Complete feed
Security advisories & CVEs
432 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Critical [CVE-2026-47323] Remote Code Execution via header injection due to missing inbound filtering
Remote Code Execution via header injection due to missing inbound filtering. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-791. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: OpenShift Serverless.
Critical [CVE-2026-2611] Arbitrary Code Execution via Improper Origin Validation
Arbitrary Code Execution via Improper Origin Validation. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-940. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-9118] Use after free in XR
Use after free in XR. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-9120] Use after free in WebRTC
Use after free in WebRTC. Red Hat rates this important (CVSS 9.6). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-9115] Insufficient policy enforcement in Service Worker
Insufficient policy enforcement in Service Worker. Red Hat rates this important (CVSS 9.3). Weakness: CWE-940. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-9119] Heap buffer overflow in WebRTC
Heap buffer overflow in WebRTC. Red Hat rates this important (CVSS 9.6). Weakness: CWE-120. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-9114] Use after free in QUIC
Use after free in QUIC. Red Hat rates this important (CVSS 9.8). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-45829] Arbitrary code execution via pre-authentication code injection
Arbitrary code execution via pre-authentication code injection. Red Hat rates this critical (CVSS 10). Weakness: CWE-502. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Enterprise Linux; python.
Critical [CVE-2021-47952] Arbitrary Code Execution via Malicious JSON Deserialization
Arbitrary Code Execution via Malicious JSON Deserialization. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-502. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: python jsonpickle.
Critical [CVE-2026-42327] Arbitrary code execution via specially crafted certificate
Arbitrary code execution via specially crafted certificate. Red Hat rates this important (CVSS 9.1). Weakness: CWE-475. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-8554] Type Confusion in ANGLE
Type Confusion in ANGLE. Red Hat rates this important (CVSS 9). Weakness: CWE-843. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-8548] Out of bounds write in Media
Out of bounds write in Media. Red Hat rates this important (CVSS 9). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-8547] Insufficient policy enforcement in Passwords
Insufficient policy enforcement in Passwords. Red Hat rates this important (CVSS 9). Weakness: CWE-266. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-8534] Integer overflow in GPU
Integer overflow in GPU. Red Hat rates this important (CVSS 9). Weakness: CWE-190. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-8533] Use after free in Accessibility
Use after free in Accessibility. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-8531] Heap buffer overflow in WebML
Heap buffer overflow in WebML. Red Hat rates this important (CVSS 9.6). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-8525] Heap buffer overflow in ANGLE
Heap buffer overflow in ANGLE. Red Hat rates this important (CVSS 9.6). Weakness: CWE-120. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-8526] Out of bounds write in WebRTC
Out of bounds write in WebRTC. Red Hat rates this important (CVSS 9.6). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-8524] Out of bounds write in WebAudio
Out of bounds write in WebAudio. Red Hat rates this important (CVSS 9.6). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-8523] Use after free in Mojo
Use after free in Mojo. Red Hat rates this important (CVSS 9). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.