Complete feed
Security advisories & CVEs
240 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Low [CVE-2026-74976] JIT miscompilation in the JavaScript Engine: JIT component
JIT miscompilation in the JavaScript Engine: JIT component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-733. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Low [CVE-2026-23938] Denial of Service via crafted JavaScript scripts
Denial of Service via crafted JavaScript scripts. Red Hat rates this low (CVSS 2.7). Weakness: CWE-770.
Low [CVE-2026-60589] Improve Resource Resolving (2026-08 Security Update)
Improve Resource Resolving (2026-08 Security Update). Red Hat rates this moderate (CVSS 3.7). Red Hat lists fixing advisory RHSA-2026:55788 with package java-21-openjdk-portable-main-21.0.12.1.1-0.1.hum1, java-25-openjdk-1:25.0.4.1.1-1.1.el9, java-25-openjdk-windows, java-25-openjdk-main-25.0.4.1.1-1.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8.
Low [CVE-2026-74797] Denial of Service via malicious zip archives
Denial of Service via malicious zip archives. Red Hat rates this low (CVSS 3.1). Weakness: CWE-400.
Low [CVE-2026-63650] User misidentification via ignored X.509 identity field
User misidentification via ignored X.509 identity field. Red Hat rates this low (CVSS 3.1). Weakness: CWE-303.
Low [CVE-2026-66807] potential XSS via dangerouslySetInnerHTML with unescaped resource name in getCodeSpan
potential XSS via dangerouslySetInnerHTML with unescaped resource name in getCodeSpan. Red Hat rates this low (CVSS 3.1). Weakness: CWE-79. Affected products named by the advisory: Multicluster Engine for Kubernetes; Red Hat Advanced Cluster Management for Kubernetes 2.
Low [CVE-2026-18096] IBM Db2 Vulnerability in NetApp Products
IBM Db2 Server version 12.1.5 on all platforms is susceptible to a vulnerability which could allow a local attacker to cause a denial of service due to a memory leak. Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
Low [CVE-2026-55987] Administrator-deactivated accounts can be reactivated via OAuth2 sign-in
Administrator-deactivated accounts can be reactivated via OAuth2 sign-in. Red Hat rates this low (CVSS 3.5). Weakness: CWE-807.
Low [CVE-2026-55984] Denial of Service via Null Pointer Dereference in AddTime API
Denial of Service via Null Pointer Dereference in AddTime API. Red Hat rates this low (CVSS 2.7). Weakness: CWE-476.
Low [CVE-2026-73626] Extension allowlist bypass allows unauthorized installations
Extension allowlist bypass allows unauthorized installations. Red Hat rates this low. Weakness: CWE-358.
Low [CVE-2026-73492] Arbitrary code execution due to URI scheme bypass
Arbitrary code execution due to URI scheme bypass. Red Hat rates this low (CVSS 3.7). Weakness: CWE-76. Affected products named by the advisory: Red Hat 3scale API Management Platform 2; Red Hat Satellite 6.
Low [CVE-2026-73491] Cross-Site Scripting via malformed `javascript:` URI parsing
Cross-Site Scripting via malformed `javascript:` URI parsing. Red Hat rates this low (CVSS 3.7). Weakness: CWE-1289.
Low [CVE-2025-9486] GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed a user with a pending membership to receive permissions granted by a custom role, due to incorrect privilege assignment that did not account for membership state
GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed a user with a pending membership to receive permissions granted by a custom role, due to incorrect privilege assignment that did not account for membership state.
Low [CVE-2026-0290] Prisma Browser: Sensitive Information Disclosure Vulnerability
Palo Alto Networks incorporated the following Chromium security fixes into our products: CVESummaryCVE-2026-13774 Use after free in ExtensionsCVE-2026-13775 Use after free in GPUCVE-2026-13776 Type Confusion in DawnCVE-2026-13777 Insufficient validation of untrusted input in iOSWebCVE-2026-13778 Use after free in WebUSBCVE-2026-13779 Use after free in ChromotingCVE-2026-13780 Insufficient validation of untrusted input in ANGLECVE-2026-13781 Insufficient validation of untrusted input in SkiaCVE-2026-13782 Use after free in BrowserCVE-2026-13783 Use after free in ViewsCVE-2026-13784 Use after free in ViewsCVE-2026-13785 Use after free in BluetoothCVE-2026-13786 Use af
Low [CVE-2026-70467] server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIEM 7.3.0 through 7.3.5, FortiSIEM 7.2 all versions, FortiSIEM 7.1 all versions, FortiSIEM 7.0 all versions, FortiSIEM 6.7 all versions, FortiSIEM 6.6 all versions, FortiSIEM 6.5 all versions may allow attacker to execute unauthorized code or commands via <insert attack vector here>
A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIEM 7.3.0 through 7.3.5, FortiSIEM 7.2 all versions, FortiSIEM 7.1 all versions, FortiSIEM 7.0 all versions, FortiSIEM 6.7 all versions, FortiSIEM 6.6 all versions, FortiSIEM 6.5 all versions may allow attacker to execute unauthorized code or commands
Low [CVE-2026-70467] Server-Side Request Forgery (SSRF)
CVSSv3 Score: 3.4 A Server-Side request forgery (SSRF) [CWE-918] vulnerability in FortiSIEM GUI may allow an authenticated attacker to send HTTP requests originating from the targeted device via specially crafted HTTP requests Revised on 2026-08-12 00:00:00
Low [CVE-2026-73281] ssh-agent allows remote execution of local operations
ssh-agent allows remote execution of local operations. Red Hat rates this low (CVSS 3.5). Weakness: CWE-266. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: openssh.
Low [CVE-2026-73071] Denial of Service via Use-After-Free in JSON Decoding
Denial of Service via Use-After-Free in JSON Decoding. Red Hat rates this low (CVSS 3.3). Weakness: CWE-416.
Low [CVE-2026-11736] stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make unauthorized modification to router software and functionality
A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make unauthorized modification to router software and functionality. Affected products named by the advisory: RAX20; RAX35v2; RAX41; RAX41v2; and 4 more. Affected products named by the advisory: RAX42; RAX42v2; RAX43; RAX43v2.
Low [CVE-2026-11735] stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to make unauthorized modification to the router's software and functionality
A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to make unauthorized modification to the router's software and functionality. Affected products named by the advisory: R7000; RAX20; RAX35v2; RAX41; and 4 more. Affected products named by the advisory: RAX41v2; RAX42; RAX42v2; RAX43.