Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.5Red Hat

High [CVE-2026-74949] Privilege escalation due to use-after-free in the Graphics: Canvas2D component

Privilege escalation due to use-after-free in the Graphics: Canvas2D component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-74949
Unclassified
Aug 18, 2026
High7.5Red Hat

High [CVE-2026-74943] Use-after-free in the Graphics: ImageLib component

Use-after-free in the Graphics: ImageLib component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-74943
Unclassified
Aug 18, 2026
High7.5Red Hat

High [CVE-2026-74942] Privilege escalation in the Remote Settings Client component

Privilege escalation in the Remote Settings Client component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-266. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-74942
Unclassified
Aug 18, 2026
High7.5Red Hat

High [CVE-2026-74944] Use-after-free in the DOM: Core & HTML component

Use-after-free in the DOM: Core & HTML component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-74944
Unclassified
Aug 18, 2026
High7.5Red Hat

High [CVE-2026-74945] Information disclosure in the Graphics: Text component

Information disclosure in the Graphics: Text component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-201. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-74945
Unclassified
Aug 18, 2026
High7.5Red Hat

High [CVE-2026-74941] Privilege escalation in the Graphics: CanvasWebGL component

Privilege escalation in the Graphics: CanvasWebGL component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-266. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-74941
Unclassified
Aug 18, 2026
High7.5Red Hat

High [CVE-2026-74940] Use-after-free in the Graphics: Text component

Use-after-free in the Graphics: Text component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-74940
Unclassified
Aug 18, 2026
High7.5Red Hat

High [CVE-2026-74939] Privilege escalation in the DOM: Navigation component

Privilege escalation in the DOM: Navigation component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-266. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-74939
Unclassified
Aug 18, 2026
High7.5Red Hat

High [CVE-2026-74934] Site isolation issue in the Graphics: CanvasWebGL component

Site isolation issue in the Graphics: CanvasWebGL component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-653. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-74934
Unclassified
Aug 18, 2026
High7.5Red Hat

High [CVE-2026-74936] Use-after-free in the JavaScript: WebAssembly component

Use-after-free in the JavaScript: WebAssembly component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-74936
Unclassified
Aug 18, 2026
High7.5Red Hat

High [CVE-2026-74935] Privilege escalation in the DOM: Networking component

Privilege escalation in the DOM: Networking component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-266. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-74935
Unclassified
Aug 18, 2026
High7.3Red Hat Updated

High [CVE-2026-75838] Cross-Site Scripting via IN_PLACE sanitization

Cross-Site Scripting via IN_PLACE sanitization. Red Hat rates this important (CVSS 7.3). Weakness: CWE-79. Affected products named by the advisory: Migration Toolkit for Virtualization; Multicluster Engine for Kubernetes; Node HealthCheck Operator; OpenShift Service Mesh 3; and 15 more. Affected products named by the advisory: Red Hat 3scale API Management Platform 2; Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Advanced Cluster Security 4; Red Hat Ansible Automation Platform 2; and 11 more.

CVE-2026-75838
Unclassified
Aug 18, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-70906] Improve font loading (2026-08 Security Update)

Improve font loading (2026-08 Security Update). Red Hat rates this moderate (CVSS 7.5). Red Hat lists fixing advisory RHSA-2026:55799 with package java-25-openjdk-portable, java-25-openjdk-1:25.0.4.1.1-1.1.el9, java-25-openjdk-windows, java-25-openjdk-main-25.0.4.1.1-1.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.

CVE-2026-70906
Unclassified
Aug 18, 2026
Medium6.8Red Hat Updated

Medium [CVE-2026-71084] Denial of Service via unauthenticated local access

Denial of Service via unauthenticated local access. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat package: mysql-connector-odbc.

CVE-2026-71084
Red Hat Enterprise Linux
Aug 18, 2026
Medium6.5Red Hat Updated

Medium [CVE-2026-71079] Denial of Service via network access by a low privileged attacker

Denial of Service via network access by a low privileged attacker. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat package: mysql-connector-odbc.

CVE-2026-71079
Red Hat Enterprise Linux
Aug 18, 2026
Medium6.8Red Hat

Medium [CVE-2026-76042] Information disclosure via uninitialized resource in GPU

Information disclosure via uninitialized resource in GPU. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-824.

CVE-2026-76042
Unclassified
Aug 18, 2026
Medium6.1Red Hat Updated

Medium [CVE-2026-16732] Request spoofing via numeric trustProxy configuration

Request spoofing via numeric trustProxy configuration. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-501. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Dev Spaces.

CVE-2026-16732
Unclassified
Aug 18, 2026
Medium5.4Red Hat Updated

Medium [CVE-2026-18504] Schema validation bypass via root primitive coercion mismatch

Schema validation bypass via root primitive coercion mismatch. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-843. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Dev Spaces.

CVE-2026-18504
Unclassified
Aug 18, 2026
Medium6.5Red Hat Updated

Medium [CVE-2026-49452] CSS Injection via Presentational Hints

WeasyPrint helps web developers to create PDF documents. Prior to 69.0, WeasyPrint embeds unescaped HTML presentational-hint attribute values into CSS in weasyprint/css/__init__.py when presentational_hints=True. The background attribute is inserted into a background-image:url() declaration and parsed by tinycss2.parse_blocks_contents(), allowing untrusted HTML to inject additional CSS declarations. Applications that render untrusted HTML with presentational hints enabled can be affected by CSS injection and server-side requests through injected url() values. This issue is fixed in version 69.0. This vulnerability allows a remote attacker to inject arbitrary CSS, potentially leading to information disclosure or the initiation of server-side requests through specially crafted url() values. Red Hat Ansible Automation Platform 2.5 ships WeasyPrint 69.0, which already includes the fix for this vulnerability, and is therefore not affected. The WeasyPrint package in EPEL ships a version within the vulnerable range. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N). Weakness: CWE-79.

CVE-2026-49452
Unclassified
Aug 18, 2026
Medium6.5Vendor: HighRed Hat

Medium [CVE-2026-66781] IPsec PSK stored cleartext in Submariner CR spec

IPsec PSK stored cleartext in Submariner CR spec. Red Hat rates this important (CVSS 6.5). Weakness: CWE-312. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/submariner-addon-rhel9:1787362694, rhacm2/submariner-addon-rhel9:1787689013, rhacm2/submariner-addon-rhel9:1787365971, rhacm2/submariner-addon-rhel9:1787362658. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.

CVE-2026-66781
Unclassified
Aug 18, 2026