Complete feed
Security advisories & CVEs
5208 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-25506] MUNGE has a buffer overflow in message unpacking allows key leakage and credential forgery
MUNGE has a buffer overflow in message unpacking allows key leakage and credential forgery. Red Hat rates this important (CVSS 7.7). Weakness: CWE-120. Affected package(s): munge, rhaiis/vllm-spyre-rhel9:1778244546. Resolved in Red Hat advisory RHSA-2026:2934 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On; and 10 more.
High [CVE-2025-14821] Insecure default configuration leads to local man-in-the-middle attacks on Windows
Insecure default configuration leads to local man-in-the-middle attacks on Windows. Red Hat rates this low (CVSS 7.8). Weakness: CWE-427. Affected package(s): libssh-main. Resolved in Red Hat advisory RHSA-2026:7067 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-25646] LIBPNG has a heap buffer overflow in png_set_quantize
LIBPNG has a heap buffer overflow in png_set_quantize. Red Hat rates this important (CVSS 7). Weakness: CWE-125. Affected package(s): rhcos, libpng15, libpng, libpng12, java, rhaiis/vllm-spyre-rhel9:1778244546. Resolved in Red Hat advisory RHSA-2026:5606 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Build of OpenJDK 17.0.9; Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 7 Extended Lifecycle Support; Red Hat Enterprise Linux 8.2 Advanced Update Support; and 30 more.
High [CVE-2025-35998] Intel (R): From CVEorg collector
Intel (R): From CVEorg collector. Red Hat rates this important (CVSS 7.9). Weakness: CWE-1220. Affected package(s): microcode_ctl. Resolved in Red Hat advisory RHSA-2026:6888 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 9.
High [CVE-2026-2315] Inappropriate implementation in WebGPU
Inappropriate implementation in WebGPU. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-2314] Heap buffer overflow in Codecs
Heap buffer overflow in Codecs. Red Hat rates this important (CVSS 8.8). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-0966] Denial of Service via zero-length input in ssh_get_hexa()
Denial of Service via zero-length input in ssh_get_hexa(). Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-124. Affected package(s): libssh, libssh-main. Resolved in Red Hat advisory RHSA-2026:18160 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
Medium [CVE-2026-0964] Improper sanitation of paths received from SCP servers
Improper sanitation of paths received from SCP servers. Red Hat rates this moderate (CVSS 5). Weakness: CWE-22. Affected package(s): libssh. Resolved in Red Hat advisory RHSA-2026:18160 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
Low [CVE-2026-0965] Denial of Service via improper configuration file handling
Denial of Service via improper configuration file handling. Red Hat rates this low (CVSS 3.3). Weakness: CWE-73. Affected package(s): libssh. Resolved in Red Hat advisory RHSA-2026:18160 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
Low [CVE-2026-0967] Denial of Service via inefficient regular expression processing
Denial of Service via inefficient regular expression processing. Red Hat rates this low (CVSS 2.2). Weakness: CWE-1333. Affected package(s): libssh. Resolved in Red Hat advisory RHSA-2026:18160 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
Low [CVE-2026-0968] Denial of Service due to malformed SFTP message
Denial of Service due to malformed SFTP message. Red Hat rates this low (CVSS 3.1). Weakness: CWE-476. Affected package(s): libssh. Resolved in Red Hat advisory RHSA-2026:18160 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9.
Critical [CVE-2026-1615] Arbitrary Code Execution via unsafe JSON Path expression evaluation
Arbitrary Code Execution via unsafe JSON Path expression evaluation. Red Hat rates this important (CVSS 9.8). Weakness: CWE-94. Affected package(s): ansible-automation-platform, rhdh/rhdh-hub-rhel9:1775140647. Resolved in Red Hat advisory RHSA-2026:6309 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.5; Red Hat Ansible Automation Platform 2.6; Red Hat Developer Hub 1.9; OpenShift Pipelines; and 2 more.
High [CVE-2026-25639] Axios affected by Denial of Service via __proto__ Key in mergeConfig
Axios affected by Denial of Service via __proto__ Key in mergeConfig. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1287. Affected package(s): rhoai/odh-mod-arch-gen-ai-rhel9:1778473763, rhoai/odh-dashboard-rhel9:1779189627, multicluster-engine/console-mce-rhel9:1776223790, ansible-automation-platform, openshift-service-mesh/kiali-ossmc-rhel9:1771372942, rhoai/odh-dashboard-rhel9:1776742021. Resolved in Red Hat advisory RHSA-2026:3107 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Advanced Cluster Management for Kubernetes 2.12; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; and 35 more.
High [CVE-2026-1609] Unauthorized Access via JWT authorization grant with disabled users
Unauthorized Access via JWT authorization grant with disabled users. Red Hat rates this important (CVSS 8.1). Weakness: CWE-284. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-1486] Disabled identity providers are still accepted for JWT Authorization Grant
Disabled identity providers are still accepted for JWT Authorization Grant. Red Hat rates this important (CVSS 8.8). Weakness: CWE-358. Affected package(s): rhbk/keycloak-rhel9, rhbk/keycloak-operator-bundle:26.4.9, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:2366 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat build of Keycloak 26.4.
High [CVE-2026-1529] Unauthorized organization registration via improper invitation token validation
Unauthorized organization registration via improper invitation token validation. Red Hat rates this important (CVSS 8.1). Weakness: CWE-347. Affected package(s): rhbk/keycloak-rhel9, rhbk/keycloak-operator-bundle:26.2.13, rhbk/keycloak-operator-bundle:26.4.9, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.2, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:2366 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat build of Keycloak 26.2; Red Hat build of Keycloak 26.4.
High [CVE-2025-66630] Predictable UUIDs from randomness source errors can lead to security bypasses
Predictable UUIDs from randomness source errors can lead to security bypasses. Red Hat rates this important (CVSS 7.7). Weakness: CWE-331. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
High [CVE-2026-1584] Remote Denial of Service via crafted ClientHello with invalid PSK binder
Remote Denial of Service via crafted ClientHello with invalid PSK binder. Red Hat rates this important (CVSS 7.5). Weakness: CWE-476. Affected package(s): gnutls-main. Resolved in Red Hat advisory RHSA-2026:7477 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat Hardened Images.
Medium [CVE-2025-14778] Incorrect ownership checks in /uma-policy/
Incorrect ownership checks in /uma-policy/. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-266. Affected package(s): rhbk/keycloak-rhel9-operator, rhbk/keycloak-operator-bundle:26.2.13, rhbk/keycloak-operator-bundle:26.4.9, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9:26.2, rhbk/keycloak-rhel9:26.4. Resolved in Red Hat advisory RHSA-2026:2366 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Medium [CVE-2026-24684] FreeRDP has a Heap-use-after-free in play_thread
FreeRDP has a Heap-use-after-free in play_thread. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-131. Affected package(s): freerdp. Resolved in Red Hat advisory RHSA-2026:6958 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.