Skip to content
VulniPulse

Complete feed

Action required

Critical/high still unreviewed, or CISA KEV listed

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High8.8Red Hat Updated

High [CVE-2026-64783] Processing maliciously crafted web content may lead to an unexpected Safari crash

Processing maliciously crafted web content may lead to an unexpected Safari crash. Red Hat rates this important (CVSS 8.8). Weakness: CWE-416. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat package: webkitgtk3; Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.

CVE-2026-64783
Red Hat Enterprise Linux
Aug 20, 2026
Critical9.1Splunk

Critical [CVE-2026-76404] Remote Code Execution (RCE) through Deserialization of Untrusted Data in Splunk MCP Server app

In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands on the underlying operating system. The vulnerability is possible because of missing input validation in the app's credential management component, which deserializes stored data without checking whether the content is of the expected type.

CVE-2026-76404
Unclassified
Aug 19, 2026
Critical9.4Splunk

Critical [CVE-2026-76312] Improper Access Control through Embedded Reports in Splunk Enterprise

In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who can read the Hypertext Markup Language (HTML) source of a page that embeds a Splunk report could use exposed session material to access all relevant data and affect system integrity. The vulnerability is possible because the dispatch archive download path does not correctly enforce the embedded-report authorization boundary and includes sensitive session material in archived search-job data. For more information see Additional configuration for embedded reports ( ) and Embed scheduled reports ( ) in the Splunk documentation.

CVE-2026-76312
Splunk Enterprise
Aug 19, 2026
Critical9.4Splunk

Critical [CVE-2026-76311] Improper Access Control in Embedded Report Dispatch Archives in Splunk Enterprise

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the dispatch archive for an embedded report search job and use exposed session material to access all relevant data and affect system integrity on the Splunk platform instance. The vulnerability is possible because the embedded report authorization flow does not block dispatch archive download requests before Splunk Enterprise begins sending the archive to the requester. For more information see Additional configuration for embedded reports ( ) and Embed scheduled reports ( ) in the Splunk documentation.

CVE-2026-76311
Splunk Enterprise
Aug 19, 2026
Critical9.4Splunk

Critical [CVE-2026-76310] Improper Access Control through Embedded Report REST API Requests in Splunk Enterprise

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the associated search job dispatch archive, recover session material, and use it to access all relevant data available to the report owner and affect system integrity, including by performing administrative actions when the owner holds the "admin" Splunk role. The vulnerability is possible because embedded report access does not block Representational State Transfer (REST) API dispatch archive download requests. For more information see Additional configuration for embedded reports ( ) and About configuring role-based user access ( ) in the Splunk documentation.

CVE-2026-76310
Splunk Enterprise
Aug 19, 2026
Critical9.9Vendor: HighRed Hat Updated

Critical [CVE-2026-70496] operator ClusterRole is cluster-admin equivalent via impersonate, RBAC write, CSR approve, and ManifestWork

operator ClusterRole is cluster-admin equivalent via impersonate, RBAC write, CSR approve, and ManifestWork. Red Hat rates this important (CVSS 9.9). Weakness: CWE-250. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/acm-search-v2-rhel9:1787682033, rhacm2/acm-search-v2-rhel9:1787681674, rhacm2/acm-search-v2-rhel9:1787681686, rhacm2/acm-search-v2-rhel9:1787682112. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.

CVE-2026-70496
Unclassified
Aug 19, 2026
Critical9.1Vendor: HighRed Hat Updated

Critical [CVE-2026-71470] Search CR imageOverride/arguments/envVar flow unsanitized into pods running impersonating SA

Search CR imageOverride/arguments/envVar flow unsanitized into pods running impersonating SA. Red Hat rates this important (CVSS 9.1). Weakness: CWE-913. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/acm-search-v2-rhel9:1787682033, rhacm2/acm-search-v2-rhel9:1787681674, rhacm2/acm-search-v2-rhel9:1787681686, rhacm2/acm-search-v2-rhel9:1787682112. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.

CVE-2026-71470
Unclassified
Aug 19, 2026
Critical9.8Red Hat Updated

Critical [CVE-2026-75143] FFmpeg Heap Buffer Overflow via RIST Protocol Reader

FFmpeg Heap Buffer Overflow via RIST Protocol Reader. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-120.

CVE-2026-75143
Unclassified
Aug 19, 2026
Critical10.0Cisco Exploited

Critical [CVE-2026-20231 +4] Cisco Secure Workload Software Security Hardening Release: August 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and to streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class — Common Weakness Enumeration (CWE) — and assigned a single Common Vulnerabilities and Exposures Identifier (CVE ID) to each CWE grouping. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.

CVE-2026-20231CVE-2026-20315CVE-2026-20317+2
Unclassified
Aug 19, 2026
Critical10.0Cisco Exploited

Critical [CVE-2026-20030 +3] Cisco Crosswork Security Hardening Release: August 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and to streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class — Common Weakness Enumeration (CWE) — and assigned a single Common Vulnerabilities and Exposures Identifier (CVE ID) to each CWE grouping. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. Affected product named by the advisory: Crosswork Planning.

