Complete feed
Recently updated
Advisories the vendor has revised
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-48120] Remote Code Execution via malicious backup files
Remote Code Execution via malicious backup files. Red Hat rates this important (CVSS 8.6). Weakness: CWE-94.
High [CVE-2026-11425] Stored cross-site scripting allows administrator account takeover
Stored cross-site scripting allows administrator account takeover. Red Hat rates this important (CVSS 7.7). Weakness: CWE-79.
High [CVE-2026-19113] Unauthenticated denial of service via unbounded request body processing
Unauthenticated denial of service via unbounded request body processing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-15972] Denial of Service via unbounded external gRPC connection acceptance
Denial of Service via unbounded external gRPC connection acceptance. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat package: grafana.
High [CVE-2026-65819] Remote Denial of Service via crafted packet processing
Remote Denial of Service via crafted packet processing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-805.
High [CVE-2026-19015] Uncontrolled resource consumption leading to denial of service
Uncontrolled resource consumption leading to denial of service. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-71556] Arbitrary file read/write via symbolic link resolution
Arbitrary file read/write via symbolic link resolution. Red Hat rates this important (CVSS 7.1). Weakness: CWE-59. Affected products named by the advisory: Multicluster Engine for Kubernetes; Red Hat Advanced Cluster Management for Kubernetes 2.
High [CVE-2026-15816] root code execution via unescaped error message written to sourced emergency hook script in die
root code execution via unescaped error message written to sourced emergency hook script in die(). Red Hat rates this important (CVSS 7.5). Weakness: CWE-78. Red Hat lists fixing advisory RHSA-2026:54575 with package dracut-0:057-54.git20250423.el9_4.3, dracut-0:057-25.git20250717.el9_2.2, dracut-0:057-89.git20250311.el9_6.1, dracut-0:105-4.el10_0.1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8. Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.8 Telecommunications Update Service; Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; and 5 more.
High [CVE-2025-63235] codepr sol: Sol: Denial of service via resource exhaustion from malformed CONNECT packets
codepr sol: Sol: Denial of service via resource exhaustion from malformed CONNECT packets. Red Hat rates this important (CVSS 7.5). Weakness: CWE-772.
Medium [CVE-2026-46405] Denial of Service from unaccessible token accumulation in Kerberos authentication.
Denial of Service from unaccessible token accumulation in Kerberos authentication. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-770.
Medium [CVE-2026-46358] Authentication material disclosure via incorrect audit log redaction
Authentication material disclosure via incorrect audit log redaction. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-312.
Medium [CVE-2026-71870] Denial of Service via crafted PDF with large /ToUnicode streams
Denial of Service via crafted PDF with large /ToUnicode streams. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-770.
Medium [CVE-2026-15970] Authorization bypass via custom public listener
Authorization bypass via custom public listener. Red Hat rates this moderate (CVSS 4.2). Weakness: CWE-551. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat package: grafana.
Medium [CVE-2026-19017] Sensitive secret exfiltration via partial arbitrary file read
Sensitive secret exfiltration via partial arbitrary file read. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat package: grafana.
Medium [CVE-2026-19014] Denial of Service via uncontrolled resource consumption in Connect authorization endpoint
Denial of Service via uncontrolled resource consumption in Connect authorization endpoint. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat package: grafana.
Medium [CVE-2026-19012] Authenticated denial of service via configuration entry
Authenticated denial of service via configuration entry. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-15. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat package: grafana.
Medium [CVE-2026-19016] Authorization bypass allows arbitrary session deletion via transaction API
Authorization bypass allows arbitrary session deletion via transaction API. Red Hat rates this moderate (CVSS 4.2). Weakness: CWE-639. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat package: grafana.
Medium [CVE-2026-71852] Denial of Service via crafted PDF with large CID font width ranges
Denial of Service via crafted PDF with large CID font width ranges. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1050.
Medium [CVE-2026-18938] Integer overflow in RPC attribute-array length calculation can under-allocate nested attribute storage on 32 bit systems
Integer overflow in RPC attribute-array length calculation can under-allocate nested attribute storage on 32 bit systems. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-122.
Medium [CVE-2026-12261] Resource poisoning via improper package archive extraction
Resource poisoning via improper package archive extraction. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-367. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 1 more. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI).