In FreeIPA versions before 4.13.3 a high severity vulnerability CVE-2026-73197 was detected. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by exhausting system memory and disrupting service availability. This occurs due to an unbounded request body read flaw in the /ipa/migration/migration.py endpoint. When processing form POST requests, the migration handler reads the entire, attacker-controlled request body directly into memory without enforcing size limits. By sending oversized requests, an attacker can force excessive memory consumption and severely slow down request handling. There’s no fix available for this issue at the moment. . For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-73197.
In OpenShift versions prior to the latest patch a high severity vulnerability CVE-2026-50236 was detected. This vulnerability allows authenticated attackers to make arbitrary network requests from the server’s privileged network position. To address this issue, users should upgrade OpenShift to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-50236.
Read more Developer ToolsIn previous versions of OpenShift a high severity vulnerability CVE-2026-50236 was detected. This vulnerability allows an authenticated attacker to target arbitrary endpoints from a privileged network position. To address this issue, users should upgrade OpenShift to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-50236.
Read more Developer ToolsIn previous versions of OpenShift a high severity vulnerability CVE-2026-50237 was detected. This vulnerability allows an attacker to bypass tenant egress restrictions. To address this issue, users should upgrade OpenShift to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-50237.
Read more Developer ToolsIn Portainer versions CE 2.44.0 and earlier a high severity vulnerability CVE-2026-72533 was detected. This vulnerability allows authenticated low-privileged users to bypass Docker proxy authorization checks. To address this issue, users should upgrade Portainer to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-72533.
Read more Developer ToolsIn Authentik versions 2026.5.6 and earlier a high severity vulnerability CVE-2026-72534 was detected. This vulnerability allows an attacker to gain superuser privileges. To address this issue, users should upgrade Authentik to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-72534.
Read more SecurityIn OpenShift a high severity vulnerability CVE-2026-50237 was detected. This vulnerability allows a namespace tenant to make the console fetch an arbitrary URL, bypassing tenant egress restrictions. To address this issue, users should upgrade OpenShift to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-50237.
Read more Developer ToolsIn Dolibarr versions up to 23.0.4 a medium severity vulnerability CVE-2026-77686 was detected. This vulnerability allows a remote attacker to bypass authorization checks, potentially leading to unauthorized access or modification of account details. This occurs due to an improper authorization flaw within the Account Handler component, specifically in the htdocs/user/card.php file. By manipulating the ID argument in the request, an attacker can access or alter resources belonging to other users. Warning: A public exploit for this vulnerability is available and could be used in active attacks. To address this issue, users should upgrade Dolibarr to version 24.0.0 or later, or apply the official patch (commit b2a2c995537cb6282383b5e903cb5ffa29b823e6). For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-77686.
In FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More component for WordPress versions 1.9.2 and earlier a high severity vulnerability CVE-2025-15028 was detected. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts in pages. To address this issue, users should upgrade FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-15028.
Read more CMS