Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

3298 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High8.1Red Hat

High [CVE-2026-15556] picketlink SAML 2.0 auth bypass via missing assertions

picketlink SAML 2.0 auth bypass via missing assertions. Red Hat rates this important (CVSS 8.1). Weakness: CWE-347. Red Hat lists fixing advisory RHSA-2026:53806 with package eap7-ironjacamar-0:1.5.26-2.Final_redhat_00001.1.el7eap, eap7-undertow-0:2.2.40-2.SP3_redhat_00001.1.el7eap, eap7-wildfly-0:7.4.25-2.GA_redhat_00001.1.el7eap, eap7-netty-0:4.1.135-1.Final_redhat_00001.1.el7eap. Affected product named by the advisory: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7.

CVE-2026-15556
Unclassified
Aug 11, 2026
High8.8Red Hat

High [CVE-2026-15555] wildfly-clustering-infinispan-marshalling: Jboss Deserialization RCE via Unfiltered River Unmarshaller

wildfly-clustering-infinispan-marshalling: Jboss Deserialization RCE via Unfiltered River Unmarshaller. Red Hat rates this important (CVSS 8.8). Weakness: CWE-502. Red Hat lists fixing advisory RHSA-2026:53806 with package eap7-ironjacamar-0:1.5.26-2.Final_redhat_00001.1.el7eap, eap7-undertow-0:2.2.40-2.SP3_redhat_00001.1.el7eap, eap7-wildfly-0:7.4.25-2.GA_redhat_00001.1.el7eap, eap7-netty-0:4.1.135-1.Final_redhat_00001.1.el7eap. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack.

CVE-2026-15555
Unclassified
Aug 11, 2026
High7.4Red Hat

High [CVE-2026-15554] Authentication Bypass via AJP ssl_cert/is_ssl Forgery

Authentication Bypass via AJP ssl_cert/is_ssl Forgery. Red Hat rates this important (CVSS 7.4). Weakness: CWE-295. Red Hat lists fixing advisory RHSA-2026:53806 with package eap7-ironjacamar-0:1.5.26-2.Final_redhat_00001.1.el7eap, eap7-undertow-0:2.2.40-2.SP3_redhat_00001.1.el7eap, eap7-wildfly-0:7.4.25-2.GA_redhat_00001.1.el7eap, eap7-netty-0:4.1.135-1.Final_redhat_00001.1.el7eap. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7; Red Hat JBoss Enterprise Application Platform 8.

CVE-2026-15554
Unclassified
Aug 11, 2026
High7.8Vendor: MediumRed Hat

High [CVE-2026-72693] Local privilege escalation in openvt via incorrect process owner verification allowing passwordless root login

Local privilege escalation in openvt via incorrect process owner verification allowing passwordless root login. Red Hat rates this moderate (CVSS 7.8). Weakness: CWE-284. Red Hat lists fixing advisory RHSA-2026:41136 with package kbd-0:2.4.0-12.el9_8, kbd-0:2.6.4-8.el10_2, kbd-main-2.10.0-2.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.

CVE-2026-72693
Unclassified
Aug 11, 2026
High7.1Red Hat

High [CVE-2026-72694] MRTG daemon symlink-following chown allows local privilege escalation via PID file path manipulation

MRTG daemon symlink-following chown allows local privilege escalation via PID file path manipulation. Red Hat rates this important (CVSS 7.1). Weakness: CWE-59. Red Hat lists fixing advisory RHSA-2026:57596 with package mrtg-0:2.17.10-12.el10_2.1, mrtg-0:2.17.7-12.el9_8.1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9.

CVE-2026-72694
Unclassified
Aug 11, 2026
High7.2Red Hat

High [CVE-2026-4757] Code execution and privilege escalation via VAPIX API improper input validation

Code execution and privilege escalation via VAPIX API improper input validation. Red Hat rates this important (CVSS 7.2). Weakness: CWE-94. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat package: axis.

