CVE Weekly Report — Week of Aug 10 – August 16, 2026
2026-W33
3
Total CVEs
0
Critical
3
High
0
Actively exploited
1 CVE is actively exploited (CISA KEV) this week. Patch these immediately: CVE-2026-71362
🔴 Critical CVEs (1)
| CVE | Product | CVSS | KEV | Description | Published |
|---|---|---|---|---|---|
| CVE-2026-71362 | Magento | 9.1 | KEV | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An att… | Aug 11 |
🟠 High CVEs (37)
| CVE | Product | CVSS | KEV | Description | Published |
|---|---|---|---|---|---|
| CVE-2026-48416 | Magento | 7.5 | — | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A… | Aug 11 |
| CVE-2026-62872 | .NET Framework | 8.8 | — | Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network. | Aug 11 |
| CVE-2026-48413 | Magento | 8.7 | — | Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged… | Aug 11 |
| CVE-2026-16239 | PostgreSQL | 8.8 | — | Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating system u… | Aug 13 |
| CVE-2026-14669 | PostgreSQL | 8.8 | — | Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code… | Aug 13 |
| CVE-2026-72642 | Elasticsearch | 8.8 | — | The native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a model operat… | Aug 13 |
| CVE-2026-18692 | MongoDB | 8.8 | — | An issue in MongoDB Server's handling of timeseries bucket lifecycle could allow an authenticated user with write privil… | Aug 11 |
| CVE-2026-15742 | PostgreSQL | 8.8 | — | Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing ar… | Aug 13 |
| CVE-2026-6471 | PostgreSQL | 7.2 | — | Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any … | Aug 13 |
| CVE-2026-18711 | MongoDB | 7.1 | — | An issue in MongoDB Server's query execution engine could allow an authenticated user with read and write privileges to … | Aug 11 |
| CVE-2026-15741 | PostgreSQL | 8.8 | — | SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hosti… | Aug 13 |
| CVE-2026-14662 | PostgreSQL | 8.8 | — | Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause … | Aug 13 |
| CVE-2026-48415 | Magento | 7.6 | — | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A… | Aug 11 |
| CVE-2026-18697 | MongoDB | 7.5 | — | An issue in MongoDB Server's aggregation framework could allow an unauthenticated party to cause a mongos (router) proce… | Aug 11 |
| CVE-2026-14664 | PostgreSQL | 8.8 | — | Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user… | Aug 13 |
| CVE-2026-14676 | PostgreSQL | 8.8 | — | Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating… | Aug 13 |
| CVE-2026-14670 | PostgreSQL | 8.8 | — | Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary code as t… | Aug 13 |
| CVE-2026-19385 | PostgreSQL | 8.8 | — | Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute arbitrar… | Aug 13 |
| CVE-2026-14680 | PostgreSQL | 8.8 | — | Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating… | Aug 13 |
| CVE-2026-14677 | PostgreSQL | 8.8 | — | Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator to cause the server to under… | Aug 13 |
| CVE-2026-14671 | PostgreSQL | 8.8 | — | Type confusion in PostgreSQL module "refint" allows an object creator to execute arbitrary code as the operating system … | Aug 13 |
| CVE-2026-16238 | PostgreSQL | 8.8 | — | Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as the oper… | Aug 13 |
| CVE-2026-18690 | MongoDB | 8.1 | — | An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action ag… | Aug 11 |
| CVE-2026-65810 | .NET Framework | 7.8 | — | Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally. | Aug 11 |
| CVE-2026-18694 | MongoDB | 7.1 | — | An issue in MongoDB Server's geospatial query processing could allow an authenticated user with write privileges to caus… | Aug 11 |
| CVE-2026-18688 | MongoDB | 7.1 | — | An issue in MongoDB Server's aggregation framework could allow an authenticated user to trigger an out-of-bounds memory … | Aug 11 |
| CVE-2026-62897 | .NET Framework | 7.0 | — | Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally. | Aug 11 |
| CVE-2026-70354 | .NET Framework | 7.8 | — | Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. | Aug 11 |
| CVE-2026-6464 | PostgreSQL | 8.1 | — | Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as p… | Aug 13 |
| CVE-2026-18691 | MongoDB | 8.8 | — | An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influenc… | Aug 11 |
| CVE-2026-18408 | PostgreSQL | 8.8 | — | Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary … | Aug 13 |
| CVE-2026-18693 | MongoDB | 7.6 | — | An issue in MongoDB Server's handling of timeseries collections could allow an authenticated user with write privileges … | Aug 11 |
| CVE-2026-14668 | PostgreSQL | 8.1 | — | Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a cal… | Aug 13 |
| CVE-2026-48414 | Magento | 7.7 | — | Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged… | Aug 11 |
| CVE-2026-14679 | PostgreSQL | 8.2 | — | Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT p… | Aug 13 |
| CVE-2026-18687 | MongoDB | 7.1 | — | MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request para… | Aug 11 |
| CVE-2026-18712 | MongoDB | 8.1 | — | An issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authenticated user with privileg… | Aug 11 |
🟡 Medium CVEs (35)
| CVE | Product | CVSS | KEV | Description | Published |
|---|---|---|---|---|---|
| CVE-2026-48411 | Magento | 6.5 | — | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A… | Aug 11 |
| CVE-2026-72686 | Elasticsearch | 6.5 | — | A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single request containing a crafted user-… | Aug 13 |
