344 | Microsoft | medium 5.5 | Microsoft Windows Print Spooler Components: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69344 2026-09-08 | CVE-2026-69345 CVE-2026-69345 | Microsoft | medium 5.5 | Microsoft Standard XPS: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69345 2026-09-08 | CVE-2026-69346 CVE-2026-69346 | Microsoft | high 8.0 | Microsoft Windows Print Spooler Components: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69346 2026-09-08 | CVE-2026-69347 CVE-2026-69347 | Microsoft | high 7.4 | Microsoft Windows Fast FAT Driver: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69347 2026-09-08 | CVE-2026-69348 CVE-2026-69348 | Microsoft | high 7.8 | Microsoft Windows Win32K: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69348 2026-09-08 | CVE-2026-69349 CVE-2026-69349 | Microsoft | medium 5.7 | Microsoft Windows Management Instrumentation: uninitialized resource | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69349 2026-09-08 | CVE-2026-69337 CVE-2026-69337 | Microsoft | high 7.1 | Microsoft Windows Registry: double free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69337 2026-09-08 | CVE-2026-69338 CVE-2026-69338 | Microsoft | high 7.1 | Microsoft Remote Desktop Gateway Service: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69338 2026-09-08 | CVE-2026-69339 CVE-2026-69339 | Microsoft | medium 5.5 | Microsoft Windows MIDI Service Module: system information exposure | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69339 2026-09-08 | CVE-2026-69340 CVE-2026-69340 | Microsoft | high 7.1 | Microsoft Windows NTFS: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69340 2026-09-08 | CVE-2026-69341 CVE-2026-69341 | Microsoft | high 7.0 | Microsoft Windows Image Acquisition: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69341 2026-09-08 | CVE-2026-69342 CVE-2026-69342 | Microsoft | high 7.5 | Microsoft Windows DHCP Server: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69342 2026-09-08 | CVE-2026-69343 CVE-2026-69343 | Microsoft | medium 5.5 | Microsoft Windows Overlay Filter: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69343 2026-09-08 | CVE-2026-69333 CVE-2026-69333 | Microsoft | high 7.0 | Microsoft Windows Win32K: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69333 2026-09-08 | CVE-2026-69334 CVE-2026-69334 | Microsoft | high 8.8 | Microsoft Windows Volume Manager Extension Driver: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69334 2026-09-08 | CVE-2026-69335 CVE-2026-69335 | Microsoft | high 7.0 | Microsoft Windows Win32K: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69335 2026-09-08 | CVE-2026-69336 CVE-2026-69336 | Microsoft | high 7.1 | Microsoft Standard XPS: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69336 2026-09-08 | CVE-2026-69324 CVE-2026-69324 | Microsoft | high 7.8 | Microsoft Windows Performance Monitor: type confusion | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69324 2026-09-08 | CVE-2026-69325 CVE-2026-69325 | Microsoft | high 8.1 | Microsoft JScript: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69325 2026-09-08 | CVE-2026-69328 CVE-2026-69328 | Microsoft | high 7.8 | Microsoft Windows Storage: untrusted search path | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69328 2026-09-08 | CVE-2026-69329 CVE-2026-69329 | Microsoft | high 7.5 | Microsoft BranchCache: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69329 2026-09-08 | CVE-2026-69331 CVE-2026-69331 | Microsoft | high 7.0 | Microsoft Windows Remote Access Connection Manager: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69331 2026-09-08 | CVE-2026-69332 CVE-2026-69332 | Microsoft | high 8.0 | Microsoft Windows NTFS: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69332 2026-09-08 | CVE-2026-69318 CVE-2026-69318 | Microsoft | medium 5.5 | Microsoft Windows Imaging Component: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69318 2026-09-08 | CVE-2026-69319 CVE-2026-69319 | Microsoft | high 7.0 | Microsoft Windows USB Video Driver: race condition | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69319 2026-09-08 | CVE-2026-69321 CVE-2026-69321 | Microsoft | medium 5.5 | Microsoft Windows Power Dependency Coordinator: missing authentication | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69321 2026-09-08 | CVE-2026-69322 CVE-2026-69322 | Microsoft | high 8.0 | Microsoft Windows Search Component: double free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69322 2026-09-08 | CVE-2026-69323 CVE-2026-69323 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69323 2026-09-08 | CVE-2026-69313 CVE-2026-69313 | Microsoft | high 7.1 | Microsoft Standard XPS: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69313 2026-09-08 | CVE-2026-69314 CVE-2026-69314 | Microsoft | high 7.1 | Microsoft Windows: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69314 2026-09-08 | CVE-2026-69315 CVE-2026-69315 | Microsoft | medium 5.5 | Microsoft Windows License Manager: system information exposure | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69315 2026-09-08 | CVE-2026-69316 CVE-2026-69316 | Microsoft | medium 4.7 | Buffer over-read in Windows Overlay Filter | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69316 2026-09-08 | CVE-2026-69317 CVE-2026-69317 | Microsoft | medium 5.7 | Microsoft Remote Desktop Client: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69317 2026-09-08 | CVE-2026-69308 CVE-2026-69308 | Microsoft | medium 5.5 | Microsoft Standard XPS: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69308 2026-09-08 | CVE-2026-69309 CVE-2026-69309 | Microsoft | high 7.0 | Microsoft Windows Print Spooler Components: double free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69309 2026-09-08 | CVE-2026-69310 CVE-2026-69310 | Microsoft | high 7.0 | Microsoft Windows DNS: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69310 2026-09-08 | CVE-2026-69311 CVE-2026-69311 | Microsoft | high 7.0 | Microsoft Windows Audio Service: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69311 2026-09-08 | CVE-2026-69312 CVE-2026-69312 | Microsoft | high 7.8 | Microsoft Windows NTFS: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69312 2026-09-08 | CVE-2026-69303 CVE-2026-69303 | Microsoft | medium 5.5 | Microsoft Push Message Routing Service: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69303 2026-09-08 | CVE-2026-69304 CVE-2026-69304 | Microsoft | medium 5.9 | Microsoft ASP.NET Core: unauthorized attacker could deny service over a network | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69304 2026-09-08 | CVE-2026-69305 CVE-2026-69305 | Microsoft | high 7.1 | Microsoft Windows Search Component: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69305 2026-09-08 | CVE-2026-69307 CVE-2026-69307 | Microsoft | high 7.8 | Microsoft Windows: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69307 2026-09-08 | CVE-2026-69296 CVE-2026-69296 | Microsoft | high 7.1 | Microsoft Windows Device Association Service: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69296 2026-09-08 | CVE-2026-69297 CVE-2026-69297 | Microsoft | medium 6.5 | Storing passwords in a recoverable format in Windows DHCP Server | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69297 2026-09-08 | CVE-2026-69298 CVE-2026-69298 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: integer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69298 2026-09-08 | CVE-2026-69299 CVE-2026-69299 | Microsoft | high 7.0 | Microsoft COM for Windows: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69299 2026-09-08 | CVE-2026-69300 CVE-2026-69300 | Microsoft | high 7.0 | Microsoft Windows Push Notifications: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69300 2026-09-08 | CVE-2026-69301 CVE-2026-69301 | Microsoft | high 8.0 | Microsoft Windows Win32K: stack buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69301 2026-09-08 | CVE-2026-69290 CVE-2026-69290 | Microsoft | high 7.8 | Microsoft Windows Storage Spaces Controller: stack buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69290 2026-09-08 | CVE-2026-69291 CVE-2026-69291 | Microsoft | high 8.8 | Microsoft Windows Volume Manager Extension Driver: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69291 2026-09-08 | CVE-2026-69292 CVE-2026-69292 | Microsoft | high 7.0 | Microsoft Remote Desktop Gateway Service: double free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69292 2026-09-08 | CVE-2026-69293 CVE-2026-69293 | Microsoft | high 7.8 | Microsoft Windows Biometric Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69293 2026-09-08 | CVE-2026-69294 CVE-2026-69294 | Microsoft | medium 5.5 | Microsoft COM for Windows: information disclosure | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69294 2026-09-08 | CVE-2026-69295 CVE-2026-69295 | Microsoft | high 7.8 | Microsoft Windows USB Driver: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69295 2026-09-08 | CVE-2026-69284 CVE-2026-69284 | Microsoft | high 7.8 | Microsoft Windows DCOM Server: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69284 2026-09-08 | CVE-2026-69285 CVE-2026-69285 | Microsoft | high 8.8 | Microsoft Office: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69285 2026-09-08 | CVE-2026-69286 CVE-2026-69286 | Microsoft | medium 5.5 | Microsoft Windows: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69286 2026-09-08 | CVE-2026-69287 CVE-2026-69287 | Microsoft | high 7.0 | Microsoft Windows Remote Desktop Services: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69287 2026-09-08 | CVE-2026-69288 CVE-2026-69288 | Microsoft | medium 5.5 | Microsoft Windows GDI+: uninitialized resource | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69288 2026-09-08 | CVE-2026-69289 CVE-2026-69289 | Microsoft | high 7.8 | Microsoft Windows Setup Files Cleanup: privilege escalation | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69289 2026-09-08 | CVE-2026-69279 CVE-2026-69279 | Microsoft | high 7.0 | Microsoft Windows Cloud Files Mini Filter Driver: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69279 2026-09-08 | CVE-2026-69280 CVE-2026-69280 | Microsoft | high 7.0 | Microsoft Windows Push Notifications: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69280 2026-09-08 | CVE-2026-69281 CVE-2026-69281 | Microsoft | high 7.0 | Microsoft Windows License Manager: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69281 2026-09-08 | CVE-2026-69282 CVE-2026-69282 | Microsoft | high 8.8 | Microsoft SharePoint Server Subscription Edition: improper access control | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69282 2026-09-08 | CVE-2026-69283 CVE-2026-69283 | Microsoft | high 7.8 | Microsoft Windows CD-ROM Driver: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69283 2026-09-08 | CVE-2026-69276 CVE-2026-69276 | Microsoft | critical 9.8 | Microsoft Windows: integer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69276 2026-09-08 | CVE-2026-69277 CVE-2026-69277 | Microsoft | high 7.8 | Microsoft Windows: stack buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69277 2026-09-08 | CVE-2026-69273 CVE-2026-69273 | Microsoft | high 8.8 | Microsoft SharePoint Server Subscription Edition: improper access control | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69273 2026-09-08 | CVE-2026-69274 CVE-2026-69274 | Microsoft | high 7.1 | Microsoft Windows Win32K: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69274 2026-09-08 | CVE-2026-69275 CVE-2026-69275 | Microsoft | high 7.0 | Microsoft Kernel Streaming WOW Thunk Service Driver: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69275 2026-09-08 | CVE-2026-69268 CVE-2026-69268 | Microsoft | high 8.8 | Microsoft SharePoint Server Subscription Edition: improper access control | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69268 2026-09-08 | CVE-2026-69269 CVE-2026-69269 | Microsoft | high 7.8 | Microsoft Standard XPS: integer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69269 2026-09-08 | CVE-2026-69270 CVE-2026-69270 | Microsoft | high 7.8 | Microsoft Windows: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69270 2026-09-08 | CVE-2026-69271 CVE-2026-69271 | Microsoft | high 8.0 | Microsoft Standard XPS: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69271 2026-09-08 | CVE-2026-69272 CVE-2026-69272 | Microsoft | high 7.1 | Microsoft Standard XPS: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69272 2026-09-08 | CVE-2026-68896 CVE-2026-68896 | Microsoft | high 7.8 | Microsoft Windows Search Component: path traversal | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68896 2026-09-08 | CVE-2026-68897 CVE-2026-68897 | Microsoft | high 7.0 | Microsoft Standard XPS: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68897 2026-09-08 | CVE-2026-68898 CVE-2026-68898 | Microsoft | medium 6.5 | Microsoft Windows: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68898 2026-09-08 | CVE-2026-69265 CVE-2026-69265 | Microsoft | high 7.8 | Microsoft Windows NTFS: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69265 2026-09-08 | CVE-2026-69266 CVE-2026-69266 | Microsoft | high 8.8 | Microsoft Windows DHCP Server: integer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69266 2026-09-08 | CVE-2026-69267 CVE-2026-69267 | Microsoft | medium 6.5 | Microsoft Windows Connected User Experiences: improper access control | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69267 2026-09-08 | CVE-2026-68891 CVE-2026-68891 | Microsoft | medium 4.7 | Microsoft Standard XPS: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68891 2026-09-08 | CVE-2026-68892 CVE-2026-68892 | Microsoft | high 7.8 | Microsoft Standard XPS: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68892 2026-09-08 | CVE-2026-68893 CVE-2026-68893 | Microsoft | high 7.1 | Microsoft Windows Remote Desktop Licensing Service: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68893 2026-09-08 | CVE-2026-68894 CVE-2026-68894 | Microsoft | high 8.0 | Microsoft Windows Error Reporting: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68894 2026-09-08 | CVE-2026-68895 CVE-2026-68895 | Microsoft | medium 5.5 | Numeric truncation error in Internet Storage Name Service | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68895 2026-09-08 | CVE-2026-68887 CVE-2026-68887 | Microsoft | high 7.5 | Microsoft Windows Message Queuing Queue Manager: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68887 2026-09-08 | CVE-2026-68888 CVE-2026-68888 | Microsoft | high 7.8 | Microsoft Standard XPS: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68888 2026-09-08 | CVE-2026-68889 CVE-2026-68889 | Microsoft | high 7.1 | Microsoft Standard XPS: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68889 2026-09-08 | CVE-2026-68890 CVE-2026-68890 | Microsoft | high 7.8 | Microsoft Standard XPS: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68890 2026-09-08 | CVE-2026-68878 CVE-2026-68878 | Microsoft | high 8.0 | Microsoft Windows Fast FAT Driver: stack buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68878 2026-09-08 | CVE-2026-68880 CVE-2026-68880 | Microsoft | high 8.0 | Microsoft Windows Win32K: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68880 2026-09-08 | CVE-2026-68881 CVE-2026-68881 | Microsoft | medium 5.5 | Microsoft Standard XPS: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68881 2026-09-08 | CVE-2026-68884 CVE-2026-68884 | Microsoft | high 7.0 | Microsoft Windows Kernel: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68884 2026-09-08 | CVE-2026-68885 CVE-2026-68885 | Microsoft | high 7.8 | Microsoft Standard XPS: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68885 2026-09-08 | CVE-2026-68886 CVE-2026-68886 | Microsoft | medium 5.5 | Microsoft Windows Network Connection Broker: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68886 2026-09-08 | CVE-2026-68852 CVE-2026-68852 | Microsoft | medium 5.5 | Microsoft Account: information disclosure | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68852 2026-09-08 | CVE-2026-68873 CVE-2026-68873 | Microsoft | medium 5.5 | Microsoft Windows Program Compatibility: information disclosure | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68873 2026-09-08 | CVE-2026-68874 CVE-2026-68874 | Microsoft | medium 5.7 | Microsoft Windows Program Compatibility Assistant Service: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68874 2026-09-08 | CVE-2026-68875 CVE-2026-68875 | Microsoft | high 7.8 | Microsoft Windows NTFS: code execution | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68875 2026-09-08 | CVE-2026-68876 CVE-2026-68876 | Microsoft | high 8.0 | Microsoft Windows Program Compatibility Assistant Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68876 2026-09-08 | CVE-2026-68877 CVE-2026-68877 | Microsoft | high 7.8 | Microsoft Windows Storage Spaces Controller: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68877 2026-09-08 | CVE-2026-68847 CVE-2026-68847 | Microsoft | high 7.0 | Microsoft Windows Connected User Experiences: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68847 2026-09-08 | CVE-2026-68848 CVE-2026-68848 | Microsoft | high 7.8 | Microsoft Windows Print Spooler Components: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68848 2026-09-08 | CVE-2026-68849 CVE-2026-68849 | Microsoft | medium 4.7 | Microsoft Windows Bluetooth Port Driver: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68849 2026-09-08 | CVE-2026-68850 CVE-2026-68850 | Microsoft | high 7.8 | Microsoft Account: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68850 2026-09-08 | CVE-2026-68851 CVE-2026-68851 | Microsoft | medium 5.5 | Buffer over-read in Windows NTFS | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68851 2026-09-08 | CVE-2026-68842 CVE-2026-68842 | Microsoft | medium 5.5 | Microsoft Windows MIDI Service Module: system information exposure | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68842 2026-09-08 | CVE-2026-68843 CVE-2026-68843 | Microsoft | medium 5.5 | Microsoft Office Word: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68843 2026-09-08 | CVE-2026-68844 CVE-2026-68844 | Microsoft | high 7.8 | Microsoft Windows Storage Spaces Controller: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68844 2026-09-08 | CVE-2026-68845 CVE-2026-68845 | Microsoft | high 7.8 | Microsoft Windows Program Compatibility Assistant Service: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68845 2026-09-08 | CVE-2026-68846 CVE-2026-68846 | Microsoft | high 7.1 | Microsoft Windows Kernel: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68846 2026-09-08 | CVE-2026-68835 CVE-2026-68835 | Microsoft | high 7.1 | Microsoft Windows Print Spooler Components: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68835 2026-09-08 | CVE-2026-68837 CVE-2026-68837 | Microsoft | high 7.0 | Microsoft Windows File History Service: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68837 2026-09-08 | CVE-2026-68838 CVE-2026-68838 | Microsoft | high 8.0 | Microsoft Windows NTFS: stack buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68838 2026-09-08 | CVE-2026-68839 CVE-2026-68839 | Microsoft | critical 9.8 | Microsoft Windows USB Mass Storage Class Driver: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68839 2026-09-08 | CVE-2026-68840 CVE-2026-68840 | Microsoft | high 7.0 | Microsoft Windows USB Driver: race condition | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68840 2026-09-08 | CVE-2026-68841 CVE-2026-68841 | Microsoft | high 7.8 | Microsoft Windows NTFS: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68841 2026-09-08 | CVE-2026-68831 CVE-2026-68831 | Microsoft | medium 5.5 | Microsoft Windows Defender Firewall Service: exposed files | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68831 2026-09-08 | CVE-2026-68832 CVE-2026-68832 | Microsoft | high 7.8 | Microsoft Windows NTFS: integer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68832 2026-09-08 | CVE-2026-68833 CVE-2026-68833 | Microsoft | medium 6.8 | Microsoft Windows NTFS: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68833 2026-09-08 | CVE-2026-68834 CVE-2026-68834 | Microsoft | high 8.0 | Microsoft Windows NTFS: stack buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68834 2026-09-08 | CVE-2026-68824 CVE-2026-68824 | Microsoft | high 7.0 | Microsoft Windows Connected User Experiences: race condition | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68824 2026-09-08 | CVE-2026-68825 CVE-2026-68825 | Microsoft | high 7.0 | Microsoft Windows Bind Filter Driver: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68825 2026-09-08 | CVE-2026-68827 CVE-2026-68827 | Microsoft | high 8.0 | Microsoft Windows GDI+: integer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68827 2026-09-08 | CVE-2026-68828 CVE-2026-68828 | Microsoft | high 8.8 | Microsoft Remote Desktop Client: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68828 2026-09-08 | CVE-2026-68830 CVE-2026-68830 | Microsoft | medium 5.5 | Microsoft Windows: link following | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68830 2026-09-08 | CVE-2026-68785 CVE-2026-68785 | Microsoft | medium 4.9 | Microsoft SQL Server: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68785 2026-09-08 | CVE-2026-68786 CVE-2026-68786 | Microsoft | high 8.8 | Microsoft SQL Server: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68786 2026-09-08 | CVE-2026-68787 CVE-2026-68787 | Microsoft | high 7.8 | Microsoft SQL Server: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68787 2026-09-08 | CVE-2026-68776 CVE-2026-68776 | Microsoft | medium 6.5 | Microsoft SQL Server: uninitialized resource | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68776 2026-09-08 | CVE-2026-68777 CVE-2026-68777 | Microsoft | medium 6.5 | Microsoft SQL Server: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68777 2026-09-08 | CVE-2026-68778 CVE-2026-68778 | Microsoft | medium 6.5 | Microsoft SQL Server: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68778 2026-09-08 | CVE-2026-68779 CVE-2026-68779 | Microsoft | medium 6.5 | Microsoft SQL Server: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68779 2026-09-08 | CVE-2026-68780 CVE-2026-68780 | Microsoft | medium 6.5 | Microsoft SQL Server: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68780 2026-09-08 | CVE-2026-68781 CVE-2026-68781 | Microsoft | medium 6.5 | Microsoft SQL Server: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68781 2026-09-08 | CVE-2026-68784 CVE-2026-68784 | Microsoft | medium 6.5 | Microsoft SQL Server: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68784 2026-09-08 | CVE-2026-67638 CVE-2026-67638 | Microsoft | high 8.8 | Microsoft SQL Server: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-67638 2026-09-08 | CVE-2026-67639 CVE-2026-67639 | Microsoft | high 8.8 | Microsoft SQL Server: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-67639 2026-09-08 | CVE-2026-67641 CVE-2026-67641 | Microsoft | medium 6.5 | Microsoft SQL Server: integer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-67641 2026-09-08 | CVE-2026-67642 CVE-2026-67642 | Microsoft | high 8.8 | Microsoft SQL Server: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-67642 2026-09-08 | CVE-2026-67643 CVE-2026-67643 | Microsoft | critical 9.8 | Microsoft SQL Server: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-67643 2026-09-08 | CVE-2026-67645 CVE-2026-67645 | Microsoft | medium 6.5 | Microsoft SQL Server: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-67645 2026-09-08 | CVE-2026-67648 CVE-2026-67648 | Microsoft | medium 6.5 | Microsoft SQL Server: uninitialized resource | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-67648 2026-09-08 | CVE-2026-68775 CVE-2026-68775 | Microsoft | high 8.8 | Microsoft SQL Server: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68775 2026-09-08 | CVE-2026-67624 CVE-2026-67624 | Microsoft | medium 6.5 | Microsoft SQL Server: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-67624 2026-09-08 | CVE-2026-67629 CVE-2026-67629 | Microsoft | medium 6.5 | Microsoft SQL Server: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-67629 2026-09-08 | CVE-2026-67630 CVE-2026-67630 | Microsoft | medium 6.5 | Microsoft SQL Server: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-67630 2026-09-08 | CVE-2026-67631 CVE-2026-67631 | Microsoft | critical 9.8 | Microsoft SQL Server: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-67631 2026-09-08 | CVE-2026-67633 CVE-2026-67633 | Microsoft | medium 6.5 | Microsoft SQL Server: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-67633 2026-09-08 | CVE-2026-67636 CVE-2026-67636 | Microsoft | critical 9.0 | Microsoft SQL Server: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-67636 2026-09-08 | CVE-2026-67385 CVE-2026-67385 | Microsoft | high 8.8 | Microsoft SQL Server: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-67385 2026-09-08 | CVE-2026-67386 CVE-2026-67386 | Microsoft | medium 6.5 | Microsoft SQL Server: uninitialized resource | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-67386 2026-09-08 | CVE-2026-67388 CVE-2026-67388 | Microsoft | high 8.8 | Microsoft SQL Server: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-67388 2026-09-08 | CVE-2026-67389 CVE-2026-67389 | Microsoft | medium 6.5 | Microsoft SQL Server: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-67389 2026-09-08 | CVE-2026-67390 CVE-2026-67390 | Microsoft | medium 6.5 | Buffer over-read in SQL Server | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-67390 2026-09-08 | CVE-2026-67393 CVE-2026-67393 | Microsoft | medium 6.5 | Buffer over-read in SQL Server | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-67393 2026-09-08 | CVE-2026-67376 CVE-2026-67376 | Microsoft | high 7.5 | Microsoft SQL Server: integer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-67376 2026-09-08 | CVE-2026-67378 CVE-2026-67378 | Microsoft | critical 9.0 | Microsoft SQL Server: remote code execution | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-67378 2026-09-08 | CVE-2026-67379 CVE-2026-67379 | Microsoft | high 8.5 | Microsoft SQL Server: stack buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-67379 2026-09-08 | CVE-2026-67380 CVE-2026-67380 | Microsoft | high 8.8 | Microsoft SQL Server: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-67380 2026-09-08 | CVE-2026-67381 CVE-2026-67381 | Microsoft | high 8.8 | Microsoft SQL Server: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-67381 2026-09-08 | CVE-2026-67383 CVE-2026-67383 | Microsoft | medium 6.5 | Microsoft SQL Server: information disclosure | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-67383 2026-09-08 | CVE-2026-67384 CVE-2026-67384 | Microsoft | high 8.8 | Microsoft SQL Server: integer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-67384 2026-09-08 | CVE-2026-66816 CVE-2026-66816 | Microsoft | medium 6.5 | Insufficient logging in SQL Server | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66816 2026-09-08 | CVE-2026-66818 CVE-2026-66818 | Microsoft | high 8.8 | Microsoft SQL Server: privilege escalation | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66818 2026-09-08 | CVE-2026-66819 CVE-2026-66819 | Microsoft | high 8.8 | Microsoft SQL Server: SQL injection | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66819 2026-09-08 | CVE-2026-66820 CVE-2026-66820 | Microsoft | high 8.8 | Microsoft SQL Server: SQL injection | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66820 2026-09-08 | CVE-2026-67368 CVE-2026-67368 | Microsoft | high 8.8 | Microsoft SQL Server: privilege escalation | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-67368 2026-09-08 | CVE-2026-67369 CVE-2026-67369 | Microsoft | medium 6.5 | Microsoft SQL Server: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-67369 2026-09-08 | CVE-2026-67370 CVE-2026-67370 | Microsoft | high 8.8 | Microsoft SQL Server: SQL injection | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-67370 2026-09-08 | CVE-2026-67373 CVE-2026-67373 | Microsoft | high 8.8 | Microsoft SQL Server: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-67373 2026-09-08 | CVE-2026-66814 CVE-2026-66814 | Microsoft | high 8.8 | Microsoft SQL Server: improper access control | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66814 2026-09-08 | CVE-2026-65812 CVE-2026-65812 | Microsoft | medium 6.8 | Microsoft Teams for Android: information disclosure | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65812 2026-09-08 | CVE-2026-65772 CVE-2026-65772 | Microsoft | high 8.8 | Microsoft Dynamics 365 (on-premises) version 9.1: unsafe deserialization | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65772 2026-09-08 | CVE-2026-65669 CVE-2026-65669 | Microsoft | critical 9.6 | Microsoft SQL Server Management Studio 22: privilege escalation | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65669 2026-09-08 | CVE-2026-64918 CVE-2026-64918 | Microsoft | medium 6.5 | Microsoft Office: spoofing | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-64918 2026-09-08 | CVE-2026-62895 CVE-2026-62895 | Microsoft | high 8.8 | Microsoft Azure Arc SQL Server Extension: privilege escalation | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62895 2026-09-08 | CVE-2026-62804 CVE-2026-62804 | Microsoft | high 7.8 | Microsoft Office Word: code execution | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62804 2026-09-08 | CVE-2026-62810 CVE-2026-62810 | Microsoft | high 7.8 | Microsoft Windows: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62810 2026-09-08 | CVE-2026-62813 CVE-2026-62813 | Microsoft | high 7.5 | Microsoft Active Directory Domain Services: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62813 2026-09-08 | CVE-2026-62801 CVE-2026-62801 | Microsoft | medium 6.5 | Microsoft Windows PowerShell: path traversal | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62801 2026-09-08 | CVE-2026-62762 CVE-2026-62762 | Microsoft | medium 6.5 | Microsoft Active Directory Domain Services: null pointer dereference | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62762 2026-09-08 | CVE-2026-62759 CVE-2026-62759 | Microsoft | high 7.5 | Microsoft Windows Netlogon: authentication bypass | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62759 2026-09-08 | CVE-2026-62744 CVE-2026-62744 | Microsoft | high 8.8 | Microsoft Windows Media Foundation: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62744 2026-09-08 | CVE-2026-62706 CVE-2026-62706 | Microsoft | high 8.8 | Microsoft Windows Media Foundation: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62706 2026-09-08 | CVE-2026-62694 CVE-2026-62694 | Microsoft | high 7.0 | Microsoft Windows Installer: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62694 2026-09-08 | CVE-2026-62697 CVE-2026-62697 | Microsoft | high 7.8 | Microsoft Windows Push Notifications: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62697 2026-09-08 | CVE-2026-58611 CVE-2026-58611 | Microsoft | high 7.8 | Microsoft Xbox Gaming Services: improper authorization | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58611 2026-09-08 | CVE-2026-58649 CVE-2026-58649 | Microsoft | medium 6.5 | Microsoft .NET 10.0: origin validation error | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58649 2026-09-08 | CVE-2026-57099 CVE-2026-57099 | Microsoft | high 7.5 | Microsoft AspNetCore.OData: resource exhaustion | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57099 2026-09-08 | CVE-2026-58599 CVE-2026-58599 | Microsoft | high 7.8 | Microsoft Windows Codecs Library: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58599 2026-09-08 | CVE-2026-58600 CVE-2026-58600 | Microsoft | high 7.8 | Microsoft Windows Codecs Library: heap buffer overflow | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58600 2026-09-08 | CVE-2026-56172 CVE-2026-56172 | Microsoft | high 7.8 | Microsoft Windows: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56172 2026-09-08 | CVE-2026-56177 CVE-2026-56177 | Microsoft | high 7.8 | Microsoft Windows Server: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56177 2026-09-08 | CVE-2026-56198 CVE-2026-56198 | Microsoft | high 7.8 | Microsoft Trace Data Helper: out-of-bounds read | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56198 2026-09-08 | CVE-2026-57098 CVE-2026-57098 | Microsoft | high 7.5 | Microsoft Remote Desktop client for Windows Desktop: improper signature check | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57098 2026-09-08 | CVE-2026-55007 CVE-2026-55007 | Microsoft | high 8.1 | Microsoft Exchange Server: double free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55007 2026-09-08 | CVE-2026-50349 CVE-2026-50349 | Microsoft | high 7.0 | Microsoft Windows Ancillary Function Driver for WinSock: race condition | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50349 2026-09-08 | CVE-2026-47297 CVE-2026-47297 | Microsoft | high 8.1 | Microsoft SQL Server: unsafe deserialization | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47297 2026-09-08 | GHSA-2mjm-fqwf-jq98 CVE-2026-81356 | Microsoft | high 8.2 | Trusted URL Validation Security Feature Bypass | https://github.com/microsoft/vscode/security/advisories/GHSA-2mjm-fqwf-jq98 2026-09-08 | CVE-2026-84385 CVE-2026-84385 | Fortinet | medium 5.4 | Fortinet FortiSOAR PaaS: improper access control | https://fortiguard.fortinet.com/psirt/FG-IR-26-164 2026-09-08 | CVE-2026-84386 CVE-2026-84386 | Fortinet | medium 5.1 | Fortinet FortiClientWindows: improper access control | https://fortiguard.fortinet.com/psirt/FG-IR-26-165 2026-09-08 | CVE-2026-84387 CVE-2026-84387 | Fortinet | high 7.2 | Fortinet FortiSandbox: command injection | https://fortiguard.fortinet.com/psirt/FG-IR-26-167 2026-09-08 | CVE-2026-84389 CVE-2026-84389 | Fortinet | low 3.1 | Fortinet FortiSIEM: open redirect | https://fortiguard.fortinet.com/psirt/FG-IR-26-169 2026-09-08 | CVE-2026-84391 CVE-2026-84391 | Fortinet | medium 6.5 | Fortinet FortiAnalyzer: denial of service | https://fortiguard.fortinet.com/psirt/FG-IR-26-172 2026-09-08 | CVE-2026-84392 CVE-2026-84392 | Fortinet | low 2.7 | Fortinet FortiOS: null pointer dereference | https://fortiguard.fortinet.com/psirt/FG-IR-26-173 2026-09-08 | CVE-2026-84393 CVE-2026-84393 | Fortinet | high 8.1 | Fortinet FortiOS: information disclosure | https://fortiguard.fortinet.com/psirt/FG-IR-26-174 2026-09-08 | CVE-2026-82070 CVE-2026-82070 | MongoDB | high 7.1 | MongoDB Server: weakly protected credentials | https://jira.mongodb.org/browse/SERVER-131423 2026-09-08 | CVE-2026-82071 CVE-2026-82071 | MongoDB | high 7.2 | MongoDB Server: denial of service | https://jira.mongodb.org/browse/SERVER-131860 2026-09-08 | CVE-2026-82073 CVE-2026-82073 | MongoDB | high 7.1 | MongoDB Server: improper authorization | https://jira.mongodb.org/browse/SERVER-132125 2026-09-08 | CVE-2026-82074 CVE-2026-82074 | MongoDB | high 7.1 | MongoDB Server: improper authorization | https://jira.mongodb.org/browse/SERVER-132275 2026-09-08 | CVE-2026-82075 CVE-2026-82075 | MongoDB | high 8.7 | MongoDB Server: resource exhaustion | https://jira.mongodb.org/browse/SERVER-132650 2026-09-08 | CVE-2026-82076 CVE-2026-82076 | MongoDB | high 7.1 | MongoDB Server: integer overflow | https://jira.mongodb.org/browse/SERVER-128253 2026-09-08 | CVE-2026-82063 CVE-2026-82063 | MongoDB | medium 6.0 | MongoDB Server: use after free | https://jira.mongodb.org/browse/SERVER-131870 2026-09-08 | CVE-2026-82064 CVE-2026-82064 | MongoDB | high 8.7 | MongoDB Server: denial of service | https://jira.mongodb.org/browse/SERVER-130759 2026-09-08 | CVE-2026-82065 CVE-2026-82065 | MongoDB | high 7.1 | MongoDB Server: denial of service | https://jira.mongodb.org/browse/SERVER-131420 2026-09-08 | CVE-2026-82066 CVE-2026-82066 | MongoDB | medium 5.3 | MongoDB Server: out-of-bounds read | https://jira.mongodb.org/browse/SERVER-131562 2026-09-08 | CVE-2026-82067 CVE-2026-82067 | MongoDB | critical 9.2 | Improper handling of case sensitivity in the configuration validation component... | https://jira.mongodb.org/browse/SERVER-131229 2026-09-08 | CVE-2026-82068 CVE-2026-82068 | MongoDB | high 7.1 | MongoDB Server: reachable assertion | https://jira.mongodb.org/browse/SERVER-131326 2026-09-08 | CVE-2026-82069 CVE-2026-82069 | MongoDB | medium 5.1 | MongoDB Server: user could access unredacted search query text | https://jira.mongodb.org/browse/SERVER-132835 2026-09-08 | CVE-2026-82057 CVE-2026-82057 | MongoDB | high 7.1 | MongoDB Server: type confusion | https://jira.mongodb.org/browse/SERVER-130495 2026-09-08 | CVE-2026-82058 CVE-2026-82058 | MongoDB | high 7.1 | MongoDB Server: authenticated user could crash the mongod server | https://jira.mongodb.org/browse/SERVER-130926 2026-09-08 | CVE-2026-82059 CVE-2026-82059 | MongoDB | medium 6.0 | MongoDB Server: denial of service | https://jira.mongodb.org/browse/SERVER-130571 2026-09-08 | CVE-2026-82060 CVE-2026-82060 | MongoDB | low 2.3 | MongoDB Server: authenticated user could store documents with specially | https://jira.mongodb.org/browse/SERVER-131202 2026-09-08 | CVE-2026-82061 CVE-2026-82061 | MongoDB | high 7.2 | MongoDB Server: use after free | https://jira.mongodb.org/browse/SERVER-130907 2026-09-08 | CVE-2026-82062 CVE-2026-82062 | MongoDB | high 7.0 | MongoDB Server: improper authorization | https://jira.mongodb.org/browse/SERVER-131138 2026-09-08 | CVE-2026-82053 CVE-2026-82053 | MongoDB | high 7.6 | MongoDB Server: improper access control | https://jira.mongodb.org/browse/SERVER-130785 2026-09-08 | CVE-2026-82054 CVE-2026-82054 | MongoDB | high 7.1 | MongoDB Server: resource exhaustion | https://jira.mongodb.org/browse/SERVER-130901 2026-09-08 | CVE-2026-82055 CVE-2026-82055 | MongoDB | high 7.1 | MongoDB Server: null pointer dereference | https://jira.mongodb.org/browse/SERVER-130202 2026-09-08 | CVE-2026-82056 CVE-2026-82056 | MongoDB | medium 6.0 | MongoDB Server: race condition | https://jira.mongodb.org/browse/SERVER-130306 2026-09-08 | CVE-2026-82052 CVE-2026-82052 | MongoDB | high 7.1 | MongoDB Server: reachable assertion | https://jira.mongodb.org/browse/SERVER-127985 2026-09-08 | CVE-2026-47625 CVE-2026-47625 | Nvidia | high 7.5 | Nvidia Triton Inference Server: missing authorization | https://github.com/NVIDIA/product-security/tree/main/2026/5875 2026-09-08 | CVE-2026-20293 CVE-2026-20293 | Cisco | high 7.1 | A vulnerability in the Unified Extensible Firmware Interface | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ucs-uefi-sb-bypass-eb6xC5GW 2026-09-08 | CVE-2026-22575 CVE-2026-22575 | Fortinet | medium 4.9 | Fortinet FortiManager: improper access control | https://fortiguard.fortinet.com/psirt/FG-IR-26-171 2026-09-08 | CVE-2026-26084 CVE-2026-26084 | Fortinet | critical 9.9 | Fortinet FortiSandbox: improper access control | https://fortiguard.fortinet.com/psirt/FG-IR-26-166 2026-09-08 | CVE-2026-16497 CVE-2026-16497 | Nvidia | high 7.5 | Nvidia Triton Inference Server: denial of service | https://github.com/NVIDIA/product-security/tree/main/2026/5875 2026-09-08 | CVE-2026-9034 CVE-2026-9034 | Arm | high 7.8 | Arm 5th Gen GPU Architecture Userspace Driver: use after free | https://support.arm.com/documentation/111552/1-0/?lang=en 2026-09-08 | CVE-2026-9040 CVE-2026-9040 | Arm | high 7.7 | Arm 5th Gen GPU Architecture Kernel Driver: race condition | https://support.arm.com/documentation/111552/1-0/?lang=en 2026-09-08 | CVE-2026-86135 CVE-2026-86135 | WatchGuard Technologies | high 7.0 | WatchGuard Technologies Dimension: cross-site request forgery | https://psirt.watchguard.com/CVE-2026-86135 2026-09-08 | CVE-2026-7476 CVE-2026-7476 | Arm | high 7.8 | Arm 5th Gen GPU Architecture Kernel Driver: use after free | https://support.arm.com/documentation/111552/1-0/?lang=en 2026-09-08 | CVE-2026-7477 CVE-2026-7477 | Arm | high 7.8 | Arm 5th Gen GPU Architecture Kernel Driver: use after free | https://support.arm.com/documentation/111552/1-0/?lang=en 2026-09-08 | CVE-2026-5729 CVE-2026-5729 | Arm | high 7.8 | Arm 5th Gen GPU Architecture Kernel Driver: use after free | https://support.arm.com/documentation/111552/1-0/?lang=en 2026-09-08 | CVE-2026-11891 CVE-2026-11891 | Arm | medium 5.1 | Arm 5th Gen GPU Architecture Userspace Driver: use after free | https://support.arm.com/documentation/111552/1-0/?lang=en 2026-09-08 | CVE-2026-12285 CVE-2026-12285 | Arm | medium 4.0 | Arm 5th Gen GPU Architecture Kernel Driver: use after free | https://support.arm.com/documentation/111552/1-0/?lang=en 2026-09-08 | CVE-2026-12387 CVE-2026-12387 | Arm | medium 5.1 | Arm 5th Gen GPU Architecture Kernel Driver: use after free | https://support.arm.com/documentation/111552/1-0/?lang=en 2026-09-08 | CVE-2026-0001 CVE-2026-0001 | Arm | medium 4.4 | Arm 5th Gen GPU Architecture Kernel Driver: use after free | https://support.arm.com/documentation/111552/1-0/?lang=en 2026-09-08 | CVE-2026-0860 CVE-2026-0860 | Arm | high 7.5 | Arm 5th Gen GPU Architecture Kernel Driver: information disclosure | https://support.arm.com/documentation/111552/1-0/?lang=en 2026-09-08 | CVE-2026-33387 CVE-2026-33387 | Nozomi Networks | medium 5.1 | Nozomi Networks Dashboards functionality: template injection | https://security.nozominetworks.com/NN-2026:16-01 2026-09-08 | CVE-2026-33388 CVE-2026-33388 | Nozomi Networks | medium 6.4 | Nozomi Networks Credentials Manager functionality: improper access control | https://security.nozominetworks.com/NN-2026:19-01 2026-09-08 | CVE-2026-33389 CVE-2026-33389 | Nozomi Networks | medium 5.3 | Nozomi Networks Smart Polling functionality: attacker could access | https://security.nozominetworks.com/NN-2026:20-01 2026-09-08 | CVE-2026-33391 CVE-2026-33391 | Nozomi Networks | medium 5.3 | Nozomi Networks Smart Polling: improper access control | https://security.nozominetworks.com/NN-2026:17-01 2026-09-08 | CVE-2026-33920 CVE-2026-33920 | Nozomi Networks | medium 5.1 | Nozomi Networks CMC: cross-site request forgery | https://security.nozominetworks.com/NN-2026:18-01 2026-09-08 | CVE-2026-77103 CVE-2026-77103 | CommVault Systems | high 8.7 | Commvault Cloud: authentication bypass | https://documentation.commvault.com/securityadvisories/CV_2026_08_5.html 2026-09-08 | CVE-2026-77104 CVE-2026-77104 | CommVault Systems | high 8.3 | Commvault Cloud: path traversal | https://documentation.commvault.com/securityadvisories/CV_2026_08_6.html 2026-09-08 | CVE-2026-77105 CVE-2026-77105 | CommVault Systems | high 8.7 | Commvault Cloud: improper signature check | https://documentation.commvault.com/securityadvisories/CV_2026_08_7.html 2026-09-08 | CVE-2026-77106 CVE-2026-77106 | CommVault Systems | high 7.7 | Commvault Cloud: missing authorization | https://documentation.commvault.com/securityadvisories/CV_2026_08_8.html 2026-09-08 | CVE-2026-77089 CVE-2026-77089 | CommVault Systems | critical 9.3 | Commvault Cloud: authentication bypass | https://documentation.commvault.com/securityadvisories/CV_2026_07_1.html 2026-09-08 | CVE-2026-77091 CVE-2026-77091 | CommVault Systems | high 8.5 | Commvault Cloud: path traversal | https://documentation.commvault.com/securityadvisories/CV_2026_07_3.html 2026-09-08 | CVE-2026-77092 CVE-2026-77092 | CommVault Systems | high 7.3 | Commvault Cloud: unsafe deserialization | https://documentation.commvault.com/securityadvisories/CV_2026_07_6.html 2026-09-08 | CVE-2026-77097 CVE-2026-77097 | CommVault Systems | high 8.8 | Commvault Cloud: missing authentication | https://documentation.commvault.com/securityadvisories/CV_2026_08_1.html 2026-09-08 | CVE-2026-77098 CVE-2026-77098 | CommVault Systems | high 8.8 | Commvault Cloud: SQL injection | https://documentation.commvault.com/securityadvisories/CV_2026_08_2.html 2026-09-08 | CVE-2026-77101 CVE-2026-77101 | CommVault Systems | high 8.7 | Commvault Cloud: stack buffer overflow | https://documentation.commvault.com/securityadvisories/CV_2026_08_3.html 2026-09-08 | CVE-2026-77102 CVE-2026-77102 | CommVault Systems | high 8.7 | Commvault Cloud: heap buffer overflow | https://documentation.commvault.com/securityadvisories/CV_2026_08_4.html 2026-09-08 | CVE-2026-11573 CVE-2026-11573 | Qt Group Plc | high 7.1 | qt: denial of service | https://codereview.qt-project.org/c/qt/qtbase/+/606899 2026-09-08 | AWS-2026-102 CVE-2026-84942 | AWS | unknown | Stored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch Dashboards | https://aws.amazon.com/security/security-bulletins/rss/2026-102-aws/ 2026-09-08 | CVE-2026-77968 CVE-2026-77968 | Red Hat | high 8.2 | Red Hat build of Apache Camel - HawtIO 4: improper privilege management | https://access.redhat.com/security/cve/CVE-2026-77968 2026-09-08 | CVE-2026-78234 CVE-2026-78234 | Red Hat | critical 9.9 | Red Hat build of Apache Camel - HawtIO 4: improper certificate validation | https://access.redhat.com/security/cve/CVE-2026-78234 2026-09-08 | CVE-2026-74860 CVE-2026-74860 | Red Hat | high 8.5 | Red Hat libxml2 with Python bindings enabled: denial of service | https://access.redhat.com/errata/RHSA-2026:64463 2026-09-08 | CVE-2026-67367 CVE-2026-67367 | Siemens | critical 9.2 | Siemens SIMOVE Fleetmanager: path traversal | https://cert-portal.siemens.com/productcert/html/ssa-517424.html 2026-09-08 | CVE-2026-74859 CVE-2026-74859 | Red Hat | medium 6.8 | Red Hat Enterprise Linux: path traversal | https://access.redhat.com/security/cve/CVE-2026-74859 2026-09-08 | CVE-2026-62649 CVE-2026-62649 | Siemens | high 8.7 | Siemens Reyrolle 7SR5: denial of service | https://cert-portal.siemens.com/productcert/html/ssa-142885.html 2026-09-08 | CVE-2026-62650 CVE-2026-62650 | Siemens | high 8.7 | Siemens Reyrolle 7SR5: improper access control | https://cert-portal.siemens.com/productcert/html/ssa-142885.html 2026-09-08 | CVE-2026-62652 CVE-2026-62652 | Siemens | medium 6.9 | Siemens Reyrolle 7SR5: unauthenticated attacker could the publicly available | https://cert-portal.siemens.com/productcert/html/ssa-142885.html 2026-09-08 | CVE-2026-62653 CVE-2026-62653 | Siemens | high 7.0 | Siemens Reyrolle 7SR5: memory corruption | https://cert-portal.siemens.com/productcert/html/ssa-142885.html 2026-09-08 | CVE-2026-62654 CVE-2026-62654 | Siemens | high 7.0 | Siemens Reyrolle 7SR5: attacker could the device to upload | https://cert-portal.siemens.com/productcert/html/ssa-142885.html 2026-09-08 | CVE-2026-58113 CVE-2026-58113 | Siemens | high 8.5 | Siemens Teamcenter: cross-site scripting | https://cert-portal.siemens.com/productcert/html/ssa-157465.html 2026-09-08 | CVE-2026-62645 CVE-2026-62645 | Siemens | critical 9.3 | Siemens Reyrolle 7SR5: authentication bypass | https://cert-portal.siemens.com/productcert/html/ssa-142885.html 2026-09-08 | CVE-2026-62646 CVE-2026-62646 | Siemens | critical 9.1 | Siemens Reyrolle 7SR5: authentication bypass | https://cert-portal.siemens.com/productcert/html/ssa-142885.html 2026-09-08 | CVE-2026-62647 CVE-2026-62647 | Siemens | critical 9.3 | Siemens Reyrolle 7SR5: unauthenticated remote attacker could more easily predict | https://cert-portal.siemens.com/productcert/html/ssa-142885.html 2026-09-08 | CVE-2026-62648 CVE-2026-62648 | Siemens | high 8.7 | Siemens Reyrolle 7SR5: out-of-bounds write | https://cert-portal.siemens.com/productcert/html/ssa-142885.html 2026-09-08 | CVE-2026-50093 CVE-2026-50093 | Siemens | high 8.9 | Siemens Siveillance Control Pro: arbitrary file upload | https://cert-portal.siemens.com/productcert/html/ssa-254516.html 2026-09-08 | CVE-2026-34223 CVE-2026-34223 | Siemens | high 8.6 | Siemens Desigo CC: code execution | https://cert-portal.siemens.com/productcert/html/ssa-330084.html 2026-09-08 | CVE-2026-76561 CVE-2026-76561 | Red Hat | high 7.2 | Red Hat Dogtag PKI: code execution | https://access.redhat.com/security/cve/CVE-2026-76561 2026-09-08 | CVE-2026-75811 CVE-2026-75811 | ASUS | medium 5.8 | ASUS Armoury Crate: local user could modify hardware configuration settings | https://www.asus.com/security-advisory 2026-09-08 | CVE-2026-18023 CVE-2026-18023 | ASUS | medium 5.7 | ASUS Armoury Crate: information disclosure | https://www.asus.com/security-advisory 2026-09-08 | CVE-2026-19397 CVE-2026-19397 | ASUS | high 7.7 | ASUS Control Center Express Agent: missing authentication | https://www.asus.com/security-advisory 2026-09-08 | CVE-2026-75808 CVE-2026-75808 | ASUS | medium 5.7 | ASUS Armoury Crate: denial of service | https://www.asus.com/security-advisory 2026-09-08 | CVE-2026-75809 CVE-2026-75809 | ASUS | medium 5.9 | ASUS Armoury Crate: improper access control | https://www.asus.com/security-advisory 2026-09-08 | CVE-2026-75810 CVE-2026-75810 | ASUS | medium 5.7 | ASUS Armoury Crate: denial of service | https://www.asus.com/security-advisory 2026-09-08 | CVE-2026-12962 CVE-2026-12962 | ASUS | medium 5.3 | ASUS Armoury Crate: remote user could obtain a local user's NTLM hash | https://www.asus.com/security-advisory 2026-09-08 | CVE-2026-16003 CVE-2026-16003 | ASUS | low 2.0 | ASUS Armoury Crate: improper access control | https://www.asus.com/security-advisory 2026-09-08 | CVE-2026-16004 CVE-2026-16004 | ASUS | medium 5.9 | ASUS Armoury Crate: improper access control | https://www.asus.com/security-advisory 2026-09-08 | CVE-2026-16005 CVE-2026-16005 | ASUS | medium 5.8 | ASUS Armoury Crate: local user could free arbitrary memory | https://www.asus.com/security-advisory 2026-09-08 | CVE-2026-16006 CVE-2026-16006 | ASUS | medium 5.7 | ASUS Armoury Crate: system information exposure | https://www.asus.com/security-advisory/ 2026-09-08 | CVE-2026-76963 CVE-2026-76963 | SAP | medium 4.3 | SAP NetWeaver and ABAP Platform: missing authorization | https://me.sap.com/notes/3772838 2026-09-08 | CVE-2026-76967 CVE-2026-76967 | SAP | high 7.8 | SAP NetWeaver Business Client: code execution | https://me.sap.com/notes/3784138 2026-09-08 | CVE-2026-76968 CVE-2026-76968 | SAP | medium 6.5 | SAP Web Dispatcher, Internet: information disclosure | https://me.sap.com/notes/3750721 2026-09-08 | CVE-2026-76969 CVE-2026-76969 | SAP | critical 9.4 | SAP Cloud Application Programming Model (CAP): weakly protected credentials | https://me.sap.com/notes/3798315 2026-09-08 | CVE-2026-76971 CVE-2026-76971 | SAP | medium 6.5 | SAP Manufacturing Integration and Intelligence: server-side request forgery | https://me.sap.com/notes/3786489 2026-09-08 | CVE-2026-76977 CVE-2026-76977 | SAP | medium 4.3 | SAP UI5 does not sufficiently validate the parent frame's origin against the... | https://me.sap.com/notes/3783189 2026-09-08 | CVE-2026-76958 CVE-2026-76958 | SAP | high 8.5 | SAP Integration Suite: resource exhaustion | https://me.sap.com/notes/3792978 2026-09-08 | CVE-2026-76959 CVE-2026-76959 | SAP | medium 4.6 | SAP S/4HANA: cross-site request forgery | https://me.sap.com/notes/3365311 2026-09-08 | CVE-2026-76960 CVE-2026-76960 | SAP | low 3.5 | SAP S/4HANA: cross-site request forgery | https://me.sap.com/notes/3365276 2026-09-08 | CVE-2026-76961 CVE-2026-76961 | SAP | low 3.5 | SAP S/4HANA: cross-site request forgery | https://me.sap.com/notes/3371336 2026-09-08 | CVE-2026-76962 CVE-2026-76962 | SAP | medium 4.3 | SAP S/4HANA (Manage Bank Chains app): missing authorization | https://me.sap.com/notes/3657599 2026-09-08 | CVE-2026-66768 CVE-2026-66768 | SAP | critical 9.0 | SAP NetWeaver (SAP GUI for Java): untrusted input in a security decision | https://me.sap.com/notes/3781729 2026-09-08 | CVE-2026-58240 CVE-2026-58240 | SAP | critical 9.8 | SAP NetWeaver Message Server does not sufficiently validate the authenticity of... | https://me.sap.com/notes/3759472 2026-09-08 | CVE-2026-66767 CVE-2026-66767 | SAP | high 7.7 | SAP NetWeaver Application Server for ABAP and ABAP Platform: integer underflow | https://me.sap.com/notes/3757002 2026-09-08 | CVE-2026-58234 CVE-2026-58234 | SAP | low 2.2 | SAP Process Integration (SOAP Adapter): XML entity expansion | https://me.sap.com/notes/3736494 2026-09-08 | CVE-2026-44756 CVE-2026-44756 | SAP | critical 10.0 | SAP Extended Passport (EPP) Processing: buffer overflow | https://me.sap.com/notes/3747649 2026-09-08 | CVE-2026-44766 CVE-2026-44766 | SAP | medium 6.5 | SAP S/4HANA (Intercompany Matching and Reconciliation): information disclosure | https://me.sap.com/notes/3756450 2026-09-07 | CVE-2026-75650 CVE-2026-75650 | Adobe | critical 10.0 | Adobe Commerce: code execution | https://helpx.adobe.com/security/products/magento/apsb26-146.html 2026-09-07 | CVE-2026-86505 CVE-2026-86505 | JetBrains | low 3.3 | JetBrains IntelliJ IDEA: information disclosure | https://www.jetbrains.com/privacy-security/issues-fixed/ 2026-09-07 | CVE-2026-86506 CVE-2026-86506 | JetBrains | medium 5.9 | JetBrains GoLand: missing authentication | https://www.jetbrains.com/privacy-security/issues-fixed/ 2026-09-07 | CVE-2026-86497 CVE-2026-86497 | JetBrains | medium 6.8 | JetBrains YouTrack: information disclosure | https://www.jetbrains.com/privacy-security/issues-fixed/ 2026-09-07 | CVE-2026-86498 CVE-2026-86498 | JetBrains | high 7.7 | JetBrains YouTrack: improper authorization | https://www.jetbrains.com/privacy-security/issues-fixed/ 2026-09-07 | CVE-2026-86499 CVE-2026-86499 | JetBrains | medium 4.3 | JetBrains YouTrack: missing authorization | https://www.jetbrains.com/privacy-security/issues-fixed/ 2026-09-07 | CVE-2026-86500 CVE-2026-86500 | JetBrains | medium 5.5 | In JetBrains YouTrack before 2026.1.14047 a missing escalation check let a user... | https://www.jetbrains.com/privacy-security/issues-fixed/ 2026-09-07 | CVE-2026-86501 CVE-2026-86501 | JetBrains | low 2.8 | JetBrains IntelliJ IDEA: secrets in logs | https://www.jetbrains.com/privacy-security/issues-fixed/ 2026-09-07 | CVE-2026-86502 CVE-2026-86502 | JetBrains | high 8.4 | JetBrains IntelliJ IDEA: remote code execution | https://www.jetbrains.com/privacy-security/issues-fixed/ 2026-09-07 | CVE-2026-86503 CVE-2026-86503 | JetBrains | low 3.3 | JetBrains IntelliJ IDEA: server-side request forgery | https://www.jetbrains.com/privacy-security/issues-fixed/ 2026-09-07 | CVE-2026-86504 CVE-2026-86504 | JetBrains | high 7.8 | JetBrains IntelliJ IDEA: code execution | https://www.jetbrains.com/privacy-security/issues-fixed/ 2026-09-07 | CVE-2026-86488 CVE-2026-86488 | JetBrains | medium 6.5 | JetBrains YouTrack: insecure direct object reference | https://www.jetbrains.com/privacy-security/issues-fixed/ 2026-09-07 | CVE-2026-86489 CVE-2026-86489 | JetBrains | medium 6.5 | JetBrains YouTrack: insecure direct object reference | https://www.jetbrains.com/privacy-security/issues-fixed/ 2026-09-07 | CVE-2026-86490 CVE-2026-86490 | JetBrains | medium 6.5 | JetBrains YouTrack: insecure permissions | https://www.jetbrains.com/privacy-security/issues-fixed/ 2026-09-07 | CVE-2026-86491 CVE-2026-86491 | JetBrains | low 3.5 | JetBrains YouTrack: cross-site scripting | https://www.jetbrains.com/privacy-security/issues-fixed/ 2026-09-07 | CVE-2026-86492 CVE-2026-86492 | JetBrains | high 8.5 | In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed... | https://www.jetbrains.com/privacy-security/issues-fixed/ 2026-09-07 | CVE-2026-86493 CVE-2026-86493 | JetBrains | medium 6.5 | JetBrains YouTrack: insecure permissions | https://www.jetbrains.com/privacy-security/issues-fixed/ 2026-09-07 | CVE-2026-86494 CVE-2026-86494 | JetBrains | high 7.7 | JetBrains YouTrack: missing authorization | https://www.jetbrains.com/privacy-security/issues-fixed/ 2026-09-07 | CVE-2026-86495 CVE-2026-86495 | JetBrains | medium 6.5 | JetBrains YouTrack: missing authorization | https://www.jetbrains.com/privacy-security/issues-fixed/ 2026-09-07 | CVE-2026-86496 CVE-2026-86496 | JetBrains | medium 4.3 | JetBrains YouTrack: improper access control | https://www.jetbrains.com/privacy-security/issues-fixed/ 2026-09-07 | CVE-2026-86479 CVE-2026-86479 | JetBrains | high 8.1 | JetBrains YouTrack: missing authorization | https://www.jetbrains.com/privacy-security/issues-fixed/ 2026-09-07 | CVE-2026-86480 CVE-2026-86480 | JetBrains | critical 9.8 | JetBrains Hub: missing authentication | https://www.jetbrains.com/privacy-security/issues-fixed/ 2026-09-07 | CVE-2026-86481 CVE-2026-86481 | JetBrains | medium 4.3 | JetBrains YouTrack: insecure direct object reference | https://www.jetbrains.com/privacy-security/issues-fixed/ 2026-09-07 | CVE-2026-86482 CVE-2026-86482 | JetBrains | high 8.8 | JetBrains YouTrack: privilege escalation | https://www.jetbrains.com/privacy-security/issues-fixed/ 2026-09-07 | CVE-2026-86483 CVE-2026-86483 | JetBrains | medium 5.4 | JetBrains YouTrack: cross-site scripting | https://www.jetbrains.com/privacy-security/issues-fixed/ 2026-09-07 | CVE-2026-86484 CVE-2026-86484 | JetBrains | medium 4.6 | JetBrains YouTrack: template injection | https://www.jetbrains.com/privacy-security/issues-fixed/ 2026-09-07 | CVE-2026-86485 CVE-2026-86485 | JetBrains | low 3.3 | JetBrains YouTrack: spoofing | https://www.jetbrains.com/privacy-security/issues-fixed/ 2026-09-07 | CVE-2026-86486 CVE-2026-86486 | JetBrains | low 3.7 | JetBrains YouTrack: missing authentication | https://www.jetbrains.com/privacy-security/issues-fixed/ 2026-09-07 | CVE-2026-86487 CVE-2026-86487 | JetBrains | low 3.1 | JetBrains YouTrack: improper authorization | https://www.jetbrains.com/privacy-security/issues-fixed/ 2026-09-07 | CVE-2026-79975 CVE-2026-79975 | Dell Technologies | medium 5.5 | Dell Technologies Secure Connect Gateway 5.0: improper certificate validation | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9 2026-09-07 | CVE-2026-80058 CVE-2026-80058 | Dell Technologies | medium 5.5 | Dell Technologies Secure Connect Gateway 5.0: cleartext secrets | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9 2026-09-07 | CVE-2026-80125 CVE-2026-80125 | Dell Technologies | medium 5.9 | Dell Technologies Secure Connect Gateway 5.0: improper certificate validation | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9 2026-09-07 | CVE-2026-80126 CVE-2026-80126 | Dell Technologies | medium 6.5 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0... | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9 2026-09-07 | CVE-2026-80166 CVE-2026-80166 | Dell Technologies | high 7.8 | Dell Technologies Secure Connect Gateway 5.0: improper privilege management | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9 2026-09-07 | CVE-2026-80167 CVE-2026-80167 | Dell Technologies | medium 5.5 | Dell Technologies Secure Connect Gateway 5.0: information disclosure | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9 2026-09-07 | CVE-2026-80176 CVE-2026-80176 | Dell Technologies | medium 4.7 | Dell Technologies Secure Connect Gateway 5.0: information disclosure | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9 2026-09-07 | CVE-2026-86478 CVE-2026-86478 | JetBrains | critical 9.8 | JetBrains YouTrack: improper authentication | https://www.jetbrains.com/privacy-security/issues-fixed/ 2026-09-07 | CVE-2026-79639 CVE-2026-79639 | Dell Technologies | high 7.6 | Dell Technologies Secure Connect Gateway 5.0: improper certificate validation | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9 2026-09-07 | CVE-2026-86469 CVE-2026-86469 | Red Hat | medium 5.3 | Red Hat GLib2.: link following | https://access.redhat.com/security/cve/CVE-2026-86469 2026-09-07 | CVE-2026-79642 CVE-2026-79642 | Dell Technologies | medium 5.6 | Dell Technologies Secure Connect Gateway 5.0: improper certificate validation | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9 2026-09-07 | CVE-2026-79643 CVE-2026-79643 | Dell Technologies | high 7.3 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0... | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9 2026-09-07 | CVE-2026-79691 CVE-2026-79691 | Dell Technologies | high 7.3 | Dell Technologies Secure Connect Gateway 5.0: improper certificate validation | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9 2026-09-07 | CVE-2026-79943 CVE-2026-79943 | Dell Technologies | medium 4.8 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0... | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9 2026-09-07 | CVE-2026-80054 CVE-2026-80054 | Dell Technologies | medium 5.5 | Dell Technologies Secure Connect Gateway 5.0: insecure permissions | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9 2026-09-07 | CVE-2026-80127 CVE-2026-80127 | Dell Technologies | high 7.2 | Dell Technologies Secure Connect Gateway 5.0: command injection | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9 2026-09-07 | CVE-2026-79645 CVE-2026-79645 | Dell Technologies | high 8.2 | Dell Technologies Secure Connect Gateway 5.0: missing authentication | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9 2026-09-07 | CVE-2026-80056 CVE-2026-80056 | Dell Technologies | medium 5.5 | Dell Technologies Secure Connect Gateway 5.0: information disclosure | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9 2026-09-07 | CVE-2026-80057 CVE-2026-80057 | Dell Technologies | medium 5.5 | Dell Technologies Secure Connect Gateway 5.0: information disclosure | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9 2026-09-07 | CVE-2026-18453 CVE-2026-18453 | Red Hat | high 7.5 | Red Hat 389 Directory Server: denial of service | https://access.redhat.com/errata/RHSA-2026:64771 2026-09-07 | CVE-2026-18922 CVE-2026-18922 | Red Hat | critical 9.8 | Red Hat 389 Directory Server: improper authentication | https://access.redhat.com/errata/RHSA-2026:64771 2026-09-07 | CVE-2026-19843 CVE-2026-19843 | Red Hat | high 8.4 | Red Hat 389-ds-base. The Cockpit 389 Console: command injection | https://access.redhat.com/errata/RHSA-2026:64768 2026-09-07 | CVE-2026-78480 CVE-2026-78480 | Dell Technologies | high 7.5 | Dell Technologies Secure Connect Gateway 5.0: missing authentication | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9 2026-09-07 | CVE-2026-78488 CVE-2026-78488 | Dell Technologies | medium 6.5 | Dell Technologies Secure Connect Gateway 5.0: command injection | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9 2026-09-07 | CVE-2026-79644 CVE-2026-79644 | Dell Technologies | high 7.4 | Dell Technologies Secure Connect Gateway 5.0: improper certificate validation | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9 2026-09-07 | CVE-2026-18355 CVE-2026-18355 | Red Hat | high 7.5 | Red Hat: buffer overflow | https://access.redhat.com/errata/RHSA-2026:64771 2026-09-07 | CVE-2026-80164 CVE-2026-80164 | Dell Technologies | high 7.4 | Dell Technologies Secure Connect Gateway 5.0: improper certificate validation | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9 2026-09-07 | CVE-2026-80170 CVE-2026-80170 | Dell Technologies | medium 6.5 | Dell Technologies Secure Connect Gateway 5.0: hard-coded credentials | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9 2026-09-07 | CVE-2026-76560 CVE-2026-76560 | Red Hat | high 7.5 | Red Hat 389 Directory Server: improper access control | https://access.redhat.com/errata/RHSA-2026:64771 2026-09-07 | CVE-2026-78487 CVE-2026-78487 | Dell Technologies | medium 5.5 | Dell Technologies Secure Connect Gateway 5.0: information disclosure | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9 2026-09-07 | CVE-2026-79734 CVE-2026-79734 | Dell Technologies | medium 5.9 | Dell Technologies Secure Connect Gateway 5.0: improper certificate validation | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9 2026-09-07 | CVE-2026-80128 CVE-2026-80128 | Dell Technologies | medium 6.4 | Dell Technologies Secure Connect Gateway 5.0: improper authentication | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9 2026-09-07 | CVE-2026-80129 CVE-2026-80129 | Dell Technologies | medium 6.5 | Dell Technologies Secure Connect Gateway 5.0: path traversal | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9 2026-09-07 | CVE-2026-80130 CVE-2026-80130 | Dell Technologies | high 7.1 | Dell Technologies Secure Connect Gateway 5.0: path traversal | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9 2026-09-07 | CVE-2026-80131 CVE-2026-80131 | Dell Technologies | high 7.4 | Dell Technologies Secure Connect Gateway 5.0: path traversal | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9 2026-09-07 | CVE-2026-80135 CVE-2026-80135 | Dell Technologies | high 7.5 | Dell Technologies Secure Connect Gateway 5.0: unhandled exceptional condition | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9 2026-09-07 | CVE-2026-80178 CVE-2026-80178 | Dell Technologies | medium 5.5 | Dell Technologies Secure Connect Gateway 5.0: improper privilege management | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9 2026-09-07 | CVE-2026-80238 CVE-2026-80238 | Dell Technologies | critical 9.3 | Dell Technologies Secure Connect Gateway 5.0: excessive privileges | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9 2026-09-07 | CVE-2026-79678 CVE-2026-79678 | Red Hat | high 8.1 | Red Hat FreeIPA: improper access control | https://access.redhat.com/errata/RHSA-2026:70564 2026-09-07 | CVE-2026-80132 CVE-2026-80132 | Dell Technologies | high 8.1 | Dell Technologies Secure Connect Gateway 5.0: missing authentication | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-07 | CVE-2026-80133 CVE-2026-80133 | Dell Technologies | high 7.4 | Dell Technologies Secure Connect Gateway 5.0: path traversal | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-07 | CVE-2026-80134 CVE-2026-80134 | Dell Technologies | high 7.7 | Dell Technologies Secure Connect Gateway 5.0: hard-coded credentials | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-07 | CVE-2026-76578 CVE-2026-76578 | Red Hat | critical 9.8 | Red Hat FreeIPA: missing authentication | https://access.redhat.com/errata/RHSA-2026:70564 2026-09-07 | CVE-2026-61409 CVE-2026-61409 | Dell Technologies | high 7.3 | Dell Technologies Secure Connect Gateway: command injection | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-07 | CVE-2026-61410 CVE-2026-61410 | Dell Technologies | critical 9.4 | Dell Technologies Secure Connect Gateway 5.0: missing authorization | https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities 2026-09-07 | CVE-2026-86404 CVE-2026-86404 | Red Hat | high 8.8 | Red Hat: unsafe deserialization | https://access.redhat.com/errata/RHSA-2026:53644 2026-09-07 | CVE-2026-86332 CVE-2026-86332 | Red Hat | medium 6.5 | Red Hat OpenShift AI (RHOAI): missing authorization | https://access.redhat.com/security/cve/CVE-2026-86332 2026-09-07 | GHSA-qmfj-jjw4-8qrq | IBM | high 8.1 | ## Summary The admin A2A-agent edit route does not enforce object ownership | https://github.com/IBM/mcp-context-forge/security/advisories/GHSA-qmfj-jjw4-8qrq 2026-09-07 | CVE-2026-86315 CVE-2026-86315 | Samsung | medium 6.2 | Samsung Escargot: out-of-bounds write | https://github.com/Samsung/escargot/pull/1660 2026-09-07 | CVE-2026-86313 CVE-2026-86313 | Samsung | high 7.8 | Samsung Walrus: out-of-bounds write | https://github.com/Samsung/walrus/pull/482 2026-09-07 | CVE-2026-86314 CVE-2026-86314 | Samsung | medium 6.2 | Samsung Walrus: integer overflow | https://github.com/Samsung/walrus/pull/482 2026-09-07 | CVE-2026-20513 CVE-2026-20513 | MediaTek | medium 4.4 | MediaTek chipset: information disclosure | https://www.mediatek.com/product-security-bulletin/September-2026 2026-09-07 | CVE-2026-20514 CVE-2026-20514 | MediaTek | medium 4.4 | MediaTek chipset: information disclosure | https://www.mediatek.com/product-security-bulletin/September-2026 2026-09-07 | CVE-2026-20515 CVE-2026-20515 | MediaTek | medium 5.5 | MediaTek chipset: use after free | https://www.mediatek.com/product-security-bulletin/September-2026 2026-09-07 | CVE-2026-20516 CVE-2026-20516 | MediaTek | medium 5.5 | MediaTek chipset: privilege escalation | https://www.mediatek.com/product-security-bulletin/September-2026 2026-09-07 | CVE-2026-20517 CVE-2026-20517 | MediaTek | medium 6.7 | MediaTek chipset: privilege escalation | https://www.mediatek.com/product-security-bulletin/September-2026 2026-09-07 | CVE-2026-20518 CVE-2026-20518 | MediaTek | medium 4.4 | MediaTek chipset: information disclosure | https://www.mediatek.com/product-security-bulletin/September-2026 2026-09-07 | CVE-2026-20503 CVE-2026-20503 | MediaTek | medium 5.3 | MediaTek chipset: denial of service | https://www.mediatek.com/product-security-bulletin/September-2026 2026-09-07 | CVE-2026-20504 CVE-2026-20504 | MediaTek | medium 5.3 | MediaTek chipset: denial of service | https://www.mediatek.com/product-security-bulletin/September-2026 2026-09-07 | CVE-2026-20506 CVE-2026-20506 | MediaTek | medium 6.7 | MediaTek chipset: privilege escalation | https://www.mediatek.com/product-security-bulletin/September-2026 2026-09-07 | CVE-2026-20507 CVE-2026-20507 | MediaTek | medium 6.7 | MediaTek chipset: privilege escalation | https://www.mediatek.com/product-security-bulletin/September-2026 2026-09-07 | CVE-2026-20508 CVE-2026-20508 | MediaTek | medium 6.7 | MediaTek chipset: privilege escalation | https://www.mediatek.com/product-security-bulletin/September-2026 2026-09-07 | CVE-2026-20509 CVE-2026-20509 | MediaTek | medium 6.7 | MediaTek chipset: out-of-bounds write | https://www.mediatek.com/product-security-bulletin/September-2026 2026-09-07 | CVE-2026-20510 CVE-2026-20510 | MediaTek | medium 6.7 | MediaTek chipset: privilege escalation | https://www.mediatek.com/product-security-bulletin/September-2026 2026-09-07 | CVE-2026-20511 CVE-2026-20511 | MediaTek | medium 6.7 | MediaTek chipset: memory corruption | https://www.mediatek.com/product-security-bulletin/September-2026 2026-09-07 | CVE-2026-20512 CVE-2026-20512 | MediaTek | medium 6.7 | MediaTek chipset: privilege escalation | https://www.mediatek.com/product-security-bulletin/September-2026 2026-09-07 | CVE-2026-20500 CVE-2026-20500 | MediaTek | medium 5.5 | MediaTek chipset: improper input validation | https://www.mediatek.com/product-security-bulletin/September-2026 2026-09-07 | CVE-2026-20501 CVE-2026-20501 | MediaTek | high 8.4 | MediaTek chipset: out-of-bounds write | https://www.mediatek.com/product-security-bulletin/September-2026 2026-09-07 | CVE-2026-20502 CVE-2026-20502 | MediaTek | high 8.4 | MediaTek chipset: out-of-bounds write | https://www.mediatek.com/product-security-bulletin/September-2026 2026-09-07 | CVE-2026-16876 CVE-2026-16876 | NEC | critical 9.3 | NEC UNIVERGE IX-R/IX-V: authentication bypass | https://jpn.nec.com/security-info/secinfo/nv26-005_en.html 2026-09-06 | CVE-2026-86218 CVE-2026-86218 | N-able | critical 10.0 | N-able N-central: remote code execution | https://me.n-able.com/s/security-advisory/aArVy0000002Ld3KAE/cve202686218-preauthentication-remote-code-execution 2026-09-05 | CVE-2026-86206 CVE-2026-86206 | N-able | medium 6.9 | N-able N-central: improper access control | https://documentation.n-able.com/N-central/Release_Notes/GA/Content/N-central_2026.3_HF3_Release_Notes.htm 2026-09-05 | CVE-2026-86207 CVE-2026-86207 | N-able | high 7.7 | N-able N-central: authentication bypass | https://documentation.n-able.com/N-central/Release_Notes/GA/Content/N-central_2026.3_HF3_Release_Notes.htm 2026-09-04 | GHSA-pr7f-p5mw-fc87 CVE-2026-73557 | vLLM | medium | vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts | https://github.com/advisories/GHSA-pr7f-p5mw-fc87 2026-09-04 | GHSA-48jh-3gj7-fg8v CVE-2026-73556 | vLLM | medium 5.3 | vLLM: denial of service | https://github.com/advisories/GHSA-48jh-3gj7-fg8v 2026-09-04 | GHSA-hwrm-c4cx-rf4j CVE-2026-73555 | vLLM | medium 5.3 | vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages | https://github.com/advisories/GHSA-hwrm-c4cx-rf4j 2026-09-04 | GHSA-8737-qx52-hjff CVE-2026-71486 | vLLM | medium 4.3 | vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds | https://github.com/advisories/GHSA-8737-qx52-hjff 2026-09-04 | GHSA-848m-r628-vrxw CVE-2026-63735 | SurrealDB | high 8.1 | SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path | https://github.com/advisories/GHSA-848m-r628-vrxw 2026-09-04 | CVE-2026-76925 CVE-2026-76925 | Red Hat | medium 5.8 | Red Hat Flatpak: race condition | https://access.redhat.com/security/cve/CVE-2026-76925 2026-09-04 | CVE-2026-81939 CVE-2026-81939 | SonicWall | critical 9.1 | SonicWall Network Security Manager (NSM): path traversal | https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0015 2026-09-04 | CVE-2026-78327 CVE-2026-78327 | SonicWall | critical 9.1 | SonicWall Network Security Manager (NSM): command injection | https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0015 2026-09-04 | CVE-2026-78328 CVE-2026-78328 | SonicWall | critical 9.1 | SonicWall Network Security Manager (NSM): missing authorization | https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0015 2026-09-04 | CVE-2026-85769 CVE-2026-85769 | Red Hat | medium 6.5 | Red Hat libtpms: denial of service | https://access.redhat.com/security/cve/CVE-2026-85769 2026-09-04 | CVE-2026-85656 CVE-2026-85656 | AWS | high 8.5 | AWS log4j-cve-2021-44228-hotpatch: command injection | https://alas.aws.amazon.com/AL2/ALAS2-2026-3784.html 2026-09-04 | CVE-2026-18175 CVE-2026-18175 | IBM | high 8.1 | IBM i: improper authorization | https://www.ibm.com/support/pages/node/7286186 2026-09-04 | CVE-2026-18221 CVE-2026-18221 | IBM | high 8.1 | IBM i: improper authentication | https://www.ibm.com/support/pages/node/7286186 2026-09-04 | CVE-2026-18341 CVE-2026-18341 | IBM | medium 6.3 | IBM i: integer overflow | https://www.ibm.com/support/pages/node/7286094 2026-09-04 | CVE-2026-18486 CVE-2026-18486 | IBM | high 8.8 | IBM ContextForge MCP Gateway: privilege escalation | https://www.ibm.com/support/pages/node/7286052 2026-09-04 | CVE-2026-18489 CVE-2026-18489 | IBM | high 7.4 | IBM ContextForge MCP Gateway - Translate utility: information disclosure | https://www.ibm.com/support/pages/node/7286056 2026-09-04 | CVE-2026-17621 CVE-2026-17621 | IBM | medium 5.4 | IBM Langflow OSS: path traversal | https://www.ibm.com/support/pages/node/7286293 2026-09-04 | CVE-2026-17622 CVE-2026-17622 | IBM | medium 6.5 | IBM Langflow OSS: information disclosure | https://www.ibm.com/support/pages/node/7286293 2026-09-04 | CVE-2026-17627 CVE-2026-17627 | IBM | medium 4.9 | IBM Langflow OSS: information disclosure | https://www.ibm.com/support/pages/node/7286294 2026-09-04 | CVE-2026-17631 CVE-2026-17631 | IBM | medium 5.0 | IBM Langflow OSS: information disclosure | https://www.ibm.com/support/pages/node/7285644 2026-09-04 | CVE-2026-18073 CVE-2026-18073 | IBM | medium 4.4 | IBM i: command injection | https://www.ibm.com/support/pages/node/7285844 2026-09-04 | CVE-2026-18076 CVE-2026-18076 | IBM | medium 4.3 | IBM i: denial of service | https://www.ibm.com/support/pages/node/7285844 2026-09-04 | CVE-2026-18078 CVE-2026-18078 | IBM | medium 4.3 | IBM i: denial of service | https://www.ibm.com/support/pages/node/7285937 2026-09-04 | CVE-2026-17442 CVE-2026-17442 | IBM | medium 5.1 | IBM App Connect Enterprise: information disclosure | https://www.ibm.com/support/pages/node/7286372 2026-09-04 | CVE-2026-17443 CVE-2026-17443 | IBM | medium 5.3 | IBM App Connect Enterprise: information disclosure | https://www.ibm.com/support/pages/node/7286372 2026-09-04 | CVE-2026-17444 CVE-2026-17444 | IBM | medium 5.3 | IBM App Connect Enterprise: information disclosure | https://www.ibm.com/support/pages/node/7286372 2026-09-04 | CVE-2026-17469 CVE-2026-17469 | IBM | medium 5.3 | IBM i: denial of service | https://www.ibm.com/support/pages/node/7285939 2026-09-04 | CVE-2026-17470 CVE-2026-17470 | IBM | medium 5.3 | IBM i: denial of service | https://www.ibm.com/support/pages/node/7285939 2026-09-04 | CVE-2026-17483 CVE-2026-17483 | IBM | medium 4.3 | IBM Db2 Mirror for i: improper access control | https://www.ibm.com/support/pages/node/7285904 2026-09-04 | CVE-2026-17499 CVE-2026-17499 | IBM | medium 4.4 | IBM i: code execution | https://www.ibm.com/support/pages/node/7285844 2026-09-04 | CVE-2026-17207 CVE-2026-17207 | IBM | medium 6.5 | IBM i: denial of service | https://www.ibm.com/support/pages/node/7285847 2026-09-04 | CVE-2026-17255 CVE-2026-17255 | IBM | medium 4.3 | IBM i: denial of service | https://www.ibm.com/support/pages/node/7286093 2026-09-04 | CVE-2026-17259 CVE-2026-17259 | IBM | medium 4.3 | IBM i: denial of service | https://www.ibm.com/support/pages/node/7285844 2026-09-04 | CVE-2026-17270 CVE-2026-17270 | IBM | medium 4.3 | IBM i: denial of service | https://www.ibm.com/support/pages/node/7285844 2026-09-04 | CVE-2026-17273 CVE-2026-17273 | IBM | medium 6.5 | IBM i: denial of service | https://www.ibm.com/support/pages/node/7285844 2026-09-04 | CVE-2026-17274 CVE-2026-17274 | IBM | medium 5.4 | IBM i: weak randomness | https://www.ibm.com/support/pages/node/7285844 2026-09-04 | CVE-2026-17440 CVE-2026-17440 | IBM | medium 5.5 | IBM App Connect Enterprise: denial of service | https://www.ibm.com/support/pages/node/7286372 2026-09-04 | CVE-2026-16660 CVE-2026-16660 | IBM | medium 5.3 | IBM Db2 Mirror for i: denial of service | https://www.ibm.com/support/pages/node/7285904 2026-09-04 | CVE-2026-16689 CVE-2026-16689 | IBM | medium 6.2 | IBM App Connect Enterprise: information disclosure | https://www.ibm.com/support/pages/node/7286372 2026-09-04 | CVE-2026-16693 CVE-2026-16693 | IBM | medium 4.4 | IBM i: information disclosure | https://www.ibm.com/support/pages/node/7285846 2026-09-04 | CVE-2026-16826 CVE-2026-16826 | IBM | medium 5.3 | IBM i: code execution | https://www.ibm.com/support/pages/node/7285844 2026-09-04 | CVE-2026-16892 CVE-2026-16892 | IBM | medium 5.4 | IBM i: improper authentication | https://www.ibm.com/support/pages/node/7285843 2026-09-04 | CVE-2026-16941 CVE-2026-16941 | IBM | medium 4.3 | IBM i: improper authorization | https://www.ibm.com/support/pages/node/7285848 2026-09-04 | CVE-2026-17057 CVE-2026-17057 | IBM | medium 6.5 | IBM i: denial of service | https://www.ibm.com/support/pages/node/7285847 2026-09-04 | CVE-2026-13297 CVE-2026-13297 | IBM | high 7.5 | IBM Security Verify Access: improper access control | https://www.ibm.com/support/pages/node/7286188 2026-09-04 | CVE-2026-14350 CVE-2026-14350 | IBM | medium 5.3 | IBM Cloud Pak: unauthorized user could inject data into log messages | https://www.ibm.com/support/pages/node/7286036 2026-09-04 | CVE-2026-14470 CVE-2026-14470 | IBM | medium 6.5 | IBM Langflow OSS: path traversal | https://www.ibm.com/support/pages/node/7286293 2026-09-04 | CVE-2026-16180 CVE-2026-16180 | IBM | medium 5.7 | IBM App Connect Enterprise: denial of service | https://www.ibm.com/support/pages/node/7286372 2026-09-04 | CVE-2026-77822 CVE-2026-77822 | IBM | high 8.2 | IBM ContextForge MCP Gateway: information disclosure | https://www.ibm.com/support/pages/node/7286055 2026-09-04 | CVE-2026-78543 CVE-2026-78543 | IBM | medium 5.3 | IBM App Connect Enterprise: denial of service | https://www.ibm.com/support/pages/node/7286372 2026-09-04 | CVE-2026-78658 CVE-2026-78658 | IBM | medium 6.5 | IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.25 | https://www.ibm.com/support/pages/node/7286256 2026-09-04 | CVE-2026-19649 CVE-2026-19649 | IBM | medium 6.2 | IBM App Connect Enterprise: information disclosure | https://www.ibm.com/support/pages/node/7286372 2026-09-04 | CVE-2026-5522 CVE-2026-5522 | IBM | medium 6.7 | IBM QRadar: hard-coded credentials | https://www.ibm.com/support/pages/node/7285277 2026-09-04 | CVE-2026-19303 CVE-2026-19303 | IBM | high 8.1 | IBM Langflow OSS: path traversal | https://www.ibm.com/support/pages/node/7285643 2026-09-04 | CVE-2026-19304 CVE-2026-19304 | IBM | high 7.7 | IBM Langflow OSS: information disclosure | https://www.ibm.com/support/pages/node/7285639 2026-09-04 | CVE-2026-19305 CVE-2026-19305 | IBM | high 8.6 | IBM Langflow OSS: information disclosure | https://www.ibm.com/support/pages/node/7285639 2026-09-04 | CVE-2026-19306 CVE-2026-19306 | IBM | high 7.7 | IBM Langflow OSS: path traversal | https://www.ibm.com/support/pages/node/7285641 2026-09-04 | CVE-2026-19645 CVE-2026-19645 | IBM | medium 6.5 | IBM MQ Agent: resource exhaustion | https://www.ibm.com/support/pages/node/7285394 2026-09-04 | CVE-2026-19302 CVE-2026-19302 | IBM | medium 6.5 | IBM Langflow OSS: information disclosure | https://www.ibm.com/support/pages/node/7285641 2026-09-04 | CVE-2026-19299 CVE-2026-19299 | IBM | medium 6.5 | IBM Langflow OSS: information disclosure | https://www.ibm.com/support/pages/node/7285641 2026-09-04 | CVE-2026-19300 CVE-2026-19300 | IBM | high 7.5 | IBM Langflow OSS: information disclosure | https://www.ibm.com/support/pages/node/7285642 2026-09-04 | CVE-2026-19301 CVE-2026-19301 | IBM | medium 5.0 | IBM Langflow OSS: information disclosure | https://www.ibm.com/support/pages/node/7285639 2026-09-04 | CVE-2026-18658 CVE-2026-18658 | IBM | critical 9.8 | IBM Operational Decision Manager: SQL injection | https://www.ibm.com/support/pages/node/7286196 2026-09-04 | CVE-2026-18858 CVE-2026-18858 | IBM | low 3.3 | IBM i: local authenticated attacker could obtain information | https://www.ibm.com/support/pages/node/7285938 2026-09-04 | CVE-2026-18887 CVE-2026-18887 | IBM | medium 6.5 | IBM i: information disclosure | https://www.ibm.com/support/pages/node/7285940 2026-09-04 | CVE-2026-18905 CVE-2026-18905 | IBM | high 7.7 | IBM ContextForge MCP Gateway: information disclosure | https://www.ibm.com/support/pages/node/7286053 2026-09-04 | CVE-2026-19274 CVE-2026-19274 | IBM | critical 9.6 | IBM Observability with Instana (Agent): improper access control | https://www.ibm.com/support/pages/node/7286070 2026-09-04 | CVE-2026-19283 CVE-2026-19283 | IBM | high 7.7 | IBM Observability with Instana (Agent): information disclosure | https://www.ibm.com/support/pages/node/7286070 2026-09-04 | CVE-2026-19298 CVE-2026-19298 | IBM | high 8.8 | IBM Langflow OSS: remote code execution | https://www.ibm.com/support/pages/node/7285640 2026-09-04 | CVE-2026-18567 CVE-2026-18567 | IBM | medium 4.4 | IBM Db2 Mirror for i: race condition | https://www.ibm.com/support/pages/node/7285904 2026-09-04 | CVE-2026-9138 CVE-2026-9138 | IBM | medium 6.5 | IBM Langflow OSS: improper input validation | https://www.ibm.com/support/pages/node/7285643 2026-09-04 | CVE-2026-9186 CVE-2026-9186 | IBM | medium 6.5 | IBM Langflow OSS: spoofing | https://www.ibm.com/support/pages/node/7285646 2026-09-04 | CVE-2026-8447 CVE-2026-8447 | IBM | medium 6.1 | IBM Langflow OSS: cross-site scripting | https://www.ibm.com/support/pages/node/7285646 2026-09-04 | CVE-2026-81832 CVE-2026-81832 | IBM | high 7.7 | IBM App Connect Enterprise: XML external entity | https://www.ibm.com/support/pages/node/7286372 2026-09-04 | CVE-2026-81859 CVE-2026-81859 | IBM | medium 6.2 | IBM Cloud Pak for Business Automation: information disclosure | https://www.ibm.com/support/pages/node/7285931 2026-09-04 | AWS-2026-101 CVE-2026-85787 | AWS | unknown | An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs... | https://aws.amazon.com/security/security-bulletins/rss/2026-101-aws/ 2026-09-04 | AWS-2026-100 CVE-2026-85786 | AWS | unknown | Incomplete fix for CVE-2026-75936 memory-amplification denial of service in Amazon... | https://aws.amazon.com/security/security-bulletins/rss/2026-100-aws/ 2026-09-04 | AWS-2026-099 CVE-2026-85781 | AWS | unknown | Unverified access point ownership in Amazon EFS CSI Driver | https://aws.amazon.com/security/security-bulletins/rss/2026-099-aws/ 2026-09-04 | CVE-2026-79707 CVE-2026-79707 | Google Cloud | high 8.7 | Google Cloud Agent Development Kit (ADK): path traversal | https://github.com/google/adk-python/blob/main/CHANGELOG.md#1220-2026-01-08 