Complete feed
Recently updated
Advisories the vendor has revised
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-14680] Arbitrary code execution via type confusion with "internal" arguments
Arbitrary code execution via type confusion with "internal" arguments. Red Hat rates this important (CVSS 8.8). Weakness: CWE-843. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Self-service automation portal 2; Red Hat package: postgresql16; Red Hat package: postgresql18.
High [CVE-2026-14677] Arbitrary code execution in 32-bit pltcl and plperl
Arbitrary code execution in 32-bit pltcl and plperl. Red Hat rates this important (CVSS 8.8). Weakness: CWE-190. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Self-service automation portal 2; Red Hat package: postgresql16; Red Hat package: postgresql18.
High [CVE-2026-14676] PostgreSQL pg_stat_statements: Arbitrary code execution via heap buffer overflow
PostgreSQL pg_stat_statements: Arbitrary code execution via heap buffer overflow. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: postgresql18.
High [CVE-2026-14669] Arbitrary code execution via long POSIX timezone abbreviation
Arbitrary code execution via long POSIX timezone abbreviation. Red Hat rates this important (CVSS 8.8). Weakness: CWE-122. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Self-service automation portal 2; Red Hat package: postgresql16; Red Hat package: postgresql18.
High [CVE-2026-14664] Arbitrary code execution via heap buffer overflow in regexp
Arbitrary code execution via heap buffer overflow in regexp. Red Hat rates this important (CVSS 8.8). Weakness: CWE-122. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Self-service automation portal 2; and 2 more. Affected products named by the advisory: Red Hat package: postgresql16; Red Hat package: postgresql18.
High [CVE-2026-14662] Arbitrary code execution via integer wraparound in tsvector and tsquery functions
Arbitrary code execution via integer wraparound in tsvector and tsquery functions. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Self-service automation portal 2; Red Hat package: postgresql16; Red Hat package: postgresql18.
High [CVE-2026-73627] Plugin manager lock-rule bypass allows unauthorized plugin control
Plugin manager lock-rule bypass allows unauthorized plugin control. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-414. Affected products named by the advisory: Migration Toolkit for Applications 8; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-73624] Arbitrary File Overwrite via improper git option validation
Arbitrary File Overwrite via improper git option validation. Red Hat rates this important (CVSS 8.1). Weakness: CWE-88. Affected products named by the advisory: Exploit Intelligence; Migration Toolkit for Applications 8; Pen Drive Powered by Red Hat Lightspeed; Red Hat AI Inference Server; and 7 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat Hardened Images; Red Hat OpenShift AI (RHOAI); and 3 more.
High [CVE-2026-73625] Remote Code Execution via kwarg value smuggling
Remote Code Execution via kwarg value smuggling. Red Hat rates this important (CVSS 8.8). Weakness: CWE-78. Affected products named by the advisory: Exploit Intelligence; Migration Toolkit for Applications 8; Pen Drive Powered by Red Hat Lightspeed; Red Hat AI Inference Server; and 7 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat Hardened Images; Red Hat OpenShift AI (RHOAI); and 3 more.
High [CVE-2026-73623] Remote Code Execution via malicious Git template
Remote Code Execution via malicious Git template. Red Hat rates this important (CVSS 7.5). Weakness: CWE-78. Affected products named by the advisory: Exploit Intelligence; Migration Toolkit for Applications 8; Pen Drive Powered by Red Hat Lightspeed; Red Hat AI Inference Server; and 7 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat Hardened Images; Red Hat OpenShift AI (RHOAI); and 3 more.
High [CVE-2026-73622] Information disclosure via environment variable expansion in URL handling
Information disclosure via environment variable expansion in URL handling. Red Hat rates this important (CVSS 7.5). Weakness: CWE-914. Affected products named by the advisory: Exploit Intelligence; Migration Toolkit for Applications 8; Pen Drive Powered by Red Hat Lightspeed; Red Hat AI Inference Server; and 7 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat Hardened Images; Red Hat OpenShift AI (RHOAI); and 3 more.
High [CVE-2026-73620] Arbitrary file overwrite and read via unsafe git option forwarding
Arbitrary file overwrite and read via unsafe git option forwarding. Red Hat rates this important (CVSS 8.8). Weakness: CWE-88. Red Hat lists fixing advisory RHSA-2026:59135 with package python3.12-gitpython-0:3.1.59-1.el8ap, python3.12-gitpython-0:3.1.59-1.el9ap. Affected products named by the advisory: Exploit Intelligence; Migration Toolkit for Applications 8; Pen Drive Powered by Red Hat Lightspeed; Red Hat AI Inference Server; and 7 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat Hardened Images; Red Hat OpenShift AI (RHOAI); and 3 more.
High [CVE-2026-45819] Denial of Service via improper input handling
Denial of Service via improper input handling. Red Hat rates this important (CVSS 7.5). Weakness: CWE-617. Red Hat lists fixing advisory RHSA-2026:54517 with package grafana13-1-main-13.1.3-0.1.1.hum1, grafana12-4-main-12.4.8-0.1.1.hum1. Affected products named by the advisory: Cryostat 4; OpenShift Lightspeed; OpenShift Pipelines; OpenShift Service Mesh 3; and 21 more. Affected products named by the advisory: Red Hat AMQ Broker 7; Red Hat Ansible Automation Platform 2; Red Hat Build of Keycloak; Red Hat Build of Podman Desktop; and 17 more.
High [CVE-2026-19484] Denial of Service via oversized multipart boundary
Denial of Service via oversized multipart boundary. Red Hat rates this important (CVSS 7.5). Weakness: CWE-606.
High [CVE-2026-19481] Denial of Service from crafted form-data headers
Denial of Service from crafted form-data headers. Red Hat rates this important (CVSS 7.5). Weakness: CWE-915. Affected products named by the advisory: OpenShift Pipelines; Red Hat AMQ Broker 7; Red Hat Ceph Storage 8; Red Hat Ceph Storage 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4.
High [CVE-2026-67986] Arbitrary code execution via Ruby code injection in AwesomeMethodArray#grep
Arbitrary code execution via Ruby code injection in AwesomeMethodArray#grep. Red Hat rates this important (CVSS 7.8). Weakness: CWE-94.
High [CVE-2026-68453] Fix buffer over-read in cca_cipher2protkey
Fix buffer over-read in cca_cipher2protkey. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-68452] Validate length for CCA AES cipher key requests
Validate length for CCA AES cipher key requests. Red Hat rates this moderate (CVSS 7). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-68451] Validate length for CCA ECC private key requests
Validate length for CCA ECC private key requests. Red Hat rates this moderate (CVSS 7). Weakness: CWE-805. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-46382] Server-Side Request Forgery in import functionality
Server-Side Request Forgery in import functionality. Red Hat rates this important (CVSS 7.5). Weakness: CWE-918.