Complete feed
Action required
Critical/high still unreviewed, or CISA KEV listed
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-55194] Heap-buffer-overflow allows arbitrary code execution via crafted RPC response
Heap-buffer-overflow allows arbitrary code execution via crafted RPC response. Red Hat rates this important (CVSS 8.8). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: freerdp.
High [CVE-2026-55193] Remote code execution or client crash via malicious TS Gateway
Remote code execution or client crash via malicious TS Gateway. Red Hat rates this important (CVSS 8.8). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: freerdp.
High [CVE-2026-55191] Arbitrary code execution via heap-buffer-overflow in AVC444 YUV buffer allocation
Arbitrary code execution via heap-buffer-overflow in AVC444 YUV buffer allocation. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: freerdp.
High [CVE-2026-75147] Information disclosure or denial of service via crafted AV1 RTP packet
Information disclosure or denial of service via crafted AV1 RTP packet. Red Hat rates this important (CVSS 7.1). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-75146] Information disclosure and denial of service via out-of-bounds read in DASH demuxer
Information disclosure and denial of service via out-of-bounds read in DASH demuxer. Red Hat rates this important (CVSS 8.1). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-75144] Memory corruption via crafted Dirac data unit
Memory corruption via crafted Dirac data unit. Red Hat rates this important (CVSS 7.8). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-75142] Stack Buffer Overflow in MPEG-PS Muxer
Stack Buffer Overflow in MPEG-PS Muxer. Red Hat rates this important (CVSS 7.8). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-20320] Cisco BroadWorks Out-of-Band Blind XML External Entity Injection Vulnerability
A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an unauthenticated, remote attacker to read sensitive configuration information on an affected system. This vulnerability exists because XML entries are improperly parsed due to external entity resolution being allowed by default. An attacker could exploit this vulnerability by sending a crafted XML message to the Open Client Interface – Provisioning (OCI-P) service. A successful exploit could allow the attacker to view sensitive files from the filesystem with the privileges of the Cisco BroadWorks user. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
High [CVE-2026-76233] Arbitrary command execution via gleam manager command injection
Arbitrary command execution via gleam manager command injection. Red Hat rates this important (CVSS 7.8). Weakness: CWE-78.
High [CVE-2026-76222] Arbitrary file creation via path traversal in.gitmodules submodule names
Arbitrary file creation via path traversal in.gitmodules submodule names. Red Hat rates this important (CVSS 8.2). Weakness: CWE-22. Affected products named by the advisory: Exploit Intelligence; Migration Toolkit for Applications 8; Red Hat AI Inference Server; Red Hat Ansible Automation Platform 2; and 5 more. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI); Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; and 1 more.
High [CVE-2026-76221] Arbitrary code execution via config-name injection
Arbitrary code execution via config-name injection. Red Hat rates this important (CVSS 8.8). Weakness: CWE-78. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat Satellite 6.
High [CVE-2026-76220] Arbitrary command execution via crafted kwargs
Arbitrary command execution via crafted kwargs. Red Hat rates this important (CVSS 8.8). Weakness: CWE-78. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat Satellite 6.
High [CVE-2026-76219] Arbitrary File Overwrite via `git read-tree` option injection
Arbitrary File Overwrite via `git read-tree` option injection. Red Hat rates this important (CVSS 8.1). Weakness: CWE-88. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat Satellite 6.
High [CVE-2026-76218] Remote Code Execution via malicious Git hooks
Remote Code Execution via malicious Git hooks. Red Hat rates this important (CVSS 7.5). Weakness: CWE-94. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat Satellite 6.
High [CVE-2020-37267] Information disclosure via unredacted logging of authorization tokens
Information disclosure via unredacted logging of authorization tokens. Red Hat rates this important (CVSS 7.5). Weakness: CWE-538.
High [CVE-2026-43961] Vimscript injection via unescaped filename in netrw s:NetrwMarkFile filter expression allows arbitrary code execution
Vimscript injection via unescaped filename in netrw s:NetrwMarkFile() filter() expression allows arbitrary code execution. Red Hat rates this important (CVSS 7.8). Weakness: CWE-94.
High [CVE-2026-19489] Vulnerability in NetScaler ADC and NetScaler Gateway
Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
High [CVE-2026-76235] unauthenticated remote memory leak via CockpitLang cookie in send_login_html
unauthenticated remote memory leak via CockpitLang cookie in send_login_html. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-401. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-58081] Heap-based buffer overflow in encoding modules
Heap-based buffer overflow in encoding modules. Red Hat rates this important (CVSS 7.3). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: php.
Critical [CVE-2026-21580] This Critical severity Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability was introduced in versions 7.1.1, 7.4.0, 7.13.0, 7.17.0, 7.19.0, 8.0.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence Data Center and Server
This Critical severity Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability was introduced in versions 7.1.1, 7.4.0, 7.13.0, 7.17.0, 7.19.0, 8.0.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence Data Center and Server. This Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability, with a CVSS Score of 8.6, allows an unauthenticated attacker to execute arbitrary HTML or JavaScript code on a victims browser, perform actions as a higher-privileged user, and to get into the system utilizing loopholes exposed from security best-practices being overlooked. Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Confluence Data Center and Server 9.2: Upgrade to a release greater than or equal to 9.2.21 See the release notes ([ ]). This vulnerability was reported via our Bug Bounty program. Affected products named by the advisory: Confluence Server.