Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.0Vendor: MediumRed Hat

High [CVE-2026-68103] reject mapping a reserved doorbell to a new queue

reject mapping a reserved doorbell to a new queue. Red Hat rates this moderate (CVSS 7). Weakness: CWE-367. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-68103
Linux Kernel
Aug 10, 2026
High7.0Red Hat

High [CVE-2026-68123] fix GSO userspace truncation underflow

fix GSO userspace truncation underflow. Red Hat rates this important (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-68123
Linux Kernel
Aug 10, 2026
High7.8Red Hat

High [CVE-2026-68264] Reset current_op in xe_pt_update_ops_init

Reset current_op in xe_pt_update_ops_init(). Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-68264
Linux Kernel
Aug 10, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-68391] hold reference for hci_conn in mgmt_pending_cmds

hold reference for hci_conn in mgmt_pending_cmds. Red Hat rates this moderate (CVSS 7). Weakness: CWE-911. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-68391
Linux Kernel
Aug 10, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-68374] add lock to bos_descriptors_read

add lock to bos_descriptors_read(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-68374
Linux Kernel
Aug 10, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-68379] fix TIME_WAIT socket reference leak on PSP policy failure

fix TIME_WAIT socket reference leak on PSP policy failure. Red Hat rates this moderate (CVSS 7). Weakness: CWE-911. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat package: kernel.

CVE-2026-68379
Linux Kernel
Aug 10, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-68181] access mei_device under device_lock on cleanup

access mei_device under device_lock on cleanup. Red Hat rates this moderate (CVSS 7). Weakness: CWE-364. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-68181
Linux Kernel
Aug 10, 2026
Medium4.4Vendor: LowRed Hat

Medium [CVE-2026-6426] vhost inflight migration VMState integer type mismatch causes out-of-bounds access

vhost inflight migration VMState integer type mismatch causes out-of-bounds access. Red Hat rates this low (CVSS 4.4). Weakness: CWE-681. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4.

CVE-2026-6426
Unclassified
Aug 10, 2026
Medium5.5Vendor: HighRed Hat

Medium [CVE-2026-18942] feast apply CronJob runs user Python with feature-server SA — tenant code to SA token escalation

feast apply CronJob runs user Python with feature-server SA — tenant code to SA token escalation. Red Hat rates this important (CVSS 5.5). Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-feature-server-rhel9:1786110051, rhoai/odh-feature-server-rhel9:1786107278. Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.4.

CVE-2026-18942
Unclassified
Aug 10, 2026
Medium6.5Vendor: HighRed Hat

Medium [CVE-2026-16456] Cross-namespace secret read via NIM Account CRD confused deputy

Cross-namespace secret read via NIM Account CRD confused deputy. Red Hat rates this important (CVSS 6.5). Weakness: CWE-441. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-model-controller-rhel9:1785187158, rhoai/odh-model-controller-rhel9:1784950479, rhoai/odh-model-controller-rhel9:1785189333. Affected products named by the advisory: Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.4.

CVE-2026-16456
Unclassified
Aug 10, 2026
Medium5.9Red Hat

Medium [CVE-2026-6791] Denial of Service via stack exhaustion during tilde expansion

Denial of Service via stack exhaustion during tilde expansion. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-120. Red Hat lists fixing advisory RHSA-2026:53069 with package glibc-main-2.43-8.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 5 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat package: glibc; and 1 more.

CVE-2026-6791
Red Hat Enterprise Linux
Aug 10, 2026
Medium5.5Red Hat

Medium [CVE-2026-6368] Process abort due to invalid memory in wordexp

Process abort due to invalid memory in wordexp. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1341. Red Hat lists fixing advisory RHSA-2026:53069 with package glibc-main-2.43-8.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 5 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat package: glibc; and 1 more.

CVE-2026-6368
Red Hat Enterprise Linux
Aug 10, 2026
Medium6.5Apache

Medium [CVE-2026-68872] The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed

The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace.

CVE-2026-68872
Airflow
Aug 10, 2026
Medium6.5Apache

Medium [CVE-2026-68871] The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed

The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with this backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using this backend. Users are advised to upgrade to apache-airflow-providers-yandex 4.5.1 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace.

CVE-2026-68871
Airflow
Aug 10, 2026
Medium5.3Apache

Medium [CVE-2026-68870] The Azure Key Vault secrets backend in Apache Airflow's Microsoft Azure provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed

The Azure Key Vault secrets backend in Apache Airflow's Microsoft Azure provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with this backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using this backend. Users are advised to upgrade to apache-airflow-providers-microsoft-azure 14.1.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace.

CVE-2026-68870
Airflow
Aug 10, 2026
Medium5.5Red Hat

Medium [CVE-2026-63623] Information disclosure via world-readable storage volume images during clone/convert

Information disclosure via world-readable storage volume images during clone/convert. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-732.

CVE-2026-63623
Unclassified
Aug 10, 2026
Medium6.3Red Hat

Medium [CVE-2026-71577] Spec-topic Read ACL leaks bootstrap kubeconfigs to all managed hubs during migration

Spec-topic Read ACL leaks bootstrap kubeconfigs to all managed hubs during migration. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-522.

CVE-2026-71577
Unclassified
Aug 10, 2026
Medium6.5Zyxel

Medium [CVE-2026-6373] Exposure of sensitive system information to an unauthorized control sphere vulnerability in Zyxel Networks WAH7601 allows Web Application Fingerprinting

Exposure of sensitive system information to an unauthorized control sphere vulnerability in Zyxel Networks WAH7601 allows Web Application Fingerprinting. This issue affects WAH7601: through 20072026.

CVE-2026-6373
Unclassified
Aug 10, 2026
Medium4.7Red Hat

Medium [CVE-2026-15060] Unprivileged users can terminate arbitrary processes

When systemd-machined >= v259 (or v258 with a custom `polkit` policy that allows `register-machine` access) is running on a desktop system, an unprivileged user logged in a desktop graphical session can kill arbitrary processes, even privileged ones. - versions older than v259 are not affected, unless unprivileged access is granted for the `register-machine` polkit action via a local, custom policy config file - versions older than v258 are not affected - unrelated to the systemd service manager (pid 1 or user session managers) - systemd-machined is not typically installed by default, and is typically in an optional, separate package (e.g.: systemd-container) - terminal-only or remote sessions (e.g.: ssh) are not affected This could lead to a denial of service or potentially allow for privilege escalation. Red Hat products are not affected by this vulnerability. Red Hat Enterprise Linux ships systemd versions well below this threshold (RHEL 7: v219, RHEL 8: v239, RHEL 9: v252, RHEL 10: v257). Red Hat severity: Moderate — CVSS 4.7 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-266. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4 as not affected.

CVE-2026-15060
Unclassified
Aug 10, 2026
Medium5.5Red Hat

Medium [CVE-2026-18370] Heap-based buffer overflow leads to denial of service

Heap-based buffer overflow leads to denial of service. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787.

CVE-2026-18370
Unclassified
Aug 10, 2026