Complete feed
Action required
Critical/high still unreviewed, or CISA KEV listed
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-66783] arbitrary image override enables privileged code execution on every node
arbitrary image override enables privileged code execution on every node. Red Hat rates this important (CVSS 8.2). Weakness: CWE-20. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.
High [CVE-2026-66782] broker API bearer token stored cleartext in CR spec
broker API bearer token stored cleartext in CR spec. Red Hat rates this important (CVSS 7.8). Weakness: CWE-312. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.
High [CVE-2026-75924] Hub addon-manager ClusterRole grants cluster-wide Secret read/write and CSR approval
Hub addon-manager ClusterRole grants cluster-wide Secret read/write and CSR approval. Red Hat rates this important (CVSS 8.7). Weakness: CWE-269. Affected product named by the advisory: Multicluster Engine for Kubernetes.
High [CVE-2026-71365] webhook status callback SSRF leaks the Git PAT
webhook status callback SSRF leaks the Git PAT. Red Hat rates this important (CVSS 7.7). Weakness: CWE-918. Red Hat lists fixing advisory RHSA-2026:59153 with package automation-controller-0:4.7.16-1.el9ap, ansible-automation-platform-26/controller-rhel9:1787244009, automation-controller-0:4.6.32-1.el8ap, ansible-automation-platform-27/controller-rhel9:1787220257. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Ansible Automation Platform 2.7.
High [CVE-2026-66793] arbitrary container image override via ManagedClusterAddOn annotation enables RCE on spoke
arbitrary container image override via ManagedClusterAddOn annotation enables RCE on spoke. Red Hat rates this important (CVSS 8.8). Weakness: CWE-20. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/acm-governance-policy-addon-controller-rhel9:1787227696, rhacm2/acm-governance-policy-addon-controller-rhel9:1787080755, rhacm2/acm-governance-policy-addon-controller-rhel9:1787259078, rhacm2/acm-governance-policy-addon-controller-rhel9:1787080753. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.
High [CVE-2026-63639] Remote code execution via use-after-free in stream deserialization
Remote code execution via use-after-free in stream deserialization. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: valkey.
High [CVE-2026-56684] Remote code execution via TLS pending-data processing use-after-free
Remote code execution via TLS pending-data processing use-after-free. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: valkey.
High [CVE-2026-74988] Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154
Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154. Red Hat rates this important (CVSS 7.5). Weakness: CWE-130.
High [CVE-2026-74947] Privilege escalation due to invalid pointer in the Graphics component
Privilege escalation due to invalid pointer in the Graphics component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825.
High [CVE-2026-74990] Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154
Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-74938] Mitigation bypass in the JavaScript: GC component
Mitigation bypass in the JavaScript: GC component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-807.
High [CVE-2026-74937] Use-after-free in the JavaScript: GC component
Use-after-free in the JavaScript: GC component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825.
High [CVE-2026-75874] Sandbox escape in the Remote Settings Client component
Sandbox escape in the Remote Settings Client component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-653.
High [CVE-2026-74987] Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154
Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-74948] Information disclosure in the Graphics component
Information disclosure in the Graphics component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-497. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-74946] Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-74949] Privilege escalation due to use-after-free in the Graphics: Canvas2D component
Privilege escalation due to use-after-free in the Graphics: Canvas2D component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-74943] Use-after-free in the Graphics: ImageLib component
Use-after-free in the Graphics: ImageLib component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-74942] Privilege escalation in the Remote Settings Client component
Privilege escalation in the Remote Settings Client component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-266. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-74944] Use-after-free in the DOM: Core & HTML component
Use-after-free in the DOM: Core & HTML component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.