CVE-2026-4757
Red Hat Enterprise Linux
Aug 11, 2026
High8.5Red Hat Updated

High [CVE-2026-66797] Velero Restore includes cluster-scoped RBAC resources with no exclusion — tampered backup yields hub cluster-admin

Velero Restore includes cluster-scoped RBAC resources with no exclusion — tampered backup yields hub cluster-admin. Red Hat rates this important (CVSS 8.5). Weakness: CWE-862. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/cluster-backup-rhel9-operator:1787684668, rhacm2/cluster-backup-rhel9-operator:1787238500, rhacm2/cluster-backup-rhel9-operator:1787227576, rhacm2/cluster-backup-rhel9-operator:1787183178. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-66797
Unclassified
Aug 11, 2026
High8.8Red Hat Updated

High [CVE-2026-66798] Restore.spec.hooks passed verbatim to Velero Restore — arbitrary command execution in restored pods

Restore.spec.hooks passed verbatim to Velero Restore — arbitrary command execution in restored pods. Red Hat rates this important (CVSS 8.8). Weakness: CWE-77. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/cluster-backup-rhel9-operator:1787684668, rhacm2/cluster-backup-rhel9-operator:1787238500, rhacm2/cluster-backup-rhel9-operator:1787227576, rhacm2/cluster-backup-rhel9-operator:1787183178. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-66798
Unclassified
Aug 11, 2026
High7.1Red Hat Updated

High [CVE-2026-66799] Restore.spec.namespaceMapping pass-through enables cross-namespace Secret/ConfigMap placement

Restore.spec.namespaceMapping pass-through enables cross-namespace Secret/ConfigMap placement. Red Hat rates this important (CVSS 7.1). Weakness: CWE-863. Red Hat lists fixing advisory RHSA-2026:60390 with package rhacm2/cluster-backup-rhel9-operator:1787238500, rhacm2/cluster-backup-rhel9-operator:1787227576, rhacm2/cluster-backup-rhel9-operator:1787183178, rhacm2/cluster-backup-rhel9-operator:1787259060. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-66799
Unclassified
Aug 11, 2026
High7.1Red Hat Updated

High [CVE-2026-66800] CleanupAll triggers unguarded cluster-wide mass-delete via operator ServiceAccount

CleanupAll triggers unguarded cluster-wide mass-delete via operator ServiceAccount. Red Hat rates this important (CVSS 7.1). Weakness: CWE-862. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/cluster-backup-rhel9-operator:1787684668, rhacm2/cluster-backup-rhel9-operator:1787238500, rhacm2/cluster-backup-rhel9-operator:1787227576, rhacm2/cluster-backup-rhel9-operator:1787183178. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-66800
Unclassified
Aug 11, 2026
High7.5Red Hat

High [CVE-2026-62901] .NET:.NET Denial of Service Vulnerability

.NET:.NET Denial of Service Vulnerability. Red Hat rates this important (CVSS 7.5). Weakness: CWE-606. Red Hat lists fixing advisory RHSA-2026:54542 with package dotnet8-0-main-8.0.130-0.1.hum1, dotnet8.0-0:8.0.130-1.el8_10, dotnet9.0-0:9.0.120-1.el9_6, dotnet10.0-0:10.0.111-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.

CVE-2026-62901
Unclassified
Aug 11, 2026
High7.8Red Hat

High [CVE-2026-62909] .NET:.NET Elevation of Privilege Vulnerability

.NET:.NET Elevation of Privilege Vulnerability. Red Hat rates this important (CVSS 7.8). Weakness: CWE-252. Red Hat lists fixing advisory RHSA-2026:54542 with package dotnet8-0-main-8.0.130-0.1.hum1, dotnet8.0-0:8.0.130-1.el8_10, dotnet9.0-0:9.0.120-1.el9_6, dotnet10.0-0:10.0.111-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.

CVE-2026-62909
Unclassified
Aug 11, 2026
High7.1Red Hat

High [CVE-2026-73266] tenant-controlled ClusterClaim labels propagated to ManagedCluster enabling cross-tenant ManagedClusterSet join

tenant-controlled ClusterClaim labels propagated to ManagedCluster enabling cross-tenant ManagedClusterSet join. Red Hat rates this important (CVSS 7.1). Weakness: CWE-441. Red Hat lists fixing advisory RHSA-2026:59593 with package multicluster-engine/clusterclaims-controller-rhel9:1787259112, multicluster-engine/clusterclaims-controller-rhel9:1786577950, multicluster-engine/clusterclaims-controller-rhel9:1787239442, multicluster-engine/clusterclaims-controller-rhel9:1787259059. Affected product named by the advisory: Multicluster Engine for Kubernetes.

