Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

7790 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.5Splunk

High [CVE-2026-76254] SPL Command Safeguards Bypass through Splunk Web in Splunk Enterprise

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, 9.4.14, and 9.3.14, an unauthenticated user could cause another user to dispatch arbitrary Search Processing Language (SPL) pipelines from Dataset Explorer with the same privileges as that user, which can allow for access to all relevant data and system integrity available to that user and affect system availability. The vulnerability is possible because Dataset Explorer does not validate or escape dataset names before building SPL searches and does not apply SPL safeguards for risky commands to those searches. The vulnerability requires the attacker to phish the user by tricking them into opening the crafted link. The unauthenticated user should not be able to exploit the vulnerability at will. For more information see Explore a dataset ( ) and SPL safeguards for risky commands ( ) in the Splunk documentation.

CVE-2026-76254
Splunk Enterprise
Aug 19, 2026
High8.8Splunk

High [CVE-2026-76253] Privilege Escalation through Scheduled Search Alert Action Configuration in Splunk Enterprise

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role with the schedule_search capability could run arbitrary Search Processing Language (SPL) commands with the highest level of system privilege and read every credential stored in the credential store, which can allow for disclosure and modification of all relevant data and affect system integrity and availability. The vulnerability is possible because scheduled search alert action configuration does not properly restrict user-specific alert action settings before the search scheduler runs alert actions. For more information see Create scheduled alerts ( ), Set up alert actions ( ), Define roles on the Splunk platform with capabilities ( ), and Configuration file precedence ( ) in the Splunk documentation.

CVE-2026-76253
Splunk Enterprise
Aug 19, 2026
High7.1Splunk

High [CVE-2026-76251] Missing Authorization through REST API Endpoints in the Splunk App for Splunk Observability Cloud

In Splunk Enterprise versions below 10.4.2, 10.2.6, and 10.0.9, a user who does not hold the "admin" or "power" Splunk roles could cause the Splunk App for Splunk Observability Cloud to forward requests to Splunk Observability Cloud, including the Splunk Observability Cloud access token stored for the app. With this access, the user could view all relevant data available to that token and make limited changes to Splunk Observability Cloud content. The vulnerability is possible because the app's Representational State Transfer (REST) API endpoint handlers do not enforce the read_o11y_content capability before forwarding requests with the stored access token. For more information see Define roles on the Splunk platform with capabilities ( ) in the Splunk documentation.

CVE-2026-76251
Splunk Enterprise
Aug 19, 2026
High8.0Red Hat

High [CVE-2026-76139] Bundle build execs unpinned stolostron/release@master with full build credentials

Bundle build execs unpinned stolostron/release@master with full build credentials. Red Hat rates this important (CVSS 8). Weakness: CWE-829. Red Hat lists fixing advisory RHSA-2026:60401 with package rhacm2/acm-operator-bundle:1787712120, rhacm2/acm-operator-bundle:1787738299, rhacm2/acm-operator-bundle:1787704547, rhacm2/acm-operator-bundle:1787711895. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.

CVE-2026-76139
Unclassified
Aug 19, 2026
High7.1Red Hat Updated

High [CVE-2026-68553] Format string vulnerability leads to denial of service and information disclosure

Format string vulnerability leads to denial of service and information disclosure. Red Hat rates this important (CVSS 7.1). Weakness: CWE-134.

CVE-2026-68553
Unclassified
Aug 19, 2026
High7.7Red Hat

High [CVE-2026-75569] Bundle-generation business logic fetched from mutable stolostron/release@master

Bundle-generation business logic fetched from mutable stolostron/release@master. Red Hat rates this important (CVSS 7.7). Weakness: CWE-829. Red Hat lists fixing advisory RHSA-2026:59643 with package multicluster-engine/mce-operator-bundle:1787318262, multicluster-engine/mce-operator-bundle:1787321579, multicluster-engine/mce-operator-bundle:1787263075, multicluster-engine/mce-operator-bundle:1787317415. Affected product named by the advisory: Multicluster Engine for Kubernetes.

CVE-2026-75569
Unclassified
Aug 19, 2026
High8.8Red Hat

High [CVE-2026-63633] Arbitrary code execution via heap buffer overflow in Opus audio decode

Arbitrary code execution via heap buffer overflow in Opus audio decode. Red Hat rates this important (CVSS 8.8). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: freerdp.

CVE-2026-63633
Red Hat Enterprise Linux
Aug 19, 2026
High8.2Red Hat

High [CVE-2026-50152] MON subscription handler exposes config-key store to low-privilege CephX users

MON subscription handler exposes config-key store to low-privilege CephX users. Red Hat rates this important (CVSS 8.2). Weakness: CWE-862. Affected products named by the advisory: Red Hat Ceph Storage 4; Red Hat Ceph Storage 5; Red Hat Ceph Storage 6; Red Hat Ceph Storage 7; and 2 more. Affected products named by the advisory: Red Hat Ceph Storage 8; Red Hat Ceph Storage 9.

