Complete feed
Security advisories & CVEs
7822 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-74581] use-after-free in fib6_rule_suppress due to stale res->rt6 pointer
use-after-free in fib6_rule_suppress due to stale res->rt6 pointer. Red Hat rates this important (CVSS 7.8). Weakness: CWE-416. Red Hat lists fixing advisory RHSA-2026:60485 with package kernel-0:5.14.0-427.147.1.el9_4, kernel-0:5.14.0-687.42.1.el9_8, kernel-0:5.14.0-570.136.1.el9_6, kernel-0:4.18.0-372.209.1.el8_6. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.
High [CVE-2026-74583] fix fastmap use-after-free on filter
fix fastmap use-after-free on filter. Red Hat rates this important (CVSS 7.8). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat package: kernel-rt.
High [CVE-2026-74580] reset the vring metadata cache on vring reconfiguration
reset the vring metadata cache on vring reconfiguration. Red Hat rates this important (CVSS 7.3). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-74582] use consistent hard_header_len in non-ring send paths
use consistent hard_header_len in non-ring send paths. Red Hat rates this important (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-77652] heap buffer overflow in WPG colormap parser via out-of-bounds palette index
heap buffer overflow in WPG colormap parser via out-of-bounds palette index. Red Hat rates this important (CVSS 7.8). Weakness: CWE-122.
High [CVE-2026-77658] stack buffer overflow in Bus object via unvalidated handle count in project files
stack buffer overflow in Bus object via unvalidated handle count in project files. Red Hat rates this important (CVSS 7.8). Weakness: CWE-121.
High [CVE-2026-58222] Samba Vulnerability in NetApp Products
Samba Active Directory Domain Controller versions 4.0.0 and higher are susceptible to a vulnerability which when successfully exploited permits an ordinary authenticated domain user to bypass access checks and query confidential Active Directory attributes (such as KDS root keys) via LDAP Compare requests. Due to a filter injection flaw and trusted execution context, the LDAP Compare operation can be turned into a protected-attribute disclosure oracle. Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
High [CVE-2026-6726] Trusted Platform Module 2.0 Vulnerability in NetApp Products
The TPM 2.0 reference library specification published by the Trusted Computing Group is susceptible to a vulnerability which when exploited could allow improper reuse of object slots between key/data objects and hash contexts, enabling an attacker to falsify TPM attestations and credentials. Successful exploitation of this vulnerability could lead to disclosure of sensitive information or addition or modification of data. NetApp states there is no workaround available at this time.
High [CVE-2026-70906] Java SE Vulnerability in NetApp Products
Java SE versions 25.0.4 and 26.0.2 are susceptible to a vulnerability which when successfully exploited could allow an unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Refer to “Oracle Critical Security Patch Update Advisory - August 2026” for additional details. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
High [CVE-2026-58224] Samba Vulnerability in NetApp Products
Samba versions 4.2 and higher are susceptible to a vulnerability which when successfully exploited could result in Denial of Service (DoS) and possible limited disclosure of adjacent memory allocations. Successful exploitation of this vulnerability could lead to disclosure of sensitive information or Denial of Service (DoS). NetApp states there is no workaround available at this time.
High [CVE-2026-6727] Trusted Platform Module 2.0 Vulnerability in NetApp Products
The TPM 2.0 reference library specification published by the Trusted Computing Group is susceptible to a vulnerability which exposes a timing side-channel in RSA OAEP decryption, enabling an attacker to decrypt sensitive blobs (import blobs, credential blobs, and session salts) encrypted to TPM-managed RSA keys, including the RSA Endorsement Key (EK), or to falsify TPM 2.0 Attestation Keys. Successful exploitation of this vulnerability could lead to disclosure of sensitive information or addition or modification of data. NetApp states there is no workaround available at this time.
High [CVE-2026-29036] cJSON Vulnerability in NetApp Products
cJSON versions 1.5.0 through 1.7.19 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data. Successful exploitation of this vulnerability could lead to addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
High [CVE-2026-6949] Samba Vulnerability in NetApp Products
Samba versions 4.0 and higher are susceptible to a vulnerability which when successfully exploited could lead to a large out-of-bounds write causing the server to crash. Successful exploitation of this vulnerability could lead to addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
High [CVE-2026-58221] Samba Vulnerability in NetApp Products
Samba AD DC versions 4.0.0 and higher are susceptible to a vulnerability which when successfully exploited permits a domain takeover by allowing low-privilege authenticated LDAP access modifications to internal LDB special DNs. Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
High [CVE-2026-14456] OpenSSL Vulnerability in NetApp Products
OpenSSL versions 4.0, 3.6, and 3.5 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
High [CVE-2026-58043] Node.js Vulnerability in NetApp Products
Node.js versions 22.x through 22.23.1, 24.x through 24.18.0, and 26.x through 26.5.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
Medium [CVE-2026-44517] Build breakout via malicious Git repository or tar archive
Build breakout via malicious Git repository or tar archive. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-22. Affected products named by the advisory: Red Hat Certification Program for Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat OpenShift Container Platform 4; Red Hat OpenShift Dev Spaces; and 4 more. Affected products named by the advisory: Red Hat OpenStack Platform 18.0; Red Hat Quay 3; Red Hat package: buildah; Red Hat package: podman.
Medium [CVE-2026-59654] Missing Release of Resource after Effective Lifetime vulnerability in Apache CloudStack's scoped global configuration functionality
Missing Release of Resource after Effective Lifetime vulnerability in Apache CloudStack's scoped global configuration functionality. It affects different modules and plugins of the CloudStack management server, including Quota, Host-HA, etc., and may lead to eventual denial of service (DoS) scenario for the management server. This issue affects Apache CloudStack: from 4.7.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.
Medium [CVE-2026-59296] Line-protocol and log injection via unsanitized input allows metric and log spoofing
Line-protocol and log injection via unsanitized input allows metric and log spoofing. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-93. Affected products named by the advisory: Exploit Intelligence; Red Hat AMQ Broker 7; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; and 9 more. Affected products named by the advisory: Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; Red Hat Build of Keycloak; Red Hat build of Quarkus; and 5 more.
Medium [CVE-2026-59323] Spring Boot: application using Micrometer Tracing with W3C baggage propagation in the Brave bridge is vulnerable to denial of s…
An application using Micrometer Tracing with W3C baggage propagation in the Brave bridge is vulnerable to denial of service (DoS) due to unbounded object allocation when extracting incoming baggage headers. Specifically, an application is vulnerable when all the following are true: - W3C propagation is active (either configured manually or active by default, such as in Spring Boot 3.x+). - Baggage propagation is enabled (which is the default in Spring Boot 3.x+) and a baggage manager (such as BraveBaggageManager) is configured to handle baggage fields. - The application processes requests or messages from untrusted sources with baggage headers which it normally should not, see:. - Network components including the (HTTP) server that receives the request do not limit the header size or the limit is high enough to cause issues. The last two points are very important: normally this should not affect applications because they should not receive untrusted and unlimited input for baggage. When extracting baggage from the W3C baggage header, incoming entries are parsed without enforcing limits on the number of entries or header size as mandated by the W3C Baggage specification. An attacker can send requests or messages with artificially inflated baggage headers containing many key-value pairs, causing unconditional BaggageField allocations per entry.