Complete feed
Security advisories & CVEs
5205 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-33218] Denial of Service via malformed message pre-authentication on leafnode port
Denial of Service via malformed message pre-authentication on leafnode port. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1286. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779579439. Resolved in Red Hat advisory RHSA-2026:21769 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat multicluster global hub 1.4.3; Red Hat multicluster global hub 1.5.2.
High [CVE-2026-33217] Access control bypass via unapplied ACLs in MQTT namespace
Access control bypass via unapplied ACLs in MQTT namespace. Red Hat rates this important (CVSS 8.1). Weakness: CWE-425. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779579439. Resolved in Red Hat advisory RHSA-2026:21769 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat multicluster global hub 1.4.3; Red Hat multicluster global hub 1.5.2.
High [CVE-2026-33216] Information disclosure of MQTT passwords through monitoring endpoints
Information disclosure of MQTT passwords through monitoring endpoints. Red Hat rates this important (CVSS 8.6). Weakness: CWE-213. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779579439. Resolved in Red Hat advisory RHSA-2026:21769 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat multicluster global hub 1.4.3; Red Hat multicluster global hub 1.5.2.
High [CVE-2026-29785] Denial of Service via leafnode compression
Denial of Service via leafnode compression. Red Hat rates this important (CVSS 7.5). Weakness: CWE-409. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779579439. Resolved in Red Hat advisory RHSA-2026:21769 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat multicluster global hub 1.4.3; Red Hat multicluster global hub 1.5.2.
High [CVE-2026-27889] Denial of Service via malformed WebSockets frame
Denial of Service via malformed WebSockets frame. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1286. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779579439. Resolved in Red Hat advisory RHSA-2026:21769 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat multicluster global hub 1.4.3; Red Hat multicluster global hub 1.5.2.
High [CVE-2026-3104] Denial of Service via specially crafted domain query causing a memory leak
Denial of Service via specially crafted domain query causing a memory leak. Red Hat rates this important (CVSS 7.5). Weakness: CWE-772. Affected package(s): bind-main. Resolved in Red Hat advisory RHSA-2026:6935 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: BIND 9; Red Hat Hardened Images.
High [CVE-2026-1519] Denial of Service via maliciously crafted DNSSEC-validated zone
Denial of Service via maliciously crafted DNSSEC-validated zone. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected package(s): bind, bind9.16, bind9.18, rhcos, bind-main. Resolved in Red Hat advisory RHSA-2026:29863 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: BIND 9; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION; Red Hat Enterprise Linux 7 Extended Lifecycle Support; and 16 more.
High [CVE-2026-3608] Denial of Service via maliciously crafted message
Denial of Service via maliciously crafted message. Red Hat rates this important (CVSS 7.5). Weakness: CWE-617. Affected package(s): kea. Resolved in Red Hat advisory RHSA-2026:7342 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support.
High [CVE-2026-23375] deny THP for files on anonymous inodes
deny THP for files on anonymous inodes. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected package(s): kernel. Resolved in Red Hat advisory RHSA-2026:21557 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.
High [CVE-2025-67030] org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in extractFile method
org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in extractFile method. Red Hat rates this important (CVSS 8.3). Weakness: CWE-22. Affected package(s): eap8-jboss-logging, eap8-guava-failureaccess, eap8-activemq-artemis, eap8-netty-transport-native-epoll, eap8-reactivex-rxjava, eap8-wildfly-javadocs. Resolved in Red Hat advisory RHSA-2026:7109 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat JBoss EAP 8.1 for RHEL 8; Red Hat JBoss EAP 8.1 for RHEL 9; Red Hat Enterprise Linux AppStream EUS (v. 10.0); Red Hat Enterprise Linux AppStream (v. 10); and 32 more.
High [CVE-2026-23392] release flowtable after rcu grace period on error
release flowtable after rcu grace period on error. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected package(s): kernel, kernel-rt. Resolved in Red Hat advisory RHSA-2026:25120 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
Medium [CVE-2026-33809] Denial of Service via maliciously crafted TIFF file
Denial of Service via maliciously crafted TIFF file. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-1285. Affected package(s): golang1. Resolved in Red Hat advisory RHSA-2026:7385 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-34085] Security flaw allows arbitrary code execution or system crash
Security flaw allows arbitrary code execution or system crash. Red Hat rates this moderate (CVSS 6.6). Weakness: CWE-193. Affected package(s): fontconfig-main. Resolved in Red Hat advisory RHSA-2026:13722 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-3591] Unauthorized access due to use-after-return vulnerability in DNS query handling
Unauthorized access due to use-after-return vulnerability in DNS query handling. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-825. Affected package(s): bind-main. Resolved in Red Hat advisory RHSA-2026:6935 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-3119] Denial of Service via authenticated TKEY queries
Denial of Service via authenticated TKEY queries. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-237. Affected package(s): bind-main. Resolved in Red Hat advisory RHSA-2026:6935 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-4371] Out of bounds read in IMAP parsing
Out of bounds read in IMAP parsing. Red Hat rates this important (CVSS 8.2). Weakness: CWE-130. Affected package(s): thunderbird. Resolved in Red Hat advisory RHSA-2026:8286 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 9 more.
High [CVE-2026-33412] Arbitrary code execution via command injection in glob() function
Arbitrary code execution via command injection in glob() function. Red Hat rates this important (CVSS 7.3). Weakness: CWE-78. Affected package(s): rhcos, rhaiis/vllm-rocm-rhel9:1778244531, rhui5/cds-kubernetes-tp-rhel9:1777459441, rhui5/haproxy-rhel9:1776868744, rhui5/installer-rhel9:1776868772, vim. Resolved in Red Hat advisory RHSA-2026:6915 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; and 23 more.
High [CVE-2026-32647] Denial of Service or Code Execution via specially crafted MP4 files
Denial of Service or Code Execution via specially crafted MP4 files. Red Hat rates this important (CVSS 7.8). Weakness: CWE-125. Affected package(s): nginx-main, nginx, nginx:1.26, nginx:1.24, rhui5/cds-rhel9:1776868774, rhui5/rhua-rhel9:1776868842. Resolved in Red Hat advisory RHSA-2026:6906 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: NGINX Open Source; NGINX Plus; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; and 7 more.
High [CVE-2026-4775] Arbitrary code execution or denial of service via signed integer overflow in TIFF file processing
Arbitrary code execution or denial of service via signed integer overflow in TIFF file processing. Red Hat rates this important (CVSS 7.8). Weakness: CWE-190. Affected package(s): libtiff-main, rhaiis/model-opt-cuda-rhel9:1782352950, rhaiis/vllm-spyre-rhel9:1782352919, compat-libtiff3, libtiff, mingw-libtiff. Resolved in Red Hat advisory RHSA-2026:30349 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 13 more.
High [CVE-2026-27651] Denial of Service via undisclosed requests when ngx_mail_auth_http_module is enabled
Denial of Service via undisclosed requests when ngx_mail_auth_http_module is enabled. Red Hat rates this important (CVSS 7.5). Weakness: CWE-476. Affected package(s): nginx-main, nginx, nginx:1.26, nginx:1.24, rhui5/cds-rhel9:1776868774, rhui5/rhua-rhel9:1776868842. Resolved in Red Hat advisory RHSA-2026:6906 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: NGINX Open Source; NGINX Plus; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8; and 6 more.