Complete feed
Security advisories & CVEs
1749 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-76956] Denial of Service via hash flooding attack with crafted XML
Denial of Service via hash flooding attack with crafted XML. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-331. Red Hat lists fixing advisory RHSA-2026:60451 with package expat-main-2.8.3-0.1.1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
Medium [CVE-2026-43804] Visiting a website may lead to an app denial-of-service
Visiting a website may lead to an app denial-of-service. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-664. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat package: webkitgtk3; Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.
Medium [CVE-2026-64713] Websites may know if the user has visited a given link
Websites may know if the user has visited a given link. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-200. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat package: webkitgtk3; Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.
Medium [CVE-2026-64728] Maliciously crafted web content may violate iframe sandboxing policy
Maliciously crafted web content may violate iframe sandboxing policy. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-693. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat package: webkitgtk3; Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.
Medium [CVE-2026-64730] Visiting a website that frames malicious content may lead to UI spoofing
Visiting a website that frames malicious content may lead to UI spoofing. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-451. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat package: webkitgtk3; Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.
Medium [CVE-2026-76928] Denial of Service via X.509IF protocol dissector crash
Denial of Service via X.509IF protocol dissector crash. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-76924] Denial of Service via Out-of-bounds Read in Kerberos Dissector
Denial of Service via Out-of-bounds Read in Kerberos Dissector. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-76923] Denial of Service due to out-of-bounds read in Bluetooth HFP dissector
Denial of Service due to out-of-bounds read in Bluetooth HFP dissector. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-76918] Denial of Service via SSH protocol dissector crash
Denial of Service via SSH protocol dissector crash. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-248. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-76917] Denial of Service via Heap-based Buffer Overflow in Bluetooth AVRCP Dissector
Denial of Service via Heap-based Buffer Overflow in Bluetooth AVRCP Dissector. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-76880] Denial of Service via RRC protocol dissector out-of-bounds write
Denial of Service via RRC protocol dissector out-of-bounds write. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: wireshark.
Medium [CVE-2026-76879] Denial of Service via C12.22 protocol dissector crash
Denial of Service via C12.22 protocol dissector crash. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-617. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-76889] Denial of Service via UMTS FP protocol dissector crash
Denial of Service via UMTS FP protocol dissector crash. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-617. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-76886] Denial of Service via C12.22 protocol dissector crash
Denial of Service via C12.22 protocol dissector crash. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-617. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: wireshark.
Medium [CVE-2026-76883] Denial of Service via heap-based buffer overflow in Catapult DCT2000 file parser
Denial of Service via heap-based buffer overflow in Catapult DCT2000 file parser. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-76882] Denial of Service via Bluetooth Attribute Protocol dissector out-of-bounds read
Denial of Service via Bluetooth Attribute Protocol dissector out-of-bounds read. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-76881] Denial of service via CMS protocol dissector crash
Denial of service via CMS protocol dissector crash. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-76405] Information Disclosure through Cleartext Storage in the App Key Value Store in the Splunk On-Call (VictorOps) app
In Splunk On-Call (VictorOps) app versions below 1.0.43 on Splunkbase, a user who does not hold the "admin" or "power" Splunk roles could read a partially masked Application Programming Interface (API) key from the App Key Value Store (KV Store). The exposure is possible because the Splunk On-Call (VictorOps) app does not fully mask the API key before storing it in a KV Store collection that the user can read. For more information see About the app key value store ( ) in the Splunk documentation.
Medium [CVE-2026-76401] Regular Expression Denial of Service (DoS) through the REST API in Splunk Connect for Kafka
In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API could configure timestamp extraction with a crafted regular expression and matching event data to block a Kafka Connect worker thread, stopping event delivery for the affected connector. The vulnerability is possible because timestamp extraction evaluates customer-supplied regular expressions without a time limit. For more information see Install Splunk Connect for Kafka ( ) and Data ingestion parameters for Splunk Connect for Kafka ( ) in the Splunk documentation.
Medium [CVE-2026-76400] Denial of Service (DoS) through the REST API in Splunk Connect for Kafka
In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API and influence responses from a Hypertext Transfer Protocol (HTTP) Event Collector endpoint in Splunk Enterprise could cause the connector to retry failed event batches until event delivery stops. The vulnerability is possible because HTTP Event Collector delivery retry handling uses an unbounded default for failed batches instead of a finite retry limit. For more information see Install Splunk Connect for Kafka ( ), Data ingestion parameters for Splunk Connect for Kafka ( ), and Set up and use HTTP Event Collector with configuration files ( ) in the Splunk documentation.