All shows actionable and meaningful updates. The MSRC view also includes subdued metadata-only revisions.
CVE-2026-60004
NVDCVSS 9.8Recently added to CISA KEVCISA KEV
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
NVD product signals: gitea gitea
- Originally published
- Aug 26, 2026
- Last modified by NVD
- Aug 27, 2026
- Added to this feed
- Aug 28, 2026
- Exploitation: known (CISA KEV)
- Audience relevance: verify locally
- Mitigation signal: vendor guidance linked
CISA federal remediation date passed: Aug 28, 2026. US federal deadline; use as an urgency signal elsewhere.
Review applicability before acting. Confirm the product, version, exposure and service impact locally.
Review the NVD record →CVE-2026-72530
NVDCVSS 9.5Recently added to CISA KEVCISA KEV
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, a…
NVD product signals: trueconf trueconf server
- Originally published
- Aug 19, 2026
- Last modified by NVD
- Aug 21, 2026
- Added to this feed
- Aug 29, 2026
- Exploitation: known (CISA KEV)
- Audience relevance: verify locally
- Mitigation: check vendor guidance
CISA federal remediation due date: Sep 03, 2026. US federal deadline; use as an urgency signal elsewhere.
Review applicability before acting. Confirm the product, version, exposure and service impact locally.
Review the NVD record →CVE-2026-65400
NVDCVSS 9.8Recently added to CISA KEVCISA KEV
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26…
NVD product signals: apple macos
- Originally published
- Aug 06, 2026
- Last modified by NVD
- Aug 19, 2026
- Added to this feed
- Aug 25, 2026
- Exploitation: known (CISA KEV)
- Audience signal: commonly used technology
- Mitigation signal: vendor guidance linked
CISA federal remediation date passed: Aug 21, 2026. US federal deadline; use as an urgency signal elsewhere.
Review applicability before acting. Confirm the product, version, exposure and service impact locally.
Review the NVD record →CVE-2026-68820
NVDCVSS 7.0Recently added to CISA KEVCISA KEV
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
NVD product signals: microsoft windows 10 21h2, microsoft windows 10 22h2, microsoft windows 10 1607
- Originally published
- Aug 11, 2026
- Last modified by NVD
- Aug 16, 2026
- Added to this feed
- Aug 25, 2026
- Exploitation: known (CISA KEV)
- Audience signal: commonly used technology
- Mitigation signal: vendor guidance linked
CISA federal remediation date passed: Aug 25, 2026. US federal deadline; use as an urgency signal elsewhere.
Review applicability before acting. Confirm the product, version, exposure and service impact locally.
Review the NVD record →CVE-2026-72898
NVDCVSS 10.0Recently added to CISA KEVCISA KEV
Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access t…
NVD product signals: metabase metabase
- Originally published
- Aug 10, 2026
- Last modified by NVD
- Aug 12, 2026
- Added to this feed
- Aug 25, 2026
- Exploitation: known (CISA KEV)
- Audience relevance: verify locally
- Mitigation signal: vendor guidance linked
CISA federal remediation date passed: Aug 14, 2026. US federal deadline; use as an urgency signal elsewhere.
Review applicability before acting. Confirm the product, version, exposure and service impact locally.
Review the NVD record →CVE-2026-20349
NVDCVSS 8.6Recently added to CISA KEVCISA KEV
A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Th…
NVD product signals: cisco adaptive security appliance software, cisco secure firewall threat defense
- Originally published
- Aug 11, 2026
- Last modified by NVD
- Aug 12, 2026
- Added to this feed
- Aug 25, 2026
- Exploitation: known (CISA KEV)
- Audience signal: commonly used technology
- Mitigation signal: vendor guidance linked
CISA federal remediation date passed: Aug 14, 2026. US federal deadline; use as an urgency signal elsewhere.
Review applicability before acting. Confirm the product, version, exposure and service impact locally.
Review the NVD record →CVE-2026-18556
NVDCVSS 8.2Recently added to CISA KEVCISA KEV
Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass.
This issue affects N-central…
NVD product signals: n-able n-central
- Originally published
- Aug 01, 2026
- Last modified by NVD
- Aug 05, 2026
- Added to this feed
- Aug 25, 2026
- Exploitation: known (CISA KEV)
- Audience signal: commonly used technology
- Mitigation signal: vendor guidance linked
CISA federal remediation date passed: Aug 07, 2026. US federal deadline; use as an urgency signal elsewhere.
Review applicability before acting. Confirm the product, version, exposure and service impact locally.
Review the NVD record →CVE-2026-18577
NVDCVSS 8.2Recently added to CISA KEVCISA KEV
An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1
NVD product signals: n-able n-central
- Originally published
- Aug 02, 2026
- Last modified by NVD
- Aug 04, 2026
- Added to this feed
- Aug 25, 2026
- Exploitation: known (CISA KEV)
- Audience signal: commonly used technology
- Mitigation signal: vendor guidance linked
CISA federal remediation date passed: Aug 06, 2026. US federal deadline; use as an urgency signal elsewhere.
