Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

2765 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.5Red Hat

High [CVE-2026-71217] iperf3 server accepts unbounded peer-controlled JSON parameters enabling remote denial of service via resource exhaustion

iperf3 server accepts unbounded peer-controlled JSON parameters enabling remote denial of service via resource exhaustion. Red Hat rates this important (CVSS 7.5). Weakness: CWE-20. Red Hat lists fixing advisory RHSA-2026:61680 with package iperf3-0:3.17.1-6.el10_2.1, iperf3-0:3.9-17.el9_8.1, iperf3-0:3.5-12.el8_10.1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-71217
Unclassified
Aug 11, 2026
High7.5Red Hat

High [CVE-2026-15567] Pre-auth denial of service on the IIOP listener

Pre-auth denial of service on the IIOP listener. Red Hat rates this important (CVSS 7.5). Red Hat lists fixing advisory RHSA-2026:53806. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 8.

CVE-2026-15567
Unclassified
Aug 11, 2026
High7.5Red Hat

High [CVE-2026-15565] Pre-Auth DoS on websocket endpoint with @ServerEndpoint class with any @OnMessage method

Pre-Auth DoS on websocket endpoint with @ServerEndpoint class with any @OnMessage method. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120. Red Hat lists fixing advisory RHSA-2026:53806. Affected products named by the advisory: Red Hat build of Apache Camel for Spring Boot 4; Red Hat Data Grid 8; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 8.

CVE-2026-15565
Unclassified
Aug 11, 2026
High7.4Red Hat

High [CVE-2026-15563] Missing authentication on EAP's IIOP NameService leads to MITM or DoS

Missing authentication on EAP's IIOP NameService leads to MITM or DoS. Red Hat rates this important (CVSS 7.4). Weakness: CWE-306. Red Hat lists fixing advisory RHSA-2026:53806 with package eap7-ironjacamar-0:1.5.26-2.Final_redhat_00001.1.el7eap, eap7-undertow-0:2.2.40-2.SP3_redhat_00001.1.el7eap, eap7-wildfly-0:7.4.25-2.GA_redhat_00001.1.el7eap, eap7-netty-0:4.1.135-1.Final_redhat_00001.1.el7eap. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7; Red Hat JBoss Enterprise Application Platform 8. Affected products named by the advisory: Red Hat Fuse 7; Red Hat Single Sign-On 7.

CVE-2026-15563
Unclassified
Aug 11, 2026
High7.5Red Hat

High [CVE-2026-15562] integer overflow in MessageReader leads to pre-authentication denial of service

integer overflow in MessageReader leads to pre-authentication denial of service. Red Hat rates this important (CVSS 7.5). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:53806 with package eap7-ironjacamar-0:1.5.26-2.Final_redhat_00001.1.el7eap, eap7-undertow-0:2.2.40-2.SP3_redhat_00001.1.el7eap, eap7-wildfly-0:7.4.25-2.GA_redhat_00001.1.el7eap, eap7-netty-0:4.1.135-1.Final_redhat_00001.1.el7eap. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7; Red Hat JBoss Enterprise Application Platform 8.

CVE-2026-15562
Unclassified
Aug 11, 2026
High7.5Red Hat

High [CVE-2026-15561] OOM via missing limits in chunked trailer in EAP's Undertow

OOM via missing limits in chunked trailer in EAP's Undertow. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:53806 with package eap7-ironjacamar-0:1.5.26-2.Final_redhat_00001.1.el7eap, eap7-undertow-0:2.2.40-2.SP3_redhat_00001.1.el7eap, eap7-wildfly-0:7.4.25-2.GA_redhat_00001.1.el7eap, eap7-netty-0:4.1.135-1.Final_redhat_00001.1.el7eap. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7; Red Hat JBoss Enterprise Application Platform 8.

CVE-2026-15561
Unclassified
Aug 11, 2026
High8.1Red Hat

High [CVE-2026-15560] unauthed class loading via IIOP in EAP

unauthed class loading via IIOP in EAP. Red Hat rates this important (CVSS 8.1). Weakness: CWE-829. Red Hat lists fixing advisory RHSA-2026:53806 with package eap7-ironjacamar-0:1.5.26-2.Final_redhat_00001.1.el7eap, eap7-undertow-0:2.2.40-2.SP3_redhat_00001.1.el7eap, eap7-wildfly-0:7.4.25-2.GA_redhat_00001.1.el7eap, openjdk-orb. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7; Red Hat JBoss Enterprise Application Platform 8.