2026-09-04 | CVE-2026-85534 CVE-2026-85534 | Red Hat | medium 5.9 | Red Hat libsoup.: reachable assertion | https://access.redhat.com/security/cve/CVE-2026-85534 2026-09-04 | CVE-2026-4644 CVE-2026-4644 | Google Cloud | high 8.5 | Google Cloud Integration Connectors: missing authorization | https://docs.cloud.google.com/support/bulletins#gcp-2026-059 2026-09-04 | CVE-2026-81666 CVE-2026-81666 | Red Hat | medium 6.5 | Red Hat Enterprise Linux 10: integer overflow | https://access.redhat.com/security/cve/CVE-2026-81666 2026-09-04 | AWS-2026-097 CVE-2026-85654 | AWS | unknown | Code injection in the CDK generator in Amazon awslabs.dynamodb-mcp-server | https://aws.amazon.com/security/security-bulletins/rss/2026-097-aws/ 2026-09-04 | CVE-2026-81665 CVE-2026-81665 | Red Hat | high 7.5 | Red Hat: heap buffer overflow | https://access.redhat.com/errata/RHSA-2026:67872 2026-09-04 | CVE-2026-85197 CVE-2026-85197 | Red Hat | high 7.6 | Red Hat libsoup: use after free | https://access.redhat.com/errata/RHSA-2026:68235 2026-09-04 | CVE-2026-85085 CVE-2026-85085 | Canva | critical 9.6 | Canva: unverified channel source | https://trust.canva.com/?tcuUid=be2ebc32-7053-4885-bf71-68771aa4589a 2026-09-04 | CVE-2026-85094 CVE-2026-85094 | Canva | high 8.8 | The Canva Android App before 2.376.0 did not restrict the headers returned to... | https://trust.canva.com/?tcuUid=be2ebc32-7053-4885-bf71-68771aa4589a 2026-09-04 | CVE-2026-75754 CVE-2026-75754 | ASUS | critical 10.0 | ASUS Control Center Enterprise (ACC): missing authentication | https://www.asus.com/security-advisory 2026-09-04 | CVE-2026-49509 CVE-2026-49509 | Samsung | medium 4.4 | Samsung rLottie: out-of-bounds read | https://github.com/Samsung/rlottie/pull/604 2026-09-03 | GHSA-8q3c-rjr9-xxrp CVE-2026-61625 | VictoriaMetrics | medium 6.8 | VictoriaMetrics vmrestore: Path traversal via crafted backup part names escapes restore root | https://github.com/advisories/GHSA-8q3c-rjr9-xxrp 2026-09-03 | CVE-2026-70178 CVE-2026-70178 | Microsoft | high 8.5 | Microsoft Fabric: missing authorization | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70178 2026-09-03 | CVE-2026-70352 CVE-2026-70352 | Microsoft | critical 10.0 | Microsoft Azure AI Language Authoring: missing authentication | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70352 2026-09-03 | CVE-2026-80098 CVE-2026-80098 | Microsoft | critical 9.3 | Microsoft Copilot Studio: privilege escalation | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-80098 2026-09-03 | CVE-2026-83711 CVE-2026-83711 | Microsoft | critical 10.0 | Microsoft Entra: privilege escalation | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83711 2026-09-03 | CVE-2026-62906 CVE-2026-62906 | Microsoft | high 7.4 | Microsoft Discovery Studio: unauthorized attacker could disclose information... | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62906 2026-09-03 | CVE-2026-62916 CVE-2026-62916 | Microsoft | critical 9.1 | Microsoft Entra: authentication bypass | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62916 2026-09-03 | CVE-2026-65818 CVE-2026-65818 | Microsoft | high 8.5 | Microsoft Power Platform: server-side request forgery | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65818 2026-09-03 | CVE-2026-69857 CVE-2026-69857 | Microsoft | high 8.5 | Microsoft Azure Cosmos DB: spoofing | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69857 2026-09-03 | CVE-2026-64197 CVE-2026-64197 | National Instruments | high 8.5 | National Instruments DASYLab: out-of-bounds write | https://www.measx.com/en/service/productsecurity/security-updates-for-measx-software/159-securityupdates/1071-out-of-bounds-write-vulnerabilities-in-dasylab-2.html 2026-09-03 | CVE-2026-64198 CVE-2026-64198 | National Instruments | high 8.5 | National Instruments DASYLab: out-of-bounds read | https://www.measx.com/en/service/productsecurity/security-updates-for-measx-software/159-securityupdates/1070-out-of-bounds-read-vulnerabilities-in-dasylab-2.html 2026-09-03 | CVE-2026-64199 CVE-2026-64199 | National Instruments | high 8.6 | National Instruments DASYLab: out-of-bounds read | https://www.measx.com/en/service/productsecurity/security-updates-for-measx-software/159-securityupdates/1070-out-of-bounds-read-vulnerabilities-in-dasylab-2.html 2026-09-03 | CVE-2026-64200 CVE-2026-64200 | National Instruments | high 8.5 | National Instruments DASYLab: out-of-bounds read | https://www.measx.com/en/service/productsecurity/security-updates-for-measx-software/159-securityupdates/1070-out-of-bounds-read-vulnerabilities-in-dasylab-2.html 2026-09-03 | CVE-2026-64195 CVE-2026-64195 | National Instruments | high 8.5 | National Instruments DASYLab: out-of-bounds write | https://www.measx.com/en/service/productsecurity/security-updates-for-measx-software/159-securityupdates/1071-out-of-bounds-write-vulnerabilities-in-dasylab-2.html 2026-09-03 | CVE-2026-64196 CVE-2026-64196 | National Instruments | high 8.5 | National Instruments DASYLab: out-of-bounds write | https://www.measx.com/en/service/productsecurity/security-updates-for-measx-software/159-securityupdates/1071-out-of-bounds-write-vulnerabilities-in-dasylab-2.html 2026-09-03 | CVE-2026-8862 CVE-2026-8862 | IBM | high 7.5 | IBM Netezza Software: information disclosure | https://www.ibm.com/support/pages/node/7284359 2026-09-03 | CVE-2026-9036 CVE-2026-9036 | IBM | medium 5.9 | IBM Netezza Software: information disclosure | https://www.ibm.com/support/pages/node/7284359 2026-09-03 | CVE-2026-9736 CVE-2026-9736 | IBM | medium 5.3 | IBM Netezza Software: unauthorized user could inject data into log messages | https://www.ibm.com/support/pages/node/7284359 2026-09-03 | CVE-2026-9744 CVE-2026-9744 | IBM | medium 5.3 | IBM Netezza Software: information disclosure | https://www.ibm.com/support/pages/node/7284359 2026-09-03 | CVE-2026-9745 CVE-2026-9745 | IBM | medium 6.5 | IBM Netezza Software: remote attacker could exploit misconfigurations or naming | https://www.ibm.com/support/pages/node/7284359 2026-09-03 | CVE-2026-84185 CVE-2026-84185 | Red Hat | medium 5.9 | Red Hat Ansible Automation Platform 2: improper signature check | https://access.redhat.com/security/cve/CVE-2026-84185 2026-09-03 | CVE-2026-85053 CVE-2026-85053 | Google | high 8.8 | Google Chrome: remote code execution | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html 2026-09-03 | CVE-2026-85050 CVE-2026-85050 | Google | critical 9.6 | Google Chrome: out-of-bounds write | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html 2026-09-03 | CVE-2026-85051 CVE-2026-85051 | Google | high 8.8 | Google Chrome: type confusion | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html 2026-09-03 | CVE-2026-85052 CVE-2026-85052 | Google | low 3.1 | Google Chrome: out-of-bounds read | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html 2026-09-03 | CVE-2026-85048 CVE-2026-85048 | Google | high 8.3 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html 2026-09-03 | CVE-2026-85049 CVE-2026-85049 | Google | high 8.8 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html 2026-09-03 | CVE-2026-85046 CVE-2026-85046 | Google | high 8.8 | Google Chrome: type confusion | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html 2026-09-03 | CVE-2026-85047 CVE-2026-85047 | Google | critical 9.6 | Google Chrome: improper input validation | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html 2026-09-03 | CVE-2026-85043 CVE-2026-85043 | Google | critical 9.1 | Google Chrome: incomplete cleanup | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html 2026-09-03 | CVE-2026-85044 CVE-2026-85044 | Google | medium 6.5 | Google Chrome: use after expiry | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html 2026-09-03 | CVE-2026-85045 CVE-2026-85045 | Google | high 7.5 | Google Chrome: race condition | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html 2026-09-03 | CVE-2026-85042 CVE-2026-85042 | Google | critical 9.6 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html 2026-09-03 | CVE-2026-19795 CVE-2026-19795 | IBM | medium 6.2 | IBM Qiskit SDK: denial of service | https://www.ibm.com/support/pages/node/7285932 2026-09-03 | CVE-2026-82298 CVE-2026-82298 | Elastic | medium 4.3 | Elastic Kibana: improper authorization | https://discuss.elastic.co/t/kibana-8-19-21-9-4-6-9-5-3-security-update-esa-2026-174/390162 2026-09-03 | CVE-2026-82299 CVE-2026-82299 | Elastic | medium 6.5 | Elastic Kibana: improper authorization | https://discuss.elastic.co/t/kibana-9-4-6-9-5-3-security-update-esa-2026-175/390163 2026-09-03 | CVE-2026-82302 CVE-2026-82302 | Elastic | high 8.1 | Elastic Kibana: improper authorization | https://discuss.elastic.co/t/kibana-8-19-22-9-4-7-9-5-3-security-update-esa-2026-178/390164 2026-09-03 | CVE-2026-78583 CVE-2026-78583 | Elastic | high 8.1 | Elastic Kibana: improper authorization | https://discuss.elastic.co/t/kibana-8-19-21-9-4-6-9-5-3-security-update-esa-2026-140/390158 2026-09-03 | CVE-2026-78593 CVE-2026-78593 | Elastic | medium 4.3 | Elastic Kibana: code injection | https://discuss.elastic.co/t/kibana-8-19-21-9-4-6-9-5-3-security-update-esa-2026-151/390159 2026-09-03 | CVE-2026-78595 CVE-2026-78595 | Elastic | medium 4.3 | Elastic Kibana: missing authorization | https://discuss.elastic.co/t/kibana-9-4-6-9-5-3-security-update-esa-2026-153/390160 2026-09-03 | CVE-2026-78596 CVE-2026-78596 | Elastic | medium 4.3 | Elastic Kibana: missing authorization | https://discuss.elastic.co/t/kibana-8-19-21-9-4-6-9-5-3-security-update-esa-2026-154/390161 2026-09-03 | CVE-2026-15431 CVE-2026-15431 | HP Inc. | high 7.3 | HP Support Assistant: privilege escalation | https://support.hp.com/us-en/document/ish_15587742-15587765-16/hpsbgn04131 2026-09-03 | CVE-2026-83959 CVE-2026-83959 | Adobe | high 7.8 | Adobe Substance 3D Sampler: heap buffer overflow | https://helpx.adobe.com/security/products/substance3d-sampler/apsb26-121.html 2026-09-03 | GHSA-j29g-r9cq-fh35 CVE-2026-84962 | MongoDB | medium 5.7 | Authenticated KMS request forgery via CRLF injection in GCP key identifier strings | https://github.com/mongodb/libmongocrypt/security/advisories/GHSA-j29g-r9cq-fh35 2026-09-03 | GHSA-j5wj-7mj9-v673 CVE-2026-84968 | MongoDB | medium 6.9 | Heap out-of-bounds read via corrupt nested BSON in field path error message | https://github.com/mongodb/mongo-php-driver/security/advisories/GHSA-j5wj-7mj9-v673 2026-09-03 | GHSA-8g5h-p67q-9m5j CVE-2026-84971 | MongoDB | high 7.1 | Persistent client crash loop via undersized FLE2 insert-update ciphertext in decryption path | https://github.com/mongodb/libmongocrypt/security/advisories/GHSA-8g5h-p67q-9m5j 2026-09-03 | GHSA-7xfm-q62h-hhjf CVE-2026-84966 | MongoDB | medium 5.9 | BSON element injection via NUL-embedded document keys in builder append | https://github.com/mongodb/mongo-cxx-driver/security/advisories/GHSA-7xfm-q62h-hhjf 2026-09-03 | GHSA-3qc5-6fx3-whp6 CVE-2026-84970 | MongoDB | medium 5.9 | Heap over-read or silent misparse via 32-bit truncation of JSON length in BSON JSON parser | https://github.com/mongodb/mongo-cxx-driver/security/advisories/GHSA-3qc5-6fx3-whp6 2026-09-03 | GHSA-fqmh-x7gg-pfgw CVE-2026-84969 | MongoDB | medium 6.3 | Heap overflow via truncated base64 encoding of binary fields in length-limited JSON output | https://github.com/mongodb/mongo-c-driver/security/advisories/GHSA-fqmh-x7gg-pfgw 2026-09-03 | CVE-2026-84967 CVE-2026-84967 | MongoDB | medium 5.1 | MongoDB for VS Code: command injection | https://jira.mongodb.org/browse/VSCODE-798 2026-09-03 | CVE-2026-83961 CVE-2026-83961 | Adobe | high 7.1 | Adobe ColdFusion: improper authentication | https://helpx.adobe.com/security/products/coldfusion/apsb26-90.html 2026-09-03 | GHSA-8vwp-6h6c-hx6h CVE-2026-84963 | MongoDB | medium 6.3 | Silent field truncation via unchecked int cast of huge JSON string values in JSON-to-BSON parser | https://github.com/mongodb/mongo-c-driver/security/advisories/GHSA-8vwp-6h6c-hx6h 2026-09-03 | GHSA-fw3j-wh78-34mj CVE-2026-84964 | MongoDB | high 8.2 | Heap corruption via OCSP request double free from crafted multi-URL certificate in TLS client | https://github.com/mongodb/mongo-c-driver/security/advisories/GHSA-fw3j-wh78-34mj 2026-09-03 | GHSA-h2g7-2gxh-c5v2 CVE-2026-84965 | MongoDB | medium 5.9 | Heap write primitive via size round-up wrap during JSON parsing on 32-bit builds | https://github.com/mongodb/mongo-c-driver/security/advisories/GHSA-h2g7-2gxh-c5v2 2026-09-03 | CVE-2026-63694 CVE-2026-63694 | Dell Technologies | medium 5.0 | Dell Technologies SmartFabric OS10: command injection | https://www.dell.com/support/kbdoc/en-us/000501840/dsa-2026-322-security-update-for-dell-networking-os10-vulnerabilities 2026-09-03 | CVE-2026-35160 CVE-2026-35160 | Dell Technologies | medium 5.0 | Dell Technologies SmartFabric OS10 Software: command injection | https://www.dell.com/support/kbdoc/en-us/000501840/dsa-2026-322-security-update-for-dell-networking-os10-vulnerabilities 2026-09-03 | CVE-2026-85150 CVE-2026-85150 | Red Hat | high 7.5 | Red Hat Enterprise Linux 7: null pointer dereference | https://access.redhat.com/errata/RHSA-2026:66460 2026-09-03 | CVE-2026-85084 CVE-2026-85084 | Samsung | medium 6.3 | Samsung Open Source TizenFX Samsung/TizenFX: out-of-bounds write | https://github.com/Samsung/TizenFX/pull/7814 2026-09-03 | CVE-2026-80465 CVE-2026-80465 | Siemens | high 8.8 | Siemens Mendix SAML (Mendix: improper signature check | https://cert-portal.siemens.com/productcert/html/ssa-887643.html 2026-09-03 | CVE-2026-74768 CVE-2026-74768 | Dell Technologies | medium 4.1 | Dell Technologies PowerProtect Data Manager: server-side request forgery | https://www.dell.com/support/kbdoc/en-us/000501452/dsa-2026-368-security-update-for-dell-powerprotect-data-manager-multiple-vulnerabilities 2026-09-03 | CVE-2026-74769 CVE-2026-74769 | Dell Technologies | medium 6.5 | Dell Technologies PowerProtect Data Manager: improper authorization | https://www.dell.com/support/kbdoc/en-us/000501452/dsa-2026-368-security-update-for-dell-powerprotect-data-manager-multiple-vulnerabilities 2026-09-03 | CVE-2026-71222 CVE-2026-71222 | Red Hat | medium 5.3 | Red Hat gfs2-utils: out-of-bounds read | https://access.redhat.com/security/cve/CVE-2026-71222 2026-09-03 | CVE-2026-71224 CVE-2026-71224 | Red Hat | medium 4.7 | Red Hat gfs2-utils. The metadata walk code: denial of service | https://access.redhat.com/security/cve/CVE-2026-71224 2026-09-03 | CVE-2026-73600 CVE-2026-73600 | Dell Technologies | high 7.8 | Dell Technologies PowerProtect Data Manager: buffer overflow | https://www.dell.com/support/kbdoc/en-us/000501452/dsa-2026-368-security-update-for-dell-powerprotect-data-manager-multiple-vulnerabilities 2026-09-03 | CVE-2026-71219 CVE-2026-71219 | Red Hat | medium 4.7 | Red Hat gfs2-utils. The hash table traversal code: denial of service | https://access.redhat.com/security/cve/CVE-2026-71219 2026-09-03 | CVE-2026-71220 CVE-2026-71220 | Red Hat | high 7.0 | Red Hat gfs2-utils.: out-of-bounds write | https://access.redhat.com/security/cve/CVE-2026-71220 2026-09-03 | CVE-2026-71221 CVE-2026-71221 | Red Hat | high 7.0 | Red Hat gfs2-utils.: out-of-bounds write | https://access.redhat.com/security/cve/CVE-2026-71221 2026-09-03 | CVE-2026-68860 CVE-2026-68860 | Dell Technologies | medium 6.8 | Dell PowerProtect Data Manager | https://www.dell.com/support/kbdoc/en-us/000501452/dsa-2026-368-security-update-for-dell-powerprotect-data-manager-multiple-vulnerabilities 2026-09-03 | AWS-2026-096 CVE-2026-85028 | AWS | unknown | Creation of Temporary File in Directory with Insecure Permissions in AWS FPGA Development... | https://aws.amazon.com/security/security-bulletins/rss/2026-096-aws/ 2026-09-03 | AWS-2026-095 CVE-2026-85012 | AWS | unknown | OS command injection in the Amazon CodeCatalyst blueprints SDK | https://aws.amazon.com/security/security-bulletins/rss/2026-095-aws/ 2026-09-02 | GHSA-gv5w-hfx8-8cwq CVE-2026-72921 | seaweedfs | high 8.1 | SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling paths | https://github.com/advisories/GHSA-gv5w-hfx8-8cwq 2026-09-02 | GHSA-p3m8-78j2-g5p3 CVE-2026-62388 | NLTK | high | NLTK: Default ENFORCE=False Disables All pathsec Security Controls | https://github.com/advisories/GHSA-p3m8-78j2-g5p3 2026-09-02 | GHSA-3gqm-fcw5-w839 CVE-2026-63311 | NLTK | medium | NLTK: SSRF Fail-Open in validate_network_url() via DNS Resolution Failure | https://github.com/advisories/GHSA-3gqm-fcw5-w839 2026-09-02 | GHSA-2v6v-25fm-p4fg CVE-2026-72920 | seaweedfs | critical 9.8 | SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control | https://github.com/advisories/GHSA-2v6v-25fm-p4fg 2026-09-02 | GHSA-ww6m-cw3f-q94g CVE-2026-81722 | NLTK | medium | NLTK: Quadratic-time DoS in PorterStemmer via long runs of 'y' | https://github.com/advisories/GHSA-ww6m-cw3f-q94g 2026-09-02 | GHSA-f794-5jv7-7672 CVE-2026-81727 | NLTK | medium 7.1 | NLTK: Downloader.download follows hardlinks and overwrites outside-root files | https://github.com/advisories/GHSA-f794-5jv7-7672 2026-09-02 | GHSA-8mgp-746c-j5xp CVE-2026-81726 | NLTK | high 7.0 | NLTK: Model-artifact APIs bypass pathsec and touch files outside allowed roots | https://github.com/advisories/GHSA-8mgp-746c-j5xp 2026-09-02 | GHSA-vp2x-qp44-57v7 CVE-2026-81723 | NLTK | medium 3.7 | NLTK: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()` | https://github.com/advisories/GHSA-vp2x-qp44-57v7 2026-09-02 | GHSA-ff5c-cp5c-9wjf CVE-2026-12876 | NLTK | medium | NLTK: Uncontrolled resource consumption in RecursiveDescentParser via ambiguous or left-recursive grammars | https://github.com/advisories/GHSA-ff5c-cp5c-9wjf 2026-09-02 | GHSA-cw6x-m8jw-qmrh CVE-2026-81724 | NLTK | medium 5.3 | NLTK: uncontrolled recursion | https://github.com/advisories/GHSA-cw6x-m8jw-qmrh 2026-09-02 | PYSEC-2026-3966 CVE-2026-32773 | Apache Spark | medium 6.1 | Apache Spark: cross-site scripting | https://osv.dev/vulnerability/PYSEC-2026-3966 2026-09-02 | CVE-2023-20577 CVE-2023-20577 | AMD | high 7.4 | AMD: code execution | https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7009.html 2026-09-02 | CVE-2023-20576 CVE-2023-20576 | AMD | high 7.7 | AMD AGESA: denial of service | https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7009.html 2026-09-02 | CVE-2026-66786 CVE-2026-66786 | Red Hat | critical 9.1 | Red Hat Advanced Cluster Management for Kubernetes 2: remote code execution | https://access.redhat.com/errata/RHSA-2026:63016 2026-09-02 | CVE-2026-20355 CVE-2026-20355 | Cisco | medium 5.9 | Cisco Secure Email: insufficient authenticity check | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-smime-disc-dzw4rEdY 2026-09-02 | CVE-2026-20277 CVE-2026-20277 | Cisco | high 8.2 | Cisco IOS XR Software: protection mechanism failure | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM 2026-09-02 | CVE-2026-20278 CVE-2026-20278 | Cisco | high 8.8 | As part of Cisco's ongoing commitment to proactive security and product quality | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM 2026-09-02 | CVE-2026-20279 CVE-2026-20279 | Cisco | critical 9.8 | Cisco IOS XR Software: improper access control | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM 2026-09-02 | CVE-2026-20280 CVE-2026-20280 | Cisco | high 8.8 | Cisco IOS XR Software: unhandled exceptional condition | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM 2026-09-02 | CVE-2026-20281 CVE-2026-20281 | Cisco | high 7.5 | Cisco Session Initiation Protocol (SIP) Software: denial of service | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-phone-dos-txMYNRzv 2026-09-02 | CVE-2026-20354 CVE-2026-20354 | Cisco | medium 5.9 | Cisco Secure Email: unauthenticated, remote attacker could recover plain text | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-smime-disc-dzw4rEdY 2026-09-02 | CVE-2026-20274 CVE-2026-20274 | Cisco | critical 9.8 | As part of Cisco's ongoing commitment to proactive security and product quality | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM 2026-09-02 | CVE-2026-20275 CVE-2026-20275 | Cisco | high 8.8 | As part of Cisco's ongoing commitment to proactive security and product quality | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM 2026-09-02 | CVE-2026-20276 CVE-2026-20276 | Cisco | high 8.6 | As part of Cisco's ongoing commitment to proactive security and product quality | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM 2026-09-02 | CVE-2026-20212 CVE-2026-20212 | Cisco | critical 9.8 | Cisco NX-OS Software: remote code execution | https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-n9k-s1-rce-EH8dEtr 2026-09-02 | CVE-2026-84837 CVE-2026-84837 | Red Hat | high 7.8 | Red Hat rpm: command injection | https://access.redhat.com/security/cve/CVE-2026-84837 2026-09-02 | CVE-2026-84838 CVE-2026-84838 | Red Hat | high 7.8 | Red Hat Enterprise Linux 10: command injection | https://access.redhat.com/security/cve/CVE-2026-84838 2026-09-02 | CVE-2026-78689 CVE-2026-78689 | F5 | critical 9.2 | F5 NGINX JavaScript: out-of-bounds write | https://my.f5.com/manage/s/article/K000162602 2026-09-02 | CVE-2026-77180 CVE-2026-77180 | F5 | high 8.7 | When NGINX Ingress Controller is configured with Ingress annotations | https://my.f5.com/manage/s/article/K000162601 2026-09-02 | CVE-2026-78222 CVE-2026-78222 | F5 | high 8.7 | F5 NGINX JavaScript: denial of service | https://my.f5.com/manage/s/article/K000162603 2026-09-02 | CVE-2026-78408 CVE-2026-78408 | Red Hat | high 7.9 | The nsenter --join-cgroup option opens the target cgroup.procs file as root and... | https://access.redhat.com/errata/RHSA-2026:63162 2026-09-02 | CVE-2026-78409 CVE-2026-78409 | Red Hat | high 7.0 | Red Hat Enterprise Linux 10: link following | https://access.redhat.com/errata/RHSA-2026:63162 2026-09-02 | CVE-2026-78410 CVE-2026-78410 | Red Hat | high 7.8 | Red Hat util-linux: race condition | https://access.redhat.com/errata/RHSA-2026:63162 2026-09-02 | CVE-2026-63020 CVE-2026-63020 | F5 | low 2.3 | F5 BIG-IP: attacker could spoof error messages Impact: An attacker may | https://my.f5.com/manage/s/article/K000161728 2026-09-02 | CVE-2026-66362 CVE-2026-66362 | F5 | high 8.6 | Description: When NGINX Plus is configured as the data plane for NGINX Gateway... | https://my.f5.com/manage/s/article/K000162600 2026-09-02 | CVE-2026-66842 CVE-2026-66842 | F5 | high 8.7 | F5 BIG-IP: privilege escalation | https://my.f5.com/manage/s/article/K000162521 2026-09-02 | CVE-2026-19475 CVE-2026-19475 | Grafana Labs | medium 6.5 | Grafana OSS: denial of service | https://grafana.com/security/security-advisories/cve-2026-19475 2026-09-02 | CVE-2026-12704 CVE-2026-12704 | Grafana Labs | medium 6.8 | Grafana Enterprise: capture-replay | https://grafana.com/security/security-advisories/cve-2026-12704 2026-09-02 | CVE-2026-14199 CVE-2026-14199 | Grafana Labs | high 7.1 | Grafana: authentication bypass | https://grafana.com/security/security-advisories/cve-2026-14199 2026-09-02 | CVE-2026-18058 CVE-2026-18058 | Lenovo | high 7.3 | Lenovo Smart Connect Application: missing authorization | https://en-us.support.motorola.com/app/answers/detail/a_id/193303 2026-09-02 | CVE-2026-18329 CVE-2026-18329 | F5 | high 8.8 | Description NGINX JavaScript | https://my.f5.com/manage/s/article/K000162599 2026-09-02 | CVE-2026-82293 CVE-2026-82293 | Elastic | medium 4.3 | Elastic Kibana: improper authorization | https://discuss.elastic.co/t/kibana-8-19-21-9-4-6-9-5-2-security-update-esa-2026-169/390119 2026-09-02 | CVE-2026-78599 CVE-2026-78599 | Elastic | medium 6.5 | Elastic Kibana: path traversal | https://discuss.elastic.co/t/kibana-8-19-18-9-4-3-security-update-esa-2026-157/390112 2026-09-02 | CVE-2026-78600 CVE-2026-78600 | Elastic | low 3.5 | Elastic Eck Operator: incomplete cleanup | https://discuss.elastic.co/t/elastic-cloud-on-kubernetes-3-5-0-security-update-esa-2026-146/390106 2026-09-02 | CVE-2026-78601 CVE-2026-78601 | Elastic | medium 5.5 | Elastic Kibana: missing authorization | https://discuss.elastic.co/t/kibana-9-4-5-security-update-esa-2026-147/390107 2026-09-02 | CVE-2026-78602 CVE-2026-78602 | Elastic | medium 5.3 | Elastic Maps Server: path traversal | https://discuss.elastic.co/t/elastic-maps-server-8-19-19-9-4-4-9-5-1-security-update-esa-2026-148/390108 2026-09-02 | CVE-2026-78604 CVE-2026-78604 | Elastic | high 7.8 | Elastic Agent: insecure permissions | https://discuss.elastic.co/t/elastic-agent-8-19-21-9-4-6-9-5-2-security-update-esa-2026-150/390109 2026-09-02 | CVE-2026-78609 CVE-2026-78609 | Elastic | medium 5.4 | Elastic Eck Operator: improper authorization | https://discuss.elastic.co/t/elastic-cloud-on-kubernetes-3-5-0-security-update-esa-2026-145/390105 2026-09-02 | CVE-2026-78586 CVE-2026-78586 | Elastic | medium 6.5 | Elastic Kibana: denial of service | https://discuss.elastic.co/t/kibana-8-19-16-9-3-5-9-4-2-security-update-esa-2026-163/390116 2026-09-02 | CVE-2026-78587 CVE-2026-78587 | Elastic | low 3.1 | Elastic Fleet Server: improper authorization | https://discuss.elastic.co/t/fleet-server-8-19-16-9-3-5-9-4-2-security-update-esa-2026-164/390117 2026-09-02 | CVE-2026-78588 CVE-2026-78588 | Elastic | medium 6.5 | Elastic Filebeat: denial of service | https://discuss.elastic.co/t/filebeat-8-19-18-9-3-1-security-update-esa-2026-165/390118 2026-09-02 | CVE-2026-78590 CVE-2026-78590 | Elastic | high 7.3 | Elastic Kibana: path traversal | https://discuss.elastic.co/t/kibana-8-19-18-9-3-6-9-4-3-security-update-esa-2026-158/390113 2026-09-02 | CVE-2026-78591 CVE-2026-78591 | Elastic | medium 6.3 | Elastic Kibana: path traversal | https://discuss.elastic.co/t/kibana-8-19-17-9-3-6-9-4-3-security-update-esa-2026-159/390114 2026-09-02 | CVE-2026-78594 CVE-2026-78594 | Elastic | medium 4.9 | Elastic Apm Server: denial of service | https://discuss.elastic.co/t/apm-server-8-19-20-9-4-5-9-5-1-security-update-esa-2026-152/390110 2026-09-02 | CVE-2026-78598 CVE-2026-78598 | Elastic | medium 5.4 | Elastic Kibana: improper authorization | https://discuss.elastic.co/t/kibana-8-19-19-9-3-8-9-4-4-security-update-esa-2026-156/390111 2026-09-02 | CVE-2026-78584 CVE-2026-78584 | Elastic | medium 4.3 | Elastic Kibana: information disclosure | https://discuss.elastic.co/t/kibana-9-4-4-security-update-esa-2026-161/390115 2026-09-02 | CVE-2026-14255 CVE-2026-14255 | Autodesk | medium 5.5 | Autodesk Shared Components: denial of service | https://www.autodesk.com/products/autodesk-access/overview 2026-09-02 | GHSA-w8vq-gj3v-h664 | IBM | medium 6.4 | Scoped admin OAuth DCR endpoints ignore token_teams restrictions and expose global registered clients | https://github.com/IBM/mcp-context-forge/security/advisories/GHSA-w8vq-gj3v-h664 2026-09-02 | CVE-2026-19219 CVE-2026-19219 | Progress Software | high 8.1 | Progress Software Telerik UI for ASP.NET AJAX: remote code execution | https://www.telerik.com/products/aspnet-ajax/documentation/knowledge-base/kb-security-dialoghandler-uploadpaths-tampering-cve-2026-19219 2026-09-02 | CVE-2026-18672 CVE-2026-18672 | Progress Software | high 7.5 | Progress Software Telerik UI for ASP.NET AJAX: path traversal | https://www.telerik.com/products/aspnet-ajax/documentation/knowledge-base/kb-security-rie-path-traversal-cve-2026-18672 2026-09-02 | CVE-2026-53683 CVE-2026-53683 | Red Hat | medium 4.3 | Red Hat Enterprise Linux: open redirect | https://access.redhat.com/security/cve/CVE-2026-53683 2026-09-02 | CVE-2026-82968 CVE-2026-82968 | Red Hat | medium 6.4 | Red Hat Build of Keycloak: insecure direct object reference | https://access.redhat.com/security/cve/CVE-2026-82968 2026-09-02 | AWS-2026-094 CVE-2026-84851 | AWS | unknown | Uncontrolled recursion in the Ion reader in Amazon Ion-C before 1.1.6 | https://aws.amazon.com/security/security-bulletins/rss/2026-094-aws/ 2026-09-02 | CVE-2026-84352 