CVE-2026-20030CVE-2026-20357CVE-2026-20358+1
Unclassified
Aug 19, 2026
Critical9.3Vendor: HighRed Hat

Critical [CVE-2026-66794] unauthenticated SSRF to arbitrary managed-cluster services via public Route

unauthenticated SSRF to arbitrary managed-cluster services via public Route. Red Hat rates this important (CVSS 9.3). Weakness: CWE-918. Red Hat lists fixing advisory RHSA-2026:59593 with package multicluster-engine/cluster-proxy-addon-rhel9:1787275519, multicluster-engine/cluster-proxy-rhel9:1787276784, multicluster-engine/cluster-proxy-addon-rhel9:1787275318, multicluster-engine/cluster-proxy-addon-rhel9:1787274923. Affected product named by the advisory: Multicluster Engine for Kubernetes.

CVE-2026-66794
Unclassified
Aug 19, 2026
Critical9.3NetScaler

Critical [CVE-2026-19490] NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

CVE-2026-19490
NetScaler Gateway
Aug 19, 2026
High7.4Splunk

High [CVE-2026-76403] Improper Certificate Validation through HTTP Event Collector Kerberos Authentication in Splunk Connect for Kafka

In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user positioned in the network path could read or alter all relevant data sent from the connector when Kerberos authentication is used with Hypertext Transfer Protocol (HTTP) Event Collector in Splunk Enterprise. The vulnerability is possible because the Kerberos authentication path does not apply the configured certificate validation options when it builds the HTTP client. For more information see Install Splunk Connect for Kafka ( ), Security configurations for Splunk Connect for Kafka ( ), and Set up and use HTTP Event Collector with configuration files ( ) in the Splunk documentation.

CVE-2026-76403
Unclassified
Aug 19, 2026
High8.2Splunk

High [CVE-2026-76402] Server-Side Request Forgery (SSRF) through the REST API in Splunk Connect for Kafka

In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API could configure a non-secure Hypertext Transfer Protocol (HTTP) Event Collector endpoint in Splunk Enterprise that causes the connector to send authentication credentials to an attacker-controlled server, allowing for exposure of credentials that compromise all relevant data sent through the connector and limited alteration of event delivery. The vulnerability is possible because HTTP Event Collector endpoint validation does not require secure transport by default. For more information see Install Splunk Connect for Kafka ( ), Data ingestion parameters for Splunk Connect for Kafka ( ), and Set up and use HTTP Event Collector with configuration files ( ) in the Splunk documentation.

CVE-2026-76402
Unclassified
Aug 19, 2026
High8.1Splunk

High [CVE-2026-76399] Incorrect Permission Assignment for Scheduled Searches in Splunk AI Toolkit

In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify app-provided scheduled searches to run arbitrary Search Processing Language (SPL) using the permissions of the search owner, which could allow access to all relevant data and affect system integrity. The vulnerability is possible because Splunk AI Toolkit gives the "power" Splunk role permission to modify scheduled searches that run using the permissions of the search owner.

CVE-2026-76399
Unclassified
Aug 19, 2026
High8.1Splunk

High [CVE-2026-76397] Improper Access Control in Experiment History through the REST API in Splunk AI Toolkit

In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could access and delete all relevant data in experiment history, including data associated with other users. The vulnerability is possible because Splunk AI Toolkit does not preserve the trusted experiment scope when it processes caller-controlled query values before accessing restricted history data. For more information see Experiment Assistants ( ) in the Splunk documentation.

CVE-2026-76397
Unclassified
Aug 19, 2026
High7.5Splunk

High [CVE-2026-76396] Improper Access Control through Scheduled Searches in Splunk AI Toolkit

In Splunk AI Toolkit versions below 6.0.0, a user that holds a role with the schedule_search capability could cause a scheduled search to load and deserialize a model file through the apply search command. The improper access control is possible because Splunk AI Toolkit does not mark the apply search command as risky. For more information see Troubleshoot the AI Toolkit ( ) in the Splunk documentation.

CVE-2026-76396
Unclassified
Aug 19, 2026
High8.8Splunk

High [CVE-2026-76395] Remote Code Execution (RCE) through Deserialization of Untrusted Data in the Model Loading REST API in Splunk AI Toolkit

In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code on the Splunk server by loading a model file containing crafted sparse matrix data. The deserialization of untrusted data is possible because a model codec in Splunk AI Toolkit deserializes sparse matrix data without guarding against embedded pickle content. For more information see Troubleshoot the Splunk Machine Learning Toolkit ( ) in the Splunk documentation.

CVE-2026-76395
Unclassified
Aug 19, 2026
High8.3Splunk

High [CVE-2026-76394] Missing Authorization in Container and Connection Management through the REST API in Splunk AI Toolkit

In Splunk AI Toolkit versions below 6.0.0, a low-privileged user who does not hold the "admin" or "power" Splunk roles could start, stop, and configure containers, and read or modify connection and configuration data through the Representational State Transfer (REST) API. The missing authorization is possible because multiple REST API handlers in Splunk AI Toolkit do not enforce authorization checks. For more information see Troubleshoot the Splunk Machine Learning Toolkit ( ) in the Splunk documentation.

CVE-2026-76394
Unclassified
Aug 19, 2026
High8.3Splunk

High [CVE-2026-76391] Improper Privilege Management through Agent Run History in Splunk AI Toolkit

In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could run searches with system-level privileges, access all relevant data, affect system integrity, and read or delete search jobs belonging to other users through Agent Run History. The improper privilege management is possible because the Agent Run History handler replaces the calling user session key with a system authentication token before it performs search operations. For more information see AI Toolkit Agent Launchpad ( ) in the Splunk documentation.

CVE-2026-76391
Unclassified
Aug 19, 2026