Review applicability before acting. Confirm the product, version, exposure and service impact locally.
Review the NVD record →CVE-2026-70331 Microsoft Edge for iOS Spoofing Vulnerability
MSRCActionable updateRevision 1
Improper neutralization of input used for llm prompting in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network.
Product signal: Microsoft Edge
Vulnerability type: Spoofing
- MSRC feed activity
- Aug 28, 2026
- Added to this feed
- Aug 28, 2026
- Exploit status: not included in MSRC RSS
- Severity/CVSS: not included in MSRC RSS
- Remediation: review the MSRC record
Review applicability before acting. Confirm the product, version, exposure and service impact locally.
Review the MSRC update →CVE-2026-58616 Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability
MSRCActionable updateRevision 1
Concurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft Edge) allows an authorized atta…
Product signal: Microsoft Edge
Vulnerability type: Information disclosure
- MSRC feed activity
- Aug 28, 2026
- Added to this feed
- Aug 28, 2026
- Exploit status: not included in MSRC RSS
- Severity/CVSS: not included in MSRC RSS
- Remediation: review the MSRC record
Review applicability before acting. Confirm the product, version, exposure and service impact locally.
Review the MSRC update →CVE-2026-62904 Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
MSRCActionable updateRevision 1
Incorrect authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Product signal: Microsoft Edge
Vulnerability type: Information disclosure
- MSRC feed activity
- Aug 28, 2026
- Added to this feed
- Aug 28, 2026
- Exploit status: not included in MSRC RSS
- Severity/CVSS: not included in MSRC RSS
- Remediation: review the MSRC record
Review applicability before acting. Confirm the product, version, exposure and service impact locally.
Review the MSRC update →CVE-2026-66323 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
MSRCActionable updateRevision 1
Improper neutralization of parameter/argument delimiters in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a net…
Product signal: Microsoft Edge
Vulnerability type: Remote code execution
- MSRC feed activity
- Aug 28, 2026
- Added to this feed
- Aug 28, 2026
- Exploit status: not included in MSRC RSS
- Severity/CVSS: not included in MSRC RSS
- Remediation: review the MSRC record
Review applicability before acting. Confirm the product, version, exposure and service impact locally.
Review the MSRC update →CVE-2026-66324 Microsoft Edge (Chromium-based) Spoofing Vulnerability
MSRCActionable updateRevision 1
External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Product signal: Microsoft Edge
Vulnerability type: Spoofing
- MSRC feed activity
- Aug 28, 2026
- Added to this feed
- Aug 28, 2026
- Exploit status: not included in MSRC RSS
- Severity/CVSS: not included in MSRC RSS
- Remediation: review the MSRC record
Review applicability before acting. Confirm the product, version, exposure and service impact locally.
Review the MSRC update →CVE-2026-66798 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
MSRCActionable updateRevision 1
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Product signal: Microsoft Edge
Vulnerability type: Remote code execution
- MSRC feed activity
- Aug 28, 2026
- Added to this feed
- Aug 28, 2026
- Exploit status: not included in MSRC RSS
- Severity/CVSS: not included in MSRC RSS
- Remediation: review the MSRC record
Review applicability before acting. Confirm the product, version, exposure and service impact locally.
Review the MSRC update →CVE-2026-68821 Windows Package Manager Elevation of Privilege Vulnerability
MSRCMetadata-only updateRevision 1.2
Changes made to the security updates links and information. This is an informational change only.
Vulnerability type: Elevation of privilege
- MSRC feed activity
- Aug 29, 2026
- Added to this feed
- Aug 29, 2026
- Exploit status: not included in MSRC RSS
- Severity/CVSS: not included in MSRC RSS
- Remediation: review the MSRC record
Review applicability before acting. Confirm the product, version, exposure and service impact locally.
Review the MSRC update →CVE-2026-65813 Microsoft Exchange Server Elevation of Privilege Vulnerability
MSRCMetadata-only updateRevision 1.1
Updated an acknowledgement. This is an informational change only.
Product signal: Microsoft Exchange Server
Vulnerability type: Elevation of privilege
- MSRC feed activity
- Aug 28, 2026
- Added to this feed
- Aug 28, 2026
- Exploit status: not included in MSRC RSS
- Severity/CVSS: not included in MSRC RSS
- Remediation: review the MSRC record
Review applicability before acting. Confirm the product, version, exposure and service impact locally.
Review the MSRC update →
Showing 16 items (8 NVD + 8 MSRC). NVD records retain the existing decision-value filter. The default All view hides 2 metadata-only MSRC updates; select MSRC to review them.