CVE-2026-84352 | Google | critical 9.6 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html 2026-09-02 | CVE-2026-84353 CVE-2026-84353 | Google | critical 9.6 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html 2026-09-02 | CVE-2026-84354 CVE-2026-84354 | Google | critical 9.6 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html 2026-09-02 | CVE-2026-84355 CVE-2026-84355 | Google | low 3.1 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html 2026-09-02 | CVE-2026-84356 CVE-2026-84356 | Google | medium 4.3 | Google Chrome: spoofing | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html 2026-09-02 | CVE-2026-84357 CVE-2026-84357 | Google | medium 6.5 | Google Chrome: improper input validation | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html 2026-09-02 | CVE-2026-84358 CVE-2026-84358 | Google | medium 4.2 | Google Chrome: improper privilege management | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html 2026-09-02 | CVE-2026-84359 CVE-2026-84359 | Google | low 3.1 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html 2026-09-02 | CVE-2026-84332 CVE-2026-84332 | Google | medium 6.5 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html 2026-09-02 | CVE-2026-84333 CVE-2026-84333 | Google | critical 9.6 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html 2026-09-02 | CVE-2026-84334 CVE-2026-84334 | Google | high 8.1 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html 2026-09-02 | CVE-2026-84335 CVE-2026-84335 | Google | high 8.3 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html 2026-09-02 | CVE-2026-84347 CVE-2026-84347 | Google | high 8.8 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html 2026-09-02 | CVE-2026-84348 CVE-2026-84348 | Google | medium 6.5 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html 2026-09-02 | CVE-2026-84349 CVE-2026-84349 | Google | high 8.3 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html 2026-09-02 | CVE-2026-84350 CVE-2026-84350 | Google | high 8.8 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html 2026-09-02 | CVE-2026-84351 CVE-2026-84351 | Google | high 8.3 | Google Chrome: buffer overflow | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html 2026-09-02 | CVE-2026-84323 CVE-2026-84323 | Google | medium 5.3 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html 2026-09-02 | CVE-2026-84324 CVE-2026-84324 | Google | critical 9.0 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html 2026-09-02 | CVE-2026-84325 CVE-2026-84325 | Google | critical 9.8 | Google Chrome: improper input validation | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html 2026-09-02 | CVE-2026-84326 CVE-2026-84326 | Google | high 8.8 | Google Chrome: remote code execution | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html 2026-09-02 | CVE-2026-84327 CVE-2026-84327 | Google | medium 6.5 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html 2026-09-02 | CVE-2026-84328 CVE-2026-84328 | Google | low 3.1 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html 2026-09-02 | CVE-2026-84329 CVE-2026-84329 | Google | medium 5.3 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html 2026-09-02 | CVE-2026-84330 CVE-2026-84330 | Google | medium 5.4 | Google Chrome: spoofing | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html 2026-09-02 | CVE-2026-84331 CVE-2026-84331 | Google | low 3.1 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html 2026-09-01 | GHSA-m4rf-3fr8-xwx3 CVE-2026-79675 | NLTK | critical 9.8 | NLTK: argument injection | https://github.com/advisories/GHSA-m4rf-3fr8-xwx3 2026-09-01 | GHSA-6hwm-xvph-95vm CVE-2026-78680 | NLTK | high 7.8 | NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary | https://github.com/advisories/GHSA-6hwm-xvph-95vm 2026-09-01 | GHSA-gqvg-gmmx-x4hm | MLflow | high 8.8 | MLflow: unsafe deserialization | https://github.com/advisories/GHSA-gqvg-gmmx-x4hm 2026-09-01 | CVE-2026-76851 CVE-2026-76851 | GitHub | high 7.7 | GitHub Enterprise Server: server-side request forgery | https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.20 2026-09-01 | CVE-2026-83548 CVE-2026-83548 | SonicWall | critical 10.0 | SonicWall SMA1000: server-side request forgery | https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016 2026-09-01 | CVE-2026-83549 CVE-2026-83549 | SonicWall | high 7.8 | SonicWall SMA1000: command injection | https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016 2026-09-01 | CVE-2026-19118 CVE-2026-19118 | GitHub | high 7.7 | GitHub Enterprise Server: race condition | https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.20 2026-09-01 | CVE-2026-18730 CVE-2026-18730 | GitHub | high 8.2 | GitHub Enterprise Server: server-side request forgery | https://docs.github.com/en/enterprise-server@3.17/admin/release-notes#3.17.21 2026-09-01 | GHSA-vx62-cvr5-x3p4 | Google | medium | Cross-Frame Scripting (XFS) via Background Proxy in Vimium | https://github.com/google/security-research/security/advisories/GHSA-vx62-cvr5-x3p4 2026-09-01 | CVE-2026-84470 CVE-2026-84470 | Red Hat | medium 6.4 | Red Hat Ansible Automation Platform: missing authorization | https://access.redhat.com/errata/RHSA-2026:71113 2026-09-01 | CVE-2026-73782 CVE-2026-73782 | Hewlett Packard Enterprise | high 8.8 | Hewlett Packard Enterprise AOS-CX: remote code execution | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US 2026-09-01 | CVE-2026-73783 CVE-2026-73783 | Hewlett Packard Enterprise | medium 4.9 | Hewlett Packard Enterprise AOS-CX: denial of service | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US 2026-09-01 | CVE-2026-73773 CVE-2026-73773 | Hewlett Packard Enterprise | high 7.5 | Hewlett Packard Enterprise AOS-CX: denial of service | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US 2026-09-01 | CVE-2026-73774 CVE-2026-73774 | Hewlett Packard Enterprise | high 7.6 | Hewlett Packard Enterprise AOS-CX: buffer overflow | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US 2026-09-01 | CVE-2026-73775 CVE-2026-73775 | Hewlett Packard Enterprise | high 7.7 | Hewlett Packard Enterprise AOS-CX: information disclosure | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US 2026-09-01 | CVE-2026-73776 CVE-2026-73776 | Hewlett Packard Enterprise | high 7.9 | Hewlett Packard Enterprise AOS-CX: code execution | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US 2026-09-01 | CVE-2026-73777 CVE-2026-73777 | Hewlett Packard Enterprise | high 8.1 | Hewlett Packard Enterprise AOS-CX: improper authentication | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US 2026-09-01 | CVE-2026-73778 CVE-2026-73778 | Hewlett Packard Enterprise | high 8.1 | Hewlett Packard Enterprise AOS-CX: weak password rules | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US 2026-09-01 | CVE-2026-73779 CVE-2026-73779 | Hewlett Packard Enterprise | high 8.2 | Hewlett Packard Enterprise AOS-CX: information disclosure | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US 2026-09-01 | CVE-2026-73780 CVE-2026-73780 | Hewlett Packard Enterprise | high 8.3 | Hewlett Packard Enterprise AOS-CX: cross-site request forgery | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US 2026-09-01 | CVE-2026-73781 CVE-2026-73781 | Hewlett Packard Enterprise | high 8.4 | Hewlett Packard Enterprise AOS-CX: cross-site scripting | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US 2026-09-01 | CVE-2026-73763 CVE-2026-73763 | Hewlett Packard Enterprise | high 7.1 | Hewlett Packard Enterprise AOS-CX: remote code execution | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US 2026-09-01 | CVE-2026-73764 CVE-2026-73764 | Hewlett Packard Enterprise | high 7.1 | Hewlett Packard Enterprise AOS-CX: improper authentication | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US 2026-09-01 | CVE-2026-73765 CVE-2026-73765 | Hewlett Packard Enterprise | high 7.2 | Hewlett Packard Enterprise AOS-CX: path traversal | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US 2026-09-01 | CVE-2026-73766 CVE-2026-73766 | Hewlett Packard Enterprise | high 7.2 | Hewlett Packard Enterprise AOS-CX: command injection | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US 2026-09-01 | CVE-2026-73767 CVE-2026-73767 | Hewlett Packard Enterprise | high 7.2 | Hewlett Packard Enterprise AOS-CX: command injection | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US 2026-09-01 | CVE-2026-73768 CVE-2026-73768 | Hewlett Packard Enterprise | high 7.3 | Hewlett Packard Enterprise AOS-CX: improper input validation | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US 2026-09-01 | CVE-2026-73770 CVE-2026-73770 | Hewlett Packard Enterprise | high 7.3 | Hewlett Packard Enterprise AOS-CX: arbitrary file write | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US 2026-09-01 | CVE-2026-73771 CVE-2026-73771 | Hewlett Packard Enterprise | high 7.5 | Hewlett Packard Enterprise AOS-CX: improper authentication | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US 2026-09-01 | CVE-2026-73772 CVE-2026-73772 | Hewlett Packard Enterprise | medium 6.5 | Hewlett Packard Enterprise AOS-CX: buffer overflow | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US 2026-09-01 | CVE-2026-73755 CVE-2026-73755 | Hewlett Packard Enterprise | medium 5.7 | Hewlett Packard Enterprise AOS-CX: privilege escalation | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US 2026-09-01 | CVE-2026-73756 CVE-2026-73756 | Hewlett Packard Enterprise | medium 5.9 | Hewlett Packard Enterprise AOS-CX: information disclosure | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US 2026-09-01 | CVE-2026-73757 CVE-2026-73757 | Hewlett Packard Enterprise | medium 6.4 | Hewlett Packard Enterprise AOS-CX: server-side request forgery | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US 2026-09-01 | CVE-2026-73758 CVE-2026-73758 | Hewlett Packard Enterprise | medium 6.5 | Hewlett Packard Enterprise AOS-CX: privilege escalation | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US 2026-09-01 | CVE-2026-73759 CVE-2026-73759 | Hewlett Packard Enterprise | medium 6.5 | Hewlett Packard Enterprise AOS-CX: denial of service | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US 2026-09-01 | CVE-2026-73760 CVE-2026-73760 | Hewlett Packard Enterprise | medium 6.5 | Hewlett Packard Enterprise AOS-CX: path traversal | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US 2026-09-01 | CVE-2026-73761 CVE-2026-73761 | Hewlett Packard Enterprise | medium 6.5 | Hewlett Packard Enterprise AOS-CX: out-of-bounds read | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US 2026-09-01 | CVE-2026-73762 CVE-2026-73762 | Hewlett Packard Enterprise | medium 6.6 | Hewlett Packard Enterprise AOS-CX: improper access control | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US 2026-09-01 | CVE-2026-73749 CVE-2026-73749 | Hewlett Packard Enterprise | critical 9.8 | Hewlett Packard Enterprise AOS-CX: remote code execution | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US 2026-09-01 | CVE-2026-73750 CVE-2026-73750 | Hewlett Packard Enterprise | high 8.8 | Hewlett Packard Enterprise AOS-CX: denial of service | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US 2026-09-01 | CVE-2026-73751 CVE-2026-73751 | Hewlett Packard Enterprise | high 8.8 | Hewlett Packard Enterprise AOS-CX: code execution | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US 2026-09-01 | CVE-2026-73752 CVE-2026-73752 | Hewlett Packard Enterprise | high 8.8 | Hewlett Packard Enterprise AOS-CX: arbitrary file write | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US 2026-09-01 | CVE-2026-73753 CVE-2026-73753 | Hewlett Packard Enterprise | high 8.8 | Hewlett Packard Enterprise AOS-CX: code execution | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US 2026-09-01 | CVE-2026-73754 CVE-2026-73754 | Hewlett Packard Enterprise | medium 5.3 | Hewlett Packard Enterprise AOS-CX: denial of service | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US 2026-09-01 | CVE-2026-78607 CVE-2026-78607 | Elastic | medium 5.4 | Elasticsearch: missing authorization | https://discuss.elastic.co/t/elasticsearch-8-19-19-9-3-8-9-4-4-9-5-1-security-update-esa-2026-143/390094 2026-09-01 | CVE-2026-78608 CVE-2026-78608 | Elastic | medium 6.5 | Elastic Kibana: missing authorization | https://discuss.elastic.co/t/kibana-8-19-21-9-4-6-9-5-2-security-update-esa-2026-144/390064 2026-09-01 | CVE-2026-76658 CVE-2026-76658 | Hewlett Packard Enterprise | critical 10.0 | Hewlett Packard Enterprise Fabric Composer: remote code execution | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-78592 CVE-2026-78592 | Elastic | high 7.3 | Elastic Kibana: path traversal | https://discuss.elastic.co/t/kibana-8-19-16-9-3-5-9-4-2-security-update-esa-2026-160/390077 2026-09-01 | CVE-2026-78597 CVE-2026-78597 | Elastic | medium 4.3 | Elastic Kibana: missing authorization | https://discuss.elastic.co/t/kibana-8-19-21-9-4-6-security-update-esa-2026-155/390072 2026-09-01 | CVE-2026-78603 CVE-2026-78603 | Elastic | medium 4.3 | Elastic Kibana: missing authorization | https://discuss.elastic.co/t/kibana-9-4-6-9-5-1-security-update-esa-2026-149/390069 2026-09-01 | CVE-2026-78605 CVE-2026-78605 | Elastic | medium 5.9 | Elasticsearch: request smuggling | https://discuss.elastic.co/t/elasticsearch-8-19-20-9-4-5-9-5-1-security-update-esa-2026-141/390092 2026-09-01 | CVE-2026-78606 CVE-2026-78606 | Elastic | medium 4.2 | Elastic Kibana: improper authorization | https://discuss.elastic.co/t/kibana-8-19-21-9-4-6-9-5-2-security-update-esa-2026-142/390093 2026-09-01 | CVE-2026-73744 CVE-2026-73744 | Hewlett Packard Enterprise | low 3.5 | Hewlett Packard Enterprise Fabric Composer: denial of service | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-73745 CVE-2026-73745 | Hewlett Packard Enterprise | low 3.1 | Hewlett Packard Enterprise Fabric Composer: information disclosure | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-73746 CVE-2026-73746 | Hewlett Packard Enterprise | low 3.1 | Hewlett Packard Enterprise Fabric Composer: denial of service | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-73747 CVE-2026-73747 | Hewlett Packard Enterprise | low 2.5 | Hewlett Packard Enterprise Fabric Composer: privilege escalation | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-73748 CVE-2026-73748 | Hewlett Packard Enterprise | low 2.2 | Hewlett Packard Enterprise Fabric Composer: information disclosure | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-76657 CVE-2026-76657 | Hewlett Packard Enterprise | critical 10.0 | Hewlett Packard Enterprise Fabric Composer: improper authentication | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-73734 CVE-2026-73734 | Hewlett Packard Enterprise | medium 5.4 | Hewlett Packard Enterprise Fabric Composer: open redirect | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-73735 CVE-2026-73735 | Hewlett Packard Enterprise | medium 5.4 | Hewlett Packard Enterprise Fabric Composer: exposed files | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-73736 CVE-2026-73736 | Hewlett Packard Enterprise | medium 5.3 | Hewlett Packard Enterprise Fabric Composer: exposed files | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-73737 CVE-2026-73737 | Hewlett Packard Enterprise | medium 4.8 | Hewlett Packard Enterprise Fabric Composer: path traversal | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-73738 CVE-2026-73738 | Hewlett Packard Enterprise | medium 4.7 | Hewlett Packard Enterprise Fabric Composer: information disclosure | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-73739 CVE-2026-73739 | Hewlett Packard Enterprise | medium 4.4 | Hewlett Packard Enterprise Fabric Composer: information disclosure | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-73740 CVE-2026-73740 | Hewlett Packard Enterprise | medium 4.4 | Hewlett Packard Enterprise Fabric Composer: privilege escalation | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-73741 CVE-2026-73741 | Hewlett Packard Enterprise | medium 4.3 | Hewlett Packard Enterprise Fabric: attacker could access limited data beyond... | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-73742 CVE-2026-73742 | Hewlett Packard Enterprise | medium 4.3 | Hewlett Packard Enterprise Fabric Composer: authentication bypass by spoofing | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-73743 CVE-2026-73743 | Hewlett Packard Enterprise | low 3.7 | Hewlett Packard Enterprise Fabric Composer: cleartext transmission | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-73725 CVE-2026-73725 | Hewlett Packard Enterprise | high 7.0 | Hewlett Packard Enterprise Fabric Composer: privilege escalation | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-73726 CVE-2026-73726 | Hewlett Packard Enterprise | medium 6.8 | Hewlett Packard Enterprise Fabric Composer: missing authentication | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-73727 CVE-2026-73727 | Hewlett Packard Enterprise | medium 6.5 | Hewlett Packard Enterprise Fabric Composer: information disclosure | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-73728 CVE-2026-73728 | Hewlett Packard Enterprise | medium 6.5 | Hewlett Packard Enterprise Fabric Composer: denial of service | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-73729 CVE-2026-73729 | Hewlett Packard Enterprise | medium 6.5 | Hewlett Packard Enterprise Fabric Composer: information disclosure | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-73730 CVE-2026-73730 | Hewlett Packard Enterprise | medium 6.5 | Hewlett Packard Enterprise Fabric Composer: privilege escalation | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-73731 CVE-2026-73731 | Hewlett Packard Enterprise | medium 6.1 | Hewlett Packard Enterprise Fabric Composer: cross-site scripting | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-73732 CVE-2026-73732 | Hewlett Packard Enterprise | medium 5.6 | Hewlett Packard Enterprise Fabric Composer: information disclosure | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-73733 CVE-2026-73733 | Hewlett Packard Enterprise | medium 5.4 | Hewlett Packard Enterprise Fabric Composer: improper authentication | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-73716 CVE-2026-73716 | Hewlett Packard Enterprise | high 7.5 | Hewlett Packard Enterprise Fabric Composer: remote code execution | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-73717 CVE-2026-73717 | Hewlett Packard Enterprise | high 7.5 | Hewlett Packard Enterprise Fabric Composer: command injection | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-73718 CVE-2026-73718 | Hewlett Packard Enterprise | high 7.4 | Hewlett Packard Enterprise Fabric Composer: information disclosure | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-73719 CVE-2026-73719 | Hewlett Packard Enterprise | high 7.2 | Hewlett Packard Enterprise Fabric Composer: arbitrary file write | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-73720 CVE-2026-73720 | Hewlett Packard Enterprise | high 7.2 | Hewlett Packard Enterprise Fabric Composer: remote code execution | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-73721 CVE-2026-73721 | Hewlett Packard Enterprise | high 7.2 | Hewlett Packard Enterprise Fabric Composer: SQL injection | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-73722 CVE-2026-73722 | Hewlett Packard Enterprise | high 7.2 | Hewlett Packard Enterprise Fabric Composer: command injection | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-73723 CVE-2026-73723 | Hewlett Packard Enterprise | high 7.1 | Hewlett Packard Enterprise Fabric Composer: privilege escalation | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-73724 CVE-2026-73724 | Hewlett Packard Enterprise | high 7.1 | Hewlett Packard Enterprise Fabric Composer: privilege escalation | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-73707 CVE-2026-73707 | Hewlett Packard Enterprise | high 8.5 | Hewlett Packard Enterprise Fabric Composer: privilege escalation | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-73708 CVE-2026-73708 | Hewlett Packard Enterprise | high 8.3 | Hewlett Packard Enterprise Fabric Composer: improper authorization | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-73709 CVE-2026-73709 | Hewlett Packard Enterprise | high 8.3 | Hewlett Packard Enterprise Fabric Composer: remote code execution | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-73710 CVE-2026-73710 | Hewlett Packard Enterprise | high 8.2 | Hewlett Packard Enterprise Fabric Composer: denial of service | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-73711 CVE-2026-73711 | Hewlett Packard Enterprise | high 8.1 | Hewlett Packard Enterprise Fabric Composer: privilege escalation | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-73712 CVE-2026-73712 | Hewlett Packard Enterprise | high 8.1 | Hewlett Packard Enterprise Fabric Composer: remote code execution | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-73713 CVE-2026-73713 | Hewlett Packard Enterprise | high 7.8 | Hewlett Packard Enterprise Fabric Composer: privilege escalation | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-73714 CVE-2026-73714 | Hewlett Packard Enterprise | high 7.6 | Hewlett Packard Enterprise Fabric Composer: information disclosure | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-73715 CVE-2026-73715 | Hewlett Packard Enterprise | high 7.5 | Hewlett Packard Enterprise Fabric Composer: denial of service | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-72654 CVE-2026-72654 | Elastic | medium 6.5 | Elastic Kibana: information disclosure | https://discuss.elastic.co/t/kibana-8-19-21-9-4-6-9-5-2-security-update-esa-2026-135/390091 2026-09-01 | CVE-2026-72682 CVE-2026-72682 | Elastic | medium 6.5 | Elastic Kibana: denial of service | https://discuss.elastic.co/t/kibana-9-4-6-security-update-esa-2026-84/390054 2026-09-01 | CVE-2026-73700 CVE-2026-73700 | Hewlett Packard Enterprise | critical 9.0 | Hewlett Packard Enterprise Fabric Composer: cross-site scripting | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-73701 CVE-2026-73701 | Hewlett Packard Enterprise | critical 9.0 | Hewlett Packard Enterprise Fabric Composer: remote code execution | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-73702 CVE-2026-73702 | Hewlett Packard Enterprise | high 8.8 | Hewlett Packard Enterprise Fabric Composer: privilege escalation | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-73703 CVE-2026-73703 | Hewlett Packard Enterprise | high 8.8 | Hewlett Packard Enterprise Fabric Composer: cross-site scripting | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-73704 CVE-2026-73704 | Hewlett Packard Enterprise | high 8.8 | Hewlett Packard Enterprise Fabric Composer: command injection | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-73705 CVE-2026-73705 | Hewlett Packard Enterprise | high 8.8 | Hewlett Packard Enterprise Fabric Composer: arbitrary file write | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-73706 CVE-2026-73706 | Hewlett Packard Enterprise | high 8.6 | Hewlett Packard Enterprise Fabric Composer: missing authentication | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-72628 CVE-2026-72628 | Elastic | medium 6.5 | Elastic Kibana: denial of service | https://discuss.elastic.co/t/kibana-8-19-21-9-4-6-9-5-2-security-update-esa-2026-125/390090 2026-09-01 | CVE-2026-72633 CVE-2026-72633 | Elastic | medium 4.3 | Elastic Kibana: improper authorization | https://discuss.elastic.co/t/kibana-9-4-6-9-5-2-security-update-esa-2026-130/390059 2026-09-01 | CVE-2026-72641 CVE-2026-72641 | Elastic | medium 5.4 | Elastic Kibana: improper authorization | https://discuss.elastic.co/t/kibana-9-4-6-9-5-1-security-update-esa-2026-122/390089 2026-09-01 | CVE-2026-72644 CVE-2026-72644 | Elastic | medium 6.5 | Elastic Kibana: denial of service | https://discuss.elastic.co/t/kibana-9-4-5-9-5-1-security-update-esa-2026-115/390088 2026-09-01 | CVE-2026-72649 CVE-2026-72649 | Elastic | high 8.8 | Elasticsearch: unsafe deserialization | https://discuss.elastic.co/t/elasticsearch-8-19-20-9-4-5-9-5-1-security-update-esa-2026-114/390087 2026-09-01 | CVE-2026-72652 CVE-2026-72652 | Elastic | medium 6.5 | Elastic Kibana: denial of service | https://discuss.elastic.co/t/kibana-8-19-19-9-3-5-security-update-esa-2026-48/390085 2026-09-01 | CVE-2026-63137 CVE-2026-63137 | Elastic | high 8.3 | Elastic Kibana: improper authorization | https://discuss.elastic.co/t/kibana-9-4-3-security-update-esa-2026-61/390086 2026-09-01 | CVE-2026-63138 CVE-2026-63138 | Elastic | medium 6.5 | Elastic Kibana: information disclosure | https://discuss.elastic.co/t/kibana-9-4-5-9-5-1-security-update-esa-2026-168/390082 2026-09-01 | CVE-2026-56143 CVE-2026-56143 | Elastic | medium 4.9 | Elasticsearch: denial of service | https://discuss.elastic.co/t/elasticsearch-8-19-20-9-3-0-security-update-esa-2026-47/390084 2026-09-01 | CVE-2026-33465 CVE-2026-33465 | Elastic | medium 6.5 | Elastic Kibana: denial of service | https://discuss.elastic.co/t/kibana-8-19-17-9-3-0-security-update-esa-2026-31/390050 2026-09-01 | CVE-2026-19766 CVE-2026-19766 | Hewlett Packard Enterprise | critical 9.6 | Hewlett Packard Enterprise Fabric Composer: authentication bypass | https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05133en_us&docLocale=en_US 2026-09-01 | CVE-2026-19590 CVE-2026-19590 | OpenAI | high 7.3 | OpenAI Codex Desktop: uncontrolled search path | https://github.com/openai/codex/pull/22843 2026-09-01 | CVE-2026-19591 CVE-2026-19591 | OpenAI | high 8.8 | OpenAI Codex CLI for Windows | https://github.com/openai/codex/pull/22643 2026-09-01 | CVE-2026-19592 CVE-2026-19592 | OpenAI | high 7.3 | OpenAI Codex CLI for Windows | https://github.com/openai/codex/pull/22652 2026-09-01 | CVE-2026-19593 CVE-2026-19593 | OpenAI | critical 9.8 | OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata... | https://openai.com/codex 2026-09-01 | CVE-2026-58566 CVE-2026-58566 | Dell Technologies | high 8.8 | Dell Technologies PowerStore: improper authorization | https://www.dell.com/support/kbdoc/en-us/000497829/dsa-2026-330-dell-powerstore-t-security-update-for-multiple-vulnerabilities 2026-09-01 | CVE-2026-84267 CVE-2026-84267 | Red Hat | medium 4.3 | Red Hat SFTP backend: uninitialized resource | https://access.redhat.com/security/cve/CVE-2026-84267 2026-09-01 | CVE-2026-84268 CVE-2026-84268 | Red Hat | high 8.8 | Red Hat SFTP backend: denial of service | https://access.redhat.com/security/cve/CVE-2026-84268 2026-09-01 | CVE-2026-84269 CVE-2026-84269 | Red Hat | medium 6.5 | Red Hat AFP backend: denial of service | https://access.redhat.com/security/cve/CVE-2026-84269 2026-09-01 | CVE-2026-84270 CVE-2026-84270 | Red Hat | medium 4.3 | Red Hat MTP backend: denial of service | https://access.redhat.com/security/cve/CVE-2026-84270 2026-09-01 | CVE-2026-84232 CVE-2026-84232 | Red Hat | medium 5.4 | Red Hat pulpcore: cross-site scripting | https://access.redhat.com/security/cve/CVE-2026-84232 2026-09-01 | CVE-2026-79687 CVE-2026-79687 | Dell Technologies | critical 9.0 | Dell Technologies PowerStore: missing authentication | https://www.dell.com/support/kbdoc/en-us/000497829/dsa-2026-330-dell-powerstore-t-security-update-for-multiple-vulnerabilities 2026-09-01 | CVE-2026-79682 CVE-2026-79682 | Dell Technologies | high 8.8 | Dell Technologies PowerStore: command injection | https://www.dell.com/support/kbdoc/en-us/000497829/dsa-2026-330-dell-powerstore-t-security-update-for-multiple-vulnerabilities 2026-09-01 | CVE-2026-61775 CVE-2026-61775 | Nvidia | high 7.8 | Nvidia Megatron Bridge: unsafe deserialization | https://github.com/NVIDIA/product-security/tree/main/2026/5868 2026-09-01 | CVE-2026-61776 CVE-2026-61776 | Nvidia | high 7.8 | Nvidia Megatron Bridge: unsafe deserialization | https://github.com/NVIDIA/product-security/tree/main/2026/5868 