| Sep 25 | FTM 4.x ALL could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity injection flaw. CVE-2026-93030Medium6.5no fix yet | | Medium6.5 | No fix yet |
| Sep 25 | A flaw was found in the Fine-Grained Admin Permissions (FGAP v2) feature of Keycloak, an identity and access management solution. CVE-2026-96448Medium6.6no fix yet | | Medium6.6 | No fix yet |
| Sep 25 | Keycloak provides a feature called mTLS holder-of-key binding which ensures that a token can only be used by the client that originally requested it by binding it to their digital certificate. CVE-2026-97846Medium6.8no fix yet | | Medium6.8 | No fix yet |
| Sep 24 | Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. CVE-2026-56792Medium4.4fixed in Rugged Control Center (RCC) 5.2.206 | | Medium4.4 | Rugged Control Center (RCC) 5.2.206 |
| Sep 24 | PYTHON-5990 Forced Unix domain socket connection via a .sock KMS endpoint in client-side field level encryption CVE-2026-96747Medium5.3fixed in 4.18.2 | | Medium5.3 | 4.18.2 |
| Sep 24 | PHP object injection via unsuppressible __pclass class inference in command monitoring events CVE-2026-96745Medium6.3fixed in 1.21.10, 2.1.10, 2.5.3 | | Medium6.3 | 1.21.10, 2.1.10, 2.5.3 |
| Sep 24 | IBM ContextForge MCP Gateway 1.0.0 through 1.0.8 was vulnerable to path traversal in its Admin API log-download endpoint (`GET /v1/admin/logs/file`). The path confinement check uses `str. CVE-2026-77825Medium4.9no fix yet | | Medium4.9 | No fix yet |
| Sep 24 | IBM Concert 1.0.0 through 3.0.0 allows recursive copying of directories without proper controls which can lead to unintentional inclusion of sensitive or unnecessary files and increased attack... CVE-2026-6544Medium6.2no fix yet | | Medium6.2 | No fix yet |
| Sep 24 | IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950. CVE-2026-18870Medium4.3no fix yet | | Medium4.3 | No fix yet |
| Sep 24 | Velociraptor contains a deadlock condition that may be triggered by authenticated users. The issue stems from a lock management bug in the user management module. CVE-2026-77798Medium6.5fixed in Velociraptor 0.77.2 | | Medium6.5 | Velociraptor 0.77.2 |
| Sep 24 | IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950. CVE-2026-17503Medium5.1no fix yet | | Medium5.1 | No fix yet |
| Sep 24 | IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950. CVE-2026-17504Medium5.1no fix yet | | Medium5.1 | No fix yet |
| Sep 24 | IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950. CVE-2026-17413Medium5.1no fix yet | | Medium5.1 | No fix yet |
| Sep 24 | An authorization bypass was found in the Ansible Automation Platform (AAP) gateway. CVE-2026-94416Medium6.8no fix yet | | Medium6.8 | No fix yet |
| Sep 24 | A flaw was found in the Admin REST API of Keycloak, an identity and access management solution. CVE-2026-97311Medium4.3no fix yet | | Medium4.3 | No fix yet |
| Sep 24 | Authentication bypass vulnerability in the password authentication mechanism of the Qt VNC Server module. CVE-2026-79680Medium4.5fixed in qt 6.8.9, qt 6.11.3 | | Medium4.5 | qt 6.8.9, qt 6.11.3 |
| Sep 24 | Authorization Bypass Through User-Controlled Key in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022. CVE-2026-78310Medium4.3fixed in DIAEnergie 1.11.00.022 | | Medium4.3 | DIAEnergie 1.11.00.022 |
| Sep 24 | Improper Access Control in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022. CVE-2026-78313Medium6.5fixed in DIAEnergie 1.11.00.022 | | Medium6.5 | DIAEnergie 1.11.00.022 |
| Sep 24 | Out-of-bounds read vulnerability in the graphics module. Successful exploitation of this vulnerability may affect availability. CVE-2026-81645Medium5.9no fix yet | | Medium5.9 | No fix yet |
| Sep 24 | A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management solution. CVE-2026-97176Medium4.2no fix yet | | Medium4.2 | No fix yet |
| Sep 24 | A flaw was found in the user update mechanism of the Keycloak Admin REST API. CVE-2026-97177Medium6.6no fix yet | | Medium6.6 | No fix yet |
