Skip to content
VulniPulse

Complete feed

Action required

Critical/high still unreviewed, or CISA KEV listed

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Critical9.1Red Hat Updated

Critical [CVE-2026-73501] ValidationHandler.Load Fail-Open Authentication Bypass via NoopAuthenticationFunc Default

ValidationHandler. Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default. Red Hat rates this critical (CVSS 9.1). Weakness: CWE-306. Red Hat lists fixing advisory RHSA-2026:59030 with package grafana13-2-main-13.2.0-0.1.1.hum1, hugo-main-0.165.0-0.1.hum1, grafana13-1-main-13.1.3-0.2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Migration Toolkit for Applications 8; OpenShift Serverless; Red Hat OpenShift Container Platform 4; and 2 more. Affected products named by the advisory: Red Hat OpenShift GitOps; Red Hat OpenStack Platform 18.0.

CVE-2026-73501
Unclassified
Aug 12, 2026
Critical9.9Vendor: HighRed Hat Updated

Critical [CVE-2026-72508] hub and spoke ServiceAccounts bound to wildcard RBAC (*/*/*)

hub and spoke ServiceAccounts bound to wildcard RBAC (*/*/*). Red Hat rates this important (CVSS 9.9). Weakness: CWE-250. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/multicluster-operators-subscription-rhel9:1787242108, rhacm2/multicluster-operators-subscription-rhel9:1787263693, rhacm2/multicluster-operators-subscription-rhel9:1787242321, rhacm2/multicluster-operators-subscription-rhel9:1787240030. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.

CVE-2026-72508
Unclassified
Aug 12, 2026
Critical9.8Apache

Critical [CVE-2026-73240] Specifically crafted inputs may lead to git argument injection in Apache Allura

Specifically crafted inputs may lead to git argument injection in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.

CVE-2026-73240
Unclassified
Aug 12, 2026
Critical9.6Vendor: HighRed Hat Updated

Critical [CVE-2026-70398] GitOpsCluster.spec.argoServer.argoNamespace writes spoke bearer tokens to attacker-chosen namespace

GitOpsCluster.spec.argoServer.argoNamespace writes spoke bearer tokens to attacker-chosen namespace. Red Hat rates this important (CVSS 9.6). Weakness: CWE-441. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/multicloud-integrations-rhel9:1787252179, rhacm2/multicloud-integrations-rhel9:1787260689, rhacm2/multicloud-integrations-rhel9:1787259106, rhacm2/multicloud-integrations-rhel9:1787243221. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.

CVE-2026-70398
Unclassified
Aug 12, 2026
Critical9.9Vendor: HighRed Hat Updated

Critical [CVE-2026-72526] pull-model propagation allows hub tenant to target arbitrary spoke cluster via unvalidated ocm-managed-cluster annotation

pull-model propagation allows hub tenant to target arbitrary spoke cluster via unvalidated ocm-managed-cluster annotation. Red Hat rates this important (CVSS 9.9). Weakness: CWE-441. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/multicloud-integrations-rhel9:1787252179, rhacm2/multicloud-integrations-rhel9:1787260689, rhacm2/multicloud-integrations-rhel9:1787259106, rhacm2/multicloud-integrations-rhel9:1787243221. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.

CVE-2026-72526
Unclassified
Aug 12, 2026
Critical9.1Apache

Critical [CVE-2026-71290] Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer

Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and the server can impersonate the server by presenting a valid certificate for a different domain. Please note the classic version of HttpClient is not affected by this vulnerability. Affected users are recommended to upgrade to at least version 5.6.4, which fixes the issue.

CVE-2026-71290
Unclassified
Aug 11, 2026
Critical9.4SonicWall Updated

Critical [CVE-2026-66145 +5] GMS: unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which…

An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacker to read sensitive data and perform arbitrary file write via zipslip.

CVE-2026-66145CVE-2026-66146CVE-2026-18634+3
GMS / Analytics
Aug 11, 2026
Critical9.9Red Hat

Critical [CVE-2026-73213] Server-Side Request Forgery via incorrect IPv6 comparison

Server-Side Request Forgery via incorrect IPv6 comparison. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-918.

CVE-2026-73213
Unclassified
Aug 11, 2026
Critical9.3Vendor: HighMS Server

Critical [CVE-2026-70306] Microsoft Office SharePoint Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. Affected products named by the advisory: Microsoft SharePoint Enterprise Server 2016; Microsoft SharePoint Server 2019; Microsoft SharePoint Server Subscription Edition.

CVE-2026-70306
SharePoint Server
Aug 11, 2026
Critical9.8MS Server

Critical [CVE-2026-65791] Windows iSCSI Target Service Remote Code Execution Vulnerability

Windows iSCSI Target Service Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-65791
Windows Server
Aug 11, 2026
Critical9.8MS Server

Critical [CVE-2026-62893] Windows Deployment Services TFTP Server Remote Code Execution Vulnerability

Windows Deployment Services TFTP Server Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-62893
Windows Server
Aug 11, 2026
Critical9.8MS Server

Critical [CVE-2026-62878] Windows DNS Server Remote Code Execution Vulnerability

Windows DNS Server Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-62878
Windows Server
Aug 11, 2026
Critical9.8MS Server

Critical [CVE-2026-62815] Microsoft QUIC Remote Code Execution Vulnerability

Microsoft QUIC Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2022; Windows Server 2025.

