Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.4 CVE-2026-9006

IBM WebSphere Application Server is affected by server-side request forgery_CVE-2026-9006

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an...

IBM WebSphere Application Server 9.0 CVE
MEDIUM 6.9 CVE-2026-8934

Cross-Project Information Leakage in Google App Engine UI_CVE-2026-8934

A Missing Authorization vulnerability in a GraphQL private API operation of the Google App Engine section of the Cloud Console allows an unauthenti...

Google Cloud Cloud Console UIs CVE
HIGH 7.5 CVE-2026-8858

IBM i is Affected By Denial of Service, HTTP Request Smuggling, and Remote Code Execution Vulnerabilities in IBM WebSphere Application Server Liberty [, , , , ]_CVE-2026-8858

IBM i 7.6, 7.5, 7.4, and 7.3, IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to remote code execution...

IBM i 7.6.0 CVE
LOW 3.8 CVE-2026-8823

User Manager can demote bot accounts to guest without bot-management permission_CVE-2026-8823

Mattermost versions 11.7.x

Mattermost Mattermost 11.7.0 CVE
HIGH 7.4 CVE-2026-8646

IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities_CVE-2026-8646

IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP reques...

IBM WebSphere Application Server 9.0.0 CVE
MEDIUM 5.5 CVE-2026-8636

Multiple Vulnerabilities in IBM Datacap_CVE-2026-8636

IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 allows an attacker to retrieve user passwords and cryptograph...

IBM Datacap 9.1.7 CVE
MEDIUM 6.1 CVE-2026-8059

Multiple Vulnerabilities in IBM Datacap_CVE-2026-8059

IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 is vulnerable to cross-site scripting. This vulnerability all...

IBM Datacap 9.1.7 CVE
CRITICAL 9.8 CVE-2026-7664

Unauthenticated Flow Execution via Webhook Endpoint in Langflow OSS_CVE-2026-7664

IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due...

IBM Langflow OSS 1.0.0 CVE
MEDIUM 5.3 CVE-2026-7253

IBM Watson Speech Services Cartridge is vulnerable to Server-Side Request Forgery (SSRF) in Sterling File Gateway_CVE-2026-7253

IBM Watson Speech Services Cartridge is vulnerable to Server-Side Request Forgery (SSRF) in Sterling File Gateway, due to a flaw which may allow an...

IBM IBM Watson Speech Services Cartridge 4.0.0 CVE
CRITICAL 9.1 CVE-2026-56104

Chainlit < 2.10.1 Session Hijacking via WebSocket Session Restoration_CVE-2026-56104

Chainlit before 2.10.1 contains a session hijacking vulnerability that allows unauthenticated attackers to restore and inherit authenticated user s...

Chainlit chainlit CVE