Complete feed
Security advisories & CVEs
3494 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-63117] Denial of Service via ADPCM frame size calculation
Denial of Service via ADPCM frame size calculation. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-369. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: freerdp.
Medium [CVE-2026-18874] annotation values rendered into YAML via text/template without escaping allows YAML injection into Subscription
annotation values rendered into YAML via text/template without escaping allows YAML injection into Subscription. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-94. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/acm-volsync-addon-controller-rhel9:1787266360, rhacm2/acm-volsync-addon-controller-rhel9:1787683560, rhacm2/acm-volsync-addon-controller-rhel9:1787266556, rhacm2/acm-volsync-addon-controller-rhel9:1787266564. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.
Medium [CVE-2026-55648] Integer overflow allows out-of-bounds read via malicious RDP server
Integer overflow allows out-of-bounds read via malicious RDP server. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: freerdp.
Medium [CVE-2026-55564] Out-of-bounds read in glyph cache leads to denial of service and information disclosure
Out-of-bounds read in glyph cache leads to denial of service and information disclosure. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: freerdp.
Medium [CVE-2026-75145] Out-of-bounds memory access due to integer narrowing conversion
Out-of-bounds memory access due to integer narrowing conversion. Red Hat rates this moderate (CVSS 5.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
Medium [CVE-2026-76878] aodh / python-watcher: cross-project alarm enumeration and webhook missing authorization
aodh / python-watcher: cross-project alarm enumeration and webhook missing authorization. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-863. Affected products named by the advisory: Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0.
Medium [CVE-2026-76231] Arbitrary command execution via unsanitized dependency names
Arbitrary command execution via unsanitized dependency names. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-78.
Medium [CVE-2026-76228] Arbitrary Code Execution via malicious Gradle Wrapper properties
Arbitrary Code Execution via malicious Gradle Wrapper properties. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-78.
Medium [CVE-2026-76229] Arbitrary Command Injection via kustomize manager
Arbitrary Command Injection via kustomize manager. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-78.
Medium [CVE-2026-76217] Arbitrary File Read via Crafted Parameters
Arbitrary File Read via Crafted Parameters. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-88. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat Satellite 6.
Medium [CVE-2026-16440] Denial of Service via crafted.class file
Denial of Service via crafted.class file. Red Hat rates this moderate (CVSS 5.7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat package: java-1.8.0-ibm.
Medium [CVE-2026-76166] mod_cluster Advertise Listener: unauthenticated DoS via crafted multicast datagram
mod_cluster Advertise Listener: unauthenticated DoS via crafted multicast datagram. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-476. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat JBoss Web Server 6; and 2 more. Affected products named by the advisory: Red Hat JBoss Web Server 7; Red Hat Single Sign-On 7.
Medium [CVE-2026-75900] Out-of-bounds read in SWTPM_NVRAM_CheckHeader due to sizeof(pointer) vs sizeof(struct) mismatch
Out-of-bounds read in SWTPM_NVRAM_CheckHeader due to sizeof(pointer) vs sizeof(struct) mismatch. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-71084] Denial of Service via unauthenticated local access
Denial of Service via unauthenticated local access. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat package: mysql-connector-odbc.
Medium [CVE-2026-71079] Denial of Service via network access by a low privileged attacker
Denial of Service via network access by a low privileged attacker. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat package: mysql-connector-odbc.
Medium [CVE-2026-76042] Information disclosure via uninitialized resource in GPU
Information disclosure via uninitialized resource in GPU. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-824.
Medium [CVE-2026-16732] Request spoofing via numeric trustProxy configuration
Request spoofing via numeric trustProxy configuration. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-501. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Dev Spaces.
Medium [CVE-2026-18504] Schema validation bypass via root primitive coercion mismatch
Schema validation bypass via root primitive coercion mismatch. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-843. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Dev Spaces.
Medium [CVE-2026-49452] CSS Injection via Presentational Hints
CSS Injection via Presentational Hints. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-79.
Medium [CVE-2026-66781] IPsec PSK stored cleartext in Submariner CR spec
IPsec PSK stored cleartext in Submariner CR spec. Red Hat rates this important (CVSS 6.5). Weakness: CWE-312. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/submariner-addon-rhel9:1787362694, rhacm2/submariner-addon-rhel9:1787689013, rhacm2/submariner-addon-rhel9:1787365971, rhacm2/submariner-addon-rhel9:1787362658. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.