CVE-2026-62815
Windows Server
Aug 11, 2026
Critical9.1Apache

Critical [CVE-2026-69223] Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF)

Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.

CVE-2026-69223
Unclassified
Aug 11, 2026
Critical9.2Commvault

Critical [CVE-2026-13738] Improper Authorization Validation

CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customer upgrade to resolved maintenance release.CVSS score: 9.2 Commvault Software To view version support lifecyle, see Commvault software releases, release types, and release tracks. Versions not listed are out of support or unaffected. Product Platforms Affected Versions Resolved Version Status Commvault Linux, Windows 11.46.0 - 11.46.9 11.46.10 and above Resolved Commvault Linux, Windows 11.44.0 - 11.44.10 11.44.11 and above Resolved Commvault Linux, Windows 11.40.0 - 11.40.62 11.40.63 and above Resolved Commvault Linux, Windows 11.36.0 - 11.36.113 11.36.114 and above Resolved Affected product named by the advisory: Commvault Cloud.

CVE-2026-13738
Commvault Cloud (Metallic)
Aug 11, 2026
Critical9.2Commvault

Critical [CVE-2026-13737] Command Restriction Bypass

CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance release.CVSS score: 9.2 Commvault Software To view version support lifecyle, see Commvault software releases, release types, and release tracks. Versions not listed are out of support or unaffected. Product Platforms Affected Versions Resolved Version Status Commvault Linux, Windows 11.46.0 - 11.46.9 11.46.10 and above Resolved Commvault Linux, Windows 11.44.0 - 11.44.10 11.44.11 and above Resolved Commvault Linux, Windows 11.40.0 - 11.40.62 11.40.63 and above Resolved Commvault Linux, Windows 11.36.0 - 11.36.113 11.36.114 and above Resolved Affected product named by the advisory: Commvault Cloud.

CVE-2026-13737
Commvault Cloud (Metallic)
Aug 11, 2026
Critical9.8Red Hat

Critical [CVE-2026-10579] auth bypass in Picketlink SAML unsolicited-response

auth bypass in Picketlink SAML unsolicited-response. Red Hat rates this critical (CVSS 9.8). Red Hat lists fixing advisory RHSA-2026:53806 with package eap7-ironjacamar-0:1.5.26-2.Final_redhat_00001.1.el7eap, eap7-undertow-0:2.2.40-2.SP3_redhat_00001.1.el7eap, eap7-wildfly-0:7.4.25-2.GA_redhat_00001.1.el7eap, eap7-netty-0:4.1.135-1.Final_redhat_00001.1.el7eap. Affected product named by the advisory: Red Hat JBoss Enterprise Application Platform 7.

CVE-2026-10579
Unclassified
Aug 11, 2026
Critical9.9Vendor: HighRed Hat

Critical [CVE-2026-73268] spec.install.overrideJob allows arbitrary Job spec injection

spec.install.overrideJob allows arbitrary Job spec injection. Red Hat rates this important (CVSS 9.9). Weakness: CWE-94. Red Hat lists fixing advisory RHSA-2026:59593 with package multicluster-engine/cluster-curator-controller-rhel9:1787238383, multicluster-engine/cluster-curator-controller-rhel9:1787264185, multicluster-engine/cluster-curator-controller-rhel9:1786750700, multicluster-engine/cluster-curator-controller-rhel9:1787259011. Affected product named by the advisory: Multicluster Engine for Kubernetes.

CVE-2026-73268
Unclassified
Aug 11, 2026
Critical9.9Vendor: HighRed Hat

Critical [CVE-2026-73269] tenant-controllable trigger creates ClusterRoleBinding granting cluster-wide secrets access to namespace-local SA

tenant-controllable trigger creates ClusterRoleBinding granting cluster-wide secrets access to namespace-local SA. Red Hat rates this important (CVSS 9.9). Weakness: CWE-269. Red Hat lists fixing advisory RHSA-2026:59593 with package multicluster-engine/cluster-curator-controller-rhel9:1787238383, multicluster-engine/cluster-curator-controller-rhel9:1787264185, multicluster-engine/cluster-curator-controller-rhel9:1786750700, multicluster-engine/cluster-curator-controller-rhel9:1787259011. Affected product named by the advisory: Multicluster Engine for Kubernetes.

CVE-2026-73269
Unclassified
Aug 11, 2026
Critical9.9Red Hat Updated

Critical [CVE-2026-18948] Unsafe dill deserialization of registry-stored UDFs — RCE on feature server and registry server

Unsafe dill deserialization of registry-stored UDFs — RCE on feature server and registry server. Red Hat rates this critical (CVSS 9.9). Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-feature-server-rhel9:1787068065, rhoai/odh-feature-server-rhel9:1786110051, rhoai/odh-feature-server-rhel9:1786110033, rhoai/odh-feature-server-rhel9:1786107278. Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.4.

CVE-2026-18948
Unclassified
Aug 10, 2026