Skip to content
VulniPulse

Complete feed

Action required

Critical/high still unreviewed, or CISA KEV listed

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Critical9.0Vendor: HighRed Hat Updated

Critical [CVE-2026-71471] Hub Search CR Collector.ImageOverride propagated to every spoke as arbitrary container image

Hub Search CR Collector. ImageOverride propagated to every spoke as arbitrary container image. Red Hat rates this important (CVSS 9). Weakness: CWE-829. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/acm-search-v2-rhel9:1787682033, rhacm2/acm-search-v2-rhel9:1787681674, rhacm2/acm-search-v2-rhel9:1787681686, rhacm2/acm-search-v2-rhel9:1787682112. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.

CVE-2026-71471
Unclassified
Aug 12, 2026
Critical9.1Red Hat Updated

Critical [CVE-2026-73501] ValidationHandler.Load Fail-Open Authentication Bypass via NoopAuthenticationFunc Default

ValidationHandler. Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default. Red Hat rates this critical (CVSS 9.1). Weakness: CWE-306. Red Hat lists fixing advisory RHSA-2026:59030 with package grafana13-2-main-13.2.0-0.1.1.hum1, hugo-main-0.165.0-0.1.hum1, grafana13-1-main-13.1.3-0.2.hum1, grafana12-4-main-12.4.9-0.4.hum1. Affected products named by the advisory: Red Hat Hardened Images; Migration Toolkit for Applications 8; OpenShift Serverless; Red Hat OpenShift Container Platform 4; and 2 more. Affected products named by the advisory: Red Hat OpenShift GitOps; Red Hat OpenStack Platform 18.0.

CVE-2026-73501
Unclassified
Aug 12, 2026
Critical9.9Vendor: HighRed Hat Updated

Critical [CVE-2026-72508] hub and spoke ServiceAccounts bound to wildcard RBAC (*/*/*)

hub and spoke ServiceAccounts bound to wildcard RBAC (*/*/*). Red Hat rates this important (CVSS 9.9). Weakness: CWE-250. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/multicluster-operators-subscription-rhel9:1787242108, rhacm2/multicluster-operators-subscription-rhel9:1787263693, rhacm2/multicluster-operators-subscription-rhel9:1787242321, rhacm2/multicluster-operators-subscription-rhel9:1787240030. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.

CVE-2026-72508
Unclassified
Aug 12, 2026
Critical9.6Vendor: HighRed Hat Updated

Critical [CVE-2026-70398] GitOpsCluster.spec.argoServer.argoNamespace writes spoke bearer tokens to attacker-chosen namespace

GitOpsCluster.spec.argoServer.argoNamespace writes spoke bearer tokens to attacker-chosen namespace. Red Hat rates this important (CVSS 9.6). Weakness: CWE-441. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/multicloud-integrations-rhel9:1787252179, rhacm2/multicloud-integrations-rhel9:1787260689, rhacm2/multicloud-integrations-rhel9:1787259106, rhacm2/multicloud-integrations-rhel9:1787243221. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.

CVE-2026-70398
Unclassified
Aug 12, 2026
Critical9.9Vendor: HighRed Hat Updated

Critical [CVE-2026-72526] pull-model propagation allows hub tenant to target arbitrary spoke cluster via unvalidated ocm-managed-cluster annotation

pull-model propagation allows hub tenant to target arbitrary spoke cluster via unvalidated ocm-managed-cluster annotation. Red Hat rates this important (CVSS 9.9). Weakness: CWE-441. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/multicloud-integrations-rhel9:1787252179, rhacm2/multicloud-integrations-rhel9:1787260689, rhacm2/multicloud-integrations-rhel9:1787259106, rhacm2/multicloud-integrations-rhel9:1787243221. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.

CVE-2026-72526
Unclassified
Aug 12, 2026
High7.5Red Hat

High [CVE-2026-46382] Server-Side Request Forgery in import functionality

Server-Side Request Forgery in import functionality. Red Hat rates this important (CVSS 7.5). Weakness: CWE-918.

