Вторник обновлений
август 2026 г.
Во второй вторник месяца Microsoft, Adobe, SAP, Siemens и Schneider Electric публикуют пакетно; Oracle — в третий вторник января, апреля, июля и октября. Здесь записи того дня из нашей базы, по баллу действия: сначала KEV и зрелые эксплойты.
Как считается: метка CNA + дата публикации (окно два дня, UTC). Полного соответствия бюллетеню производителя не утверждается; внеплановые обновления выходят в другие дни.
записей: 470 · KEV: 3
Затрагивают ваш стек
Записи этого месяца, совпадающие с продуктами и версиями вашего стека.
Войдите, чтобы увидеть совпадения со стеком; записи и уведомления бесплатны. →
Microsoft · 11 августа
400 · KEV: 2 · критических: 9| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
66На этой неделе | CVE-2026-65660Готовый эксплойт | Microsoft SharePoint Server Remote Code Execution Vulnerabilitymicrosoft · sharepoint server · CWE-94 | Высокая8,8 | KEV | 2,1 % | 11 авг. 2026 г. |
58В плане | CVE-2026-68820Готовый эксплойт | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1607 · CWE-416 | Высокая7,0 | KEV | 0,3 % | 11 авг. 2026 г. |
39Наблюдать | CVE-2026-59124Эксплойта нет | Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerabilitymicrosoft · windows app · CWE-502 | Критическая9,8 | — | 1,5 % | 11 авг. 2026 г. |
39Наблюдать | CVE-2026-62815Эксплойта нет | Microsoft QUIC Remote Code Execution Vulnerabilitymicrosoft · windows 11 23h2 · CWE-416 | Критическая9,8 | — | 1,0 % | 11 авг. 2026 г. |
39Наблюдать | CVE-2026-62878Proof of concept | Windows DNS Server Remote Code Execution Vulnerabilitymicrosoft · windows 10 1607 · CWE-121 | Критическая9,8 | — | 1,0 % | 11 авг. 2026 г. |
39Наблюдать | CVE-2026-62893Эксплойта нет | Windows Deployment Services TFTP Server Remote Code Execution Vulnerabilitymicrosoft · windows 10 1607 · CWE-416 | Критическая9,8 | — | 1,0 % | 11 авг. 2026 г. |
39Наблюдать | CVE-2026-65768Эксплойта нет | Microsoft Teams Remote Code Execution Vulnerabilitymicrosoft · teams · CWE-22 | Критическая9,8 | — | 0,9 % | 11 авг. 2026 г. |
39Наблюдать | CVE-2026-65791Эксплойта нет | Windows iSCSI Target Service Remote Code Execution Vulnerabilitymicrosoft · windows 10 1607 · CWE-122 | Критическая9,8 | — | 1,0 % | 11 авг. 2026 г. |
38Наблюдать | CVE-2026-57104Эксплойта нет | Azure Storage Explorer Elevation of Privilege Vulnerabilitymicrosoft · azure storage explorer · CWE-79 | Критическая9,6 | — | 0,9 % | 11 авг. 2026 г. |
37Наблюдать | CVE-2026-50516Эксплойта нет | Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerabilitymicrosoft · azure kubernetes service · CWE-306 | Критическая9,4 | — | 0,8 % | 11 авг. 2026 г. |
37Наблюдать | CVE-2026-70306Эксплойта нет | Microsoft Office SharePoint Spoofing Vulnerabilitymicrosoft · sharepoint server · CWE-79 | Критическая9,3 | — | 1,0 % | 11 авг. 2026 г. |
36Наблюдать | CVE-2026-63514Эксплойта нет | Microsoft SharePoint Server Remote Code Execution Vulnerabilitymicrosoft · sharepoint server · CWE-502 | Высокая8,8 | — | 2,0 % | 11 авг. 2026 г. |
- CVE-2026-6566066На этой неделе
Microsoft SharePoint Server Remote Code Execution Vulnerability
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 2 %microsoft · sharepoint server11 авг. 2026 г.
- CVE-2026-6882058В плане
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
ВысокаяCVSS 7,0KEVГотовый эксплойтEPSS 0 %microsoft · windows 10 160711 авг. 2026 г.
- CVE-2026-5912439Наблюдать
Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %microsoft · windows app11 авг. 2026 г.
- CVE-2026-6281539Наблюдать
Microsoft QUIC Remote Code Execution Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %microsoft · windows 11 23h211 авг. 2026 г.
- CVE-2026-6287839Наблюдать
Windows DNS Server Remote Code Execution Vulnerability
КритическаяCVSS 9,8Proof of conceptEPSS 1 %microsoft · windows 10 160711 авг. 2026 г.
- CVE-2026-6289339Наблюдать
Windows Deployment Services TFTP Server Remote Code Execution Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %microsoft · windows 10 160711 авг. 2026 г.
- CVE-2026-6576839Наблюдать
Microsoft Teams Remote Code Execution Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %microsoft · teams11 авг. 2026 г.
- CVE-2026-6579139Наблюдать
Windows iSCSI Target Service Remote Code Execution Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %microsoft · windows 10 160711 авг. 2026 г.
