← Back to the live CVE advisory feed

CVE-2026-59335: UAA

Severity
8.7 (HIGH)
Vendor
VMWARE
Affected versions
0 through before 78.16.0; 0 through before 57.0.0
Fixed version
78.16.0
Patch status
Patched
Published
2026-08-25T11:16:53.817
Modified
2026-08-25T13:19:25.070

Why it matters

High-severity vulnerability requiring prioritized review.

Recommended admin actions

  • Review and patch based on exposure, asset criticality, and business impact.
  • Treat internet-facing systems as higher priority.

Technical summary

Improper handling of case sensitivity (CWE-178) in the identity zone authorization check in the Identity Zone Endpoint in Cloud Foundry UAA allows a remote authenticated attacker holding only the zones.write authority to bypass the intended restriction that this authority does not grant access to the privileged uaa (system) identity zone, by referring to the zone identifier in a non-lowercase form (e.g. UAA) in the request path and body. The authorization layer performs a case-sensitive comparison against the system zone identifier, while the underlying MySQL persistence layer resolves identifiers case-insensitively under its default collation, so the request is authorized incorrectly and is then resolved against the real system zone record. This allows the attacker to overwrite the system zone's JWT signing key with attacker-controlled key material, forge JWTs claiming the admin client and administrator scopes, and fully compromise UAA and any Cloud Foundry deployment that trusts it. This issue only affects UAA deployments backed by MySQL using its default collation; PostgreSQL and HSQLDB backends are not affected.

CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.