CVE-2026-46382
Unclassified
Aug 12, 2026
High7.5Red Hat Updated

High [CVE-2026-71469] Unbounded tokenReviews cache allows unauthenticated memory-exhaustion DoS

Unbounded tokenReviews cache allows unauthenticated memory-exhaustion DoS. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/acm-search-v2-api-rhel9:1787191668, rhacm2/acm-search-v2-api-rhel9:1787263804, rhacm2/acm-search-v2-api-rhel9:1787238618, rhacm2/acm-search-v2-api-rhel9:1787229541. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.

CVE-2026-71469
Unclassified
Aug 12, 2026
High8.5Red Hat Updated

High [CVE-2026-71473] addonfactory.GetValuesFromAddonAnnotation enables arbitrary Helm-values override per spoke

addonfactory. GetValuesFromAddonAnnotation enables arbitrary Helm-values override per spoke. Red Hat rates this important (CVSS 8.5). Weakness: CWE-915. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/acm-search-v2-rhel9:1787682033, rhacm2/acm-search-v2-rhel9:1787681674, rhacm2/acm-search-v2-rhel9:1787681686, rhacm2/acm-search-v2-rhel9:1787682112. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.

CVE-2026-71473
Unclassified
Aug 12, 2026
High7.5Red Hat

High [CVE-2026-73500] Denial of Service via unbounded TLS handshake goroutines

Denial of Service via unbounded TLS handshake goroutines. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Multicluster Global Hub; Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Ansible Automation Platform 2; Red Hat Ceph Storage 5; and 11 more. Affected products named by the advisory: Red Hat Ceph Storage 6; Red Hat Ceph Storage 7; Red Hat Ceph Storage 8; Red Hat Ceph Storage 9; and 7 more.

CVE-2026-73500
Unclassified
Aug 12, 2026
High7.5Red Hat

High [CVE-2026-19654] Rsyslog: a configuration-dependent issue in rsyslog's optional imptcp input module can allow an unauthenticated remote peer to crash rsyslogd

A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege escalation, or code execution has been identified. imtcp and the default imptcp framing modes are not affected. This vulnerability in rsyslog allows an unauthenticated peer to crash the rsyslogd deamon, resulting a a Denial-of-Service, by sending a crafted input sequence. This happens because the malicious input ends creating an invalid internal message length, which crashes the rsyslogd receiving the input. This vulnerability is only exploitable when the following conditions are met: * imptcp module is explicitly loaded * There's an imptcp listener using the non-default framing.delimiter.regex mode * The attacker is able to establish a TCP connection to the target listener Although this vulnerability has been rated as having an Important severity in upstream, the Red Hat Product Security team has rated it as having a MODERATE severity in supported Red Hat Products. This happens because the conditions described above are not met in default configurations of the `rsyslog` package as shipped with Red Hat Enterprise Linux Versions. Weakness: CWE-125.

CVE-2026-19654
Red Hat Enterprise Linux
Aug 12, 2026
High8.8Red Hat

High [CVE-2026-13622] virt-handler migration proxy follows symlinks allowing container escape to host

virt-handler migration proxy follows symlinks allowing container escape to host. Red Hat rates this important (CVSS 8.8). Weakness: CWE-22. Red Hat lists fixing advisory RHSA-2026:53763 with package container-native-virtualization/virt-handler-rhel9:1786348529, container-native-virtualization/virt-handler-rhel9:1786309624, container-native-virtualization/virt-handler:1785837722, container-native-virtualization/virt-handler-rhel9:1786334215. Affected products named by the advisory: Red Hat Container Native Virtualization 4.12; Red Hat Container Native Virtualization 4.13; Red Hat Container Native Virtualization 4.14; Red Hat Container Native Virtualization 4.15; and 7 more. Affected products named by the advisory: Red Hat Container Native Virtualization 4.16; Red Hat Container Native Virtualization 4.17; Red Hat Container Native Virtualization 4.18; Red Hat Container Native Virtualization 4.19; and 3 more.

