Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.4 CVE-2026-8646

IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities_CVE-2026-8646

IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP reques...

IBM WebSphere Application Server 9.0.0 CVE
MEDIUM 5.5 CVE-2026-8636

Multiple Vulnerabilities in IBM Datacap_CVE-2026-8636

IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 allows an attacker to retrieve user passwords and cryptograph...

IBM Datacap 9.1.7 CVE
MEDIUM 6.1 CVE-2026-8059

Multiple Vulnerabilities in IBM Datacap_CVE-2026-8059

IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 is vulnerable to cross-site scripting. This vulnerability all...

IBM Datacap 9.1.7 CVE
CRITICAL 9.8 CVE-2026-7664

Unauthenticated Flow Execution via Webhook Endpoint in Langflow OSS_CVE-2026-7664

IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due...

IBM Langflow OSS 1.0.0 CVE
MEDIUM 5.3 CVE-2026-7253

IBM Watson Speech Services Cartridge is vulnerable to Server-Side Request Forgery (SSRF) in Sterling File Gateway_CVE-2026-7253

IBM Watson Speech Services Cartridge is vulnerable to Server-Side Request Forgery (SSRF) in Sterling File Gateway, due to a flaw which may allow an...

IBM IBM Watson Speech Services Cartridge 4.0.0 CVE
CRITICAL 9.1 CVE-2026-56104

Chainlit < 2.10.1 Session Hijacking via WebSocket Session Restoration_CVE-2026-56104

Chainlit before 2.10.1 contains a session hijacking vulnerability that allows unauthenticated attackers to restore and inherit authenticated user s...

Chainlit chainlit CVE
HIGH 8.2 CVE-2026-54268

Angular: Denial of Service (DoS) via OOM in Date Formatting (formatDate)_CVE-2026-54268

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1...

angular angular >= 22.0.0-next.0 < 22.0.1 CVE
HIGH 8.6 CVE-2026-54267

Angular Client Hydration DOM Clobbering & Response-Cache Poisoning_CVE-2026-54267

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1...

angular angular >= 22.0.0-next.0 < 22.0.1 CVE
HIGH 8.8 CVE-2026-54266

Angular: Weak 32-Bit Cache Key Hashing in `HttpTransferCache` Leading to Cross-Request Data Leakage and State Poisoning_CVE-2026-54266

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1...

angular angular >= 22.0.0-next.0 < 22.0.1 CVE
MEDIUM 5.3 CVE-2026-54265

Angular: Two-Way Property Binding Sanitization Bypass (XSS)_CVE-2026-54265

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1...

angular angular >= 22.0.0-next.0 < 22.0.1 CVE