| CVE-2026-2395 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Xpoda Türkiye Informatics Technology Inc. No Code Platform allows SQL Injection. This issue affects No Code Platform: from 4.1.3 before 4.1.4. | critical | 2026-07-30 |
| CVE-2026-23904 | Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to that destination. A remote requester with network access to the proxy can cause the Kyuubi server to send HTTP requests to arbitrary reachable hosts, resulting in SSRF or open-proxy behavior. This issue affects Apache Kyuubi: from 1.8.0 before 1.12.0. Users are recommended to upgrade to version 1.12.0, which disables the proxy by default. To restore proxied Engine UI, set kyuubi.frontend.rest.engine.ui.proxy.enabled=true and configure allowed target hosts with kyuubi.frontend.rest.engine.ui.proxy.hosts. | high | 2026-07-30 |
| CVE-2026-22068 | Regular Expression without Anchors vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.X through 10.1.3, from 9.0.X through 9.2.14. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue. | medium | 2026-07-30 |
| CVE-2026-21655 | Deserialization of untrusted data vulnerability in Johnson Control victor on Windows allows capec-586. This issue affects victor: from 2.9 before 3.0. | high | 2026-07-30 |
| CVE-2026-21653 | Victor SSRF vulnerability in Johnson Controls CCure 9000 and victor application server allows Server Side Request Forgery. This issue affects CCure 9000 and victor application server: from 2.9 through 3.0. | high | 2026-07-30 |
| CVE-2026-21639 | A malicious actor in Wi-Fi range of the affected product could leverage a vulnerability in the airMAX Wireless Protocol to achieve a remote code execution (RCE) within the affected product. | medium | 2026-07-30 |
| CVE-2026-21265 | Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching expiration, and devices containing affected certificate versions must update them to maintain Secure Boot functionality and avoid compromising security by losing security fixes related to Windows boot manager or Secure Boot. The operating system’s certificate update protection mechanism relies on firmware components that might contain defects, which can cause certificate trust updates to fail or behave unpredictably. This leads to potential disruption of the Secure Boot trust chain and requires careful validation and deployment to restore intended security guarantees. Certificate Authority (CA) Location Purpose Expiration Date Microsoft Corporation KEK CA 2011 KEK Signs updates to the DB and DBX 06/24/2026 Microsoft Corporation UEFI CA 2011 DB Signs 3rd party boot loaders, Option ROMs, etc. 06/27/2026 Microsoft Windows Production PCA 2011 DB Signs the Windows Boot Manager 10/19/2026 For more information see this CVE and Windows Secure Boot certificate expiration and CA updates. | medium | 2026-07-30 |
| CVE-2026-21221 | Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally. | high | 2026-07-30 |
| CVE-2026-21047 | Out-of-bounds write in ImsService prior to SMR Jul-2026 Release 1 allows remote attackers to potentially execute arbitrary code. | high | 2026-07-30 |
| CVE-2026-20962 | Use of uninitialized resource in Dynamic Root of Trust for Measurement (DRTM) allows an authorized attacker to disclose information locally. | medium | 2026-07-30 |
| CVE-2026-20941 | Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally. | high | 2026-07-30 |
| CVE-2026-20940 | Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. | high | 2026-07-30 |
| CVE-2026-20939 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | medium | 2026-07-30 |
| CVE-2026-20938 | Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally. | high | 2026-07-30 |
| CVE-2026-20937 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | medium | 2026-07-30 |
| CVE-2026-20936 | Out-of-bounds read in Windows NDIS allows an authorized attacker to disclose information with a physical attack. | medium | 2026-07-30 |
| CVE-2026-20935 | Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an unauthorized attacker to disclose information locally. | medium | 2026-07-30 |
| CVE-2026-20934 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network. | high | 2026-07-30 |
| CVE-2026-20932 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | medium | 2026-07-30 |
| CVE-2026-20931 | External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges over an adjacent network. | high | 2026-07-30 |
| CVE-2026-20929 | Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network. | high | 2026-07-30 |
| CVE-2026-20927 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to deny service over a network. | medium | 2026-07-30 |
| CVE-2026-20926 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network. | high | 2026-07-30 |
| CVE-2026-20925 | External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. | medium | 2026-07-30 |
| CVE-2026-20924 | Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. | high | 2026-07-30 |
| CVE-2026-20923 | Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. | high | 2026-07-30 |
| CVE-2026-20922 | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | high | 2026-07-30 |
| CVE-2026-20921 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network. | high | 2026-07-30 |
| CVE-2026-20920 | Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. | high | 2026-07-30 |
| CVE-2026-20919 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network. | high | 2026-07-30 |
| CVE-2026-20918 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally. | high | 2026-07-30 |
| CVE-2026-20877 | Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. | high | 2026-07-30 |
| CVE-2026-20876 | Heap-based buffer overflow in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally. | medium | 2026-07-30 |
| CVE-2026-20875 | Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network. | high | 2026-07-30 |
| CVE-2026-20874 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally. | high | 2026-07-30 |
| CVE-2026-20873 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally. | high | 2026-07-30 |
| CVE-2026-20872 | External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. | medium | 2026-07-30 |
| CVE-2026-20871 | Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locally. | high | 2026-07-30 |
| CVE-2026-20870 | Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. | high | 2026-07-30 |
| CVE-2026-20869 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Local Session Manager (LSM) allows an authorized attacker to elevate privileges locally. | high | 2026-07-30 |
| CVE-2026-20868 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | high | 2026-07-30 |
| CVE-2026-20867 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally. | high | 2026-07-30 |
| CVE-2026-20866 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally. | high | 2026-07-30 |
| CVE-2026-20865 | Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. | high | 2026-07-30 |
| CVE-2026-20864 | Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally. | high | 2026-07-30 |
| CVE-2026-20863 | Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. | high | 2026-07-30 |
| CVE-2026-20862 | Exposure of sensitive information to an unauthorized actor in Windows Management Services allows an authorized attacker to disclose information locally. | medium | 2026-07-30 |
| CVE-2026-20861 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally. | high | 2026-07-30 |
| CVE-2026-20860 | Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | high | 2026-07-30 |
| CVE-2026-20859 | Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. | high | 2026-07-30 |