CVE-2026-13622
Unclassified
Aug 12, 2026
High8.1Red Hat Updated

High [CVE-2026-73422] Arbitrary code execution via unescaped View Transition animation properties

Arbitrary code execution via unescaped View Transition animation properties. Red Hat rates this important (CVSS 8.1). Weakness: CWE-79. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).

CVE-2026-73422
Unclassified
Aug 12, 2026
High8.0Red Hat

High [CVE-2026-73415] Arbitrary code execution via malicious image in image viewer

Arbitrary code execution via malicious image in image viewer. Red Hat rates this important (CVSS 8). Weakness: CWE-911. Affected products named by the advisory: Migration Toolkit for Applications 8; Red Hat OpenShift AI (RHOAI).

CVE-2026-73415
Unclassified
Aug 12, 2026
High7.6Vendor: MediumRed Hat

High [CVE-2026-18724] Stack buffer overflow in idbm record parsing

Stack buffer overflow in idbm record parsing. Red Hat rates this moderate (CVSS 7.6). Weakness: CWE-121. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: iscsi-initiator-utils.

CVE-2026-18724
Red Hat Enterprise Linux
Aug 12, 2026
High7.7Red Hat Updated

High [CVE-2026-73122] auto-generated Role grants every managed-cluster agent secrets:get,list,watch in Channel namespaces

auto-generated Role grants every managed-cluster agent secrets:get,list,watch in Channel namespaces. Red Hat rates this important (CVSS 7.7). Weakness: CWE-269. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/multicluster-operators-channel-rhel9:1787259310, rhacm2/multicluster-operators-channel-rhel9:1787242099, rhacm2/multicluster-operators-channel-rhel9:1787238600, rhacm2/multicluster-operators-channel-rhel9:1787260663. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.

CVE-2026-73122
Unclassified
Aug 12, 2026
High7.7Red Hat Updated

High [CVE-2026-66878] FetchChannelReferences honours Channel.spec.secretRef.namespace enabling cross-namespace Secret exfiltration

FetchChannelReferences honours Channel.spec.secretRef.namespace enabling cross-namespace Secret exfiltration. Red Hat rates this important (CVSS 7.7). Weakness: CWE-639. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/multicluster-operators-subscription-rhel9:1787242108, rhacm2/multicluster-operators-subscription-rhel9:1787263693, rhacm2/multicluster-operators-subscription-rhel9:1787242321, rhacm2/multicluster-operators-subscription-rhel9:1787240030. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.

CVE-2026-66878
Unclassified
Aug 12, 2026
High7.0Red Hat

High [CVE-2026-68432] require CAP_NET_ADMIN in the device netns for changelink

require CAP_NET_ADMIN in the device netns for changelink. Red Hat rates this important (CVSS 7). Weakness: CWE-266. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-68432
Linux Kernel
Aug 12, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-68442] don't propagate EXTENT_FLAG_LOGGING to split extent maps

don't propagate EXTENT_FLAG_LOGGING to split extent maps. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux for NVIDIA 26; Red Hat package: kernel.

CVE-2026-68442
Linux Kernel
Aug 12, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-68448] check access to copy_file_range source with src mounter creds

check access to copy_file_range source with src mounter creds. Red Hat rates this moderate (CVSS 7). Weakness: CWE-266. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26; Red Hat package: kernel-rt.

CVE-2026-68448
Linux Kernel
Aug 12, 2026
Critical9.9Red Hat

Critical [CVE-2026-73213] Server-Side Request Forgery via incorrect IPv6 comparison

Server-Side Request Forgery via incorrect IPv6 comparison. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-918.

CVE-2026-73213
Unclassified
Aug 11, 2026