CVE Tools

Tooling

12 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Tooling, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.

Tooling CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Tooling CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-021
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-111
2025-120
2026-010
2026-020
2026-030
2026-041
2026-051
2026-060
2026-076
2026-081
2026-091

Severity

How the 12 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical325%
  • High758%
  • Medium217%

Latest CVEs

The 12 most recently published vulnerabilities affecting Tooling.

  1. CVE-2026-87993Consul-template vulnerable to an information disclosure issue in error handling7.7
  2. CVE-2026-8715Vault Secrets Operator vulnerable to arbitrary file read and credential exfiltration via AppRole secretIDPath9.6
  3. CVE-2026-16326consul-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode10.0
  4. CVE-2026-16328consul-mcp-server vulnerable to server side request forgery leading to token exposure8.6
  5. CVE-2026-16498terraform-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode10.0
  6. CVE-2026-16496terraform-mcp-server vulnerable to cross-user credential inheritance if an MCP session ID is obtained by another user8.9
  7. CVE-2026-14869terraform-mcp-server vulnerable to server side request forgery leading to token exposure8.6
  8. CVE-2026-14361Consul-template is vulnerable to path redirection in writeToFile through symlink attack4.7
  9. CVE-2026-5061Consul-template vulnerable to sandbox path bypass in file helper via a symlink attack4.7
  10. CVE-2026-4660Go-getter may allow to arbitrary filesystem reads through git operations7.5
  11. CVE-2025-13357Vault Terraform Provider Applied Incorrect Defaults for LDAP Auth Method7.4
  12. CVE-2025-1293HashiCorp Hermes Improperly Validates AWS ALB JWTs, which May Lead to Authentication Bypass8.2

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store