Complete feed
Security advisories & CVEs
302 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Low [CVE-2026-74976] JIT miscompilation in the JavaScript Engine: JIT component
JIT miscompilation in the JavaScript Engine: JIT component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-733. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Low [CVE-2026-23938] Denial of Service via crafted JavaScript scripts
Denial of Service via crafted JavaScript scripts. Red Hat rates this low (CVSS 2.7). Weakness: CWE-770.
Low [CVE-2026-60589] Improve Resource Resolving (2026-08 Security Update)
Improve Resource Resolving (2026-08 Security Update). Red Hat rates this moderate (CVSS 3.7). Red Hat lists fixing advisory RHSA-2026:55788 with package java-21-openjdk-portable-main-21.0.12.1.1-0.1.hum1, java-25-openjdk-1:25.0.4.1.1-1.1.el9, java-25-openjdk-windows, java-25-openjdk-main-25.0.4.1.1-1.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8.
Low [CVE-2026-74797] Denial of Service via malicious zip archives
Denial of Service via malicious zip archives. Red Hat rates this low (CVSS 3.1). Weakness: CWE-400.
Low [CVE-2026-63650] User misidentification via ignored X.509 identity field
User misidentification via ignored X.509 identity field. Red Hat rates this low (CVSS 3.1). Weakness: CWE-303.
Low [CVE-2026-66807] potential XSS via dangerouslySetInnerHTML with unescaped resource name in getCodeSpan
potential XSS via dangerouslySetInnerHTML with unescaped resource name in getCodeSpan. Red Hat rates this low (CVSS 3.1). Weakness: CWE-79. Affected products named by the advisory: Multicluster Engine for Kubernetes; Red Hat Advanced Cluster Management for Kubernetes 2.
Low [CVE-2026-55987] Administrator-deactivated accounts can be reactivated via OAuth2 sign-in
Administrator-deactivated accounts can be reactivated via OAuth2 sign-in. Red Hat rates this low (CVSS 3.5). Weakness: CWE-807.
Low [CVE-2026-55984] Denial of Service via Null Pointer Dereference in AddTime API
Denial of Service via Null Pointer Dereference in AddTime API. Red Hat rates this low (CVSS 2.7). Weakness: CWE-476.
Low [CVE-2026-73626] Extension allowlist bypass allows unauthorized installations
Extension allowlist bypass allows unauthorized installations. Red Hat rates this low. Weakness: CWE-358.
Low [CVE-2026-73492] Arbitrary code execution due to URI scheme bypass
Arbitrary code execution due to URI scheme bypass. Red Hat rates this low (CVSS 3.7). Weakness: CWE-76. Affected products named by the advisory: Red Hat 3scale API Management Platform 2; Red Hat Satellite 6.
Low [CVE-2026-73491] Cross-Site Scripting via malformed `javascript:` URI parsing
Cross-Site Scripting via malformed `javascript:` URI parsing. Red Hat rates this low (CVSS 3.7). Weakness: CWE-1289.
Low [CVE-2026-73281] ssh-agent allows remote execution of local operations
ssh-agent allows remote execution of local operations. Red Hat rates this low (CVSS 3.5). Weakness: CWE-266. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: openssh.
Low [CVE-2026-73071] Denial of Service via Use-After-Free in JSON Decoding
Denial of Service via Use-After-Free in JSON Decoding. Red Hat rates this low (CVSS 3.3). Weakness: CWE-416.
Low [CVE-2026-18503] Denial of Service via super-linear regular expression work in csv.Sniffer.sniff
Denial of Service via super-linear regular expression work in csv. Sniffer.sniff(). Red Hat rates this low (CVSS 2.8). Weakness: CWE-1333. Red Hat lists fixing advisory RHSA-2026:54534 with package python3-10-main-3.10.21-1.hum1, python3-14-main-3.14.7-1.hum1, python3-13-main-3.13.15-1.hum1, python3-11-main-3.11.16-1.hum1.
Low [CVE-2026-66484] GNU cpio: Path Traversal allows creating hard links outside intended directory via malicious tar archives.
GNU cpio: Path Traversal allows creating hard links outside intended directory via malicious tar archives. Red Hat rates this low (CVSS 3.3). Weakness: CWE-22. Red Hat lists fixing advisory RHSA-2026:54508 with package cpio-main-2.15-10.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat package: cpio.
Low [CVE-2026-71391] off-by-one error via a malicious font file
off-by-one error via a malicious font file. Red Hat rates this low (CVSS 3.3). Weakness: CWE-193.
Low [CVE-2026-19411] shim/dp.c library: NULL-pointer dereference in is_removable_media_path when DevicePathToStr returns NULL
shim/dp.c library: NULL-pointer dereference in is_removable_media_path() when DevicePathToStr() returns NULL. Red Hat rates this low (CVSS 3.9). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Low [CVE-2026-12372] Server-Side Request Forgery via improper network URL validation
Server-Side Request Forgery via improper network URL validation. Red Hat rates this low (CVSS 3.7). Weakness: CWE-918. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 1 more. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI).
Low [CVE-2026-61477] newline injection in network XML DNS TXT/SRV fields allows dnsmasq config directive injection
newline injection in network XML DNS TXT/SRV fields allows dnsmasq config directive injection. Red Hat rates this low (CVSS 2.3). Weakness: CWE-93. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26.
Low [CVE-2026-71326] Authenticated identity spoofing via BasicAuth key collision
Authenticated identity spoofing via BasicAuth key collision. Red Hat rates this low (CVSS 3.8). Weakness: CWE-836.