Complete feed
Recently updated
Advisories the vendor has revised
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-80553] Cancel existing workqueues
Cancel existing workqueues. Red Hat rates this moderate (CVSS 7). Weakness: CWE-364. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-80558] Avoid using invalid osd indices from primary_temp
Avoid using invalid osd indices from primary_temp. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
High [CVE-2026-80571] papr-phy-attest - validate cmd.length, plug mem leak
papr-phy-attest - validate cmd.length, plug mem leak. Red Hat rates this moderate (CVSS 7). Weakness: CWE-805. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-80582] Check VMA boundaries for PMD mappings
Check VMA boundaries for PMD mappings. Red Hat rates this moderate (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.
High [CVE-2026-74737] Fix port_id extraction from SRC TAG
Fix port_id extraction from SRC TAG. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.
High [CVE-2026-80584] validate user buffer length in SNMP and ARP query ioctls
validate user buffer length in SNMP and ARP query ioctls. Red Hat rates this moderate (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-80521] Unlink scc_entry in unix_del_edge
Unlink scc_entry in unix_del_edge(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-367. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat package: kernel.
High [CVE-2026-74746] publish GC-visible tuple last
publish GC-visible tuple last. Red Hat rates this important (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-80540] Fix UVD decode image min size calculation
Fix UVD decode image min size calculation. Red Hat rates this moderate (CVSS 7). Weakness: CWE-190.
High [CVE-2026-80589] stop the timeout timer when releasing a never added disk
stop the timeout timer when releasing a never added disk. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-80528] avoid fs reclaim while using current->journal_info
avoid fs reclaim while using current->journal_info. Red Hat rates this moderate (CVSS 7). Weakness: CWE-843. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
High [CVE-2026-80552] Ensure index for read/write regions are within range
Ensure index for read/write regions are within range. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-80561] fix multiple unsafe decodes in decode_locker
fix multiple unsafe decodes in decode_locker(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
High [CVE-2026-57171] Arbitrary file write via path traversal in author generate commands
Arbitrary file write via path traversal in author generate commands. Red Hat rates this important (CVSS 7.7). Weakness: CWE-22. Affected product named by the advisory: File Integrity Operator.
High [CVE-2026-57170] Arbitrary code execution via Server-Side Template Injection
Arbitrary code execution via Server-Side Template Injection. Red Hat rates this important (CVSS 7.8). Weakness: CWE-917. Affected product named by the advisory: File Integrity Operator.
High [CVE-2026-52776] Server-Side Request Forgery (SSRF) bypass via IPv4-mapped IPv6 and 0.0.0.0
Server-Side Request Forgery (SSRF) bypass via IPv4-mapped IPv6 and 0.0.0.0. Red Hat rates this important (CVSS 8.1). Weakness: CWE-1289. Affected product named by the advisory: File Integrity Operator.
High [CVE-2026-54757] Remote Code Execution via Server-Side Template Injection
Remote Code Execution via Server-Side Template Injection. Red Hat rates this important (CVSS 7.8). Weakness: CWE-917. Affected product named by the advisory: File Integrity Operator.
High [CVE-2026-41707] Spring Security: Authentication Bypass by Capture-replay vulnerability in Spring Spring Security allows Spring Security's DPoPProofJwt…
Authentication Bypass by Capture-replay vulnerability in Spring Spring Security allows Spring Security's DPoPProofJwtDecoderFactory contains a cache-based replay attack vulnerability. The internal cache storing JWT ID claims has a strict size limit, allowing attackers to evict legitimate entries by flooding the server with dummy requests, then replay intercepted valid DPoP proofs. This issue affects Spring Security: 7.1.0, from 7.0.0 through 7.0.6, and from 6.5.0 through 6.5.11.
High [CVE-2026-16645] Unauthorized access due to missing authorization
Unauthorized access due to missing authorization. Red Hat rates this important (CVSS 7.5). Weakness: CWE-425.
High [CVE-2026-68763] Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/2 backlog tracking when a stream is reset This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.39 through 9.0.120
Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/2 backlog tracking when a stream is reset This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.39 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.59 through 8.5.100. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.