Complete feed
Recently updated
Advisories the vendor has revised
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Critical [CVE-2026-62940] Incus has a project restriction bypass via instance migration config override
Incus has a project restriction bypass via instance migration config override. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-863.
Critical [CVE-2026-62867] Incus has an argument injection in storage volume block.create_options that leads to arbitrary command execution
Incus has an argument injection in storage volume block.create_options that leads to arbitrary command execution. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-88.
Critical [CVE-2026-48769] Incus has an arbitrary file write on its client due to trusted image hash
Incus has an arbitrary file write on its client due to trusted image hash. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-345.
Critical [CVE-2026-48755] Incus has an argument injection in backup compression algorithm leading to AFW and ACE
Incus has an argument injection in backup compression algorithm leading to AFW and ACE. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-88.
Critical [CVE-2026-48753] Incus has an arbitrary file write via path traversal in S3 multipart upload
Incus has an arbitrary file write via path traversal in S3 multipart upload. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-22.
Critical [CVE-2026-48752] Incus has arbitrary file read+write on host via templates/ symlink in malicious image
Incus has arbitrary file read+write on host via templates/ symlink in malicious image. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-61.
Critical [CVE-2026-48751] Incus has a restricted project bypass leading to arbitrary command execution
Incus has a restricted project bypass leading to arbitrary command execution. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-863.
Critical [CVE-2026-48750] Incus has an arbitrary file write on host via `exec-output` symlink in crafted image
Incus has an arbitrary file write on host via `exec-output` symlink in crafted image. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-61.
Critical [CVE-2026-48749] Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious image
Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious image. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-61.
High [CVE-2026-77219] Heap over-read leading to information disclosure via crafted image
Heap over-read leading to information disclosure via crafted image. Red Hat rates this important (CVSS 7.1). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: emacs.
High [CVE-2026-54789] Denial of Service via malformed state cookie parsing
Denial of Service via malformed state cookie parsing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: mod_auth_openidc.
High [CVE-2026-49114] Arbitrary file write via symlink following and path traversal
Arbitrary file write via symlink following and path traversal. Red Hat rates this important (CVSS 7.3). Weakness: CWE-367.
High [CVE-2026-77682] JavaScript code injection in autofill via unsanitized CSS selector from element id
JavaScript code injection in autofill via unsanitized CSS selector from element id. Red Hat rates this important (CVSS 7.1). Weakness: CWE-94.
High [CVE-2026-74581] use-after-free in fib6_rule_suppress due to stale res->rt6 pointer
use-after-free in fib6_rule_suppress due to stale res->rt6 pointer. Red Hat rates this important (CVSS 7.8). Weakness: CWE-416. Red Hat lists fixing advisory RHSA-2026:60485 with package kernel-0:5.14.0-427.147.1.el9_4, kernel-0:5.14.0-687.42.1.el9_8, kernel-0:5.14.0-570.136.1.el9_6, kernel-0:4.18.0-372.209.1.el8_6. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.
High [CVE-2026-74583] fix fastmap use-after-free on filter
fix fastmap use-after-free on filter. Red Hat rates this important (CVSS 7.8). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat package: kernel-rt.
High [CVE-2026-74580] reset the vring metadata cache on vring reconfiguration
reset the vring metadata cache on vring reconfiguration. Red Hat rates this important (CVSS 7.3). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-74582] use consistent hard_header_len in non-ring send paths
use consistent hard_header_len in non-ring send paths. Red Hat rates this important (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-77652] heap buffer overflow in WPG colormap parser via out-of-bounds palette index
heap buffer overflow in WPG colormap parser via out-of-bounds palette index. Red Hat rates this important (CVSS 7.8). Weakness: CWE-122.
High [CVE-2026-77658] stack buffer overflow in Bus object via unvalidated handle count in project files
stack buffer overflow in Bus object via unvalidated handle count in project files. Red Hat rates this important (CVSS 7.8). Weakness: CWE-121.
Medium [CVE-2026-44517] Build breakout via malicious Git repository or tar archive
Build breakout via malicious Git repository or tar archive. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-22. Affected products named by the advisory: Red Hat Certification Program for Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat OpenShift Container Platform 4; Red Hat OpenShift Dev Spaces; and 4 more. Affected products named by the advisory: Red Hat OpenStack Platform 18.0; Red Hat Quay 3; Red Hat package: buildah; Red Hat package: podman.