12 findings
SLA breaches are highlighted. Data is synthetic; synthetic vulnerability identifiers, not real CVEs.
| ID | Identifier | Title | Severity | CVSS | Affected assets | Status | Discovered | Owner | SLA due |
|---|---|---|---|---|---|---|---|---|---|
| VLN-2001 | SYN-2026-10041 | Remote code execution in HTTP parsing library | critical | 9.8 | AST-1001, AST-1002, AST-1015 | in progress | 2026-08-04 | Platform Engineering | 2026-08-11 · breached |
| VLN-2002 | SYN-2026-10188 | Privilege escalation via unsafe setuid helper | critical | 9.1 | AST-1004 | open | 2026-08-07 | Data Platform | 2026-08-14 |
| VLN-2003 | SYN-2026-10222 | Authentication bypass in session refresh flow | critical | 8.9 | AST-1003 | in progress | 2026-08-08 | Identity Services | 2026-08-15 |
| VLN-2004 | SYN-2026-10310 | Improper certificate validation in outbound client | high | 7.9 | AST-1006, AST-1015 | open | 2026-08-05 | Cloud Operations | 2026-08-19 |
| VLN-2005 | SYN-2026-10388 | Stored cross-site scripting in reporting console | high | 7.4 | AST-1011 | in progress | 2026-08-02 | Analytics | 2026-08-16 |
| VLN-2006 | SYN-2026-10402 | Excessive IAM permissions on deployment role | high | 7.2 | AST-1007 | mitigated | 2026-07-28 | DevSecOps | 2026-08-11 |
| VLN-2007 | SYN-2026-10455 | Outdated TLS cipher suites enabled on edge listener | medium | 6.1 | AST-1001, AST-1002 | open | 2026-08-09 | Network Security | 2026-08-30 |
| VLN-2008 | SYN-2026-10501 | Verbose error responses leak stack traces | medium | 5.4 | AST-1015 | in progress | 2026-08-03 | Platform Engineering | 2026-08-24 |
| VLN-2009 | SYN-2026-10577 | Missing rate limiting on password reset endpoint | medium | 5.9 | AST-1003 | open | 2026-08-10 | Identity Services | 2026-09-01 |
| VLN-2010 | SYN-2026-10611 | Unencrypted local diagnostic cache | low | 3.3 | AST-1009, AST-1010 | accepted | 2026-07-21 | Security Operations | 2026-09-15 |
| VLN-2011 | SYN-2026-10644 | Deprecated dependency with no known exploit path | low | 2.8 | AST-1014 | open | 2026-08-06 | Engineering Enablement | 2026-09-20 |
| VLN-2012 | SYN-2026-10702 | Secrets proxy audit logging gap under load | high | 7.6 | AST-1013 | open | 2026-08-11 | Security Engineering | 2026-08-25 |