Skip to content
VulniPulse

Complete feed

Action required

Critical/high still unreviewed, or CISA KEV listed

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Critical9.2Commvault

Critical [CVE-2026-13738] Improper Authorization Validation

CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customer upgrade to resolved maintenance release.CVSS score: 9.2 Commvault Software To view version support lifecyle, see Commvault software releases, release types, and release tracks. Versions not listed are out of support or unaffected. Product Platforms Affected Versions Resolved Version Status Commvault Linux, Windows 11.46.0 - 11.46.9 11.46.10 and above Resolved Commvault Linux, Windows 11.44.0 - 11.44.10 11.44.11 and above Resolved Commvault Linux, Windows 11.40.0 - 11.40.62 11.40.63 and above Resolved Commvault Linux, Windows 11.36.0 - 11.36.113 11.36.114 and above Resolved Affected product named by the advisory: Commvault Cloud.

CVE-2026-13738
Commvault Cloud (Metallic)
Aug 11, 2026
Critical9.2Commvault

Critical [CVE-2026-13737] Command Restriction Bypass

CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance release.CVSS score: 9.2 Commvault Software To view version support lifecyle, see Commvault software releases, release types, and release tracks. Versions not listed are out of support or unaffected. Product Platforms Affected Versions Resolved Version Status Commvault Linux, Windows 11.46.0 - 11.46.9 11.46.10 and above Resolved Commvault Linux, Windows 11.44.0 - 11.44.10 11.44.11 and above Resolved Commvault Linux, Windows 11.40.0 - 11.40.62 11.40.63 and above Resolved Commvault Linux, Windows 11.36.0 - 11.36.113 11.36.114 and above Resolved Affected product named by the advisory: Commvault Cloud.

CVE-2026-13737
Commvault Cloud (Metallic)
Aug 11, 2026
Critical9.8Red Hat

Critical [CVE-2026-10579] auth bypass in Picketlink SAML unsolicited-response

auth bypass in Picketlink SAML unsolicited-response. Red Hat rates this critical (CVSS 9.8). Red Hat lists fixing advisory RHSA-2026:53806 with package eap7-ironjacamar-0:1.5.26-2.Final_redhat_00001.1.el7eap, eap7-undertow-0:2.2.40-2.SP3_redhat_00001.1.el7eap, eap7-wildfly-0:7.4.25-2.GA_redhat_00001.1.el7eap, eap7-netty-0:4.1.135-1.Final_redhat_00001.1.el7eap. Affected product named by the advisory: Red Hat JBoss Enterprise Application Platform 7.

CVE-2026-10579
Unclassified
Aug 11, 2026
Critical9.9Vendor: HighRed Hat

Critical [CVE-2026-73268] spec.install.overrideJob allows arbitrary Job spec injection

spec.install.overrideJob allows arbitrary Job spec injection. Red Hat rates this important (CVSS 9.9). Weakness: CWE-94. Red Hat lists fixing advisory RHSA-2026:59593 with package multicluster-engine/cluster-curator-controller-rhel9:1787238383, multicluster-engine/cluster-curator-controller-rhel9:1787264185, multicluster-engine/cluster-curator-controller-rhel9:1786750700, multicluster-engine/cluster-curator-controller-rhel9:1787259011. Affected product named by the advisory: Multicluster Engine for Kubernetes.

CVE-2026-73268
Unclassified
Aug 11, 2026
Critical9.9Vendor: HighRed Hat

Critical [CVE-2026-73269] tenant-controllable trigger creates ClusterRoleBinding granting cluster-wide secrets access to namespace-local SA

tenant-controllable trigger creates ClusterRoleBinding granting cluster-wide secrets access to namespace-local SA. Red Hat rates this important (CVSS 9.9). Weakness: CWE-269. Red Hat lists fixing advisory RHSA-2026:59593 with package multicluster-engine/cluster-curator-controller-rhel9:1787238383, multicluster-engine/cluster-curator-controller-rhel9:1787264185, multicluster-engine/cluster-curator-controller-rhel9:1786750700, multicluster-engine/cluster-curator-controller-rhel9:1787259011. Affected product named by the advisory: Multicluster Engine for Kubernetes.

CVE-2026-73269
Unclassified
Aug 11, 2026
High8.8Red Hat

High [CVE-2026-5917] Arbitrary code execution via shell command injection in SSH backend

Arbitrary code execution via shell command injection in SSH backend. Red Hat rates this important (CVSS 8.8). Weakness: CWE-78. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux AI (RHEL AI) 3; and 2 more. Affected products named by the advisory: Red Hat package: rust; Red Hat package: libgit2.

