Complete feed
Action required
Critical/high still unreviewed, or CISA KEV listed
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-70461] Information disclosure and denial of service via crafted files-from entry
Information disclosure and denial of service via crafted files-from entry. Red Hat rates this important (CVSS 8.2). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: rsync.
High [CVE-2026-70463] Authorization bypass via `auth users` directive parsing
Authorization bypass via `auth users` directive parsing. Red Hat rates this important (CVSS 8.1). Weakness: CWE-863. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: rsync.
High [CVE-2026-70464] Denial of Service via handshake stall
Denial of Service via handshake stall. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.
High [CVE-2026-53795] Arbitrary file write via --temp-dir or --link-dest options
Arbitrary file write via --temp-dir or --link-dest options. Red Hat rates this important (CVSS 8.1). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.
High [CVE-2026-53793] rsync < 3.5.0 Path Confinement Bypass via /./ Boundary Marker in Chroot Mode
rsync < 3.5.0 Path Confinement Bypass via /./ Boundary Marker in Chroot Mode. Red Hat rates this important (CVSS 7.4). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.
High [CVE-2026-53791] rsync < 3.5.0 Daemon IP Spoofing via PROXY Protocol Header
rsync < 3.5.0 Daemon IP Spoofing via PROXY Protocol Header. Red Hat rates this important (CVSS 7.4). Weakness: CWE-290. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.
High [CVE-2026-53790] rsync < 3.5.0 Command Injection via Multiple Code Paths
rsync < 3.5.0 Command Injection via Multiple Code Paths. Red Hat rates this important (CVSS 8.1). Weakness: CWE-78. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.
High [CVE-2026-53785] Arbitrary file write via path traversal in --relative mode
Arbitrary file write via path traversal in --relative mode. Red Hat rates this important (CVSS 7.1). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.
High [CVE-2026-53784] Unauthorized File Access via Symlink Module Root
Unauthorized File Access via Symlink Module Root. Red Hat rates this important (CVSS 7.1). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.
High [CVE-2026-53783] Directory escape via TOCTOU race condition in rrsync
Directory escape via TOCTOU race condition in rrsync. Red Hat rates this important (CVSS 8.1). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: rsync.
High [CVE-2026-53803] Local Privilege Escalation via Symlink Following
Local Privilege Escalation via Symlink Following. Red Hat rates this important (CVSS 7). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.
High [CVE-2026-73508] Denial of Service via Memory Leak in DNS Record Decoder with Malformed Domain Names
Denial of Service via Memory Leak in DNS Record Decoder with Malformed Domain Names. Red Hat rates this important (CVSS 7.5). Weakness: CWE-772. Affected products named by the advisory: OpenShift Serverless; Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; Red Hat Data Grid 8; and 7 more. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; and 3 more.
High [CVE-2026-73507] Denial of Service via CPU Exhaustion in XmlFrameDecoder
Denial of Service via CPU Exhaustion in XmlFrameDecoder. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835. Affected products named by the advisory: Red Hat build of Apache Camel for Spring Boot 4; Red Hat Single Sign-On 7.
High [CVE-2026-73505] Arbitrary command execution via template injection in directory names
Arbitrary command execution via template injection in directory names. Red Hat rates this important (CVSS 7.8). Weakness: CWE-78.
High [CVE-2026-14456] Denial of Service via unbounded memory growth in QUIC server
Denial of Service via unbounded memory growth in QUIC server. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:56097 with package openssl-main-3.5.6-0.5.hum1. Affected products named by the advisory: Red Hat Developer Hub; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Hardened Images; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: openssl.
High [CVE-2026-66804] authenticated SSRF via /ansibletower allows arbitrary host access with full response disclosure
authenticated SSRF via /ansibletower allows arbitrary host access with full response disclosure. Red Hat rates this important (CVSS 7.7). Weakness: CWE-918. Red Hat lists fixing advisory RHSA-2026:57194 with package multicluster-engine/console-mce-rhel9:1787079359, rhacm2/console-rhel9:1787339248, multicluster-engine/console-mce-rhel9:1787264250, multicluster-engine/console-mce-rhel9:1786668856. Affected products named by the advisory: Multicluster Engine for Kubernetes; Red Hat Advanced Cluster Management for Kubernetes 2.
High [CVE-2026-6471] Arbitrary code execution via logical decoding plugin
Arbitrary code execution via logical decoding plugin. Red Hat rates this important (CVSS 7.2). Weakness: CWE-94. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Self-service automation portal 2; and 2 more. Affected products named by the advisory: Red Hat package: postgresql16; Red Hat package: postgresql18.
High [CVE-2026-19385] PostgreSQL pg_dump: Arbitrary code execution via crafted transform lists
PostgreSQL pg_dump: Arbitrary code execution via crafted transform lists. Red Hat rates this important (CVSS 8.8). Weakness: CWE-122. Red Hat lists fixing advisory RHSA-2026:57198 with package postgresql17-main-17.11-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Self-service automation portal 2; Red Hat package: postgresql16; Red Hat package: postgresql18.
High [CVE-2026-16239] Arbitrary code execution via type confusion in cursor lifecycle
Arbitrary code execution via type confusion in cursor lifecycle. Red Hat rates this important (CVSS 8.8). Weakness: CWE-843. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Self-service automation portal 2; Red Hat package: postgresql16; Red Hat package: postgresql18.
High [CVE-2026-16238] Arbitrary code execution via type confusion in pg_restore_attribute_stats
Arbitrary code execution via type confusion in pg_restore_attribute_stats(). Red Hat rates this important (CVSS 8.8). Weakness: CWE-843. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: postgresql18.