Complete feed
Security advisories & CVEs
432 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Critical [CVE-2026-18948] Unsafe dill deserialization of registry-stored UDFs — RCE on feature server and registry server
Unsafe dill deserialization of registry-stored UDFs — RCE on feature server and registry server. Red Hat rates this critical (CVSS 9.9). Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-feature-server-rhel9:1787068065, rhoai/odh-feature-server-rhel9:1786110051, rhoai/odh-feature-server-rhel9:1786110033, rhoai/odh-feature-server-rhel9:1786107278. Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.4.
Critical [CVE-2026-14450] Privilege escalation via forged HTTP headers due to missing authentication
Privilege escalation via forged HTTP headers due to missing authentication. Red Hat rates this important (CVSS 9.9). Weakness: CWE-290. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-maas-api-rhel9:1785850409, rhoai/odh-maas-api-rhel9:1787153683. Affected product named by the advisory: Red Hat OpenShift AI 3.4.
Critical [CVE-2026-66801] shared Kafka gh-spec topic Write ACL plus spoofable CloudEvent source enables fleet-wide cluster-admin from any compromised managed hub
shared Kafka gh-spec topic Write ACL plus spoofable CloudEvent source enables fleet-wide cluster-admin from any compromised managed hub. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-290. Red Hat lists fixing advisory RHSA-2026:54577 with package multicluster-globalhub/multicluster-globalhub-rhel9-operator:1786621416, multicluster-globalhub/multicluster-globalhub-rhel9-operator:1786071343, multicluster-globalhub/multicluster-globalhub-rhel9-operator:1786067967, multicluster-globalhub/multicluster-globalhub-rhel9-operator:1785773214.
Critical [CVE-2026-19173] Sandbox escape via out-of-bounds write in Chromium
Sandbox escape via out-of-bounds write in Chromium. Red Hat rates this important (CVSS 9). Weakness: CWE-787.
Critical [CVE-2026-19155] Sandbox escape via use-after-free in Payments
Sandbox escape via use-after-free in Payments. Red Hat rates this important (CVSS 9). Weakness: CWE-825.
Critical [CVE-2026-19137] Google Chrome on Android: Sandbox escape via use after free in WebGL
Google Chrome on Android: Sandbox escape via use after free in WebGL. Red Hat rates this important (CVSS 9). Weakness: CWE-825.
Critical [CVE-2026-71476] @nx/s3-cache: @nx/gcs-cache: @nx/azure-cache: @nx/shared-fs-cache: @nx/powerpack-s3-cache: @nx/powerpack-gcs-cache: @nx/powerpack-azure-cache: @nx/powerpack-shared-fs-cache: Nx: Remote Code Executi…
@nx/s3-cache: @nx/gcs-cache: @nx/azure-cache: @nx/shared-fs-cache: @nx/powerpack-s3-cache: @nx/powerpack-gcs-cache: @nx/powerpack-azure-cache: @nx/powerpack-shared-fs-cache: Nx: Remote Code Execution via Zip-Slip vulnerability in self-hosted remote cache. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-22. Affected product named by the advisory: Red Hat Ansible Automation Platform 2.
Critical [CVE-2026-5134] Loca Software Informatics Technology Ltd. Co. CMS: CMS: Critical SQL Injection vulnerability
Loca Software Informatics Technology Ltd. Co. CMS: CMS: Critical SQL Injection vulnerability. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-89.
Critical [CVE-2026-10090] namespace edit user can deploy cluster-scoped ClusterRoleBinding and become cluster-admin via Application Subscription
namespace edit user can deploy cluster-scoped ClusterRoleBinding and become cluster-admin via Application Subscription. Red Hat rates this important (CVSS 9). Weakness: CWE-267. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat Advanced Cluster Management for Kubernetes 2.17; Red Hat Advanced Cluster Management for Kubernetes 2.11; and 2 more.
Critical [CVE-2026-10059] namespace admin can escalate to cluster-wide curator authority via ClusterCurator ServiceAccount token
namespace admin can escalate to cluster-wide curator authority via ClusterCurator ServiceAccount token. Red Hat rates this important (CVSS 9.1). Weakness: CWE-266. Red Hat lists fixing advisory RHSA-2026:59557 with package multicluster-engine/cluster-curator-controller-rhel9:1787238383, multicluster-engine/cluster-curator-controller-rhel9:1787264185, multicluster-engine/cluster-curator-controller-rhel9:1787259011, multicluster-engine/cluster-curator-controller-rhel9:1787201612. Affected product named by the advisory: Multicluster Engine for Kubernetes.
Critical [CVE-2026-69240] SQL Injection via improper handling of Oracle date functions
SQL Injection via improper handling of Oracle date functions. Red Hat rates this important (CVSS 9.8). Weakness: CWE-89. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Satellite 6.
Critical [CVE-2026-68579] Arbitrary Code Execution via Heap Overflow in Clipboard Processing
Arbitrary Code Execution via Heap Overflow in Clipboard Processing. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-787.
Critical [CVE-2026-17566] pgAdmin 4: pgAdmin 4: Remote Code Execution via backslash-escape mismatch in Import/Export Data tool
pgAdmin 4: pgAdmin 4: Remote Code Execution via backslash-escape mismatch in Import/Export Data tool. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-78.
Critical [CVE-2026-17349] pgAdmin 4: Unauthorized database credential access via adhoc server cloning
pgAdmin 4: Unauthorized database credential access via adhoc server cloning. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-639.
Critical [CVE-2026-18363] Account compromise via password reset token bypass
Account compromise via password reset token bypass. Red Hat rates this critical (CVSS 9.1). Weakness: CWE-640.
Critical [CVE-2026-44092] Integrity and availability loss via malicious MQTT input injection
Integrity and availability loss via malicious MQTT input injection. Red Hat rates this critical (CVSS 9.1). Weakness: CWE-94.
Critical [CVE-2026-17893] Insufficient validation of untrusted input in Updater
Insufficient validation of untrusted input in Updater. Red Hat rates this moderate (CVSS 9). Weakness: CWE-1286.
Critical [CVE-2026-17890] Insufficient validation of untrusted input in DevTools
Insufficient validation of untrusted input in DevTools. Red Hat rates this moderate (CVSS 9). Weakness: CWE-1286.
Critical [CVE-2026-17848] Insufficient validation of untrusted input in Codecs
Insufficient validation of untrusted input in Codecs. Red Hat rates this moderate (CVSS 9.6). Weakness: CWE-190.
Critical [CVE-2026-17850] Inappropriate implementation in Permissions
Inappropriate implementation in Permissions. Red Hat rates this moderate (CVSS 9.3). Weakness: CWE-346.