Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

7850 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Critical9.8Red Hat Updated

Critical [CVE-2026-75143] FFmpeg Heap Buffer Overflow via RIST Protocol Reader

FFmpeg Heap Buffer Overflow via RIST Protocol Reader. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-120.

CVE-2026-75143
Unclassified
Aug 19, 2026
Critical9.3Vendor: HighRed Hat

Critical [CVE-2026-66794] unauthenticated SSRF to arbitrary managed-cluster services via public Route

unauthenticated SSRF to arbitrary managed-cluster services via public Route. Red Hat rates this important (CVSS 9.3). Weakness: CWE-918. Red Hat lists fixing advisory RHSA-2026:59593 with package multicluster-engine/cluster-proxy-addon-rhel9:1787275519, multicluster-engine/cluster-proxy-rhel9:1787276784, multicluster-engine/cluster-proxy-addon-rhel9:1787275318, multicluster-engine/cluster-proxy-addon-rhel9:1787274923. Affected product named by the advisory: Multicluster Engine for Kubernetes.

CVE-2026-66794
Unclassified
Aug 19, 2026
High8.0Red Hat Updated

High [CVE-2026-76139] Bundle build execs unpinned stolostron/release@master with full build credentials

Bundle build execs unpinned stolostron/release@master with full build credentials. Red Hat rates this important (CVSS 8). Weakness: CWE-829. Red Hat lists fixing advisory RHSA-2026:60401 with package rhacm2/acm-operator-bundle:1787712120, rhacm2/acm-operator-bundle:1787738299, rhacm2/acm-operator-bundle:1787704547, rhacm2/acm-operator-bundle:1787711895. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.

CVE-2026-76139
Unclassified
Aug 19, 2026
High7.1Red Hat Updated

High [CVE-2026-68553] Format string vulnerability leads to denial of service and information disclosure

Format string vulnerability leads to denial of service and information disclosure. Red Hat rates this important (CVSS 7.1). Weakness: CWE-134.

CVE-2026-68553
Unclassified
Aug 19, 2026
High7.7Red Hat

High [CVE-2026-75569] Bundle-generation business logic fetched from mutable stolostron/release@master

Bundle-generation business logic fetched from mutable stolostron/release@master. Red Hat rates this important (CVSS 7.7). Weakness: CWE-829. Red Hat lists fixing advisory RHSA-2026:59643 with package multicluster-engine/mce-operator-bundle:1787318262, multicluster-engine/mce-operator-bundle:1787321579, multicluster-engine/mce-operator-bundle:1787263075, multicluster-engine/mce-operator-bundle:1787317415. Affected product named by the advisory: Multicluster Engine for Kubernetes.

CVE-2026-75569
Unclassified
Aug 19, 2026
High8.8Red Hat Updated

High [CVE-2026-63633] Arbitrary code execution via heap buffer overflow in Opus audio decode

Arbitrary code execution via heap buffer overflow in Opus audio decode. Red Hat rates this important (CVSS 8.8). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: freerdp.

CVE-2026-63633
Red Hat Enterprise Linux
Aug 19, 2026
High8.2Red Hat

High [CVE-2026-50152] MON subscription handler exposes config-key store to low-privilege CephX users

MON subscription handler exposes config-key store to low-privilege CephX users. Red Hat rates this important (CVSS 8.2). Weakness: CWE-862. Affected products named by the advisory: Red Hat Ceph Storage 4; Red Hat Ceph Storage 5; Red Hat Ceph Storage 6; Red Hat Ceph Storage 7; and 2 more. Affected products named by the advisory: Red Hat Ceph Storage 8; Red Hat Ceph Storage 9.

CVE-2026-50152
Unclassified
Aug 19, 2026
High8.2Red Hat

High [CVE-2026-54330] RGW SigV4 verifier allows attachment of arbitrary unsigned x-amz-* headers leading to privilege escalation

RGW SigV4 verifier allows attachment of arbitrary unsigned x-amz-* headers leading to privilege escalation. Red Hat rates this important (CVSS 8.2). Weakness: CWE-347. Affected products named by the advisory: Red Hat Ceph Storage 4; Red Hat Ceph Storage 5; Red Hat Ceph Storage 6; Red Hat Ceph Storage 7; and 2 more. Affected products named by the advisory: Red Hat Ceph Storage 8; Red Hat Ceph Storage 9.

