Complete feed
Recently updated
Advisories the vendor has revised
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-45699] Stack-based buffer overflow in copydir allows arbitrary code execution
Stack-based buffer overflow in copydir() allows arbitrary code execution. Red Hat rates this important (CVSS 7.5). Weakness: CWE-120.
High [CVE-2026-46439] Remote Code Execution via Recursive Server-Side Template Injection
Remote Code Execution via Recursive Server-Side Template Injection. Red Hat rates this important (CVSS 7.8). Weakness: CWE-917. Affected product named by the advisory: File Integrity Operator.
High [CVE-2026-73633] Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts
Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an application is configured to populate actions from a JSON request body, the plugin reads that body into memory without bounding how much it will accept, so a single request can exhaust the heap and deny service to other users. The plugin's configurable JSON input length limit does not bound this read. The JSON plugin is an optional component; applications that do not use it, or use it without enabling JSON request-body handling, are not affected. This issue affects Apache Struts: from 2.1.8 through 2.3.37, from 2.5.0 through 2.5.33, from 6.0.0 through 6.10.0, from 7.0.0 through 7.2.1. Users are recommended to upgrade to version 6.11.0 or 7.3.0, which fixes the issue.
High [CVE-2026-72813] Denial of Service via empty Range header in GET requests
Denial of Service via empty Range header in GET requests. Red Hat rates this important (CVSS 7.5). Weakness: CWE-617. Affected product named by the advisory: Red Hat OpenShift Update Service.
High [CVE-2026-54876] OpenSSL Vulnerability in NetApp Products
OpenSSL versions 3.6.0 prior to 3.6.4 and 4.0.0 prior to 4.0.2 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
High [CVE-2026-58086] FreeBSD Vulnerability in NetApp Products
FreeBSD versions 15.1 and 15.0 are susceptible to a vulnerability which when successfully exploited could allow an unprivileged user in a jail that has permission to debug the target process to modify the jailed root user's ktrace(2) flags, or disable tracing outright. Successful exploitation of this vulnerability could lead to addition or modification of data or Denial of Service (DoS). NetApp states there is no workaround available at this time.
High [CVE-2026-10543] IBM Db2 Vulnerability in NetApp Products
IBM Db2 Server versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5 on all platforms are susceptible to a vulnerability which could allow privilege escalation with a specially crafted query. Successful exploitation of this vulnerability could lead to disclosure of sensitive information or addition or modification of data. NetApp states there is no workaround available at this time.
High [CVE-2026-58085] FreeBSD Vulnerability in NetApp Products
All supported versions of FreeBSD using wg(4) are susceptible to a vulnerability which when successfully exploited could allow a remote attacker who can send UDP packets to a WireGuard endpoint or intercept WireGuard packets bound for a FreeBSD host to inject forged or modified transport data packets into the tunnel or modify the ciphertext and authenticated data without detection by the receiver. Successful exploitation of this vulnerability could lead to addition or modification of data. NetApp states there is no workaround available at this time.
High [CVE-2026-73417] Cross-site scripting (XSS) allows arbitrary code execution
Cross-site scripting (XSS) allows arbitrary code execution. Red Hat rates this important (CVSS 8.3). Weakness: CWE-79. Affected products named by the advisory: Migration Toolkit for Applications 8; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-56860] golang net/url: Denial of Service from quadratic complexity in path resolution
golang net/url: Denial of Service from quadratic complexity in path resolution. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:59561 with package golang-0:1.26.7-1.el9_8, openshift-service-mesh/kiali-rhel9:1787077108, golang1-26-main-1.26.6-0.1.hum1, golang1-25-main-1.25.13-0.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.
High [CVE-2026-56853] Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service
Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:59561 with package golang-0:1.26.7-1.el9_8, openshift-service-mesh/kiali-rhel9:1787077108, golang1-26-main-1.26.6-0.1.hum1, golang1-25-main-1.25.13-0.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.
High [CVE-2026-56858] Go html/template: Cross-Site Scripting via pathological input
Go html/template: Cross-Site Scripting via pathological input. Red Hat rates this important (CVSS 8.1). Weakness: CWE-79. Red Hat lists fixing advisory RHSA-2026:59561 with package golang-0:1.26.7-1.el9_8, openshift-service-mesh/kiali-rhel9:1787077108, golang1-26-main-1.26.6-0.1.hum1, golang1-25-main-1.25.13-0.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.
High [CVE-2026-56862] Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages
Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1050. Red Hat lists fixing advisory RHSA-2026:59561 with package golang-0:1.26.7-1.el9_8, openshift-service-mesh/kiali-rhel9:1787077108, golang1-26-main-1.26.6-0.1.hum1, golang1-25-main-1.25.13-0.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.
High [CVE-2026-56865] Supply chain compromise via transparency log tile verification bypass
Supply chain compromise via transparency log tile verification bypass. Red Hat rates this important (CVSS 8.8). Weakness: CWE-347.
High [CVE-2026-33818] Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal
Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal. Red Hat rates this important (CVSS 7.5). Weakness: CWE-776. Red Hat lists fixing advisory RHSA-2026:59561 with package golang-0:1.26.7-1.el9_8, openshift-service-mesh/kiali-rhel9:1787077108, golang1-26-main-1.26.6-0.1.hum1, golang1-25-main-1.25.13-0.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.
High [CVE-2026-56859] Denial of Service via XML decoding recursion depth issue
Denial of Service via XML decoding recursion depth issue. Red Hat rates this important (CVSS 7.5). Weakness: CWE-776. Red Hat lists fixing advisory RHSA-2026:59561 with package golang-0:1.26.7-1.el9_8, openshift-service-mesh/kiali-rhel9:1787077108, golang1-26-main-1.26.6-0.1.hum1, golang1-25-main-1.25.13-0.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.
High [CVE-2026-73662] FreePBX Music on Hold: Arbitrary command execution by authenticated administrator
FreePBX Music on Hold: Arbitrary command execution by authenticated administrator. Red Hat rates this important (CVSS 7.2). Weakness: CWE-78.
High [CVE-2026-45774] Arbitrary file read via path traversal in profile import
Arbitrary file read via path traversal in profile import. Red Hat rates this important (CVSS 7.4). Weakness: CWE-22. Affected product named by the advisory: File Integrity Operator.
High [CVE-2026-45725] Arbitrary file write via path traversal in remote fetching mechanism
Arbitrary file write via path traversal in remote fetching mechanism. Red Hat rates this important (CVSS 7.4). Weakness: CWE-22. Affected product named by the advisory: File Integrity Operator.
High [CVE-2026-48099] Filesystem path traversal via encoded dot segments
Filesystem path traversal via encoded dot segments. Red Hat rates this important (CVSS 7.1). Weakness: CWE-22.