CVE Weekly Report — Week of Aug 10 – August 16, 2026

2026-W33

3
Total CVEs
0
Critical
3
High
0
Actively exploited

1 CVE is actively exploited (CISA KEV) this week. Patch these immediately: CVE-2026-71362

🔴 Critical CVEs (1)

CVEProductCVSSKEVDescriptionPublished
CVE-2026-71362Magento9.1KEVAdobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An att…Aug 11

🟠 High CVEs (37)

CVEProductCVSSKEVDescriptionPublished
CVE-2026-48416Magento7.5—Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A…Aug 11
CVE-2026-62872.NET Framework8.8—Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.Aug 11
CVE-2026-48413Magento8.7—Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged…Aug 11
CVE-2026-16239PostgreSQL8.8—Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating system u…Aug 13
CVE-2026-14669PostgreSQL8.8—Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code…Aug 13
CVE-2026-72642Elasticsearch8.8—The native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a model operat…Aug 13
CVE-2026-18692MongoDB8.8—An issue in MongoDB Server's handling of timeseries bucket lifecycle could allow an authenticated user with write privil…Aug 11
CVE-2026-15742PostgreSQL8.8—Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing ar…Aug 13
CVE-2026-6471PostgreSQL7.2—Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any …Aug 13
CVE-2026-18711MongoDB7.1—An issue in MongoDB Server's query execution engine could allow an authenticated user with read and write privileges to …Aug 11
CVE-2026-15741PostgreSQL8.8—SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hosti…Aug 13
CVE-2026-14662PostgreSQL8.8—Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause …Aug 13
CVE-2026-48415Magento7.6—Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A…Aug 11
CVE-2026-18697MongoDB7.5—An issue in MongoDB Server's aggregation framework could allow an unauthenticated party to cause a mongos (router) proce…Aug 11
CVE-2026-14664PostgreSQL8.8—Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user…Aug 13
CVE-2026-14676PostgreSQL8.8—Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating…Aug 13
CVE-2026-14670PostgreSQL8.8—Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary code as t…Aug 13
CVE-2026-19385PostgreSQL8.8—Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute arbitrar…Aug 13
CVE-2026-14680PostgreSQL8.8—Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating…Aug 13
CVE-2026-14677PostgreSQL8.8—Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator to cause the server to under…Aug 13
CVE-2026-14671PostgreSQL8.8—Type confusion in PostgreSQL module "refint" allows an object creator to execute arbitrary code as the operating system …Aug 13
CVE-2026-16238PostgreSQL8.8—Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as the oper…Aug 13
CVE-2026-18690MongoDB8.1—An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action ag…Aug 11
CVE-2026-65810.NET Framework7.8—Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.Aug 11
CVE-2026-18694MongoDB7.1—An issue in MongoDB Server's geospatial query processing could allow an authenticated user with write privileges to caus…Aug 11
CVE-2026-18688MongoDB7.1—An issue in MongoDB Server's aggregation framework could allow an authenticated user to trigger an out-of-bounds memory …Aug 11
CVE-2026-62897.NET Framework7.0—Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.Aug 11
CVE-2026-70354.NET Framework7.8—Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.Aug 11
CVE-2026-6464PostgreSQL8.1—Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as p…Aug 13
CVE-2026-18691MongoDB8.8—An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influenc…Aug 11
CVE-2026-18408PostgreSQL8.8—Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary …Aug 13
CVE-2026-18693MongoDB7.6—An issue in MongoDB Server's handling of timeseries collections could allow an authenticated user with write privileges …Aug 11
CVE-2026-14668PostgreSQL8.1—Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a cal…Aug 13
CVE-2026-48414Magento7.7—Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged…Aug 11
CVE-2026-14679PostgreSQL8.2—Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT p…Aug 13
CVE-2026-18687MongoDB7.1—MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request para…Aug 11
CVE-2026-18712MongoDB8.1—An issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authenticated user with privileg…Aug 11

🟡 Medium CVEs (35)

