Overview
- Amazon Ion
- Amazon Ion Java
18 Aug 2026
Published
19 Aug 2026
Updated
CVSS v3.1
HIGH (7.5)
EPSS
0.44%
KEV
Description
Uncontrolled memory allocation in the binary Ion stream cursor in Amazon ion-java before 1.12.0 might allow remote actors to cause a denial of service via a crafted Ion binary document containing a declared-length field that causes excessive heap preallocation.
To remediate this issue, users should upgrade to version 1.12.0.
Statistics
- 1 Post
Last activity: 23 hours ago
Overview
- Amazon Ion
- Amazon Ion Java
18 Aug 2026
Published
19 Aug 2026
Updated
CVSS v3.1
HIGH (7.5)
EPSS
0.44%
KEV
Description
Improper handling of highly compressed data in the GZIP auto-decompression handler in Amazon ion-java before 1.12.0 might allow remote actors to cause a denial of service via a crafted compressed Ion document that expands to an arbitrarily large size upon decompression.
To remediate this issue, users should upgrade to version 1.12.0 and configure withGzipDecompressionEnabled(false) and/or set an explicit withMaximumBufferSize() when parsing untrusted input.
Statistics
- 1 Post
Last activity: 23 hours ago
Overview
Description
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution
Statistics
- 1 Post
Last activity: 7 hours ago
Overview
- ivanti
- Sentry
09 Jun 2026
Published
10 Jun 2026
Updated
CVSS v3.1
CRITICAL (9.9)
EPSS
51.87%
KEV
Description
An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access
Statistics
- 1 Post
Last activity: 7 hours ago
Overview
- Red Hat
- Red Hat Advanced Cluster Management for Kubernetes 2
- rhacm2/acm-search-v2-rhel9
19 Aug 2026
Published
19 Aug 2026
Updated
CVSS
Pending
EPSS
0.26%
KEV
Description
A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a cluster administrator, allowing it to impersonate other entities, write Role-Based Access Control (RBAC) configurations, approve Certificate Signing Requests (CSRs), and manage ManifestWork. This grants excessive privileges beyond what is necessary for the operator's intended function, potentially leading to privilege escalation within the cluster.
Statistics
- 1 Post
Last activity: 16 hours ago
Overview
- Cisco
- Cisco Secure Workload
19 Aug 2026
Published
20 Aug 2026
Updated
CVSS v3.1
CRITICAL (10.0)
EPSS
0.32%
KEV
Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.
The vulnerabilities tracked by CVE-2026-20315 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284.
Statistics
- 1 Post
Last activity: 10 hours ago
Fediverse
「Ciscoのバグの深刻度警告は、オリンピック体操競技の得点のように、10、10、9.9、9.6、7.5と表示されます。
/Secure Workload Softwareには5つの重大な欠陥があり、SaaSユーザーでさえアップデートをインストールする必要がある。 」: #TheRegister
「シスコは、ネットワーク内での攻撃者の横方向への移動を阻止することを目的としたマイクロセグメンテーションツールであるセキュアワークロードソフトウェア(旧称Tetration)に、4つの重大な欠陥と、さらに1つの深刻なバグが存在することを明らかにした。
CVE-2026-20315とCVE-2026-20317は、最高評価の10点満点バグです。どちらも不適切なアクセス制御に関連しています。 」