Complete feed
Security advisories & CVEs
7850 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-64778] Visiting a maliciously crafted website may leak sensitive data
Visiting a maliciously crafted website may leak sensitive data. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-200. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat package: webkitgtk3; Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.
Medium [CVE-2026-73560] Server-Side Request Forgery and arbitrary file read via improper media processing
Server-Side Request Forgery and arbitrary file read via improper media processing. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-918. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
Medium [CVE-2026-71486] Denial of Service via unbounded token ID decoding
Denial of Service via unbounded token ID decoding. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-770. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
Medium [CVE-2026-59894] Arbitrary code execution via unescaped backslashes in generated snippets
Arbitrary code execution via unescaped backslashes in generated snippets. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-94. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Discovery 2; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4; and 7 more. Affected products named by the advisory: Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0; Red Hat Satellite 6; and 3 more.
Medium [CVE-2026-19999] Remote buffer overflow allows information disclosure or denial of service
Remote buffer overflow allows information disclosure or denial of service. Red Hat rates this moderate (CVSS 5.6). Weakness: CWE-120.
Medium [CVE-2026-19970] Remote heap-based buffer overflow vulnerability
Remote heap-based buffer overflow vulnerability. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: qt6-qtquick3d; Red Hat package: qt5-qt3d.
Medium [CVE-2026-19969] Buffer overflow in 3DGS MDL7 model processing
Buffer overflow in 3DGS MDL7 model processing. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: qt6-qtquick3d; Red Hat package: qt5-qt3d.
Medium [CVE-2026-19968] Denial of service via heap-based buffer overflow in 3DGS MDL7 Model Parser
Denial of service via heap-based buffer overflow in 3DGS MDL7 Model Parser. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: qt6-qtquick3d; Red Hat package: qt5-qt3d.
Medium [CVE-2026-19967] Heap-based buffer overflow in file decompression
Heap-based buffer overflow in file decompression. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: qt6-qtquick3d; Red Hat package: qt5-qt3d.
Medium [CVE-2026-74579] fix mask build for partial field offload
fix mask build for partial field offload. Red Hat rates this low (CVSS 5.5). Weakness: CWE-1335. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-74796] Arbitrary file write via symlink following path traversal
Arbitrary file write via symlink following path traversal. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-59.
Medium [CVE-2024-58375] Sensitive information disclosure via static evaluation
Sensitive information disclosure via static evaluation. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-497.
Medium [CVE-2026-74578] algif_skcipher - force synchronous processing on trees without ctx->state
algif_skcipher - force synchronous processing on trees without ctx->state. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1204. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Low [CVE-2026-74797] Denial of Service via malicious zip archives
Denial of Service via malicious zip archives. Red Hat rates this low (CVSS 3.1). Weakness: CWE-400.
Critical [CVE-2026-68457] use opener credentials for FSCTL mutations
use opener credentials for FSCTL mutations. Red Hat rates this important (CVSS 9.1). Weakness: CWE-270. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.
High [CVE-2026-73194] DBI for Perl: Heap out-of-bounds write via unvalidated numeric placeholder
DBI for Perl: Heap out-of-bounds write via unvalidated numeric placeholder. Red Hat rates this important (CVSS 7.3). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: perl-dbi.
High [CVE-2026-73193] Arbitrary Code Execution on 32-bit Perl via Integer Wraparound
Arbitrary Code Execution on 32-bit Perl via Integer Wraparound. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat package: perl-dbi.
High [CVE-2026-72310] fix overflow in passthrough ioctl bounds check
fix overflow in passthrough ioctl bounds check. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-72042] Fix user refcount underflow in event delivery
Fix user refcount underflow in event delivery. Red Hat rates this important (CVSS 7). Weakness: CWE-825.
High [CVE-2026-72069] Fix the incorrect RCU protection in rt_spin_unlock
Fix the incorrect RCU protection in rt_spin_unlock(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.