Complete feed
Security advisories & CVEs
2766 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-62899] .NET:.NET Core:.NET Security Feature Bypass Vulnerability
.NET:.NET Core:.NET Security Feature Bypass Vulnerability. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-444. Red Hat lists fixing advisory RHSA-2026:54542 with package dotnet8-0-main-8.0.130-0.1.hum1, dotnet8.0-0:8.0.130-1.el8_10, dotnet9.0-0:9.0.120-1.el9_6, dotnet10.0-0:10.0.111-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.
Medium [CVE-2026-62900] .NET:.NET Information Disclosure Vulnerability
.NET:.NET Information Disclosure Vulnerability. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-212. Red Hat lists fixing advisory RHSA-2026:54542 with package dotnet8-0-main-8.0.130-0.1.hum1, dotnet8.0-0:8.0.130-1.el8_10, dotnet9.0-0:9.0.120-1.el9_6, dotnet10.0-0:10.0.111-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.
Low [CVE-2026-73281] ssh-agent allows remote execution of local operations
ssh-agent allows remote execution of local operations. Red Hat rates this low (CVSS 3.5). Weakness: CWE-266. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: openssh.
Low [CVE-2026-73071] Denial of Service via Use-After-Free in JSON Decoding
Denial of Service via Use-After-Free in JSON Decoding. Red Hat rates this low (CVSS 3.3). Weakness: CWE-416.
Critical [CVE-2026-18948] Unsafe dill deserialization of registry-stored UDFs — RCE on feature server and registry server
Unsafe dill deserialization of registry-stored UDFs — RCE on feature server and registry server. Red Hat rates this critical (CVSS 9.9). Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-feature-server-rhel9:1787068065, rhoai/odh-feature-server-rhel9:1786110051, rhoai/odh-feature-server-rhel9:1786110033, rhoai/odh-feature-server-rhel9:1786107278. Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.4.
Critical [CVE-2026-14450] Privilege escalation via forged HTTP headers due to missing authentication
Privilege escalation via forged HTTP headers due to missing authentication. Red Hat rates this important (CVSS 9.9). Weakness: CWE-290. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-maas-api-rhel9:1785850409, rhoai/odh-maas-api-rhel9:1787153683. Affected product named by the advisory: Red Hat OpenShift AI 3.4.
Critical [CVE-2026-66801] shared Kafka gh-spec topic Write ACL plus spoofable CloudEvent source enables fleet-wide cluster-admin from any compromised managed hub
shared Kafka gh-spec topic Write ACL plus spoofable CloudEvent source enables fleet-wide cluster-admin from any compromised managed hub. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-290. Red Hat lists fixing advisory RHSA-2026:54577 with package multicluster-globalhub/multicluster-globalhub-rhel9-operator:1786621416, multicluster-globalhub/multicluster-globalhub-rhel9-operator:1786071343, multicluster-globalhub/multicluster-globalhub-rhel9-operator:1786067967, multicluster-globalhub/multicluster-globalhub-rhel9-operator:1785773214.
High [CVE-2026-66806] TLS verification disabled when sending hub pull-secret to console.redhat.com
TLS verification disabled when sending hub pull-secret to console.redhat.com. Red Hat rates this important (CVSS 7.4). Weakness: CWE-295. Red Hat lists fixing advisory RHSA-2026:59579 with package multicluster-engine/console-mce-rhel9:1787264250, rhacm2/console-rhel9:1787687062. Affected products named by the advisory: Multicluster Engine for Kubernetes; Red Hat Advanced Cluster Management for Kubernetes 2.
High [CVE-2026-72913] Arbitrary Code Execution via Chained DCS Escape Sequences
Arbitrary Code Execution via Chained DCS Escape Sequences. Red Hat rates this important (CVSS 7.8). Weakness: CWE-78. Affected products named by the advisory: External Secrets Operator for Red Hat OpenShift; Logging Subsystem for Red Hat OpenShift; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: gvisor-tap-vsock.
High [CVE-2026-63622] swtpm privilege escalation via symlink following
swtpm privilege escalation via symlink following. Red Hat rates this important (CVSS 7.8). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux for NVIDIA 26; Red Hat package: libvirt.
High [CVE-2026-18982] RHOAI fork aggregates training job create onto native edit/admin ClusterRoles
RHOAI fork aggregates training job create onto native edit/admin ClusterRoles. Red Hat rates this critical (CVSS 8.8). Weakness: CWE-250. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-training-operator-rhel9:1787361677, rhoai/odh-training-operator-rhel9:1784814352, rhoai/odh-training-operator-rhel9:1785187053, rhoai/odh-training-operator-rhel9:1785188461. Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.4.
