Skip to content
VulniPulse

Complete feed

Action required

Critical/high still unreviewed, or CISA KEV listed

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.5Apache

High [CVE-2026-68074] Apache Qpid Broker-J: pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue.

CVE-2026-68074
Unclassified
Aug 5, 2026
High7.5Red Hat

High [CVE-2026-66257] Denial of Service via unbounded symbol value caching

Denial of Service via unbounded symbol value caching. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.

CVE-2026-66257
Unclassified
Aug 5, 2026
High7.5Apache

High [CVE-2026-66257] Apache Qpid Proton-J: pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.

CVE-2026-66257
Unclassified
Aug 5, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64572] free fib_alias with kfree_rcu on insert error path

free fib_alias with kfree_rcu() on insert error path. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-64572
Unclassified
Aug 5, 2026
High7.5Red Hat

High [CVE-2026-67863] Denial of Service via use-after-free vulnerability

Denial of Service via use-after-free vulnerability. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825.

CVE-2026-67863
Unclassified
Aug 5, 2026
High7.5Red Hat

High [CVE-2026-67870] Denial of Service via incomplete validation in AddReferences

Denial of Service via incomplete validation in AddReferences. Red Hat rates this important (CVSS 7.5). Weakness: CWE-476.

CVE-2026-67870
Unclassified
Aug 5, 2026
High7.5Red Hat

High [CVE-2026-67869] Denial of Service via buffer overflow in Service_Call

Denial of Service via buffer overflow in Service_Call. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125.

CVE-2026-67869
Unclassified
Aug 5, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64577] check skb_pull_data return in gtp1u_send_echo_resp

check skb_pull_data() return in gtp1u_send_echo_resp(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-124.

CVE-2026-64577
Unclassified
Aug 5, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-64573] fix NVM tag length underflow in TLV parser

fix NVM tag length underflow in TLV parser. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125.

CVE-2026-64573
Unclassified
Aug 5, 2026
High7.0Red Hat

High [CVE-2026-64582] Fix a use-after-free problem in rxe_mmap

Fix a use-after-free problem in rxe_mmap. Red Hat rates this important (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-64582
Unclassified
Aug 5, 2026
High7.5Red Hat

High [CVE-2026-67864] Denial of Service via NodeManagement type-instantiation logic

Denial of Service via NodeManagement type-instantiation logic. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1287.

CVE-2026-67864
Unclassified
Aug 5, 2026
Critical9.8Aruba

Critical [CVE-2026-63456] Authentication bypass via spoofed HTTP headers Orchestrator REST API

Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify potentially sensitive information on the target system. Affected product named by the advisory: EdgeConnect SD-WAN Orchestrator.

CVE-2026-63456
EdgeConnect SD-WANWireless & Controllers
Aug 4, 2026
Critical9.5Veeam

Critical [CVE-2026-58067 +3] Vulnerabilities Resolved in Veeam Service Provider Console 9.3

Vulnerabilities Resolved in Veeam Service Provider Console 9.3 KB ID: 4893 Product: Published: 2026-08-04 Last Modified: Veeam Software Security Commitment Veeam® is committed to ensuring its products protect customers from potential risks. As part of that commitment, we operate a Vulnerability Disclosure Program (VDP) for all Veeam products and perform extensive internal code audits. When a vulnerability is identified, our team promptly develops a patch to address and mitigate the risk. In line with our dedication to transparency, we publicly disclose the vulnerability and provide detailed mitigation information. This approach ensures that all potentially affected customers can quickly implement the necessary measures to safeguard their systems. It’s important to note that once a vulnerability and its associated patch are disclosed, attackers will likely attempt to reverse-engineer the patch to exploit unpatched deployments of Veeam software. This reality underscores the critical importance of ensuring that all customers use the latest versions of our software and install all updates and patches without delay. Issue Details A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent and obtain that agent's credentials. Severity: Critical

CVE-2026-58067CVE-2026-58071CVE-2026-58072+1
Service Provider Console
Aug 4, 2026
High7.5Red Hat

High [CVE-2026-56848] Heap-use-after-free in HTTP/2 handling can lead to denial of service