| Sep 24 | GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4. CVE-2026-92529Medium4.3fixed in GitLab 19.2.7, GitLab 19.3.3, GitLab 19.4.1 | | Medium4.3 | GitLab 19.2.7, GitLab 19.3.3, GitLab 19.4.1 |
| Sep 24 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.1 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4. CVE-2026-92530Medium4.3fixed in GitLab 19.2.7, GitLab 19.3.3, GitLab 19.4.1 | | Medium4.3 | GitLab 19.2.7, GitLab 19.3.3, GitLab 19.4.1 |
| Sep 24 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4. CVE-2026-92874Medium5.4fixed in GitLab 19.2.7, GitLab 19.3.3, GitLab 19.4.1 | | Medium5.4 | GitLab 19.2.7, GitLab 19.3.3, GitLab 19.4.1 |
| Sep 23 | IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. CVE-2026-6925Medium5.3no fix yet | | Medium5.3 | No fix yet |
| Sep 23 | IBM Concert 1.0.0 through 3.0.0 is vulnerable to improper access control which allows unauthorized modification of application files. CVE-2026-6718Medium6.2no fix yet | | Medium6.2 | No fix yet |
| Sep 23 | An argument-injection flaw was found in the Ansible Automation Platform automation-controller system-job subsystem. CVE-2026-84724Medium6.6no fix yet | | Medium6.6 | No fix yet |
| Sep 23 | A flaw was found in the automation-controller instance install-bundle endpoint. When a System Administrator downloads an execution/hop node's install bundle, the controller signs an X. CVE-2026-84716Medium6.6no fix yet | | Medium6.6 | No fix yet |
| Sep 23 | A flaw was found in the Ansible Automation Platform automation-controller. CVE-2026-84717Medium5.3no fix yet | | Medium5.3 | No fix yet |
| Sep 23 | A flaw was found in the Ansible Automation Platform automation-controller. CVE-2026-84718Medium4.3no fix yet | | Medium4.3 | No fix yet |
| Sep 23 | A flaw was found in the Ansible Automation Platform automation-controller. The WorkflowJobNode. CVE-2026-84720Medium6.5no fix yet | | Medium6.5 | No fix yet |
| Sep 23 | A server-side request forgery flaw was found in the Ansible Automation Platform automation-controller email notification backend. CVE-2026-84721Medium6.4no fix yet | | Medium6.4 | No fix yet |
| Sep 23 | A flaw was found in the automation-controller API. The unauthenticated health-check endpoint /api/v2/ping/ (ApiV2PingView, AllowAny) over-serializes RBAC-gated automation-mesh data into its anonymous... CVE-2026-84712Medium5.3no fix yet | | Medium5.3 | No fix yet |
| Sep 23 | A flaw was found in the automation-controller notification subsystem. Although NotificationTemplate. CVE-2026-84713Medium6.5no fix yet | | Medium6.5 | No fix yet |
| Sep 23 | An out-of-bounds heap read flaw was found in GIMP's TIM image loader. CVE-2026-96545Medium4.4no fix yet | | Medium4.4 | No fix yet |
| Sep 23 | StringListPathField.to_internal_value() calls os.path.exists() on unbounded user-supplied paths. 200 vs 400 response reveals existence of arbitrary absolute paths on the controller-web pod. CVE-2026-71462Medium4.1no fix yet | | Medium4.1 | No fix yet |
| Sep 23 | JobJobEventsChildrenSummary view has no model/parent_model. ModelAccessPermission.check_get_permissions() falls through (returns True) for any authenticated user. CVE-2026-71459Medium5.0no fix yet | | Medium5.0 | No fix yet |
| Sep 23 | /api/v2/config/ is protected only by IsAuthenticated. license_info (account_number, subscription_id, pool_id, sku, support_level, instance counts) returned to any authenticated user. CVE-2026-71460Medium4.3no fix yet | | Medium4.3 | No fix yet |
| Sep 23 | HostList.list() catches bare Exception and returns str(e) verbatim. CVE-2026-71461Medium4.3no fix yet | | Medium4.3 | No fix yet |
| Sep 23 | URLModificationMiddleware resolves named-URL lookups against unfiltered Model.objects before RBAC. CVE-2026-71458Medium5.0no fix yet | | Medium5.0 | No fix yet |
| Sep 23 | BusyBox httpd IP deny rules with invalid CIDR prefix lengths fail open, leaving a parsed IP with a zeroed mask so the rule matches no clients. CVE-2026-88831Medium5.3no fix yet | | Medium5.3 | No fix yet |