CVEProductCVSSKEVDescriptionPublished
CVE-2026-48411Magento6.5—Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A…Aug 11
CVE-2026-72686Elasticsearch6.5—A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single request containing a crafted user-…Aug 13
CVE-2026-72683Elasticsearch6.5—A flaw in Elasticsearch allows an authenticated user with the privileges required to invoke the simulate pipeline API en…Aug 13
CVE-2026-72679Elasticsearch6.5—Elasticsearch does not apply its configurable input length restriction to a user-supplied pattern accepted by an interva…Aug 13
CVE-2026-72678Elasticsearch6.5—Elasticsearch does not validate a size value taken from a user-supplied input before that value is used to reserve memor…Aug 13
CVE-2026-18706MongoDB6.6—An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able to issue aggregation …Aug 11
CVE-2026-72687Elasticsearch6.5—A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single small request containing a forged …Aug 13
CVE-2026-72684Elasticsearch6.5—A flaw in Elasticsearch allows an authenticated user holding only read privileges to submit a small search request conta…Aug 13
CVE-2026-72656Elasticsearch6.5—Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial …Aug 13
CVE-2026-72647Elasticsearch6.5—Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Serialized Data with Nested Payloads…Aug 13
CVE-2026-72645Elasticsearch6.5—Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Alloc…Aug 13
CVE-2026-72639Elasticsearch6.5—Elasticsearch does not enforce an upper bound on a user-supplied count accepted by a search highlighting option, and the…Aug 13
CVE-2026-72638Elasticsearch6.5—Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153).…Aug 13
CVE-2026-72636Elasticsearch6.5—Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matching helper can lead to a denial of service via Exces…Aug 13
CVE-2026-18701MongoDB6.5—An issue in MongoDB Server's query subsystem could allow an authenticated user with read privileges to cause the server …Aug 11
CVE-2026-18700MongoDB6.5—An issue in MongoDB Server's geospatial validation could allow an authenticated user with write privileges to cause an i…Aug 11
CVE-2026-18699MongoDB6.5—An issue in MongoDB Server's query planner could allow an authenticated user with read-level privileges to cause the ser…Aug 11
CVE-2026-18695MongoDB6.5—An issue in MongoDB Server's handling of certain query predicates against time-series collections with a metaField could…Aug 11
CVE-2026-18696MongoDB6.5—An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to …Aug 11
CVE-2026-18708MongoDB6.4—An issue in MongoDB Server's JavaScript scripting engine could allow an authenticated user with write privileges to caus…Aug 11
CVE-2026-72685Elasticsearch4.3—A flaw in Elasticsearch allows a low-privileged authenticated user who can index documents to submit a single small docu…Aug 13
CVE-2026-18705MongoDB6.5—An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to one view …Aug 11
CVE-2026-6470PostgreSQL4.3—Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and…Aug 13
CVE-2026-18702MongoDB6.4—An issue in MongoDB Server could allow an authenticated user with limited, database-scoped privileges to modify diagnost…Aug 11
CVE-2026-18707MongoDB4.3—An issue in MongoDB Server could allow an authenticated user, including one with no assigned privileges, to cause the se…Aug 11
CVE-2026-14672PostgreSQL5.3—Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence …Aug 13
CVE-2026-18698MongoDB5.4—An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action ag…Aug 11
CVE-2026-18704MongoDB6.5—An issue in MongoDB Server's aggregation framework could allow an authenticated user with only read privileges to perfor…Aug 11
CVE-2026-18709MongoDB6.4—An issue in MongoDB Server could allow an authenticated user with direct network access to a shard to improperly commit …Aug 11
CVE-2026-18024PostgreSQL4.3—Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific …Aug 13
CVE-2026-14678PostgreSQL4.3—Buffer over-read in PostgreSQL pg_trgm index picksplit function reads past end of a heap buffer. This might allow a tab…Aug 13
CVE-2026-14666PostgreSQL4.2—Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database ownership allows a query …Aug 13
CVE-2026-18703MongoDB4.2—An issue in MongoDB Server could allow a party with a valid client certificate and a corresponding user account to authe…Aug 11
CVE-2026-14663PostgreSQL6.5—Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of …Aug 13
CVE-2026-14681PostgreSQL4.2—Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_…Aug 13

🔵 Low CVEs (4)

CVEProductCVSSKEVDescriptionPublished
CVE-2026-48412Magento2.7—Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An att…Aug 11
CVE-2026-6469PostgreSQL3.8—Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics …Aug 13
CVE-2026-16241PostgreSQL3.8—Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service again…Aug 13
CVE-2026-14673PostgreSQL3.8—Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary …Aug 13

📦 Most affected products