Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Product reference — Apache Airflow by Apache · sector: Open Source Ecosystems. Cumulative disclosure record for this product across the archive.
Follow Apache Airflow — Atom feed
| All-time | YTD | |
|---|---|---|
| CVEs | 36 | 36 |
| KEV entries | 0 | 0 |
| KEV/100 | Med CVSS | Med EPSS | C | H | M | L |
|---|---|---|---|---|---|---|
| 0.0 | 6.5 | .0041 | 2 | 10 | 22 | 2 |
KEV/100 = KEV entries ÷ CVEs × 100. Med CVSS / Med EPSS are medians over this product's disclosures. C/H/M/L = disclosures by CVSS severity band.
Trend (by first-seen month, full archive): ▁▁█▃▆
| Month | New CVEs |
|---|---|
| 2026-04 | 1 |
| 2026-05 | 0 |
| 2026-06 | 17 |
| 2026-07 | 6 |
| 2026-08 | 12 |
Ranked by the published formula: KEV → EPSS → CVSS → CVE ID.
| CVE | CVSS | EPSS %ile | Severity | KEV | First seen |
|---|---|---|---|---|---|
| CVE-2026-33264 | 9.8 | 59.8 | CRITICAL | — | 2026-07-07 |
| CVE-2026-67260 | 7.3 | 53.1 | HIGH | — | 2026-08-12 |
| CVE-2026-40861 | 6.5 | 50.0 | MEDIUM | — | 2026-06-01 |
| CVE-2026-45360 | 7.3 | 49.4 | HIGH | — | 2026-06-01 |
| CVE-2026-40961 | 7.2 | 48.3 | HIGH | — | 2026-06-01 |
| CVE-2026-67587 | 8.8 | 46.6 | HIGH | — | 2026-08-12 |
| CVE-2026-59242 | 5.4 | 45.4 | MEDIUM | — | 2026-08-12 |
| CVE-2025-54550 | 8.1 | 45.1 | HIGH | — | 2026-04-15 |
| CVE-2026-42359 | 8.8 | 44.7 | HIGH | — | 2026-06-01 |
| CVE-2026-49298 | 8.8 | 40.1 | HIGH | — | 2026-06-01 |
| CVE-2026-58076 | 8.8 | 39.8 | HIGH | — | 2026-08-12 |
| CVE-2026-40963 | 3.1 | 39.4 | LOW | — | 2026-06-01 |
| CVE-2026-41084 | 7.5 | 39.3 | HIGH | — | 2026-06-01 |
| CVE-2026-54183 | 4.3 | 38.7 | MEDIUM | — | 2026-08-12 |
| CVE-2026-45192 | 6.5 | 35.7 | MEDIUM | — | 2026-06-01 |
| CVE | CVSS | EPSS %ile | Severity | KEV | First seen |
|---|---|---|---|---|---|
| CVE-2026-68969 | 6.5 | 29.0 | MEDIUM | — | 2026-08-12 |
| CVE-2026-68968 | 7.5 | 34.9 | HIGH | — | 2026-08-12 |
| CVE-2026-59244 | 6.5 | 14.1 | MEDIUM | — | 2026-08-12 |
| CVE-2026-58076 | 8.8 | 39.8 | HIGH | — | 2026-08-12 |
| CVE-2026-68971 | 6.5 | 25.8 | MEDIUM | — | 2026-08-12 |
| CVE-2026-67587 | 8.8 | 46.6 | HIGH | — | 2026-08-12 |
| CVE-2026-65017 | 6.5 | 32.1 | MEDIUM | — | 2026-08-12 |
| CVE-2026-67260 | 7.3 | 53.1 | HIGH | — | 2026-08-12 |
| CVE-2026-54183 | 4.3 | 38.7 | MEDIUM | — | 2026-08-12 |
| CVE-2026-59242 | 5.4 | 45.4 | MEDIUM | — | 2026-08-12 |
| CVE-2026-68970 | 6.5 | 14.1 | MEDIUM | — | 2026-08-12 |
| CVE-2026-68076 | 5.4 | 27.4 | MEDIUM | — | 2026-08-12 |
| CVE-2026-49487 | 6.5 | 34.3 | MEDIUM | — | 2026-07-07 |
| CVE-2026-49296 | 6.5 | 33.3 | MEDIUM | — | 2026-07-07 |
| CVE-2026-48892 | 6.5 | 34.3 | MEDIUM | — | 2026-07-07 |
No entries in the CISA KEV catalog.
Vendor: Apache — all products and the full vendor record.
A product is a (vendor, product) pair as named in the affected-product data. Rate statistics are arithmetic over published figures. Counts key to first-seen day. Raw counts are not comparable across products; this is a reference page assembled from the public record, not a ranking by our judgment.
Sources. CVE Program (cvelistV5), NVD (NIST), CISA KEV, FIRST EPSS.