2026-09-01 | CVE-2026-61777 CVE-2026-61777 | Nvidia | high 7.8 | Nvidia Megatron Bridge: unsafe deserialization | https://github.com/NVIDIA/product-security/tree/main/2026/5868 2026-09-01 | CVE-2026-61778 CVE-2026-61778 | Nvidia | high 7.8 | Nvidia Megatron Bridge: unsafe deserialization | https://github.com/NVIDIA/product-security/tree/main/2026/5868 2026-09-01 | CVE-2026-61779 CVE-2026-61779 | Nvidia | high 7.8 | Nvidia Megatron Bridge: unsafe deserialization | https://github.com/NVIDIA/product-security/tree/main/2026/5868 2026-09-01 | CVE-2026-61773 CVE-2026-61773 | Nvidia | high 7.8 | Nvidia Megatron Bridge: unsafe deserialization | https://github.com/NVIDIA/product-security/tree/main/2026/5868 2026-09-01 | CVE-2026-61774 CVE-2026-61774 | Nvidia | high 7.8 | Nvidia Megatron Bridge: unsafe deserialization | https://github.com/NVIDIA/product-security/tree/main/2026/5868 2026-09-01 | CVE-2026-61769 CVE-2026-61769 | Nvidia | high 7.8 | Nvidia Megatron Bridge: unsafe deserialization | https://github.com/NVIDIA/product-security/tree/main/2026/5868 2026-09-01 | CVE-2026-61770 CVE-2026-61770 | Nvidia | high 7.8 | Nvidia Megatron Bridge: unsafe deserialization | https://github.com/NVIDIA/product-security/tree/main/2026/5868 2026-09-01 | CVE-2026-61771 CVE-2026-61771 | Nvidia | high 7.8 | Nvidia Megatron Bridge: unsafe deserialization | https://github.com/NVIDIA/product-security/tree/main/2026/5868 2026-09-01 | CVE-2026-61772 CVE-2026-61772 | Nvidia | high 7.8 | Nvidia Megatron Bridge: unsafe deserialization | https://github.com/NVIDIA/product-security/tree/main/2026/5868 2026-09-01 | CVE-2026-61760 CVE-2026-61760 | Nvidia | high 7.8 | Nvidia Megatron Bridge: unsafe deserialization | https://github.com/NVIDIA/product-security/tree/main/2026/5868 2026-09-01 | CVE-2026-61761 CVE-2026-61761 | Nvidia | high 7.8 | Nvidia Megatron Bridge: unsafe deserialization | https://github.com/NVIDIA/product-security/tree/main/2026/5868 2026-09-01 | CVE-2026-61762 CVE-2026-61762 | Nvidia | high 7.8 | Nvidia Megatron Bridge: unsafe deserialization | https://github.com/NVIDIA/product-security/tree/main/2026/5868 2026-09-01 | CVE-2026-61763 CVE-2026-61763 | Nvidia | high 7.8 | Nvidia Megatron Bridge: unsafe deserialization | https://github.com/NVIDIA/product-security/tree/main/2026/5868 2026-09-01 | CVE-2026-61764 CVE-2026-61764 | Nvidia | high 7.8 | Nvidia Megatron Bridge: unsafe deserialization | https://github.com/NVIDIA/product-security/tree/main/2026/5868 2026-09-01 | CVE-2026-61765 CVE-2026-61765 | Nvidia | high 7.8 | Nvidia Megatron Bridge: unsafe deserialization | https://github.com/NVIDIA/product-security/tree/main/2026/5868 2026-09-01 | CVE-2026-61766 CVE-2026-61766 | Nvidia | high 7.8 | Nvidia Megatron Bridge: unsafe deserialization | https://github.com/NVIDIA/product-security/tree/main/2026/5868 2026-09-01 | CVE-2026-61767 CVE-2026-61767 | Nvidia | high 7.8 | Nvidia Megatron Bridge: unsafe deserialization | https://github.com/NVIDIA/product-security/tree/main/2026/5868 2026-09-01 | CVE-2026-61768 CVE-2026-61768 | Nvidia | high 7.8 | Nvidia Megatron Bridge: unsafe deserialization | https://github.com/NVIDIA/product-security/tree/main/2026/5868 2026-09-01 | CVE-2026-61751 CVE-2026-61751 | Nvidia | high 7.8 | Nvidia Megatron Bridge: unsafe deserialization | https://github.com/NVIDIA/product-security/tree/main/2026/5868 2026-09-01 | CVE-2026-61752 CVE-2026-61752 | Nvidia | high 7.8 | Nvidia Megatron Bridge: unsafe deserialization | https://github.com/NVIDIA/product-security/tree/main/2026/5868 2026-09-01 | CVE-2026-61753 CVE-2026-61753 | Nvidia | high 7.8 | Nvidia Megatron Bridge: unsafe deserialization | https://github.com/NVIDIA/product-security/tree/main/2026/5868 2026-09-01 | CVE-2026-61754 CVE-2026-61754 | Nvidia | high 7.8 | Nvidia Megatron Bridge: unsafe deserialization | https://github.com/NVIDIA/product-security/tree/main/2026/5868 2026-09-01 | CVE-2026-61755 CVE-2026-61755 | Nvidia | high 7.8 | Nvidia Megatron Bridge: unsafe deserialization | https://github.com/NVIDIA/product-security/tree/main/2026/5868 2026-09-01 | CVE-2026-61756 CVE-2026-61756 | Nvidia | high 7.8 | Nvidia Megatron Bridge: unsafe deserialization | https://github.com/NVIDIA/product-security/tree/main/2026/5868 2026-09-01 | CVE-2026-61757 CVE-2026-61757 | Nvidia | high 7.8 | Nvidia Megatron Bridge: unsafe deserialization | https://github.com/NVIDIA/product-security/tree/main/2026/5868 2026-09-01 | CVE-2026-61758 CVE-2026-61758 | Nvidia | high 7.8 | Nvidia Megatron Bridge: unsafe deserialization | https://github.com/NVIDIA/product-security/tree/main/2026/5868 2026-09-01 | CVE-2026-61759 CVE-2026-61759 | Nvidia | high 7.8 | Nvidia Megatron Bridge: unsafe deserialization | https://github.com/NVIDIA/product-security/tree/main/2026/5868 2026-09-01 | CVE-2026-61750 CVE-2026-61750 | Nvidia | high 7.8 | Nvidia Megatron Bridge: unsafe deserialization | https://github.com/NVIDIA/product-security/tree/main/2026/5868 2026-09-01 | CVE-2026-58567 CVE-2026-58567 | Dell Technologies | high 8.8 | Dell Technologies PowerStore: command injection | https://www.dell.com/support/kbdoc/en-us/000497829/dsa-2026-330-dell-powerstore-t-security-update-for-multiple-vulnerabilities 2026-09-01 | CVE-2026-49329 CVE-2026-49329 | Red Hat | high 7.5 | Red Hat OpenShift Container Platform 4: resource exhaustion | https://access.redhat.com/security/cve/CVE-2026-49329 2026-09-01 | CVE-2026-84233 CVE-2026-84233 | Red Hat | high 7.0 | Red Hat rpm. A local attacker: code execution | https://access.redhat.com/security/cve/CVE-2026-84233 2026-09-01 | CVE-2026-79685 CVE-2026-79685 | Dell Technologies | medium 6.5 | Dell Technologies PowerStore: argument injection | https://www.dell.com/support/kbdoc/en-us/000497829/dsa-2026-330-dell-powerstore-t-security-update-for-multiple-vulnerabilities 2026-09-01 | CVE-2026-79686 CVE-2026-79686 | Dell Technologies | high 8.8 | Dell Technologies PowerStore: protection mechanism failure | https://www.dell.com/support/kbdoc/en-us/000497829/dsa-2026-330-dell-powerstore-t-security-update-for-multiple-vulnerabilities 2026-09-01 | CVE-2026-58569 CVE-2026-58569 | Dell Technologies | high 8.8 | Dell Technologies PowerStore: code execution | https://www.dell.com/support/kbdoc/en-us/000497829/dsa-2026-330-dell-powerstore-t-security-update-for-multiple-vulnerabilities 2026-09-01 | CVE-2026-84218 CVE-2026-84218 | Red Hat | high 8.1 | Red Hat Jolokia: incomplete denylist | https://access.redhat.com/security/cve/CVE-2026-84218 2026-09-01 | CVE-2026-79684 CVE-2026-79684 | Dell Technologies | high 8.8 | Dell Technologies PowerStore: protection mechanism failure | https://www.dell.com/support/kbdoc/en-us/000497829/dsa-2026-330-dell-powerstore-t-security-update-for-multiple-vulnerabilities 2026-09-01 | CVE-2026-58571 CVE-2026-58571 | Dell Technologies | high 8.8 | Dell Technologies PowerStore: command injection | https://www.dell.com/support/kbdoc/en-us/000497829/dsa-2026-330-dell-powerstore-t-security-update-for-multiple-vulnerabilities 2026-09-01 | CVE-2026-58572 CVE-2026-58572 | Dell Technologies | high 8.8 | Dell Technologies PowerStore: code injection | https://www.dell.com/support/kbdoc/en-us/000497829/dsa-2026-330-dell-powerstore-t-security-update-for-multiple-vulnerabilities 2026-09-01 | CVE-2026-13336 CVE-2026-13336 | Schneider Electric | high 7.3 | Schneider Electric NetBotz 5 - 750/755: command injection | https://download.se.com/files?p_Doc_Ref=SEVD-2026-223-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-223-02.pdf 2026-09-01 | CVE-2026-13337 CVE-2026-13337 | Schneider Electric | medium 5.1 | Schneider Electric NetBotz 5 - 750/755: SQL injection | https://download.se.com/files?p_Doc_Ref=SEVD-2026-223-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-223-02.pdf 2026-09-01 | CVE-2026-13348 CVE-2026-13348 | Schneider Electric | medium 6.9 | Schneider Electric PowerChute Serial Shutdown: no brute-force limit | https://download.se.com/files?p_Doc_Ref=SEVD-2026-223-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2026-223-01.pdf 2026-09-01 | CVE-2024-14047 CVE-2024-14047 | Elastic | high 7.2 | Elastic Security: denial of service | https://discuss.elastic.co/t/winlogbeat-8-13-0-security-update-esa-2024-49/390044 2026-09-01 | CVE-2024-10085 CVE-2024-10085 | Schneider Electric | high 8.2 | Schneider Electric EcoStruxure: denial of service | https://download.se.com/files?p_Doc_Ref=SEVD-2025-287-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2025-287-01.pdf 2026-09-01 | CVE-2026-79683 CVE-2026-79683 | Dell Technologies | high 8.8 | Dell Technologies PowerStore: protection mechanism failure | https://www.dell.com/support/kbdoc/en-us/000497829/dsa-2026-330-dell-powerstore-t-security-update-for-multiple-vulnerabilities 2026-09-01 | CVE-2026-58575 CVE-2026-58575 | Dell Technologies | high 8.8 | Dell Technologies PowerStore: authentication bypass | https://www.dell.com/support/kbdoc/en-us/000497829/dsa-2026-330-dell-powerstore-t-security-update-for-multiple-vulnerabilities 2026-09-01 | CVE-2026-53682 CVE-2026-53682 | Red Hat | medium 5.3 | Red Hat Certificate System 9: system information exposure | https://access.redhat.com/security/cve/CVE-2026-53682 2026-09-01 | CVE-2026-76111 CVE-2026-76111 | Dell Technologies | high 8.8 | Dell Technologies PowerStore: improper authorization | https://www.dell.com/support/kbdoc/en-us/000497829/dsa-2026-330-dell-powerstore-t-security-update-for-multiple-vulnerabilities 2026-09-01 | CVE-2026-11873 CVE-2026-11873 | Red Hat | medium 6.5 | Red Hat Certificate System 9: resource exhaustion | https://access.redhat.com/security/cve/CVE-2026-11873 2026-09-01 | CVE-2026-10420 CVE-2026-10420 | Samsung | medium 5.5 | Samsung mTower: untrusted pointer dereference | https://github.com/Samsung/mTower/pull/252 2026-09-01 | CVE-2026-82926 CVE-2026-82926 | Samsung | medium 5.5 | Samsung mTower: null pointer dereference | https://github.com/Samsung/mTower/pull/248 2026-09-01 | CVE-2026-82927 CVE-2026-82927 | Samsung | medium 5.5 | Samsung mTower: untrusted pointer dereference | https://github.com/Samsung/mTower/pull/250 2026-09-01 | AWS-2026-093 CVE-2026-83551 | AWS | unknown | Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK | https://aws.amazon.com/security/security-bulletins/rss/2026-093-aws/ 2026-09-01 | CVE-2026-18743 CVE-2026-18743 | Red Hat | low 2.5 | Red Hat popt. This vulnerability: memory corruption | https://access.redhat.com/errata/RHSA-2026:56984 2026-08-31 | CVE-2026-83596 CVE-2026-83596 | Red Hat | high 8.8 | Red Hat WebKitGTK: memory corruption | https://access.redhat.com/errata/RHSA-2026:69098 2026-08-31 | CVE-2026-82346 CVE-2026-82346 | HP Inc. | high 7.0 | HP ImageDiags: privilege escalation | https://support.hp.com/us-en/document/ish_15572821-15572929-16/hpsbgn04143 2026-08-31 | CVE-2026-13732 CVE-2026-13732 | Red Hat | high 7.0 | Red Hat GDB: out-of-bounds write | https://access.redhat.com/security/cve/CVE-2026-13732 2026-08-31 | CVE-2023-20511 CVE-2023-20511 | AMD | medium 6.4 | AMD: double free | https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-6018.html 2026-08-31 | CVE-2023-31308 CVE-2023-31308 | AMD | low 3.3 | AMD: denial of service | https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-6018.html 2026-08-31 | CVE-2026-17615 CVE-2026-17615 | Red Hat | high 7.5 | Red Hat RESTEasy: XML external entity | https://access.redhat.com/errata/RHSA-2026:62515 2026-08-31 | CVE-2026-83492 CVE-2026-83492 | Tenable | medium 6.9 | Tenable Kubio AI Website Builder: improper input validation | https://www.tenable.com/security/research/tra-2026-58 2026-08-31 | CVE-2026-76763 CVE-2026-76763 | Red Hat | high 7.5 | Red Hat build of Quarkus: denial of service | https://access.redhat.com/security/cve/CVE-2026-76763 2026-08-31 | CVE-2026-12894 CVE-2026-12894 | Red Hat | high 8.8 | Red Hat Qute template engine: template injection | https://access.redhat.com/errata/RHSA-2026:62515 2026-08-31 | CVE-2026-82797 CVE-2026-82797 | Samsung | medium 5.5 | Samsung rlottie: uncontrolled recursion | https://github.com/Samsung/rlottie/pull/603 2026-08-31 | AWS-2026-092 CVE-2026-83497 | AWS | unknown | OpenSearch SQL Plugin - Unrestricted Java Deserialization in Cursor Pagination | https://aws.amazon.com/security/security-bulletins/rss/2026-092-aws/ 2026-08-31 | CVE-2026-19410 CVE-2026-19410 | Google Cloud | critical 9.4 | Google Cloud Build: improper authorization | https://docs.cloud.google.com/build/docs/release-notes#August_24_2026 2026-08-31 | CVE-2026-81624 CVE-2026-81624 | Red Hat | high 7.5 | Red Hat Enterprise Linux 10: resource exhaustion | https://access.redhat.com/security/cve/CVE-2026-81624 2026-08-31 | CVE-2026-58574 CVE-2026-58574 | Dell Technologies | critical 9.8 | Dell Technologies PowerStore: missing authentication | https://www.dell.com/support/kbdoc/en-us/000497829/dsa-2026-330-dell-powerstore-t-security-update-for-multiple-vulnerabilities 2026-08-31 | CVE-2026-40464 CVE-2026-40464 | Nokia | medium 5.4 | Nokia NSP: cross-site scripting | https://www.nokia.com/we-are-nokia/security/product-security-advisory/cve-2026-40464/ 2026-08-31 | CVE-2026-40465 CVE-2026-40465 | Nokia | medium 5.3 | Nokia NSP: open redirect | https://www.nokia.com/we-are-nokia/security/product-security-advisory/cve-2026-40465/ 2026-08-31 | CVE-2026-40463 CVE-2026-40463 | Nokia | high 7.6 | Nokia WaveSuite: improper access control | https://www.nokia.com/we-are-nokia/security/product-security-advisory/cve-2026-40463/ 2026-08-30 | GHSA-g3rx-2m58-rr63 | Apple | medium | Unpacking a crafted image layer with an invalid length extended-attribute name crashes the unpacking process | https://github.com/apple/containerization/security/advisories/GHSA-g3rx-2m58-rr63 2026-08-30 | GHSA-697p-8837-37h3 | Apple | medium | Unpacking a crafted image layer with a long(invalid) file name crashes the unpacking process | https://github.com/apple/containerization/security/advisories/GHSA-697p-8837-37h3 2026-08-30 | GHSA-r3h2-rgqf-9hv9 | Apple | medium | Loading an OCI image layout can read host files through a symlink | https://github.com/apple/containerization/security/advisories/GHSA-r3h2-rgqf-9hv9 2026-08-30 | GHSA-mx96-5vvg-x2mg CVE-2026-65388 | Apple | medium | `RegistryClient` follows the `WWW-Authenticate` realm without validating its host or scheme | https://github.com/apple/containerization/security/advisories/GHSA-mx96-5vvg-x2mg 2026-08-30 | GHSA-f689-h8m7-3jp2 | Apple | high | Apple: path traversal | https://github.com/apple/containerization/security/advisories/GHSA-f689-h8m7-3jp2 2026-08-30 | GHSA-x7pf-2jmj-pgcq | Apple | high | ## Impact An attacker who can choose a container or exec id may be able to... | https://github.com/apple/containerization/security/advisories/GHSA-x7pf-2jmj-pgcq 2026-08-29 | GHSA-846c-fpfg-rj9m | GitHub | critical 9.6 | Arbitrary host filesystem & Docker-socket mounts via MCP server `mounts` | https://github.com/github/gh-aw/security/advisories/GHSA-846c-fpfg-rj9m 2026-08-29 | CVE-2026-41012 CVE-2026-41012 | VMware | high 7.7 | VMware bosh-vsphere-cpi-release: improper certificate validation | https://www.cloudfoundry.org/blog/cve-2026-41012-bosh-vsphere-cpi-improper-cert-validation/ 2026-08-28 | GHSA-56wq-x3wv-3ff4 CVE-2026-55874 | seaweedfs | high 7.7 | SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read | https://github.com/advisories/GHSA-56wq-x3wv-3ff4 2026-08-28 | GHSA-hgpf-8634-g44c CVE-2026-55873 | seaweedfs | medium 4.3 | seaweedfs: improper authorization | https://github.com/advisories/GHSA-hgpf-8634-g44c 2026-08-28 | GHSA-j769-9gv9-65gr CVE-2026-55867 | Graylog | medium | Graylog token revocation endpoint allows authenticated users to delete other users’ access tokens | https://github.com/advisories/GHSA-j769-9gv9-65gr 2026-08-28 | GHSA-gqr6-r77p-c2pj CVE-2026-55841 | Graylog | high 7.5 | Fortigate syslog message parser can be exploited to modify or delete fields from the original message | https://github.com/advisories/GHSA-gqr6-r77p-c2pj 2026-08-28 | GHSA-q79r-r9xg-r863 CVE-2026-55425 | Graylog | medium 5.0 | Graylog Server: System Catalog titles endpoint can be used to retrieve values of protected database fields | https://github.com/advisories/GHSA-q79r-r9xg-r863 2026-08-28 | CVE-2026-81490 CVE-2026-81490 | MongoDB | high 8.3 | MongoDB BI Connector: null pointer dereference | https://www.mongodb.com/docs/bi-connector/current/release-notes/ 2026-08-28 | CVE-2026-81517 CVE-2026-81517 | MongoDB | high 8.7 | An unauthenticated party able to reach the port of a MongoDB Connector for BI | https://www.mongodb.com/docs/bi-connector/current/release-notes/ 2026-08-28 | CVE-2026-81518 CVE-2026-81518 | MongoDB | high 8.7 | MongoDB BI Connector: improper certificate validation | https://www.mongodb.com/docs/bi-connector/current/release-notes/ 2026-08-28 | CVE-2026-81520 CVE-2026-81520 | MongoDB | high 8.7 | A network-reachable client | https://www.mongodb.com/docs/bi-connector/current/release-notes/ 2026-08-28 | CVE-2026-81532 CVE-2026-81532 | MongoDB | high 8.7 | MongoDB BI Connector ODBC Driver: stack buffer overflow | https://github.com/mongodb/mongo-bi-connector-odbc-driver/releases 2026-08-28 | CVE-2026-81533 CVE-2026-81533 | MongoDB | medium 6.0 | MongoDB BI Connector ODBC Driver: stack buffer overflow | https://github.com/mongodb/mongo-bi-connector-odbc-driver/releases 2026-08-28 | CVE-2026-3627 CVE-2026-3627 | IBM | critical 9.1 | IBM Concert: SQL injection | https://www.ibm.com/support/pages/node/7285337 2026-08-28 | CVE-2026-3686 CVE-2026-3686 | IBM | medium 6.2 | IBM Cloud Pak for Data System: denial of service | https://www.ibm.com/support/pages/node/7285507 2026-08-28 | CVE-2026-18899 CVE-2026-18899 | IBM | high 7.5 | IBM Langflow OSS: path traversal | https://www.ibm.com/support/pages/node/7284579 2026-08-28 | CVE-2026-18904 CVE-2026-18904 | IBM | high 8.2 | IBM Langflow OSS: information disclosure | https://www.ibm.com/support/pages/node/7284579 2026-08-28 | CVE-2026-19286 CVE-2026-19286 | IBM | critical 9.8 | IBM Langflow OSS: remote code execution | https://www.ibm.com/support/pages/node/7284733 2026-08-28 | CVE-2026-19294 CVE-2026-19294 | IBM | medium 6.4 | IBM Langflow OSS: improper authorization | https://www.ibm.com/support/pages/node/7284579 2026-08-28 | CVE-2026-19295 CVE-2026-19295 | IBM | critical 9.9 | IBM Langflow OSS: privilege escalation | https://www.ibm.com/support/pages/node/7284733 2026-08-28 | CVE-2026-22056 CVE-2026-22056 | NetApp | low 2.3 | NetApp StorageGRID: denial of service | https://security.netapp.com/advisory/NTAP-20260828-0021/ 2026-08-28 | CVE-2026-16821 CVE-2026-16821 | IBM | high 7.0 | IBM AIX: privilege escalation | https://www.ibm.com/support/pages/node/7283858 2026-08-28 | CVE-2026-17203 CVE-2026-17203 | IBM | high 7.5 | IBM Administration Runtime Expert for i: information disclosure | https://www.ibm.com/support/pages/node/7284580 2026-08-28 | CVE-2026-18527 CVE-2026-18527 | IBM | critical 9.9 | IBM Administration Runtime Expert for i: privilege escalation | https://www.ibm.com/support/pages/node/7284580 2026-08-28 | CVE-2026-18545 CVE-2026-18545 | IBM | medium 4.3 | IBM Langflow OSS: server-side request forgery | https://www.ibm.com/support/pages/node/7284579 2026-08-28 | CVE-2026-18729 CVE-2026-18729 | IBM | high 8.8 | IBM Langflow OSS: remote code execution | https://www.ibm.com/support/pages/node/7284733 2026-08-28 | CVE-2026-18891 CVE-2026-18891 | IBM | high 8.2 | IBM Langflow OSS: information disclosure | https://www.ibm.com/support/pages/node/7284579 2026-08-28 | CVE-2025-36271 CVE-2025-36271 | IBM | medium 5.9 | IBM Integrated Analytics System: information disclosure | https://www.ibm.com/support/pages/node/7285147 2026-08-28 | CVE-2025-36290 CVE-2025-36290 | IBM | medium 5.9 | IBM Integrated Analytics System: information disclosure | https://www.ibm.com/support/pages/node/7285149 2026-08-28 | CVE-2025-64649 CVE-2025-64649 | IBM | medium 5.9 | IBM Concert: improper certificate validation | https://www.ibm.com/support/pages/node/7285337 2026-08-28 | CVE-2026-82329 CVE-2026-82329 | JFrog | critical 9.8 | JFrog artifactory: improper authentication | https://docs.jfrog.com/releases/docs/jfrog-security-advisories 2026-08-28 | CVE-2026-82343 CVE-2026-82343 | Red Hat | medium 6.1 | Red Hat file-psd plugin: out-of-bounds read | https://access.redhat.com/security/cve/CVE-2026-82343 2026-08-28 | CVE-2026-77586 CVE-2026-77586 | MongoDB | high 8.5 | MongoDB BI Connector: SQL injection | https://www.mongodb.com/docs/bi-connector/current/release-notes/ 2026-08-28 | CVE-2026-76797 CVE-2026-76797 | MongoDB | medium 5.8 | MongoDB BI Connector Transition Readiness Report: CSV injection | https://www.mongodb.com/docs/sql-interface/changelog/ 2026-08-28 | CVE-2026-76798 CVE-2026-76798 | MongoDB | medium 6.9 | MongoDB BI Connector Transition Readiness Report: cross-site scripting | https://www.mongodb.com/docs/sql-interface/changelog/ 2026-08-28 | CVE-2026-77184 CVE-2026-77184 | MongoDB | medium 5.7 | MongoDB BI Connector: SQL injection | https://www.mongodb.com/docs/bi-connector/current/release-notes/ 2026-08-28 | CVE-2026-76794 CVE-2026-76794 | MongoDB | medium 4.8 | MongoDB BI Connector Transition Readiness Report: cross-site scripting | https://www.mongodb.com/docs/sql-interface/changelog/ 2026-08-28 | CVE-2026-72984 CVE-2026-72984 | Microsoft | high 8.8 | Microsoft Edge: type confusion | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72984 2026-08-28 | CVE-2026-70331 CVE-2026-70331 | Microsoft | medium 5.4 | Microsoft Edge: spoofing | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70331 2026-08-28 | CVE-2026-70309 CVE-2026-70309 | Microsoft | medium 5.4 | Microsoft Edge (Chromium-based): origin validation error | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70309 2026-08-28 | CVE-2026-66323 CVE-2026-66323 | Microsoft | medium 5.4 | Microsoft Edge for: remote code execution | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66323 2026-08-28 | CVE-2026-66324 CVE-2026-66324 | Microsoft | medium 6.5 | Microsoft Edge for: spoofing | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66324 2026-08-28 | CVE-2026-66798 CVE-2026-66798 | Microsoft | medium 4.3 | Microsoft Edge: use after free | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66798 2026-08-28 | CVE-2026-62904 CVE-2026-62904 | Microsoft | medium 5.4 | Microsoft Edge: improper authorization | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62904 2026-08-28 | CVE-2026-58616 CVE-2026-58616 | Microsoft | medium 4.4 | Microsoft Edge: race condition | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58616 2026-08-28 | CVE-2026-82327 CVE-2026-82327 | Red Hat | medium 5.5 | Red Hat libsolv: denial of service | https://access.redhat.com/security/cve/CVE-2026-82327 2026-08-28 | CVE-2026-82328 CVE-2026-82328 | Red Hat | medium 6.1 | Red Hat file-ico plugin: out-of-bounds read | https://access.redhat.com/security/cve/CVE-2026-82328 2026-08-28 | CVE-2026-82330 CVE-2026-82330 | Red Hat | medium 6.1 | Red Hat file-pvr plugin: out-of-bounds read | https://access.redhat.com/security/cve/CVE-2026-82330 2026-08-28 | CVE-2026-82324 CVE-2026-82324 | Red Hat | medium 6.1 | Red Hat GIMP: denial of service | https://access.redhat.com/security/cve/CVE-2026-82324 2026-08-28 | CVE-2026-58106 CVE-2026-58106 | Ericsson | low 2.0 | Ericsson CodeChecker: out-of-bounds write | https://github.com/Ericsson/codechecker/security/advisories/GHSA-9gcg-v8fg-39q8 2026-08-28 | CVE-2026-58107 CVE-2026-58107 | Ericsson | medium 5.5 | Ericsson CodeChecker: denial of service | https://github.com/Ericsson/codechecker/security/advisories/GHSA-w7jw-x567-hqr4 2026-08-28 | CVE-2026-13761 CVE-2026-13761 | Pegasystems | high 8.8 | Pegasystems Pega Infinity: denial of service | https://support.pega.com/support-doc/pega-security-advisory-n26-vulnerability-remediation-note 2026-08-28 | CVE-2026-18393 CVE-2026-18393 | Red Hat | medium 5.4 | Red Hat FFmpeg: denial of service | https://access.redhat.com/security/cve/CVE-2026-18393 2026-08-28 | AWS-2026-091 CVE-2026-81849 | AWS | unknown | Path traversal in the aws:downloadContent plugin in amazon-ssm-agent | https://aws.amazon.com/security/security-bulletins/rss/2026-091-aws/ 2026-08-28 | CVE-2026-82123 CVE-2026-82123 | Tenable | medium 6.5 | Tenable Loops & Logic: cross-site scripting | https://www.tenable.com/security/research/tra-2026-57 2026-08-28 | CVE-2026-78614 CVE-2026-78614 | WatchGuard Technologies | high 8.6 | WatchGuard Technologies Dimension: SQL injection | https://psirt.watchguard.com/CVE-2026-78614 2026-08-28 | CVE-2026-78615 CVE-2026-78615 | WatchGuard Technologies | medium 4.6 | WatchGuard Technologies Dimension: cross-site scripting | https://psirt.watchguard.com/CVE-2026-78615 2026-08-28 | CVE-2026-78616 CVE-2026-78616 | WatchGuard Technologies | medium 4.8 | WatchGuard Technologies Dimension: cross-site scripting | https://psirt.watchguard.com/CVE-2026-78616 2026-08-28 | CVE-2026-78617 CVE-2026-78617 | WatchGuard Technologies | medium 6.3 | WatchGuard Technologies Dimension: observable discrepancy | https://psirt.watchguard.com/CVE-2026-78617 2026-08-28 | CVE-2026-78618 CVE-2026-78618 | WatchGuard Technologies | medium 6.9 | WatchGuard Technologies Dimension: improper access control | https://psirt.watchguard.com/CVE-2026-78618 2026-08-28 | CVE-2026-78495 CVE-2026-78495 | WatchGuard Technologies | medium 5.3 | WatchGuard Technologies Dimension: server-side request forgery | https://psirt.watchguard.com/CVE-2026-78495 2026-08-28 | CVE-2026-78498 CVE-2026-78498 | WatchGuard Technologies | medium 5.1 | WatchGuard Technologies Dimension: server-side request forgery | https://psirt.watchguard.com/CVE-2026-78498 2026-08-28 | CVE-2026-78499 CVE-2026-78499 | WatchGuard Technologies | medium 5.1 | WatchGuard Technologies Dimension: server-side request forgery | https://psirt.watchguard.com/CVE-2026-78499 2026-08-28 | CVE-2026-78500 CVE-2026-78500 | WatchGuard Technologies | medium 5.1 | WatchGuard Technologies Dimension: server-side request forgery | https://psirt.watchguard.com/CVE-2026-78500 2026-08-28 | CVE-2026-78610 CVE-2026-78610 | WatchGuard Technologies | high 8.4 | WatchGuard Technologies Dimension: cross-site request forgery | https://psirt.watchguard.com/CVE-2026-78610 2026-08-28 | CVE-2026-78612 CVE-2026-78612 | WatchGuard Technologies | high 8.6 | WatchGuard Technologies Dimension: SQL injection | https://psirt.watchguard.com/CVE-2026-78612 2026-08-28 | CVE-2026-78613 CVE-2026-78613 | WatchGuard Technologies | high 8.6 | WatchGuard Technologies Dimension: SQL injection | https://psirt.watchguard.com/CVE-2026-78613 2026-08-28 | CVE-2026-78008 CVE-2026-78008 | WatchGuard Technologies | high 8.6 | WatchGuard Technologies Fireware OS: buffer overflow | https://psirt.watchguard.com/CVE-2026-78008 2026-08-28 | CVE-2026-78009 CVE-2026-78009 | WatchGuard Technologies | high 8.7 | WatchGuard Technologies Fireware OS: out-of-bounds read | https://psirt.watchguard.com/CVE-2026-78009 2026-08-28 | CVE-2026-78010 CVE-2026-78010 | WatchGuard Technologies | high 8.7 | WatchGuard Technologies Fireware OS: stack buffer overflow | https://psirt.watchguard.com/CVE-2026-78010 2026-08-28 | CVE-2026-78011 CVE-2026-78011 | WatchGuard Technologies | high 8.7 | WatchGuard Technologies Fireware OS: integer overflow | https://psirt.watchguard.com/CVE-2026-78011 2026-08-28 | CVE-2026-78047 CVE-2026-78047 | WatchGuard Technologies | medium 5.1 | WatchGuard Technologies Dimension: cross-site scripting | https://psirt.watchguard.com/CVE-2026-78047 2026-08-28 | CVE-2026-78103 CVE-2026-78103 | WatchGuard Technologies | medium 5.1 | WatchGuard Technologies Dimension: authenticated administrator could submit... | https://psirt.watchguard.com/CVE-2026-78103 2026-08-28 | CVE-2026-78174 