Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

569 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Critical9.1Apache Updated

Critical [CVE-2026-59085] Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook module, exploitable via webhook delivery requests

Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook module, exploitable via webhook delivery requests. This issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.

CVE-2026-59085
Infra & Gateways
Aug 21, 2026
Critical9.1Apache Updated

Critical [CVE-2026-61398] Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Instance Reset Password functionality

Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Instance Reset Password functionality. This issue affects Apache CloudStack: from 4.15.1.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.

CVE-2026-61398
Infra & Gateways
Aug 21, 2026
Critical9.1Apache Updated

Critical [CVE-2026-62440] Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service (CKS) plugin, allowing cross-tenant manipulation of the Kubernetes cluster while adding and removing nodes

Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service (CKS) plugin, allowing cross-tenant manipulation of the Kubernetes cluster while adding and removing nodes. This issue affects Apache CloudStack: from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.22.1.1 or later, which fixes the issue.

CVE-2026-62440
Infra & Gateways
Aug 21, 2026
Critical9.1NetApp

Critical [CVE-2026-40976] Spring Boot Vulnerability in NetApp Products

Spring Boot versions 4.0.0 through 4.0.5 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-40976
Unclassified
Aug 21, 2026
Critical9.6Vendor: HighRed Hat Updated

Critical [CVE-2026-76018] Arbitrary Code Execution via crafted file in Import component

Arbitrary Code Execution via crafted file in Import component. Red Hat rates this important (CVSS 9.6). Weakness: CWE-641.

CVE-2026-76018
Unclassified
Aug 20, 2026
Critical9.9Vendor: HighRed Hat Updated

Critical [CVE-2026-67567] HelmRelease chart applied with controller SA without GVK or namespace restriction

HelmRelease chart applied with controller SA without GVK or namespace restriction. Red Hat rates this important (CVSS 9.9). Weakness: CWE-441. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/multicluster-operators-subscription-rhel9:1787242108, rhacm2/multicluster-operators-subscription-rhel9:1787263693, rhacm2/multicluster-operators-subscription-rhel9:1787242321, rhacm2/multicluster-operators-subscription-rhel9:1787240030. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat Advanced Cluster Management for Kubernetes 2.17.

CVE-2026-67567
Unclassified
Aug 20, 2026
Critical9.9Vendor: HighRed Hat

Critical [CVE-2026-66788] arbitrary local-namespace injection via attacker-controlled LabelSourceNamespace

arbitrary local-namespace injection via attacker-controlled LabelSourceNamespace. Red Hat rates this important (CVSS 9.9). Weakness: CWE-284. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-66788
Unclassified
Aug 20, 2026
Critical9.9Vendor: HighRed Hat Updated

Critical [CVE-2026-66785] unvalidated Endpoint.Spec.Subnets propagated into WireGuard AllowedIPs / IPsec enables traffic hijack

unvalidated Endpoint. Spec. Subnets propagated into WireGuard AllowedIPs / IPsec enables traffic hijack. Red Hat rates this important (CVSS 9.9). Weakness: CWE-20. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-66785
Unclassified
Aug 20, 2026
Critical9.8Apache Updated

Critical [CVE-2026-63039] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This allows an attacker to inject the string value into the SQL statement, enabling SQL injection. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1].

CVE-2026-63039
Unclassified
Aug 20, 2026
Critical9.8Apache Updated

Critical [CVE-2026-63038] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This allows an attacker to inject arbitrary SQL code through the dbName, tableName, schemaName, and username parameters. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1].

CVE-2026-63038
Unclassified
Aug 20, 2026
Critical9.8Apache Updated

Critical [CVE-2026-63037] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This appears to allow SQL injection in the ORDER BY clause against the Manager backend database. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1].

CVE-2026-63037
Unclassified
Aug 20, 2026
Critical9.6Vendor: MediumRed Hat

Critical [CVE-2026-11861] Obtaining TGS with impersonating cname through trust relationships

Obtaining TGS with impersonating cname through trust relationships. Red Hat rates this moderate (CVSS 9.6). Weakness: CWE-266. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: ipa.

