Complete feed
Recently updated
Advisories the vendor has revised
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Low [CVE-2026-76885] Denial of Service via Tektronix K12xx file parsing
Denial of Service via Tektronix K12xx file parsing. Red Hat rates this low (CVSS 3.1). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Low [CVE-2026-76888] Heap-based Buffer Overflow in RDP dissector leads to Denial of Service
Heap-based Buffer Overflow in RDP dissector leads to Denial of Service. Red Hat rates this low (CVSS 3.1). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Low [CVE-2026-76887] Denial of service via heap-based buffer overflow in dissection engine
Denial of service via heap-based buffer overflow in dissection engine. Red Hat rates this low (CVSS 3.1). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Low [CVE-2026-76884] Denial of Service via ERF file parser crash
Denial of Service via ERF file parser crash. Red Hat rates this low (CVSS 3.3). Weakness: CWE-130. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Critical [CVE-2026-21580] This Critical severity Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability was introduced in versions 7.1.1, 7.4.0, 7.13.0, 7.17.0, 7.19.0, 8.0.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence Data Center and Server
This Critical severity Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability was introduced in versions 7.1.1, 7.4.0, 7.13.0, 7.17.0, 7.19.0, 8.0.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence Data Center and Server. This Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability, with a CVSS Score of 8.6, allows an unauthenticated attacker to execute arbitrary HTML or JavaScript code on a victims browser, perform actions as a higher-privileged user, and to get into the system utilizing loopholes exposed from security best-practices being overlooked. Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Confluence Data Center and Server 9.2: Upgrade to a release greater than or equal to 9.2.21 See the release notes ([ ]). This vulnerability was reported via our Bug Bounty program. Affected products named by the advisory: Confluence Server.
Critical [CVE-2026-76044] Arbitrary code execution due to a race condition in USB
Arbitrary code execution due to a race condition in USB. Red Hat rates this important (CVSS 9). Weakness: CWE-368.
Critical [CVE-2026-66780] flat broker trust model grants every spoke full CRUD on all endpoints, secrets, and endpointslices in broker namespace
flat broker trust model grants every spoke full CRUD on all endpoints, secrets, and endpointslices in broker namespace. Red Hat rates this important (CVSS 9.9). Weakness: CWE-284. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/submariner-addon-rhel9:1787362694, rhacm2/submariner-addon-rhel9:1787689013, rhacm2/submariner-addon-rhel9:1787365971, rhacm2/submariner-addon-rhel9:1787362658. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.
Critical [CVE-2026-18963] Unauthenticated account takeover via reset-credentials flow bypass
Unauthenticated account takeover via reset-credentials flow bypass. Red Hat rates this critical (CVSS 9.1). Weakness: CWE-640. Red Hat lists fixing advisory RHSA-2026:56524 with package rhbk/keycloak-rhel9:26.6-12, rhbk-keycloak-rhel9/rhbk-keycloak-rhel9, keycloak-services, rhbk-openshift-rhel9/rhbk-openshift-rhel9. Affected products named by the advisory: Red Hat build of Keycloak 26.4; Red Hat build of Keycloak 26.6.
Critical [CVE-2026-34884] SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP
SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP. This issue affects Apache SkyWalking MCP: 0.1.0. Users are recommended to upgrade to version 0.2.0, which fixes this issue.
High [CVE-2026-21584] Confluence: This High severity Improper Authorization vulnerability was introduced in versions 10.0.0, 10.1.0, 10.2.0, 11.0.0, 12.0.0, and 12.1.0 of Bamboo Data Center
This High severity Improper Authorization vulnerability was introduced in versions 10.0.0, 10.1.0, 10.2.0, 11.0.0, 12.0.0, and 12.1.0 of Bamboo Data Center. This Improper Authorization vulnerability, with a CVSS Score of 7.6, allows an authenticated attacker to gain unintended access and can lead to the exposure of resources or functionality, possibly providing attackers with sensitive information or even execute arbitrary code. Atlassian recommends that Bamboo Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: - Bamboo Data Center 10.2: Upgrade to a release greater than or equal to 10.2.22 See the release notes ( ). This vulnerability was reported via our Penetration Testing program.
High [CVE-2026-21582] Confluence: This High severity BASM (Broken Authentication & Session Management) vulnerability known as CVE-2026-21582 was introduced in version 7.2.1 of Crowd Data Center
This High severity BASM (Broken Authentication & Session Management) vulnerability known as CVE-2026-21582 was introduced in version 7.2.1 of Crowd Data Center. This BASM (Broken Authentication & Session Management) vulnerability, with a CVSS Score of 8.8, allows an unauthenticated attacker to perform actions as another user. Atlassian recommends that Crowd Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Crowd Data Center 7.2: Upgrade to a release greater than or equal to 7.2.2 See the release notes ( ). This vulnerability was reported via our Penetration Testing program.
High [CVE-2026-76038] Remote code execution via type confusion in crafted HTML.
Remote code execution via type confusion in crafted HTML. Red Hat rates this important (CVSS 8.8). Weakness: CWE-843.
High [CVE-2026-76041] Information leak allows web origin policy bypass
Information leak allows web origin policy bypass. Red Hat rates this important (CVSS 7.4). Weakness: CWE-346.
High [CVE-2026-76047] Arbitrary code execution via type confusion in V8
Arbitrary code execution via type confusion in V8. Red Hat rates this important (CVSS 8.3). Weakness: CWE-843.
High [CVE-2026-76045] Arbitrary code execution via use-after-free
Arbitrary code execution via use-after-free. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825.
High [CVE-2026-76043] Arbitrary code execution via incorrect calculation in HTML processing
Arbitrary code execution via incorrect calculation in HTML processing. Red Hat rates this important (CVSS 8.8). Weakness: CWE-190.
High [CVE-2026-76039] Information disclosure via incorrect reference resolution
Information disclosure via incorrect reference resolution. Red Hat rates this important (CVSS 7.1). Weakness: CWE-386.
High [CVE-2026-76040] Arbitrary code execution via use-after-free vulnerability
Arbitrary code execution via use-after-free vulnerability. Red Hat rates this important (CVSS 8.3). Weakness: CWE-825.
High [CVE-2026-76037] Arbitrary Code Execution via Link Following
Arbitrary Code Execution via Link Following. Red Hat rates this important (CVSS 8.2). Weakness: CWE-59.
High [CVE-2026-76033] Site isolation bypass due to inappropriate CORS implementation
Site isolation bypass due to inappropriate CORS implementation. Red Hat rates this important (CVSS 8.7). Weakness: CWE-653.