Complete feed
Security advisories & CVEs
5198 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-27888] Denial of Service via crafted PDF
Denial of Service via crafted PDF. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-1050. Affected package(s): rhoai/odh-llama-stack-core-rhel9:1775144403. Resolved in Red Hat advisory RHSA-2026:10184 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-27606] Remote Code Execution via Path Traversal Vulnerability
Remote Code Execution via Path Traversal Vulnerability. Red Hat rates this important (CVSS 9.1). Weakness: CWE-22. Affected package(s): rhdh/rhdh-hub-rhel9:1774545605, automation-gateway, ansible-automation-platform, devspaces/traefik-rhel9:1776718585, automation-platform-ui, quay/quay-rhel8:1773971077. Resolved in Red Hat advisory RHSA-2026:5649 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Developer Hub 1.8; and 10 more.
High [CVE-2026-27148] Remote Code Execution via WebSocket Hijacking
Remote Code Execution via WebSocket Hijacking. Red Hat rates this important (CVSS 8.8). Weakness: CWE-346. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-26965] Arbitrary code execution via heap out-of-bounds write in RLE planar decode path
Arbitrary code execution via heap out-of-bounds write in RLE planar decode path. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787. Affected package(s): freerdp. Resolved in Red Hat advisory RHSA-2026:5936 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 10 more.
High [CVE-2026-26955] Arbitrary code execution via heap buffer overflow in GDI surface pipeline
Arbitrary code execution via heap buffer overflow in GDI surface pipeline. Red Hat rates this important (CVSS 8.8). Weakness: CWE-805. Affected package(s): freerdp. Resolved in Red Hat advisory RHSA-2026:5936 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; and 10 more.
High [CVE-2026-25554] Authentication bypass due to SQL injection in JWT processing
Authentication bypass due to SQL injection in JWT processing. Red Hat rates this important (CVSS 8.2). Weakness: CWE-89. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-27727] Arbitrary code execution via JNDI dereferencing of crafted objects
Arbitrary code execution via JNDI dereferencing of crafted objects. Red Hat rates this important (CVSS 8.3). Weakness: CWE-502. Affected package(s): candlepin, eap8-hibernate, mchange-commons-java. Resolved in Red Hat advisory RHSA-2026:18054 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat build of Apache Camel 4.14.4 for Spring Boot 3.5.11; Red Hat Build of Debezium 3.2; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9; and 8 more.
High [CVE-2026-27699] File overwrite due to path traversal
File overwrite due to path traversal. Red Hat rates this important (CVSS 7.5). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-26103] Missing Authorization Check Allows Unprivileged Users to Restore LUKS Headers via udisks D-Bus API
Missing Authorization Check Allows Unprivileged Users to Restore LUKS Headers via udisks D-Bus API. Red Hat rates this important (CVSS 7.1). Weakness: CWE-862. Affected package(s): udisks2. Resolved in Red Hat advisory RHSA-2026:5831 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support.
High [CVE-2026-27628] possible infinite loop when loading circular /Prev entries in cross-reference streams
possible infinite loop when loading circular /Prev entries in cross-reference streams. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-835. Affected package(s): quay/quay-rhel9:1775069491, rhoai/odh-llama-stack-core-rhel9:1775144403, quay/quay-rhel8:1773771962, quay/quay-rhel8:1773971077, quay/quay-rhel9:1775169226, quay/quay-rhel8:1773936323. Resolved in Red Hat advisory RHSA-2026:10184 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-27951] Denial of Service via endless blocking loop in Stream_EnsureCapacity
Denial of Service via endless blocking loop in Stream_EnsureCapacity. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-190. Affected package(s): freerdp. Resolved in Red Hat advisory RHSA-2026:19811 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.
Medium [CVE-2026-26986] Denial of Service via double free vulnerability during disconnect
Denial of Service via double free vulnerability during disconnect. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-825. Affected package(s): freerdp. Resolved in Red Hat advisory RHSA-2026:19142 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 1.
Medium [CVE-2026-25997] Denial of service via heap use-after-free during auto-reconnect
Denial of service via heap use-after-free during auto-reconnect. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-825. Affected package(s): freerdp. Resolved in Red Hat advisory RHSA-2026:16014 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.
Medium [CVE-2026-25952] Denial of service due to use-after-free vulnerability
Denial of service due to use-after-free vulnerability. Red Hat rates this moderate (CVSS 6.4). Weakness: CWE-825. Affected package(s): freerdp. Resolved in Red Hat advisory RHSA-2026:19142 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 1.
Medium [CVE-2026-3203] Buffer Over-read in Wireshark
Buffer Over-read in Wireshark. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-126. Affected package(s): wireshark. Resolved in Red Hat advisory RHSA-2026:26182 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.
Medium [CVE-2026-3201] Improperly Controlled Sequential Memory Allocation in Wireshark
Improperly Controlled Sequential Memory Allocation in Wireshark. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1325. Affected package(s): wireshark. Resolved in Red Hat advisory RHSA-2026:26182 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.
Medium [CVE-2026-3190] Information Disclosure via improper role enforcement in UMA 2.0 Protection API
Information Disclosure via improper role enforcement in UMA 2.0 Protection API. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-280. Affected package(s): rhbk/keycloak-operator-bundle:26.4.11, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:6478 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-26104] Missing Authorization Check Allows Unprivileged Users to Back Up LUKS Headers via udisks D-Bus API
Missing Authorization Check Allows Unprivileged Users to Back Up LUKS Headers via udisks D-Bus API. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-862. Affected package(s): udisks2. Resolved in Red Hat advisory RHSA-2026:5831 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1.
Low [CVE-2026-3184] Access control bypass due to improper hostname canonicalization
Access control bypass due to improper hostname canonicalization. Red Hat rates this low (CVSS 3.7). Weakness: CWE-289. Affected package(s): util-linux-main. Resolved in Red Hat advisory RHSA-2026:7180 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-27571] WebSockets pre-auth memory DoS
WebSockets pre-auth memory DoS. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-770. Affected package(s): multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1773650060, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1773650767. Resolved in Red Hat advisory RHSA-2026:6226 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.