Complete feed
Security advisories & CVEs
7822 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-74725] fix tx_hang_reset use-after-free on device removal
fix tx_hang_reset use-after-free on device removal. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-364. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-74685] (ltc4282) Clamp negative current limits
(ltc4282) Clamp negative current limits. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-190.
Medium [CVE-2026-74708] validate launch-time metadata size
validate launch-time metadata size. Red Hat rates this low (CVSS 5.5). Weakness: CWE-1284. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-74658] Prevent robust futex exit race some more
Prevent robust futex exit race some more. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-367. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-74636] Fix race between update_event_fields and, event_define_fields
Fix race between update_event_fields and, event_define_fields. Red Hat rates this low (CVSS 5.5). Weakness: CWE-366. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-74627] prevent net-iov / page mixing
prevent net-iov / page mixing. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-843. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat package: kernel.
Medium [CVE-2026-74687] prevent timer rearm during teardown
prevent timer rearm during teardown. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825.
Critical [CVE-2026-66786] ipsec.conf stanza injection via remote-supplied CableName and Subnets
ipsec.conf stanza injection via remote-supplied CableName and Subnets. Red Hat rates this moderate (CVSS 9.1). Weakness: CWE-94.
Critical [CVE-2026-63125] Incus vulnerable to root RCE via image backup.yaml symlink
Incus vulnerable to root RCE via image backup.yaml symlink. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-61.
Critical [CVE-2026-62941] Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge
Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-367.
Critical [CVE-2026-62940] Incus has a project restriction bypass via instance migration config override
Incus has a project restriction bypass via instance migration config override. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-863.
Critical [CVE-2026-62867] Incus has an argument injection in storage volume block.create_options that leads to arbitrary command execution
Incus has an argument injection in storage volume block.create_options that leads to arbitrary command execution. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-88.
Critical [CVE-2026-48769] Incus has an arbitrary file write on its client due to trusted image hash
Incus has an arbitrary file write on its client due to trusted image hash. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-345.
Critical [CVE-2026-48755] Incus has an argument injection in backup compression algorithm leading to AFW and ACE
Incus has an argument injection in backup compression algorithm leading to AFW and ACE. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-88.
Critical [CVE-2026-48753] Incus has an arbitrary file write via path traversal in S3 multipart upload
Incus has an arbitrary file write via path traversal in S3 multipart upload. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-22.
Critical [CVE-2026-48752] Incus has arbitrary file read+write on host via templates/ symlink in malicious image
Incus has arbitrary file read+write on host via templates/ symlink in malicious image. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-61.
Critical [CVE-2026-48751] Incus has a restricted project bypass leading to arbitrary command execution
Incus has a restricted project bypass leading to arbitrary command execution. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-863.
Critical [CVE-2026-48750] Incus has an arbitrary file write on host via `exec-output` symlink in crafted image
Incus has an arbitrary file write on host via `exec-output` symlink in crafted image. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-61.
Critical [CVE-2026-48749] Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious image
Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious image. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-61.
Critical [CVE-2026-59085] Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook module, exploitable via webhook delivery requests
Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook module, exploitable via webhook delivery requests. This issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.