CVE-2026-78174 | WatchGuard Technologies | critical 9.3 | WatchGuard Technologies Dimension: information disclosure | https://psirt.watchguard.com/CVE-2026-78174 2026-08-28 | CVE-2026-19318 CVE-2026-19318 | WatchGuard Technologies | critical 9.3 | WatchGuard Technologies Fireware OS: stack buffer overflow | https://psirt.watchguard.com/CVE-2026-19318 2026-08-28 | CVE-2026-13086 CVE-2026-13086 | WatchGuard Technologies | critical 9.3 | WatchGuard Technologies Fireware OS: stack buffer overflow | https://psirt.watchguard.com/CVE-2026-13086 2026-08-28 | CVE-2026-13108 CVE-2026-13108 | WatchGuard Technologies | high 8.7 | WatchGuard Technologies Dimension: denial of service | https://psirt.watchguard.com/CVE-2026-13108 2026-08-28 | CVE-2026-19313 CVE-2026-19313 | WatchGuard Technologies | critical 9.3 | WatchGuard Technologies Fireware OS: remote code execution | https://psirt.watchguard.com/CVE-2026-19313 2026-08-28 | CVE-2026-19314 CVE-2026-19314 | WatchGuard Technologies | high 8.7 | WatchGuard Technologies Fireware OS: integer overflow | https://psirt.watchguard.com/CVE-2026-19314 2026-08-28 | CVE-2026-19315 CVE-2026-19315 | WatchGuard Technologies | critical 9.3 | WatchGuard Technologies Fireware OS: type confusion | https://psirt.watchguard.com/CVE-2026-19315 2026-08-28 | CVE-2026-19316 CVE-2026-19316 | WatchGuard Technologies | high 8.7 | WatchGuard Technologies Fireware OS: denial of service | https://psirt.watchguard.com/CVE-2026-19316 2026-08-28 | CVE-2026-19317 CVE-2026-19317 | WatchGuard Technologies | high 8.7 | WatchGuard Technologies Fireware OS: out-of-bounds read | https://psirt.watchguard.com/CVE-2026-19317 2026-08-28 | GHSA-69ch-cc3g-4mh4 | Google | critical 9.8 | Google: path traversal | https://github.com/google/android-cuttlefish/security/advisories/GHSA-69ch-cc3g-4mh4 2026-08-28 | CVE-2026-81851 CVE-2026-81851 | WatchGuard Technologies | medium 6.9 | WatchGuard Technologies Fireware OS: heap buffer overflow | https://psirt.watchguard.com/CVE-2026-81851 2026-08-28 | CVE-2026-82072 CVE-2026-82072 | Google | high 8.8 | Google Chrome: out-of-bounds read | https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html 2026-08-28 | CVE-2026-80179 CVE-2026-80179 | Red Hat | medium 5.9 | Red Hat Ansible Automation Platform 2: resource exhaustion | https://access.redhat.com/security/cve/CVE-2026-80179 2026-08-27 | GHSA-6wvf-77m9-58rm CVE-2026-37004 | LiteLLM | critical 9.8 | LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint | https://github.com/advisories/GHSA-6wvf-77m9-58rm 2026-08-27 | GHSA-prrp-g8rp-4h65 CVE-2026-81528 | MongoDB | medium 5.4 | NoSQL injection via array replacement bypassing update shape validation in driver write path | https://github.com/mongodb/mongo-csharp-driver/security/advisories/GHSA-prrp-g8rp-4h65 2026-08-27 | GHSA-9w68-f89p-56c9 CVE-2026-81527 | MongoDB | medium 6.5 | NoSQL injection in LINQ pipeline translation | https://github.com/mongodb/mongo-csharp-driver/security/advisories/GHSA-9w68-f89p-56c9 2026-08-27 | GHSA-7jhm-4g3c-cf75 CVE-2026-81530 | MongoDB | medium 5.6 | KMS master key exposure via unredacted credential serialization in driver settings string | https://github.com/mongodb/mongo-csharp-driver/security/advisories/GHSA-7jhm-4g3c-cf75 2026-08-27 | GHSA-93xj-pqc8-f28v CVE-2026-81529 | MongoDB | high 7.1 | Connection-option injection via unescaped settings in the canonical MongoDB URL builder | https://github.com/mongodb/mongo-csharp-driver/security/advisories/GHSA-93xj-pqc8-f28v 2026-08-27 | CVE-2026-81893 CVE-2026-81893 | Red Hat | medium 4.7 | Red Hat gdk-pixbuf.: out-of-bounds write | https://access.redhat.com/security/cve/CVE-2026-81893 2026-08-27 | CVE-2026-75889 CVE-2026-75889 | Grafana Labs | high 7.7 | Grafana Labs Alloy: exposed files | https://grafana.com/security/security-advisories/cve-2026-75889 2026-08-27 | CVE-2026-74820 CVE-2026-74820 | ServiceNow | critical 10.0 | ServiceNow AI Platform: SQL injection | https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB3152242 2026-08-27 | CVE-2026-6876 CVE-2026-6876 | ServiceNow | critical 10.0 | ServiceNow AI Platform: remote code execution | https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB3152242 2026-08-27 | CVE-2026-59320 CVE-2026-59320 | VMware | medium 6.5 | VMware Spring AMQP: resource leak | https://spring.io/security/cve-2026-59320 2026-08-27 | CVE-2026-59321 CVE-2026-59321 | VMware | medium 4.2 | VMware Spring Integration: race condition | https://spring.io/security/cve-2026-59321 2026-08-27 | CVE-2026-59322 CVE-2026-59322 | VMware | medium 6.3 | VMware Spring Integration: improper input validation | https://spring.io/security/cve-2026-59322 2026-08-27 | CVE-2026-59324 CVE-2026-59324 | VMware | high 8.2 | VMware Spring Integration: race condition | https://spring.io/security/cve-2026-59324 2026-08-27 | CVE-2026-59307 CVE-2026-59307 | VMware | high 8.0 | VMware Spring Integration: unsafe deserialization | https://spring.io/security/cve-2026-59307 2026-08-27 | CVE-2026-59311 CVE-2026-59311 | VMware | medium 6.8 | VMware Spring Integration: link following | https://spring.io/security/cve-2026-59311 2026-08-27 | CVE-2026-59313 CVE-2026-59313 | VMware | critical 9.8 | Spring MVC applications using the functional web framework are vulnerable to... | https://spring.io/security/cve-2026-59313 2026-08-27 | CVE-2026-59314 CVE-2026-59314 | VMware | low 3.7 | Applications that build a Content-Disposition header value from untrusted input... | https://spring.io/security/cve-2026-59314 2026-08-27 | CVE-2026-59315 CVE-2026-59315 | VMware | medium 5.3 | VMware Spring Cloud Config: denial of service | https://spring.io/security/cve-2026-59315 2026-08-27 | CVE-2026-59316 CVE-2026-59316 | VMware | high 8.2 | VMware Spring Authorization Server: cross-site scripting | https://spring.io/security/cve-2026-59316 2026-08-27 | CVE-2026-59317 CVE-2026-59317 | VMware | medium 6.5 | VMware Spring for Apache Kafka: improper quantity validation | https://spring.io/security/cve-2026-59317 2026-08-27 | CVE-2026-59319 CVE-2026-59319 | VMware | medium 4.3 | VMware Spring AI: attacker could inject RediSearch syntax | https://spring.io/security/cve-2026-59319 2026-08-27 | CVE-2026-59298 CVE-2026-59298 | VMware | low 3.1 | VMware Spring Cloud Function: improper input validation | https://spring.io/security/cve-2026-59298 2026-08-27 | CVE-2026-59299 CVE-2026-59299 | VMware | low 3.1 | Composition lookup can potentially poison base function in Spring Cloud Function | https://spring.io/security/cve-2026-59299 2026-08-27 | CVE-2026-59300 CVE-2026-59300 | VMware | low 3.1 | VMware Spring Cloud Function: secrets in logs | https://spring.io/security/cve-2026-59300 2026-08-27 | CVE-2026-59301 CVE-2026-59301 | VMware | low 3.1 | VMware Spring Cloud Function: secrets in logs | https://spring.io/security/cve-2026-59301 2026-08-27 | CVE-2026-59302 CVE-2026-59302 | VMware | low 3.1 | VMware Spring Cloud Stream: secrets in logs | https://spring.io/security/cve-2026-59302 2026-08-27 | CVE-2026-59303 CVE-2026-59303 | VMware | low 3.1 | VMware Spring Cloud Stream: resource exhaustion | https://spring.io/security/cve-2026-59303 2026-08-27 | CVE-2026-59304 CVE-2026-59304 | VMware | low 3.1 | VMware Spring Cloud Stream: type confusion | https://spring.io/security/cve-2026-59304 2026-08-27 | CVE-2026-59305 CVE-2026-59305 | VMware | low 3.1 | Partition interceptor may be improperly added while sending message | https://spring.io/security/cve-2026-59305 2026-08-27 | CVE-2026-59306 CVE-2026-59306 | VMware | low 3.1 | VMware Spring Cloud Stream: unsafe deserialization | https://spring.io/security/cve-2026-59306 2026-08-27 | CVE-2026-59288 CVE-2026-59288 | VMware | high 7.4 | VMware Spring for GraphQL: information disclosure | https://spring.io/security/cve-2026-59288 2026-08-27 | CVE-2026-59289 CVE-2026-59289 | VMware | high 7.5 | VMware Spring for GraphQL: denial of service | https://spring.io/security/cve-2026-59289 2026-08-27 | CVE-2026-59291 CVE-2026-59291 | VMware | low 2.0 | VMware Spring Cloud Function: arbitrary file read | https://spring.io/security/cve-2026-59291 2026-08-27 | CVE-2026-59292 CVE-2026-59292 | VMware | low 3.2 | VMware Spring Integration: insecure permissions | https://spring.io/security/cve-2026-59292 2026-08-27 | CVE-2026-59293 CVE-2026-59293 | VMware | medium 6.6 | VMware Spring Integration: tampering | https://spring.io/security/cve-2026-59293 2026-08-27 | CVE-2026-59294 CVE-2026-59294 | VMware | medium 5.9 | VMware Spring AI: path traversal | https://spring.io/security/cve-2026-59294 2026-08-27 | CVE-2026-59297 CVE-2026-59297 | VMware | low 3.1 | VMware Spring Cloud Function: origin validation error | https://spring.io/security/cve-2026-59297 2026-08-27 | CVE-2026-59281 CVE-2026-59281 | VMware | medium 6.1 | VMware Spring Framework: code injection | https://spring.io/security/cve-2026-59281 2026-08-27 | CVE-2026-59282 CVE-2026-59282 | VMware | high 7.5 | VMware Spring Framework: denial of service | https://spring.io/security/cve-2026-59282 2026-08-27 | CVE-2026-59283 CVE-2026-59283 | VMware | critical 9.1 | Applications that evaluate Spring Expression Language | https://spring.io/security/cve-2026-59283 2026-08-27 | CVE-2026-59284 CVE-2026-59284 | VMware | high 7.6 | VMware Spring Cloud Commons: mass assignment | https://spring.io/security/cve-2026-59284 2026-08-27 | CVE-2026-59285 CVE-2026-59285 | VMware | high 8.1 | VMware Spring for GraphQL: unsafe deserialization | https://spring.io/security/cve-2026-59285 2026-08-27 | CVE-2026-59286 CVE-2026-59286 | VMware | high 8.1 | VMware Spring for GraphQL: code execution | https://spring.io/security/cve-2026-59286 2026-08-27 | CVE-2026-59287 CVE-2026-59287 | VMware | medium 5.9 | VMware Spring for GraphQL: denial of service | https://spring.io/security/cve-2026-59287 2026-08-27 | CVE-2026-59276 CVE-2026-59276 | VMware | medium 5.9 | Several components in Spring Security compare security-sensitive values using... | https://spring.io/security/cve-2026-59276 2026-08-27 | CVE-2026-59277 CVE-2026-59277 | VMware | low 3.7 | VMware Spring Security: protection mechanism failure | https://spring.io/security/cve-2026-59277 2026-08-27 | CVE-2026-34620 CVE-2026-34620 | Adobe | medium 5.5 | Adobe DNG Software Development Kit (SDK): out-of-bounds write | https://helpx.adobe.com/security/products/dng-sdk/apsb26-41.html 2026-08-27 | CVE-2026-34616 CVE-2026-34616 | Adobe | medium 5.5 | Adobe DNG Software Development Kit (SDK): out-of-bounds read | https://helpx.adobe.com/security/products/dng-sdk/apsb26-41.html 2026-08-27 | CVE-2026-18886 CVE-2026-18886 | ServiceNow | critical 10.0 | ServiceNow AI Platform: improper access control | https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB3152242 2026-08-27 | CVE-2026-18885 CVE-2026-18885 | ServiceNow | critical 10.0 | ServiceNow AI Platform: code injection | https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB3152242 2026-08-27 | GHSA-65fr-j4p9-vc33 CVE-2026-81525 | MongoDB | high 8.1 | Cross-tenant database retargeting via dot/NUL injection in namespace strings in the PHP Driver | https://github.com/mongodb/mongo-php-library/security/advisories/GHSA-65fr-j4p9-vc33 2026-08-27 | GHSA-v86x-jf74-vqfx CVE-2026-81521 | MongoDB | high 7.1 | Cross-database write retargeting via unvalidated dotted database name in Client.BulkWrite | https://github.com/mongodb/mongo-go-driver/security/advisories/GHSA-v86x-jf74-vqfx 2026-08-27 | GHSA-r58q-vf9r-vxfc CVE-2026-81526 | MongoDB | medium 6.5 | Cross-database write redirection via unvalidated dotted database name in bulk write namespaces | https://github.com/mongodb/mongo-rust-driver/security/advisories/GHSA-r58q-vf9r-vxfc 2026-08-27 | GHSA-8g9w-8cw9-q38w CVE-2026-81523 | MongoDB | medium 4.4 | Cross-tenant database retargeting via dot/NUL injection in namespace strings in libmongocrypt | https://github.com/mongodb/libmongocrypt/security/advisories/GHSA-8g9w-8cw9-q38w 2026-08-27 | GHSA-69mq-vf3m-pgj6 CVE-2026-81522 | MongoDB | high 8.1 | Cross-tenant database retargeting via dot/NUL injection in namespace strings in the C++ Driver | https://github.com/mongodb/mongo-cxx-driver/security/advisories/GHSA-69mq-vf3m-pgj6 2026-08-27 | GHSA-c9qr-rh56-vvrc CVE-2026-81524 | MongoDB | medium 5.4 | Cross-tenant database retargeting via dot/NUL injection in namespace strings in the C Driver | https://github.com/mongodb/mongo-c-driver/security/advisories/GHSA-c9qr-rh56-vvrc 2026-08-27 | GHSA-8h78-hpm7-29gg | GitHub | critical 9.1 | Safe-output artifacts may expose CI trigger tokens | https://github.com/github/gh-aw/security/advisories/GHSA-8h78-hpm7-29gg 2026-08-27 | CVE-2026-78002 CVE-2026-78002 | Red Hat | high 7.5 | Red Hat rsyslog: buffer overflow | https://access.redhat.com/errata/RHSA-2026:69540 2026-08-27 | CVE-2026-75871 CVE-2026-75871 | GitLab | high 8.2 | GitLab AI Gateway: server-side request forgery | https://gitlab.com/gitlab-org/gitlab/-/work_items/616990 2026-08-27 | CVE-2026-75573 CVE-2026-75573 | MongoDB | medium 4.1 | MongoDB BI Connector: secrets in logs | https://www.mongodb.com/docs/bi-connector/current/release-notes/#mongodb-connector-for-bi-2.14.30 2026-08-27 | CVE-2026-75159 CVE-2026-75159 | MongoDB | high 8.2 | MongoDB BI Connector: double free | https://www.mongodb.com/docs/bi-connector/current/release-notes/#mongodb-connector-for-bi-2.14.30 2026-08-27 | CVE-2026-5680 CVE-2026-5680 | Red Hat | high 7.5 | Red Hat Undertow. A remote attacker: resource exhaustion | https://access.redhat.com/errata/RHSA-2026:70228 2026-08-27 | CVE-2026-59272 CVE-2026-59272 | VMware | medium 6.8 | Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender | https://spring.io/security/cve-2026-59272 2026-08-27 | CVE-2026-59280 CVE-2026-59280 | VMware | medium 4.3 | VMware Spring Framework: path traversal | https://spring.io/security/cve-2026-59280 2026-08-27 | CVE-2026-34674 CVE-2026-34674 | Adobe | high 7.8 | Adobe Substance 3D Sampler: heap buffer overflow | https://helpx.adobe.com/security/products/substance3d-sampler/apsb26-54.html 2026-08-27 | CVE-2026-19854 CVE-2026-19854 | Grafana Labs | medium 6.1 | Grafana Labs Clickhouse Datasource: cleartext transmission | https://grafana.com/security/security-advisories/cve-2026-19854 2026-08-27 | CVE-2026-19889 CVE-2026-19889 | GitLab | high 8.2 | GitLab AI Gateway: server-side request forgery | https://gitlab.com/gitlab-org/gitlab/-/work_items/614164 2026-08-27 | CVE-2026-16279 CVE-2026-16279 | Dassault Systèmes | critical 9.3 | Dassault Systèmes 3DSwymer: improper authorization | https://www.3ds.com/trust-center/security/security-advisories/cve-2026-16279 2026-08-27 | CVE-2026-81658 CVE-2026-81658 | Red Hat | medium 6.5 | Red Hat Satellite 6: insecure direct object reference | https://access.redhat.com/security/cve/CVE-2026-81658 2026-08-27 | CVE-2026-81668 CVE-2026-81668 | Red Hat | medium 5.4 | Red Hat Satellite 6: insecure direct object reference | https://access.redhat.com/security/cve/CVE-2026-81668 2026-08-27 | CVE-2026-66155 CVE-2026-66155 | Siemens | high 7.0 | Siemens Element maps-ng: cross-site scripting | https://cert-portal.siemens.com/productcert/html/ssa-682041.html 2026-08-27 | AWS-2026-090 CVE-2026-81838 | AWS | unknown | Zip Slip path traversal in awsdac (diagram-as-code) | https://aws.amazon.com/security/security-bulletins/rss/2026-090-aws/ 2026-08-27 | CVE-2026-59354 CVE-2026-59354 | VMware | critical 9.6 | VMware Spring Security: cross-site scripting | https://spring.io/security/cve-2026-59354 2026-08-27 | CVE-2026-59355 CVE-2026-59355 | VMware | medium 6.1 | VMware Spring Authorization Server: open redirect | https://spring.io/security/cve-2026-59355 2026-08-27 | CVE-2026-59275 CVE-2026-59275 | VMware | medium 6.6 | VMware Spring AMQP: unsafe deserialization | https://spring.io/security/cve-2026-59275 2026-08-27 | CVE-2026-59278 CVE-2026-59278 | VMware | medium 6.5 | VMware Spring for Apache Kafka: server-side request forgery | https://spring.io/security/cve-2026-59278 2026-08-27 | CVE-2026-59270 CVE-2026-59270 | VMware | critical 9.4 | VMware Spring Security: improper authorization | https://spring.io/security/cve-2026-59270 2026-08-27 | CVE-2026-59271 CVE-2026-59271 | VMware | medium 5.3 | VMware Spring AMQP: information disclosure in errors | https://spring.io/security/cve-2026-59271 2026-08-27 | CVE-2026-59274 CVE-2026-59274 | VMware | medium 6.5 | VMware Spring Integration: denial of service | https://spring.io/security/cve-2026-59274 2026-08-27 | CVE-2026-47890 CVE-2026-47890 | VMware | critical 9.8 | Spring MVC and WebFlux applications are vulnerable to stream corruption | https://spring.io/security/cve-2026-47890 2026-08-27 | CVE-2026-47891 CVE-2026-47891 | VMware | critical 9.8 | VMware Spring Framework: resource exhaustion | https://spring.io/security/cve-2026-47891 2026-08-27 | CVE-2026-47892 CVE-2026-47892 | VMware | critical 9.8 | VMware Spring Framework: improper authorization | https://spring.io/security/cve-2026-47892 2026-08-27 | CVE-2026-47893 CVE-2026-47893 | VMware | high 7.5 | VMware Spring Framework: information disclosure in errors | https://spring.io/security/cve-2026-47893 2026-08-27 | CVE-2026-47894 CVE-2026-47894 | VMware | medium 4.9 | Spring Cloud Config Server native environment repository | https://spring.io/security/cve-2026-47894 2026-08-27 | CVE-2026-47886 CVE-2026-47886 | VMware | high 7.5 | VMware Spring Framework: denial of service | https://spring.io/security/cve-2026-47886 2026-08-27 | CVE-2026-47887 CVE-2026-47887 | VMware | medium 6.1 | VMware Spring Framework: open redirect | https://spring.io/security/cve-2026-47887 2026-08-27 | CVE-2026-47888 CVE-2026-47888 | VMware | high 7.5 | VMware Spring Framework: memory leak | https://spring.io/security/cve-2026-47888 2026-08-27 | CVE-2026-47889 CVE-2026-47889 | VMware | high 7.5 | A WebFlux application running on the Jetty 12 Core reactive adapter serializes... | https://spring.io/security/cve-2026-47889 2026-08-27 | CVE-2026-47881 CVE-2026-47881 | VMware | medium 5.9 | VMware Spring Batch: resource exhaustion | https://spring.io/security/cve-2026-47881 2026-08-27 | CVE-2026-47883 CVE-2026-47883 | VMware | medium 6.1 | VMware Spring Framework: open redirect | https://spring.io/security/cve-2026-47883 2026-08-27 | CVE-2026-47884 CVE-2026-47884 | VMware | critical 9.8 | VMware Spring Framework: server-side request forgery | https://spring.io/security/cve-2026-47884 2026-08-27 | CVE-2026-47885 CVE-2026-47885 | VMware | high 7.5 | VMware Spring Framework: resource exhaustion | https://spring.io/security/cve-2026-47885 2026-08-27 | CVE-2026-47864 CVE-2026-47864 | VMware | medium 6.4 | VMware Spring Integration: unsafe deserialization | https://spring.io/security/cve-2026-47864 2026-08-27 | CVE-2026-47875 CVE-2026-47875 | VMware | medium 5.6 | VMware Spring Batch: unsafe deserialization | https://spring.io/security/cve-2026-47875 2026-08-27 | CVE-2026-47877 CVE-2026-47877 | VMware | high 8.2 | VMware Spring Security: cross-site scripting | https://spring.io/security/cve-2026-47877 2026-08-27 | CVE-2026-47878 CVE-2026-47878 | VMware | medium 5.6 | VMware Spring Batch: unsafe deserialization | https://spring.io/security/cve-2026-47878 2026-08-27 | CVE-2026-47879 CVE-2026-47879 | VMware | high 7.7 | VMware Spring Cloud Gateway: server-side request forgery | https://spring.io/security/cve-2026-47879 2026-08-27 | CVE-2026-47880 CVE-2026-47880 | VMware | medium 5.4 | VMware Spring Integration: improper input validation | https://spring.io/security/cve-2026-47880 2026-08-27 | CVE-2026-47849 CVE-2026-47849 | VMware | high 7.1 | VMware Spring Data REST: mass assignment | https://spring.io/security/cve-2026-47849 2026-08-27 | CVE-2026-16895 CVE-2026-16895 | Rapid7 | medium 5.1 | A logic vulnerability | https://github.com/rapid7/metasploit-framework/pull/21768 2026-08-27 | CVE-2026-19398 CVE-2026-19398 | ASUS | medium 6.8 | ASUS FA507NU: out-of-bounds write | https://www.asus.com/security-advisory 2026-08-27 | CVE-2026-47860 CVE-2026-47860 | VMware | medium 6.5 | VMware Spring AMQP: infinite loop | https://spring.io/security/cve-2026-47860 2026-08-27 | CVE-2026-47861 CVE-2026-47861 | VMware | medium 6.3 | VMware Spring Integration: server-side request forgery | https://spring.io/security/cve-2026-47861 2026-08-27 | CVE-2026-47862 CVE-2026-47862 | VMware | medium 5.4 | VMware Spring Integration: path traversal | https://spring.io/security/cve-2026-47862 2026-08-27 | CVE-2026-47863 CVE-2026-47863 | VMware | medium 5.9 | VMware Reactor Core: denial of service | https://spring.io/security/cve-2026-47863 2026-08-27 | CVE-2026-47874 CVE-2026-47874 | VMware | medium 5.3 | VMware Reactor Netty: resource exhaustion | https://spring.io/security/cve-2026-47874 2026-08-27 | CVE-2026-47851 CVE-2026-47851 | VMware | high 7.5 | VMware Spring AI: uncontrolled recursion | https://spring.io/security/cve-2026-47851 2026-08-27 | CVE-2026-47852 CVE-2026-47852 | VMware | high 7.5 | A local attacker on a multi-user host can pre-create the deterministic cache... | https://spring.io/security/cve-2026-47852 2026-08-27 | CVE-2026-47856 CVE-2026-47856 | VMware | medium 6.3 | VMware Spring Integration: unsafe deserialization | https://spring.io/security/cve-2026-47856 2026-08-27 | CVE-2026-47857 CVE-2026-47857 | VMware | medium 5.9 | VMware Reactor Core: denial of service | https://spring.io/security/cve-2026-47857 2026-08-27 | CVE-2026-47859 CVE-2026-47859 | VMware | medium 5.4 | VMware Spring Integration: resource exhaustion | https://spring.io/security/cve-2026-47859 2026-08-27 | CVE-2026-47845 CVE-2026-47845 | VMware | medium 5.3 | VMware Reactor Netty: authentication bypass by spoofing | https://spring.io/security/cve-2026-47845 2026-08-27 | CVE-2026-47850 CVE-2026-47850 | VMware | medium 4.3 | VMware Spring Data REST: mass assignment | https://spring.io/security/cve-2026-47850 2026-08-26 | CVE-2026-80158 CVE-2026-80158 | Red Hat | medium 5.5 | A flaw was found in the ipa_getkeytab module of the community.general Ansible... | https://access.redhat.com/security/cve/CVE-2026-80158 2026-08-26 | CVE-2026-79938 CVE-2026-79938 | Dell Technologies | high 7.6 | Dell Technologies Cyber Recovery: improper authentication | https://www.dell.com/support/kbdoc/en-us/000501456/dsa-2026-370-security-update-for-dell-powerprotect-cyber-recovery-multiple-third-party-component-vulnerabilities 2026-08-26 | CVE-2026-79939 CVE-2026-79939 | Dell Technologies | medium 5.8 | Dell PowerProtect Cyber Recovery | https://www.dell.com/support/kbdoc/en-us/000501456/dsa-2026-370-security-update-for-dell-powerprotect-cyber-recovery-multiple-third-party-component-vulnerabilities 2026-08-26 | CVE-2026-71172 CVE-2026-71172 | Dell Technologies | medium 4.3 | Dell Technologies Cloud Disaster Recovery: server-side request forgery | https://www.dell.com/support/kbdoc/en-us/000500898/dsa-2026-353-security-update-for-cloud-disaster-recovery-vulnerabilities 2026-08-26 | CVE-2026-74770 CVE-2026-74770 | Dell Technologies | high 8.8 | Dell Technologies PowerProtect One: command injection | https://www.dell.com/support/kbdoc/en-us/000500902/dsa-2026-369-security-update-for-dell-powerprotect-one-multiple-vulnerabilities 2026-08-26 | CVE-2026-74771 CVE-2026-74771 | Dell Technologies | medium 6.5 | Dell Technologies PowerProtect One: tampering | https://www.dell.com/support/kbdoc/en-us/000500902/dsa-2026-369-security-update-for-dell-powerprotect-one-multiple-vulnerabilities 2026-08-26 | CVE-2026-74774 CVE-2026-74774 | Dell Technologies | medium 5.9 | Dell Technologies PowerProtect One: improper certificate validation | https://www.dell.com/support/kbdoc/en-us/000500902/dsa-2026-369-security-update-for-dell-powerprotect-one-multiple-vulnerabilities 2026-08-26 | CVE-2026-71054 CVE-2026-71054 | Oracle | medium 6.5 | Oracle Java SE: resource exhaustion | https://support.oracle.com/support/?documentId=CPU330 2026-08-26 | CVE-2026-67275 CVE-2026-67275 | Dell Technologies | medium 5.3 | Dell PowerProtect One | https://www.dell.com/support/kbdoc/en-us/000500902/dsa-2026-369-security-update-for-dell-powerprotect-one-multiple-vulnerabilities 2026-08-26 | CVE-2026-68861 CVE-2026-68861 | Dell Technologies | high 8.8 | Dell Technologies PowerProtect One: command injection | https://www.dell.com/support/kbdoc/en-us/000500902/dsa-2026-369-security-update-for-dell-powerprotect-one-multiple-vulnerabilities 2026-08-26 | CVE-2026-68863 CVE-2026-68863 | Dell Technologies | high 7.5 | Dell Technologies PowerProtect One: stack buffer overflow | https://www.dell.com/support/kbdoc/en-us/000500902/dsa-2026-369-security-update-for-dell-powerprotect-one-multiple-vulnerabilities 2026-08-26 | CVE-2026-49809 CVE-2026-49809 | Dell Technologies | medium 6.5 | Dell Technologies Cyber Recovery: SQL injection | https://www.dell.com/support/kbdoc/en-us/000501456/dsa-2026-370-security-update-for-dell-powerprotect-cyber-recovery-multiple-third-party-component-vulnerabilities 2026-08-26 | CVE-2026-47848 CVE-2026-47848 | VMware | medium 6.1 | VMware Reactor Netty: open redirect | https://spring.io/security/cve-2026-47848 2026-08-26 | CVE-2026-47843 CVE-2026-47843 | VMware | low 3.7 | In specific scenarios involving multiple clients with different DNS resolver... | https://spring.io/security/cve-2026-47843 2026-08-26 | CVE-2026-47844 CVE-2026-47844 | VMware | medium 5.3 | In specific scenarios | https://spring.io/security/cve-2026-47844 2026-08-26 | CVE-2026-47842 CVE-2026-47842 | VMware | medium 6.5 | VMware Spring Security: weak encryption | https://spring.io/security/cve-2026-47842 2026-08-26 | CVE-2026-47834 CVE-2026-47834 | VMware | medium 4.8 | Spring Data JPA's Sort validation can be bypassed | https://spring.io/security/cve-2026-47834 2026-08-26 | CVE-2026-79940 CVE-2026-79940 | Dell Technologies | medium 5.9 | Dell Technologies iDRAC9: improper access control | https://www.dell.com/support/kbdoc/en-us/000502514/dsa-2026-374-security-update-for-dell-idrac9-vulnerability 2026-08-26 | CVE-2026-71171 CVE-2026-71171 | Dell Technologies | high 7.2 | Dell Technologies Cloud Disaster Recovery: command injection | https://www.dell.com/support/kbdoc/en-us/000500898/dsa-2026-353-security-update-for-cloud-disaster-recovery-vulnerabilities 2026-08-26 | CVE-2026-70419 CVE-2026-70419 | Dell Technologies | critical 9.1 | Dell Technologies Cloud Disaster Recovery: command injection | https://www.dell.com/support/kbdoc/en-us/000500898/dsa-2026-353-security-update-for-cloud-disaster-recovery-vulnerabilities 2026-08-26 | CVE-2026-19485 CVE-2026-19485 | Google Cloud | critical 9.3 | Google Cloud Vertex AI Search for Commerce: weak randomness | https://unit42.paloaltonetworks.com/hijacking-vertex-ai-model/ 2026-08-26 | CVE-2026-47836 CVE-2026-47836 | VMware | high 7.2 | VMware Spring Cloud Config: race condition | https://spring.io/security/cve-2026-47836 2026-08-26 | CVE-2026-47837 CVE-2026-47837 | VMware | medium 6.8 | VMware Spring Cloud Config: missing authentication | https://spring.io/security/cve-2026-47837 2026-08-26 | CVE-2026-47841 CVE-2026-47841 | VMware | high 7.4 | VMware Spring Security: improper authorization | https://spring.io/security/cve-2026-47841 2026-08-26 | CVE-2026-75062 CVE-2026-75062 | Google | critical 9.2 | Google langfun: insecure default | https://github.com/google/langfun 2026-08-26 | CVE-2026-7487 CVE-2026-7487 | GitLab | low 3.5 | GitLab: improper authorization | https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-1-released/ 2026-08-26 | CVE-2026-79902 CVE-2026-79902 | Red Hat | medium 5.5 | Red Hat Seattle FilmWorks plugin: integer overflow | https://access.redhat.com/security/cve/CVE-2026-79902 2026-08-26 | CVE-2026-77801 CVE-2026-77801 | GitLab | medium 6.5 | GitLab: denial of service | https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-1-released/ 