| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-68970 | Apache Airflow: Values of a list-shaped Variable are not masked in task logs and the Rendered Templates UI | Apache Software Foundation | Apache Airflow | - | - | 2026-08-12 15:24:53 | Deep Dive |
| CVE-2026-68971 | Apache Airflow: Cross-team authorization bypass in the asset materialization and dag-run result endpoints | Apache Software Foundation | Apache Airflow | - | - | 2026-08-12 15:24:11 | Deep Dive |
| CVE-2026-65941 | WhatsUp Gold versions prior to 26.0.2 contain an unauthenticated remote code execution vulnerability in an internal report scheduling service. | Progress Software Corporation | WhatsUp Gold | High | 8.8 | 2026-08-12 15:23:54 | Deep Dive |
| CVE-2026-65940 | WhatsUp Gold versions prior to 26.0.2 excessive file system permissions allows a privileged attacker to write arbitrary files to a web-accessible location on the host server. | Progress Software Corporation | WhatsUp Gold | Medium | 6.8 | 2026-08-12 15:23:28 | Deep Dive |
| CVE-2026-68076 | Apache Airflow: Connections test API: team-scope guard bypass resolves another team's environment Connection | Apache Software Foundation | Apache Airflow | - | - | 2026-08-12 15:23:23 | Deep Dive |
| CVE-2026-65939 | WhatsUp Gold versions prior to 26.0.2 contain an arbitrary file write vulnerability in the LogToFile action handler. | Progress Software Corporation | WhatsUp Gold | Medium | 6.8 | 2026-08-12 15:23:07 | Deep Dive |
| CVE-2026-65938 | WhatsUp Gold versions prior to 26.0.2 contain an improper authorization vulnerability in the Scheduled Reports API. | Progress Software Corporation | WhatsUp Gold | Medium | 4.3 | 2026-08-12 15:22:44 | Deep Dive |
| CVE-2026-65937 | WhatsUp Gold versions prior to 26.0.2 contain multiple stored cross-site scripting (XSS) vulnerabilities across the web UI | Progress Software Corporation | WhatsUp Gold | High | 8.0 | 2026-08-12 15:21:55 | Deep Dive |
| CVE-2026-69105 | Potential package cache integrity issue in JFrog Artifactory | jfrog | artifactory | High | 8.1 | 2026-08-12 15:19:40 | Deep Dive |
| CVE-2026-70547 | Potential unauthorized metadata exposure in JFrog Artifactory | jfrog | artifactory | Medium | 4.3 | 2026-08-12 15:18:29 | Deep Dive |
| CVE-2026-66016 | Rendered Artifactory Helm manifests may contain generated TLS private keys | jfrog | artifactory | Medium | 6.7 | 2026-08-12 15:16:40 | Deep Dive |
| CVE-2026-68759 | Integration credential holders may impersonate users in JFrog Access | jfrog | artifactory | High | 7.2 | 2026-08-12 15:15:51 | Deep Dive |
| CVE-2026-65926 | Private Release Bundle versions may be disclosed under specific configurations | jfrog | artifactory | Low | 3.1 | 2026-08-12 15:14:43 | Deep Dive |
| CVE-2026-66384 | Authenticated users may write data outside the intended Docker cache path | jfrog | artifactory | Medium | 5.3 | 2026-08-12 15:14:05 | Deep Dive |
| CVE-2026-68758 | Authenticated users may access restricted Artifactory support information | jfrog | artifactory | Medium | 6.5 | 2026-08-12 15:12:57 | Deep Dive |
| CVE-2026-66375 | Low-privilege users may remove protected Artifactory metadata | jfrog | artifactory | High | 8.1 | 2026-08-12 15:11:36 | Deep Dive |
| CVE-2026-68757 | Potential improper SAML signature verification in JFrog Artifactory | jfrog | artifactory | High | 7.5 | 2026-08-12 15:10:23 | Deep Dive |
| CVE-2026-68756 | Potential insecure deserialization in JFrog Artifactory | jfrog | artifactory | Medium | 6.6 | 2026-08-12 15:09:22 | Deep Dive |
| CVE-2026-66382 | Authenticated users may write files outside the intended Artifactory work directory | jfrog | artifactory | Medium | 4.3 | 2026-08-12 15:08:11 | Deep Dive |
| CVE-2026-66381 | Repository readers may access content outside configured upstream paths | jfrog | artifactory | Medium | 5.3 | 2026-08-12 15:07:02 | Deep Dive |