Complete feed
Security advisories & CVEs
3463 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-13097] Privilege escalation via krbCanonicalName manipulation due to realm-unaware uniqueness enforcement in FreeIPA LDAP datastore
Privilege escalation via krbCanonicalName manipulation due to realm-unaware uniqueness enforcement in FreeIPA LDAP datastore. Red Hat rates this important (CVSS 8.7). Weakness: CWE-706. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-73197] Unauthenticated DoS in `/ipa/migration/migration.py` via Unbounded Request Body Read
Unauthenticated DoS in `/ipa/migration/migration.py` via Unbounded Request Body Read. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-18917] Libvirt: integer overflow in nodegetfreepages rpc handler leading to heap buffer overflow
A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This flaw allows crafted values to bypass a size check, leading to an undersized memory buffer. Subsequently, real NUMA node data can overwrite this buffer. This heap buffer overflow can corrupt the root libvirt daemon's memory, potentially leading to a denial of service or local privilege escalation. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-190. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: libvirt.
High [CVE-2026-19582] Stack Buffer Overflow in GNU Binutils in rsrc_print_name from an untrusted PE file
Stack Buffer Overflow in GNU Binutils in rsrc_print_name from an untrusted PE file. Red Hat rates this a security issue. Weakness: CWE-787. Affected products named by the advisory: Migration Toolkit for Containers; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4.
High [CVE-2026-28984] Processing maliciously crafted web content may lead to an unexpected Safari crash
Processing maliciously crafted web content may lead to an unexpected Safari crash. Red Hat rates this important (CVSS 8.8). Weakness: CWE-120. Red Hat lists fixing advisory RHSA-2026:25918 with package webkit2gtk3-0:2.52.4-1.el8_8, webkit2gtk3-0:2.52.4-1.el9_8, webkit2gtk3-0:2.52.4-1.el8_4, webkit2gtk3-0:2.52.4-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.
High [CVE-2026-64719] Processing maliciously crafted web content may lead to an unexpected Safari crash
Processing maliciously crafted web content may lead to an unexpected Safari crash. Red Hat rates this important (CVSS 8.8). Weakness: CWE-120.
High [CVE-2026-64787] Processing maliciously crafted web content may lead to an unexpected process termination
Processing maliciously crafted web content may lead to an unexpected process termination. Red Hat rates this important (CVSS 8.8). Weakness: CWE-416. Red Hat lists fixing advisory RHSA-2026:42088 with package webkit2gtk3-0:2.52.5-1.el8_10, webkit2gtk3-0:2.52.5-1.el9_2, webkit2gtk3-0:2.52.5-1.el8_4, webkit2gtk3-0:2.52.5-1.el9_4. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.
High [CVE-2026-64757] Processing maliciously crafted web content may lead to an unexpected Safari crash
Processing maliciously crafted web content may lead to an unexpected Safari crash. Red Hat rates this important (CVSS 8.8). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat package: webkitgtk3; Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.
High [CVE-2026-64783] Processing maliciously crafted web content may lead to an unexpected Safari crash
Processing maliciously crafted web content may lead to an unexpected Safari crash. Red Hat rates this important (CVSS 8.8). Weakness: CWE-416. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat package: webkitgtk3; Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.
High [CVE-2026-76403] Improper Certificate Validation through HTTP Event Collector Kerberos Authentication in Splunk Connect for Kafka
In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user positioned in the network path could read or alter all relevant data sent from the connector when Kerberos authentication is used with Hypertext Transfer Protocol (HTTP) Event Collector in Splunk Enterprise. The vulnerability is possible because the Kerberos authentication path does not apply the configured certificate validation options when it builds the HTTP client. For more information see Install Splunk Connect for Kafka ( ), Security configurations for Splunk Connect for Kafka ( ), and Set up and use HTTP Event Collector with configuration files ( ) in the Splunk documentation.
High [CVE-2026-76402] Server-Side Request Forgery (SSRF) through the REST API in Splunk Connect for Kafka
In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API could configure a non-secure Hypertext Transfer Protocol (HTTP) Event Collector endpoint in Splunk Enterprise that causes the connector to send authentication credentials to an attacker-controlled server, allowing for exposure of credentials that compromise all relevant data sent through the connector and limited alteration of event delivery. The vulnerability is possible because HTTP Event Collector endpoint validation does not require secure transport by default. For more information see Install Splunk Connect for Kafka ( ), Data ingestion parameters for Splunk Connect for Kafka ( ), and Set up and use HTTP Event Collector with configuration files ( ) in the Splunk documentation.
