Complete feed
Recently updated
Advisories the vendor has revised
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Low [CVE-2026-74977] Integer overflow in the Graphics component
Integer overflow in the Graphics component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-190.
Low [CVE-2026-74978] Clickjacking issue in the Widget component
Clickjacking issue in the Widget component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-1021.
Low [CVE-2026-74979] Mitigation bypass in the Add-ons Manager component
Mitigation bypass in the Add-ons Manager component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-807.
Low [CVE-2026-74975] Spoofing issue in the Downloads component in Firefox for Android
Spoofing issue in the Downloads component in Firefox for Android. Red Hat rates this low (CVSS 3.4). Weakness: CWE-494.
Low [CVE-2026-74983] Mitigation bypass in the Data Loss Prevention component
Mitigation bypass in the Data Loss Prevention component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-807. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Low [CVE-2026-74976] JIT miscompilation in the JavaScript Engine: JIT component
JIT miscompilation in the JavaScript Engine: JIT component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-733. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Low [CVE-2026-23938] Denial of Service via crafted JavaScript scripts
Denial of Service via crafted JavaScript scripts. Red Hat rates this low (CVSS 2.7). Weakness: CWE-770.
Low [CVE-2026-60589] Improve Resource Resolving (2026-08 Security Update)
Improve Resource Resolving (2026-08 Security Update). Red Hat rates this moderate (CVSS 3.7). Red Hat lists fixing advisory RHSA-2026:55788 with package java-21-openjdk-portable-main-21.0.12.1.1-0.1.hum1, java-25-openjdk-1:25.0.4.1.1-1.1.el9, java-25-openjdk-windows, java-25-openjdk-main-25.0.4.1.1-1.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8.
Critical [CVE-2026-66795] CSR auto-approver does not validate certificate Subject, signerName, or requester identity
CSR auto-approver does not validate certificate Subject, signerName, or requester identity. Red Hat rates this important (CVSS 9.1). Weakness: CWE-295. Red Hat lists fixing advisory RHSA-2026:59593 with package multicluster-engine/managedcluster-import-controller-rhel9:1787078307, multicluster-engine/managedcluster-import-controller-rhel9:1786577915, multicluster-engine/managedcluster-import-controller-rhel9:1787260779, multicluster-engine/managedcluster-import-controller-rhel9:1787259044. Affected product named by the advisory: Multicluster Engine for Kubernetes.
Critical [CVE-2026-71472] Shell-command and SQL injection in postgresql-start.sh via CR-supplied WORK_MEM
Shell-command and SQL injection in postgresql-start.sh via CR-supplied WORK_MEM. Red Hat rates this important (CVSS 9.1). Weakness: CWE-78. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/acm-search-v2-rhel9:1787682033, rhacm2/acm-search-v2-rhel9:1787681674, rhacm2/acm-search-v2-rhel9:1787681686, rhacm2/acm-search-v2-rhel9:1787682112. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.
Critical [CVE-2026-66792] IsClusterAdmin trusts user-settable annotations on managed clusters
IsClusterAdmin() trusts user-settable annotations on managed clusters. Red Hat rates this important (CVSS 9.9). Weakness: CWE-863. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/multicluster-operators-application-rhel9:1787259284, rhacm2/multicluster-operators-application-rhel9:1787238598, rhacm2/multicluster-operators-subscription-rhel9:1787242108, rhacm2/multicluster-operators-application-rhel9:1787262214. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 3 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17; Red Hat OpenShift Container Platform 4.
High [CVE-2026-43794] Processing maliciously crafted web content may lead to memory corruption
Processing maliciously crafted web content may lead to memory corruption. Red Hat rates this important (CVSS 8.8). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat package: webkitgtk.
High [CVE-2026-64782] Processing maliciously crafted web content may lead to an unexpected Safari crash
Processing maliciously crafted web content may lead to an unexpected Safari crash. Red Hat rates this important (CVSS 8.8). Weakness: CWE-667. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat package: webkitgtk3; Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.
High [CVE-2026-65341] Processing maliciously crafted web content may lead to memory corruption
Processing maliciously crafted web content may lead to memory corruption. Red Hat rates this important (CVSS 8.8). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat package: webkitgtk3; Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.
High [CVE-2026-64781] Processing maliciously crafted web content may lead to an unexpected Safari crash
Processing maliciously crafted web content may lead to an unexpected Safari crash. Red Hat rates this important (CVSS 8.8). Weakness: CWE-20. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat package: webkitgtk.
High [CVE-2026-64715] Processing maliciously crafted web content may lead to an unexpected process crash
Processing maliciously crafted web content may lead to an unexpected process crash. Red Hat rates this important (CVSS 8.8). Weakness: CWE-416. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat package: webkitgtk3; Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.
High [CVE-2026-64780] Processing maliciously crafted web content may lead to an unexpected Safari crash
Processing maliciously crafted web content may lead to an unexpected Safari crash. Red Hat rates this important (CVSS 8.8). Weakness: CWE-20. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat package: webkitgtk3; Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.
High [CVE-2026-64849] Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding). Red Hat rates this important (CVSS 8.5). Weakness: CWE-918. Red Hat lists fixing advisory RHSA-2026:60520 with package rhoai/odh-mlflow-rhel9:1787226790. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).
High [CVE-2026-34398] Arbitrary Code Execution via malicious BIM project template
Arbitrary Code Execution via malicious BIM project template. Red Hat rates this important (CVSS 7.8). Weakness: CWE-94.
High [CVE-2026-34789] Arbitrary code execution via crafted document restoration
Arbitrary code execution via crafted document restoration. Red Hat rates this important (CVSS 7.8). Weakness: CWE-502.