CVE-2026-50152
Unclassified
Aug 19, 2026
High8.2Red Hat

High [CVE-2026-54330] RGW SigV4 verifier allows attachment of arbitrary unsigned x-amz-* headers leading to privilege escalation

RGW SigV4 verifier allows attachment of arbitrary unsigned x-amz-* headers leading to privilege escalation. Red Hat rates this important (CVSS 8.2). Weakness: CWE-347. Affected products named by the advisory: Red Hat Ceph Storage 4; Red Hat Ceph Storage 5; Red Hat Ceph Storage 6; Red Hat Ceph Storage 7; and 2 more. Affected products named by the advisory: Red Hat Ceph Storage 8; Red Hat Ceph Storage 9.

CVE-2026-54330
Unclassified
Aug 19, 2026
High8.5Red Hat

High [CVE-2026-39944] RGW STS session tokens vulnerable to CBC bit-flip attack enabling admin privilege escalation

RGW STS session tokens vulnerable to CBC bit-flip attack enabling admin privilege escalation. Red Hat rates this important (CVSS 8.5). Weakness: CWE-327. Affected products named by the advisory: Red Hat Ceph Storage 4; Red Hat Ceph Storage 5; Red Hat Ceph Storage 6; Red Hat Ceph Storage 7; and 2 more. Affected products named by the advisory: Red Hat Ceph Storage 8; Red Hat Ceph Storage 9.

CVE-2026-39944
Unclassified
Aug 19, 2026
High8.1Red Hat

High [CVE-2026-55192] Out-of-bounds read leads to memory disclosure or client crash

Out-of-bounds read leads to memory disclosure or client crash. Red Hat rates this important (CVSS 8.1). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: freerdp.

CVE-2026-55192
Red Hat Enterprise Linux
Aug 19, 2026
High8.8Red Hat

High [CVE-2026-55194] Heap-buffer-overflow allows arbitrary code execution via crafted RPC response

Heap-buffer-overflow allows arbitrary code execution via crafted RPC response. Red Hat rates this important (CVSS 8.8). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: freerdp.

CVE-2026-55194
Red Hat Enterprise Linux
Aug 19, 2026
High8.8Red Hat Updated

High [CVE-2026-55193] Remote code execution or client crash via malicious TS Gateway

Remote code execution or client crash via malicious TS Gateway. Red Hat rates this important (CVSS 8.8). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: freerdp.

CVE-2026-55193
Red Hat Enterprise Linux
Aug 19, 2026
High8.8Red Hat Updated

High [CVE-2026-55191] Arbitrary code execution via heap-buffer-overflow in AVC444 YUV buffer allocation

Arbitrary code execution via heap-buffer-overflow in AVC444 YUV buffer allocation. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: freerdp.

CVE-2026-55191
Red Hat Enterprise Linux
Aug 19, 2026
High7.1Red Hat Updated

High [CVE-2026-75147] Information disclosure or denial of service via crafted AV1 RTP packet

Information disclosure or denial of service via crafted AV1 RTP packet. Red Hat rates this important (CVSS 7.1). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-75147
Unclassified
Aug 19, 2026
High8.1Red Hat Updated

High [CVE-2026-75146] Information disclosure and denial of service via out-of-bounds read in DASH demuxer

Information disclosure and denial of service via out-of-bounds read in DASH demuxer. Red Hat rates this important (CVSS 8.1). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-75146
Unclassified
Aug 19, 2026
High7.8Red Hat Updated

High [CVE-2026-75144] Memory corruption via crafted Dirac data unit

Memory corruption via crafted Dirac data unit. Red Hat rates this important (CVSS 7.8). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-75144
Unclassified
Aug 19, 2026
High7.8Red Hat Updated

High [CVE-2026-75142] Stack Buffer Overflow in MPEG-PS Muxer

Stack Buffer Overflow in MPEG-PS Muxer. Red Hat rates this important (CVSS 7.8). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-75142
Unclassified
Aug 19, 2026
High7.5Cisco

High [CVE-2026-20320] Cisco BroadWorks Out-of-Band Blind XML External Entity Injection Vulnerability

A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an unauthenticated, remote attacker to read sensitive configuration information on an affected system. This vulnerability exists because XML entries are improperly parsed due to external entity resolution being allowed by default. An attacker could exploit this vulnerability by sending a crafted XML message to the Open Client Interface – Provisioning (OCI-P) service. A successful exploit could allow the attacker to view sensitive files from the filesystem with the privileges of the Cisco BroadWorks user. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

CVE-2026-20320
Unclassified
Aug 19, 2026
High7.8Red Hat Updated

High [CVE-2026-76233] Arbitrary command execution via gleam manager command injection

Arbitrary command execution via gleam manager command injection. Red Hat rates this important (CVSS 7.8). Weakness: CWE-78.

CVE-2026-76233
Unclassified
Aug 19, 2026