High [CVE-2026-18951] [Trainer v2 Security] TRN-02: RHOAI overlay aggregates trainjobs CRUD into standard edit ClusterRole
[Trainer v2 Security] TRN-02: RHOAI overlay aggregates trainjobs CRUD into standard edit ClusterRole. Red Hat rates this critical (CVSS 8.8). Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-training-operator-rhel9:1787361677, rhoai/odh-training-operator-rhel9:1784814352, rhoai/odh-training-operator-rhel9:1785188461. Affected products named by the advisory: Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.4.
High [CVE-2026-18950] Confused-deputy privilege escalation via unchecked roleRef in RoleBinding creation
Confused-deputy privilege escalation via unchecked roleRef in RoleBinding creation. Red Hat rates this critical (CVSS 8.8). Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-dashboard-rhel9:1786109665, rhoai/odh-dashboard-rhel9:1785940823, rhoai/odh-dashboard-rhel9:1786109683. Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.4.
High [CVE-2026-18949] ClusterRole grants cluster-wide CRUD on secrets and RBAC management resources
ClusterRole grants cluster-wide CRUD on secrets and RBAC management resources. Red Hat rates this critical (CVSS 8.8). Weakness: CWE-250. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-dashboard-rhel9:1786109665, rhoai/odh-dashboard-rhel9:1785940823, rhoai/odh-dashboard-rhel9:1786109683. Affected products named by the advisory: Red Hat OpenShift AI 3.3; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-18947] Authorization bypass in /materialize endpoints enables DoS via unauthorized full re-materialization
Authorization bypass in /materialize endpoints enables DoS via unauthorized full re-materialization. Red Hat rates this important (CVSS 8.5). Red Hat lists fixing advisory RHSA-2026:53263 with package rhoai/odh-feature-server-rhel9:1786110051, rhoai/odh-feature-server-rhel9:1786110033. Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3.
High [CVE-2026-18941] Default authentication mode is no_auth — shared multi-tenant instances deployed without authentication
Default authentication mode is no_auth — shared multi-tenant instances deployed without authentication. Red Hat rates this important (CVSS 7.7). Weakness: CWE-306. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-feature-server-rhel9:1786110051, rhoai/odh-feature-server-rhel9:1786110033, rhoai/odh-feature-server-rhel9:1786107278. Affected products named by the advisory: Red Hat OpenShift AI 3.3; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.4.
High [CVE-2026-15581] TAS internal Service bypasses kube-rbac-proxy, exposing unauthenticated Quarkus API cluster-wide
TAS internal Service bypasses kube-rbac-proxy, exposing unauthenticated Quarkus API cluster-wide. Red Hat rates this important (CVSS 8). Weakness: CWE-306. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-trustyai-service-operator-rhel9:1784993206, rhoai/odh-trustyai-service-operator-rhel9:1786614608, rhoai/odh-trustyai-service-operator-rhel9:1785187521, rhoai/odh-trustyai-service-operator-rhel9:1785187119. Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.4.
High [CVE-2026-15467] LMEvalJob sidecar containers bypass protected environment variable filtering, allowing TRUST_REMOTE_CODE policy override
LMEvalJob sidecar containers bypass protected environment variable filtering, allowing TRUST_REMOTE_CODE policy override. Red Hat rates this important (CVSS 8.1). Weakness: CWE-266. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-trustyai-service-operator-rhel9:1784993206, rhoai/odh-trustyai-service-operator-rhel9:1786614608, rhoai/odh-trustyai-service-operator-rhel9:1785187521, rhoai/odh-trustyai-service-operator-rhel9:1785187119. Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.4.
High [CVE-2026-13717] MaaS/llm-d inference Gateway: default allowedRoutes.namespaces.from: All allows namespace users to hijack shared model-serving traffic (tokens, prompts, outputs)
MaaS/llm-d inference Gateway: default allowedRoutes.namespaces.from: All allows namespace users to hijack shared model-serving traffic (tokens, prompts, outputs). Red Hat rates this important (CVSS 8.8). Weakness: CWE-284. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-rhel9-operator:1786123541, rhoai/odh-maas-controller-rhel9:1787153684. Affected products named by the advisory: Red Hat OpenShift AI 3.4; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-66805] stored DOM XSS via unescaped pod logs in document.write
stored DOM XSS via unescaped pod logs in document.write. Red Hat rates this important (CVSS 8). Weakness: CWE-79. Red Hat lists fixing advisory RHSA-2026:54432 with package multicluster-engine/console-mce-rhel9:1787079359, rhacm2/console-rhel9:1787339248, multicluster-engine/console-mce-rhel9:1787264250, rhacm2/console-rhel9:1787339213.