Complete feed
Recently updated
Advisories the vendor has revised
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-76229] Arbitrary Command Injection via kustomize manager
Arbitrary Command Injection via kustomize manager. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-78.
Medium [CVE-2026-76217] Arbitrary File Read via Crafted Parameters
Arbitrary File Read via Crafted Parameters. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-88. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat Satellite 6.
Medium [CVE-2026-16440] Denial of Service via crafted.class file
Denial of Service via crafted.class file. Red Hat rates this moderate (CVSS 5.7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat package: java-1.8.0-ibm.
Medium [CVE-2026-76166] mod_cluster Advertise Listener: unauthenticated DoS via crafted multicast datagram
mod_cluster Advertise Listener: unauthenticated DoS via crafted multicast datagram. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-476. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat JBoss Web Server 6; and 2 more. Affected products named by the advisory: Red Hat JBoss Web Server 7; Red Hat Single Sign-On 7.
Medium [CVE-2026-75900] Out-of-bounds read in SWTPM_NVRAM_CheckHeader due to sizeof(pointer) vs sizeof(struct) mismatch
Out-of-bounds read in SWTPM_NVRAM_CheckHeader due to sizeof(pointer) vs sizeof(struct) mismatch. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Low [CVE-2026-76891] Denial of Service via sharkd crash
Denial of Service via sharkd crash. Red Hat rates this low (CVSS 3.1). Weakness: CWE-248. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Low [CVE-2026-76885] Denial of Service via Tektronix K12xx file parsing
Denial of Service via Tektronix K12xx file parsing. Red Hat rates this low (CVSS 3.1). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Low [CVE-2026-76888] Heap-based Buffer Overflow in RDP dissector leads to Denial of Service
Heap-based Buffer Overflow in RDP dissector leads to Denial of Service. Red Hat rates this low (CVSS 3.1). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Low [CVE-2026-76887] Denial of service via heap-based buffer overflow in dissection engine
Denial of service via heap-based buffer overflow in dissection engine. Red Hat rates this low (CVSS 3.1). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Low [CVE-2026-76884] Denial of Service via ERF file parser crash
Denial of Service via ERF file parser crash. Red Hat rates this low (CVSS 3.3). Weakness: CWE-130. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Critical [CVE-2026-76044] Arbitrary code execution due to a race condition in USB
Arbitrary code execution due to a race condition in USB. Red Hat rates this important (CVSS 9). Weakness: CWE-368.
Critical [CVE-2026-66780] flat broker trust model grants every spoke full CRUD on all endpoints, secrets, and endpointslices in broker namespace
flat broker trust model grants every spoke full CRUD on all endpoints, secrets, and endpointslices in broker namespace. Red Hat rates this important (CVSS 9.9). Weakness: CWE-284. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/submariner-addon-rhel9:1787362694, rhacm2/submariner-addon-rhel9:1787689013, rhacm2/submariner-addon-rhel9:1787365971, rhacm2/submariner-addon-rhel9:1787362658. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.
Critical [CVE-2026-18963] Unauthenticated account takeover via reset-credentials flow bypass
Unauthenticated account takeover via reset-credentials flow bypass. Red Hat rates this critical (CVSS 9.1). Weakness: CWE-640. Red Hat lists fixing advisory RHSA-2026:56524 with package rhbk/keycloak-rhel9:26.6-12, rhbk-keycloak-rhel9/rhbk-keycloak-rhel9, keycloak-services, rhbk-openshift-rhel9/rhbk-openshift-rhel9. Affected products named by the advisory: Red Hat build of Keycloak 26.4; Red Hat build of Keycloak 26.6.
High [CVE-2026-76038] Remote code execution via type confusion in crafted HTML.
Remote code execution via type confusion in crafted HTML. Red Hat rates this important (CVSS 8.8). Weakness: CWE-843.
High [CVE-2026-76041] Information leak allows web origin policy bypass
Information leak allows web origin policy bypass. Red Hat rates this important (CVSS 7.4). Weakness: CWE-346.
High [CVE-2026-76047] Arbitrary code execution via type confusion in V8
Arbitrary code execution via type confusion in V8. Red Hat rates this important (CVSS 8.3). Weakness: CWE-843.
High [CVE-2026-76045] Arbitrary code execution via use-after-free
Arbitrary code execution via use-after-free. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825.
High [CVE-2026-76043] Arbitrary code execution via incorrect calculation in HTML processing
Arbitrary code execution via incorrect calculation in HTML processing. Red Hat rates this important (CVSS 8.8). Weakness: CWE-190.
High [CVE-2026-76039] Information disclosure via incorrect reference resolution
Information disclosure via incorrect reference resolution. Red Hat rates this important (CVSS 7.1). Weakness: CWE-386.
High [CVE-2026-76040] Arbitrary code execution via use-after-free vulnerability
Arbitrary code execution via use-after-free vulnerability. Red Hat rates this important (CVSS 8.3). Weakness: CWE-825.