Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

2455 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Low3.3Red Hat Updated

Low [CVE-2026-76884] Denial of Service via ERF file parser crash

Denial of Service via ERF file parser crash. Red Hat rates this low (CVSS 3.3). Weakness: CWE-130. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.

CVE-2026-76884
Red Hat Enterprise Linux
Aug 19, 2026
Critical9.0Vendor: HighRed Hat

Critical [CVE-2026-76044] Arbitrary code execution due to a race condition in USB

Arbitrary code execution due to a race condition in USB. Red Hat rates this important (CVSS 9). Weakness: CWE-368.

CVE-2026-76044
Unclassified
Aug 18, 2026
Critical9.9Vendor: HighRed Hat Updated

Critical [CVE-2026-66780] flat broker trust model grants every spoke full CRUD on all endpoints, secrets, and endpointslices in broker namespace

flat broker trust model grants every spoke full CRUD on all endpoints, secrets, and endpointslices in broker namespace. Red Hat rates this important (CVSS 9.9). Weakness: CWE-284. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/submariner-addon-rhel9:1787362694, rhacm2/submariner-addon-rhel9:1787689013, rhacm2/submariner-addon-rhel9:1787365971, rhacm2/submariner-addon-rhel9:1787362658. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.

CVE-2026-66780
Unclassified
Aug 18, 2026
Critical9.1Red Hat

Critical [CVE-2026-18963] Unauthenticated account takeover via reset-credentials flow bypass

Unauthenticated account takeover via reset-credentials flow bypass. Red Hat rates this critical (CVSS 9.1). Weakness: CWE-640. Red Hat lists fixing advisory RHSA-2026:56524 with package rhbk/keycloak-rhel9:26.6-12, rhbk-keycloak-rhel9/rhbk-keycloak-rhel9, keycloak-services, rhbk-openshift-rhel9/rhbk-openshift-rhel9. Affected products named by the advisory: Red Hat build of Keycloak 26.4; Red Hat build of Keycloak 26.6.

CVE-2026-18963
Unclassified
Aug 18, 2026
Critical9.6Red Hat

Critical [CVE-2026-12564] Automation-controller: automation-controller: kubernetes service account token exfiltration via hashicorp vault credential ssrf

A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. An authenticated attacker with credential-creation privileges can exfiltrate the service account token, gaining Kubernetes API access to the control plane namespaces with full pod CRUD and secret read permissions, including database credentials and the Django SECRET_KEY. The vulnerability is particularly impactful in AAP Cloud (managed service) environments where the Kubernetes control plane is managed by Red Hat and tenant isolation is a security boundary. On-premise deployments are also affected, though the impact is lower since the administrator already has access to the infrastructure. The vulnerable code path exists in all AAP versions that ship the hashivault credential plugin with kubernetes_role authentication support. Red Hat severity: Critical — CVSS 9.6 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N). Weakness: CWE-918. Affected Red Hat products: Red Hat Ansible Automation Platform 2. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-12564
Unclassified
Aug 18, 2026
High8.8Red Hat

High [CVE-2026-76038] Remote code execution via type confusion in crafted HTML.

Remote code execution via type confusion in crafted HTML. Red Hat rates this important (CVSS 8.8). Weakness: CWE-843.

CVE-2026-76038
Unclassified
Aug 18, 2026
High7.4Red Hat

High [CVE-2026-76041] Information leak allows web origin policy bypass

Information leak allows web origin policy bypass. Red Hat rates this important (CVSS 7.4). Weakness: CWE-346.

CVE-2026-76041
Unclassified
Aug 18, 2026
High8.3Red Hat

High [CVE-2026-76047] Arbitrary code execution via type confusion in V8

Arbitrary code execution via type confusion in V8. Red Hat rates this important (CVSS 8.3). Weakness: CWE-843.

CVE-2026-76047
Unclassified
Aug 18, 2026
High8.8Red Hat

High [CVE-2026-76045] Arbitrary code execution via use-after-free

Arbitrary code execution via use-after-free. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825.

