Complete feed
Recently updated
Advisories the vendor has revised
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-19012] Authenticated denial of service via configuration entry
Authenticated denial of service via configuration entry. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-15. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat package: grafana.
Medium [CVE-2026-19016] Authorization bypass allows arbitrary session deletion via transaction API
Authorization bypass allows arbitrary session deletion via transaction API. Red Hat rates this moderate (CVSS 4.2). Weakness: CWE-639. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat package: grafana.
Medium [CVE-2026-71852] Denial of Service via crafted PDF with large CID font width ranges
Denial of Service via crafted PDF with large CID font width ranges. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1050.
Medium [CVE-2026-18938] Integer overflow in RPC attribute-array length calculation can under-allocate nested attribute storage on 32 bit systems
Integer overflow in RPC attribute-array length calculation can under-allocate nested attribute storage on 32 bit systems. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-122.
Medium [CVE-2026-12261] Resource poisoning via improper package archive extraction
Resource poisoning via improper package archive extraction. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-367. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 1 more. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI).
Medium [CVE-2026-56145] Elasticsearch Vulnerability in NetApp Products
Elasticsearch versions 8.19.0 through 8.19.17, 9.3.0 through 9.3.6, and 9.4.0 through 9.4.3 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
Medium [CVE-2026-63144] Elasticsearch Vulnerability in NetApp Products
Elasticsearch versions 8.19.0 through 8.19.18, 9.3.0 through 9.3.7, and 9.4.0 through 9.4.3 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
Medium [CVE-2026-63136] Elasticsearch Vulnerability in NetApp Products
Elasticsearch versions 8.0.0 through 8.19.14, 9.0.0 through 9.2.8, and 9.3.0 through 9.3.3 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
Low [CVE-2026-61477] newline injection in network XML DNS TXT/SRV fields allows dnsmasq config directive injection
newline injection in network XML DNS TXT/SRV fields allows dnsmasq config directive injection. Red Hat rates this low (CVSS 2.3). Weakness: CWE-93. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26.
Critical [CVE-2026-18367] privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2026.1.1 and Sophos Home for macOS older than version 10.11.6
A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2026.1.1 and Sophos Home for macOS older than version 10.11.6.
Critical [CVE-2026-19173] Sandbox escape via out-of-bounds write in Chromium
Sandbox escape via out-of-bounds write in Chromium. Red Hat rates this important (CVSS 9). Weakness: CWE-787.
Critical [CVE-2026-19155] Sandbox escape via use-after-free in Payments
Sandbox escape via use-after-free in Payments. Red Hat rates this important (CVSS 9). Weakness: CWE-825.
Critical [CVE-2026-19137] Google Chrome on Android: Sandbox escape via use after free in WebGL
Google Chrome on Android: Sandbox escape via use after free in WebGL. Red Hat rates this important (CVSS 9). Weakness: CWE-825.
Critical [CVE-2026-71476] @nx/s3-cache: @nx/gcs-cache: @nx/azure-cache: @nx/shared-fs-cache: @nx/powerpack-s3-cache: @nx/powerpack-gcs-cache: @nx/powerpack-azure-cache: @nx/powerpack-shared-fs-cache: Nx: Remote Code Executi…
@nx/s3-cache: @nx/gcs-cache: @nx/azure-cache: @nx/shared-fs-cache: @nx/powerpack-s3-cache: @nx/powerpack-gcs-cache: @nx/powerpack-azure-cache: @nx/powerpack-shared-fs-cache: Nx: Remote Code Execution via Zip-Slip vulnerability in self-hosted remote cache. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-22. Affected product named by the advisory: Red Hat Ansible Automation Platform 2.
Critical [CVE-2026-32327] bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem function
A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.
Critical [CVE-2026-34191] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3
Critical [CVE-2026-5134] Loca Software Informatics Technology Ltd. Co. CMS: CMS: Critical SQL Injection vulnerability
Loca Software Informatics Technology Ltd. Co. CMS: CMS: Critical SQL Injection vulnerability. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-89.
Critical [CVE-2026-61466] In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without validating it against an AS-defined allowlist
In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without validating it against an AS-defined allowlist. This could lead to a client self-assigning privileged scopes at registration time. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
Critical [CVE-2026-63687] Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensitive parameters
Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensitive parameters. A client that can produce a validly-signed request JWT (e.g., one whose client_secret is known or compromised) can thereby substitute the code_challenge, code_challenge_method, nonce, and state values that were set in the outer HTTP request, undermining PKCE integrity and OpenID Connect replay protection. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
Critical [CVE-2026-65583] Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/time and sub_jwk binding), enabling authentication bypass with crafted tokens
Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/time and sub_jwk binding), enabling authentication bypass with crafted tokens. However, note that self-issued ID tokens are not accepted by default in the validator. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fixes this issue.