| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-68760 | Potential remember-me authentication bypass in JFrog Artifactory | jfrog | artifactory | Medium | 5.3 | 2026-08-12 15:04:59 | Deep Dive |
| CVE-2026-66379 | Authenticated users may view private Puppet module metadata | jfrog | artifactory | Medium | 4.3 | 2026-08-12 15:03:03 | Deep Dive |
| CVE-2026-66378 | Authenticated users may access private NuGet metadata | jfrog | artifactory | Medium | 4.3 | 2026-08-12 15:02:09 | Deep Dive |
| CVE-2026-66377 | Anonymous users may access restricted Artifactory repository information | jfrog | artifactory | Medium | 5.3 | 2026-08-12 15:00:50 | Deep Dive |
| CVE-2026-68755 | Bundle writers may alter trusted release information in JFrog Artifactory | jfrog | artifactory | Medium | 4.3 | 2026-08-12 15:00:06 | Deep Dive |
| CVE-2026-66380 | Authenticated users may access private OCI referrer metadata | jfrog | artifactory | Medium | 4.3 | 2026-08-12 14:59:25 | Deep Dive |
| CVE-2026-68754 | Publishers without delete permission can overwrite docker layer information | jfrog | artifactory | Medium | 6.5 | 2026-08-12 14:58:44 | Deep Dive |
| CVE-2026-68753 | Anonymous users may access restricted Artifactory content under specific configurations | jfrog | artifactory | Medium | 5.3 | 2026-08-12 14:57:39 | Deep Dive |
| CVE-2026-66376 | Deleted users may temporarily retain access to JFrog Artifactory | jfrog | artifactory | Medium | 4.2 | 2026-08-12 14:55:59 | Deep Dive |
| CVE-2026-68752 | Project Resource Managers may escalate privileges in JFrog Artifactory | jfrog | artifactory | High | 7.2 | 2026-08-12 14:55:01 | Deep Dive |
| CVE-2026-14479 | Denial of Service in Autodesk Installer IPC Channel | Autodesk | Installer | Medium | 5.5 | 2026-08-12 14:54:59 | Deep Dive |
| CVE-2026-14478 | Incorrect Permission Assignment in Autodesk Installer Named Pipes | Autodesk | Installer | High | 7.8 | 2026-08-12 14:54:06 | Deep Dive |
| CVE-2026-73291🧪 | Seerr: Path traversal to RCE via /avatarproxy image cache filename from upstream ETag | seerr-team | seerr | High | 7.1 | 2026-08-12 14:48:22 | Deep Dive |
| CVE-2026-18171 | Docker Sandboxes read-only runtime mount writable through its shared-export alias | Docker | Docker Sandboxes | Medium | 5.7 | 2026-08-12 14:47:25 | Deep Dive |
| CVE-2026-73290 | RustFS: Anonymous ListObjectVersions bypasses RestrictPublicBuckets through the ListBucket fallback | rustfs | rustfs | Medium | 5.3 | 2026-08-12 14:46:20 | Deep Dive |
| CVE-2026-73289🧪 | RustFS: ForAllValues/ForAnyValue negated string conditions are transposed, inverting IAM and bucket-policy decisions | rustfs | rustfs | High | 8.1 | 2026-08-12 14:43:59 | Deep Dive |
| CVE-2026-73288 | RustFS: Object Lock (WORM) protections are treated as absent when bucket metadata cannot be read, allowing retained objects to be deleted | rustfs | rustfs | Medium | 6.1 | 2026-08-12 14:42:50 | Deep Dive |
| CVE-2026-73287 | RustFS: FTPS MKD bypasses IAM CreateBucket authorization | rustfs | rustfs | Medium | 5.4 | 2026-08-12 14:41:15 | Deep Dive |
| CVE-2026-73432 | Stored Server-Side Request Forgery in Remote-Instance Synchronization Allows Access to Internal Services in vulnerability-lookup | vulnerability-lookup | vulnerability-lookup | Medium | 5.1 | 2026-08-12 14:40:16 | Deep Dive |
| CVE-2026-73286🧪 | RustF: Request headers can populate server-derived IAM condition keys, letting a caller satisfy identity-based policy conditions | rustfs | rustfs | High | 8.1 | 2026-08-12 14:40:05 | Deep Dive |