Complete feed
Security advisories & CVEs
2765 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-73267] ManagedCluster deletion keyed solely on ClusterClaim.Spec.Namespace with no ownership check
ManagedCluster deletion keyed solely on ClusterClaim. Spec. Namespace with no ownership check. Red Hat rates this important (CVSS 7.7). Weakness: CWE-602. Red Hat lists fixing advisory RHSA-2026:59593 with package multicluster-engine/clusterclaims-controller-rhel9:1787259112, multicluster-engine/clusterclaims-controller-rhel9:1786577950, multicluster-engine/clusterclaims-controller-rhel9:1787239442, multicluster-engine/clusterclaims-controller-rhel9:1787259059. Affected products named by the advisory: multicluster engine for Kubernetes 2.10; multicluster engine for Kubernetes 2.11; multicluster engine for Kubernetes 2.17; multicluster engine for Kubernetes 2.6; and 2 more. Affected products named by the advisory: multicluster engine for Kubernetes 2.8; multicluster engine for Kubernetes 2.9.
Medium [CVE-2026-18710] Credential disclosure via cleartext logging during client initialization
Credential disclosure via cleartext logging during client initialization. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-312. Affected products named by the advisory: Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Debezium 3; Red Hat build of Quarkus.
Medium [CVE-2026-73242] Out-of-bounds memory access in Kerberos decryption
Out-of-bounds memory access in Kerberos decryption. Red Hat rates this moderate (CVSS 6.4). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:61378 with package freerdp-2:3.10.3-12.el10_2.10. Affected product named by the advisory: Red Hat Enterprise Linux 10.
Medium [CVE-2026-71474] Pull-secret bearer token written to logs on non-200 CCX response
Pull-secret bearer token written to logs on non-200 CCX response. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-532. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/insights-client-rhel9:1787227689, rhacm2/insights-client-rhel9:1787184541, rhacm2/insights-client-rhel9:1787688993, rhacm2/insights-client-rhel9:1787259125. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.
Medium [CVE-2026-71468] Cross-user bearer-token reuse via global federation-config cache
Cross-user bearer-token reuse via global federation-config cache. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-266. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/acm-search-v2-api-rhel9:1787191668, rhacm2/acm-search-v2-api-rhel9:1787263804, rhacm2/acm-search-v2-api-rhel9:1787238618, rhacm2/acm-search-v2-api-rhel9:1787229541. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.
Medium [CVE-2026-71475] Spoke-controlled ClusterID injected unencoded into Insights API URL path
Spoke-controlled ClusterID injected unencoded into Insights API URL path. Red Hat rates this moderate (CVSS 5). Weakness: CWE-22. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/insights-client-rhel9:1787227689, rhacm2/insights-client-rhel9:1787184541, rhacm2/insights-client-rhel9:1787259125, rhacm2/insights-client-rhel9:1787238585. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat Advanced Cluster Management for Kubernetes 2.16; and 1 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.17.
Medium [CVE-2026-71845] CCX_TOKEN bearer credential logged in clear text at startup via setDefault
CCX_TOKEN bearer credential logged in clear text at startup via setDefault(). Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-532. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/insights-client-rhel9:1787227689, rhacm2/insights-client-rhel9:1787184541, rhacm2/insights-client-rhel9:1787688993, rhacm2/insights-client-rhel9:1787259125. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.
Medium [CVE-2026-73283] Tunnel forwarding restriction bypass
Tunnel forwarding restriction bypass. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-305. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat package: openssh.
Medium [CVE-2026-73282] Information disclosure and data corruption via use-after-free in ssh client
Information disclosure and data corruption via use-after-free in ssh client. Red Hat rates this moderate (CVSS 5.6). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat package: openssh.
Medium [CVE-2026-73229] Django REST framework: Information disclosure via improper permission checks in AdminRenderer
Django REST framework: Information disclosure via improper permission checks in AdminRenderer. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-425. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Discovery 2; Red Hat Satellite 6; Red Hat Update Infrastructure 4 for Cloud Providers; and 1 more. Affected products named by the advisory: Red Hat Update Infrastructure 5.
Medium [CVE-2026-73228] Django REST framework: Denial of Service via oversized request bodies
Django REST framework: Denial of Service via oversized request bodies. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-770. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Discovery 2; Red Hat Satellite 6; Red Hat Update Infrastructure 4 for Cloud Providers; and 1 more. Affected products named by the advisory: Red Hat Update Infrastructure 5.
Medium [CVE-2026-73216] Authenticated client can exhaust relay capacity via quota bypass
Authenticated client can exhaust relay capacity via quota bypass. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-911.
Medium [CVE-2026-73215] Denial of Service due to incorrect port allocation
Denial of Service due to incorrect port allocation. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-772.
Medium [CVE-2026-72712] Denial of Service via zero-length TCP option packet
Denial of Service via zero-length TCP option packet. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-835. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: nmap.
Medium [CVE-2026-62902] .NET: Information Disclosure Vulnerability
Inclusion of functionality from untrusted control sphere in.NET allows an unauthorized attacker to disclose information over a network. A flaw was found in.NET. The issue arises from the inclusion of functionality from an untrusted control sphere, which can be exploited to reveal data. Red Hat has determined that shipped versions of.NET in Red Hat products already include the fix for this vulnerability. The.NET 8.0 (8.0.30), 9.0 (9.0.19), and 10.0 (10.0.11) runtime fix versions are included in current Red Hat packages. Furthermore, the upstream advisory identifies only Microsoft. WindowsDesktop. App.Runtime (Windows Desktop) packages as vulnerable — a component not present in Red Hat's Linux.NET builds. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N). Weakness: CWE-829. Affected Red Hat products: Red Hat Hardened Images. Red Hat fixing advisory: RHSA-2026:44914, RHSA-2026:55405.
Medium [CVE-2026-32791] Escalation of Privilege via Untrusted Search Path
Escalation of Privilege via Untrusted Search Path. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-426. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: pcm.
Medium [CVE-2025-31936] Privilege escalation via improper memory range handling in SMM
Privilege escalation via improper memory range handling in SMM. Red Hat rates this moderate (CVSS 5.7). Weakness: CWE-823. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: microcode_ctl.
Medium [CVE-2026-21399] Intel Open Volume Kernel Library: Intel Open Volume Kernel Library: Denial of Service via heap-based buffer overflow
Intel Open Volume Kernel Library: Intel Open Volume Kernel Library: Denial of Service via heap-based buffer overflow. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-120.
Medium [CVE-2026-20908] Intel NPU Driver for Windows: Denial of Service via time-of-check time-of-use race condition
Intel NPU Driver for Windows: Denial of Service via time-of-check time-of-use race condition. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-367.
Medium [CVE-2026-20786] Denial of service via out-of-bounds read
Denial of service via out-of-bounds read. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-125.