CVE-2026-73266
Unclassified
Aug 11, 2026
High7.7Red Hat Updated

High [CVE-2026-73267] ManagedCluster deletion keyed solely on ClusterClaim.Spec.Namespace with no ownership check

ManagedCluster deletion keyed solely on ClusterClaim. Spec. Namespace with no ownership check. Red Hat rates this important (CVSS 7.7). Weakness: CWE-602. Red Hat lists fixing advisory RHSA-2026:59593 with package multicluster-engine/clusterclaims-controller-rhel9:1787259112, multicluster-engine/clusterclaims-controller-rhel9:1786577950, multicluster-engine/clusterclaims-controller-rhel9:1787239442, multicluster-engine/clusterclaims-controller-rhel9:1787259059. Affected products named by the advisory: multicluster engine for Kubernetes 2.10; multicluster engine for Kubernetes 2.11; multicluster engine for Kubernetes 2.17; multicluster engine for Kubernetes 2.6; and 2 more. Affected products named by the advisory: multicluster engine for Kubernetes 2.8; multicluster engine for Kubernetes 2.9.

CVE-2026-73267
Unclassified
Aug 11, 2026
High7.4Red Hat Updated

High [CVE-2026-66806] TLS verification disabled when sending hub pull-secret to console.redhat.com

TLS verification disabled when sending hub pull-secret to console.redhat.com. Red Hat rates this important (CVSS 7.4). Weakness: CWE-295. Red Hat lists fixing advisory RHSA-2026:59579 with package multicluster-engine/console-mce-rhel9:1787264250, rhacm2/console-rhel9:1787687062. Affected products named by the advisory: Multicluster Engine for Kubernetes; Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-66806
Unclassified
Aug 10, 2026
High7.8Red Hat

High [CVE-2026-72913] Arbitrary Code Execution via Chained DCS Escape Sequences

Arbitrary Code Execution via Chained DCS Escape Sequences. Red Hat rates this important (CVSS 7.8). Weakness: CWE-78. Affected products named by the advisory: External Secrets Operator for Red Hat OpenShift; Logging Subsystem for Red Hat OpenShift; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: gvisor-tap-vsock.

CVE-2026-72913
Red Hat Enterprise Linux
Aug 10, 2026
High7.8Red Hat

High [CVE-2026-63622] swtpm privilege escalation via symlink following

swtpm privilege escalation via symlink following. Red Hat rates this important (CVSS 7.8). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux for NVIDIA 26; Red Hat package: libvirt.

CVE-2026-63622
Red Hat Enterprise Linux
Aug 10, 2026
High8.8Vendor: CriticalRed Hat Updated

High [CVE-2026-18982] RHOAI fork aggregates training job create onto native edit/admin ClusterRoles

RHOAI fork aggregates training job create onto native edit/admin ClusterRoles. Red Hat rates this critical (CVSS 8.8). Weakness: CWE-250. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-training-operator-rhel9:1787361677, rhoai/odh-training-operator-rhel9:1784814352, rhoai/odh-training-operator-rhel9:1785187053, rhoai/odh-training-operator-rhel9:1785188461. Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.4.

CVE-2026-18982
Unclassified
Aug 10, 2026
High8.8Vendor: CriticalRed Hat Updated

High [CVE-2026-18951] [Trainer v2 Security] TRN-02: RHOAI overlay aggregates trainjobs CRUD into standard edit ClusterRole

[Trainer v2 Security] TRN-02: RHOAI overlay aggregates trainjobs CRUD into standard edit ClusterRole. Red Hat rates this critical (CVSS 8.8). Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-training-operator-rhel9:1787361677, rhoai/odh-training-operator-rhel9:1784814352, rhoai/odh-training-operator-rhel9:1785188461. Affected products named by the advisory: Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.4.

CVE-2026-18951
Unclassified
Aug 10, 2026
High8.8Vendor: CriticalRed Hat

High [CVE-2026-18950] Confused-deputy privilege escalation via unchecked roleRef in RoleBinding creation

Confused-deputy privilege escalation via unchecked roleRef in RoleBinding creation. Red Hat rates this critical (CVSS 8.8). Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-dashboard-rhel9:1786109665, rhoai/odh-dashboard-rhel9:1785940823, rhoai/odh-dashboard-rhel9:1786109683. Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.4.

CVE-2026-18950
Unclassified
Aug 10, 2026