High [CVE-2026-76399] Incorrect Permission Assignment for Scheduled Searches in Splunk AI Toolkit
In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify app-provided scheduled searches to run arbitrary Search Processing Language (SPL) using the permissions of the search owner, which could allow access to all relevant data and affect system integrity. The vulnerability is possible because Splunk AI Toolkit gives the "power" Splunk role permission to modify scheduled searches that run using the permissions of the search owner.
High [CVE-2026-76397] Improper Access Control in Experiment History through the REST API in Splunk AI Toolkit
In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could access and delete all relevant data in experiment history, including data associated with other users. The vulnerability is possible because Splunk AI Toolkit does not preserve the trusted experiment scope when it processes caller-controlled query values before accessing restricted history data. For more information see Experiment Assistants ( ) in the Splunk documentation.
High [CVE-2026-76396] Improper Access Control through Scheduled Searches in Splunk AI Toolkit
In Splunk AI Toolkit versions below 6.0.0, a user that holds a role with the schedule_search capability could cause a scheduled search to load and deserialize a model file through the apply search command. The improper access control is possible because Splunk AI Toolkit does not mark the apply search command as risky. For more information see Troubleshoot the AI Toolkit ( ) in the Splunk documentation.
High [CVE-2026-76395] Remote Code Execution (RCE) through Deserialization of Untrusted Data in the Model Loading REST API in Splunk AI Toolkit
In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code on the Splunk server by loading a model file containing crafted sparse matrix data. The deserialization of untrusted data is possible because a model codec in Splunk AI Toolkit deserializes sparse matrix data without guarding against embedded pickle content. For more information see Troubleshoot the Splunk Machine Learning Toolkit ( ) in the Splunk documentation.
High [CVE-2026-76394] Missing Authorization in Container and Connection Management through the REST API in Splunk AI Toolkit
In Splunk AI Toolkit versions below 6.0.0, a low-privileged user who does not hold the "admin" or "power" Splunk roles could start, stop, and configure containers, and read or modify connection and configuration data through the Representational State Transfer (REST) API. The missing authorization is possible because multiple REST API handlers in Splunk AI Toolkit do not enforce authorization checks. For more information see Troubleshoot the Splunk Machine Learning Toolkit ( ) in the Splunk documentation.
High [CVE-2026-76391] Improper Privilege Management through Agent Run History in Splunk AI Toolkit
In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could run searches with system-level privileges, access all relevant data, affect system integrity, and read or delete search jobs belonging to other users through Agent Run History. The improper privilege management is possible because the Agent Run History handler replaces the calling user session key with a system authentication token before it performs search operations. For more information see AI Toolkit Agent Launchpad ( ) in the Splunk documentation.
High [CVE-2026-76389] Server-Side Request Forgery (SSRF) through the REST API in Cisco Talos Intelligence for Enterprise Security Cloud
In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, a user that holds a role with the get_talos_enrichment capability could send a crafted request to the Talos intelligence enrichment Representational State Transfer (REST) API endpoint and cause the instance to make an outbound request to an attacker-controlled server. The request could expose tokens that compromise all relevant data and system integrity in the Splunk instance. The vulnerability is possible because the Talos intelligence enrichment REST endpoint accepts the destination for authenticated Splunk management requests from request data. For more information see Deploy Cisco Talos Intelligence for Splunk Enterprise Security ( ) in the Splunk documentation.
High [CVE-2026-76388] Privilege Escalation through Search Macro Permissions in Splunk Enterprise Security
In Splunk Enterprise Security versions below 8.6.1, a user who holds the ess_analyst Splunk Enterprise Security role could change User and Entity Behavior Analytics (UEBA) search macros that scheduled searches run with administrator permissions, allowing for access to all relevant data and system integrity through those searches. The vulnerability is possible because the UEBA app metadata grants analyst roles write access to search macros that should be writable only by administrator roles. For more information see Users and roles for Splunk Enterprise Security ( ) and Roles and knowledge objects in UEBA for Splunk Enterprise Security ( ) in the Splunk documentation.
High [CVE-2026-76387] SPL Injection through the REST API in Splunk Enterprise Security
In Splunk Enterprise Security versions below 8.6.1, a user who holds a Splunk Enterprise Security role that contains the mc_investigation_read capability could inject Search Processing Language (SPL) through Analyst Queue search filters, allowing for access to all relevant data and system integrity available to the scheduled searches that run for that user. The vulnerability is possible because the Analyst Queue search filter handling does not validate filter field names before the fields are included in SPL searches. For more information see Users and roles for Splunk Enterprise Security ( ), Manage analyst workflows using the analyst queue in Splunk Enterprise Security ( ), and Overview of Mission Control in Splunk Enterprise Security ( ) in the Splunk documentation.