VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
19,287 CVE recordsPage 804 of 1286 · EPSS data 2026.08.04
ReviewHigh
CVE-2026-43481

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: net-shapers: don't free reply skb after genlmsg_reply() genlmsg_reply() hands the reply skb to netlink, and netlink_unicast() consumes it on all return paths, whether the skb is queued successfully or freed on an error path. net_shaper_nl_get_doit() and net_shaper_nl_cap_get_doit() currently jump to free_msg after genlmsg_reply() fails and call nlmsg_free(msg), which can hit the same skb twice. Return the genlmsg_reply() error directly and keep free_msg only for pre-reply failures.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-43476

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: iio: chemical: sps30_i2c: fix buffer size in sps30_i2c_read_meas() sizeof(num) evaluates to sizeof(size_t) (8 bytes on 64-bit) instead of the intended __be32 element size (4 bytes). Use sizeof(*meas) to correctly match the buffer element type.

The CVSS severity warrants an early asset and exposure review.
PriorityCritical
CVE-2026-42945

F5 NGINX Plus, NGINX Open Source, Red Hat Enterprise Linux 10

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execut...

FIRST EPSS indicates an elevated probability of exploitation.
ReviewHigh
CVE-2026-42781

F5 BIG-IP, big-ip access policy manager, big-ip advanced firewall manager

When embedded Packet Velocity Acceleration (ePVA) acceleration is configured, undisclosed local ethernet traffic can cause an increase in ePVA and Traffic Management Microkernel (TMM) resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-42557

jupyterlab jupyterlab, notebook, Red Hat Migration Toolkit for Applications 8.2

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.7, JupyterLab's HTML sanitizer allowlists data-commandlinker-command and data-commandlinker-args on button elements, while CommandLinker listens for all click events on document.body and executes the named command without checking whether the element came from trusted JupyterLab UI. A notebook with a pre-saved HTML cell output containing a deceptive button can trigger arbitrary JupyterLab commands - including arbitrary code execution - on a single user...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-42409

F5 BIG-IP, BIG-IP Next SPK, BIG-IP Next CNF

When an HTTP/2 profile and an iRule containing the HTTP::redirect or HTTP::respond command are configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-42406

F5 BIG-IP, BIG-IQ, big-ip access policy manager

A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-42266

jupyterlab jupyterlab, Red Hat Migration Toolkit for Applications 8.2, Red Hat OpenShift AI (RHOAI)

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-41959

F5 BIG-IP, BIG-IQ, big-ip access policy manager

Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) network diagnostics commands and in BIG-IP iControl REST. These vulnerabilities may allow an authenticated attacker to view the network status of destination systems. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-41957

F5 BIG-IP, BIG-IQ, big-ip access policy manager

An authenticated remote code execution vulnerability through undisclosed vectors exists in the BIG-IP and BIG-IQ Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-41956

F5 BIG-IP, BIG-IP Next CNF, BIG-IP Next for Kubernetes

When a classification profile is configured on a UDP virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-41953

F5 BIG-IP, big-ip access policy manager, big-ip advanced firewall manager

A vulnerability exists in BIG-IP systems where a highly privileged, authenticated attacker with at least the Resource Administrator role can modify configuration objects resulting in privilege escalation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-41227

F5 BIG-IP, big-ip advanced web application firewall, big-ip application security manager

On an HTTP/2 virtual server with Layer 7 DoS Protection configured, undisclosed traffic can result in an increase in memory consumption causing the Traffic Management Microkernel (TMM) process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-41219

F5 BIG-IP, BIG-IQ, big-ip access policy manager

An improper sanitization vulnerability exists in the BIG-IP QKView utility that allows a low-privileged attacker to read sensitive information from a QKView file. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

The CVSS severity warrants an early asset and exposure review.