CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-68872

mediumCVSS 6.5covered by 2 sourcesfirst seen 2026-08-10
A remote authenticated attacker can exploit multiple vulnerabilities in Apache Airflow to disclose information.

CSIRTS triage

What
Remote authenticated attacker can disclose sensitive information through multiple vulnerabilities in Apache Airflow Provider.
Who is affected
Deployments of Apache Airflow Provider are affected.
Urgency
Medium; requires authentication and limited to information disclosure.
Action
Update Apache Airflow Provider to a patched version.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-68872

Get an email if CVE-2026-68872 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-68872

CVE.org record

Embed the live status

CVE-2026-68872 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-68872 status](https://www.csirts.com/badge/CVE-2026-68872)](https://www.csirts.com/cve/CVE-2026-68872)