CVE-2026-11861
Red Hat Enterprise Linux
Aug 20, 2026
Critical9.1Splunk

Critical [CVE-2026-76404] Remote Code Execution (RCE) through Deserialization of Untrusted Data in Splunk MCP Server app

In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands on the underlying operating system. The vulnerability is possible because of missing input validation in the app's credential management component, which deserializes stored data without checking whether the content is of the expected type.

CVE-2026-76404
Unclassified
Aug 19, 2026
Critical9.4Splunk

Critical [CVE-2026-76312] Improper Access Control through Embedded Reports in Splunk Enterprise

In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who can read the Hypertext Markup Language (HTML) source of a page that embeds a Splunk report could use exposed session material to access all relevant data and affect system integrity. The vulnerability is possible because the dispatch archive download path does not correctly enforce the embedded-report authorization boundary and includes sensitive session material in archived search-job data. For more information see Additional configuration for embedded reports ( ) and Embed scheduled reports ( ) in the Splunk documentation.

CVE-2026-76312
Splunk Enterprise
Aug 19, 2026
Critical9.4Splunk

Critical [CVE-2026-76311] Improper Access Control in Embedded Report Dispatch Archives in Splunk Enterprise

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the dispatch archive for an embedded report search job and use exposed session material to access all relevant data and affect system integrity on the Splunk platform instance. The vulnerability is possible because the embedded report authorization flow does not block dispatch archive download requests before Splunk Enterprise begins sending the archive to the requester. For more information see Additional configuration for embedded reports ( ) and Embed scheduled reports ( ) in the Splunk documentation.

CVE-2026-76311
Splunk Enterprise
Aug 19, 2026
Critical9.4Splunk

Critical [CVE-2026-76310] Improper Access Control through Embedded Report REST API Requests in Splunk Enterprise

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the associated search job dispatch archive, recover session material, and use it to access all relevant data available to the report owner and affect system integrity, including by performing administrative actions when the owner holds the "admin" Splunk role. The vulnerability is possible because embedded report access does not block Representational State Transfer (REST) API dispatch archive download requests. For more information see Additional configuration for embedded reports ( ) and About configuring role-based user access ( ) in the Splunk documentation.

CVE-2026-76310
Splunk Enterprise
Aug 19, 2026
Critical9.9Vendor: HighRed Hat Updated

Critical [CVE-2026-70496] operator ClusterRole is cluster-admin equivalent via impersonate, RBAC write, CSR approve, and ManifestWork

operator ClusterRole is cluster-admin equivalent via impersonate, RBAC write, CSR approve, and ManifestWork. Red Hat rates this important (CVSS 9.9). Weakness: CWE-250. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/acm-search-v2-rhel9:1787682033, rhacm2/acm-search-v2-rhel9:1787681674, rhacm2/acm-search-v2-rhel9:1787681686, rhacm2/acm-search-v2-rhel9:1787682112. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.

CVE-2026-70496
Unclassified
Aug 19, 2026
Critical9.1Vendor: HighRed Hat Updated

Critical [CVE-2026-71470] Search CR imageOverride/arguments/envVar flow unsanitized into pods running impersonating SA

Search CR imageOverride/arguments/envVar flow unsanitized into pods running impersonating SA. Red Hat rates this important (CVSS 9.1). Weakness: CWE-913. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/acm-search-v2-rhel9:1787682033, rhacm2/acm-search-v2-rhel9:1787681674, rhacm2/acm-search-v2-rhel9:1787681686, rhacm2/acm-search-v2-rhel9:1787682112. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.

CVE-2026-71470
Unclassified
Aug 19, 2026
Critical9.8Red Hat Updated

Critical [CVE-2026-75143] FFmpeg Heap Buffer Overflow via RIST Protocol Reader

FFmpeg Heap Buffer Overflow via RIST Protocol Reader. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-120.

CVE-2026-75143
Unclassified
Aug 19, 2026
Critical10.0Cisco Exploited

Critical [CVE-2026-20231 +4] Cisco Secure Workload Software Security Hardening Release: August 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and to streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class — Common Weakness Enumeration (CWE) — and assigned a single Common Vulnerabilities and Exposures Identifier (CVE ID) to each CWE grouping. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.

CVE-2026-20231CVE-2026-20315CVE-2026-20317+2
Unclassified
Aug 19, 2026