VULNERABILITY PULSE

LAST UPDATED: AUG 26, 2026 12:00 AM UTC
771 RECORDS
SECURE FEED ACTIVE
AFFECTED PRODUCT ACTION
CVE-2026-77998
SAML SSO for Joomla extension for Joomla
Reporter: SECURITY
10
CRITICAL
VIEW RECORD
CVE-2026-76193
Product identification pending
Reporter: PSIRT
10
CRITICAL
VIEW RECORD
CVE-2026-76195
Product identification pending
Reporter: PSIRT
10
CRITICAL
VIEW RECORD
CVE-2026-76197
Product identification pending
Reporter: PSIRT
10
CRITICAL
VIEW RECORD
CVE-2026-65083
Product identification pending
Reporter: PSIRT
9.9
CRITICAL
VIEW RECORD
CVE-2026-65093
Product identification pending
Reporter: PSIRT
9.9
CRITICAL
VIEW RECORD
CVE-2026-13214
Product identification pending
Reporter: VULNERABILITIES
9.8
CRITICAL
VIEW RECORD
CVE-2026-78477
Jawn
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-78568
Total Donations
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-78570
Total Donations
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-49845
Product identification pending PATCH
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-16286
Product identification pending PATCH
Reporter: ILETISIM
9.8
CRITICAL
VIEW RECORD
CVE-2026-55546
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.8
CRITICAL
VIEW RECORD
CVE-2026-45018
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.8
CRITICAL
VIEW RECORD
CVE-2026-77136
Extension "powermail"
Reporter: F4FB688C-4412-4426-B4B8-421ECF27B14A
9.5
CRITICAL
VIEW RECORD
CVE-2026-78683
Product identification pending PATCH
Reporter: DISCLOSURE
9.4
CRITICAL
VIEW RECORD
CVE-2026-57909
WatchGuard Agent
Reporter: 5D1C2695-1A31-4499-88AE-E847036FD7E3
9.4
CRITICAL
VIEW RECORD
CVE-2026-56705
adminer PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-56710
Product identification pending PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-72699
grav PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-72702
Product identification pending PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-78676
Product identification pending PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-63586
Product identification pending
Reporter: INFO
9.3
CRITICAL
VIEW RECORD
CVE-2026-77138
Extension "HTML5 Video Player vs. Powermail"
Reporter: F4FB688C-4412-4426-B4B8-421ECF27B14A
9.3
CRITICAL
VIEW RECORD
CVE-2026-57910
WatchGuard Agent
Reporter: 5D1C2695-1A31-4499-88AE-E847036FD7E3
9.3
CRITICAL
VIEW RECORD
CVE-2026-79657
Product identification pending PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2022-51000
Product identification pending PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2024-58377
Product identification pending PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2024-58378
Product identification pending PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2025-71407
Product identification pending PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-79675
Product identification pending PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-79774
winter PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-79782
Product identification pending PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-79787
alluxio
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-80104
DB-GPT
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-79911
N600R
Reporter: CNA
9.3
CRITICAL
VIEW RECORD
CVE-2026-78379
Product identification pending PATCH
Reporter: FF89BA41-3AA1-4D27-914A-91399E9639E5
9.2
CRITICAL
VIEW RECORD
CVE-2026-80138
clipbucket-v5
Reporter: DISCLOSURE
9.2
CRITICAL
VIEW RECORD
CVE-2026-79664
Product identification pending PATCH
Reporter: DISCLOSURE
9.1
CRITICAL
VIEW RECORD
CVE-2026-55536
PraisonAI PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-55640
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-62862
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-19892
InfusedWoo Pro
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-16601
CM Map Locations – Visualize and share your locations in a few clicks
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-59769
FA-50
Reporter: VULTURES
8.8
HIGH
VIEW RECORD
CVE-2026-63587
Product identification pending
Reporter: INFO
8.8
HIGH
VIEW RECORD
CVE-2026-77141
Extension "Club Directory"
Reporter: F4FB688C-4412-4426-B4B8-421ECF27B14A
8.8
HIGH
VIEW RECORD
CVE-2026-77142
Extension "Industry Directory"
Reporter: F4FB688C-4412-4426-B4B8-421ECF27B14A
8.8
HIGH
VIEW RECORD
CVE-2026-77143
Extension "Forum"
Reporter: F4FB688C-4412-4426-B4B8-421ECF27B14A
8.8
HIGH
VIEW RECORD
CVE-2026-49050
Product identification pending PATCH
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-19949
All-in-One WP Migration and Backup
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-79662
Product identification pending PATCH
Reporter: DISCLOSURE
8.8
HIGH
VIEW RECORD
CVE-2026-55541
PraisonAI PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2022-50999
Product identification pending PATCH
Reporter: DISCLOSURE
8.8
HIGH
VIEW RECORD
CVE-2026-79674
Product identification pending PATCH
Reporter: DISCLOSURE
8.8
HIGH
VIEW RECORD
CVE-2026-24170
Product identification pending
Reporter: PSIRT
8.8
HIGH
VIEW RECORD
CVE-2026-55585
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-55637
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-65091
Product identification pending
Reporter: PSIRT
8.8
HIGH
VIEW RECORD
CVE-2026-56709
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-72700
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-75574
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-76839
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-76846
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-78677
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-78681
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-78682
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-67578
FA-50
Reporter: VULTURES
8.7
HIGH
VIEW RECORD
CVE-2026-77140
Extension "Telephone Directory"
Reporter: F4FB688C-4412-4426-B4B8-421ECF27B14A
8.7
HIGH
VIEW RECORD
CVE-2026-12600
Innodata Labs
Reporter: CVE-COORDINATION
8.7
HIGH
VIEW RECORD
CVE-2026-59335
UAA PATCH
Reporter: SECURITY
8.7
HIGH
VIEW RECORD
CVE-2026-79658
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-79665
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-57863
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2021-47996
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2022-50998
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2023-54354
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2025-71346
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2025-71406
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-79769
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-79770
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-80049
airbyte-platform
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-77357
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-62865
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-63403
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-56703
Product identification pending PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-72696
Product identification pending PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-78675
Product identification pending PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-78685
Product identification pending
Reporter: TWCERT
8.6
HIGH
VIEW RECORD
CVE-2026-12878
Product identification pending
Reporter: SECURITY
8.6
HIGH
VIEW RECORD
CVE-2026-55534
PraisonAI PATCH
Reporter: SECURITY-ADVISORIES
8.6
HIGH
VIEW RECORD
CVE-2026-55539
PraisonAI PATCH
Reporter: SECURITY-ADVISORIES
8.6
HIGH
VIEW RECORD
CVE-2026-55580
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.6
HIGH
VIEW RECORD
CVE-2026-79784
vocos
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-55557
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.6
HIGH
VIEW RECORD
CVE-2026-75496
Product identification pending PATCH
Reporter: 9119A7D8-5EAB-497F-8521-727C672E3725
8.6
HIGH
VIEW RECORD
CVE-2026-75497
QloApps PATCH
Reporter: 9119A7D8-5EAB-497F-8521-727C672E3725
8.6
HIGH
VIEW RECORD
CVE-2026-75498
QloApps PATCH
Reporter: 9119A7D8-5EAB-497F-8521-727C672E3725
8.6
HIGH
VIEW RECORD
CVE-2026-78680
Product identification pending PATCH
Reporter: DISCLOSURE
8.5
HIGH
VIEW RECORD
CVE-2026-66109
SKYSEA Client View
Reporter: VULTURES
8.5
HIGH
VIEW RECORD

About the Vulnerability Pulse CVE Feed

The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.

How to Use the CVE Advisory Tracker

Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.

What Is a CVE Advisory?

A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.

CVE Analysis & Writeups

For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.