| Sep 23 | BusyBox dpkg read_package_field() steps past a NUL terminator on malformed .deb packages, causing an out-of-bounds heap read. CVE-2026-88835Medium6.1no fix yet | | Medium6.1 | No fix yet |
| Sep 23 | BusyBox httpd treats yescrypt ($y$) password hashes as plaintext during Basic Authentication, inverting the authentication check. CVE-2026-88837Medium6.5no fix yet | | Medium6.5 | No fix yet |
| Sep 23 | BusyBox passwd/group tokenize() references a stale endpoint pointer after trimming, causing an out-of-bounds write of heap pointers. CVE-2026-88839Medium6.7no fix yet | | Medium6.7 | No fix yet |
| Sep 23 | BusyBox TLS get_client_hello() reads past the end of the input buffer when parsing a truncated ClientHello message. CVE-2026-88840Medium5.3no fix yet | | Medium5.3 | No fix yet |
| Sep 23 | IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. CVE-2026-3626Medium5.3no fix yet | | Medium5.3 | No fix yet |
| Sep 23 | IBM Concert 1.0.0 through 3.0.0 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files. CVE-2026-6327Medium4.3no fix yet | | Medium4.3 | No fix yet |
| Sep 23 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to missing authentication on the Business Rules Manager commands REST endpoint (`CommandsResource.java:31`). CVE-2026-19267Medium6.2no fix yet | | Medium6.2 | No fix yet |
| Sep 23 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to open redirect in the PMP `HostHeaderFilter` (`HostHeaderFilter.java:151`). CVE-2026-18505Medium5.4no fix yet | | Medium5.4 | No fix yet |
| Sep 23 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to achieve privilege escalation within the container due to improper privilege management. CVE-2026-19087Medium4.4no fix yet | | Medium4.4 | No fix yet |
| Sep 23 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to SQL injection. CVE-2026-18180Medium6.5no fix yet | | Medium6.5 | No fix yet |
| Sep 23 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Insufficient Session Expiration vulnerability. CVE-2026-73586Medium6.4fixed in Secure Connect Gateway (SCG) Policy Manager 5.36.00.16 or later | | Medium6.4 | Secure Connect Gateway (SCG) Policy Manager 5.36.00.16 or later |
| Sep 23 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Certificate Validation vulnerability. CVE-2026-73587Medium6.8fixed in Secure Connect Gateway (SCG) Policy Manager 5.36.00.16 or later | | Medium6.8 | Secure Connect Gateway (SCG) Policy Manager 5.36.00.16 or later |
| Sep 23 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains a Weak Encoding for Password vulnerability. CVE-2026-73589Medium6.3fixed in Secure Connect Gateway (SCG) Policy Manager 5.36.00.16 or later | | Medium6.3 | Secure Connect Gateway (SCG) Policy Manager 5.36.00.16 or later |
| Sep 23 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Restriction of Rendered UI Layers or Frames vulnerability. CVE-2026-71177Medium5.4fixed in Secure Connect Gateway (SCG) Policy Manager 5.36.00.16 or later | | Medium5.4 | Secure Connect Gateway (SCG) Policy Manager 5.36.00.16 or later |
| Sep 23 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Privilege Management vulnerability. CVE-2026-61413Medium6.8fixed in Secure Connect Gateway (SCG) Policy Manager 5.36.00.16 or later | | Medium6.8 | Secure Connect Gateway (SCG) Policy Manager 5.36.00.16 or later |
| Sep 23 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to clear active chat sessions due to improper authorization. CVE-2026-18179Medium6.5no fix yet | | Medium6.5 | No fix yet |
| Sep 23 | A flaw was found in the Conditional OTP authenticator of Keycloak, an identity and access management solution. CVE-2026-96445Medium6.8no fix yet | | Medium6.8 | No fix yet |
| Sep 23 | A flaw was found in the Pushed Authorization Request PAR implementation of Keycloak. CVE-2026-96446Medium4.2no fix yet | | Medium4.2 | No fix yet |
| Sep 23 | A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader’s handling of wide strings in embedded PDF JavaScript. CVE-2026-91817Medium6.1no fix yet | | Medium6.1 | No fix yet |