- CVE-2026-5710438Наблюдать
Azure Storage Explorer Elevation of Privilege Vulnerability
КритическаяCVSS 9,6Эксплойта нетEPSS 1 %microsoft · azure storage explorer11 авг. 2026 г.
- CVE-2026-5051637Наблюдать
Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
КритическаяCVSS 9,4Эксплойта нетEPSS 1 %microsoft · azure kubernetes service11 авг. 2026 г.
- CVE-2026-7030637Наблюдать
Microsoft Office SharePoint Spoofing Vulnerability
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %microsoft · sharepoint server11 авг. 2026 г.
- CVE-2026-6351436Наблюдать
Microsoft SharePoint Server Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %microsoft · sharepoint server11 авг. 2026 г.
+388 ещёВсе записи производителя
Adobe · 11 августа
52 · KEV: 1 · критических: 6| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
92Срочно | CVE-2026-71362Готовый эксплойт | Adobe Commerce | Incorrect Authorization (CWE-863)adobe · commerce · CWE-863 | Критическая9,1 | KEV | 87,5 % | 11 авг. 2026 г. |
41В плане | CVE-2026-48362Эксплойта нет | ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)adobe · coldfusion · CWE-78 | Критическая10,0 | — | 3,5 % | 11 авг. 2026 г. |
40В плане | CVE-2026-27302Эксплойта нет | Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)adobe · campaign · CWE-863 | Критическая10,0 | — | 1,2 % | 11 авг. 2026 г. |
40В плане | CVE-2026-71398Эксплойта нет | Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)adobe · campaign · CWE-863 | Критическая10,0 | — | 1,2 % | 11 авг. 2026 г. |
38Наблюдать | CVE-2026-71384Эксплойта нет | ColdFusion | Incorrect Authorization (CWE-863)adobe · coldfusion · CWE-863 | Критическая9,6 | — | 0,5 % | 11 авг. 2026 г. |
36Наблюдать | CVE-2026-48381Эксплойта нет | Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)adobe · campaign · CWE-89 | Критическая9,0 | — | 0,8 % | 11 авг. 2026 г. |
35Наблюдать | CVE-2026-71386Эксплойта нет | ColdFusion | Cross-site Scripting (XSS) (CWE-79)adobe · coldfusion · CWE-79 | Высокая8,8 | — | 0,6 % | 11 авг. 2026 г. |
35Наблюдать | CVE-2026-71387Эксплойта нет | ColdFusion | Incorrect Authorization (CWE-863)adobe · coldfusion · CWE-863 | Высокая8,8 | — | 0,5 % | 11 авг. 2026 г. |
34Наблюдать | CVE-2026-21273Эксплойта нет | ColdFusion | Improper Input Validation (CWE-20)adobe · coldfusion · CWE-20 | Высокая8,7 | — | 0,9 % | 11 авг. 2026 г. |
34Наблюдать | CVE-2026-48397Эксплойта нет | Lightroom Classic | Deserialization of Untrusted Data (CWE-502)adobe · lightroom · CWE-502 | Высокая8,6 | — | 1,0 % | 11 авг. 2026 г. |
34Наблюдать | CVE-2026-48413Эксплойта нет | Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)adobe · commerce · CWE-79 | Высокая8,7 | — | 0,7 % | 11 авг. 2026 г. |
34Наблюдать | CVE-2026-48414Эксплойта нет | Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)adobe · commerce · CWE-79 | Высокая8,7 | — | 0,3 % | 11 авг. 2026 г. |
- CVE-2026-7136292Срочно
Adobe Commerce | Incorrect Authorization (CWE-863)
КритическаяCVSS 9,1KEVГотовый эксплойтEPSS 88 %adobe · commerce11 авг. 2026 г.
- CVE-2026-4836241В плане
ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %adobe · coldfusion11 авг. 2026 г.
- CVE-2026-2730240В плане
Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %adobe · campaign11 авг. 2026 г.
- CVE-2026-7139840В плане
Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %adobe · campaign11 авг. 2026 г.
- CVE-2026-7138438Наблюдать
ColdFusion | Incorrect Authorization (CWE-863)
КритическаяCVSS 9,6Эксплойта нетEPSS 0 %adobe · coldfusion11 авг. 2026 г.
- CVE-2026-4838136Наблюдать
Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
КритическаяCVSS 9,0Эксплойта нетEPSS 1 %adobe · campaign11 авг. 2026 г.
- CVE-2026-7138635Наблюдать
ColdFusion | Cross-site Scripting (XSS) (CWE-79)
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %adobe · coldfusion11 авг. 2026 г.
- CVE-2026-7138735Наблюдать
ColdFusion | Incorrect Authorization (CWE-863)
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %adobe · coldfusion11 авг. 2026 г.
- CVE-2026-2127334Наблюдать
ColdFusion | Improper Input Validation (CWE-20)
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %adobe · coldfusion11 авг. 2026 г.
- CVE-2026-4839734Наблюдать
Lightroom Classic | Deserialization of Untrusted Data (CWE-502)
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %adobe · lightroom11 авг. 2026 г.