2026-08-26 | CVE-2026-3035 CVE-2026-3035 | GitLab | medium 5.5 | GitLab: improper authorization | https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-1-released/ 2026-08-26 | CVE-2026-18252 CVE-2026-18252 | GitLab | high 7.3 | GitLab: untrusted functionality included | https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-1-released/ 2026-08-26 | CVE-2026-12717 CVE-2026-12717 | Google Cloud | critical 9.4 | Google Cloud BigQuery Data Transfer Service: improper input validation | https://docs.cloud.google.com/support/bulletins#gcp-2026-056 2026-08-26 | CVE-2026-15387 CVE-2026-15387 | GitLab | medium 4.3 | GitLab has remediated an issue in GitLab EE affecting all versions from 19.1... | https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-1-released/ 2026-08-26 | CVE-2025-10903 CVE-2025-10903 | GitLab | medium 6.5 | GitLab: denial of service | https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-1-released/ 2026-08-26 | CVE-2026-19197 CVE-2026-19197 | Grafana Labs | medium 6.3 | Grafana: improper access control | https://grafana.com/security/security-advisories/cve-2026-19197 2026-08-26 | CVE-2026-58108 CVE-2026-58108 | Ericsson | low 1.2 | Ericsson CodeChecker: improper access control | https://github.com/Ericsson/codechecker/security/advisories/GHSA-mwpp-2jmv-26vv 2026-08-26 | CVE-2026-79654 CVE-2026-79654 | Red Hat | medium 4.3 | Red Hat Satellite 6: insecure direct object reference | https://access.redhat.com/security/cve/CVE-2026-79654 2026-08-25 | GO-2026-6261 CVE-2026-54061 | Dgraph | critical 9.1 | Dgraph Alpha exposes the RPCs used for external snapshot import on the public... | https://pkg.go.dev/vuln/GO-2026-6261 2026-08-25 | GHSA-p43p-whwx-q52h CVE-2026-54338 | Jupyter | medium 5.3 | JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login | https://github.com/advisories/GHSA-p43p-whwx-q52h 2026-08-25 | GHSA-hvfh-5mj3-5f3j CVE-2026-45019 | chainlit | high 7.2 | chainlit: server-side request forgery | https://github.com/advisories/GHSA-hvfh-5mj3-5f3j 2026-08-25 | GHSA-w3fx-mc44-mf6j CVE-2026-45018 | chainlit | critical 9.8 | Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution | https://github.com/advisories/GHSA-w3fx-mc44-mf6j 2026-08-25 | CVE-2026-41707 CVE-2026-41707 | VMware | high 7.4 | VMware Spring Security: authentication bypass | https://spring.io/security/cve-2026-41707 2026-08-25 | GHSA-rgvh-j93q-rw6f CVE-2026-56132 | Nvidia | medium 6.9 | Bundled CloudXR libPoco.so statically links libexpat 2.8.1 (CVE-2026-56132 + CVE-2026-56403..56409) | https://github.com/NVIDIA/IsaacTeleop/security/advisories/GHSA-rgvh-j93q-rw6f 2026-08-25 | CVE-2026-80185 CVE-2026-80185 | Red Hat | medium 5.7 | Red Hat Enterprise Linux: type confusion | https://access.redhat.com/security/cve/CVE-2026-80185 2026-08-25 | CVE-2026-80186 CVE-2026-80186 | Red Hat | high 7.6 | Red Hat Enterprise Linux: stack buffer overflow | https://access.redhat.com/security/cve/CVE-2026-80186 2026-08-25 | CVE-2026-80101 CVE-2026-80101 | Red Hat | medium 4.4 | Red Hat file-xwd plugin: out-of-bounds read | https://access.redhat.com/security/cve/CVE-2026-80101 2026-08-25 | CVE-2026-79289 CVE-2026-79289 | Google | low 3.1 | Improper control of a resource through its lifetime in Workers in Google Chrome... | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79290 CVE-2026-79290 | Google | critical 9.6 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79291 CVE-2026-79291 | Google | medium 6.5 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79292 CVE-2026-79292 | Google | high 8.3 | Google Chrome: integer overflow | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79293 CVE-2026-79293 | Google | medium 6.5 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79275 CVE-2026-79275 | Google | critical 9.6 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79276 CVE-2026-79276 | Google | medium 4.3 | Google Chrome: improper privilege management | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79282 CVE-2026-79282 | Google | critical 9.6 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79283 CVE-2026-79283 | Google | medium 5.4 | Google Chrome: spoofing | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79284 CVE-2026-79284 | Google | medium 4.3 | Google Chrome: spoofing | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79285 CVE-2026-79285 | Google | medium 6.5 | Google Chrome: uninitialized resource | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79286 CVE-2026-79286 | Google | high 7.4 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79287 CVE-2026-79287 | Google | medium 5.3 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79288 CVE-2026-79288 | Google | medium 6.5 | Google Chrome: improper input validation | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79264 CVE-2026-79264 | Google | medium 4.3 | Google Chrome: remote attacker could bypass web origin policy | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79265 CVE-2026-79265 | Google | medium 5.3 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79266 CVE-2026-79266 | Google | high 8.8 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79267 CVE-2026-79267 | Google | medium 4.3 | Google Chrome: race condition | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79269 CVE-2026-79269 | Google | medium 4.3 | Google Chrome: uninitialized resource | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79270 CVE-2026-79270 | Google | medium 6.5 | Google Chrome: uninitialized resource | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79271 CVE-2026-79271 | Google | medium 6.5 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79272 CVE-2026-79272 | Google | low 3.1 | Google Chrome: improper input validation | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79273 CVE-2026-79273 | Google | medium 4.3 | Google Chrome: remote attacker could potentially bypass web origin policy | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79274 CVE-2026-79274 | Google | medium 4.3 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79255 CVE-2026-79255 | Google | low 3.1 | Google Chrome: improper input validation | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79256 CVE-2026-79256 | Google | high 8.3 | Google Chrome: remote code execution | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79257 CVE-2026-79257 | Google | critical 9.6 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79258 CVE-2026-79258 | Google | medium 6.5 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79259 CVE-2026-79259 | Google | medium 4.3 | Google Chrome: improper input validation | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79260 CVE-2026-79260 | Google | medium 6.5 | Google Chrome: improper input validation | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79261 CVE-2026-79261 | Google | medium 4.3 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79262 CVE-2026-79262 | Google | medium 4.3 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79263 CVE-2026-79263 | Google | high 8.1 | Google Chrome: race condition | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79246 CVE-2026-79246 | Google | medium 6.5 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79247 CVE-2026-79247 | Google | high 8.3 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79248 CVE-2026-79248 | Google | medium 4.3 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79249 CVE-2026-79249 | Google | medium 6.5 | Google Chrome: code injection | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79250 CVE-2026-79250 | Google | medium 5.4 | Google Chrome: spoofing | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79251 CVE-2026-79251 | Google | medium 4.3 | Google Chrome: improper input validation | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79252 CVE-2026-79252 | Google | medium 4.3 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79253 CVE-2026-79253 | Google | medium 6.5 | Google Chrome: improper input validation | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79254 CVE-2026-79254 | Google | medium 4.3 | Google Chrome: remote attacker could bypass system access restrictions | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79238 CVE-2026-79238 | Google | medium 4.3 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79239 CVE-2026-79239 | Google | medium 6.5 | Google Chrome: out-of-bounds read | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79240 CVE-2026-79240 | Google | high 8.8 | Google Chrome: out-of-bounds write | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79241 CVE-2026-79241 | Google | medium 6.5 | Google Chrome: out-of-bounds read | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79242 CVE-2026-79242 | Google | medium 5.3 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79243 CVE-2026-79243 | Google | medium 6.5 | Google Chrome: improper input validation | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79244 CVE-2026-79244 | Google | high 8.8 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79245 CVE-2026-79245 | Google | high 7.7 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79229 CVE-2026-79229 | Google | medium 6.5 | Google Chrome: uninitialized resource | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79230 CVE-2026-79230 | Google | high 8.8 | Google Chrome: improper input validation | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79231 CVE-2026-79231 | Google | high 8.8 | Google Chrome: buffer overflow | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79232 CVE-2026-79232 | Google | critical 9.6 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79233 CVE-2026-79233 | Google | medium 4.3 | Google Chrome: spoofing | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79234 CVE-2026-79234 | Google | medium 6.5 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79235 CVE-2026-79235 | Google | critical 9.6 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79236 CVE-2026-79236 | Google | high 8.8 | Google Chrome: type confusion | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79237 CVE-2026-79237 | Google | medium 4.3 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79220 CVE-2026-79220 | Google | medium 5.3 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79221 CVE-2026-79221 | Google | medium 6.5 | Google Chrome: uninitialized resource | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79222 CVE-2026-79222 | Google | medium 4.3 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79223 CVE-2026-79223 | Google | high 8.8 | Google Chrome: integer overflow | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79224 CVE-2026-79224 | Google | high 8.3 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79225 CVE-2026-79225 | Google | medium 4.3 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79226 CVE-2026-79226 | Google | high 8.8 | Google Chrome: improper privilege management | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79227 CVE-2026-79227 | Google | high 8.8 | Google Chrome: type confusion | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79228 CVE-2026-79228 | Google | low 3.1 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79211 CVE-2026-79211 | Google | medium 4.3 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79212 CVE-2026-79212 | Google | medium 4.3 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79213 CVE-2026-79213 | Google | medium 4.3 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79214 CVE-2026-79214 | Google | medium 4.3 | Google Chrome: improper input validation | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79215 CVE-2026-79215 | Google | high 8.8 | Google Chrome: integer overflow | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79216 CVE-2026-79216 | Google | high 7.5 | Google Chrome: buffer overflow | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79217 CVE-2026-79217 | Google | medium 4.3 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79218 CVE-2026-79218 | Google | high 8.3 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79219 CVE-2026-79219 | Google | high 8.8 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79202 CVE-2026-79202 | Google | high 8.8 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79203 CVE-2026-79203 | Google | low 3.1 | Google Chrome: improper input validation | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79204 CVE-2026-79204 | Google | medium 5.4 | Google Chrome: spoofing | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79205 CVE-2026-79205 | Google | medium 4.3 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79206 CVE-2026-79206 | Google | medium 6.5 | Google Chrome: out-of-bounds read | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79207 CVE-2026-79207 | Google | medium 6.5 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79208 CVE-2026-79208 | Google | medium 5.9 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79209 CVE-2026-79209 | Google | high 8.8 | Google Chrome: type confusion | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79210 CVE-2026-79210 | Google | high 8.3 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79193 CVE-2026-79193 | Google | medium 4.3 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79194 CVE-2026-79194 | Google | high 8.1 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79195 CVE-2026-79195 | Google | high 8.8 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79196 CVE-2026-79196 | Google | medium 5.3 | Google Chrome: race condition | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79197 CVE-2026-79197 | Google | high 8.8 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79198 CVE-2026-79198 | Google | high 8.8 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79199 CVE-2026-79199 | Google | medium 4.3 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79200 CVE-2026-79200 | Google | critical 9.6 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79201 CVE-2026-79201 | Google | medium 4.3 | Google Chrome: improper access control | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79184 CVE-2026-79184 | Google | medium 4.3 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79185 CVE-2026-79185 | Google | medium 4.3 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79186 CVE-2026-79186 | Google | low 3.1 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79187 CVE-2026-79187 | Google | high 8.8 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79188 CVE-2026-79188 | Google | critical 9.6 | Google Chrome: out-of-bounds write | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79189 CVE-2026-79189 | Google | critical 9.6 | Google Chrome: out-of-bounds write | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79190 CVE-2026-79190 | Google | medium 4.3 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79191 CVE-2026-79191 | Google | low 3.1 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79192 CVE-2026-79192 | Google | medium 4.3 | Google Chrome: improper input validation | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79175 CVE-2026-79175 | Google | high 8.3 | Google Chrome: type confusion | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79176 CVE-2026-79176 | Google | medium 6.5 | Google Chrome: spoofing | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79177 CVE-2026-79177 | Google | medium 6.5 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79178 CVE-2026-79178 | Google | medium 4.3 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79179 CVE-2026-79179 | Google | medium 6.5 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79180 CVE-2026-79180 | Google | medium 5.4 | Google Chrome: spoofing | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79181 CVE-2026-79181 | Google | medium 5.3 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79182 CVE-2026-79182 | Google | high 8.8 | Google Chrome: improper input validation | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79183 CVE-2026-79183 | Google | high 8.8 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79148 CVE-2026-79148 | Google | critical 9.1 | Off-by-one error in DevTools in Google Chrome prior to 152.0.7977.65 allowed a... | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79149 CVE-2026-79149 | Google | critical 9.6 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79150 CVE-2026-79150 | Google | critical 9.6 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79151 CVE-2026-79151 | Google | medium 4.3 | Google Chrome: improper input validation | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79152 CVE-2026-79152 | Google | critical 9.8 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79154 CVE-2026-79154 | Google | medium 6.5 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79155 CVE-2026-79155 | Google | high 8.3 | Google Chrome: race condition | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79173 CVE-2026-79173 | Google | medium 5.4 | Google Chrome: spoofing | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79174 CVE-2026-79174 | Google | medium 4.3 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79138 CVE-2026-79138 | Google | critical 9.6 | Google Chrome: out-of-bounds write | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79139 CVE-2026-79139 | Google | high 7.5 | Google Chrome: improper input validation | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79140 CVE-2026-79140 | Google | critical 9.6 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79141 CVE-2026-79141 | Google | medium 4.3 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79142 CVE-2026-79142 | Google | high 8.8 | Google Chrome: buffer overflow | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79143 CVE-2026-79143 | Google | medium 4.3 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79144 CVE-2026-79144 | Google | medium 4.3 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79146 CVE-2026-79146 | Google | medium 5.5 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79147 CVE-2026-79147 | Google | medium 5.3 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79129 CVE-2026-79129 | Google | critical 9.6 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79130 CVE-2026-79130 | Google | critical 9.6 | Google Chrome: buffer overflow | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79131 CVE-2026-79131 | Google | critical 9.6 | Google Chrome: out-of-bounds write | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79132 CVE-2026-79132 | Google | high 8.3 | Google Chrome: improper input validation | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79133 CVE-2026-79133 | Google | medium 6.5 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79134 CVE-2026-79134 | Google | medium 6.5 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79136 CVE-2026-79136 | Google | medium 4.3 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79137 CVE-2026-79137 | Google | medium 4.3 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79120 CVE-2026-79120 | Google | medium 6.5 | Google Chrome: uninitialized resource | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79121 CVE-2026-79121 | Google | high 8.3 | Google Chrome: improper input validation | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79122 CVE-2026-79122 | Google | medium 5.9 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79123 CVE-2026-79123 | Google | medium 6.5 | Google Chrome: improper input validation | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79124 CVE-2026-79124 | Google | medium 6.5 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79125 CVE-2026-79125 | Google | medium 6.5 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79126 CVE-2026-79126 | Google | medium 5.9 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79127 CVE-2026-79127 | Google | high 8.8 | Google Chrome: out-of-bounds write | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79128 CVE-2026-79128 | Google | critical 9.6 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79107 CVE-2026-79107 | Google | medium 6.5 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79108 CVE-2026-79108 | Google | medium 6.5 | Google Chrome: spoofing | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79109 CVE-2026-79109 | Google | high 8.3 | Google Chrome: improper input validation | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79110 CVE-2026-79110 | Google | medium 4.3 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79111 CVE-2026-79111 | Google | critical 9.6 | Google Chrome: improper input validation | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79112 CVE-2026-79112 | Google | medium 6.5 | Google Chrome: out-of-bounds read | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79116 CVE-2026-79116 | Google | medium 4.3 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79117 CVE-2026-79117 | Google | medium 4.3 | Google Chrome: race condition | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79118 CVE-2026-79118 | Google | medium 4.3 | Google Chrome: uninitialized resource | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79119 CVE-2026-79119 | Google | high 8.8 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79095 CVE-2026-79095 | Google | medium 4.3 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79097 CVE-2026-79097 | Google | high 8.8 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79098 CVE-2026-79098 | Google | medium 4.3 | Google Chrome: spoofing | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79099 CVE-2026-79099 | Google | medium 6.5 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79103 CVE-2026-79103 | Google | low 3.1 | Incorrect reference resolution in Speech in Google Chrome prior to... | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79104 CVE-2026-79104 | Google | medium 5.3 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79105 CVE-2026-79105 | Google | medium 4.3 | Google Chrome: improper input validation | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79106 CVE-2026-79106 | Google | medium 4.3 | Google Chrome: improper input validation | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79085 CVE-2026-79085 | Google | medium 4.3 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79086 CVE-2026-79086 | Google | medium 5.1 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79087 CVE-2026-79087 | Google | medium 4.3 | Google Chrome: remote attacker could potentially bypass system access | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79088 CVE-2026-79088 | Google | medium 6.5 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79089 CVE-2026-79089 | Google | medium 5.3 | Google Chrome: race condition | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79090 CVE-2026-79090 | Google | critical 9.8 | Google Chrome: improper privilege management | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79091 CVE-2026-79091 | Google | critical 9.6 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79093 CVE-2026-79093 | Google | medium 4.3 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79094 CVE-2026-79094 | Google | medium 6.5 | Google Chrome: race condition | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79073 CVE-2026-79073 | Google | high 8.8 | Google Chrome: remote code execution | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79074 CVE-2026-79074 | Google | medium 5.3 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79075 CVE-2026-79075 | Google | medium 6.5 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79076 CVE-2026-79076 | Google | medium 6.5 | Google Chrome: improper input validation | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79077 CVE-2026-79077 | Google | medium 4.3 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79078 CVE-2026-79078 | Google | critical 9.6 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79082 CVE-2026-79082 | Google | medium 4.3 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79083 CVE-2026-79083 | Google | high 7.5 | Google Chrome: remote code execution | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79084 CVE-2026-79084 | Google | medium 4.3 | Google Chrome: weak encryption | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79064 CVE-2026-79064 | Google | critical 9.6 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79065 CVE-2026-79065 | Google | medium 4.3 | Google Chrome: improper input validation | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79066 CVE-2026-79066 | Google | low 3.1 | Google Chrome: improper input validation | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79067 CVE-2026-79067 | Google | medium 4.3 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79068 CVE-2026-79068 | Google | medium 4.3 | Google Chrome: remote attacker could potentially bypass web origin policy | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79069 CVE-2026-79069 | Google | high 8.8 | Google Chrome: memory corruption | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79070 CVE-2026-79070 | Google | medium 4.3 | Google Chrome: remote attacker could bypass web origin policy | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79071 CVE-2026-79071 | Google | high 8.3 | Google Chrome: race condition | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79072 CVE-2026-79072 | Google | high 8.1 | Google Chrome: remote attacker could potentially read memory inside | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79052 CVE-2026-79052 | Google | critical 9.6 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79053 CVE-2026-79053 | Google | low 3.1 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79054 CVE-2026-79054 | Google | high 8.3 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79055 CVE-2026-79055 | Google | medium 5.1 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79056 CVE-2026-79056 | Google | critical 9.6 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79057 CVE-2026-79057 | Google | high 8.1 | Google Chrome: race condition | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79058 CVE-2026-79058 | Google | critical 9.1 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79059 CVE-2026-79059 | Google | low 3.1 | Google Chrome: information disclosure | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79060 CVE-2026-79060 | Google | medium 6.5 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79043 CVE-2026-79043 | Google | critical 9.6 | Google Chrome: out-of-bounds write | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79044 CVE-2026-79044 | Google | medium 5.3 | Google Chrome: missing authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79045 CVE-2026-79045 | Google | high 8.8 | Google Chrome: type confusion | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79046 CVE-2026-79046 | Google | medium 4.3 | Google Chrome: race condition | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79047 CVE-2026-79047 | Google | critical 9.6 | Google Chrome: use after free | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79048 CVE-2026-79048 | Google | high 8.8 | Google Chrome: out-of-bounds write | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79049 CVE-2026-79049 | Google | medium 4.3 | Google Chrome: remote attacker could bypass system access restrictions | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79050 CVE-2026-79050 | Google | medium 4.3 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79051 CVE-2026-79051 | Google | medium 4.3 | Google Chrome: improper authorization | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html 2026-08-25 | CVE-2026-79031 CVE-2026-79031 | Google | low 3.1 | Google Chrome: remote attacker could bypass site isolation | https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html