Skip to content
VulniPulse

Complete feed

Action required

Critical/high still unreviewed, or CISA KEV listed

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Critical9.8Red Hat

Critical [CVE-2026-10579] auth bypass in Picketlink SAML unsolicited-response

auth bypass in Picketlink SAML unsolicited-response. Red Hat rates this critical (CVSS 9.8). Red Hat lists fixing advisory RHSA-2026:53806 with package eap7-ironjacamar-0:1.5.26-2.Final_redhat_00001.1.el7eap, eap7-undertow-0:2.2.40-2.SP3_redhat_00001.1.el7eap, eap7-wildfly-0:7.4.25-2.GA_redhat_00001.1.el7eap, eap7-netty-0:4.1.135-1.Final_redhat_00001.1.el7eap. Affected product named by the advisory: Red Hat JBoss Enterprise Application Platform 7.

CVE-2026-10579
Unclassified
Aug 11, 2026
Critical9.9Vendor: HighRed Hat

Critical [CVE-2026-73268] spec.install.overrideJob allows arbitrary Job spec injection

spec.install.overrideJob allows arbitrary Job spec injection. Red Hat rates this important (CVSS 9.9). Weakness: CWE-94. Red Hat lists fixing advisory RHSA-2026:59593 with package multicluster-engine/cluster-curator-controller-rhel9:1787238383, multicluster-engine/cluster-curator-controller-rhel9:1787264185, multicluster-engine/cluster-curator-controller-rhel9:1786750700, multicluster-engine/cluster-curator-controller-rhel9:1787259011. Affected product named by the advisory: Multicluster Engine for Kubernetes.

CVE-2026-73268
Unclassified
Aug 11, 2026
Critical9.9Vendor: HighRed Hat

Critical [CVE-2026-73269] tenant-controllable trigger creates ClusterRoleBinding granting cluster-wide secrets access to namespace-local SA

tenant-controllable trigger creates ClusterRoleBinding granting cluster-wide secrets access to namespace-local SA. Red Hat rates this important (CVSS 9.9). Weakness: CWE-269. Red Hat lists fixing advisory RHSA-2026:59593 with package multicluster-engine/cluster-curator-controller-rhel9:1787238383, multicluster-engine/cluster-curator-controller-rhel9:1787264185, multicluster-engine/cluster-curator-controller-rhel9:1786750700, multicluster-engine/cluster-curator-controller-rhel9:1787259011. Affected product named by the advisory: Multicluster Engine for Kubernetes.

CVE-2026-73269
Unclassified
Aug 11, 2026
High8.8Red Hat

High [CVE-2026-5917] Arbitrary code execution via shell command injection in SSH backend

Arbitrary code execution via shell command injection in SSH backend. Red Hat rates this important (CVSS 8.8). Weakness: CWE-78. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux AI (RHEL AI) 3; and 2 more. Affected products named by the advisory: Red Hat package: rust; Red Hat package: libgit2.

CVE-2026-5917
Red Hat Enterprise Linux
Aug 11, 2026
High7.5Red Hat

High [CVE-2026-29036] Data corruption and unauthorized modification via JSON Pointer escape decoding

Data corruption and unauthorized modification via JSON Pointer escape decoding. Red Hat rates this important (CVSS 7.5). Weakness: CWE-386.

CVE-2026-29036
Unclassified
Aug 11, 2026
High8.8Red Hat

High [CVE-2026-19560] Arbitrary code execution via use-after-free in Blink

Arbitrary code execution via use-after-free in Blink. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825.

CVE-2026-19560
Unclassified
Aug 11, 2026
High8.8Red Hat

High [CVE-2026-19559] Arbitrary code execution via use after free in HTML

Arbitrary code execution via use after free in HTML. Red Hat rates this important (CVSS 8.8). Weakness: CWE-416.

CVE-2026-19559
Unclassified
Aug 11, 2026
High8.2Red Hat

High [CVE-2026-19557] Sandbox escape via use-after-free in TabStrip

Sandbox escape via use-after-free in TabStrip. Red Hat rates this important (CVSS 8.2). Weakness: CWE-825.

CVE-2026-19557
Unclassified
Aug 11, 2026
High7.3Red Hat

High [CVE-2026-19558] Arbitrary code execution via malicious extension installation

Arbitrary code execution via malicious extension installation. Red Hat rates this important (CVSS 7.3). Weakness: CWE-416.

