Complete feed
Security advisories & CVEs
7850 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-76220] Arbitrary command execution via crafted kwargs
Arbitrary command execution via crafted kwargs. Red Hat rates this important (CVSS 8.8). Weakness: CWE-78. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat Satellite 6.
High [CVE-2026-76219] Arbitrary File Overwrite via `git read-tree` option injection
Arbitrary File Overwrite via `git read-tree` option injection. Red Hat rates this important (CVSS 8.1). Weakness: CWE-88. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat Satellite 6.
High [CVE-2026-76218] Remote Code Execution via malicious Git hooks
Remote Code Execution via malicious Git hooks. Red Hat rates this important (CVSS 7.5). Weakness: CWE-94. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat Satellite 6.
High [CVE-2020-37267] Information disclosure via unredacted logging of authorization tokens
Information disclosure via unredacted logging of authorization tokens. Red Hat rates this important (CVSS 7.5). Weakness: CWE-538.
High [CVE-2026-43961] Vimscript injection via unescaped filename in netrw s:NetrwMarkFile filter expression allows arbitrary code execution
Vimscript injection via unescaped filename in netrw s:NetrwMarkFile() filter() expression allows arbitrary code execution. Red Hat rates this important (CVSS 7.8). Weakness: CWE-94.
High [CVE-2026-76235] unauthenticated remote memory leak via CockpitLang cookie in send_login_html
unauthenticated remote memory leak via CockpitLang cookie in send_login_html. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-401. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-58081] Heap-based buffer overflow in encoding modules
Heap-based buffer overflow in encoding modules. Red Hat rates this important (CVSS 7.3). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: php.
Medium [CVE-2026-76928] Denial of Service via X.509IF protocol dissector crash
Denial of Service via X.509IF protocol dissector crash. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-76924] Denial of Service via Out-of-bounds Read in Kerberos Dissector
Denial of Service via Out-of-bounds Read in Kerberos Dissector. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-76923] Denial of Service due to out-of-bounds read in Bluetooth HFP dissector
Denial of Service due to out-of-bounds read in Bluetooth HFP dissector. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-76918] Denial of Service via SSH protocol dissector crash
Denial of Service via SSH protocol dissector crash. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-248. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-76917] Denial of Service via Heap-based Buffer Overflow in Bluetooth AVRCP Dissector
Denial of Service via Heap-based Buffer Overflow in Bluetooth AVRCP Dissector. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-76880] Denial of Service via RRC protocol dissector out-of-bounds write
Denial of Service via RRC protocol dissector out-of-bounds write. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: wireshark.
Medium [CVE-2026-76879] Denial of Service via C12.22 protocol dissector crash
Denial of Service via C12.22 protocol dissector crash. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-617. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-76889] Denial of Service via UMTS FP protocol dissector crash
Denial of Service via UMTS FP protocol dissector crash. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-617. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-76886] Denial of Service via C12.22 protocol dissector crash
Denial of Service via C12.22 protocol dissector crash. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-617. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: wireshark.
Medium [CVE-2026-76883] Denial of Service via heap-based buffer overflow in Catapult DCT2000 file parser
Denial of Service via heap-based buffer overflow in Catapult DCT2000 file parser. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-76882] Denial of Service via Bluetooth Attribute Protocol dissector out-of-bounds read
Denial of Service via Bluetooth Attribute Protocol dissector out-of-bounds read. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-76881] Denial of service via CMS protocol dissector crash
Denial of service via CMS protocol dissector crash. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-76827] UPDATE/DELETE operations not scoped to caller's cluster (cross-tenant data tampering)
UPDATE/DELETE operations not scoped to caller's cluster (cross-tenant data tampering). Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-693. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/acm-search-indexer-rhel9:1787688957, rhacm2/acm-search-indexer-rhel9:1787247085, rhacm2/acm-search-indexer-rhel9:1787250074, rhacm2/acm-search-indexer-rhel9:1787262474. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.