Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

3544 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium5.7Docker

Medium [CVE-2026-18171] Docker Sandboxes (sbx) applies the read-only intent of a runtime host mount to the in-guest container bind only: the underlying virtio-fs host-edge grant is added to the sandbox's policy-share allowlist with no access mode

Docker Sandboxes (sbx) applies the read-only intent of a runtime host mount to the in-guest container bind only: the underlying virtio-fs host-edge grant is added to the sandbox's policy-share allowlist with no access mode. The directory stays writable at its shared-export path, so unprivileged code inside the sandbox can derive that path and write to a host directory the operator attached read-only.

CVE-2026-18171
Docker Desktop
Aug 12, 2026
Medium4.8Fortinet

Medium [CVE-2026-70466] incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow attacker to improper access control via <insert attack vector here>

A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow attacker to improper access control Affected products named by the advisory: FortiOS.

CVE-2026-70466
FortiWeb
Aug 12, 2026
Medium5.1Fortinet

Medium [CVE-2026-71407] Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the context of the WAD daemon via crafted sockets, only if the explicit proxy is configured with Kerberos authentication and SOCKS enabled

A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the context of the WAD daemon via crafted sockets, only if the explicit proxy is configured with Kerberos authentication and SOCKS enabled. Affected products named by the advisory: FortiProxy.

CVE-2026-71407
FortiGateFirewallFortiOS
Aug 12, 2026
Medium5.0Fortinet

Medium [CVE-2026-71408] allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions may allow attacker to denial of service via <insert attack vector here>

A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions may allow attacker to denial of service

CVE-2026-71408
FortiGateFirewallFortiOS
Aug 12, 2026
Medium6.5Apache

Medium [CVE-2026-68868] The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Variables: the caller's `team_name` was accepted by the backend but dropped at the internal call boundary, so every lookup resolved against the team-agnostic secret name

The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Variables: the caller's `team_name` was accepted by the backend but dropped at the internal call boundary, so every lookup resolved against the team-agnostic secret name. In a deployment running multi-team mode with this backend, a task or Dag belonging to one team resolved another team's Connection or Variable, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using this backend. Users are advised to upgrade to apache-airflow-providers-google 22.3.0 or later, which builds and applies the team-scoped secret name.

CVE-2026-68868
Airflow
Aug 12, 2026
Medium5.9Red Hat

Medium [CVE-2026-18663] pre-authentication double-free in get_ldapmessage_controls_ext via critical Session Tracking control

pre-authentication double-free in get_ldapmessage_controls_ext() via critical Session Tracking control. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-415. Affected products named by the advisory: Red Hat Directory Server 13; Red Hat Enterprise Linux 10.

CVE-2026-18663
Unclassified
Aug 12, 2026
Medium4.8Fortinet

Medium [CVE-2026-70466] Content-Encoding WAF Evasion

CVSSv3 Score: 4.8 An incomplete list of disallowed inputs [CWE-184] in FortiWeb WAF may allow an unauthenticated attacker to bypass policies via specifically crafted requests. Revised on 2026-08-12 00:00:00

CVE-2026-70466
FortiWeb
Aug 12, 2026
Medium5.8Fortinet

Medium [CVE-2026-49975] HTTP/2 Bomb CVE-2026-49975

CVSSv3 Score: 5.8 CVE-2026-49975 Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67. Revised on 2026-08-19 00:00:00 Affected product named by the advisory: FortiProxy.

CVE-2026-49975
FortiProxy
Aug 12, 2026
Medium5.1Fortinet

Medium [CVE-2026-71407] Stack buffer overflow in WAD

CVSSv3 Score: 5.1 A Stack-based Buffer Overflow vulnerability [CWE-121] in FortiOS explicit proxy may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the context of the WAD daemon via crafted sockets, only if the explicit proxy is configured with Kerberos authentication and SOCKS enabled. Revised on 2026-08-12 00:00:00

CVE-2026-71407
FortiGateFirewallFortiOS
Aug 12, 2026
Medium5.0Fortinet

Medium [CVE-2026-71408] UI DoS attack

CVSSv3 Score: 5.0 An Allocation of Resources Without Limits or Throttling vulnerability [CWE-770] in FortiOS may allow an unauthenticated attacker to perform a slow HTTP DoS attack on the web interface via crafted HTTP requests. Revised on 2026-08-12 00:00:00

CVE-2026-71408
FortiGateFirewallFortiOS
Aug 12, 2026
Medium5.4Red Hat

Medium [CVE-2026-9318] Arbitrary JavaScript execution via stored Cross-Site Scripting in HTML export

Arbitrary JavaScript execution via stored Cross-Site Scripting in HTML export. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-79. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Satellite 6; Red Hat Update Infrastructure 4 for Cloud Providers; Red Hat Update Infrastructure 5.

CVE-2026-9318
Unclassified
Aug 12, 2026
Medium6.5Red Hat

Medium [CVE-2026-19587] Denial of Service due to excessive resource allocation

Denial of Service due to excessive resource allocation. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-1050.

CVE-2026-19587
Unclassified
Aug 12, 2026
Medium6.4Red Hat

Medium [CVE-2026-64927] cross-namespace Secret and ConfigMap mutation via spec.secretRef.namespace confused deputy

cross-namespace Secret and ConfigMap mutation via spec.secretRef.namespace confused deputy. Red Hat rates this moderate (CVSS 6.4). Weakness: CWE-639. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/multicluster-operators-channel-rhel9:1787259310, rhacm2/multicluster-operators-channel-rhel9:1787242099, rhacm2/multicluster-operators-channel-rhel9:1787238600, rhacm2/multicluster-operators-channel-rhel9:1787260663. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.

CVE-2026-64927
Unclassified
Aug 12, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-68430] drop unecessary BUG_ON

drop unecessary BUG_ON(). Red Hat rates this low (CVSS 5.5). Weakness: CWE-617. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 5 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; and 1 more.

CVE-2026-68430
Linux Kernel
Aug 12, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-68450] free mapping node on duplicate reloc root insert

free mapping node on duplicate reloc root insert. Red Hat rates this low (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26; Red Hat Hardened Images; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel.

CVE-2026-68450
Linux Kernel
Aug 12, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-68429] Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe

Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe(). Red Hat rates this low (CVSS 5.5). Weakness: CWE-367. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel.

CVE-2026-68429
Linux Kernel
Aug 12, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-68436] use kvzalloc to allocate struct dc

use kvzalloc to allocate struct dc. Red Hat rates this low (CVSS 5.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-68436
Linux Kernel
Aug 12, 2026
Medium5.5Red Hat

Medium [CVE-2026-68446] Validate vmw_surface_metadata::array_size

Validate vmw_surface_metadata::array_size. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-805. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-68446
Linux Kernel
Aug 12, 2026
Medium5.5Vendor: LowRed Hat

Medium [CVE-2026-68439] fix possible NULL-pointer deref in mt7925_mcu_bss_he_tlv

fix possible NULL-pointer deref in mt7925_mcu_bss_he_tlv(). Red Hat rates this low (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26; Red Hat package: kernel.

CVE-2026-68439
Linux Kernel
Aug 12, 2026
Medium5.5Red Hat

Medium [CVE-2026-68431] validate minimum PDU size for transform requests

validate minimum PDU size for transform requests. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux for NVIDIA 26; Red Hat package: kernel.

CVE-2026-68431
Linux Kernel
Aug 12, 2026