Complete feed
Recently updated
Advisories the vendor has revised
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Critical [CVE-2026-17660] Insufficient validation of untrusted input in Network
Insufficient validation of untrusted input in Network. Red Hat rates this important (CVSS 9). Weakness: CWE-1286.
Critical [CVE-2026-17656] Use after free in Ozone
Use after free in Ozone. Red Hat rates this critical (CVSS 10). Weakness: CWE-825.
Critical [CVE-2026-17655] Insufficient validation of untrusted input in ANGLE
Insufficient validation of untrusted input in ANGLE. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-1286.
Critical [CVE-2026-17653] Use after free in Skia
Use after free in Skia. Red Hat rates this critical (CVSS 9). Weakness: CWE-825.
Critical [CVE-2026-17651] Insufficient validation of untrusted input in Dawn
Insufficient validation of untrusted input in Dawn. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-79.
Critical [CVE-2026-17650] Use after free in Compositing
Use after free in Compositing. Red Hat rates this important (CVSS 9.9). Weakness: CWE-825.
Critical [CVE-2026-17652] Use after free in Views
Use after free in Views. Red Hat rates this critical (CVSS 9). Weakness: CWE-825.
High [CVE-2026-18157] Remote Code Execution via APT Argument Injection
Remote Code Execution via APT Argument Injection. Red Hat rates this important (CVSS 7.8). Weakness: CWE-88.
High [CVE-2026-66066] Remote Code Execution via Unsafe libvips Operations
Remote Code Execution via Unsafe libvips Operations. Red Hat rates this important (CVSS 8.9). Weakness: CWE-434.
High [CVE-2026-12932] Denial of Service due to memory leak in tls-crypt-v2 client key extraction
Denial of Service due to memory leak in tls-crypt-v2 client key extraction. Red Hat rates this important (CVSS 7.5). Weakness: CWE-771.
High [CVE-2026-62663] Information Disclosure via Path Traversal in Media Filters
Information Disclosure via Path Traversal in Media Filters. Red Hat rates this important (CVSS 7.5). Weakness: CWE-22. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2.
High [CVE-2026-60075] Date::Manip for Perl: Denial of Service via CPU exhaustion in date parsing
Date::Manip for Perl: Denial of Service via CPU exhaustion in date parsing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Red Hat lists fixing advisory RHSA-2026:56971 with package perl-Date-Manip-0:6.85-3.el9_8.1, perl-Date-Manip-0:6.94-5.el10_2.1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.
High [CVE-2026-17544] Arbitrary code execution via out-of-bounds write in bccomp
Arbitrary code execution via out-of-bounds write in bccomp(). Red Hat rates this important (CVSS 8.1). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:47200 with package php-main-8.5.9-1.hum1, php8.4-0:8.4.24-1.el10_2. Affected product named by the advisory: Red Hat Enterprise Linux 10.
High [CVE-2026-17543] SQL injection via improper backslash escaping
SQL injection via improper backslash escaping. Red Hat rates this important (CVSS 7.4). Weakness: CWE-89. Red Hat lists fixing advisory RHSA-2026:47200 with package php-main-8.5.9-1.hum1, php8.4-0:8.4.24-1.el10_2. Affected product named by the advisory: Red Hat Enterprise Linux 10.
High [CVE-2026-18353] Unauthenticated Server-Side Request Forgery via OIDC issuer allowlist bypass
Unauthenticated Server-Side Request Forgery via OIDC issuer allowlist bypass. Red Hat rates this important (CVSS 8.2). Weakness: CWE-918.
High [CVE-2026-58043] Unauthorized filesystem access due to Permission Model enforcement flaw
Unauthorized filesystem access due to Permission Model enforcement flaw. Red Hat rates this important (CVSS 7.5). Weakness: CWE-551. Red Hat lists fixing advisory RHSA-2026:48273 with package nodejs26-main-26.5.1-1.5.hum1, nodejs22-main-22.23.2-2.3.hum1, nodejs24-main-24.18.1-0.1.hum1.
High [CVE-2026-16529] Denial of Service due to signed integer overflow
Denial of Service due to signed integer overflow. Red Hat rates this important (CVSS 7.5). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:55740 with package pcp-0:7.0.3-5.el10_2, pcp-0:5.3.7-22.el8_10.5, pcp-0:6.3.7-8.el9_8.4. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Affected products named by the advisory: Red Hat Enterprise Linux 7.
High [CVE-2026-16527] PCP pmproxy: Unauthenticated access to /store endpoint allows bypassing pmcd access rules
PCP pmproxy: Unauthenticated access to /store endpoint allows bypassing pmcd access rules. Red Hat rates this important (CVSS 7.3). Weakness: CWE-306. Red Hat lists fixing advisory RHSA-2026:55740 with package pcp-0:7.0.3-5.el10_2, pcp-0:5.3.7-22.el8_10.5, pcp-0:6.3.7-8.el9_8.4. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Affected products named by the advisory: Red Hat Enterprise Linux 7.
High [CVE-2026-16526] Privilege escalation to root via linux_sockets PMDA vulnerability
Privilege escalation to root via linux_sockets PMDA vulnerability. Red Hat rates this important (CVSS 8.8). Weakness: CWE-403. Red Hat lists fixing advisory RHSA-2026:55740 with package pcp-0:7.0.3-5.el10_2, pcp-0:5.3.7-22.el8_10.5, pcp-0:6.3.7-8.el9_8.4. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Affected products named by the advisory: Red Hat Enterprise Linux 7.
High [CVE-2026-16524] PCP linux_sockets PMDA: Arbitrary Command Execution via Command Injection
PCP linux_sockets PMDA: Arbitrary Command Execution via Command Injection. Red Hat rates this important (CVSS 7.8). Weakness: CWE-78. Red Hat lists fixing advisory RHSA-2026:55740 with package pcp-0:7.0.3-5.el10_2, pcp-0:5.3.7-22.el8_10.5, pcp-0:6.3.7-8.el9_8.4. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Affected products named by the advisory: Red Hat Enterprise Linux 7.