Yama Salısı
Temmuz 2026
Her ayın ikinci salısı Microsoft, Adobe, SAP, Siemens ve Schneider Electric toplu yayın yapar; Oracle ocak, nisan, temmuz ve ekimde üçüncü salı. Burada o gün yayımlanan kayıtlar kendi veritabanımızdan, eylem puanına göre sıralı: önce KEV ve istismarı olgun olanlar.
Nasıl hesaplanır: CNA damgası + yayın tarihi (iki günlük pencere, UTC). Üreticinin bülteniyle bire bir eşleşme iddiası yok; ara güncellemeler ayrı günlerde çıkar.
891 kayıt · 5 KEV
Stack'inizi etkileyenler
Bu ayın kayıtlarından stack'inizdeki ürün ve sürümlere uyanlar.
Stack'inize uyanları görmek için giriş yapın; kayıtlar ve bildirimler ücretsiz. →
Microsoft · 14 Temmuz
400 · 5 KEV · 31 kritik| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
87Hemen | CVE-2026-55040Silahlaştırılmış | Microsoft SharePoint Server Security Feature Bypass Vulnerabilitymicrosoft · sharepoint server · CWE-1390 | Kritik9,1 | KEV | %69,5 | 14 Tem 2026 |
74Bu hafta | CVE-2026-58644Silahlaştırılmış | Microsoft SharePoint Remote Code Execution Vulnerabilitymicrosoft · sharepoint server · CWE-502 | Kritik9,8 | KEV | %15,9 | 14 Tem 2026 |
70Bu hafta | CVE-2026-50522Silahlaştırılmış | Microsoft SharePoint Remote Code Execution Vulnerabilitymicrosoft · sharepoint server · CWE-502 | Kritik9,8 | KEV | %3,0 | 14 Tem 2026 |
69Bu hafta | CVE-2026-56164Silahlaştırılmış | Microsoft SharePoint Server Elevation of Privilege Vulnerabilitymicrosoft · sharepoint server · CWE-306 | Kritik9,8 | KEV | %1,0 | 14 Tem 2026 |
61Bu hafta | CVE-2026-56155Silahlaştırılmış | Active Directory Federation Services Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1607 · CWE-1220 | Yüksek7,8 | KEV | %0,3 | 14 Tem 2026 |
39İzleyin | CVE-2026-42990İstismar yok | SQL Server ODBC driver Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1607 · CWE-122 | Kritik9,8 | — | %1,0 | 14 Tem 2026 |
39İzleyin | CVE-2026-47304İstismar yok | .NET Security Feature Bypass Vulnerabilitymicrosoft · .net framework · CWE-345 | Kritik9,8 | — | %0,3 | 14 Tem 2026 |
39İzleyin | CVE-2026-49164İstismar yok | Windows Active Directory Domain Services Remote Code Execution Vulnerabilitymicrosoft · windows 10 1607 · CWE-122 | Kritik9,8 | — | %0,8 | 14 Tem 2026 |
39İzleyin | CVE-2026-49172İstismar yok | Windows FTP Service Remote Code Execution Vulnerabilitymicrosoft · windows 10 1607 · CWE-122 | Kritik9,8 | — | %1,0 | 14 Tem 2026 |
39İzleyin | CVE-2026-49181İstismar yok | Windows DHCP Client Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1607 · CWE-191 | Kritik9,8 | — | %1,2 | 14 Tem 2026 |
39İzleyin | CVE-2026-50330İstismar yok | Windows Remote Desktop Client Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1607 · CWE-122 | Kritik9,8 | — | %1,3 | 14 Tem 2026 |
39İzleyin | CVE-2026-50439İstismar yok | Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerabilitymicrosoft · windows 10 1607 · CWE-416 | Kritik9,8 | — | %0,8 | 14 Tem 2026 |
- CVE-2026-5504087Hemen
Microsoft SharePoint Server Security Feature Bypass Vulnerability
KritikCVSS 9,1KEVSilahlaştırılmışEPSS %70microsoft · sharepoint server14 Tem 2026
- CVE-2026-5864474Bu hafta
Microsoft SharePoint Remote Code Execution Vulnerability
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %16microsoft · sharepoint server14 Tem 2026
- CVE-2026-5052270Bu hafta
Microsoft SharePoint Remote Code Execution Vulnerability
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %3microsoft · sharepoint server14 Tem 2026
- CVE-2026-5616469Bu hafta
