Complete feed
Security advisories & CVEs
7822 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Critical [CVE-2026-63037] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This appears to allow SQL injection in the ORDER BY clause against the Manager backend database. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1].
Critical [CVE-2026-11861] Obtaining TGS with impersonating cname through trust relationships
Obtaining TGS with impersonating cname through trust relationships. Red Hat rates this moderate (CVSS 9.6). Weakness: CWE-266. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: ipa.
High [CVE-2026-72848] Server-Side Request Forgery and Information Disclosure via nested sitemap entries
Server-Side Request Forgery and Information Disclosure via nested sitemap entries. Red Hat rates this important (CVSS 8.6). Weakness: CWE-918. Affected products named by the advisory: Exploit Intelligence; Migration Toolkit for Applications 8; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-69519] Azure Stack HCI Information Disclosure Vulnerability
Azure Stack HCI Information Disclosure Vulnerability
High [CVE-2026-55893] Heap buffer overflow with potential code execution
Heap buffer overflow with potential code execution. Red Hat rates this moderate (CVSS 7). Weakness: CWE-805. Red Hat lists fixing advisory RHSA-2026:59419 with package capstone-main-5.0.8-0.3.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: capstone.
High [CVE-2026-73137] cross-namespace Secret exfiltration via HelmRelease.repo.secretRef.namespace
cross-namespace Secret exfiltration via HelmRelease.repo.secretRef.namespace. Red Hat rates this important (CVSS 7.7). Weakness: CWE-200. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/multicluster-operators-subscription-rhel9:1787242108, rhacm2/multicluster-operators-subscription-rhel9:1787263693, rhacm2/multicluster-operators-subscription-rhel9:1787242321, rhacm2/multicluster-operators-subscription-rhel9:1787240030. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat Advanced Cluster Management for Kubernetes 2.17.
High [CVE-2026-43678] Denial of Service via specially crafted WebSocket frame
Denial of Service via specially crafted WebSocket frame. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-53587] Denial of Service due to heap out-of-bounds read from malicious Git server
Denial of Service due to heap out-of-bounds read from malicious Git server. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:59361 with package libgit2-main-1.9.7-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat package: rust; Red Hat package: libgit2.
High [CVE-2026-66787] cross-cluster DNS spoofing via unvalidated EndpointSlice and ServiceImport IPs
cross-cluster DNS spoofing via unvalidated EndpointSlice and ServiceImport IPs. Red Hat rates this important (CVSS 8.7). Weakness: CWE-345. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.
High [CVE-2026-63387] Off-by-one stack buffer overflow leading to denial of service or data corruption
Off-by-one stack buffer overflow leading to denial of service or data corruption. Red Hat rates this important (CVSS 8.6). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat package: libevent2.
High [CVE-2026-63384] Denial of Service via integer conversion error in `evtag_unmarshal_header`
Denial of Service via integer conversion error in `evtag_unmarshal_header`. Red Hat rates this important (CVSS 7.5). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:60853 with package libevent-main-2.1.12-19.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat package: libevent2.
High [CVE-2026-63495] Remote denial of service via unbounded memory accumulation in WebSocket server
Remote denial of service via unbounded memory accumulation in WebSocket server. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:41176 with package libevent-main-2.1.12-19.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: libevent2.
High [CVE-2026-63383] Denial of Service via malformed RPC data
Denial of Service via malformed RPC data. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:60853 with package libevent-main-2.1.12-19.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat package: libevent2.
High [CVE-2026-63388] Arbitrary code execution via heap out-of-bounds write in AF_UNIX handling
Arbitrary code execution via heap out-of-bounds write in AF_UNIX handling. Red Hat rates this important (CVSS 8.4). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:60853 with package libevent-main-2.1.12-19.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat package: libevent2.
High [CVE-2026-54770] Open redirect vulnerability leading to phishing and token theft
Open redirect vulnerability leading to phishing and token theft. Red Hat rates this important (CVSS 7.4). Weakness: CWE-601. Affected products named by the advisory: Red Hat Ceph Storage 4; Red Hat Ceph Storage 7; Red Hat Ceph Storage 8; Red Hat Enterprise Linux 6; and 7 more. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat OpenShift Container Platform 4; Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; and 3 more.
High [CVE-2026-15679] Hugging Face PyTorch Image Models: Remote Code Execution via Deserialization of Untrusted Data
Hugging Face PyTorch Image Models: Remote Code Execution via Deserialization of Untrusted Data. Red Hat rates this important (CVSS 8.8). Weakness: CWE-502. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-18309] Remote Code Execution via APNG file parsing integer overflow
Remote Code Execution via APNG file parsing integer overflow. Red Hat rates this important (CVSS 7.8). Weakness: CWE-190. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat package: gimp.
High [CVE-2026-18308] Remote Code Execution via TIF File Parsing Integer Overflow
Remote Code Execution via TIF File Parsing Integer Overflow. Red Hat rates this important (CVSS 7.8). Weakness: CWE-190. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 9; Red Hat package: gimp.
High [CVE-2026-18307] Remote code execution via TIF file parsing heap-based buffer overflow
Remote code execution via TIF file parsing heap-based buffer overflow. Red Hat rates this important (CVSS 7.8). Weakness: CWE-131. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: gimp.
High [CVE-2026-18306] Remote Code Execution via SGI File Parsing Integer Overflow
Remote Code Execution via SGI File Parsing Integer Overflow. Red Hat rates this important (CVSS 7.8). Weakness: CWE-190. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: gimp.