CVE-2026-15560
Unclassified
Aug 11, 2026
High8.1Red Hat

High [CVE-2026-15556] picketlink SAML 2.0 auth bypass via missing assertions

picketlink SAML 2.0 auth bypass via missing assertions. Red Hat rates this important (CVSS 8.1). Weakness: CWE-347. Red Hat lists fixing advisory RHSA-2026:53806 with package eap7-ironjacamar-0:1.5.26-2.Final_redhat_00001.1.el7eap, eap7-undertow-0:2.2.40-2.SP3_redhat_00001.1.el7eap, eap7-wildfly-0:7.4.25-2.GA_redhat_00001.1.el7eap, eap7-netty-0:4.1.135-1.Final_redhat_00001.1.el7eap. Affected product named by the advisory: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7.

CVE-2026-15556
Unclassified
Aug 11, 2026
High8.8Red Hat

High [CVE-2026-15555] wildfly-clustering-infinispan-marshalling: Jboss Deserialization RCE via Unfiltered River Unmarshaller

wildfly-clustering-infinispan-marshalling: Jboss Deserialization RCE via Unfiltered River Unmarshaller. Red Hat rates this important (CVSS 8.8). Weakness: CWE-502. Red Hat lists fixing advisory RHSA-2026:53806 with package eap7-ironjacamar-0:1.5.26-2.Final_redhat_00001.1.el7eap, eap7-undertow-0:2.2.40-2.SP3_redhat_00001.1.el7eap, eap7-wildfly-0:7.4.25-2.GA_redhat_00001.1.el7eap, eap7-netty-0:4.1.135-1.Final_redhat_00001.1.el7eap. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack.

CVE-2026-15555
Unclassified
Aug 11, 2026
High7.4Red Hat

High [CVE-2026-15554] Authentication Bypass via AJP ssl_cert/is_ssl Forgery

Authentication Bypass via AJP ssl_cert/is_ssl Forgery. Red Hat rates this important (CVSS 7.4). Weakness: CWE-295. Red Hat lists fixing advisory RHSA-2026:53806 with package eap7-ironjacamar-0:1.5.26-2.Final_redhat_00001.1.el7eap, eap7-undertow-0:2.2.40-2.SP3_redhat_00001.1.el7eap, eap7-wildfly-0:7.4.25-2.GA_redhat_00001.1.el7eap, eap7-netty-0:4.1.135-1.Final_redhat_00001.1.el7eap. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7; Red Hat JBoss Enterprise Application Platform 8.

CVE-2026-15554
Unclassified
Aug 11, 2026
High7.8Vendor: MediumRed Hat

High [CVE-2026-72693] Local privilege escalation in openvt via incorrect process owner verification allowing passwordless root login

Local privilege escalation in openvt via incorrect process owner verification allowing passwordless root login. Red Hat rates this moderate (CVSS 7.8). Weakness: CWE-284. Red Hat lists fixing advisory RHSA-2026:41136 with package kbd-0:2.4.0-12.el9_8, kbd-0:2.6.4-8.el10_2, kbd-main-2.10.0-2.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat OpenShift Container Platform 4.22.

CVE-2026-72693
Unclassified
Aug 11, 2026
High7.1Red Hat

High [CVE-2026-72694] MRTG daemon symlink-following chown allows local privilege escalation via PID file path manipulation

MRTG daemon symlink-following chown allows local privilege escalation via PID file path manipulation. Red Hat rates this important (CVSS 7.1). Weakness: CWE-59. Red Hat lists fixing advisory RHSA-2026:57596 with package mrtg-0:2.17.10-12.el10_2.1, mrtg-0:2.17.7-12.el9_8.1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9.

CVE-2026-72694
Unclassified
Aug 11, 2026
High7.2Red Hat

High [CVE-2026-4757] Code execution and privilege escalation via VAPIX API improper input validation

Code execution and privilege escalation via VAPIX API improper input validation. Red Hat rates this important (CVSS 7.2). Weakness: CWE-94. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat package: axis.

