Skip to content
VulniPulse

Complete feed

Action required

Critical/high still unreviewed, or CISA KEV listed

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.5Apache

High [CVE-2026-73635] Allocation of resources without limits or throttling vulnerability in Apache Struts

Allocation of resources without limits or throttling vulnerability in Apache Struts. When no fixed locale is configured, the locale used for localized-text lookups is taken from the incoming request, allowing an unauthenticated remote client to cause the framework's internal localized-text caches to grow without bound and exhaust the Java heap, denying service to other users. Applications that configure a fixed locale are not affected. This issue affects Apache Struts: from 2.0.0 through 2.3.37, from 2.5.0 through 2.5.33, from 6.0.0 through 6.10.0, from 7.0.0 through 7.2.1. Users are recommended to upgrade to version 6.11.0 or 7.3.0, which fixes the issue.

CVE-2026-73635
Struts
Aug 15, 2026
High7.5Apache

High [CVE-2026-73634] Uncontrolled resource consumption vulnerability in Apache Struts

Uncontrolled resource consumption vulnerability in Apache Struts. An application that exposes an endpoint collecting Content Security Policy violation reports reads the submitted report into memory without bounding how much it will accept, so a single request can exhaust the heap and deny service to other users. Such endpoints are ordinarily reachable without authentication. The core distribution maps no such endpoint by default; applications that do not collect violation reports are not affected. This issue affects Apache Struts: from 6.0.0 through 6.10.0, from 7.0.0 through 7.2.1. Users are recommended to upgrade to version 6.11.0 or 7.3.0, which fixes the issue.

CVE-2026-73634
Struts
Aug 15, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-72310] fix overflow in passthrough ioctl bounds check

fix overflow in passthrough ioctl bounds check. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-72310
Linux Kernel
Aug 15, 2026
High7.0Red Hat

High [CVE-2026-72042] Fix user refcount underflow in event delivery

Fix user refcount underflow in event delivery. Red Hat rates this important (CVSS 7). Weakness: CWE-825.

CVE-2026-72042
Unclassified
Aug 15, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-72069] Fix the incorrect RCU protection in rt_spin_unlock

Fix the incorrect RCU protection in rt_spin_unlock(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-72069
Linux Kernel
Aug 15, 2026
High7.0Red Hat

High [CVE-2026-72220] harden rq_procinfo lifecycle to prevent double-free

harden rq_procinfo lifecycle to prevent double-free. Red Hat rates this important (CVSS 7). Weakness: CWE-1341. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.

CVE-2026-72220
Linux Kernel
Aug 15, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-72287] Move vTPR vs. TPR Threshold consistency check into "normal" checks

Move vTPR vs. TPR Threshold consistency check into "normal" checks. Red Hat rates this moderate (CVSS 7). Weakness: CWE-367. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.

CVE-2026-72287
Linux Kernel
Aug 15, 2026
High7.0Red Hat

High [CVE-2026-72248] support IPIP tunnel with direct xmit

support IPIP tunnel with direct xmit. Red Hat rates this important (CVSS 7). Weakness: CWE-824. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.

CVE-2026-72248
Linux Kernel
Aug 15, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-72051] require CAP_NET_ADMIN in the device netns for changelink

require CAP_NET_ADMIN in the device netns for changelink. Red Hat rates this moderate (CVSS 7). Weakness: CWE-270. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-72051
Linux Kernel
Aug 15, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-72361] Fix double-free of managed BO in error path

Fix double-free of managed BO in error path. Red Hat rates this moderate (CVSS 7). Weakness: CWE-1341. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-72361
Linux Kernel
Aug 15, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-72247] fix zone comparison in tuple dedup

fix zone comparison in tuple dedup. Red Hat rates this moderate (CVSS 7). Weakness: CWE-628. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-72247
Linux Kernel
Aug 15, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-72066] Bound hotplug states sysfs output

Bound hotplug states sysfs output. Red Hat rates this moderate (CVSS 7). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-72066
Linux Kernel
Aug 15, 2026
High7.0Red Hat

High [CVE-2026-68470] validate extension-frame layout before RX

validate extension-frame layout before RX. Red Hat rates this important (CVSS 7). Weakness: CWE-1285. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-68470
Linux Kernel
Aug 15, 2026
High7.8Red Hat Updated

High [CVE-2026-72052] require CAP_NET_ADMIN in the device netns for changelink

require CAP_NET_ADMIN in the device netns for changelink. Red Hat rates this important (CVSS 7.8). Weakness: CWE-266. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-72052
Linux Kernel
Aug 15, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-68458] cache secctx size before release zeroes it

cache secctx size before release zeroes it. Red Hat rates this moderate (CVSS 7). Weakness: CWE-120.

CVE-2026-68458
Unclassified
Aug 15, 2026
High7.0Red Hat

High [CVE-2026-72061] require CAP_NET_ADMIN in the device netns for changelink

require CAP_NET_ADMIN in the device netns for changelink. Red Hat rates this important (CVSS 7). Weakness: CWE-266. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-72061
Linux Kernel
Aug 15, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-72065] Validate the packet length reported by the NIC

Validate the packet length reported by the NIC. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-72065
Linux Kernel
Aug 15, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-72095] Make dma_fence_dedup_array robust against 0-count input

Make dma_fence_dedup_array() robust against 0-count input. Red Hat rates this moderate (CVSS 7). Weakness: CWE-824. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-72095
Linux Kernel
Aug 15, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-72123] defer rx_op deallocation to workqueue to fix thrtimer UAF

defer rx_op deallocation to workqueue to fix thrtimer UAF. Red Hat rates this moderate (CVSS 7). Weakness: CWE-364. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-72123
Linux Kernel
Aug 15, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-68479] validate firmware patch bounds

validate firmware patch bounds. Red Hat rates this moderate (CVSS 7). Weakness: CWE-805. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-68479
Linux Kernel
Aug 15, 2026