CVE-2026-76045
Unclassified
Aug 18, 2026
High8.8Red Hat

High [CVE-2026-76043] Arbitrary code execution via incorrect calculation in HTML processing

Arbitrary code execution via incorrect calculation in HTML processing. Red Hat rates this important (CVSS 8.8). Weakness: CWE-190.

CVE-2026-76043
Unclassified
Aug 18, 2026
High7.1Red Hat

High [CVE-2026-76039] Information disclosure via incorrect reference resolution

Information disclosure via incorrect reference resolution. Red Hat rates this important (CVSS 7.1). Weakness: CWE-386.

CVE-2026-76039
Unclassified
Aug 18, 2026
High8.3Red Hat

High [CVE-2026-76040] Arbitrary code execution via use-after-free vulnerability

Arbitrary code execution via use-after-free vulnerability. Red Hat rates this important (CVSS 8.3). Weakness: CWE-825.

CVE-2026-76040
Unclassified
Aug 18, 2026
High8.2Red Hat

High [CVE-2026-76037] Arbitrary Code Execution via Link Following

Arbitrary Code Execution via Link Following. Red Hat rates this important (CVSS 8.2). Weakness: CWE-59.

CVE-2026-76037
Unclassified
Aug 18, 2026
High8.7Red Hat

High [CVE-2026-76033] Site isolation bypass due to inappropriate CORS implementation

Site isolation bypass due to inappropriate CORS implementation. Red Hat rates this important (CVSS 8.7). Weakness: CWE-653.

CVE-2026-76033
Unclassified
Aug 18, 2026
High8.3Red Hat

High [CVE-2026-76036] Dawn in Google Chrome: Arbitrary code execution via crafted HTML page

Dawn in Google Chrome: Arbitrary code execution via crafted HTML page. Red Hat rates this important (CVSS 8.3). Weakness: CWE-120.

CVE-2026-76036
Unclassified
Aug 18, 2026
High7.3Red Hat

High [CVE-2026-15571] Predictable account-linking hash enables account takeover via malicious OIDC client

Predictable account-linking hash enables account takeover via malicious OIDC client. Red Hat rates this important (CVSS 7.3). Weakness: CWE-341. Red Hat lists fixing advisory RHSA-2026:56524 with package rhbk/keycloak-rhel9:26.6-12, rhbk/keycloak-rhel9, keycloak-services, rhbk-openshift-rhel9/rhbk-openshift-rhel9. Affected product named by the advisory: Red Hat build of Keycloak 26.6.

CVE-2026-15571
Unclassified
Aug 18, 2026
High7.9Red Hat Updated

High [CVE-2026-54552] Incomplete privilege drop allows child processes to retain privileged group access.

Incomplete privilege drop allows child processes to retain privileged group access. Red Hat rates this important (CVSS 7.9). Weakness: CWE-273. Affected product named by the advisory: Red Hat OpenShift Virtualization 4.

CVE-2026-54552
Unclassified
Aug 18, 2026
High8.2Red Hat

High [CVE-2026-66783] arbitrary image override enables privileged code execution on every node

arbitrary image override enables privileged code execution on every node. Red Hat rates this important (CVSS 8.2). Weakness: CWE-20. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-66783
Unclassified
Aug 18, 2026
High7.8Red Hat

High [CVE-2026-66782] broker API bearer token stored cleartext in CR spec

broker API bearer token stored cleartext in CR spec. Red Hat rates this important (CVSS 7.8). Weakness: CWE-312. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-66782
Unclassified
Aug 18, 2026
High8.7Red Hat

High [CVE-2026-75924] Hub addon-manager ClusterRole grants cluster-wide Secret read/write and CSR approval

Hub addon-manager ClusterRole grants cluster-wide Secret read/write and CSR approval. Red Hat rates this important (CVSS 8.7). Weakness: CWE-269. Affected product named by the advisory: Multicluster Engine for Kubernetes.

CVE-2026-75924
Unclassified
Aug 18, 2026