Microsoft SharePoint Server Elevation of Privilege Vulnerability
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %1microsoft · sharepoint server14 Tem 2026
- CVE-2026-5615561Bu hafta
Active Directory Federation Services Elevation of Privilege Vulnerability
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %0microsoft · windows 10 160714 Tem 2026
- CVE-2026-4299039İzleyin
SQL Server ODBC driver Elevation of Privilege Vulnerability
KritikCVSS 9,8İstismar yokEPSS %1microsoft · windows 10 160714 Tem 2026
- CVE-2026-4730439İzleyin
.NET Security Feature Bypass Vulnerability
KritikCVSS 9,8İstismar yokEPSS %0microsoft · .net framework14 Tem 2026
- CVE-2026-4916439İzleyin
Windows Active Directory Domain Services Remote Code Execution Vulnerability
KritikCVSS 9,8İstismar yokEPSS %1microsoft · windows 10 160714 Tem 2026
- CVE-2026-4917239İzleyin
Windows FTP Service Remote Code Execution Vulnerability
KritikCVSS 9,8İstismar yokEPSS %1microsoft · windows 10 160714 Tem 2026
- CVE-2026-4918139İzleyin
Windows DHCP Client Elevation of Privilege Vulnerability
KritikCVSS 9,8İstismar yokEPSS %1microsoft · windows 10 160714 Tem 2026
- CVE-2026-5033039İzleyin
Windows Remote Desktop Client Elevation of Privilege Vulnerability
KritikCVSS 9,8İstismar yokEPSS %1microsoft · windows 10 160714 Tem 2026
- CVE-2026-5043939İzleyin
Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability
KritikCVSS 9,8İstismar yokEPSS %1microsoft · windows 10 160714 Tem 2026
+388 kayıt dahaÜreticinin tüm kayıtları
Adobe · 14 Temmuz
88 · 0 KEV · 13 kritik| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2026-48318İstismar yok | ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)adobe · coldfusion · CWE-22 | Kritik9,9 | — | %1,1 | 14 Tem 2026 |
39İzleyin | CVE-2026-48322İstismar yok | ColdFusion | Improper Control of Generation of Code ('Code Injection') (CWE-94)adobe · coldfusion · CWE-94 | Kritik9,9 | — | %1,2 | 14 Tem 2026 |
38İzleyin | CVE-2026-48259İstismar yok | Adobe Experience Manager | Server-Side Request Forgery (SSRF) (CWE-918)adobe · experience manager · CWE-918 | Kritik9,6 | — | %0,9 | 14 Tem 2026 |
38İzleyin | CVE-2026-48284İstismar yok | ColdFusion | Improper Input Validation (CWE-20)adobe · coldfusion · CWE-20 | Kritik9,6 | — | %0,5 | 14 Tem 2026 |
38İzleyin | CVE-2026-48359İstismar yok | Adobe Experience Manager | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)adobe · experience manager · CWE-611 | Kritik9,6 | — | %1,0 | 14 Tem 2026 |
37İzleyin | CVE-2026-48321İstismar yok | ColdFusion | Incorrect Authorization (CWE-863)adobe · coldfusion · CWE-863 | Kritik9,3 | — | %0,4 | 14 Tem 2026 |
37İzleyin | CVE-2026-48325İstismar yok | ColdFusion | Missing Authentication for Critical Function (CWE-306)adobe · coldfusion · CWE-306 | Kritik9,3 | — | %0,6 | 14 Tem 2026 |
37İzleyin | CVE-2026-48334İstismar yok | Illustrator | Improper Input Validation (CWE-20)adobe · illustrator · CWE-20 | Kritik9,3 | — | %1,0 | 14 Tem 2026 |
37İzleyin | CVE-2026-48356Kavram kanıtı | Adobe Commerce | Unrestricted Upload of File with Dangerous Type (CWE-434)adobe · commerce · CWE-434 | Kritik9,3 | — | %1,0 | 14 Tem 2026 |
36İzleyin | CVE-2026-48319İstismar yok | ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)adobe · coldfusion · CWE-22 | Kritik9,1 | — | %1,4 | 14 Tem 2026 |
36İzleyin | CVE-2026-48324İstismar yok | ColdFusion | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)adobe · coldfusion · CWE-89 | Kritik9,1 | — | %1,1 | 14 Tem 2026 |