CVE-2026-19558
Unclassified
Aug 11, 2026
High8.8Red Hat

High [CVE-2026-19556] Arbitrary code execution via use-after-free in V8

Arbitrary code execution via use-after-free in V8. Red Hat rates this important (CVSS 8.8). Weakness: CWE-416.

CVE-2026-19556
Unclassified
Aug 11, 2026
High8.2Red Hat

High [CVE-2026-19550] trust-fetch-domains uses trust-read ACI to gate a privileged AD trust refresh, allowing unauthorized LDAP writes

trust-fetch-domains uses trust-read ACI to gate a privileged AD trust refresh, allowing unauthorized LDAP writes. Red Hat rates this important (CVSS 8.2). Weakness: CWE-863. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-19550
Unclassified
Aug 11, 2026
High8.1Red Hat

High [CVE-2026-71290] Server impersonation via improper TLS hostname verification

Server impersonation via improper TLS hostname verification. Red Hat rates this important (CVSS 8.1). Weakness: CWE-295.

CVE-2026-71290
Unclassified
Aug 11, 2026
High7.5Red Hat

High [CVE-2026-29035] Arbitrary code execution via crafted WebSocket frames

Arbitrary code execution via crafted WebSocket frames. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787.

CVE-2026-29035
Unclassified
Aug 11, 2026
High7.5Red Hat

High [CVE-2026-73241] Authentication bypass via incorrect RDSTLS PDU handling

Authentication bypass via incorrect RDSTLS PDU handling. Red Hat rates this important (CVSS 7.5). Weakness: CWE-287. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: freerdp.

CVE-2026-73241
Red Hat Enterprise Linux
Aug 11, 2026
High8.8Red Hat

High [CVE-2026-73231] @faker-js/faker: Faker: Arbitrary Code Execution via attacker-controlled fake templates

@faker-js/faker: Faker: Arbitrary Code Execution via attacker-controlled fake templates. Red Hat rates this important (CVSS 8.8). Weakness: CWE-94. Affected products named by the advisory: Cryostat 4; Red Hat AMQ Broker 7; Red Hat Build of Keycloak; Red Hat Enterprise Linux 10; and 4 more. Affected products named by the advisory: Red Hat Hardened Images; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat package: grafana.

CVE-2026-73231
Red Hat Enterprise Linux
Aug 11, 2026
High7.5Red Hat

High [CVE-2026-71467] Authentication bypass on /federated via Upgrade: websocket header spoofing

Authentication bypass on /federated via Upgrade: websocket header spoofing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-287. Red Hat lists fixing advisory RHSA-2026:60386 with package rhacm2/acm-search-v2-api-rhel9:1787229541. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.17.

CVE-2026-71467
Unclassified
Aug 11, 2026
High7.5Red Hat

High [CVE-2026-48804] Denial of Service via binary attachment accumulation

Denial of Service via binary attachment accumulation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.

CVE-2026-48804
Unclassified
Aug 11, 2026
High7.5Red Hat

High [CVE-2026-73214] Denial of Service via unverified DTLS session state

Denial of Service via unverified DTLS session state. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.

CVE-2026-73214
Unclassified
Aug 11, 2026
High7.7Red Hat Updated

High [CVE-2026-73212] Server-Side Request Forgery and Remote Code Execution via IP address canonicalization bypass

Server-Side Request Forgery and Remote Code Execution via IP address canonicalization bypass. Red Hat rates this important (CVSS 7.7). Weakness: CWE-1389.

CVE-2026-73212
Unclassified
Aug 11, 2026
High7.5Red Hat

High [CVE-2026-73089] Denial of Service via unbounded memory growth from distinct query results

Denial of Service via unbounded memory growth from distinct query results. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:56338 with package ansible-automation-platform/automation-portal:1787047114, grafana13-1-main-13.1.3-0.1.1.hum1, discovery/discovery-ui-rhel9:1786634825, ansible-automation-platform/automation-portal:1787047188. Affected products named by the advisory: Red Hat Hardened Images; Cryostat 4; Gatekeeper 3; Migration Toolkit for Containers; and 43 more. Affected products named by the advisory: Node HealthCheck Operator; OpenShift Lightspeed; OpenShift Pipelines; OpenShift Service Mesh 3; and 39 more.

CVE-2026-73089
Red Hat Enterprise Linux
Aug 11, 2026