Complete feed
Recently updated
Advisories the vendor has revised
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-59296] Line-protocol and log injection via unsanitized input allows metric and log spoofing
Line-protocol and log injection via unsanitized input allows metric and log spoofing. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-93. Affected products named by the advisory: Exploit Intelligence; Red Hat AMQ Broker 7; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; and 9 more. Affected products named by the advisory: Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; Red Hat Build of Keycloak; Red Hat build of Quarkus; and 5 more.
Medium [CVE-2026-77679] path traversal in WebExtension XPI extraction (ZIP slip)
path traversal in WebExtension XPI extraction (ZIP slip). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-22.
Critical [CVE-2026-76018] Arbitrary Code Execution via crafted file in Import component
Arbitrary Code Execution via crafted file in Import component. Red Hat rates this important (CVSS 9.6). Weakness: CWE-641.
Critical [CVE-2026-67567] HelmRelease chart applied with controller SA without GVK or namespace restriction
HelmRelease chart applied with controller SA without GVK or namespace restriction. Red Hat rates this important (CVSS 9.9). Weakness: CWE-441. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/multicluster-operators-subscription-rhel9:1787242108, rhacm2/multicluster-operators-subscription-rhel9:1787263693, rhacm2/multicluster-operators-subscription-rhel9:1787242321, rhacm2/multicluster-operators-subscription-rhel9:1787240030. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat Advanced Cluster Management for Kubernetes 2.17.
Critical [CVE-2026-66788] arbitrary local-namespace injection via attacker-controlled LabelSourceNamespace
arbitrary local-namespace injection via attacker-controlled LabelSourceNamespace. Red Hat rates this important (CVSS 9.9). Weakness: CWE-284. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.
Critical [CVE-2026-66785] unvalidated Endpoint.Spec.Subnets propagated into WireGuard AllowedIPs / IPsec enables traffic hijack
unvalidated Endpoint. Spec. Subnets propagated into WireGuard AllowedIPs / IPsec enables traffic hijack. Red Hat rates this important (CVSS 9.9). Weakness: CWE-20. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.
Critical [CVE-2026-11861] Obtaining TGS with impersonating cname through trust relationships
Obtaining TGS with impersonating cname through trust relationships. Red Hat rates this moderate (CVSS 9.6). Weakness: CWE-266. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: ipa.
High [CVE-2026-72848] Server-Side Request Forgery and Information Disclosure via nested sitemap entries
Server-Side Request Forgery and Information Disclosure via nested sitemap entries. Red Hat rates this important (CVSS 8.6). Weakness: CWE-918. Affected products named by the advisory: Exploit Intelligence; Migration Toolkit for Applications 8; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-55893] Heap buffer overflow with potential code execution
Heap buffer overflow with potential code execution. Red Hat rates this moderate (CVSS 7). Weakness: CWE-805. Red Hat lists fixing advisory RHSA-2026:59419 with package capstone-main-5.0.8-0.3.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: capstone.
High [CVE-2026-73137] cross-namespace Secret exfiltration via HelmRelease.repo.secretRef.namespace
cross-namespace Secret exfiltration via HelmRelease.repo.secretRef.namespace. Red Hat rates this important (CVSS 7.7). Weakness: CWE-200. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/multicluster-operators-subscription-rhel9:1787242108, rhacm2/multicluster-operators-subscription-rhel9:1787263693, rhacm2/multicluster-operators-subscription-rhel9:1787242321, rhacm2/multicluster-operators-subscription-rhel9:1787240030. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat Advanced Cluster Management for Kubernetes 2.17.
High [CVE-2026-43678] Denial of Service via specially crafted WebSocket frame
Denial of Service via specially crafted WebSocket frame. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-53587] Denial of Service due to heap out-of-bounds read from malicious Git server
Denial of Service due to heap out-of-bounds read from malicious Git server. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:59361 with package libgit2-main-1.9.7-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat package: rust; Red Hat package: libgit2.
High [CVE-2026-66787] cross-cluster DNS spoofing via unvalidated EndpointSlice and ServiceImport IPs
cross-cluster DNS spoofing via unvalidated EndpointSlice and ServiceImport IPs. Red Hat rates this important (CVSS 8.7). Weakness: CWE-345. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.
High [CVE-2026-63387] Off-by-one stack buffer overflow leading to denial of service or data corruption
Off-by-one stack buffer overflow leading to denial of service or data corruption. Red Hat rates this important (CVSS 8.6). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat package: libevent2.
High [CVE-2026-63384] Denial of Service via integer conversion error in `evtag_unmarshal_header`
Denial of Service via integer conversion error in `evtag_unmarshal_header`. Red Hat rates this important (CVSS 7.5). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:60853 with package libevent-main-2.1.12-19.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat package: libevent2.
High [CVE-2026-63495] Remote denial of service via unbounded memory accumulation in WebSocket server
Remote denial of service via unbounded memory accumulation in WebSocket server. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:41176 with package libevent-main-2.1.12-19.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: libevent2.
High [CVE-2026-63383] Denial of Service via malformed RPC data
Denial of Service via malformed RPC data. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:60853 with package libevent-main-2.1.12-19.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat package: libevent2.
High [CVE-2026-63388] Arbitrary code execution via heap out-of-bounds write in AF_UNIX handling
Arbitrary code execution via heap out-of-bounds write in AF_UNIX handling. Red Hat rates this important (CVSS 8.4). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:60853 with package libevent-main-2.1.12-19.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat package: libevent2.
High [CVE-2026-54770] Open redirect vulnerability leading to phishing and token theft
Open redirect vulnerability leading to phishing and token theft. Red Hat rates this important (CVSS 7.4). Weakness: CWE-601. Affected products named by the advisory: Red Hat Ceph Storage 4; Red Hat Ceph Storage 7; Red Hat Ceph Storage 8; Red Hat Enterprise Linux 6; and 7 more. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat OpenShift Container Platform 4; Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; and 3 more.
High [CVE-2026-15679] Hugging Face PyTorch Image Models: Remote Code Execution via Deserialization of Untrusted Data
Hugging Face PyTorch Image Models: Remote Code Execution via Deserialization of Untrusted Data. Red Hat rates this important (CVSS 8.8). Weakness: CWE-502. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).