Complete feed
Security advisories & CVEs
7850 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-18297] Arbitrary code execution via OGG file parsing buffer overflow
Arbitrary code execution via OGG file parsing buffer overflow. Red Hat rates this important (CVSS 7.8). Weakness: CWE-120. Red Hat lists fixing advisory RHSA-2026:59097 with package gstreamer1-plugins-base-0:1.16.1-6.el8_10.1, gstreamer1-plugins-base-0:1.26.7-2.el10_2.1. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10.
High [CVE-2026-18296] Remote Code Execution via MRF file parsing heap-based buffer overflow
Remote Code Execution via MRF file parsing heap-based buffer overflow. Red Hat rates this important (CVSS 7.8). Weakness: CWE-120. Red Hat lists fixing advisory RHSA-2026:59152 with package gstreamer1-plugins-good-0:1.22.12-7.el9_8.8, gstreamer1-plugins-good-0:1.16.1-7.el8_10.7, gstreamer1-plugins-good-0:1.26.7-2.el10_2.7. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10.
High [CVE-2026-18295] Remote code execution via MRF file parsing
Remote code execution via MRF file parsing. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:59152 with package gstreamer1-plugins-good-0:1.22.12-7.el9_8.8, gstreamer1-plugins-good-0:1.16.1-7.el8_10.7. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.
High [CVE-2026-77176] Insufficient validation of CreateContainer mount and storage rules in genpolicy
Insufficient validation of CreateContainer mount and storage rules in genpolicy. Red Hat rates this important (CVSS 8.1). Weakness: CWE-73. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
High [CVE-2026-19611] Wildfly-elytron: org.wildfly.security/wildfly-elytron-password-impl: wildfly-elytron: password keyspace reduction via nfkc fullwidth folding
A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can collapse fullwidth characters to ASCII equivalents. A remote attacker can more easily guess affected passwords by using an ASCII-only dictionary against accounts whose passwords were intended to include those non-ASCII characters, leading to unauthorized access. This issue has Moderate impact. Successful exploitation depends on accounts using fullwidth or other NFKC-compatibility characters in passwords and on the feasibility of password guessing against the deployed hash algorithm. Red Hat severity: Moderate — CVSS 7.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N). Weakness: CWE-173. Affected Red Hat products: Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Debezium 3; Red Hat Build of Keycloak; Red Hat build of Quarkus; Red Hat Data Grid 8; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat Single Sign-On 7. Will not fix / out of support: Red Hat JBoss Enterprise Application Platform 7. Red Hat does not currently list a fixing RHSA for this CVE.
High [CVE-2026-49825] URL bypass vulnerability in Cleaner via missing xlink:href
URL bypass vulnerability in Cleaner via missing xlink:href. Red Hat rates this important (CVSS 8.2). Weakness: CWE-166. Affected products named by the advisory: Lightspeed Core; Migration Toolkit for Applications 8; Red Hat AI Inference Server; Red Hat Ansible Automation Platform 2; and 20 more. Affected products named by the advisory: Red Hat Ansible Automation Platform Ansible Core 2; Red Hat Ceph Storage 7; Red Hat Ceph Storage 8; Red Hat Ceph Storage 9; and 16 more.
High [CVE-2026-61898] Arbitrary code execution via shell injection
Arbitrary code execution via shell injection. Red Hat rates this important (CVSS 7.8). Weakness: CWE-78.
High [CVE-2026-61897] Local privilege escalation via incomplete privilege drop in language helper scripts
Local privilege escalation via incomplete privilege drop in language helper scripts. Red Hat rates this important (CVSS 7.8). Weakness: CWE-273.
High [CVE-2026-73198] Unauthenticated DoS in `/ipa/i18n_messages` via Unbounded Request Body Read
Unauthenticated DoS in `/ipa/i18n_messages` via Unbounded Request Body Read. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: ipa.
High [CVE-2026-13097] Privilege escalation via krbCanonicalName manipulation due to realm-unaware uniqueness enforcement in FreeIPA LDAP datastore
Privilege escalation via krbCanonicalName manipulation due to realm-unaware uniqueness enforcement in FreeIPA LDAP datastore. Red Hat rates this important (CVSS 8.7). Weakness: CWE-706. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-73197] Unauthenticated DoS in `/ipa/migration/migration.py` via Unbounded Request Body Read
Unauthenticated DoS in `/ipa/migration/migration.py` via Unbounded Request Body Read. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-18917] Libvirt: integer overflow in nodegetfreepages rpc handler leading to heap buffer overflow
A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This flaw allows crafted values to bypass a size check, leading to an undersized memory buffer. Subsequently, real NUMA node data can overwrite this buffer. This heap buffer overflow can corrupt the root libvirt daemon's memory, potentially leading to a denial of service or local privilege escalation. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-190. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: libvirt.
High [CVE-2026-19582] Stack Buffer Overflow in GNU Binutils in rsrc_print_name from an untrusted PE file
Stack Buffer Overflow in GNU Binutils in rsrc_print_name from an untrusted PE file. Red Hat rates this a security issue. Weakness: CWE-787. Affected products named by the advisory: Migration Toolkit for Containers; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4.
High [CVE-2026-28984] Processing maliciously crafted web content may lead to an unexpected Safari crash
Processing maliciously crafted web content may lead to an unexpected Safari crash. Red Hat rates this important (CVSS 8.8). Weakness: CWE-120. Red Hat lists fixing advisory RHSA-2026:25918 with package webkit2gtk3-0:2.52.4-1.el8_8, webkit2gtk3-0:2.52.4-1.el9_8, webkit2gtk3-0:2.52.4-1.el8_4, webkit2gtk3-0:2.52.4-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.
High [CVE-2026-64719] Processing maliciously crafted web content may lead to an unexpected Safari crash
Processing maliciously crafted web content may lead to an unexpected Safari crash. Red Hat rates this important (CVSS 8.8). Weakness: CWE-120.
High [CVE-2026-64787] Processing maliciously crafted web content may lead to an unexpected process termination
Processing maliciously crafted web content may lead to an unexpected process termination. Red Hat rates this important (CVSS 8.8). Weakness: CWE-416. Red Hat lists fixing advisory RHSA-2026:42088 with package webkit2gtk3-0:2.52.5-1.el8_10, webkit2gtk3-0:2.52.5-1.el9_2, webkit2gtk3-0:2.52.5-1.el8_4, webkit2gtk3-0:2.52.5-1.el9_4. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.
High [CVE-2026-64757] Processing maliciously crafted web content may lead to an unexpected Safari crash
Processing maliciously crafted web content may lead to an unexpected Safari crash. Red Hat rates this important (CVSS 8.8). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat package: webkitgtk3; Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.
High [CVE-2026-64783] Processing maliciously crafted web content may lead to an unexpected Safari crash
Processing maliciously crafted web content may lead to an unexpected Safari crash. Red Hat rates this important (CVSS 8.8). Weakness: CWE-416. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat package: webkitgtk3; Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.
Medium [CVE-2026-55894] Denial of Service via crafted SH2A bytecode
Denial of Service via crafted SH2A bytecode. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:59419 with package capstone-main-5.0.8-0.3.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: capstone.
Medium [CVE-2026-77643] Xapian xapian-core: Arbitrary code execution via incomplete HTML escaping
Xapian xapian-core: Arbitrary code execution via incomplete HTML escaping. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-79. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: xapian-core.