- CVE-2026-4841334Наблюдать
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %adobe · commerce11 авг. 2026 г.
- CVE-2026-4841434Наблюдать
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %adobe · commerce11 авг. 2026 г.
+40 ещёВсе записи производителя
SAP · 11 августа
1 · KEV: 0 · критических: 1| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2026-58231Proof of concept | Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)sap_se · sap commerce cloud (data hub adapter) · CWE-94 | Критическая10,0 | — | 0,9 % | 11 авг. 2026 г. |
- CVE-2026-5823140В плане
Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)
КритическаяCVSS 10,0Proof of conceptEPSS 1 %sap_se · sap commerce cloud (data hub adapter)11 авг. 2026 г.
Siemens · 11 августа
17 · KEV: 0 · критических: 1| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2026-58115Эксплойта нет | A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Nodsiemens · simatic iot2050 advanced · CWE-306 | Критическая10,0 | — | 1,0 % | 11 авг. 2026 г. |
34Наблюдать | CVE-2026-69109Эксплойта нет | A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.3).siemens · siemens license server (sls) · CWE-35 | Высокая8,7 | — | 0,6 % | 11 авг. 2026 г. |
33Наблюдать | CVE-2026-69108Эксплойта нет | A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.1).siemens · siemens license server (sls) · CWE-732 | Высокая8,3 | — | 0,2 % | 11 авг. 2026 г. |
29Наблюдать | CVE-2026-50058Эксплойта нет | A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update siemens · solid edge se2025 · CWE-125 | Высокая7,3 | — | 0,2 % | 11 авг. 2026 г. |
29Наблюдать | CVE-2026-50059Эксплойта нет | A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update siemens · solid edge se2025 · CWE-787 | Высокая7,3 | — | 0,2 % | 11 авг. 2026 г. |
29Наблюдать | CVE-2026-50060Эксплойта нет | A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update siemens · solid edge se2025 · CWE-416 | Высокая7,3 | — | 0,2 % | 11 авг. 2026 г. |
29Наблюдать | CVE-2026-50061Эксплойта нет | A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update siemens · solid edge se2025 · CWE-416 | Высокая7,3 | — | 0,2 % | 11 авг. 2026 г. |
29Наблюдать | CVE-2026-50062Эксплойта нет | A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update siemens · solid edge se2025 · CWE-125 | Высокая7,3 | — | 0,2 % | 11 авг. 2026 г. |
29Наблюдать | CVE-2026-50063Эксплойта нет | A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update siemens · solid edge se2025 · CWE-125 | Высокая7,3 | — | 0,2 % | 11 авг. 2026 г. |
29Наблюдать | CVE-2026-50064Эксплойта нет | A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update siemens · solid edge se2025 · CWE-787 | Высокая7,3 | — | 0,2 % | 11 авг. 2026 г. |
29Наблюдать | CVE-2026-59086Эксплойта нет | A vulnerability has been identified in Simcenter Femap (All versions < V2606), Simcenter Nastran (All versions < V2606).siemens · simcenter femap · CWE-121 | Высокая7,3 | — | 0,2 % | 11 авг. 2026 г. |
29Наблюдать | CVE-2026-59700Эксплойта нет | A vulnerability has been identified in Simcenter Femap (All versions < V2606.0001).siemens · simcenter femap · CWE-125 | Высокая7,3 | — | 0,2 % | 11 авг. 2026 г. |
- CVE-2026-5811540В плане
A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Nod
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %siemens · simatic iot2050 advanced11 авг. 2026 г.
- CVE-2026-6910934Наблюдать
A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.3).
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %siemens · siemens license server (sls)11 авг. 2026 г.
- CVE-2026-6910833Наблюдать
A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.1).
ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %siemens · siemens license server (sls)11 авг. 2026 г.
- CVE-2026-5005829Наблюдать
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update
ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %siemens · solid edge se202511 авг. 2026 г.
- CVE-2026-5005929Наблюдать
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update
ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %siemens · solid edge se202511 авг. 2026 г.
- CVE-2026-5006029Наблюдать
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update
ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %siemens · solid edge se202511 авг. 2026 г.
- CVE-2026-5006129Наблюдать
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update
ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %siemens · solid edge se202511 авг. 2026 г.
- CVE-2026-5006229Наблюдать
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update
ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %siemens · solid edge se202511 авг. 2026 г.
- CVE-2026-5006329Наблюдать
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update
ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %siemens · solid edge se202511 авг. 2026 г.
- CVE-2026-5006429Наблюдать
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update
ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %siemens · solid edge se202511 авг. 2026 г.
- CVE-2026-5908629Наблюдать
A vulnerability has been identified in Simcenter Femap (All versions < V2606), Simcenter Nastran (All versions < V2606).
ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %siemens · simcenter femap11 авг. 2026 г.
- CVE-2026-5970029Наблюдать
A vulnerability has been identified in Simcenter Femap (All versions < V2606.0001).
ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %siemens · simcenter femap11 авг. 2026 г.
+5 ещёВсе записи производителя
Schneider Electric · 11 августа
0 · KEV: 0 · критических: 0В этом окне записей нет.