CVE-2026-4757
Red Hat Enterprise Linux
Aug 11, 2026
High8.5Red Hat

High [CVE-2026-66797] Velero Restore includes cluster-scoped RBAC resources with no exclusion — tampered backup yields hub cluster-admin

Velero Restore includes cluster-scoped RBAC resources with no exclusion — tampered backup yields hub cluster-admin. Red Hat rates this important (CVSS 8.5). Weakness: CWE-862. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/cluster-backup-rhel9-operator:1787684668, rhacm2/cluster-backup-rhel9-operator:1787238500, rhacm2/cluster-backup-rhel9-operator:1787227576, rhacm2/cluster-backup-rhel9-operator:1787183178. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-66797
Unclassified
Aug 11, 2026
High8.8Red Hat

High [CVE-2026-66798] Restore.spec.hooks passed verbatim to Velero Restore — arbitrary command execution in restored pods

Restore.spec.hooks passed verbatim to Velero Restore — arbitrary command execution in restored pods. Red Hat rates this important (CVSS 8.8). Weakness: CWE-77. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/cluster-backup-rhel9-operator:1787684668, rhacm2/cluster-backup-rhel9-operator:1787238500, rhacm2/cluster-backup-rhel9-operator:1787227576, rhacm2/cluster-backup-rhel9-operator:1787183178. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-66798
Unclassified
Aug 11, 2026
High7.1Red Hat

High [CVE-2026-66799] Restore.spec.namespaceMapping pass-through enables cross-namespace Secret/ConfigMap placement

Restore.spec.namespaceMapping pass-through enables cross-namespace Secret/ConfigMap placement. Red Hat rates this important (CVSS 7.1). Weakness: CWE-863. Red Hat lists fixing advisory RHSA-2026:60390 with package rhacm2/cluster-backup-rhel9-operator:1787238500, rhacm2/cluster-backup-rhel9-operator:1787227576, rhacm2/cluster-backup-rhel9-operator:1787183178, rhacm2/cluster-backup-rhel9-operator:1787259060. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-66799
Unclassified
Aug 11, 2026
High7.1Red Hat

High [CVE-2026-66800] CleanupAll triggers unguarded cluster-wide mass-delete via operator ServiceAccount

CleanupAll triggers unguarded cluster-wide mass-delete via operator ServiceAccount. Red Hat rates this important (CVSS 7.1). Weakness: CWE-862. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/cluster-backup-rhel9-operator:1787684668, rhacm2/cluster-backup-rhel9-operator:1787238500, rhacm2/cluster-backup-rhel9-operator:1787227576, rhacm2/cluster-backup-rhel9-operator:1787183178. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-66800
Unclassified
Aug 11, 2026
High7.5Red Hat

High [CVE-2026-62901] .NET:.NET Denial of Service Vulnerability

.NET:.NET Denial of Service Vulnerability. Red Hat rates this important (CVSS 7.5). Weakness: CWE-606. Red Hat lists fixing advisory RHSA-2026:54542 with package dotnet8-0-main-8.0.130-0.1.hum1, dotnet8.0-0:8.0.130-1.el8_10, dotnet9.0-0:9.0.120-1.el9_6, dotnet10.0-0:10.0.111-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.

CVE-2026-62901
Unclassified
Aug 11, 2026
High7.8Red Hat

High [CVE-2026-62909] .NET:.NET Elevation of Privilege Vulnerability

.NET:.NET Elevation of Privilege Vulnerability. Red Hat rates this important (CVSS 7.8). Weakness: CWE-252. Red Hat lists fixing advisory RHSA-2026:54542 with package dotnet8-0-main-8.0.130-0.1.hum1, dotnet8.0-0:8.0.130-1.el8_10, dotnet9.0-0:9.0.120-1.el9_6, dotnet10.0-0:10.0.111-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.

CVE-2026-62909
Unclassified
Aug 11, 2026
High7.1Red Hat

High [CVE-2026-73266] tenant-controlled ClusterClaim labels propagated to ManagedCluster enabling cross-tenant ManagedClusterSet join

tenant-controlled ClusterClaim labels propagated to ManagedCluster enabling cross-tenant ManagedClusterSet join. Red Hat rates this important (CVSS 7.1). Weakness: CWE-441. Red Hat lists fixing advisory RHSA-2026:59593 with package multicluster-engine/clusterclaims-controller-rhel9:1787259112, multicluster-engine/clusterclaims-controller-rhel9:1786577950, multicluster-engine/clusterclaims-controller-rhel9:1787239442, multicluster-engine/clusterclaims-controller-rhel9:1787259059. Affected product named by the advisory: Multicluster Engine for Kubernetes.

CVE-2026-73266
Unclassified
Aug 11, 2026