36İzleyin | CVE-2026-48327İstismar yok | ColdFusion | Incorrect Authorization (CWE-863)adobe · coldfusion · CWE-863 | Kritik9,0 | — | %0,4 | 14 Tem 2026 |
- CVE-2026-4831839İzleyin
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
KritikCVSS 9,9İstismar yokEPSS %1adobe · coldfusion14 Tem 2026
- CVE-2026-4832239İzleyin
ColdFusion | Improper Control of Generation of Code ('Code Injection') (CWE-94)
KritikCVSS 9,9İstismar yokEPSS %1adobe · coldfusion14 Tem 2026
- CVE-2026-4825938İzleyin
Adobe Experience Manager | Server-Side Request Forgery (SSRF) (CWE-918)
KritikCVSS 9,6İstismar yokEPSS %1adobe · experience manager14 Tem 2026
- CVE-2026-4828438İzleyin
ColdFusion | Improper Input Validation (CWE-20)
KritikCVSS 9,6İstismar yokEPSS %0adobe · coldfusion14 Tem 2026
- CVE-2026-4835938İzleyin
Adobe Experience Manager | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)
KritikCVSS 9,6İstismar yokEPSS %1adobe · experience manager14 Tem 2026
- CVE-2026-4832137İzleyin
ColdFusion | Incorrect Authorization (CWE-863)
KritikCVSS 9,3İstismar yokEPSS %0adobe · coldfusion14 Tem 2026
- CVE-2026-4832537İzleyin
ColdFusion | Missing Authentication for Critical Function (CWE-306)
KritikCVSS 9,3İstismar yokEPSS %1adobe · coldfusion14 Tem 2026
- CVE-2026-4833437İzleyin
Illustrator | Improper Input Validation (CWE-20)
KritikCVSS 9,3İstismar yokEPSS %1adobe · illustrator14 Tem 2026
- CVE-2026-4835637İzleyin
Adobe Commerce | Unrestricted Upload of File with Dangerous Type (CWE-434)
KritikCVSS 9,3Kavram kanıtıEPSS %1adobe · commerce14 Tem 2026
- CVE-2026-4831936İzleyin
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
KritikCVSS 9,1İstismar yokEPSS %1adobe · coldfusion14 Tem 2026
- CVE-2026-4832436İzleyin
ColdFusion | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
KritikCVSS 9,1İstismar yokEPSS %1adobe · coldfusion14 Tem 2026
- CVE-2026-4832736İzleyin
ColdFusion | Incorrect Authorization (CWE-863)
KritikCVSS 9,0İstismar yokEPSS %0adobe · coldfusion14 Tem 2026
+76 kayıt dahaÜreticinin tüm kayıtları
SAP · 14 Temmuz
0 · 0 KEV · 0 kritikBu pencerede kayıt yok.
Siemens · 14 Temmuz
3 · 0 KEV · 1 kritik| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2026-56451İstismar yok | A vulnerability has been identified in Opcenter X (All versions < V2604).siemens · opcenter x · CWE-347 | Kritik10,0 | — | %0,5 | 14 Tem 2026 |
34İzleyin | CVE-2025-40945İstismar yok | A vulnerability has been identified in COMOS V10.4.5 (All versions < V10.4.5.0.2), COMOS V10.6 (All versions < V10.6.1), Designcenter NX (Alsiemens · comos v10.4.5 · CWE-426 | Yüksek8,5 | — | %0,2 | 14 Tem 2026 |
24İzleyin | CVE-2026-54429İstismar yok | A vulnerability has been identified in SIMATIC S7-PLCSIM Advanced (All versions).siemens · simatic s7-plcsim advanced · CWE-770 | Orta6,0 | — | %0,3 | 14 Tem 2026 |
- CVE-2026-5645140Planlayın
A vulnerability has been identified in Opcenter X (All versions < V2604).
KritikCVSS 10,0İstismar yokEPSS %0siemens · opcenter x14 Tem 2026
- CVE-2025-4094534İzleyin
A vulnerability has been identified in COMOS V10.4.5 (All versions < V10.4.5.0.2), COMOS V10.6 (All versions < V10.6.1), Designcenter NX (Al
YüksekCVSS 8,5İstismar yokEPSS %0siemens · comos v10.4.514 Tem 2026
- CVE-2026-5442924İzleyin
A vulnerability has been identified in SIMATIC S7-PLCSIM Advanced (All versions).
OrtaCVSS 6,0İstismar yokEPSS %0siemens · simatic s7-plcsim advanced14 Tem 2026
Schneider Electric · 14 Temmuz
0 · 0 KEV · 0 kritikBu pencerede kayıt yok.