| CVE-2026-72683 | Elasticsearch | 6.5 | — | A flaw in Elasticsearch allows an authenticated user with the privileges required to invoke the simulate pipeline API en… | Aug 13 |
| CVE-2026-72679 | Elasticsearch | 6.5 | — | Elasticsearch does not apply its configurable input length restriction to a user-supplied pattern accepted by an interva… | Aug 13 |
| CVE-2026-72678 | Elasticsearch | 6.5 | — | Elasticsearch does not validate a size value taken from a user-supplied input before that value is used to reserve memor… | Aug 13 |
| CVE-2026-18706 | MongoDB | 6.6 | — | An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able to issue aggregation … | Aug 11 |
| CVE-2026-72687 | Elasticsearch | 6.5 | — | A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single small request containing a forged … | Aug 13 |
| CVE-2026-72684 | Elasticsearch | 6.5 | — | A flaw in Elasticsearch allows an authenticated user holding only read privileges to submit a small search request conta… | Aug 13 |
| CVE-2026-72656 | Elasticsearch | 6.5 | — | Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial … | Aug 13 |
| CVE-2026-72647 | Elasticsearch | 6.5 | — | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Serialized Data with Nested Payloads… | Aug 13 |
| CVE-2026-72645 | Elasticsearch | 6.5 | — | Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Alloc… | Aug 13 |
| CVE-2026-72639 | Elasticsearch | 6.5 | — | Elasticsearch does not enforce an upper bound on a user-supplied count accepted by a search highlighting option, and the… | Aug 13 |
| CVE-2026-72638 | Elasticsearch | 6.5 | — | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153).… | Aug 13 |
| CVE-2026-72636 | Elasticsearch | 6.5 | — | Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matching helper can lead to a denial of service via Exces… | Aug 13 |
| CVE-2026-18701 | MongoDB | 6.5 | — | An issue in MongoDB Server's query subsystem could allow an authenticated user with read privileges to cause the server … | Aug 11 |
| CVE-2026-18700 | MongoDB | 6.5 | — | An issue in MongoDB Server's geospatial validation could allow an authenticated user with write privileges to cause an i… | Aug 11 |
| CVE-2026-18699 | MongoDB | 6.5 | — | An issue in MongoDB Server's query planner could allow an authenticated user with read-level privileges to cause the ser… | Aug 11 |
| CVE-2026-18695 | MongoDB | 6.5 | — | An issue in MongoDB Server's handling of certain query predicates against time-series collections with a metaField could… | Aug 11 |
| CVE-2026-18696 | MongoDB | 6.5 | — | An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to … | Aug 11 |
| CVE-2026-18708 | MongoDB | 6.4 | — | An issue in MongoDB Server's JavaScript scripting engine could allow an authenticated user with write privileges to caus… | Aug 11 |
| CVE-2026-72685 | Elasticsearch | 4.3 | — | A flaw in Elasticsearch allows a low-privileged authenticated user who can index documents to submit a single small docu… | Aug 13 |
| CVE-2026-18705 | MongoDB | 6.5 | — | An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to one view … | Aug 11 |
| CVE-2026-6470 | PostgreSQL | 4.3 | — | Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and… | Aug 13 |
| CVE-2026-18702 | MongoDB | 6.4 | — | An issue in MongoDB Server could allow an authenticated user with limited, database-scoped privileges to modify diagnost… | Aug 11 |
| CVE-2026-18707 | MongoDB | 4.3 | — | An issue in MongoDB Server could allow an authenticated user, including one with no assigned privileges, to cause the se… | Aug 11 |
| CVE-2026-14672 | PostgreSQL | 5.3 | — | Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence … | Aug 13 |
| CVE-2026-18698 | MongoDB | 5.4 | — | An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action ag… | Aug 11 |
| CVE-2026-18704 | MongoDB | 6.5 | — | An issue in MongoDB Server's aggregation framework could allow an authenticated user with only read privileges to perfor… | Aug 11 |
| CVE-2026-18709 | MongoDB | 6.4 | — | An issue in MongoDB Server could allow an authenticated user with direct network access to a shard to improperly commit … | Aug 11 |
| CVE-2026-18024 | PostgreSQL | 4.3 | — | Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific … | Aug 13 |
| CVE-2026-14678 | PostgreSQL | 4.3 | — | Buffer over-read in PostgreSQL pg_trgm index picksplit function reads past end of a heap buffer. This might allow a tab… | Aug 13 |
| CVE-2026-14666 | PostgreSQL | 4.2 | — | Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database ownership allows a query … | Aug 13 |
| CVE-2026-18703 | MongoDB | 4.2 | — | An issue in MongoDB Server could allow a party with a valid client certificate and a corresponding user account to authe… | Aug 11 |
| CVE-2026-14663 | PostgreSQL | 6.5 | — | Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of … | Aug 13 |
| CVE-2026-14681 | PostgreSQL | 4.2 | — | Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_… | Aug 13 |
🔵 Low CVEs (4)
| CVE | Product | CVSS | KEV | Description | Published |
|---|---|---|---|---|---|
| CVE-2026-48412 | Magento | 2.7 | — | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An att… | Aug 11 |
| CVE-2026-6469 | PostgreSQL | 3.8 | — | Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics … | Aug 13 |
| CVE-2026-16241 | PostgreSQL | 3.8 | — | Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service again… | Aug 13 |
| CVE-2026-14673 | PostgreSQL | 3.8 | — | Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary … | Aug 13 |