CVE-2026-5917
Red Hat Enterprise Linux
Aug 11, 2026
High7.5Red Hat

High [CVE-2026-29036] Data corruption and unauthorized modification via JSON Pointer escape decoding

Data corruption and unauthorized modification via JSON Pointer escape decoding. Red Hat rates this important (CVSS 7.5). Weakness: CWE-386.

CVE-2026-29036
Unclassified
Aug 11, 2026
High8.8Red Hat

High [CVE-2026-19560] Arbitrary code execution via use-after-free in Blink

Arbitrary code execution via use-after-free in Blink. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825.

CVE-2026-19560
Unclassified
Aug 11, 2026
High8.8Red Hat

High [CVE-2026-19559] Arbitrary code execution via use after free in HTML

Arbitrary code execution via use after free in HTML. Red Hat rates this important (CVSS 8.8). Weakness: CWE-416.

CVE-2026-19559
Unclassified
Aug 11, 2026
High8.2Red Hat

High [CVE-2026-19557] Sandbox escape via use-after-free in TabStrip

Sandbox escape via use-after-free in TabStrip. Red Hat rates this important (CVSS 8.2). Weakness: CWE-825.

CVE-2026-19557
Unclassified
Aug 11, 2026
High7.3Red Hat

High [CVE-2026-19558] Arbitrary code execution via malicious extension installation

Arbitrary code execution via malicious extension installation. Red Hat rates this important (CVSS 7.3). Weakness: CWE-416.

CVE-2026-19558
Unclassified
Aug 11, 2026
High8.8Red Hat

High [CVE-2026-19556] Arbitrary code execution via use-after-free in V8

Arbitrary code execution via use-after-free in V8. Red Hat rates this important (CVSS 8.8). Weakness: CWE-416.

CVE-2026-19556
Unclassified
Aug 11, 2026
High7.8SonicWall Updated

High [CVE-2026-66149 +1] Email Security: Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an aut…

Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via netmask.

CVE-2026-66149CVE-2026-66150
Email Security
Aug 11, 2026
High8.2Red Hat

High [CVE-2026-19550] trust-fetch-domains uses trust-read ACI to gate a privileged AD trust refresh, allowing unauthorized LDAP writes

trust-fetch-domains uses trust-read ACI to gate a privileged AD trust refresh, allowing unauthorized LDAP writes. Red Hat rates this important (CVSS 8.2). Weakness: CWE-863. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-19550
Unclassified
Aug 11, 2026
High8.1Red Hat

High [CVE-2026-71290] Server impersonation via improper TLS hostname verification

Server impersonation via improper TLS hostname verification. Red Hat rates this important (CVSS 8.1). Weakness: CWE-295.

CVE-2026-71290
Unclassified
Aug 11, 2026
High7.5Red Hat

High [CVE-2026-29035] Arbitrary code execution via crafted WebSocket frames

Arbitrary code execution via crafted WebSocket frames. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787.

CVE-2026-29035
Unclassified
Aug 11, 2026
High7.5Red Hat

High [CVE-2026-73241] Authentication bypass via incorrect RDSTLS PDU handling

Authentication bypass via incorrect RDSTLS PDU handling. Red Hat rates this important (CVSS 7.5). Weakness: CWE-287. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: freerdp.

CVE-2026-73241
Red Hat Enterprise Linux
Aug 11, 2026
High8.8Red Hat

High [CVE-2026-73231] @faker-js/faker: Faker: Arbitrary Code Execution via attacker-controlled fake templates

@faker-js/faker: Faker: Arbitrary Code Execution via attacker-controlled fake templates. Red Hat rates this important (CVSS 8.8). Weakness: CWE-94. Affected products named by the advisory: Cryostat 4; Red Hat AMQ Broker 7; Red Hat Build of Keycloak; Red Hat Enterprise Linux 10; and 4 more. Affected products named by the advisory: Red Hat Hardened Images; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat package: grafana.

CVE-2026-73231
Red Hat Enterprise Linux
Aug 11, 2026
High7.5Red Hat

High [CVE-2026-71467] Authentication bypass on /federated via Upgrade: websocket header spoofing

Authentication bypass on /federated via Upgrade: websocket header spoofing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-287. Red Hat lists fixing advisory RHSA-2026:60386 with package rhacm2/acm-search-v2-api-rhel9:1787229541. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.17.

CVE-2026-71467
Unclassified
Aug 11, 2026
High7.5Red Hat

High [CVE-2026-48804] Denial of Service via binary attachment accumulation

Denial of Service via binary attachment accumulation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.

CVE-2026-48804
Unclassified
Aug 11, 2026