Oracle (Critical Patch Update) · 21 Temmuz
400 · 0 KEV · 210 kritik| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2026-47056İstismar yok | Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Rest Service).oracle · data integrator · CWE-306 | Kritik10,0 | — | %0,5 | 21 Tem 2026 |
40Planlayın | CVE-2026-60217İstismar yok | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).oracle · coherence · CWE-306 | Kritik10,0 | — | %0,5 | 21 Tem 2026 |
40Planlayın | CVE-2026-60358İstismar yok | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).oracle · access manager · CWE-284 | Kritik10,0 | — | %0,5 | 21 Tem 2026 |
40Planlayın | CVE-2026-60360İstismar yok | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core).oracle · unified directory · CWE-306 | Kritik10,0 | — | %0,5 | 21 Tem 2026 |
40Planlayın | CVE-2026-60365İstismar yok | Vulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: WebLogic Server Proxy Plug-In for oracle · http server · CWE-306 | Kritik10,0 | — | %0,4 | 21 Tem 2026 |
40Planlayın | CVE-2026-60366İstismar yok | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars).oracle · platform security for java · CWE-269 | Kritik10,0 | — | %0,5 | 22 Tem 2026 |
40Planlayın | CVE-2026-60379İstismar yok | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).oracle · service delivery platform · CWE-306 | Kritik10,0 | — | %0,5 | 21 Tem 2026 |
40Planlayın | CVE-2026-60389İstismar yok | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).oracle · service delivery platform · CWE-306 | Kritik10,0 | — | %0,5 | 21 Tem 2026 |
40Planlayın | CVE-2026-60644İstismar yok | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).oracle · webcenter content · CWE-306 | Kritik10,0 | — | %0,5 | 21 Tem 2026 |
39İzleyin | CVE-2026-35290İstismar yok | Vulnerability in Oracle Application Testing Suite.oracle · application testing suite · CWE-284 | Kritik9,8 | — | %0,5 | 21 Tem 2026 |
39İzleyin | CVE-2026-46876İstismar yok | Vulnerability in Oracle Application Testing Suite.oracle · application testing suite · CWE-284 | Kritik9,8 | — | %0,5 | 21 Tem 2026 |
39İzleyin | CVE-2026-46924İstismar yok | Vulnerability in Oracle Application Testing Suite.oracle · application testing suite · CWE-284 | Kritik9,8 | — | %0,5 | 21 Tem 2026 |
- CVE-2026-4705640Planlayın
Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Rest Service).
KritikCVSS 10,0İstismar yokEPSS %1oracle · data integrator21 Tem 2026
- CVE-2026-6021740Planlayın
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).
KritikCVSS 10,0İstismar yokEPSS %1oracle · coherence21 Tem 2026
- CVE-2026-6035840Planlayın
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).
KritikCVSS 10,0İstismar yokEPSS %1oracle · access manager21 Tem 2026
- CVE-2026-6036040Planlayın
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core).
KritikCVSS 10,0İstismar yokEPSS %1oracle · unified directory21 Tem 2026
- CVE-2026-6036540Planlayın
Vulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: WebLogic Server Proxy Plug-In for
KritikCVSS 10,0İstismar yokEPSS %0oracle · http server21 Tem 2026
- CVE-2026-6036640Planlayın
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars).
KritikCVSS 10,0İstismar yokEPSS %1oracle · platform security for java22 Tem 2026
- CVE-2026-6037940Planlayın
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).
KritikCVSS 10,0İstismar yokEPSS %1oracle · service delivery platform21 Tem 2026
- CVE-2026-6038940Planlayın
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).
KritikCVSS 10,0İstismar yokEPSS %1oracle · service delivery platform21 Tem 2026
- CVE-2026-6064440Planlayın
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).
KritikCVSS 10,0İstismar yokEPSS %1oracle · webcenter content21 Tem 2026
- CVE-2026-3529039İzleyin
Vulnerability in Oracle Application Testing Suite.
KritikCVSS 9,8İstismar yokEPSS %1oracle · application testing suite21 Tem 2026
- CVE-2026-4687639İzleyin
Vulnerability in Oracle Application Testing Suite.
KritikCVSS 9,8İstismar yokEPSS %1oracle · application testing suite21 Tem 2026
- CVE-2026-4692439İzleyin
Vulnerability in Oracle Application Testing Suite.
KritikCVSS 9,8İstismar yokEPSS %1oracle · application testing suite21 Tem 2026
+388 kayıt dahaÜreticinin tüm kayıtları