VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
19,735 CVE recordsPage 495 of 1316 · EPSS data 2026.08.12
ReviewCritical
CVE-2026-7874

IBM Langflow OSS, langflow

IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow disclosure of all stored credentials due to the use of a weak and reversible key derivation mechanism for encryption at rest.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-7873

IBM Langflow OSS, langflow

IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated attackers to execute arbitrary OS commands and read sensitive files including credentials, enabling complete system compromise and lateral movement.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-7871

IBM Langflow OSS, langflow

IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full application privileges, compromising all secrets, data, and system integrity.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-7803

IBM Langflow OSS, langflow

IBM Langflow OSS 1.0.0 through 1.10.0 could allow arbitrary code execution due to improper validation of flow nodes with missing or empty component type fields.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-7663

IBM Langflow OSS, langflow

IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-13773

IBM WebSphere Extreme Scale, websphere extreme scale

IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 generated CORBA stub classes in WebSphere eXtreme Scale's ogclient.jar call ORB.string_to_object() on an attacker-controlled IOR string during Java deserialization, turning any unfiltered ObjectInputStream sink in WAS into outbound IIOP SSRF to an attacker-chosen host; when chained with the IBM ORB's getUserException class-instantiation flaw (WAS-26), this SSRF escalates to remote code execution on the calling JVM.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-13772

IBM WebSphere Extreme Scale, websphere extreme scale

IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 's Object Query Language engine resolves attacker-supplied class names via Class.forName() and invokes their constructors with no allow-list at three distinct sinks (SELECT NEW, enum literals, and reflection-based comparators); an authenticated remote attacker who can influence an application-built OQL query string can execute arbitrary constructors on the WAS JVM, and a SELECT DISTINCT variant using planted grid values fires the same gadget post-readObject in a manner that survives JEP-290 serialization filters across grid node boundaries

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-13759

IBM WebSphere Extreme Scale, websphere extreme scale

IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 ships three ObjectInputStream subclasses (WsObjectInputStream, ObjectStreamPool$ReusableInputStream, ObjectInputStreamResolver) that install no JEP-290 class filter; when Coherence is on the classpath, multiple RCE gadget chains including RemoteConstructor.readResolve and PriorityQueue/ExtractorComparator are confirmed working, allowing a post-login attacker who can write a session attribute or a LAN-adjacent attacker on the grid replication wire to execute arbitrary code on peer WAS JVMs

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-12084

IBM UCD - IBM DevOps Deploy, devops deploy

IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains.

The CVSS severity warrants an early asset and exposure review.