Heap-use-after-free in HTTP/2 handling can lead to denial of service. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-56848
Unclassified
Aug 4, 2026
High8.8Red Hat

High [CVE-2026-15307] Remote code execution via GeoDjango spatial lookups

Remote code execution via GeoDjango spatial lookups. Red Hat rates this important (CVSS 8.8). Weakness: CWE-434. Red Hat lists fixing advisory RHSA-2026:59153 with package ansible-automation-platform-25/hub-rhel8:1787101922, ansible-automation-platform-26/lightspeed-rhel9:1787244079, python3.12-django-0:5.2.17-1.el8ap, ansible-automation-platform-25/lightspeed-rhel8:1787229385. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Discovery 2; Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; and 5 more. Affected products named by the advisory: Red Hat OpenStack Platform 18.0; Red Hat Satellite 6; Red Hat Update Infrastructure 4 for Cloud Providers; Red Hat Update Infrastructure 5; and 1 more.

CVE-2026-15307
Unclassified
Aug 4, 2026
High7.5Red Hat

High [CVE-2026-68494] Denial of Service via incomplete fix in async JSON parser

Denial of Service via incomplete fix in async JSON parser. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:53643 with package eap7-ironjacamar-0:1.5.26-2.Final_redhat_00001.1.el7eap, eap7-undertow-0:2.2.40-2.SP3_redhat_00001.1.el7eap, eap7-wildfly-0:7.4.25-2.GA_redhat_00001.1.el7eap, jackson-core. Affected products named by the advisory: Cryostat 4; OpenShift Developer Tools and Services; OpenShift Serverless; Red Hat AI Inference Server; and 28 more. Affected products named by the advisory: Red Hat AMQ Broker 7; Red Hat AMQ Clients; Red Hat Ansible Automation Platform 2; Red Hat build of Apache Camel 4 for Quarkus 3; and 24 more.

CVE-2026-68494
Unclassified
Aug 4, 2026
High7.3Vendor: MediumRed Hat

High [CVE-2026-42169] GIMP APNG loader heap-buffer-overflow when fcTL width exceeds IHDR width (file-png.c)

GIMP APNG loader heap-buffer-overflow when fcTL width exceeds IHDR width (file-png.c). Red Hat rates this moderate (CVSS 7.3). Weakness: CWE-131. Red Hat lists fixing advisory RHSA-2026:50817 with package gimp-2:3.0.4-4.el9_8.9. Affected product named by the advisory: Red Hat Enterprise Linux 9.

CVE-2026-42169
Unclassified
Aug 4, 2026
High7.2Zyxel

High [CVE-2026-14818] path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versions from V4.32 through V5.42 Patch 1, USG FLEX series firmware versions from V4.50 through V5.42 Patch 1, USG FLEX 50(W) series firmware versions from V4.16 through V5.42 Patch 1, and USG20(W)-VPN series firmware versions from V4.16 through V5.42 Patch 1 could allow an authenticated attacker with administrator privileges to execute a crafted malicious configuration file on an affected device

A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versions from V4.32 through V5.42 Patch 1, USG FLEX series firmware versions from V4.50 through V5.42 Patch 1, USG FLEX 50(W) series firmware versions from V4.16 through V5.42 Patch 1, and USG20(W)-VPN series firmware versions from V4.16 through V5.42 Patch 1 could allow an authenticated attacker with administrator privileges to execute a crafted malicious configuration file on an affected device.

CVE-2026-14818
Firewalls (USG FLEX/ATP)
Aug 4, 2026
High7.2Zyxel

High [CVE-2026-6837] post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device

A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.

CVE-2026-6837
Unclassified
Aug 4, 2026
High7.5Red Hat

High [CVE-2026-56846] Remote memory exhaustion via HTTP/2 retained header blocks

Remote memory exhaustion via HTTP/2 retained header blocks. Red Hat rates this important (CVSS 7.5). Weakness: CWE-400. Red Hat lists fixing advisory RHSA-2026:48305 with package nodejs22-main-22.23.2-2.3.hum1, nodejs24-main-24.18.1-0.1.hum1.

CVE-2026-56846
Unclassified
Aug 4, 2026