CVE-2026-54330
Unclassified
Aug 19, 2026
High8.5Red Hat

High [CVE-2026-39944] RGW STS session tokens vulnerable to CBC bit-flip attack enabling admin privilege escalation

RGW STS session tokens vulnerable to CBC bit-flip attack enabling admin privilege escalation. Red Hat rates this important (CVSS 8.5). Weakness: CWE-327. Affected products named by the advisory: Red Hat Ceph Storage 4; Red Hat Ceph Storage 5; Red Hat Ceph Storage 6; Red Hat Ceph Storage 7; and 2 more. Affected products named by the advisory: Red Hat Ceph Storage 8; Red Hat Ceph Storage 9.

CVE-2026-39944
Unclassified
Aug 19, 2026
High8.1Red Hat Updated

High [CVE-2026-55192] Out-of-bounds read leads to memory disclosure or client crash

Out-of-bounds read leads to memory disclosure or client crash. Red Hat rates this important (CVSS 8.1). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: freerdp.

CVE-2026-55192
Red Hat Enterprise Linux
Aug 19, 2026
High8.8Red Hat Updated

High [CVE-2026-55194] Heap-buffer-overflow allows arbitrary code execution via crafted RPC response

Heap-buffer-overflow allows arbitrary code execution via crafted RPC response. Red Hat rates this important (CVSS 8.8). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: freerdp.

CVE-2026-55194
Red Hat Enterprise Linux
Aug 19, 2026
High8.8Red Hat Updated

High [CVE-2026-55193] Remote code execution or client crash via malicious TS Gateway

Remote code execution or client crash via malicious TS Gateway. Red Hat rates this important (CVSS 8.8). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: freerdp.

CVE-2026-55193
Red Hat Enterprise Linux
Aug 19, 2026
High8.8Red Hat Updated

High [CVE-2026-55191] Arbitrary code execution via heap-buffer-overflow in AVC444 YUV buffer allocation

Arbitrary code execution via heap-buffer-overflow in AVC444 YUV buffer allocation. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: freerdp.

CVE-2026-55191
Red Hat Enterprise Linux
Aug 19, 2026
High7.1Red Hat Updated

High [CVE-2026-75147] Information disclosure or denial of service via crafted AV1 RTP packet

Information disclosure or denial of service via crafted AV1 RTP packet. Red Hat rates this important (CVSS 7.1). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-75147
Unclassified
Aug 19, 2026
High8.1Red Hat Updated

High [CVE-2026-75146] Information disclosure and denial of service via out-of-bounds read in DASH demuxer

Information disclosure and denial of service via out-of-bounds read in DASH demuxer. Red Hat rates this important (CVSS 8.1). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-75146
Unclassified
Aug 19, 2026
High7.8Red Hat Updated

High [CVE-2026-75144] Memory corruption via crafted Dirac data unit

Memory corruption via crafted Dirac data unit. Red Hat rates this important (CVSS 7.8). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-75144
Unclassified
Aug 19, 2026
High7.8Red Hat Updated

High [CVE-2026-75142] Stack Buffer Overflow in MPEG-PS Muxer

Stack Buffer Overflow in MPEG-PS Muxer. Red Hat rates this important (CVSS 7.8). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).

CVE-2026-75142
Unclassified
Aug 19, 2026
High7.8Red Hat Updated

High [CVE-2026-76233] Arbitrary command execution via gleam manager command injection

Arbitrary command execution via gleam manager command injection. Red Hat rates this important (CVSS 7.8). Weakness: CWE-78.

CVE-2026-76233
Unclassified
Aug 19, 2026
High8.2Red Hat Updated

High [CVE-2026-76222] Arbitrary file creation via path traversal in.gitmodules submodule names

Arbitrary file creation via path traversal in.gitmodules submodule names. Red Hat rates this important (CVSS 8.2). Weakness: CWE-22. Affected products named by the advisory: Exploit Intelligence; Migration Toolkit for Applications 8; Red Hat AI Inference Server; Red Hat Ansible Automation Platform 2; and 5 more. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI); Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; and 1 more.

CVE-2026-76222
Unclassified
Aug 19, 2026
High8.8Red Hat Updated

High [CVE-2026-76221] Arbitrary code execution via config-name injection

Arbitrary code execution via config-name injection. Red Hat rates this important (CVSS 8.8). Weakness: CWE-78. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat Satellite 6.

CVE-2026-76221
Unclassified
Aug 19, 2026