Complete feed
Security advisories & CVEs
5207 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-4325] Replay of action tokens via improper handling of single-use entries
Replay of action tokens via improper handling of single-use entries. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-653. Affected package(s): rhbk/keycloak-rhel9-operator:26.2, rhbk/keycloak-rhel9, rhbk/keycloak-operator-bundle:26.4.11, rhbk/keycloak-rhel9:26.2, rhbk/keycloak-operator-bundle:26.2.15, rhbk/keycloak-rhel9-operator:26.4. Resolved in Red Hat advisory RHSA-2026:6478 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Low [CVE-2026-35388] Low integrity impact from unconfirmed proxy-mode multiplexing sessions
Low integrity impact from unconfirmed proxy-mode multiplexing sessions. Red Hat rates this low (CVSS 2.2). Weakness: CWE-306. Affected package(s): openssh, rhaiis/model-opt-cuda-rhel9:1780681984, discovery/discovery-ui-rhel9:1778156756, rhui5/rhua-rhel9:1779798222, discovery/discovery-server-rhel9:1778101579, rhui5/installer-rhel9:1779798165. Resolved in Red Hat advisory RHSA-2026:14937 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
Low [CVE-2026-35387] Information disclosure due to unintended cryptographic algorithm usage
Information disclosure due to unintended cryptographic algorithm usage. Red Hat rates this low (CVSS 3.1). Weakness: CWE-115. Affected package(s): openssh, rhaiis/model-opt-cuda-rhel9:1780681984, rhui5/rhua-rhel9:1779798222, discovery/discovery-server-rhel9:1778101579, rhui5/installer-rhel9:1779798165. Resolved in Red Hat advisory RHSA-2026:14937 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
Low [CVE-2026-35386] Arbitrary command execution via shell metacharacters in username
Arbitrary command execution via shell metacharacters in username. Red Hat rates this low (CVSS 3.6). Weakness: CWE-78. Affected package(s): openssh, rhaiis/model-opt-cuda-rhel9:1780681984, rhui5/rhua-rhel9:1779798222, discovery/discovery-server-rhel9:1778101579, rhui5/installer-rhel9:1779798165. Resolved in Red Hat advisory RHSA-2026:14937 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
Critical [CVE-2026-34875] Mbed TLS and TF-PSA-Crypto: Arbitrary code execution due to buffer overflow in FFDH key export
Mbed TLS and TF-PSA-Crypto: Arbitrary code execution due to buffer overflow in FFDH key export. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-120. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-34873] Client impersonation during TLS 1.3 session resumption
Client impersonation during TLS 1.3 session resumption. Red Hat rates this critical (CVSS 10). Weakness: CWE-290. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-34545] Remote code execution via crafted EXR files
Remote code execution via crafted EXR files. Red Hat rates this important (CVSS 8.8). Weakness: CWE-1284. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-27489] Information Disclosure via Path Traversal Vulnerability
Information Disclosure via Path Traversal Vulnerability. Red Hat rates this important (CVSS 8.6). Weakness: CWE-22. Affected package(s): rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9:1780078429, rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9:1780417775, rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9:1780078388, rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9:1780069222, rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9:1780078632, rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9:1780078312. Resolved in Red Hat advisory RHSA-2026:24977 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-35092] Denial of Service via integer overflow in join message validation
Denial of Service via integer overflow in join message validation. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-190. Affected package(s): corosync. Resolved in Red Hat advisory RHSA-2026:19043 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.
High [CVE-2026-35091] Denial of Service and information disclosure via crafted UDP packet
Denial of Service and information disclosure via crafted UDP packet. Red Hat rates this moderate (CVSS 8.2). Weakness: CWE-253. Affected package(s): corosync. Resolved in Red Hat advisory RHSA-2026:19043 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.
High [CVE-2026-23401] Linux kernel KVM: Privilege escalation or denial of service due to improper shadow page table entry handling
Linux kernel KVM: Privilege escalation or denial of service due to improper shadow page table entry handling. Red Hat rates this important (CVSS 8.1). Weakness: CWE-416. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:13936 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Telecommunications Update Service; Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions; and 6 more.
High [CVE-2026-35093] Unauthorized code execution and information disclosure through Lua bytecode plugins
Unauthorized code execution and information disclosure through Lua bytecode plugins. Red Hat rates this important (CVSS 8.8). Weakness: CWE-94. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-34872] Mbed TLS and TF-PSA-Crypto: Shared secret manipulation via improper FFDH input validation
Mbed TLS and TF-PSA-Crypto: Shared secret manipulation via improper FFDH input validation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1287. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-5272] Heap buffer overflow in GPU
Heap buffer overflow in GPU. Red Hat rates this important (CVSS 9.6). Weakness: CWE-120. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-5284] Use after free in Dawn
Use after free in Dawn. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-5278] Use after free in Web MIDI
Use after free in Web MIDI. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-5285] Use after free in WebGL
Use after free in WebGL. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-5274] Integer overflow in Codecs
Integer overflow in Codecs. Red Hat rates this important (CVSS 9.6). Weakness: CWE-190. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-5275] Heap buffer overflow in ANGLE
Heap buffer overflow in ANGLE. Red Hat rates this important (CVSS 9.6). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-5273] Use after free in CSS
Use after free in CSS. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.