Complete feed
Recently updated
Advisories the vendor has revised
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-63016] Uncontrolled Resource Consumption vulnerability in Apache InLong
Uncontrolled Resource Consumption vulnerability in Apache InLong. Users could affect operational configuration or allow upload of non-official packages. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1]
Medium [CVE-2026-63015] Uncontrolled Resource Consumption vulnerability in Apache InLong
Uncontrolled Resource Consumption vulnerability in Apache InLong. Non-template responsible persons can view template information. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1]
Medium [CVE-2026-73199] NULL Pointer Dereference in `ipa-enrollment` Extended Operation (`JOIN_OID`) via Missing Request Value
NULL Pointer Dereference in `ipa-enrollment` Extended Operation (`JOIN_OID`) via Missing Request Value. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: ipa.
Medium [CVE-2026-73196] Authenticated DoS in `otptoken-add` via unbounded OTP key decoding/re-encoding
Authenticated DoS in `otptoken-add` via unbounded OTP key decoding/re-encoding. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: ipa.
Medium [CVE-2026-76957] Memory corruption vulnerability allows arbitrary code execution or denial of service
Memory corruption vulnerability allows arbitrary code execution or denial of service. Red Hat rates this moderate (CVSS 4.9). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:60451 with package expat-main-2.8.3-0.1.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 9 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: expat; and 5 more.
Medium [CVE-2026-76956] Denial of Service via hash flooding attack with crafted XML
Denial of Service via hash flooding attack with crafted XML. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-331. Red Hat lists fixing advisory RHSA-2026:60451 with package expat-main-2.8.3-0.1.1.hum1. Affected product named by the advisory: Red Hat Hardened Images.
Medium [CVE-2026-43804] Visiting a website may lead to an app denial-of-service
Visiting a website may lead to an app denial-of-service. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-664. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat package: webkitgtk3; Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.
Medium [CVE-2026-64713] Websites may know if the user has visited a given link
Websites may know if the user has visited a given link. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-200. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat package: webkitgtk3; Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.
Medium [CVE-2026-64728] Maliciously crafted web content may violate iframe sandboxing policy
Maliciously crafted web content may violate iframe sandboxing policy. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-693. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat package: webkitgtk3; Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.
Medium [CVE-2026-64730] Visiting a website that frames malicious content may lead to UI spoofing
Visiting a website that frames malicious content may lead to UI spoofing. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-451. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat package: webkitgtk3; Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.
Low [CVE-2026-77648] Server-Side Request Forgery allows internal URL access by administrators
Server-Side Request Forgery allows internal URL access by administrators. Red Hat rates this low (CVSS 2.2). Weakness: CWE-918.
Low [CVE-2026-53584] Submodule path traversal allows arbitrary directory creation
Submodule path traversal allows arbitrary directory creation. Red Hat rates this low (CVSS 3.5). Weakness: CWE-22. Red Hat lists fixing advisory RHSA-2026:59361 with package libgit2-main-1.9.7-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat package: rust; Red Hat package: libgit2.
Critical [CVE-2026-70496] operator ClusterRole is cluster-admin equivalent via impersonate, RBAC write, CSR approve, and ManifestWork
operator ClusterRole is cluster-admin equivalent via impersonate, RBAC write, CSR approve, and ManifestWork. Red Hat rates this important (CVSS 9.9). Weakness: CWE-250. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/acm-search-v2-rhel9:1787682033, rhacm2/acm-search-v2-rhel9:1787681674, rhacm2/acm-search-v2-rhel9:1787681686, rhacm2/acm-search-v2-rhel9:1787682112. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.
Critical [CVE-2026-71470] Search CR imageOverride/arguments/envVar flow unsanitized into pods running impersonating SA
Search CR imageOverride/arguments/envVar flow unsanitized into pods running impersonating SA. Red Hat rates this important (CVSS 9.1). Weakness: CWE-913. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/acm-search-v2-rhel9:1787682033, rhacm2/acm-search-v2-rhel9:1787681674, rhacm2/acm-search-v2-rhel9:1787681686, rhacm2/acm-search-v2-rhel9:1787682112. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.
Critical [CVE-2026-20231 +4] Cisco Secure Workload Software Security Hardening Release: August 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and to streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class — Common Weakness Enumeration (CWE) — and assigned a single Common Vulnerabilities and Exposures Identifier (CVE ID) to each CWE grouping. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
Critical [CVE-2026-20030 +3] Cisco Crosswork Security Hardening Release: August 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and to streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class — Common Weakness Enumeration (CWE) — and assigned a single Common Vulnerabilities and Exposures Identifier (CVE ID) to each CWE grouping. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. Affected product named by the advisory: Crosswork Planning.
Critical [CVE-2026-66794] unauthenticated SSRF to arbitrary managed-cluster services via public Route
unauthenticated SSRF to arbitrary managed-cluster services via public Route. Red Hat rates this important (CVSS 9.3). Weakness: CWE-918. Red Hat lists fixing advisory RHSA-2026:59593 with package multicluster-engine/cluster-proxy-addon-rhel9:1787275519, multicluster-engine/cluster-proxy-rhel9:1787276784, multicluster-engine/cluster-proxy-addon-rhel9:1787275318, multicluster-engine/cluster-proxy-addon-rhel9:1787274923. Affected product named by the advisory: Multicluster Engine for Kubernetes.
High [CVE-2026-76139] Bundle build execs unpinned stolostron/release@master with full build credentials
Bundle build execs unpinned stolostron/release@master with full build credentials. Red Hat rates this important (CVSS 8). Weakness: CWE-829. Red Hat lists fixing advisory RHSA-2026:60401 with package rhacm2/acm-operator-bundle:1787712120, rhacm2/acm-operator-bundle:1787738299, rhacm2/acm-operator-bundle:1787704547, rhacm2/acm-operator-bundle:1787711895. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.
High [CVE-2026-68553] Format string vulnerability leads to denial of service and information disclosure
Format string vulnerability leads to denial of service and information disclosure. Red Hat rates this important (CVSS 7.1). Weakness: CWE-134.
High [CVE-2026-75569] Bundle-generation business logic fetched from mutable stolostron/release@master
Bundle-generation business logic fetched from mutable stolostron/release@master. Red Hat rates this important (CVSS 7.7). Weakness: CWE-829. Red Hat lists fixing advisory RHSA-2026:59643 with package multicluster-engine/mce-operator-bundle:1787318262, multicluster-engine/mce-operator-bundle:1787321579, multicluster-engine/mce-operator-bundle:1787263075, multicluster-engine/mce-operator-bundle:1787317415. Affected product named by the advisory: Multicluster Engine for Kubernetes.