Complete feed
Recently updated
Advisories the vendor has revised
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-66149 +1] Email Security: Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an aut…
Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via netmask.
High [CVE-2026-19550] trust-fetch-domains uses trust-read ACI to gate a privileged AD trust refresh, allowing unauthorized LDAP writes
trust-fetch-domains uses trust-read ACI to gate a privileged AD trust refresh, allowing unauthorized LDAP writes. Red Hat rates this important (CVSS 8.2). Weakness: CWE-863. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-71290] Server impersonation via improper TLS hostname verification
Server impersonation via improper TLS hostname verification. Red Hat rates this important (CVSS 8.1). Weakness: CWE-295.
High [CVE-2026-29035] Arbitrary code execution via crafted WebSocket frames
Arbitrary code execution via crafted WebSocket frames. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787.
High [CVE-2026-73241] Authentication bypass via incorrect RDSTLS PDU handling
Authentication bypass via incorrect RDSTLS PDU handling. Red Hat rates this important (CVSS 7.5). Weakness: CWE-287. Red Hat lists fixing advisory RHSA-2026:61378 with package freerdp-2:3.10.3-12.el10_2.10. Affected product named by the advisory: Red Hat Enterprise Linux 10.
High [CVE-2026-73231] @faker-js/faker: Faker: Arbitrary Code Execution via attacker-controlled fake templates
@faker-js/faker: Faker: Arbitrary Code Execution via attacker-controlled fake templates. Red Hat rates this important (CVSS 8.8). Weakness: CWE-94. Affected products named by the advisory: Cryostat 4; Red Hat AMQ Broker 7; Red Hat Build of Keycloak; Red Hat Enterprise Linux 10; and 4 more. Affected products named by the advisory: Red Hat Hardened Images; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat package: grafana.
High [CVE-2026-71467] Authentication bypass on /federated via Upgrade: websocket header spoofing
Authentication bypass on /federated via Upgrade: websocket header spoofing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-287. Red Hat lists fixing advisory RHSA-2026:60386 with package rhacm2/acm-search-v2-api-rhel9:1787229541. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.17.
High [CVE-2026-48804] Denial of Service via binary attachment accumulation
Denial of Service via binary attachment accumulation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-73214] Denial of Service via unverified DTLS session state
Denial of Service via unverified DTLS session state. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-73212] Server-Side Request Forgery and Remote Code Execution via IP address canonicalization bypass
Server-Side Request Forgery and Remote Code Execution via IP address canonicalization bypass. Red Hat rates this important (CVSS 7.7). Weakness: CWE-1389.
High [CVE-2026-71331] Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability
Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025.
High [CVE-2026-70326] Microsoft SharePoint Server Elevation of Privilege Vulnerability
Microsoft SharePoint Server Elevation of Privilege Vulnerability Affected product named by the advisory: Microsoft SharePoint Server Subscription Edition.
High [CVE-2026-56179] Windows Network Address Translation (NAT) Spoofing Vulnerability
Windows Network Address Translation (NAT) Spoofing Vulnerability Affected product named by the advisory: Windows Server 2025.
High [CVE-2026-66808] Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability Affected products named by the advisory: Microsoft SharePoint Enterprise Server 2016; Microsoft SharePoint Server 2019; Microsoft SharePoint Server Subscription Edition.
High [CVE-2026-65790] Windows Message Queuing Elevation of Privilege Vulnerability
Windows Message Queuing Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.
High [CVE-2026-65776] Windows Win32k Elevation of Privilege Vulnerability
Windows Win32k Elevation of Privilege Vulnerability Affected product named by the advisory: Windows Server 2025.
High [CVE-2026-65775] Windows Win32k Elevation of Privilege Vulnerability
Windows Win32k Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.
High [CVE-2026-65774] Windows Installer Elevation of Privilege Vulnerability
Windows Installer Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.
High [CVE-2026-65773] Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025.
High [CVE-2026-65681] Windows iSCSI Target Service Denial of Service Vulnerability
Windows iSCSI Target Service Denial of Service Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016.