Complete feed
Security advisories & CVEs
1750 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-60589 +2] August 2026 Java SE Vulnerabilities in NetApp Products
Java SE versions 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, and 26.0.2 are susceptible to vulnerabilities that allow unauthenticated attackers with network access via multiple protocols (including HTTP and TLS) to compromise Oracle Java SE. Refer to “Oracle Critical Security Patch Update Advisory - August 2026” for additional details. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE accessible data, unauthorized access to critical data or complete access to all Oracle Java SE accessible data or unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE. Affected products: Data Infrastructure Insights and Data Secure Storage Workload Security Agent. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
Medium [CVE-2026-71073 +2] August 2026 MySQL Connector/ODBC Vulnerabilities in NetApp Products
MySQL Connector/ODBC version 26.7.0 is susceptible to vulnerabilities that allow low privileged or unauthenticated attackers with network access via multiple protocols or logon to the infrastructure where MySQL Connectors executes to compromise MySQL Connectors. Refer to “Oracle Critical Security Patch Update Advisory - August 2026” for additional details. Successful attacks of these vulnerabilities can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors and unauthorized read access to a subset of MySQL Connectors accessible data. NetApp states there is no workaround available at this time.
Medium [CVE-2026-1245] Node.js Vulnerability in NetApp Products
Node.js versions prior to 2.3.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
Medium [CVE-2026-73282] OpenSSH Vulnerability in NetApp Products
OpenSSH versions through 10.4 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
Medium [CVE-2026-55894] Denial of Service via crafted SH2A bytecode
Denial of Service via crafted SH2A bytecode. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:59419 with package capstone-main-5.0.8-0.3.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: capstone.
Medium [CVE-2026-77643] Xapian xapian-core: Arbitrary code execution via incomplete HTML escaping
Xapian xapian-core: Arbitrary code execution via incomplete HTML escaping. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-79. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: xapian-core.
Medium [CVE-2026-53586] Information disclosure via HTTP redirect allows credential leakage
Information disclosure via HTTP redirect allows credential leakage. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-201. Red Hat lists fixing advisory RHSA-2026:59361 with package libgit2-main-1.9.7-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat package: rust; Red Hat package: libgit2.
Medium [CVE-2026-53583] Network attacker can intercept HTTPS connections via inverted IP SubjectAltName comparison
Network attacker can intercept HTTPS connections via inverted IP SubjectAltName comparison. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-295. Red Hat lists fixing advisory RHSA-2026:59361 with package libgit2-main-1.9.7-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat package: rust; Red Hat package: libgit2.
Medium [CVE-2026-53585] Denial of Service via Unbounded Memory Allocation
Denial of Service via Unbounded Memory Allocation. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:59361 with package libgit2-main-1.9.7-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat package: rust; Red Hat package: libgit2.
Medium [CVE-2026-63379] HTTP header smuggling allows authorization bypass or cache poisoning
HTTP header smuggling allows authorization bypass or cache poisoning. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-444. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat package: libevent2.
Medium [CVE-2026-63380] Denial of Service via Null Pointer Dereference
Denial of Service via Null Pointer Dereference. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: libevent2.
Medium [CVE-2026-63381] Memory corruption due to use-after-free
Memory corruption due to use-after-free. Red Hat rates this moderate (CVSS 6.6). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat package: libevent2.
Medium [CVE-2026-71492] Arbitrary file write via path traversal
Arbitrary file write via path traversal. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-22.
Medium [CVE-2026-63044] Server-Side Request Forgery (SSRF) vulnerability in Apache InLong
Server-Side Request Forgery (SSRF) vulnerability in Apache InLong. Any authenticated user (no admin role required) can cause the InLong Manager server to make outbound HTTP requests or TCP connections to arbitrary internal hosts and ports. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1].
Medium [CVE-2026-63016] Uncontrolled Resource Consumption vulnerability in Apache InLong
Uncontrolled Resource Consumption vulnerability in Apache InLong. Users could affect operational configuration or allow upload of non-official packages. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1]
Medium [CVE-2026-63015] Uncontrolled Resource Consumption vulnerability in Apache InLong
Uncontrolled Resource Consumption vulnerability in Apache InLong. Non-template responsible persons can view template information. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1]
Medium [CVE-2026-73199] NULL Pointer Dereference in `ipa-enrollment` Extended Operation (`JOIN_OID`) via Missing Request Value
NULL Pointer Dereference in `ipa-enrollment` Extended Operation (`JOIN_OID`) via Missing Request Value. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: ipa.
Medium [CVE-2026-73196] Authenticated DoS in `otptoken-add` via unbounded OTP key decoding/re-encoding
Authenticated DoS in `otptoken-add` via unbounded OTP key decoding/re-encoding. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: ipa.
Medium [CVE-2026-77014] Libsoup: libsoup: integer truncation in sort_ranges comparator causes silent omission of http range responses
A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-headers.c truncates a 64-bit subtraction result to 32-bit int, flipping the sign for range offsets differing by more than INT_MAX. This causes silent omission of requested byte ranges from HTTP 206 Partial Content responses on resources larger than approximately 2 GB. A remote attacker can exploit this to cause the server to silently omit requested byte ranges from responses. Exploitation requires the server to be serving resources larger than approximately 2 GB, which limits real-world impact. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N). Weakness: CWE-197. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: libsoup3; Red Hat package: gnome-clocks; Red Hat package: podman.
Medium [CVE-2026-76957] Memory corruption vulnerability allows arbitrary code execution or denial of service
Memory corruption vulnerability allows arbitrary code execution or denial of service. Red Hat rates this moderate (CVSS 4.9). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:60451 with package expat-main-2.8.3-0.1.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 9 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: expat; and 5 more.